MITRE ATT&CK technique
Office Application Startup detection rulesT1137
Office Application Startup (T1137) is a MITRE ATT&CK technique in the Persistence tactic. This page lists the 16 community-maintained Sigma detection rules in the library mapped to T1137 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, macos.
Tactic
Code Executed Via Office Add-in XLL File
highAdversaries may abuse Microsoft Office add-ins to obtain persistence on a compromised system. Office add-ins can be used to add functionality to Office programs
windows · ps_script
Outlook Macro Execution Without Warning Setting Enabled
highDetects the modification of Outlook security setting to allow unprompted execution of macros.
windows · registry_set
Potential Persistence Via Excel Add-in - Registry
highDetect potential persistence via the creation of an excel add-in (XLL) file to make it run automatically when Excel is started.
windows · registry_set
Potential Persistence Via Microsoft Office Add-In
highDetects potential persistence activity via startup add-ins that load when Microsoft Office starts (.wll/.xll are simply .dll fit for Word or Excel).
windows · file_event
Potential Persistence Via Microsoft Office Startup Folder
highDetects creation of Microsoft Office files inside of one of the default startup folders in order to achieve persistence.
windows · file_event
Potential Persistence Via Outlook Form
highDetects the creation of a new Outlook form which can contain malicious code
windows · file_event
Potential Persistence Via Outlook LoadMacroProviderOnBoot Setting
highDetects the modification of Outlook setting "LoadMacroProviderOnBoot" which if enabled allows the automatic loading of any configured VBA project/module
windows · registry_set
Suspicious Microsoft Office Child Process - MacOS
highDetects suspicious child processes spawning from microsoft office suite applications such as word or excel. This could indicates malicious macro execution
macos · process_creation
Suspicious Outlook Macro Created
highDetects the creation of a macro file for Outlook.
windows · file_event
IE Change Domain Zone
mediumHides the file extension through modification of the registry
windows · registry_set
New Outlook Macro Created
mediumDetects the creation of a macro file for Outlook.
windows · file_event
Office Application Startup - Office Test
mediumDetects the addition of office test registry that allows a user to specify an arbitrary DLL that will be executed every time an Office application is started
windows · registry_event
Outlook Security Settings Updated - Registry
mediumDetects changes to the registry values related to outlook security settings
windows · registry_set
Potential Persistence Via Visual Studio Tools for Office
mediumDetects persistence via Visual Studio Tools for Office (VSTO) add-ins in Office applications.
windows · registry_set
Registry Modification to Hidden File Extension
mediumHides the file extension through modification of the registry
windows · registry_set
Outlook Task/Note Reminder Received
lowDetects changes to the registry values related to outlook that indicates that a reminder was triggered for a Note or Task item. This could be a sign of exploitation of CVE-2023-23397. Further investigation is required to determine the success of an exploitation.
windows · registry_set