Exploit for CVE-2017-8759 — Detection Rule

Detects Winword starting uncommon sub process csc.exe as used in exploits for CVE-2017-8759

Read the full analysis on IntelFusions