Decoy TrainingAnnouncement.pdf opened via 'start /max' to mask backdoor install (Operation QUICSILVER)
This rule detects the execution of 'cmd.exe' with specific arguments 'start /max' used to open a file named 'TrainingAnnouncement.pdf'. This pattern is associated with Operation QUICSILVER, where attackers use this specific command line invocation to masquerade a malicious process or backdoor installation as a benign document opening event.
Microsoft Sentinel (KQL)

