Microsoft Office injects code into a process
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
Injection Analytics
ATT&CK Tactic
Initial Access (TA0001), Stealth (TA0005)
ATT&CK Technique
Phishing: Spearphishing Attachment (T1566.001), Process Injection (T1055)
Severity
Low
Description
An attacker may inject payloads into processes via Microsoft Office. While legitimate in certain cases, code injection can also be used in malicious ways.
Attacker's Goals
An attacker attempts to gain code execution via a phishing document.
Attackers may inject code into processes to evade process-based defenses, as well as possibly elevate privileges.
Investigative actions
Check the source of the document (received by mail or loaded locally).
Check whether the injecting process is benign and if this was a desired behavior as part of its normal execution flow.
Variations
Was this helpful?
