Log sources › m365:office
m365:office
Inverted view: what can be detected if this is the log you have. Office Suite
4
channels
3
analytics
3
techniques
0
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
Anomalous editing of invoice or payment document templates |
DC0061 File Modification | AN1365 | 1 |
External HTTP/DNS connection from Office binary shortly after macro trigger |
DC0085 Network Traffic Content | AN0029 | 1 |
Startup execution includes non-default component |
DC0064 Command Execution | AN0881 | 1 |
VBA auto_open, auto_close, or document_open events |
DC0029 Script Execution | AN0029 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1137.002 Office Test | persistence | 2 | 0 |
| T1546 Event Triggered Execution | privilege escalation, persistence | 10 | 0 |
| T1657 Financial Theft | impact | 0 | 0 |