T1114 Email Collection via non-standard POP3/IMAP clients

This rule detects processes initiating network connections to standard POP3 (110, 995) and IMAP (143, 993) ports that are not identified as trusted, well-known mail clients. By filtering out connections from common email application paths and local IP ranges, it aims to identify potentially malicious processes, scripts, or non-standard tools attempting to perform email collection or exfiltration directly from mail servers.