CVE-2025-60727 Excel-Spawned Process Outbound HTTP via WinHTTP Callback
This rule detects outbound HTTP traffic generated by the WinHTTP library, specifically when the User-Agent identifies as WinHttp.WinHttpRequest. This pattern is indicative of potential post-exploitation activity, such as command-and-control communication or data exfiltration, originating from a process associated with an exploited Excel document (CVE-2025-60727).
Suricata

