Windows process creation: Winword launching FLTLDR.exe exploitation behavior

Alerts when Winword spawns a FLTLDR.exe child process, matching a CVE-2017-0261-style exploit chain.

FreeReviewedSigma · Medium · v5
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2018-02-22
Updated
2026-07-31

ATT&CK techniques

Initial Access → Execution
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags instances where WINWORD.EXE spawns a process containing FLTLDR.exe in the executable path. Such a parent/child pairing is consistent with document-based exploitation activity targeting CVE-2017-0261/0262. It relies on Windows process creation telemetry, matching on the parent image name and the child image path content.

Related detections9 linkedT1566.001 — drag to rearrange
Windows Process Creation: EQNEDT32.EXE Used as CVE-2017-11882 Exploit Dropper Parent
Windows: Winword spawning csc.exe indicative of CVE-2017-8759 exploitation
Malicious Equation Editor Child Process Indicating Exploit
Malicious Script Execution from WinRAR Extraction Directory via CVE-2023-38831
Suspicious DLL Written to Explorer IconCache Path
Malicious Microsoft Word Spawning Anomalous Child Process via CVE-2023-36884 (via process_creation)
Malicious Equation Editor Child Process Execution via process_creation
Ursnif C2 Proxy Traffic Identified by Base64 URI Encoding and .avi/.images Pattern
Windows: Suspicious subprocess execution from Hwp.exe spawning gbb.exe
Windows process creation: Winword launching FLTLDR.exe exploitation behavior
Pivot detection · T1566.001 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.