Suspicious RFQ Email Attachment and File Creation -- FlowerStorm
This rule detects potential spearphishing activity by correlating email attachments containing specific 'Request for Quotation' filenames with subsequent suspicious file creation events on endpoints. It specifically looks for matching attachments (MSG or PDF) from email logs and tracks if similar file patterns appear in Microsoft Outlook content or temporary folders on host devices.
Microsoft Sentinel (KQL)

