PsExec-style remote service creation via ADMIN$ + transient service

Detects the creation of suspicious services that are preceded by an administrative SMB share (ADMIN$) connection and a network logon event (Type 3) from the same source. This pattern is commonly used by lateral movement tools (like PsExec) to execute payloads remotely by installing a service, accessing the administrative share to drop the binary, and executing the service.