Forced NTLM Authentication Capture via Responder, Inveigh, PetitPotam, or UNC Coercion

Detects the execution of known NTLM relay and credential harvesting tools such as Responder, Inveigh, and PetitPotam, or suspicious command-line patterns involving the use of 'net use' or common Windows binaries (e.g., powershell.exe, rundll32.exe) to access or force SMB authentication with remote IP addresses.