APT28 Spearphishing Lure RTF/DOC Opened via Office or Outlook
Detects the opening of suspected APT28 (Fancy Bear) spearphishing lure documents by Microsoft Office or Outlook. The rule monitors for file access, creation, or renaming events where the filename matches known lure patterns associated with APT28 activities, such as naming conventions containing 'BULLETEN', 'OperInformativ', 'Courses', 'Consultation', 'Weapons', or 'Smuggling' in Word or Outlook processes.
Microsoft Sentinel (KQL)

