Windows Office Document Drop into Startup Folders for Persistence

Alerts when Office documents/templates are created in Word/Excel startup folders on Windows, suggesting persistence attempts.

FreeUnreviewedSigmahighv1
title: Windows Office Document Drop into Startup Folders for Persistence
id: c8555838-3658-48e9-bca3-9091d03a0ce8
status: test
description: This rule flags file creation events where Microsoft Office document or template files are written into default Word/Excel startup paths, including directories under Microsoft\Word\STARTUP, Microsoft\Excel\XLSTART, and related startup folders within Office Program Files. Attackers may use these locations to persist and trigger execution of documents or templates when Office starts. The detection relies on Windows file event telemetry capturing TargetFilename and Image context to exclude direct activity from WINWORD.exe and EXCEL.exe.
references:
  - https://insight-jp.nttsecurity.com/post/102hojk/operation-restylink-apt-campaign-targeting-japanese-companies
  - https://learn.microsoft.com/en-us/office/troubleshoot/excel/use-startup-folders
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_office_startup_persistence.yml
author: Max Altgelt (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-06-02
modified: 2023-06-22
tags:
  - attack.persistence
  - attack.t1137
logsource:
  category: file_event
  product: windows
detection:
  selection_word_paths:
    - TargetFilename|contains: \Microsoft\Word\STARTUP
    - TargetFilename|contains|all:
        - \Office
        - \Program Files
        - \STARTUP
  selection_word_extension:
    TargetFilename|endswith:
      - .doc
      - .docm
      - .docx
      - .dot
      - .dotm
      - .rtf
  selection_excel_paths:
    - TargetFilename|contains: \Microsoft\Excel\XLSTART
    - TargetFilename|contains|all:
        - \Office
        - \Program Files
        - \XLSTART
  selection_excel_extension:
    TargetFilename|endswith:
      - .xls
      - .xlsm
      - .xlsx
      - .xlt
      - .xltm
  filter_main_office:
    Image|endswith:
      - \WINWORD.exe
      - \EXCEL.exe
  condition: (all of selection_word_* or all of selection_excel_*) and not filter_main_office
falsepositives:
  - Loading a user environment from a backup or a domain controller
  - Synchronization of templates
level: high
license: DRL-1.1
related:
  - id: 0e20c89d-2264-44ae-8238-aeeaba609ece
    type: derived

What it detects

This rule flags file creation events where Microsoft Office document or template files are written into default Word/Excel startup paths, including directories under Microsoft\Word\STARTUP, Microsoft\Excel\XLSTART, and related startup folders within Office Program Files. Attackers may use these locations to persist and trigger execution of documents or templates when Office starts. The detection relies on Windows file event telemetry capturing TargetFilename and Image context to exclude direct activity from WINWORD.exe and EXCEL.exe.

Known false positives

  • Loading a user environment from a backup or a domain controller
  • Synchronization of templates

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.