Suspicious Binary In User Directory Spawned From Office Application — Detection Rule

Detects an executable in the users directory started from one of the Microsoft Office suite applications (Word, Excel, PowerPoint, Publisher, Visio)

Read the full analysis on IntelFusions