Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

2 detections

This detection identifies instances where a Microsoft Office application (Word, Excel, PowerPoint, or Outlook) spawns a child process commonly associated with script execution or living-off-the-land binary (LOLBin) abuse — including wscript.exe, cscript.exe, mshta.exe, powershell.exe, cmd.exe, regsvr32.exe, rundll32.exe, certutil.exe, and bitsadmin.exe.

This behavior is a well-known indicator of malicious macro or embedded-object execution following a phishing lure: a victim opens a weaponized document, and a macro (or OLE/DDE object) launches a script interpreter or LOLBin to download, decode, or execute a second-stage payload. Office applications rarely need to spawn these processes during legitimate use, making this a high-fidelity pivot point for detecting initial access and user-execution activity.

Rationale
Office applications spawning script hosts or command interpreters is atypical for normal document/spreadsheet/presentation workflows.
Threat actors frequently abuse Office macros (VBA), DDE, or OLE objects as an initial access vector, then use LOLBins to evade detection and blend in with legitimate system activity.
Tools like mshta.exe, certutil.exe, and bitsadmin.exe are commonly abused for downloading and executing remote payloads while evading traditional AV/EDR signatures.

MITRE ATT&CK Mapping
Technique Tactic
T1566 (Phishing) Initial Access
T1204 (User Execution) / T1204.002 (Malicious File) Execution
T1059 (Command and Scripting Interpreter) Execution
T1218 (System Binary Proxy Execution) — e.g. T1218.005 Mshta, T1218.010 Regsvr32, T1218.011 Rundll32 Defense Evasion
T1197 (BITS Jobs) Defense Evasion, Persistence
T1140 (Deobfuscate/Decode Files or Information) — via certutil Defense Evasion
Data Source
Microsoft Defender for Endpoint — DeviceProcessEvents

Logic Summary
Flags process creation events over the last 30 days where:

The initiating (parent) process is winword.exe, excel.exe, powerpnt.exe, or outlook.exe, and
The spawned (child) process i
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
2 months ago
11033
Detects execution artifacts of the ChainDrop (Shai-Hulud) npm supply-chain campaign on endpoints. The campaign abuses npm `preinstall` lifecycle hooks in compromised packages to run `setup.mjs`, which downloads a Bun runtime and executes the `Math_Symbol.js` / `math_init.js` payload for credential and token theft.


The query matches on two signals:



- **CampaignArtifact (High)** — the filenames `setup.mjs`, `Math_Symbol.js` or `math_init.js` appearing in either the process or parent process command line. Effectively unique to this campaign; `setup.mjs` has occasional legitimate use and is verified via the repository path.

- **BunFromNodeModules (Contextual)** — `bun.exe` spawning child processes from a `node_modules` path. Covers the case where `setup.mjs` downloads and invokes Bun internally, leaving no URL or version string in process telemetry. Also survives a variant renaming the payload files.



Set `IncludeBunBranch = false` to drop the contextual branch; the remaining artifact branches are low-volume and suitable for scheduled execution. Leave it enabled for manual hunts. Baseline Bun usage across the developer estate before scheduling with the branch on.


**Coverage limits:** endpoint execution only. Does not cover the initial package download, GitHub Actions workflow injection, or exfiltration to attacker infrastructure. Pair with the SHA256 file-hash query for pre-execution detection.
avatar
Matthias Chladek@msxreminds
avatar
Detections.ai Community
2 months ago
12018