NotDoor APT28 Email Exfiltration via Outlook to chmilewskii Addresses

This rule detects activities associated with the NotDoor malware used by APT28 for email-based exfiltration. It specifically monitors for the creation of staging files in temporary directories, the use of Outlook.exe to establish external SMTP connections on common mail ports, and the transmission of emails to known adversary-controlled addresses.