Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0005 ✕ technique: T1055 ✕
Download CSV Show ATT&CK heatmapOffice process spawned with suspicious command-line arguments Low 2 variations
An Office process was executed with LOLBIN-like command-line arguments. This behavior is exhibited in the VBA-RunPE tool that executes executables from the memory of Word/Excel/PowerPoint.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Stealth (TA0005)ATT&CK techniques: Process Injection: Process Hollowing (T1055.012)Required data: XDR AgentAttacker's goals: Execute arbitrary code or run malicious applications undetected.Investigative actions: Check the file that spawns the office application and search for macros, formulas, or scripts.Variations
Masqueraded office process spawned with suspicious command-line arguments
Medium overridden
An executable masquerading an office process was executed with LOLBIN-like command-line arguments. overridden
PowerPoint process accesses a suspicious PPAM file
Low overridden
A PowerPoint process opened a PPAM file which might be used to execute malicious code. overridden