{"id":"T1137","name":"Office Application Startup","url":"https://attack.mitre.org/techniques/T1137","tactics":["persistence"],"platforms":["Windows","Office Suite"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0398","stix_id":"x-mitre-detection-strategy--71a8576b-c9ef-4485-b461-d706fd757a67","name":"Detect Office Startup-Based Persistence via Macros, Forms, and Registry Hooks","url":"https://attack.mitre.org/detectionstrategies/DET0398","analytics":[{"id":"AN1116","stix_id":"x-mitre-analytic--e643c4aa-dc7d-43d9-b36e-f13d733f8e9a","name":"Analytic 1116","description":"Office-based persistence via Office template macros, Outlook forms/rules/homepage, or registry-persistent scripts. Adversary modifies registry keys or Office application directories to load malicious scripts at startup.","url":"https://attack.mitre.org/detectionstrategies/DET0398#AN1116","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=13, 14","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Application","channel":"Outlook rule creation, form load, or homepage redirection","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"wineventlog-application"}],"mutable_elements":[{"field":"ParentProcessName","description":"Tune based on expected Office process tree (e.g., WINWORD.EXE spawning cmd.exe)"},{"field":"RegistryPath","description":"Specific keys related to Office startup such as Outlook Today, AddIns, or Template Macros"},{"field":"TimeWindow","description":"Window of process execution after user login or Outlook launch"},{"field":"UserContext","description":"Detect persistence within high-value user mailboxes (e.g., admin, finance, C-suite)"}],"live":true,"detection_strategies":["DET0398"],"techniques":["T1137"]},{"id":"AN1117","stix_id":"x-mitre-analytic--59bfb473-611f-4443-9d11-f44e7ace93fb","name":"Analytic 1117","description":"Startup-based persistence mechanisms within Microsoft Office Suite like template macros and home page redirects being configured through internal automation or client-side settings.","url":"https://attack.mitre.org/detectionstrategies/DET0398#AN1117","platforms":["Office Suite"],"log_source_references":[{"name":"m365:unified","channel":"Set-Mailbox, Set-InboxRule, Set-MailboxFolderPermission","data_component":"DC0010","data_component_name":"User Account Modification","log_source_slug":"m365-unified"},{"name":"m365:mailboxaudit","channel":"Outlook rule creation or custom form deployment","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-mailboxaudit"}],"mutable_elements":[{"field":"RuleAction","description":"Identify rule actions that execute scripts, forward emails externally, or start external content"},{"field":"MailboxTarget","description":"Focus on users with sensitive roles or shared mailboxes"},{"field":"TimeWindow","description":"Detect persistence artifacts created shortly after credential access or login from an unusual location"}],"live":true,"detection_strategies":["DET0398"],"techniques":["T1137"]}],"live":true,"version":"1.0","techniques":["T1137"]}],"sigma_rules":[{"id":"0e20c89d-2264-44ae-8238-aeeaba609ece","title":"Potential Persistence Via Microsoft Office Startup Folder","author":"Max Altgelt (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-06-02","modified":"2023-06-22","description":"Detects creation of Microsoft Office files inside of one of the default startup folders in order to achieve persistence.","references":["https://insight-jp.nttsecurity.com/post/102hojk/operation-restylink-apt-campaign-targeting-japanese-companies","https://learn.microsoft.com/en-us/office/troubleshoot/excel/use-startup-folders"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.persistence","attack.t1137"],"path":"rules/windows/file/file_event/file_event_win_office_startup_persistence.yml","techniques":["T1137"],"cves":[]},{"id":"117d3d3a-755c-4a61-b23e-9171146d094c","title":"Suspicious Outlook Macro Created","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-02-08","modified":null,"description":"Detects the creation of a macro file for Outlook.","references":["https://www.mdsec.co.uk/2020/11/a-fresh-outlook-on-mail-based-persistence/","https://speakerdeck.com/heirhabarov/hunting-for-persistence-via-microsoft-exchange-server-or-outlook?slide=53","https://www.linkedin.com/pulse/outlook-backdoor-using-vba-samir-b-/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.privilege-escalation","attack.persistence","attack.command-and-control","attack.t1137","attack.t1008","attack.t1546"],"path":"rules/windows/file/file_event/file_event_win_office_outlook_susp_macro_creation.yml","techniques":["T1137","T1008","T1546"],"cves":[]},{"id":"396ae3eb-4174-4b9b-880e-dc0364d78a19","title":"Potential Persistence Via Outlook LoadMacroProviderOnBoot Setting","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2021-04-05","modified":"2023-08-17","description":"Detects the modification of Outlook setting \"LoadMacroProviderOnBoot\" which if enabled allows the automatic loading of any configured VBA project/module","references":["https://speakerdeck.com/heirhabarov/hunting-for-persistence-via-microsoft-exchange-server-or-outlook?slide=53","https://www.linkedin.com/pulse/outlook-backdoor-using-vba-samir-b-/"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.privilege-escalation","attack.persistence","attack.command-and-control","attack.t1137","attack.t1008","attack.t1546"],"path":"rules/windows/registry/registry_set/registry_set_office_outlook_enable_load_macro_provider_on_boot.yml","techniques":["T1137","T1008","T1546"],"cves":[]},{"id":"45e112d0-7759-4c2a-aa36-9f8fb79d3393","title":"IE Change Domain Zone","author":"frack113","status":"test","level":"medium","date":"2022-01-22","modified":"2023-08-17","description":"Hides the file extension through modification of the registry","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1112/T1112.md#atomic-test-4---add-domain-to-trusted-sites-zone","https://learn.microsoft.com/en-us/troubleshoot/developer/browsers/security-privacy/ie-security-zones-registry-entries"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.persistence","attack.t1137"],"path":"rules/windows/registry/registry_set/registry_set_change_security_zones.yml","techniques":["T1137"],"cves":[]},{"id":"5df86130-4e95-4a54-90f7-26541b40aec2","title":"Registry Modification to Hidden File Extension","author":"frack113","status":"test","level":"medium","date":"2022-01-22","modified":"2023-08-17","description":"Hides the file extension through modification of the registry","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1112/T1112.md#atomic-test-1---modify-registry-of-current-user-profile---cmd","https://unit42.paloaltonetworks.com/ransomware-families/","https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=TrojanSpy%3aMSIL%2fHakey.A"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.persistence","attack.t1137"],"path":"rules/windows/registry/registry_set/registry_set_hidden_extention.yml","techniques":["T1137"],"cves":[]},{"id":"8c31f563-f9a7-450c-bfa8-35f8f32f1f61","title":"New Outlook Macro Created","author":"@ScoubiMtl","status":"test","level":"medium","date":"2021-04-05","modified":"2023-02-08","description":"Detects the creation of a macro file for Outlook.","references":["https://www.mdsec.co.uk/2020/11/a-fresh-outlook-on-mail-based-persistence/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.privilege-escalation","attack.persistence","attack.command-and-control","attack.t1137","attack.t1008","attack.t1546"],"path":"rules/windows/file/file_event/file_event_win_office_outlook_macro_creation.yml","techniques":["T1137","T1008","T1546"],"cves":[]},{"id":"c3cefdf4-6703-4e1c-bad8-bf422fc5015a","title":"Outlook Security Settings Updated - Registry","author":"frack113","status":"test","level":"medium","date":"2021-12-28","modified":"2026-01-09","description":"Detects changes to the registry values related to outlook security settings","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1137/T1137.md","https://learn.microsoft.com/en-us/outlook/troubleshoot/security/information-about-email-security-settings"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.persistence","attack.t1137"],"path":"rules/windows/registry/registry_set/registry_set_office_outlook_security_settings.yml","techniques":["T1137"],"cves":[]},{"id":"e3b50fa5-3c3f-444e-937b-0a99d33731cd","title":"Outlook Macro Execution Without Warning Setting Enabled","author":"@ScoubiMtl","status":"test","level":"high","date":"2021-04-05","modified":"2023-08-17","description":"Detects the modification of Outlook security setting to allow unprompted execution of macros.","references":["https://www.mdsec.co.uk/2020/11/a-fresh-outlook-on-mail-based-persistence/","https://speakerdeck.com/heirhabarov/hunting-for-persistence-via-microsoft-exchange-server-or-outlook?slide=53"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.privilege-escalation","attack.persistence","attack.command-and-control","attack.t1137","attack.t1008","attack.t1546"],"path":"rules/windows/registry/registry_set/registry_set_office_outlook_enable_macro_execution.yml","techniques":["T1137","T1008","T1546"],"cves":[]},{"id":"fc06e655-d98c-412f-ac76-05c2698b1cb2","title":"Outlook Task/Note Reminder Received","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"low","date":"2023-04-05","modified":"2023-08-17","description":"Detects changes to the registry values related to outlook that indicates that a reminder was triggered for a Note or Task item. This could be a sign of exploitation of CVE-2023-23397. Further investigation is required to determine the success of an exploitation.","references":["https://www.microsoft.com/en-us/security/blog/2023/03/24/guidance-for-investigating-attacks-using-cve-2023-23397/"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.persistence","attack.t1137","cve.2023-23397","detection.emerging-threats"],"path":"rules-emerging-threats/2023/Exploits/CVE-2023-23397/registry_set_exploit_cve_2023_23397_outlook_reminder_trigger.yml","techniques":["T1137"],"cves":["CVE-2023-23397"]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}