AnyDesk Execution Shortly After Microsoft Teams Call (Vishing)

This rule detects the execution of AnyDesk within a 30-minute window of Microsoft Teams activity on the same device. This pattern is indicative of a vishing attack, where a malicious actor lures a victim into installing remote access software during a fake technical support session initiated via Teams.