According to ZDNet, there is a Zero-Day flaw in IE that can be exploited if a malicious actor tricks a user into opening a malicious MHT file which will allow the external actor to steal data from the host. Even after the flaw was reported to Microsoft, they chose not to patch it. Looks like a PoC was released by the researcher on 4/12. I guess since Microsoft knows about it but declined to fix it, it's maybe a One-Day.
Anyway, is this activity something that Sophos Endpoint or Hitman Pro would be able to catch?
https://www.zdnet.com/article/internet-explorer-zero-day-lets-hackers-steal-files-from-windows-pcs/
This thread was automatically locked due to age.