Windows: Suspicious Process Spawning from Microsoft Office Applications

Alerts when Office apps spawn common execution tools or scripts from typical attacker staging paths on Windows.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems), Markus Neis, FPT.EagleEye Team, Vadim Khrykov, Cyb3rEng, Michael Haag, Christopher Peacock @securepeacock, @scythe_io (SigmaHQ), DRL 1.1
Published
2018-04-06
Updated
2026-07-30

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Windows executions where a Microsoft Office application process (e.g., Word, Excel, PowerPoint, Publisher, Visio, OneNote, Access) spawns a child process consistent with common LOLBins and scripting/tooling abuse. Attackers frequently use Office to launch additional binaries to execute commands, download content, or stage payloads while blending into user-driven activity. The detection relies on process creation telemetry, matching parent executable name suffixes and child process original file name or image path patterns, plus suspicious filesystem locations used for staging.

Related detections9 linkedT1047 — drag to rearrange
Windows WmiPrvSE.exe Spawning Suspicious Script and LOLBIN Child Processes
Windows Process Creation: Office-Launched WMIC with LOLBIN-Style Command Arguments
Malicious Office Application Loading a User-Path DLL via Regsvr32 or Rundll32 (via process_creation)
Windows Process Creation: Maze Ransomware Doc Dropper and Shadow Copy Deletion Indicators
Windows Process Creation: Suspicious Children Spawned by HTML Help (hh.exe)
Windows: Alert on Suspicious HH.EXE Process Execution
Suspicious OneNote Spawning Script Interpreter (via process_creation)
Lateral Movement via WMIC Remote Process Creation
Suspicious vbc.exe Spawned by Installer Process
Windows: Suspicious Process Spawning from Microsoft Office Applications
Pivot detection · T1047 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.