Executable file creation from a macro-enabled Microsoft Office document
Identifies the Microsoft Office process writing an executable file type and the call stack reveals the file creation was originated from the Microsoft Visual Basic for Applications module. This may be an indicator of initial access using malicious macro-enabled documents.
- Platform: Windows
- Severity: High
- MITRE Tactic: Initial Access
- MITRE Techniques: T1566, T1566.001