Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0315 — Detect Persistence via Office Test Registry DLL Injection
DET0315

Detect Persistence via Office Test Registry DLL Injection

2 analytic(s) · 1 technique(s) detected

Analytics

2
AN0880 Analytic 0880
Windows

Adversaries create the 'Office Test\Special\Perf' registry key and specify a malicious DLL path that is auto-loaded when an Office application starts. This DLL is injected into the Office process memory space and can provide persistent execution without requiring macro enablement.

WinEventLog:Sysmon EventCode=13, 14 WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=7 WinEventLog:Sysmon EventCode=11 WinEventLog:Microsoft-Office-Alerts Unexpected DLL or component loaded at Office startup
[RegistryPath] Path to 'Office test\Special\Perf' may vary by Office version, 32/64-bit, or architecture (HKCU vs HKLM)
[DLLPath] Injected DLL may reside in different user-writable locations (e.g., %APPDATA%, %TEMP%, or network shares)
[OfficeProcessName] Process name (e.g., winword.exe, excel.exe) may vary by Office deployment and usage
[TimeWindow] Time between DLL registry creation and first Office execution may vary depending on user activity
[UserContext] Malicious DLL may target only specific users, necessitating correlation with interactive logon sessions
AN0881 Analytic 0881
Office Suite

Office application auto-loads a non-standard DLL during startup triggered via Office Test Registry key, often without macro warning banners. DLL persistence mechanism circumvents traditional macro defenses.

m365:unified Non-standard Office startup component detected (e.g., unexpected DLL path) m365:office Startup execution includes non-default component
[TrustedLocationBypass] DLL may be placed in location trusted by Office configuration or signed to evade alerts
[AuditPolicyScope] Only specific tenants or users may have Office auditing enabled at granular DLL load level

Detected Techniques

1

Persistence (1)

Details

MITRE ID
DET0315
STIX ID
x-mitre-detection-strategy--cb0a01e5-d88a-4ac8-a70a-1472c5dccd10
Analytics
2
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.