Windows Office Document Drop into Startup Folders for Persistence
Alerts when Office documents/templates are created in Word/Excel startup folders on Windows, suggesting persistence attempts.
FreeUnreviewedSigmahighv1
windows-office-document-drop-into-startup-folders-for-persistence-0e20c89d
title: Windows Office Document Drop into Startup Folders for Persistence
id: c8555838-3658-48e9-bca3-9091d03a0ce8
status: test
description: This rule flags file creation events where Microsoft Office document or template files are written into default Word/Excel startup paths, including directories under Microsoft\Word\STARTUP, Microsoft\Excel\XLSTART, and related startup folders within Office Program Files. Attackers may use these locations to persist and trigger execution of documents or templates when Office starts. The detection relies on Windows file event telemetry capturing TargetFilename and Image context to exclude direct activity from WINWORD.exe and EXCEL.exe.
references:
- https://insight-jp.nttsecurity.com/post/102hojk/operation-restylink-apt-campaign-targeting-japanese-companies
- https://learn.microsoft.com/en-us/office/troubleshoot/excel/use-startup-folders
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_office_startup_persistence.yml
author: Max Altgelt (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-06-02
modified: 2023-06-22
tags:
- attack.persistence
- attack.t1137
logsource:
category: file_event
product: windows
detection:
selection_word_paths:
- TargetFilename|contains: \Microsoft\Word\STARTUP
- TargetFilename|contains|all:
- \Office
- \Program Files
- \STARTUP
selection_word_extension:
TargetFilename|endswith:
- .doc
- .docm
- .docx
- .dot
- .dotm
- .rtf
selection_excel_paths:
- TargetFilename|contains: \Microsoft\Excel\XLSTART
- TargetFilename|contains|all:
- \Office
- \Program Files
- \XLSTART
selection_excel_extension:
TargetFilename|endswith:
- .xls
- .xlsm
- .xlsx
- .xlt
- .xltm
filter_main_office:
Image|endswith:
- \WINWORD.exe
- \EXCEL.exe
condition: (all of selection_word_* or all of selection_excel_*) and not filter_main_office
falsepositives:
- Loading a user environment from a backup or a domain controller
- Synchronization of templates
level: high
license: DRL-1.1
related:
- id: 0e20c89d-2264-44ae-8238-aeeaba609ece
type: derived
What it detects
This rule flags file creation events where Microsoft Office document or template files are written into default Word/Excel startup paths, including directories under Microsoft\Word\STARTUP, Microsoft\Excel\XLSTART, and related startup folders within Office Program Files. Attackers may use these locations to persist and trigger execution of documents or templates when Office starts. The detection relies on Windows file event telemetry capturing TargetFilename and Image context to exclude direct activity from WINWORD.exe and EXCEL.exe.
Known false positives
- Loading a user environment from a backup or a domain controller
- Synchronization of templates
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.