Turla STOCKSTAY - Malicious RDP File Execution from Phishing Path
Detects the execution of RDP files (mstsc.exe) initiated by common application vectors (email clients, browsers, archive utilities) from suspicious user-writable paths like Temp, Downloads, or AppData directories. This behavior is consistent with Turla group's phishing delivery chain where malicious RDP files are used for persistence or lateral movement.
Microsoft Sentinel (KQL)

