VBScript Execution from Suspicious Document Names
This rule detects the execution of VBScript files (.vbs or .vbe) by wscript.exe or cscript.exe where the filename contains keywords commonly associated with phishing lures (e.g., 'Invoice', 'Bill', 'Statement', 'Report', 'Debit', 'Credit', 'Notice', 'Alert', 'Urgent', 'Payment'). The rule triggers if three or more such executions are observed within a one-hour window on a single device, indicating potential malicious activity often associated with phishing campaigns.
Microsoft Sentinel (KQL)

