Detecting Office Document Exploitation: Defender XDR and Sentinel Hunting Queries
Retrospective: this article looks back at events from June 2022, written in 2026 with the benefit of hindsight.
Malicious Office documents remain a top initial access method. Detecting Office applications launching unusual processes catches many techniques, from macros to Follina-style exploits.
Signals worth watching
WINWORD.EXE,EXCEL.EXE,POWERPNT.EXEorOUTLOOK.EXEspawningcmd.exe,powershell.exe,msdt.exe,mshta.exe,wscript.exe,rundll32.exeorregsvr32.exe.- Office applications making network connections to unusual domains right after a document opens.
- ASR rule audit or block events.
- Documents arriving by email from external senders followed by these behaviors.
Where the data lives
- Defender for Endpoint:
DeviceProcessEvents,DeviceEvents(ASR events). - Defender for Office 365:
EmailEventsandEmailAttachmentInfoto trace the document's origin.
A starting query
DeviceProcessEvents
| where InitiatingProcessFileName in~ ("winword.exe", "excel.exe", "powerpnt.exe", "outlook.exe")
| where FileName in~ ("cmd.exe", "powershell.exe", "msdt.exe", "mshta.exe", "wscript.exe",
"cscript.exe", "rundll32.exe", "regsvr32.exe")
| project Timestamp, DeviceName, AccountName, InitiatingProcessFileName, FileName, ProcessCommandLine
Link to email
Join with EmailAttachmentInfo on file hash (SHA256) to find who else received the same attachment.
Response
- Isolate the device.
- Remove the document from all mailboxes (Defender for Office 365 remediation actions).
- Investigate processes and network connections.
- Block indicators and confirm ASR rules are in block mode.
- Follina (May–June 2022): Office Documents That Ran Code Without Macros Incident Teardowns
- How to Configure Attack Surface Reduction Rules in Defender for Endpoint How-To & Hardening
- CIO Brief: Attackers Adapt When You Block Macros CIO Briefings