macOS Office Apps Spawning Shell or Scripting Processes

Alerts when Microsoft Office on macOS launches suspicious shell/script or download utilities as child processes.

FreeReviewedSigma · High · v2
Product
macos
Category
process_creation
Author
Sohan G (D4rkCiph3r) (SigmaHQ), DRL 1.1
Published
2023-01-31
Updated
2026-07-31

ATT&CK techniques

Execution → Persistence
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags macOS process executions where a Microsoft Office application (Word, Excel, PowerPoint, or OneNote) spawns a child process whose executable name ends with common command-line or scripting interpreters/tools (e.g., bash, sh, zsh, python, curl, wget, osascript, osacompile). Such behavior is suspicious because Office-driven execution is often used to run external commands after user interaction, including macro or script activity. The detection relies on process creation telemetry that includes parent process image names and the child process executable path.

Related detections9 linkedT1204.002 — drag to rearrange
Suspicious Shell Execution Referencing Mounted DMG Volume via Terminal (macOS)
Suspicious Microsoft Office Test Persistence Key Creation (via registry_set)
Suspicious n8n Campaign RMM Installer Masquerading as OneDrive Document
Suspicious NFe-Themed Brazilian Lure Executable Execution
Suspicious Osascript Requesting Administrator Privileges (via process_creation)
Suspicious Executable Dropped in Public Users Directory Named Ctrlpanel (via file_event)
Suspicious Interlock Fake Updater Executable Execution
Malicious Office Application Loading a User-Path DLL via Regsvr32 or Rundll32 (via process_creation)
Suspicious Program Execution From a Mounted ISO or Disk Image (via process_creation)
macOS Office Apps Spawning Shell or Scripting Processes
Pivot detection · T1204.002 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.