APT28 NotDoor: OUTLOOK.EXE Spawning Shell with Outbound C2 Connection
Detects Microsoft Outlook spawning a command-line interpreter (cmd.exe or powershell.exe) followed by a network connection originating from that interpreter within a 5-minute window. This behavior is highly suspicious and often indicative of malicious macro execution or exploit delivery via email attachments leading to command-and-control activity.
Splunk (SPL)

