Teams.exe Drops MSI/EXE into User Temp or AppData - Impersonation Campaign
This rule detects when the Microsoft Teams process (Teams.exe) creates an executable or installer file (.exe or .msi) in common user-writable directories such as AppData, Temp, or Users/Public. This behavior is indicative of potential malicious activity, as legitimate Teams application updates and add-ins typically reside in specific, protected subdirectories within the Teams folder structure.
Microsoft Sentinel (KQL)

