Ransomware Series: Malicious LNK/Office Macro Spearphishing Execution Chain

Detects instances where Microsoft Office applications or Windows Explorer (via LNK file execution) spawn suspicious child processes, such as script interpreters or known LOLBins, within a short timeframe. This is a common pattern for initial access via spearphishing attachments where a malicious document or shortcut executes a payload.