Windows Office Startup Add-In Persistence via .wll/.xll/.xlam
Alerts on Office startup/add-ins DLL-based files (.wll/.xll/.xlam and related) written to Word/Excel startup paths.
- Product
- windows
- Category
- file_event
- Author
- NVISO (SigmaHQ), DRL 1.1
- Published
- 2020-05-11
- Updated
- 2026-07-31
ATT&CK techniques
PersistenceRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags file creation events consistent with persistence using Microsoft Office startup add-ins, focusing on Office-specific directories and common add-in file types (.wll, .xll, .xlam, .xla, .ppam). Attackers may leverage these load-on-startup mechanisms to execute code whenever Word or Excel starts. It relies on Windows file event telemetry that includes the target file path and filename.
Reporting behind it
- Internal ResearchInternal Research
- labs.withsecure.comhttps://labs.withsecure.com/publications/add-in-opportunities-for-office-persistence
- github.comhttps://github.com/redcanaryco/atomic-red-team/blob/4ae9580a1a8772db87a1b6cdb0d03e5af231e966/atomics/T1137.006/T1137.006.md
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_office_addin_persistence.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Office Startup Add-In Persistence via .wll/.xll/.xlam
id: 445e3736-ff3e-4742-a0f3-8447cd595b19
status: test
description: This rule flags file creation events consistent with persistence using Microsoft Office startup add-ins, focusing on Office-specific directories and common add-in file types (.wll, .xll, .xlam, .xla, .ppam). Attackers may leverage these load-on-startup mechanisms to execute code whenever Word or Excel starts. It relies on Windows file event telemetry that includes the target file path and filename.
references:
- Internal Research
- https://labs.withsecure.com/publications/add-in-opportunities-for-office-persistence
- https://github.com/redcanaryco/atomic-red-team/blob/4ae9580a1a8772db87a1b6cdb0d03e5af231e966/atomics/T1137.006/T1137.006.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_office_addin_persistence.yml
author: NVISO, Huntrule Team
date: 2020-05-11
modified: 2023-02-08
tags:
- attack.persistence
- attack.t1137.006
logsource:
category: file_event
product: windows
detection:
selection_wlldropped:
TargetFilename|contains: \Microsoft\Word\Startup\
TargetFilename|endswith: .wll
selection_xlldropped:
TargetFilename|contains: \Microsoft\Excel\Startup\
TargetFilename|endswith: .xll
selection_xladropped:
TargetFilename|contains: Microsoft\Excel\XLSTART\
TargetFilename|endswith: .xlam
selection_generic:
TargetFilename|contains: \Microsoft\Addins\
TargetFilename|endswith:
- .xlam
- .xla
- .ppam
condition: 1 of selection_*
falsepositives:
- Legitimate add-ins
level: high
license: DRL-1.1
related:
- id: 8e1cb247-6cf6-42fa-b440-3f27d57e9936
type: derived