Suspicious Network Connections to Common Ports from Internal IPs

This rule detects suspicious network connections originating from internal IP addresses to common service ports (DNS, SMB, RDP, WinRM) on remote, non-internal IP addresses. It flags instances where a single process on a device makes 10 or more such connections within an hour, which could indicate reconnaissance, lateral movement, or data exfiltration attempts.