Suspicious Remote Execution Tool Usage
Detects suspicious usage of remote execution tools like PsExec, WMIC, and PowerShell, which are commonly used for lateral movement by adversaries. The rule identifies instances where these tools are executed multiple times within a short period (more than 2 times in 5 minutes) from non-system accounts and outside of standard system directories, indicating potential malicious activity.
Microsoft Sentinel (KQL)

