Windows File Creation by Microsoft Office with Executable or Script Extensions
Flags Office application processes creating .exe/.dll/.ps1 and other script or executable files on Windows.
FreeUnreviewedSigmahighv1
windows-file-creation-by-microsoft-office-with-executable-or-script-extensions-c7a74c80
title: Windows File Creation by Microsoft Office with Executable or Script Extensions
id: 93307671-1387-4342-ad6f-d0e18fbc72d8
status: test
description: This rule identifies when a Microsoft Office process creates a file whose name ends with common executable or script extensions (for example .exe, .dll, .ps1, .bat, .vbs). Attackers may use Office applications to drop payloads or launch code by writing additional executable content from within the Office workflow. It relies on Windows file event telemetry that records the creating process image path and the target filename, with exclusions for specific local assembly and Office web or cache locations to reduce noise.
references:
- https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/
- https://github.com/vadim-hunter/Detection-Ideas-Rules/blob/02bcbfc2bfb8b4da601bb30de0344ae453aa1afe/Threat%20Intelligence/The%20DFIR%20Report/20210329_Sodinokibi_(aka_REvil)_Ransomware.yaml
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_office_susp_file_extension.yml
author: Vadim Khrykov (ThreatIntel), Cyb3rEng (Rule), Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2021-08-23
modified: 2025-10-17
tags:
- attack.t1204.002
- attack.execution
logsource:
product: windows
category: file_event
detection:
selection1:
Image|endswith:
- \excel.exe
- \msaccess.exe
- \mspub.exe
- \powerpnt.exe
- \visio.exe
- \winword.exe
selection2:
TargetFilename|endswith:
- .bat
- .cmd
- .com
- .dll
- .exe
- .hta
- .ocx
- .proj
- .ps1
- .scf
- .scr
- .sys
- .vbe
- .vbs
- .wsf
- .wsh
filter_main_localassembly:
TargetFilename|contains: \AppData\Local\assembly\tmp\
TargetFilename|endswith: .dll
filter_optional_webservicecache:
TargetFilename|contains|all:
- C:\Users\
- \AppData\Local\Microsoft\Office\
- \WebServiceCache\AllUsers
TargetFilename|endswith: .com
filter_optional_webex:
Image|endswith: \winword.exe
TargetFilename|contains: \AppData\Local\Temp\webexdelta\
TargetFilename|endswith:
- .dll
- .exe
filter_optional_backstageinappnavcache:
TargetFilename|contains|all:
- C:\Users\
- \AppData\Local\Microsoft\Office\
- \BackstageInAppNavCache\
TargetFilename|endswith: .com
condition: all of selection* and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: c7a74c80-ba5a-486e-9974-ab9e682bc5e4
type: derived
What it detects
This rule identifies when a Microsoft Office process creates a file whose name ends with common executable or script extensions (for example .exe, .dll, .ps1, .bat, .vbs). Attackers may use Office applications to drop payloads or launch code by writing additional executable content from within the Office workflow. It relies on Windows file event telemetry that records the creating process image path and the target filename, with exclusions for specific local assembly and Office web or cache locations to reduce noise.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.