Template Injection T1221

Tactic: Stealth

Adversaries may create or modify references in user document templates to conceal malicious code or force authentication attempts. For example, Microsoft’s Office Open XML (OOXML) specification defines an XML-based format for Office documents (.docx, xlsx, .pptx) to replace older binary formats (.doc, .xls, .ppt). OOXML files are packed together ZIP archives compromised of various XML files, referred to as parts, containing properties that collectively define how a document is rendered.

Events covered

1 catalog event is tagged with this technique by at least one rule.

ProviderEventTitle
SysmonEvent ID 13RegistryEvent (Value Set)

Authoring guide

These 2 rules share fields, values, and exclusions.

Fields filtered most (3 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
TargetObject1starts_with 1hkcr\ms-msdt\
cs-method1eq 1get
sc-status1eq 1404

Top indicator values (3 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
TargetObjectstarts_with
hkcr\ms-msdt\
1
cs-methodeq
get
149
sc-statuseq
404
1

Exclusions (1 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
sc-statuseq
404
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 2 rules