AN1436
Analytic 1436
Windows
Adversaries inject VBA macros into Office templates such as Normal.dotm or Personal.xlsb or redirect Office template load path via registry key (GlobalDotName) to gain persistence. Template macros trigger execution of malicious code on application startup.
WinEventLog:Sysmon
EventCode=11
WinEventLog:Sysmon
EventCode=15
WinEventLog:Sysmon
EventCode=1
WinEventLog:Sysmon
EventCode=13, 14
WinEventLog:Microsoft-Office-Alerts
Office application warning or alert on macro execution from template
[TemplatePath]
Path to Normal.dotm, Personal.xlsb, or Excel/Word startup templates may vary by Office version and user
[RegistryPath]
GlobalDotName or equivalent registry keys may differ across Office versions or deployments
[TimeWindow]
Office process creation and macro execution timing after system or user login
[UserContext]
May be scoped to high-value users or those with access to sensitive templates
AN1437
Analytic 1437
Office Suite
Malicious VBA macros embedded in base templates like Normal.dotm or Personal.xlsb are automatically loaded and executed at startup. Template path may be hijacked to load a remote or attacker-controlled template via GlobalDotName registry setting.
m365:unified
Set-Mailbox, Set-MailboxPolicy, Set-TrustedLocation
[TemplateSource]
Macros may be embedded in local user templates or retrieved from shared network paths
[MacroSecurityLevel]
Macro execution policy (disabled, warn, enabled) varies by tenant or user configuration