Office process accessed an unusual .LNK file
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
7 Days
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Execution (TA0002), Persistence (TA0003)
ATT&CK Technique
User Execution (T1204), Boot or Logon Autostart Execution: Shortcut Modification (T1547.009)
Severity
Low
Description
An attacker may embed a .LNK file in an Office document to execute malicious code.
Attacker's Goals
Modify or create a shortcut to gain code or program execution.
Investigative actions
Check if the Office document contains a shortcut object.
Check the content (strings) of the document object for a .LNK shortcut.
Check the content of the shortcut.
PreviousObject versioning was disabled
NextOffice process spawned with suspicious command-line arguments
Was this helpful?
