Office Macro Spawning Suspicious Child Process (T1204.002/T1566.001)

Detects the execution of common command-line utilities (cmd, powershell, wscript, cscript, mshta, certutil) directly spawned by Microsoft Office applications (Word, Excel, PowerPoint, Outlook). This is a common indicator of macro-based attacks or other exploit delivery chains where Office documents are used to execute malicious payloads.