Office Application Spawning Suspicious Child Process
This detection identifies instances where a Microsoft Office application (Word, Excel, PowerPoint, or Outlook) spawns a child process commonly associated with script execution or living-off-the-land binary (LOLBin) abuse — including wscript.exe, cscript.exe, mshta.exe, powershell.exe, cmd.exe, regsvr32.exe, rundll32.exe, certutil.exe, and bitsadmin.exe. This behavior is a well-known indicator of malicious macro or embedded-object execution following a phishing lure: a victim opens a weaponized document, and a macro (or OLE/DDE object) launches a script interpreter or LOLBin to download, decode, or execute a second-stage payload. Office applications rarely need to spawn these processes during legitimate use, making this a high-fidelity pivot point for detecting initial access and user-execution activity. Rationale Office applications spawning script hosts or command interpreters is atypical for normal document/spreadsheet/presentation workflows. Threat actors frequently abuse Office macros (VBA), DDE, or OLE objects as an initial access vector, then use LOLBins to evade detection and blend in with legitimate system activity. Tools like mshta.exe, certutil.exe, and bitsadmin.exe are commonly abused for downloading and executing remote payloads while evading traditional AV/EDR signatures. MITRE ATT&CK Mapping Technique Tactic T1566 (Phishing) Initial Access T1204 (User Execution) / T1204.002 (Malicious File) Execution T1059 (Command and Scripting Interpreter) Execution T1218 (System Binary Proxy Execution) — e.g. T1218.005 Mshta, T1218.010 Regsvr32, T1218.011 Rundll32 Defense Evasion T1197 (BITS Jobs) Defense Evasion, Persistence T1140 (Deobfuscate/Decode Files or Information) — via certutil Defense Evasion Data Source Microsoft Defender for Endpoint — DeviceProcessEvents Logic Summary Flags process creation events over the last 30 days where: The initiating (parent) process is winword.exe, excel.exe, powerpnt.exe, or outlook.exe, and The spawned (child) process i
Microsoft Sentinel (KQL)

