Image Masquerading as Business Document
This rule detects the creation or modification of executable files (.com, .exe, .scr, .pif, .bat, .cmd) in common user directories (Documents, Downloads, Desktop) where the initiating process is a legitimate application like explorer.exe, winrar.exe, or 7z.exe. This pattern is often used in phishing attacks where malicious executables are disguised as benign documents.
Microsoft Sentinel (KQL)

