Potentially Suspicious Office Document Executed From Trusted Location — Detection Rule

Detects the execution of an Office application that points to a document that is located in a trusted location. Attackers often used this to avoid macro security and execute their malicious code.

Read the full analysis on IntelFusions