Unusual Inbound Connections to Quick Share or Nearby Sharing Processes
Detects inbound network connections initiated by common Windows Nearby Sharing processes ('NearShare.exe', 'NearbySharing.exe', 'quickshare.exe', 'NearbyConnectionsService.exe') that occur on non-standard ports, potentially indicating unauthorized or malicious use of these utilities.
Microsoft Sentinel (KQL)

