Suspicious Web Browser Launch from PDF/Office Reader on Windows over HTTP(S)

Alerts when Acrobat/Office/PDF readers launch common browsers with HTTP(S) URLs, excluding known Microsoft and Foxit redirect patterns.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Joseph Kamau (SigmaHQ), DRL 1.1
Published
2024-05-27
Updated
2026-07-30

ATT&CK techniques

Execution
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Windows process creations where a PDF or Office document reader spawns a web browser binary and the browser command line includes the string "http". Such activity can indicate phishing or link-driven payload delivery from a document-rendering context. It relies on process creation telemetry, including parent process image names, child browser executable names, and the child command line content. It excludes cases involving Microsoft help redirect links and specific Foxit service tracking/redirect URLs.

Related detections9 linkedT1204.002 — drag to rearrange
Suspicious n8n Campaign RMM Installer Masquerading as OneDrive Document
Suspicious NFe-Themed Brazilian Lure Executable Execution
Suspicious Executable Dropped in Public Users Directory Named Ctrlpanel (via file_event)
Suspicious Interlock Fake Updater Executable Execution
Malicious Office Application Loading a User-Path DLL via Regsvr32 or Rundll32 (via process_creation)
Suspicious Program Execution From a Mounted ISO or Disk Image (via process_creation)
SocGholish Fake Browser Update Script Execution (via process_creation)
Uncommon Executable Written to Startup Folder by WinRAR via CVE-2025-8088 Path Traversal (via file_event)
Malicious KB Document Masqueraded Executable Spawned by Script Interpreter via RoKRAT Loader (via process_creation)
Suspicious Web Browser Launch from PDF/Office Reader on Windows over HTTP(S)
Pivot detection · T1204.002 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.