Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0519 — Detect Persistence via Office Template Macro Injection or Registry Hijack
DET0519

Detect Persistence via Office Template Macro Injection or Registry Hijack

2 analytic(s) · 1 technique(s) detected

Analytics

2
AN1436 Analytic 1436
Windows

Adversaries inject VBA macros into Office templates such as Normal.dotm or Personal.xlsb or redirect Office template load path via registry key (GlobalDotName) to gain persistence. Template macros trigger execution of malicious code on application startup.

WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=15 WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=13, 14 WinEventLog:Microsoft-Office-Alerts Office application warning or alert on macro execution from template
[TemplatePath] Path to Normal.dotm, Personal.xlsb, or Excel/Word startup templates may vary by Office version and user
[RegistryPath] GlobalDotName or equivalent registry keys may differ across Office versions or deployments
[TimeWindow] Office process creation and macro execution timing after system or user login
[UserContext] May be scoped to high-value users or those with access to sensitive templates
AN1437 Analytic 1437
Office Suite

Malicious VBA macros embedded in base templates like Normal.dotm or Personal.xlsb are automatically loaded and executed at startup. Template path may be hijacked to load a remote or attacker-controlled template via GlobalDotName registry setting.

m365:unified Set-Mailbox, Set-MailboxPolicy, Set-TrustedLocation
[TemplateSource] Macros may be embedded in local user templates or retrieved from shared network paths
[MacroSecurityLevel] Macro execution policy (disabled, warn, enabled) varies by tenant or user configuration

Detected Techniques

1

Details

MITRE ID
DET0519
STIX ID
x-mitre-detection-strategy--e04f7ddf-6a1e-4731-afd6-5edb74f4c624
Analytics
2
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.