Microsoft 365Detection & ResponseRetrospectives

Detecting Office Document Exploitation: Defender XDR and Sentinel Hunting Queries

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from June 2022, written in 2026 with the benefit of hindsight.

Malicious Office documents remain a top initial access method. Detecting Office applications launching unusual processes catches many techniques, from macros to Follina-style exploits.

Signals worth watching

  • WINWORD.EXE, EXCEL.EXE, POWERPNT.EXE or OUTLOOK.EXE spawning cmd.exe, powershell.exe, msdt.exe, mshta.exe, wscript.exe, rundll32.exe or regsvr32.exe.
  • Office applications making network connections to unusual domains right after a document opens.
  • ASR rule audit or block events.
  • Documents arriving by email from external senders followed by these behaviors.

Where the data lives

  • Defender for Endpoint: DeviceProcessEvents, DeviceEvents (ASR events).
  • Defender for Office 365: EmailEvents and EmailAttachmentInfo to trace the document's origin.

A starting query

DeviceProcessEvents
| where InitiatingProcessFileName in~ ("winword.exe", "excel.exe", "powerpnt.exe", "outlook.exe")
| where FileName in~ ("cmd.exe", "powershell.exe", "msdt.exe", "mshta.exe", "wscript.exe",
    "cscript.exe", "rundll32.exe", "regsvr32.exe")
| project Timestamp, DeviceName, AccountName, InitiatingProcessFileName, FileName, ProcessCommandLine

Link to email

Join with EmailAttachmentInfo on file hash (SHA256) to find who else received the same attachment.

Response

  1. Isolate the device.
  2. Remove the document from all mailboxes (Defender for Office 365 remediation actions).
  3. Investigate processes and network connections.
  4. Block indicators and confirm ASR rules are in block mode.
detect office document exploitationFollina2022

More on this story