Windows File Events: Office Startup Add-in Files (.wll/.xll/.xlam) for Persistence
Alerts on Office startup/add-ins DLL-based files (.wll/.xll/.xlam and related) written to Word/Excel startup paths.
FreeUnreviewedSigmahighv1
windows-file-events-office-startup-add-in-files-wll-xll-xlam-for-persistence-8e1cb247
title: "Windows File Events: Office Startup Add-in Files (.wll/.xll/.xlam) for Persistence"
id: 445e3736-ff3e-4742-a0f3-8447cd595b19
status: test
description: This rule flags creation or dropping of Microsoft Office add-in files in common Office startup and add-in directories. Attackers can use these add-ins to load code when Word or Excel starts, providing persistence without needing a traditional startup mechanism. The detection relies on Windows file event telemetry that records the target file path and filename extensions associated with Office add-ins.
references:
- Internal Research
- https://labs.withsecure.com/publications/add-in-opportunities-for-office-persistence
- https://github.com/redcanaryco/atomic-red-team/blob/4ae9580a1a8772db87a1b6cdb0d03e5af231e966/atomics/T1137.006/T1137.006.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_office_addin_persistence.yml
author: NVISO, Huntrule Team
date: 2020-05-11
modified: 2023-02-08
tags:
- attack.persistence
- attack.t1137.006
logsource:
category: file_event
product: windows
detection:
selection_wlldropped:
TargetFilename|contains: \Microsoft\Word\Startup\
TargetFilename|endswith: .wll
selection_xlldropped:
TargetFilename|contains: \Microsoft\Excel\Startup\
TargetFilename|endswith: .xll
selection_xladropped:
TargetFilename|contains: Microsoft\Excel\XLSTART\
TargetFilename|endswith: .xlam
selection_generic:
TargetFilename|contains: \Microsoft\Addins\
TargetFilename|endswith:
- .xlam
- .xla
- .ppam
condition: 1 of selection_*
falsepositives:
- Legitimate add-ins
level: high
license: DRL-1.1
related:
- id: 8e1cb247-6cf6-42fa-b440-3f27d57e9936
type: derived
What it detects
This rule flags creation or dropping of Microsoft Office add-in files in common Office startup and add-in directories. Attackers can use these add-ins to load code when Word or Excel starts, providing persistence without needing a traditional startup mechanism. The detection relies on Windows file event telemetry that records the target file path and filename extensions associated with Office add-ins.
Known false positives
- Legitimate add-ins
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.