CVE-2025-60727 Excel RCE - Suspicious Outbound Network Connection from Excel.exe
Detects instances where the Excel process (excel.exe) initiates outbound network connections to non-private IP addresses on specific ports often associated with command and control or data exfiltration. This rule specifically excludes known Microsoft-owned CDN and update infrastructure, aiming to identify potential exploitation activity, such as that potentially associated with CVE-2025-60727.
Microsoft Sentinel (KQL)

