Analytics BIOC
Low
✕
Microsoft Office process spawns conhost.exe
This unusual parent-child relationship may indicate that a Microsoft Office application executed a console-based application.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Execution (TA0002) Initial Access (TA0001)
ATT&CK techniques: User Execution: Malicious File (T1204.002) Phishing (T1566)
Attacker's goals:
An attacker attempts to gain code execution via an Office application or via an Office document.
Investigative actions:
Check the source of the file or email (received by mail or loaded locally). Investigate the child processes for malicious activity and network connections to an external host.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day