Windows Office Startup Folder File Drop for Persistence via Office Documents

Alerts when Office documents/templates are created in Word/Excel startup folders on Windows, suggesting persistence attempts.

FreeReviewedSigma · High · v2
Product
windows
Category
file_event
Author
Max Altgelt (Nextron Systems), Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-06-02
Updated
2026-07-31

ATT&CK techniques

Persistence
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies creation of Microsoft Office documents in default Word or Excel startup folder paths that can be used to trigger persistent execution when Office loads templates or documents. Attackers may leverage these locations to establish persistence using Office file types, relying on Windows file event telemetry and matching target filename path and extension patterns. It excludes activity where the initiating image is WINWORD.exe or EXCEL.exe to reduce noise from legitimate Office operations.

Related detections9 linkedT1137 — drag to rearrange
Suspicious Office Application Spawning Mshta With Remote HTA
Malicious NotDoor Outlook VBA Persistence via VbaProject.OTM Deployment (via process_creation)
Malicious NotDoor Outlook Macro Auto-Execution Enablement via Registry (via registry_set)
Office Persistence via WLL Add-in Dropped to Word STARTUP Folder
Windows Registry Changes for Outlook Task/Note Reminder Trigger
Windows: Suspicious Outlook VbaProject.OTM Macro File Created
Windows Registry: IE ZoneMap Domain Zone Change via ZoneMap\Domains
Windows Registry Set to Hide File Extensions via Explorer Advanced Keys
Windows Registry Changes to Outlook Security Settings
Windows Office Startup Folder File Drop for Persistence via Office Documents
Pivot detection · T1137 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.