pc-app.exe writes/executes mscopilot.exe in C:\Microsoft.Office365\
This rule detects suspicious activity originating from the PaperCut 'pc-app.exe' process. It monitors for the creation or execution of a file named 'mscopilot.exe' within the non-standard directory 'C:\Microsoft.Office365\'. The rule matches based on a known malicious SHA1 hash or the specific file-write-then-execute behavior within a one-hour window, indicating potential AdaptixC2 loader activity.
Microsoft Sentinel (KQL)

