High Volume Remote Access Command Line Activity
This rule detects a high volume (5 or more within an hour) of process creation events where the command line contains keywords associated with remote access protocols like DCOM, WMI, or RPC. This could indicate an adversary utilizing these protocols for lateral movement or remote execution.
Microsoft Sentinel (KQL)

