Payload reconstruction via copy /b of header.doc+body.doc into Windowsupdate.exe
Detects the use of the Windows 'copy /b' command to join multiple files into a single executable, specifically targeting patterns where document files are merged with a binary named 'Windowsupdate.exe'. This technique is often used to reassemble malicious payloads by combining split components or masquerading malicious content within seemingly benign file operations in temporary user directories.
Microsoft Sentinel (KQL)

