ID | Name |
---|---|
T1137.001 | Office Template Macros |
T1137.002 | Office Test |
T1137.003 | Outlook Forms |
T1137.004 | Outlook Home Page |
T1137.005 | Outlook Rules |
T1137.006 | Add-ins |
Adversaries may abuse Microsoft Office add-ins to obtain persistence on a compromised system. Office add-ins can be used to add functionality to Office programs. [1] There are different types of add-ins that can be used by the various Office products; including Word/Excel add-in Libraries (WLL/XLL), VBA add-ins, Office Component Object Model (COM) add-ins, automation add-ins, VBA Editor (VBE), Visual Studio Tools for Office (VSTO) add-ins, and Outlook add-ins. [2][3]
Add-ins can be used to obtain persistence because they can be set to execute code when an Office application starts.
ID | Name | Description |
---|---|---|
S0268 | Bisonal |
Bisonal has been loaded through a |
S1143 | LunarLoader |
LunarLoader has the ability to use Microsoft Outlook add-ins to establish persistence. [5] |
S1142 | LunarMail |
LunarMail has the ability to use Outlook add-ins for persistence.[5] |
G0019 | Naikon |
Naikon has used the RoyalRoad exploit builder to drop a second stage loader, intel.wll, into the Word Startup folder on the compromised host.[6] |
ID | Mitigation | Description |
---|---|---|
M1040 | Behavior Prevention on Endpoint |
On Windows 10, enable Attack Surface Reduction (ASR) rules to prevent Office applications from creating child processes and from writing potentially malicious executable content to disk. [7] |
ID | Data Source | Data Component | Detects |
---|---|---|---|
DS0017 | Command | Command Execution |
Monitor executed commands and arguments that may abuse Microsoft Office add-ins to obtain persistence on a compromised system. |
DS0022 | File | File Creation |
Monitor for newly constructed files that may abuse Microsoft Office add-ins to obtain persistence on a compromised system. |
File Modification |
Monitor for changes made to files that may abuse Microsoft Office add-ins to obtain persistence on a compromised system. |
||
DS0009 | Process | Process Creation |
Monitor newly executed processes that may abuse Microsoft Office add-ins to obtain persistence on a compromised system. |
DS0024 | Windows Registry | Windows Registry Key Creation |
Audit the Registry entries relevant for enabling add-ins.[8][2] |
Windows Registry Key Modification |
Audit the Registry entries relevant for enabling add-ins.[8][2] |