Microsoft Edge Launched by Productivity Applications via Suspicious Command Line

This rule detects the Microsoft Edge browser (msedge.exe) being spawned by common productivity applications like Adobe Acrobat or Microsoft Outlook using the '--single-argument' command-line flag. This pattern is frequently used to force a specific browser window to open a malicious URL, which can be an indicator of a malicious document or phishing email attempting to direct the user to a credential harvesting or malware delivery site.