Potential Maldoc Execution Chain Observed

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Detects the aftermath of a successfully executed Microsoft Office maldoc: a document opened from an email or download spawns a suspicious execution and attempts to run code via common Windows binaries such as powershell, cmd or rundll32.

Attribute Value
Type Hunting Query
Solution Intel471
ID 02909982-664b-4858-b703-429cbe031fef
Tactics Execution, InitialAccess
Techniques T1059, T1566.001
Required Connectors SecurityEvents, WindowsSecurityEvents
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
SecurityEvent ✓ ✓ ✓

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Hunting Queries · Back to Intel471