{"id":"T1137.002","name":"Office Test","url":"https://attack.mitre.org/techniques/T1137/002","tactics":["persistence"],"platforms":["Windows","Office Suite"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0315","stix_id":"x-mitre-detection-strategy--cb0a01e5-d88a-4ac8-a70a-1472c5dccd10","name":"Detect Persistence via Office Test Registry DLL Injection","url":"https://attack.mitre.org/detectionstrategies/DET0315","analytics":[{"id":"AN0880","stix_id":"x-mitre-analytic--80be1bd7-b4e8-4d1b-b294-56b1c073bbe0","name":"Analytic 0880","description":"Adversaries create the 'Office Test\\Special\\Perf' registry key and specify a malicious DLL path that is auto-loaded when an Office application starts. This DLL is injected into the Office process memory space and can provide persistent execution without requiring macro enablement.","url":"https://attack.mitre.org/detectionstrategies/DET0315#AN0880","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=13, 14","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Microsoft-Office-Alerts","channel":"Unexpected DLL or component loaded at Office startup","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"wineventlog-microsoft-office-alerts"}],"mutable_elements":[{"field":"RegistryPath","description":"Path to 'Office test\\Special\\Perf' may vary by Office version, 32/64-bit, or architecture (HKCU vs HKLM)"},{"field":"DLLPath","description":"Injected DLL may reside in different user-writable locations (e.g., %APPDATA%, %TEMP%, or network shares)"},{"field":"OfficeProcessName","description":"Process name (e.g., winword.exe, excel.exe) may vary by Office deployment and usage"},{"field":"TimeWindow","description":"Time between DLL registry creation and first Office execution may vary depending on user activity"},{"field":"UserContext","description":"Malicious DLL may target only specific users, necessitating correlation with interactive logon sessions"}],"live":true,"detection_strategies":["DET0315"],"techniques":["T1137.002"]},{"id":"AN0881","stix_id":"x-mitre-analytic--a677cebe-06e8-4993-bd4c-6a6884862444","name":"Analytic 0881","description":"Office application auto-loads a non-standard DLL during startup triggered via Office Test Registry key, often without macro warning banners. DLL persistence mechanism circumvents traditional macro defenses.","url":"https://attack.mitre.org/detectionstrategies/DET0315#AN0881","platforms":["Office Suite"],"log_source_references":[{"name":"m365:unified","channel":"Non-standard Office startup component detected (e.g., unexpected DLL path)","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"m365-unified"},{"name":"m365:office","channel":"Startup execution includes non-default component","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"m365-office"}],"mutable_elements":[{"field":"TrustedLocationBypass","description":"DLL may be placed in location trusted by Office configuration or signed to evade alerts"},{"field":"AuditPolicyScope","description":"Only specific tenants or users may have Office auditing enabled at granular DLL load level"}],"live":true,"detection_strategies":["DET0315"],"techniques":["T1137.002"]}],"live":true,"version":"1.0","techniques":["T1137.002"]}],"sigma_rules":[{"id":"3d27f6dd-1c74-4687-b4fa-ca849d128d1c","title":"Office Application Startup - Office Test","author":"omkar72","status":"test","level":"medium","date":"2020-10-25","modified":"2023-11-08","description":"Detects the addition of office test registry that allows a user to specify an arbitrary DLL that will be executed every time an Office application is started","references":["https://unit42.paloaltonetworks.com/unit42-technical-walkthrough-office-test-persistence-method-used-in-recent-sofacy-attacks/"],"logsource":{"product":"windows","category":"registry_event"},"tags":["attack.persistence","attack.t1137.002"],"path":"rules/windows/registry/registry_event/registry_event_office_test_regadd.yml","techniques":["T1137.002"],"cves":[]},{"id":"69483748-1525-4a6c-95ca-90dc8d431b68","title":"Suspicious Microsoft Office Child Process - MacOS","author":"Sohan G (D4rkCiph3r)","status":"test","level":"high","date":"2023-01-31","modified":"2023-02-04","description":"Detects suspicious child processes spawning from microsoft office suite applications such as word or excel. This could indicates malicious macro execution","references":["https://redcanary.com/blog/applescript/","https://objective-see.org/blog/blog_0x4B.html"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.execution","attack.persistence","attack.t1059.002","attack.t1137.002","attack.t1204.002"],"path":"rules/macos/process_creation/proc_creation_macos_office_susp_child_processes.yml","techniques":["T1059.002","T1137.002","T1204.002"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}