SVG Smuggling - Browser Spawns Shell After SVG Write to Download/Temp
This rule detects the creation of an SVG file in common user-writable/temporary directories, followed closely (within 60 seconds) by the execution of common scripting interpreters (cmd.exe, powershell.exe, wscript.exe) by a web browser. This behavior is often associated with browser-based exploitation or malicious file downloads where an attacker uses an SVG or accompanying file to trigger secondary malicious processes.
Microsoft Sentinel (KQL)

