Initial Access Broker RDP Login from New Country Followed by Discovery

This rule detects anomalous RDP (Logon Type 10) sessions occurring outside of typical business hours or from previously unseen geographic locations, followed closely by the execution of system discovery commands (net.exe, ipconfig.exe, whoami.exe, systeminfo.exe) within a 10-minute window. This behavior is indicative of post-exploitation reconnaissance following an unauthorized or suspicious remote access session.