ALT-2400 · Sysmon
Encoded PowerShell spawned by Microsoft Word
WINWORD.EXE spawned powershell.exe with a base64 encoded command block moments after a macro-enabled attachment was opened. Behaviour matches a phishing-to-loader chain.
criticalEscalatedconfidence 61% · 1970-01-01 01:33:00Z · rule DET-0142 Office Child Process — Encoded CommandLinked to INC-1041
Detection summary
WINWORD.EXE spawned powershell.exe with a base64 encoded command block moments after a macro-enabled attachment was opened. Behaviour matches a phishing-to-loader chain.
- Affected host
- WS-FIN-014
- Affected user
- a.pratama
- Source IP
- 10.20.14.61
- Detection rule
- DET-0142 Office Child Process — Encoded Command
- Log source
- Sysmon
- Assignee
- Unassigned
Recommended actions
- Isolate the endpoint from the network
- Collect the parent document and submit for detonation
- Reset credentials for the affected user
- Block the C2 IP at the perimeter firewall
Analyst decision
Triage checklist
- 1. Confirm the detection logic matched genuine activity.
- 2. Check user and asset context for expected behaviour.
- 3. Pivot on host, user, IP and hash in the Log Explorer.
- 4. Enrich IOCs with threat intelligence.
- 5. Set a verdict and record your reasoning.