Potential Arbitrary File Download Using Office Application

    Date: 09/30/2026

    Severity: High

    Summary

    Detects potential arbitrary file downloads initiated through Microsoft Office applications.

    Indicators of Compromise (IOC) List

    Image :

    - '\EXCEL.EXE'

    - '\MSOXMLED.EXE'

    - '\POWERPNT.EXE'

    - '\WINWORD.exe'

    Original Filename: 

    - 'Excel.exe'

    - 'msoxmled.exe'

    - 'POWERPNT.EXE'

    - 'WinWord.exe'

    CommandLine : 

    - 'http://'

    - 'https://'

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    datasourcename = "Winodws Security" and eventtype = "4688" and (processname like "\EXCEL.EXE" or processname like "\MSOXMLED.EXE" or processname like "\POWERPNT.EXE" or processname like "\WINWORD.exe") and (originalfilename like "Excel.exe" or originalfilename like "msoxmled.exe" or originalfilename like "POWERPNT.EXE" or originalfilename like "WinWord.exe") and (commandline like "http://" or commandline like "https://")

    Detection Query 2 :

    technologygroup = "EDR" and (processname like "\EXCEL.EXE" or processname like "\MSOXMLED.EXE" or processname like "\POWERPNT.EXE" or processname like "\WINWORD.exe") and (originalfilename like "Excel.exe" or originalfilename like "msoxmled.exe" or originalfilename like "POWERPNT.EXE" or originalfilename like "WinWord.exe") and (commandline like "http://" or commandline like "https://")


    Reference:     

     https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_office_arbitrary_cli_download.yml


    Tags

    SigmaMicrosoft

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags