AnyDesk Installed via Edge Browser Following Social-Engineered Vishing Call

Detects the execution of the AnyDesk remote support application when initiated from a web browser (msedge.exe) or the Windows file explorer (explorer.exe). This pattern is often indicative of user-driven execution, potentially as part of a tech support scam or unauthorized remote access attempt.