Pass-the-Hash Activity via NTLM Logon (Mimikatz sekurlsa::pth)

Detects potential Pass-the-Hash (PtH) activity by monitoring Windows Security Event ID 4624 (Logon). The rule specifically targets logon type 9 (NewCredentials) combined with specific process/package names indicative of tools like Mimikatz, or anomalous NTLM network logons (logon type 3) that are not anonymous.