Pass-the-Hash: NTLM network logon w/o Kerberos pre-auth (T1550.002)
This rule identifies potential lateral movement or account compromise by detecting accounts that have performed NTLM network logons or authentication (Events 4624/4776) without corresponding Kerberos pre-authentication or interactive logon events within a 15-minute window. This pattern often indicates the use of stolen credentials (e.g., Pass-the-Hash) to access network resources rather than standard interactive user activity.
Splunk (SPL)

