Well I had some problems getting the command to find Python, but finally got it resoled. After I ran the command I got this:
View attachment 267451
...as expected. Then when I double-clicked the clickme.docx file (10kB file size) it opened only to a blank page then nothing else happened; no alerts from OSA, but in the H_C firewall logs I see it was blocked - as I sort of expected, because i block MS Office apps via H_C firewall settings and because I have severely limited technical skills in this area:
Code:
!!! Blocked Windows Firewall outbound connections !!!
Event[1]:
Local Time: 2022/06/12 14:14:48
ProcessID: 10644
Application: C:\program files\microsoft office\root\office16\winword.exe
Direction: Outbound
SourceAddress: 192.168.1.72
SourcePort: 52495
DestAddress: 52.168.117.169
DestPort: 443
Protocol: 6
FilterRTID: 78701
LayerName: %%14611
LayerRTID: 48
RemoteUserID: S-1-0-0
RemoteMachineID: S-1-0-0
That's where I'm at now. No other testing yet. Hopefully I didn't screw up
EDIT
Actually that remote IP address belongs to Microsoft
Not what I expected but I guess that's normal for MS apps when they open they connect to mothership MS.