Execution of .PIF file masquerading as an image file
This rule detects potentially malicious file execution by monitoring for the usage of .pif files, often disguised as image files or documents, which subsequently launch suspicious child processes such as msiexec, wscript, cscript, or rundll32. The detection logic matches on specific parent processes (e.g., browsers, email clients, file explorers) triggering the file, followed by suspicious command line arguments within a 10-minute window.
Microsoft Sentinel (KQL)

