Suspicious Child Process Spawned from Office Applications
Detects instances where common Microsoft Office applications (Word, Excel, PowerPoint, Outlook) spawn child processes that are typically associated with command interpretation, scripting, or LOLBins (Living Off the Land Binaries). This behavior is often indicative of malicious macro execution, exploit payloads, or obfuscated command execution originating from malicious documents.
Sigma

