Unusual Inbound Connections to Quick Share or Nearby Sharing Processes

Detects inbound network connections initiated by common Windows Nearby Sharing processes ('NearShare.exe', 'NearbySharing.exe', 'quickshare.exe', 'NearbyConnectionsService.exe') that occur on non-standard ports, potentially indicating unauthorized or malicious use of these utilities.