T1550 Pass-the-Hash/Ticket: NTLM or Kerberos Ticket Reuse Across Hosts

Detects anomalous authentication behavior where a user account utilizes the same authentication session (LogonId) or material to authenticate across multiple distinct destination hosts in a short timeframe. This rule monitors for both NTLM (Type 3) and Kerberos (TGS/TGT) events, which are indicative of lateral movement techniques such as Pass-the-Hash or Pass-the-Ticket.