UC-L3-004
Macro-Enabled Office Document Spawning Shell
Windows Security / Sysmon Event ID 1
Use case development / Protect Against Ransomware / Prevent Ransomware Delivery
sigma
Detection rule
title: Office Application Spawning Shell
status: experimental
description: Detects Office applications spawning command interpreters
logsource:
product: windows
category: process_creation
detection:
selection:
ParentImage|endswith:
- '\WINWORD.EXE'
- '\EXCEL.EXE'
- '\POWERPNT.EXE'
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\wscript.exe'
condition: selection
falsepositives:
- Legitimate Office automation
level: high
tags:
- attack.execution
- attack.t1204Test cases
- Open macro-enabled document that spawns cmd.exe
False positive guidance
Whitelist known automation scripts and trusted macros.