Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0566 — Template Injection Detection - Windows
DET0566

Template Injection Detection - Windows

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1564 Analytic 1564
Windows

Detection of Office or document viewer processes (e.g., winword.exe) initiating network connections to remote templates or executing scripts due to manipulated template references (e.g., embedded in .docx, .rtf, or .dotm files), followed by suspicious child process creation (e.g., PowerShell).

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=3, 22
[TemplateURLPatterns] Can be tuned to flag known bad domains or external resources in template fields.
[ParentProcess] May be environment-specific; typically Word, Excel, PowerPoint.
[TimeWindow] Correlation window for process + network activity.
[ChildProcessAnomalyThreshold] Trigger when document-spawned child process deviates from expected profile.

Detected Techniques

1

Details

MITRE ID
DET0566
STIX ID
x-mitre-detection-strategy--481a55d3-5f23-4428-9438-0220eab78678
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.