Spearphishing Delivery with Auth Failure Followed by Endpoint Execution
This rule monitors for email events where the email is flagged for suspicious properties (SPF/DKIM/DMARC failure, threat categorization) and includes potentially malicious attachments or URLs. It then correlates these suspicious emails with subsequent process execution events on the recipient's endpoint within a 30-minute window, identifying a potential successful execution of a phishing payload.
Microsoft Sentinel (KQL)

