Out-of-Network Remote Access Attempt Detected

This rule detects connection attempts to common administrative and remote access ports (RDP, SSH, SMB, RPC) from non-internal IP address ranges. Such activity may indicate an attempt to bypass Zero-Trust network policies or unauthorized remote access attempts from external or untrusted segments.