Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0050 — Detect Persistence via Malicious Office Add-ins
DET0050

Detect Persistence via Malicious Office Add-ins

2 analytic(s) · 1 technique(s) detected

Analytics

2
AN0137 Analytic 0137
Windows

An adversary writes or drops a malicious Office Add-in (e.g., WLL, XLL, COM) to a trusted directory or modifies registry keys to load malicious add-ins on Office application launch. Upon user opening Word or Excel, the add-in is automatically loaded, triggering execution of the payload, often spawning scripting engines or anomalous child processes.

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=2 WinEventLog:Sysmon EventCode=13, 14
[AddInExtension] Malicious add-ins may have varying extensions (.wll, .xll, .dll, .vsto)
[TrustedPath] Office trusted add-in paths may differ across enterprise configurations
[RegistryPath] Registry keys used to load add-ins may be version- and app-specific
[ChildProcessName] Office processes spawning mshta.exe, powershell.exe, or rundll32.exe are abnormal
[TimeWindow] Add-in loading may occur only during Office launch windows
AN0138 Analytic 0138
Office Suite

Malicious Office add-ins loaded via VSTO, COM, or VBA auto-load paths. Upon launch of Word/Excel/Outlook, the add-in executes code without user action. Add-in resides in trusted directory or registered via Office COM/VBE subsystem. Behavior includes unsigned add-in execution, anomalous load context, or add-in spawning interpreter process.

WinEventLog:Application Office Add-in load errors, abnormal loading context, or unsigned add-in warnings WinEventLog:Microsoft-Office/OutlookAddinMonitor Outlook loading add-in via unexpected load path or non-default profile context
[UnsignedAddInBehavior] Admins may allow or block unsigned add-ins depending on GPO configuration
[OfficeProductVersion] Different Office versions store trusted paths and add-in configs in version-specific locations
[AddInTrigger] Some add-ins only load on specific actions (new document, open file, etc.)

Detected Techniques

1

Persistence (1)

Details

MITRE ID
DET0050
STIX ID
x-mitre-detection-strategy--53144b02-d6b1-42de-b5cf-e785a59c43bd
Analytics
2
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.