Cross-source coverage
T1137 / ATT&CK
Office Application Startup
64 rules · 62 families across 8 sources.
3 deprecated hidden · include
From MITRE ATT&CK 19.2
Adversaries may leverage Microsoft Office-based applications for persistence between startups. Microsoft Office is a fairly common application suite on Windows-based operating systems within an enterprise network. There are multiple mechanisms that can be used with Office for persistence when an Office-based application is started; this can include the use of Office Template Macros and add-ins.
A variety of features have been discovered in Outlook that can be abused to obtain persistence, such as Outlook rules, forms, and Home Page. These persistence mechanisms can work within Outlook or be used through Office 365.
- Tactics
- Persistence
- Platforms
- Windows · Office Suite
- Telemetry
-
WinEventLog:SysmonWinEventLog:Applicationm365:unifiedm365:mailboxaudit
How MITRE says to detect it DET0398
Detect Office Startup-Based Persistence via Macros, Forms, and Registry Hooks
Windows Analytic 1116
Office-based persistence via Office template macros, Outlook forms/rules/homepage, or registry-persistent scripts. Adversary modifies registry keys or Office application directories to load malicious scripts at startup.
WinEventLog:SysmonEventCode=1WinEventLog:SysmonEventCode=11WinEventLog:SysmonEventCode=13, 14WinEventLog:ApplicationOutlook rule creation, form load, or homepage redirection
Office Suite Analytic 1117
Startup-based persistence mechanisms within Microsoft Office Suite like template macros and home page redirects being configured through internal automation or client-side settings.
m365:unifiedSet-Mailbox, Set-InboxRule, Set-MailboxFolderPermissionm365:mailboxauditOutlook rule creation or custom form deployment
Sub-techniques with coverage
Counted in the 64 above — a rule tagged a sub-technique covers this technique too.
socfortress/Wazuh-Rules
28 rules · 27 families+ 18 more from socfortress/Wazuh-Rules → showing the 10 highest-severity
SigmaHQ/sigma
16 rules| Detection | Severity | Format |
|---|---|---|
| Code Executed Via Office Add-in XLL File | High | Sigma |
| Outlook Macro Execution Without Warning Setting Enabled | High | Sigma |
| Potential Persistence Via Excel Add-in - Registry | High | Sigma |
| Potential Persistence Via Microsoft Office Add-In | High | Sigma |
| Potential Persistence Via Microsoft Office Startup Folder | High | Sigma |
| Potential Persistence Via Outlook Form | High | Sigma |
| Potential Persistence Via Outlook LoadMacroProviderOnBoot Setting | High | Sigma |
| Suspicious Microsoft Office Child Process - MacOS | High | Sigma |
| Suspicious Outlook Macro Created | High | Sigma |
| IE Change Domain Zone | Medium | Sigma |
+ 6 more from SigmaHQ/sigma → showing the 10 highest-severity
elastic/detection-rules
7 rules| Detection | Severity | Format |
|---|---|---|
| M365 Exchange Inbox Phishing Evasion Rule Created | High | Elastic TOML |
| Outlook Home Page Registry Modification | High | Elastic TOML |
| Persistence via Microsoft Office AddIns | High | Elastic TOML |
| M365 Exchange Inbox Rule with Obfuscated Name | Medium | Elastic TOML |
| Persistence via Microsoft Outlook VBA | Medium | Elastic TOML |
| Suspicious Execution via Microsoft Office Add-Ins | Medium | Elastic TOML |
| Office Test Registry Persistence | Low | Elastic TOML |
elastic/protections-artifacts
6 rules| Detection | Severity | Format |
|---|---|---|
| Execution via Microsoft Excel XLL Add-In | Undefined | Elastic TOML |
| Microsoft Office AddIn Creation | Undefined | Elastic TOML |
| Microsoft Office AddIn Loaded | Undefined | Elastic TOML |
| Office Application Startup via Template File Modification | Undefined | Elastic TOML |
| Outlook Home Page Registry Modification | Undefined | Elastic TOML |
| Process Creation via Microsoft Office Add-Ins | Undefined | Elastic TOML |
splunk/security_content
3 rules| Detection | Severity | Format |
|---|---|---|
| Windows Outlook LoadMacroProviderOnBoot Persistence | Undefined | SPL |
| Windows Outlook Macro Created by Suspicious Process | Undefined | SPL |
| Windows Outlook Macro Security Modified | Undefined | SPL |
Bert-JanP/Hunting-Queries-Detection-Rules
2 rules| Detection | Severity | Format |
|---|---|---|
| ASR Executable Office Content | Undefined | KQL |
| MITRE ATT&CK Mapping | Undefined | KQL |
Wazuh Core Ruleset
1 rule| Detection | Severity | Format |
|---|---|---|
| Office 365: Microsoft Power Automate (formerly called Microsoft Flow) events. | Low | Wazuh XML |
panther-labs/panther-analysis
1 rule| Detection | Severity | Format |
|---|---|---|
| Microsoft Exchange External Forwarding | High | Panther Python |