Exploit for CVE-2015-1641 — Detection Rule

Detects Winword starting uncommon sub process MicroScMgmt.exe as used in exploits for CVE-2015-1641

Read the full analysis on IntelFusions