Phishing impersonating 'Microsoft Account Team' OTP alert with ZIP/LNK lure
This rule detects potentially malicious emails that impersonate Microsoft account security notifications or security advisories. It looks for emails with specific social engineering themes in the sender name, sender address, or subject line, accompanied by .zip attachments that contain suspicious file names related to cybersecurity warnings or OTP abuse, which are common lures for malware delivery.
Microsoft Sentinel (KQL)

