Windows Office Startup Add-In Persistence via .wll/.xll/.xlam

Alerts on Office startup/add-ins DLL-based files (.wll/.xll/.xlam and related) written to Word/Excel startup paths.

FreeReviewedSigma · High · v2
Product
windows
Category
file_event
Author
NVISO (SigmaHQ), DRL 1.1
Published
2020-05-11
Updated
2026-07-31

ATT&CK techniques

Persistence
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule flags file creation events consistent with persistence using Microsoft Office startup add-ins, focusing on Office-specific directories and common add-in file types (.wll, .xll, .xlam, .xla, .ppam). Attackers may leverage these load-on-startup mechanisms to execute code whenever Word or Excel starts. It relies on Windows file event telemetry that includes the target file path and filename.

Related detections3 linkedT1137.006 — drag to rearrange
Windows Registry: Excel Options Run Entry Point for XLL Add-in Persistence
PowerShell Script Blocks Register Malicious XLL via Office COM Automation on Windows
Windows Registry Persistence via VSTO Add-ins in Microsoft Office
Windows Office Startup Add-In Persistence via .wll/.xll/.xlam
Pivot detection · T1137.006 · 3 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.