Emails with Macro-Enabled Documents
This rule detects emails containing macro-enabled documents (.docm, .xlsm, .pptm). It specifically looks for instances where a sender sends two or more such emails within an hour, which could indicate a targeted phishing attempt using malicious macros.
Microsoft Sentinel (KQL)

