Remote Logon Followed by Suspicious wmiprvse.exe Child Process
This rule detects potential lateral movement by identifying suspicious child processes (such as cmd, powershell, or rundll32) spawned by WmiPrvSE.exe shortly after a remote interactive or network logon on the same device.
Microsoft Sentinel (KQL)

