Quick Share Anomalous High-Frequency Remote Connections

Detects anomalous network activity originating from 'NearShareReceive.exe' (Windows Near Share) to public IP addresses on non-standard ports, potentially indicating unauthorized use of the Near Share feature for data staging or exfiltration.