For the complete documentation index, see llms.txt. This page is also available as Markdown.

Microsoft Office injects code into a process

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

Detector Tags

Injection Analytics

ATT&CK Tactic

Initial Access (TA0001), Stealth (TA0005)

ATT&CK Technique

Phishing: Spearphishing Attachment (T1566.001), Process Injection (T1055)

Severity

Low

Description

An attacker may inject payloads into processes via Microsoft Office. While legitimate in certain cases, code injection can also be used in malicious ways.

Attacker's Goals

  • An attacker attempts to gain code execution via a phishing document.

  • Attackers may inject code into processes to evade process-based defenses, as well as possibly elevate privileges.

Investigative actions

  • Check the source of the document (received by mail or loaded locally).

  • Check whether the injecting process is benign and if this was a desired behavior as part of its normal execution flow.

Variations

Unsigned Microsoft Office injects code into a process

Synopsis

Field
Value

ATT&CK Tactic

Initial Access (TA0001), Stealth (TA0005)

ATT&CK Technique

Phishing: Spearphishing Attachment (T1566.001), Process Injection (T1055), Masquerading: Match Legitimate Resource Name or Location (T1036.005)

Severity

High

Description

An attacker may inject payloads into processes via Microsoft Office. While legitimate in certain cases, code injection can also be used in malicious ways.

Attacker's Goals

  • An attacker attempts to gain code execution via a phishing document.

  • Attackers may inject code into processes to evade process-based defenses, as well as possibly elevate privileges.

Investigative actions

  • Check the source of the document (received by mail or loaded locally).

  • Check whether the injecting process is benign and if this was a desired behavior as part of its normal execution flow.

Microsoft Office injects code into a process to a non-standard PE section

Synopsis

Field
Value

ATT&CK Tactic

Initial Access (TA0001), Stealth (TA0005)

ATT&CK Technique

Phishing: Spearphishing Attachment (T1566.001), Process Injection (T1055)

Severity

High

Description

An attacker may inject payloads into processes via Microsoft Office. While legitimate in certain cases, code injection can also be used in malicious ways.

Attacker's Goals

  • An attacker attempts to gain code execution via a phishing document.

  • Attackers may inject code into processes to evade process-based defenses, as well as possibly elevate privileges.

Investigative actions

  • Check the source of the document (received by mail or loaded locally).

  • Check whether the injecting process is benign and if this was a desired behavior as part of its normal execution flow.

Microsoft Office injects code into a process to an undeclared memory page

Synopsis

Field
Value

ATT&CK Tactic

Initial Access (TA0001), Stealth (TA0005)

ATT&CK Technique

Phishing: Spearphishing Attachment (T1566.001), Process Injection (T1055)

Severity

Medium

Description

An attacker may inject payloads into processes via Microsoft Office. While legitimate in certain cases, code injection can also be used in malicious ways.

Attacker's Goals

  • An attacker attempts to gain code execution via a phishing document.

  • Attackers may inject code into processes to evade process-based defenses, as well as possibly elevate privileges.

Investigative actions

  • Check the source of the document (received by mail or loaded locally).

  • Check whether the injecting process is benign and if this was a desired behavior as part of its normal execution flow.

Microsoft Office injects code into a process from an unsigned process

Synopsis

Field
Value

ATT&CK Tactic

Initial Access (TA0001), Stealth (TA0005)

ATT&CK Technique

Phishing: Spearphishing Attachment (T1566.001), Process Injection (T1055)

Severity

Medium

Description

An attacker may inject payloads into processes via Microsoft Office. While legitimate in certain cases, code injection can also be used in malicious ways.

Attacker's Goals

  • An attacker attempts to gain code execution via a phishing document.

  • Attackers may inject code into processes to evade process-based defenses, as well as possibly elevate privileges.

Investigative actions

  • Check the source of the document (received by mail or loaded locally).

  • Check whether the injecting process is benign and if this was a desired behavior as part of its normal execution flow.

Microsoft Office macro-enabled spreadsheet (XLSM) injects code into a process

Synopsis

Field
Value

ATT&CK Tactic

Initial Access (TA0001), Stealth (TA0005)

ATT&CK Technique

Phishing: Spearphishing Attachment (T1566.001), Process Injection (T1055)

Severity

Medium

Description

An attacker may inject payloads into processes via Microsoft Office. While legitimate in certain cases, code injection can also be used in malicious ways.

Attacker's Goals

  • An attacker attempts to gain code execution via a phishing document.

  • Attackers may inject code into processes to evade process-based defenses, as well as possibly elevate privileges.

Investigative actions

  • Check the source of the document (received by mail or loaded locally).

  • Check whether the injecting process is benign and if this was a desired behavior as part of its normal execution flow.

Was this helpful?