Phishing Series 2026: Weaponized Calendar/ICS Invite Phishing
Detects inbound .ics calendar invite attachments that contain URLs, originating from sender domains not previously seen within the organization over the last 90 days, and distributed to 10 or more recipients. This pattern is indicative of a mass-distributed phishing campaign using calendar invites as a lure.
Microsoft Sentinel (KQL)

