Vendor: Microsoft

June 14, 2023 · View on GitHub

Product: Azure

Use-Case: Phishing

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
20111
Event TypeRulesModels
process-createdT1566.001 - T1566.001
A-Exec-Outlook-Temp: A suspicious program was executed in the Outlook temp folder on this asset.
Exec-Outlook-Temp: A suspicious program was executed in the Outlook temp folder.