T1091 Removable Media: Autorun.inf Drop & Multi-Host Execution

This rule detects potentially malicious activity associated with removable media (USB drives) by identifying two distinct patterns: first, the creation of an 'autorun.inf' file on a removable drive followed by the execution of a script or executable from that same drive shortly after. Second, it identifies executables appearing on removable media that are launched across multiple distinct hosts within a one-hour window, which may indicate worm-like spreading or mass-malware distribution via portable storage.