Suspicious Microsoft Office Test Persistence Key Creation (via registry_set)

PremiumReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
HuntRule
Published
2026-09-13
Updated
2026-09-13

ATT&CK techniques

Persistence
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects creation or modification of the Office test Special Perf registry value which forces Microsoft Office applications to load an arbitrary DLL at startup. This rarely used key gives adversaries stealthy persistence through trusted Office processes.

Related detections2 linkedT1137.002 — drag to rearrange
macOS Office Apps Spawning Shell or Scripting Processes
Windows Registry Persistence via Office Test Startup Key
Suspicious Microsoft Office Test Persistence Key Creation (via registry_set)
Pivot detection · T1137.002 · 2 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.