NovaCookies/Excel phishing campaign redirecting to known malicious domains via outbound connections
This rule detects potential phishing activity by correlating email delivery of Excel attachments with subsequent network connections to known malicious domains initiated by common browser or office processes. It identifies cases where a user may have opened a suspicious Excel file and initiated an outbound network request to a flagged domain within 24 hours of receiving the email.
Microsoft Sentinel (KQL)

