Vishing Callback RAT Spawned by Office or PDF Document Opener
This rule detects when common document-handling applications (such as Microsoft Office suite or PDF readers) spawn known remote access and support tools. This behavior is highly indicative of vishing-based social engineering attacks, where a user is tricked into downloading and executing a remote management tool via a malicious document.
SentinelOne

