Generic FlowerStorm / Storm-1167 Credential Phishing Kit Pattern
This rule detects instances where a PDF file located in the Outlook temporary internet cache is opened or accessed, followed shortly (within 3 minutes) by a network request from the device to a Google Sites URL. This behavior is indicative of a phishing attack where an email attachment redirects the user to a malicious site for credential harvesting or malware delivery.
Microsoft Sentinel (KQL)

