T1543.003: Remote Service Creation for Lateral Movement (PsExec-style)

Detects the creation of Windows services immediately following a network logon event (Logon Type 3) using NTLM or Kerberos. The rule monitors for service names or file paths characteristic of PsExec-style remote execution tools, specifically focusing on suspicious paths (e.g., Temp, UNC paths) or file extensions (e.g., .bat, .ps1, .tmp) used by attackers to execute payloads laterally.