CVE-2025-60727 Excel RCE - Suspicious Child Process Spawned by excel.exe
This rule detects instances where Microsoft Excel (excel.exe) acts as a parent process for suspicious child processes, including command-line interpreters (cmd.exe, powershell.exe), scripting hosts (wscript.exe, cscript.exe, mshta.exe), or binary proxies (rundll32.exe, regsvr32.exe). This pattern is commonly associated with weaponized office documents executing malicious payloads via macros or other embedded scripts.
Splunk (SPL)

