Windows: Suspicious Process Spawning from Microsoft Office Applications

Alerts when Office apps spawn common execution tools or scripts from typical attacker staging paths on Windows.

FreeUnreviewedSigmahighv1
title: "Windows: Suspicious Process Spawning from Microsoft Office Applications"
id: ecca27ac-aa9d-418c-84c5-b11febfb7e6f
related:
  - id: c27515df-97a9-4162-8a60-dc0eeb51b775
    type: derived
  - id: e1693bc8-7168-4eab-8718-cdcaa68a1738
    type: derived
  - id: 23daeb52-e6eb-493c-8607-c4f0246cb7d8
    type: obsolete
  - id: 518643ba-7d9c-4fa5-9f37-baed36059f6a
    type: obsolete
  - id: 04f5363a-6bca-42ff-be70-0d28bf629ead
    type: obsolete
  - id: 438025f9-5856-4663-83f7-52f878a70a50
    type: derived
status: test
description: This rule flags Windows executions where a Microsoft Office application process (e.g., Word, Excel, PowerPoint, Publisher, Visio, OneNote, Access) spawns a child process consistent with common LOLBins and scripting/tooling abuse. Attackers frequently use Office to launch additional binaries to execute commands, download content, or stage payloads while blending into user-driven activity. The detection relies on process creation telemetry, matching parent executable name suffixes and child process original file name or image path patterns, plus suspicious filesystem locations used for staging.
references:
  - https://www.hybrid-analysis.com/sample/465aabe132ccb949e75b8ab9c5bda36d80cf2fd503d52b8bad54e295f28bbc21?environmentId=100
  - https://mgreen27.github.io/posts/2018/04/02/DownloadCradle.html
  - https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/
  - https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability-1a47fce5629e
  - https://github.com/vadim-hunter/Detection-Ideas-Rules/blob/02bcbfc2bfb8b4da601bb30de0344ae453aa1afe/Threat%20Intelligence/The%20DFIR%20Report/20210329_Sodinokibi_(aka_REvil)_Ransomware.yaml
  - https://github.com/splunk/security_content/blob/300af51b88ad5d5b27ce4f5f54e4d6e6a3a2c06d/detections/endpoint/office_spawning_control.yml
  - https://twitter.com/andythevariable/status/1576953781581144064?s=20&t=QiJILvK4ZiBdR8RJe24u-A
  - https://www.elastic.co/security-labs/exploring-the-ref2731-intrusion-set
  - https://github.com/elastic/detection-rules/blob/c76a39796972ecde44cb1da6df47f1b6562c9770/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml
  - https://www.vmray.com/analyses/2d2fa29185ad/report/overview.html
  - https://app.any.run/tasks/c903e9c8-0350-440c-8688-3881b556b8e0/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_office_susp_child_processes.yml
author: Florian Roth (Nextron Systems), Markus Neis, FPT.EagleEye Team, Vadim Khrykov, Cyb3rEng, Michael Haag, Christopher Peacock @securepeacock, @scythe_io, Huntrule Team
date: 2018-04-06
modified: 2023-04-24
tags:
  - attack.execution
  - attack.stealth
  - attack.t1047
  - attack.t1204.002
  - attack.t1218.010
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith:
      - \EQNEDT32.EXE
      - \EXCEL.EXE
      - \MSACCESS.EXE
      - \MSPUB.exe
      - \ONENOTE.EXE
      - \POWERPNT.exe
      - \VISIO.exe
      - \WINWORD.EXE
      - \wordpad.exe
      - \wordview.exe
  selection_child_processes:
    - OriginalFileName:
        - bitsadmin.exe
        - CertOC.exe
        - CertUtil.exe
        - Cmd.Exe
        - CMSTP.EXE
        - cscript.exe
        - curl.exe
        - HH.exe
        - IEExec.exe
        - InstallUtil.exe
        - javaw.exe
        - Microsoft.Workflow.Compiler.exe
        - msdt.exe
        - MSHTA.EXE
        - msiexec.exe
        - Msxsl.exe
        - odbcconf.exe
        - pcalua.exe
        - PowerShell.EXE
        - RegAsm.exe
        - RegSvcs.exe
        - REGSVR32.exe
        - RUNDLL32.exe
        - schtasks.exe
        - ScriptRunner.exe
        - wmic.exe
        - WorkFolders.exe
        - wscript.exe
    - Image|endswith:
        - \AppVLP.exe
        - \bash.exe
        - \bitsadmin.exe
        - \certoc.exe
        - \certutil.exe
        - \cmd.exe
        - \cmstp.exe
        - \control.exe
        - \cscript.exe
        - \curl.exe
        - \forfiles.exe
        - \hh.exe
        - \ieexec.exe
        - \installutil.exe
        - \javaw.exe
        - \mftrace.exe
        - \Microsoft.Workflow.Compiler.exe
        - \msbuild.exe
        - \msdt.exe
        - \mshta.exe
        - \msidb.exe
        - \msiexec.exe
        - \msxsl.exe
        - \odbcconf.exe
        - \pcalua.exe
        - \powershell.exe
        - \pwsh.exe
        - \regasm.exe
        - \regsvcs.exe
        - \regsvr32.exe
        - \rundll32.exe
        - \schtasks.exe
        - \scrcons.exe
        - \scriptrunner.exe
        - \sh.exe
        - \svchost.exe
        - \verclsid.exe
        - \wmic.exe
        - \workfolders.exe
        - \wscript.exe
  selection_child_susp_paths:
    Image|contains:
      - \AppData\
      - \Users\Public\
      - \ProgramData\
      - \Windows\Tasks\
      - \Windows\Temp\
      - \Windows\System32\Tasks\
  condition: selection_parent and 1 of selection_child_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1

What it detects

This rule flags Windows executions where a Microsoft Office application process (e.g., Word, Excel, PowerPoint, Publisher, Visio, OneNote, Access) spawns a child process consistent with common LOLBins and scripting/tooling abuse. Attackers frequently use Office to launch additional binaries to execute commands, download content, or stage payloads while blending into user-driven activity. The detection relies on process creation telemetry, matching parent executable name suffixes and child process original file name or image path patterns, plus suspicious filesystem locations used for staging.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.