CVE-2026-21509 Office WebDAV OLE exploit (APT28 Neusploit)

This rule detects potentially malicious behavior associated with Microsoft Office applications, such as Word, initiating suspicious WebDAV network connections, dropping executable or sensitive files, or spawning known LOLBAS processes (rundll32, explorer, regsvr32) from suspicious directories like Temp or WebDAV paths. It also includes a blocklist for known malicious file hashes associated with these patterns.