This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Office Application Startup - Office Test
Original Source:
[Sigma source]
Title:
Office Application Startup - Office Test
Status:
test
Description:
Detects the addition of office test registry that allows a user to specify an arbitrary DLL that will be executed every time an Office application is started
References:
-https://unit42.paloaltonetworks.com/unit42-technical-walkthrough-office-test-persistence-method-used-in-recent-sofacy-attacks/
Author:
omkar72
Date:
2020-10-25
modified:
2023-11-08
Tags:
-'attack.persistence'
-'attack.t1137.002'
Logsource:
category: registry_event
product: windows
Detection:
selection:
TargetObject|contains
:
'\Software\Microsoft\Office test\Special\Perf'
condition
:
selection
Falsepositives:
-Unlikely
Level:
medium