Detect DCs potentially being abused in Win-DDoS botnet attacks

This rule detects an unusually high number of outbound network connections originating from the Local Security Authority Subsystem Service (LSASS) process on a Windows machine. LSASS is a critical system process responsible for enforcing security policy on the system, including user authentication, and typically does not initiate a large number of outbound connections. A high count of outbound connections from LSASS could indicate credential dumping activity, where an attacker is exfiltrating harvested credentials, or other malicious activity compromising the LSASS process.