Windows File Events: Office Startup Add-in Files (.wll/.xll/.xlam) for Persistence

Alerts on Office startup/add-ins DLL-based files (.wll/.xll/.xlam and related) written to Word/Excel startup paths.

FreeUnreviewedSigmahighv1
title: "Windows File Events: Office Startup Add-in Files (.wll/.xll/.xlam) for Persistence"
id: 445e3736-ff3e-4742-a0f3-8447cd595b19
status: test
description: This rule flags creation or dropping of Microsoft Office add-in files in common Office startup and add-in directories. Attackers can use these add-ins to load code when Word or Excel starts, providing persistence without needing a traditional startup mechanism. The detection relies on Windows file event telemetry that records the target file path and filename extensions associated with Office add-ins.
references:
  - Internal Research
  - https://labs.withsecure.com/publications/add-in-opportunities-for-office-persistence
  - https://github.com/redcanaryco/atomic-red-team/blob/4ae9580a1a8772db87a1b6cdb0d03e5af231e966/atomics/T1137.006/T1137.006.md
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_office_addin_persistence.yml
author: NVISO, Huntrule Team
date: 2020-05-11
modified: 2023-02-08
tags:
  - attack.persistence
  - attack.t1137.006
logsource:
  category: file_event
  product: windows
detection:
  selection_wlldropped:
    TargetFilename|contains: \Microsoft\Word\Startup\
    TargetFilename|endswith: .wll
  selection_xlldropped:
    TargetFilename|contains: \Microsoft\Excel\Startup\
    TargetFilename|endswith: .xll
  selection_xladropped:
    TargetFilename|contains: Microsoft\Excel\XLSTART\
    TargetFilename|endswith: .xlam
  selection_generic:
    TargetFilename|contains: \Microsoft\Addins\
    TargetFilename|endswith:
      - .xlam
      - .xla
      - .ppam
  condition: 1 of selection_*
falsepositives:
  - Legitimate add-ins
level: high
license: DRL-1.1
related:
  - id: 8e1cb247-6cf6-42fa-b440-3f27d57e9936
    type: derived

What it detects

This rule flags creation or dropping of Microsoft Office add-in files in common Office startup and add-in directories. Attackers can use these add-ins to load code when Word or Excel starts, providing persistence without needing a traditional startup mechanism. The detection relies on Windows file event telemetry that records the target file path and filename extensions associated with Office add-ins.

Known false positives

  • Legitimate add-ins

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.