T1021 Remote Services: New Logon Then Fast Execution

Detects anomalous remote interactive or network logons where the specific account and remote host/IP combination has not been observed in the previous 14 days. The rule correlates these new login events with subsequent process execution on the destination host within a short window (5 minutes) to identify potential lateral movement where an adversary uses valid credentials to log in and immediately execute commands.