EXPLORE
← Back to Explore
T1137

Office Application Startup

Adversaries may leverage Microsoft Office-based applications for persistence between startups. Microsoft Office is a fairly common application suite on Windows-based operating systems within an enterprise network. There are multiple mechanisms that can be used with Office for persistence when an Office-based application is started; this can include the use of Office Template Macros and add-ins. A variety of features have been discovered in Outlook that can be abused to obtain persistence, such ...

WindowsOffice Suite
18
Detections
3
Sources
2
Threat Actors

BY SOURCE

8sigma7elastic3splunk_escu

PROCEDURES (12)

Registry4 detections

Auto-extracted: 4 detections for registry

Macro2 detections

Auto-extracted: 2 detections for macro

Macro2 detections

Auto-extracted: 2 detections for macro

Email2 detections

Auto-extracted: 2 detections for email

Office1 detections

Auto-extracted: 1 detections for office

Persist1 detections

Auto-extracted: 1 detections for persist

Office1 detections

Auto-extracted: 1 detections for office

Suspicious1 detections

Auto-extracted: 1 detections for suspicious

Suspicious1 detections

Auto-extracted: 1 detections for suspicious

Suspicious1 detections

Auto-extracted: 1 detections for suspicious

General Monitoring1 detections

Auto-extracted: 1 detections for general monitoring

Office1 detections

Auto-extracted: 1 detections for office

THREAT ACTORS (2)

DETECTIONS (18)