Title:
Office Macro File Download
Status:
test
Description:Detects the creation of a new office macro files on the system via an application (browser, mail client).
This can help identify potential malicious activity, such as the download of macro-enabled documents that could be used for exploitation.
References:
-https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1566.001/T1566.001.md
-https://learn.microsoft.com/en-us/deployoffice/compat/office-file-format-reference
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-01-23
modified:2025-10-29
Tags:
- -'attack.initial-access'
- -'attack.t1566.001'
Logsource:
- category: file_event
- product: windows
Detection:
selection_processes:
Image|endswith:
-'\RuntimeBroker.exe'
-'\outlook.exe'
-'\thunderbird.exe'
-'\brave.exe'
-'\chrome.exe'
-'\firefox.exe'
-'\iexplore.exe'
-'\maxthon.exe'
-'\MicrosoftEdge.exe'
-'\msedge.exe'
-'\msedgewebview2.exe'
-'\opera.exe'
-'\safari.exe'
-'\seamonkey.exe'
-'\vivaldi.exe'
-'\whale.exe'
selection_ext:
- TargetFilename|endswith:
- '.docm'
- '.dotm'
- '.xlsm'
- '.xltm'
- '.potm'
- '.pptm'
- TargetFilename|contains:
- '.docm:Zone'
- '.dotm:Zone'
- '.xlsm:Zone'
- '.xltm:Zone'
- '.potm:Zone'
- '.pptm:Zone'
condition:
all of selection_*
Falsepositives:
-Legitimate macro files downloaded from the internet
-Legitimate macro files sent as attachments via emails
Level:
low