New Quick Assist/AnyDesk Remote Session Preceded by Email Flood
This rule detects the execution of common remote access tools (Quick Assist, AnyDesk) on a host that does not have a prior history of using those specific tools. This is intended to identify potential hands-on-keyboard activity by adversaries following initial access via social engineering, such as vishing or email-bombing, where they attempt to establish a persistent remote access foothold.
Cortex XDR

