PetitPotam-style MS-EFSRPC NTLM Coercion (EfsRpcOpenFileRaw)

Detects anomalous network traffic patterns characteristic of the PetitPotam exploit, specifically targeting the MS-EFSRPC interface on Windows SMB pipes. This behavior is used to force a remote system to initiate authentication to a specified target, facilitating NTLM relay attacks.