Suspicious MSXSL or WMIC Execution via Scripting Files
Detects the use of msxsl.exe or wmic.exe to process .xsl or .xslt files, potentially indicating the execution of embedded scripts. The rule calculates a risk score based on the combination of the utility name, the presence of an XSL/XSLT file reference in the command line, usage of suspicious file paths (e.g., Temp, AppData), and being launched by potentially suspicious parent processes like cmd.exe or powershell.exe.
Microsoft Sentinel (KQL)

