QUICSILVER: copy /b reconstructs Windowsupdate.exe from header.doc+body.doc
This rule detects the use of the Windows 'copy /b' command to reconstruct an executable file (named Windowsupdate.exe) by concatenating two separate files ('header.doc' and 'body.doc'). This behavior is consistent with file-based reconstruction techniques used to bypass security controls by splitting payloads into seemingly benign components.
Microsoft Sentinel (KQL)

