Fake 'API Logic Flaw' lure delivering javascript: paste-to-execute code
This rule monitors for a multi-stage attack pattern involving two potential indicators: first, it identifies phishing emails containing a 'Google Docs' link combined with an attachment named 'API Logic Flaw'. Second, it detects browser activity involving the paste of JavaScript code or suspicious browser clipboard activity, which may indicate an attacker attempting to execute malicious scripts directly in the user's browser context.
Microsoft Sentinel (KQL)

