// MITRE ATT&CK
T1137 · Office Application Startup
Adversaries may leverage Microsoft Office-based applications for persistence between startups. Microsoft Office is a fairly common application suite on Windows-based operating systems within an enterprise network. There are multiple mechanisms that can be used with Office for persistence when an Off...
¿Cómo detectarlo y mitigarlo?
La detección de Office Application Startup parte de la telemetría de tu SIEM/EDR. Escribe una regla de detección con el generador Sigma, analiza logs sospechosos en el analizador de logs y sitúa la técnica en tu cobertura con la matriz ATT&CK.
Sub-técnicas (6)
T1137.001
Office Template Macros T1137.002
Office Test T1137.003
Outlook Forms T1137.004
Outlook Home Page T1137.005
Outlook Rules T1137.006
Add-ins
Office Template Macros T1137.002
Office Test T1137.003
Outlook Forms T1137.004
Outlook Home Page T1137.005
Outlook Rules T1137.006
Add-ins
Técnicas relacionadas
T1037
Boot or Logon Initialization Scripts T1543
Create or Modify System Process T1133
External Remote Services T1547
Boot or Logon Autostart Execution T1547.014
Active Setup T1176.001
Browser Extensions T1543.003
Windows Service T1098.003
Additional Cloud Roles
Boot or Logon Initialization Scripts T1543
Create or Modify System Process T1133
External Remote Services T1547
Boot or Logon Autostart Execution T1547.014
Active Setup T1176.001
Browser Extensions T1543.003
Windows Service T1098.003
Additional Cloud Roles
Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.