AN1116
Analytic 1116
Windows
Office-based persistence via Office template macros, Outlook forms/rules/homepage, or registry-persistent scripts. Adversary modifies registry keys or Office application directories to load malicious scripts at startup.
WinEventLog:Sysmon
EventCode=1
WinEventLog:Sysmon
EventCode=11
WinEventLog:Sysmon
EventCode=13, 14
WinEventLog:Application
Outlook rule creation, form load, or homepage redirection
[ParentProcessName]
Tune based on expected Office process tree (e.g., WINWORD.EXE spawning cmd.exe)
[RegistryPath]
Specific keys related to Office startup such as Outlook Today, AddIns, or Template Macros
[TimeWindow]
Window of process execution after user login or Outlook launch
[UserContext]
Detect persistence within high-value user mailboxes (e.g., admin, finance, C-suite)
AN1117
Analytic 1117
Office Suite
Startup-based persistence mechanisms within Microsoft Office Suite like template macros and home page redirects being configured through internal automation or client-side settings.
m365:unified
Set-Mailbox, Set-InboxRule, Set-MailboxFolderPermission
m365:mailboxaudit
Outlook rule creation or custom form deployment
[RuleAction]
Identify rule actions that execute scripts, forward emails externally, or start external content
[MailboxTarget]
Focus on users with sensitive roles or shared mailboxes
[TimeWindow]
Detect persistence artifacts created shortly after credential access or login from an unusual location