Potential Suspicious Browser Launch From Document Reader Process — Detection Rule
Detects when a browser process or browser tab is launched from an application that handles document files such as Adobe, Microsoft Office, etc. And connects to a web application over http(s), this could indicate a possible phishing attempt.