How would I convert this rule to Netwitness? logsource: product: windows
service: security definition: The successful use of PtH for lateral
movement between workstations would trigger event ID 4624, a failed
logon attempt would trigger an event ID 4...