Cross-source coverage

T1137 / ATT&CK

Office Application Startup

64 rules · 62 families across 8 sources.

3 deprecated hidden · include

From MITRE ATT&CK 19.2

Adversaries may leverage Microsoft Office-based applications for persistence between startups. Microsoft Office is a fairly common application suite on Windows-based operating systems within an enterprise network. There are multiple mechanisms that can be used with Office for persistence when an Office-based application is started; this can include the use of Office Template Macros and add-ins.

A variety of features have been discovered in Outlook that can be abused to obtain persistence, such as Outlook rules, forms, and Home Page. These persistence mechanisms can work within Outlook or be used through Office 365.

Tactics
Persistence
Platforms
Windows · Office Suite
Telemetry
WinEventLog:SysmonWinEventLog:Applicationm365:unifiedm365:mailboxaudit

How MITRE says to detect it DET0398

Detect Office Startup-Based Persistence via Macros, Forms, and Registry Hooks

Windows Analytic 1116

Office-based persistence via Office template macros, Outlook forms/rules/homepage, or registry-persistent scripts. Adversary modifies registry keys or Office application directories to load malicious scripts at startup.

  • WinEventLog:Sysmon EventCode=1
  • WinEventLog:Sysmon EventCode=11
  • WinEventLog:Sysmon EventCode=13, 14
  • WinEventLog:Application Outlook rule creation, form load, or homepage redirection

Office Suite Analytic 1117

Startup-based persistence mechanisms within Microsoft Office Suite like template macros and home page redirects being configured through internal automation or client-side settings.

  • m365:unified Set-Mailbox, Set-InboxRule, Set-MailboxFolderPermission
  • m365:mailboxaudit Outlook rule creation or custom form deployment

Sub-techniques with coverage

Counted in the 64 above — a rule tagged a sub-technique covers this technique too.


socfortress/Wazuh-Rules

28 rules · 27 families
Detection Severity Format
Sysmon - Event 1: Process creation · Excel Add-in XLL Execution (T1137.006) High Wazuh XML
Sysmon - Event 1: Process creation · Excel Auto-Loaded Add-in from AppData (T1137.006) High Wazuh XML
Sysmon - Event 1: Process creation · Excel VBA Add-in Auto-Start (XLAM) (T1137.006) High Wazuh XML
Sysmon - Event 1: Process creation · Office Add-in Launching Suspicious Child (T1137.006) High Wazuh XML
Sysmon - Event 1: Process creation · Office Application Startup (T1137) 2 variants High Wazuh XML
Sysmon - Event 1: Process creation · PowerPoint Add-in Auto-Start (PPAM) (T1137.006) High Wazuh XML
Sysmon - Event 1: Process creation · Word Auto-Loaded Add-in (WLL) (T1137.006) High Wazuh XML
T1137 - Outlook Macro Security Level Persistence detected via Registry SetValue (Target: ) · win.eventdata.eventType = (?i)^SetValue, win.eventdata.targetObject = (?i)Software\\\\Microsoft\\\\Office\\\\.*\\\\Outlook\\\\Sec… High Wazuh XML
T1137 - Outlook VbaProject.OTM Persistence File Created (Target: ) · win.eventdata.targetFilename = (?i)\\\\Microsoft\\\\Outlook\\\\VbaProject\.OTM High Wazuh XML
operation. · office_365.Operation = LaunchPowerApp Low Wazuh XML

+ 18 more from socfortress/Wazuh-Rules → showing the 10 highest-severity

SigmaHQ/sigma

16 rules
Detection Severity Format
Code Executed Via Office Add-in XLL File High Sigma
Outlook Macro Execution Without Warning Setting Enabled High Sigma
Potential Persistence Via Excel Add-in - Registry High Sigma
Potential Persistence Via Microsoft Office Add-In High Sigma
Potential Persistence Via Microsoft Office Startup Folder High Sigma
Potential Persistence Via Outlook Form High Sigma
Potential Persistence Via Outlook LoadMacroProviderOnBoot Setting High Sigma
Suspicious Microsoft Office Child Process - MacOS High Sigma
Suspicious Outlook Macro Created High Sigma
IE Change Domain Zone Medium Sigma

+ 6 more from SigmaHQ/sigma → showing the 10 highest-severity

elastic/detection-rules

7 rules
Detection Severity Format
M365 Exchange Inbox Phishing Evasion Rule Created High Elastic TOML
Outlook Home Page Registry Modification High Elastic TOML
Persistence via Microsoft Office AddIns High Elastic TOML
M365 Exchange Inbox Rule with Obfuscated Name Medium Elastic TOML
Persistence via Microsoft Outlook VBA Medium Elastic TOML
Suspicious Execution via Microsoft Office Add-Ins Medium Elastic TOML
Office Test Registry Persistence Low Elastic TOML

elastic/protections-artifacts

6 rules
Detection Severity Format
Execution via Microsoft Excel XLL Add-In Undefined Elastic TOML
Microsoft Office AddIn Creation Undefined Elastic TOML
Microsoft Office AddIn Loaded Undefined Elastic TOML
Office Application Startup via Template File Modification Undefined Elastic TOML
Outlook Home Page Registry Modification Undefined Elastic TOML
Process Creation via Microsoft Office Add-Ins Undefined Elastic TOML

splunk/security_content

3 rules
Detection Severity Format
Windows Outlook LoadMacroProviderOnBoot Persistence Undefined SPL
Windows Outlook Macro Created by Suspicious Process Undefined SPL
Windows Outlook Macro Security Modified Undefined SPL

Bert-JanP/Hunting-Queries-Detection-Rules

2 rules
Detection Severity Format
ASR Executable Office Content Undefined KQL
MITRE ATT&CK Mapping Undefined KQL

Wazuh Core Ruleset

1 rule
Detection Severity Format
Office 365: Microsoft Power Automate (formerly called Microsoft Flow) events. Low Wazuh XML

panther-labs/panther-analysis

1 rule
Detection Severity Format
Microsoft Exchange External Forwarding High Panther Python

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.