For the complete documentation index, see llms.txt. This page is also available as Markdown.

Microsoft Office process spawns conhost.exe

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

ATT&CK Tactic

Execution (TA0002), Initial Access (TA0001)

ATT&CK Technique

User Execution: Malicious File (T1204.002), Phishing (T1566)

Severity

Low

Description

This unusual parent-child relationship may indicate that a Microsoft Office application executed a console-based application.

Attacker's Goals

An attacker attempts to gain code execution via an Office application or via an Office document.

Investigative actions

  • Check the source of the file or email (received by mail or loaded locally).

  • Investigate the child processes for malicious activity and network connections to an external host.

Was this helpful?