Word Documents with Macros Forensic Analysis

Attacks in memory are growing and attracting increasing attention. The consumer deceives the inclusion of macros in a Microsoft Office Word document that is delivered by email. Users will receive several email options, regardless of whether it has a built-in link or attachment.


Pablo Delgado had previously spoken about Sysmon. System Monitor (Sysmon) is a Windows system service and device driver that once installed on a system, remains resident across the system, reboots to monitor and log system activity to the Windows event log. It provides detailed information about process creations, network connections, and changes to file creation time.

This article contains some investigation into the general incident that occurs every day; Users click on emails with links or attachments and open text documents with support for macros.

 

More.