Office Application Spawning Suspicious Child Process with External Network Activity
This rule detects scenarios where Microsoft Office applications (Word, Excel, Outlook, PowerPoint, OneNote) spawn known suspicious child processes (LOLBAS) that exhibit command-line flags indicative of remote content retrieval or script execution (e.g., download strings, encoded commands) and subsequently initiate network connections to public IP addresses or URLs within a 15-minute window.
Microsoft Sentinel (KQL)

