Process spawned from macro-enabled Microsoft Office document
Identifies the execution of the child process spawned by Microsoft Office parent process where the call stack contains the Visual Basic for Applications modules or suspicious symbols. This is a strong indicative of the presence of a weaponized macro-enabled document.
- Platform: Windows
- Severity: High
- MITRE Tactic: Initial Access
- MITRE Techniques: T1566, T1566.001