Windows Office Macro File Creation via Office Applications
Alerts on creation of macro-enabled Office documents/templates by Office apps on Windows, excluding Office temporary files.
- Product
- windows
- Category
- file_event
- Author
- Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2022-01-23
- Updated
- 2026-07-31
ATT&CK techniques
Initial AccessRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies the creation of Office macro-enabled documents and templates (.docm, .dotm, .xlsm, .xltm, .potm, .pptm) on Windows. It helps catch attacker behavior that relies on generating macro-capable files for later execution, using file create events from process and target filename telemetry. Detection focuses on files created by the Office app executables while excluding common temporary Office files (e.g., names containing "\~$").
Reporting behind it
- github.comhttps://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1566.001/T1566.001.md
- learn.microsoft.comhttps://learn.microsoft.com/en-us/deployoffice/compat/office-file-format-reference
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_office_macro_files_created.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Office Macro File Creation via Office Applications
id: 20129d54-8875-4b77-8dbf-e795d03fdcbf
related:
- id: 0e29e3a7-1ad8-40aa-b691-9f82ecd33d66
type: similar
- id: 91174a41-dc8f-401b-be89-7bfc140612a0
type: derived
status: test
description: This rule identifies the creation of Office macro-enabled documents and templates (.docm, .dotm, .xlsm, .xltm, .potm, .pptm) on Windows. It helps catch attacker behavior that relies on generating macro-capable files for later execution, using file create events from process and target filename telemetry. Detection focuses on files created by the Office app executables while excluding common temporary Office files (e.g., names containing "\~$").
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1566.001/T1566.001.md
- https://learn.microsoft.com/en-us/deployoffice/compat/office-file-format-reference
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_office_macro_files_created.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-01-23
modified: 2026-01-09
tags:
- attack.initial-access
- attack.t1566.001
logsource:
category: file_event
product: windows
detection:
selection:
TargetFilename|endswith:
- .docm
- .dotm
- .xlsm
- .xltm
- .potm
- .pptm
filter_main_office:
Image|startswith:
- C:\Program Files\Microsoft Office\
- C:\Program Files (x86)\Microsoft Office\
Image|endswith:
- \WINWORD.EXE
- \EXCEL.EXE
- \POWERPNT.EXE
TargetFilename|contains: \~$
condition: selection and not 1 of filter_main_*
falsepositives:
- Very common in environments that rely heavily on macro documents
level: low
license: DRL-1.1