Suspicious Office Application Spawning Script Or Shell Interpreter

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-10
Updated
2026-09-10

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects a Microsoft Office application spawning a command shell or scripting interpreter. MacroPack-generated maldocs used VBA to launch child interpreters that injected and executed offensive-tool loaders such as Havoc and Brute Ratel. Office applications spawning cmd powershell wscript or rundll32 is a strong macro-abuse signal for the initial execution stage of an intrusion.

Related detections9 linkedT1055 — drag to rearrange
Suspicious VBScript Launcher Execution via Wscript for Mining Operation (via process_creation)
Suspicious Network Connection From wabmig.exe (Turian Injection)
Suspicious Outbound Network Connection from Explorer Process
Suspicious AppLaunch.exe Spawned As Injection Target (via process_creation)
Malicious Script Host Spawning PowerShell With Invoke-Expression (via process_creation)
Suspicious BugSleep Marker File in Public Directory
Suspicious MSHTA VBScript WScript Shell Execution
Suspicious CRAT Injection Named Pipe ChromeUpdatePipe (via pipe_created)
Malicious Kimsuky VBE Payload Download via Curl to AppData and Execution (via process_creation)
Suspicious Office Application Spawning Script Or Shell Interpreter
Pivot detection · T1055 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.