Composite chain: email bombing → external Teams call → RAT launch
Detects a suspicious sequence of events suggesting potential technical support scam or social engineering activity: a rapid influx of emails (email bombing) followed by an external Microsoft Teams call, and subsequently the execution of a common remote access tool on the same host within a short timeframe.
Microsoft Sentinel (KQL)

