2026 Critical Enterprise Intrusion Chain Detection: Internal Lateral Movement Fan-Out from Infostealer-Flagged Host

Detects the use of administrative utilities (psexec.exe, wmic.exe, powershell.exe, cmd.exe) initiating network connections over common remote management ports (135, 139, 445, 3389, 5985, 5986) to internal destinations. This behavior is indicative of lateral movement activity, particularly when initiated from a host that has recently engaged in credential harvesting or infostealer-related activity. The rule excludes common, expected sources to minimize noise.