CalPhishing .ics Drop by Outlook or Browser in Downloads/Temp
Detects the creation of .ics calendar invitation files in common user download and temporary directories when originated by web browsers or Microsoft Outlook. This pattern is often indicative of spearphishing campaigns where attackers use weaponized calendar files to deliver malicious payloads or links, attempting to exploit users through social engineering.
SentinelOne

