For the complete documentation index, see llms.txt. This page is also available as Markdown.

Rare Unsigned Process Spawned by Office Process Under Suspicious Directory

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204)

Severity

Low

Description

Microsoft Office executed an unsigned process in a suspicious directory. This behavior is common with malicious macros.

Attacker's Goals

Attackers execute commands after infiltrating by using phishing or exploiting a vulnerability in an office.

Investigative actions

  • Investigate the executed process.

  • Investigate the document/email that initiated it.

Was this helpful?