Office Assistant Supply Chain Attack Detection
This rule detects indicators associated with the 'Office Assistant' supply chain attack. It identifies malicious browser extensions by their IDs in file paths or names, and also detects known malicious file MD5s and C2 communication domains. The rule correlates file events and network events to provide a comprehensive view of the attack.
Microsoft Sentinel (KQL)

