Turla STOCKSTAY - Malicious RDP File Execution from Phishing Path

Detects the execution of RDP files (mstsc.exe) initiated by common application vectors (email clients, browsers, archive utilities) from suspicious user-writable paths like Temp, Downloads, or AppData directories. This behavior is consistent with Turla group's phishing delivery chain where malicious RDP files are used for persistence or lateral movement.