Application/Executable: Network Detective Data Collector (nddc.exe)
WTF Behavior Description: The executable for Network Detective Data Collector displays false positive activity similar to Impacket's WMI/SMBexec
Link to Documentation of Behavior: It's a Rapid Fire Tools / Kaseya bit of tooling. Unfortunately I can't find specific section of documentation that explains the context of this activity.