Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0398 — Detect Office Startup-Based Persistence via Macros, Forms, and Registry Hooks
DET0398

Detect Office Startup-Based Persistence via Macros, Forms, and Registry Hooks

2 analytic(s) · 1 technique(s) detected

Analytics

2
AN1116 Analytic 1116
Windows

Office-based persistence via Office template macros, Outlook forms/rules/homepage, or registry-persistent scripts. Adversary modifies registry keys or Office application directories to load malicious scripts at startup.

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=13, 14 WinEventLog:Application Outlook rule creation, form load, or homepage redirection
[ParentProcessName] Tune based on expected Office process tree (e.g., WINWORD.EXE spawning cmd.exe)
[RegistryPath] Specific keys related to Office startup such as Outlook Today, AddIns, or Template Macros
[TimeWindow] Window of process execution after user login or Outlook launch
[UserContext] Detect persistence within high-value user mailboxes (e.g., admin, finance, C-suite)
AN1117 Analytic 1117
Office Suite

Startup-based persistence mechanisms within Microsoft Office Suite like template macros and home page redirects being configured through internal automation or client-side settings.

m365:unified Set-Mailbox, Set-InboxRule, Set-MailboxFolderPermission m365:mailboxaudit Outlook rule creation or custom form deployment
[RuleAction] Identify rule actions that execute scripts, forward emails externally, or start external content
[MailboxTarget] Focus on users with sensitive roles or shared mailboxes
[TimeWindow] Detect persistence artifacts created shortly after credential access or login from an unusual location

Detected Techniques

1

Details

MITRE ID
DET0398
STIX ID
x-mitre-detection-strategy--71a8576b-c9ef-4485-b461-d706fd757a67
Analytics
2
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.