Office Application Startup T1137
Tactic: Persistence
Adversaries may leverage Microsoft Office-based applications for persistence between startups. Microsoft Office is a fairly common application suite on Windows-based operating systems within an enterprise network. There are multiple mechanisms that can be used with Office for persistence when an Office-based application is started; this can include the use of Office Template Macros and add-ins.
Events covered
8 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 1 | Process creation |
| Sysmon | Event ID 11 | FileCreate |
| Sysmon | Event ID 12 | RegistryEvent (Object create and delete) |
| Sysmon | Event ID 13 | RegistryEvent (Value Set) |
| Sysmon | Event ID 14 | RegistryEvent (Key and Value Rename) |
| Security-Auditing | Event ID 4688 | A new process has been created. |
| ESF | exec | Process Execution |
| PowerShell | Event ID 4104 | Creating Scriptblock text (MessageNumber of MessageTotal). |
Authoring guide
These 34 rules share fields, values, and exclusions.
Fields filtered most (39 distinct)
These fields appear most often in rule filters.
Top indicator values (211 distinct)
These values appear most often in rule predicates.
Exclusions (98 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 16 rules
- Code Executed Via Office Add-in XLL File
- IE Change Domain Zone
- New Outlook Macro Created
- Office Application Startup - Office Test
- Outlook Macro Execution Without Warning Setting Enabled
- Outlook Security Settings Updated - Registry
- Outlook Task/Note Reminder Received
- Potential Persistence Via Excel Add-in - Registry
- Potential Persistence Via Microsoft Office Add-In
- Potential Persistence Via Microsoft Office Startup Folder
- Potential Persistence Via Outlook Form
- Potential Persistence Via Outlook LoadMacroProviderOnBoot Setting
- Potential Persistence Via Visual Studio Tools for Office
- Registry Modification to Hidden File Extension
- Suspicious Microsoft Office Child Process - MacOS
- Suspicious Outlook Macro Created
Elastic 13 rules
- Execution via Microsoft Excel XLL Add-In
- M365 Exchange Inbox Phishing Evasion Rule Created
- M365 Exchange Inbox Rule with Obfuscated Name
- Microsoft Office AddIn Creation
- Microsoft Office AddIn Loaded
- Office Application Startup via Template File Modification
- Office Test Registry Persistence
- Outlook Home Page Registry Modification
- Outlook Home Page Registry Modification
- Persistence via Microsoft Office AddIns
- Persistence via Microsoft Outlook VBA
- Process Creation via Microsoft Office Add-Ins
- Suspicious Execution via Microsoft Office Add-Ins
Splunk 3 rules
- Windows Outlook LoadMacroProviderOnBoot Persistence
- Windows Outlook Macro Created by Suspicious Process
- Windows Outlook Macro Security Modified