Windows File Creation by Microsoft Office with Executable or Script Extensions

Flags Office application processes creating .exe/.dll/.ps1 and other script or executable files on Windows.

FreeUnreviewedSigmahighv1
title: Windows File Creation by Microsoft Office with Executable or Script Extensions
id: 93307671-1387-4342-ad6f-d0e18fbc72d8
status: test
description: This rule identifies when a Microsoft Office process creates a file whose name ends with common executable or script extensions (for example .exe, .dll, .ps1, .bat, .vbs). Attackers may use Office applications to drop payloads or launch code by writing additional executable content from within the Office workflow. It relies on Windows file event telemetry that records the creating process image path and the target filename, with exclusions for specific local assembly and Office web or cache locations to reduce noise.
references:
  - https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/
  - https://github.com/vadim-hunter/Detection-Ideas-Rules/blob/02bcbfc2bfb8b4da601bb30de0344ae453aa1afe/Threat%20Intelligence/The%20DFIR%20Report/20210329_Sodinokibi_(aka_REvil)_Ransomware.yaml
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_office_susp_file_extension.yml
author: Vadim Khrykov (ThreatIntel), Cyb3rEng (Rule), Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2021-08-23
modified: 2025-10-17
tags:
  - attack.t1204.002
  - attack.execution
logsource:
  product: windows
  category: file_event
detection:
  selection1:
    Image|endswith:
      - \excel.exe
      - \msaccess.exe
      - \mspub.exe
      - \powerpnt.exe
      - \visio.exe
      - \winword.exe
  selection2:
    TargetFilename|endswith:
      - .bat
      - .cmd
      - .com
      - .dll
      - .exe
      - .hta
      - .ocx
      - .proj
      - .ps1
      - .scf
      - .scr
      - .sys
      - .vbe
      - .vbs
      - .wsf
      - .wsh
  filter_main_localassembly:
    TargetFilename|contains: \AppData\Local\assembly\tmp\
    TargetFilename|endswith: .dll
  filter_optional_webservicecache:
    TargetFilename|contains|all:
      - C:\Users\
      - \AppData\Local\Microsoft\Office\
      - \WebServiceCache\AllUsers
    TargetFilename|endswith: .com
  filter_optional_webex:
    Image|endswith: \winword.exe
    TargetFilename|contains: \AppData\Local\Temp\webexdelta\
    TargetFilename|endswith:
      - .dll
      - .exe
  filter_optional_backstageinappnavcache:
    TargetFilename|contains|all:
      - C:\Users\
      - \AppData\Local\Microsoft\Office\
      - \BackstageInAppNavCache\
    TargetFilename|endswith: .com
  condition: all of selection* and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1
related:
  - id: c7a74c80-ba5a-486e-9974-ab9e682bc5e4
    type: derived

What it detects

This rule identifies when a Microsoft Office process creates a file whose name ends with common executable or script extensions (for example .exe, .dll, .ps1, .bat, .vbs). Attackers may use Office applications to drop payloads or launch code by writing additional executable content from within the Office workflow. It relies on Windows file event telemetry that records the creating process image path and the target filename, with exclusions for specific local assembly and Office web or cache locations to reduce noise.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.