Execution of lure batch file 'Right-click to open Invoice Details.bat'
This rule detects the execution or presence of batch files named 'Invoice Details.bat'. The use of such naming conventions in scripts is often a tactic employed in phishing campaigns to lure users into executing malicious code disguised as business-related documents.
Microsoft Sentinel (KQL)

