RDP Lateral Movement via Unusual Process on Port 3389 (T1021.001)

Detects network connections over port 3389 (RDP) initiated by processes other than standard Remote Desktop clients (mstsc.exe). This rule specifically looks for suspicious indicators such as execution from non-standard or temporary file paths, or the use of common living-off-the-land binaries (like powershell.exe, cmd.exe, rundll32.exe) that might be acting as a proxy for remote access or lateral movement.