Microsoft Teams Spawning Suspicious Shell Processes - T1566.003/T1059
Detects instances where Microsoft Teams (teams.exe) initiates child processes that are commonly used as interpreters, such as cmd.exe, powershell.exe, mshta.exe, wscript.exe, or rundll32.exe. This activity is frequently associated with the execution of malicious payloads delivered via phishing or collaboration platforms.
SentinelOne

