Description
Detects a document exploiting CVE-2017-0199, the Office OLE2link flaw, to run hidden script host commands that launch PowerShell. The rule matches the shell and file system object chains that fetch and execute payloads without user interaction.
