Windows: Suspicious Outlook VbaProject.OTM Macro File Created

High-confidence file creation alert for Microsoft\Outlook\VbaProject.OTM while excluding outlook.exe.

FreeReviewedSigma · High · v2
Product
windows
Category
file_event
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-02-08
Updated
2026-07-31

ATT&CK techniques

Persistence → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. Exfiltration

  11. Impact

What it detects

This rule identifies creation of a macro document at a specific Outlook VBA project path ending with \Microsoft\Outlook\VbaProject.OTM. Attackers may use Outlook macro content as a persistence mechanism to execute VBA when Outlook processes or uses the stored project. It relies on Windows file creation telemetry, matching the target filename and excluding events where outlook.exe is the creating process.

Related detections9 linkedT1137 — drag to rearrange
Windows Persistence: Outlook LoadMacroProviderOnBoot Registry Setting Modification
Windows: New Outlook VBAProject OTM Macro File Created
Windows Registry: Outlook Macro Security Level Set to Enable All Macros
Suspicious Office Application Spawning Mshta With Remote HTA
AdminSDHolder Permissions Changed for Persistence (via security)
Malicious NotDoor Outlook VBA Persistence via VbaProject.OTM Deployment (via process_creation)
Malicious NotDoor Outlook Macro Auto-Execution Enablement via Registry (via registry_set)
Suspicious Persistence via Shell Script Dropped in profile.d Directory (via file_event)
Office Persistence via WLL Add-in Dropped to Word STARTUP Folder
Windows: Suspicious Outlook VbaProject.OTM Macro File Created
Pivot detection · T1137 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.