Analytics BIOC
Low
✕
Office process spawned with suspicious command-line arguments
An Office process was executed with LOLBIN-like command-line arguments. This behavior is exhibited in the VBA-RunPE tool that executes executables from the memory of Word/Excel/PowerPoint.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Process Injection: Process Hollowing (T1055.012)
Attacker's goals:
Execute arbitrary code or run malicious applications undetected.
Investigative actions:
Check the file that spawns the office application and search for macros, formulas, or scripts.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- Masqueraded office process spawned with suspicious command-line arguments Medium (parent: Low) Adds Masquerading (T1036)
- PowerPoint process accesses a suspicious PPAM file Low