M365 Groups Phishing Follow-Up: Suspicious File Access in Group Mailbox
This rule detects when users access or download suspicious file types (specifically .xlsm, .docm, or .ics) from Microsoft SharePoint, Teams, or Exchange, where the filenames contain keywords associated with common phishing lures such as credentials, invoices, payroll, or password resets. This monitors for indicators of potential spearphishing attempts involving malicious documents or calendar invites within the M365 environment.
SentinelOne

