Microsoft Office process spawns a commonly abused process
Common weaponized office document behavior.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Execution
- Status:
- Enabled
Process action type = execution AND target process name = cmd.exe , powershell.exe , powershell_ise.exe , wsmprovhost.exe , cscript.exe , wscript.exe , mshta.exe , wmic.exe , rundll32.exe , regsvr32.exe , certutil.exe , installutil.exe , msbuild.exe , ieexec.exe , dfsvc.exe , presentationhost.exe , msxsl.exe , msdt.exe , forfiles.exe , regsvcs.exe , odbcconf.exe , regasm.exe , pcalua.exe , sdiagnhost.exe , bginfo.exe , dcomcnfg.exe , dbghost.exe , cdb.exe , dnx.exe , rcsi.exe , csi.exe , windbg.exe , cdb.exe , kd.exe , cmstp.exe , fsi.exe , javaw.exe , java.exe , javac.exe , javaws.exe , jp2launcher.exe AND target process cmd != *\spool\DRIVERS* AND *C:\Windows\system32\shell32.dll,OpenAs_RunDLL* AND *ServerRunDll {3eef301f-b596-4c0b-bd92-013beafce793}* Process initiated by = outlook.exe , excel.exe , winword.exe , powerpnt.exe , visio.exe , winproj.exe , onenote.exe , msaccess.exe
Preventable: yes