That looks great, thanks for sharing!
I do have a couple of questions though…
Established TCP and UDP Connections
…it looks like it’s actually checking for established RDP connections, maybe should be renamed?
And on the Telnet client, is there actually a telnet client service, or should it actually be checking for telnet client processes? I don’t have the telnet client myself, so I am unsure but a telnet client service seems unlikely.