{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3omicrosoftwindows_server_2008r2sp1/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_10_20h2:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_10_21h1:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_20h2:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2022-30190"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Microsoft Office"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eMicrosoft Office suite applications (Word, Excel, PowerPoint, etc.) are common vectors for initial access and execution. Attackers exploit these applications via malicious documents containing macros, DDE, or embedded vulnerabilities (such as Follina, CVE-2022-30190) to force the host application to spawn child processes. These spawned processes are frequently used to execute secondary stages of an attack, such as downloading further malware, establishing persistence, or executing administrative commands. Because legitimate Office activity rarely involves launching system binaries like PowerShell, cmd, or rundll32, monitoring these parent-child relationships is a critical control for detection engineering teams. Defenders should focus on identifying atypical process lineage where Office applications act as the parent for system tools or binaries located in suspicious writeable directories.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eVictim opens a weaponized Microsoft Office document via email or download.\u003c/li\u003e\n\u003cli\u003eThe document executes embedded malicious code (Macro, OLE object, or exploit).\u003c/li\u003e\n\u003cli\u003eThe Office application invokes a system utility (e.g., cmd.exe or powershell.exe) to bypass security controls.\u003c/li\u003e\n\u003cli\u003eThe spawned child process executes encoded scripts or downloads external payloads.\u003c/li\u003e\n\u003cli\u003eThe attacker gains initial execution and proceeds to execute secondary modules.\u003c/li\u003e\n\u003cli\u003ePersistence mechanisms are established via scheduled tasks or registry modifications.\u003c/li\u003e\n\u003cli\u003eFinal objective (e.g., ransomware deployment or credential theft) is achieved.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vector allows adversaries to gain initial access, execute code under the context of the user, move laterally, and deploy ransomware or information-stealing malware within an enterprise environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided Sigma rule to alert on suspicious process spawning from Microsoft Office applications.\u003c/li\u003e\n\u003cli\u003eMonitor for process creation events (Event ID 1) where the ParentImage matches the Microsoft Office suite.\u003c/li\u003e\n\u003cli\u003eInvestigate instances where Office processes spawn tools like PowerShell, CMD, WScript, or MSHTA, particularly if they are originating from non-standard paths like \\AppData\\ or \\Windows\\Temp.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-03T08:54:21Z","date_published":"2026-08-03T08:54:21Z","id":"https://feed.craftedsignal.io/briefs/2026-08-office-child-processes/","summary":"Microsoft Office applications are frequently abused to spawn system processes to execute malicious code, download payloads, or facilitate privilege escalation.","title":"Suspicious Microsoft Office Child Process Activity","url":"https://feed.craftedsignal.io/briefs/2026-08-office-child-processes/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}