Suspicious Office Application Spawning Script Interpreter

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-05
Updated
2026-10-05

ATT&CK techniques

Initial Access → Execution
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects Microsoft Office applications launching PowerShell, WScript, CScript or WMIC, the phishing-payload execution chain highlighted in this threat hunt. A document or spreadsheet spawning a scripting engine indicates the user enabled malicious macro content. Office products have no routine need to invoke these interpreters.

Related detections9 linkedT1059.001 — drag to rearrange
Malicious Excel Macro Spawning Scripting Interpreter Downloader (via process_creation)
Windows AppLocker Audit-Mode Events Indicate Files Would Have Been Blocked
Windows AppLocker Blocked Application, Script, MSI, or Packaged-App Execution
Windows Process Creation: Suspicious Children Spawned by HTML Help (hh.exe)
Windows: Alert on Suspicious HH.EXE Process Execution
Malicious Office Application Spawning Command Interpreter
Suspicious Microsoft Word Spawning PowerShell
Malicious Office Application Spawning PowerShell with Encoded Command
Suspicious Node Package Install Spawning Script Interpreters via process_creation
Suspicious Office Application Spawning Script Interpreter
Pivot detection · T1059.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.