// MITRE ATT&CK
T1137 · Office Application Startup
Adversaries may leverage Microsoft Office-based applications for persistence between startups. Microsoft Office is a fairly common application suite on Windows-based operating systems within an enterprise network. There are multiple mechanisms that can be used with Office for persistence when an Off...
How to detect & mitigate it
Detecting Office Application Startup starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Sub-techniques (6)
T1137.001
Office Template Macros T1137.002
Office Test T1137.003
Outlook Forms T1137.004
Outlook Home Page T1137.005
Outlook Rules T1137.006
Add-ins
Office Template Macros T1137.002
Office Test T1137.003
Outlook Forms T1137.004
Outlook Home Page T1137.005
Outlook Rules T1137.006
Add-ins
Related techniques
T1037
Boot or Logon Initialization Scripts T1543
Create or Modify System Process T1133
External Remote Services T1547
Boot or Logon Autostart Execution T1547.014
Active Setup T1176.001
Browser Extensions T1543.003
Windows Service T1098.003
Additional Cloud Roles
Boot or Logon Initialization Scripts T1543
Create or Modify System Process T1133
External Remote Services T1547
Boot or Logon Autostart Execution T1547.014
Active Setup T1176.001
Browser Extensions T1543.003
Windows Service T1098.003
Additional Cloud Roles
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.