Most Significant TTP 2026: Fake Video-Conference Overlay Redirect Preceding Clic
This rule detects a multi-stage attack pattern involving potential social engineering via lookalike conferencing domains. It identifies users visiting suspicious domains resembling well-known conferencing platforms (e.g., Teams, Meet, Zoom), followed by modifications to the Windows RunMRU registry key and subsequent execution of suspicious commands (PowerShell, CMD, mshta) by explorer.exe within a short timeframe.
Microsoft Sentinel (KQL)

