Windows: Winword spawning csc.exe indicative of CVE-2017-8759 exploitation

Flags Word (WINWORD.EXE) spawning csc.exe, a suspicious execution pattern observed in some exploit chains.

FreeReviewedSigma · Critical · v5
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2017-09-15
Updated
2026-07-31

ATT&CK techniques

Initial Access → Execution
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags process creation events where WINWORD.EXE spawns a child process running as csc.exe. The csc.exe execution from Word is a behavior commonly seen in real-world exploit chains and may indicate malicious code execution rather than normal office activity. Telemetry required is Windows process creation, including parent and child process image paths.

Related detections9 linkedT1203 — drag to rearrange
Windows process creation: Winword launching FLTLDR.exe exploitation behavior
Windows Process Creation: EQNEDT32.EXE Used as CVE-2017-11882 Exploit Dropper Parent
Malicious Script Execution from WinRAR Extraction Directory via CVE-2023-38831
Suspicious DLL Written to Explorer IconCache Path
Malicious Microsoft Word Spawning Anomalous Child Process via CVE-2023-36884 (via process_creation)
Malicious Equation Editor Child Process Execution via process_creation
Ursnif C2 Proxy Traffic Identified by Base64 URI Encoding and .avi/.images Pattern
Windows: Suspicious subprocess execution from Hwp.exe spawning gbb.exe
Proxy downloads of executable and document files from suspicious TLDs (blacklisted domains)
Windows: Winword spawning csc.exe indicative of CVE-2017-8759 exploitation
Pivot detection · T1203 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.