Suspicious Execution of Banking-Related Executable Files
Detects the creation of executable files (.exe, .com, .scr, .vbs, .js) that contain financial-themed keywords (e.g., GST, NEFT, RTGS, IMPS, Banking) in their filename. This pattern is commonly used in social engineering and phishing attacks to trick users into executing malicious payloads disguised as legitimate banking or financial documents.
Microsoft Sentinel (KQL)

