Windows Office Macro File Creation from Browser or Email Client

Flags Windows creation of macro-enabled Office files (.docm/.xlsm/.pptm) initiated by common browsers or email clients.

FreeReviewedSigma · Low · v2
Product
windows
Category
file_event
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-01-23
Updated
2026-07-31
title: Windows Office Macro File Creation from Browser or Email Client
id: 9052bbe4-5000-4314-99f2-3b6597bdf932
related:
  - id: 91174a41-dc8f-401b-be89-7bfc140612a0
    type: similar
  - id: 0e29e3a7-1ad8-40aa-b691-9f82ecd33d66
    type: derived
status: test
description: This rule flags the creation of macro-enabled Office files (.docm, .dotm, .xlsm, .xltm, .potm, .pptm) when the activity is initiated by common browsers or email clients on Windows. Attackers may use downloaded or attached macro documents to establish initial access or deliver malicious payloads, making these file creation events an important early signal. The detection relies on Windows file event telemetry that includes the creating process path and the target filename (including :Zone indicators).
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1566.001/T1566.001.md
  - https://learn.microsoft.com/en-us/deployoffice/compat/office-file-format-reference
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_office_macro_files_downloaded.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-01-23
modified: 2025-10-29
tags:
  - attack.initial-access
  - attack.t1566.001
logsource:
  category: file_event
  product: windows
detection:
  selection_processes:
    Image|endswith:
      - \RuntimeBroker.exe
      - \outlook.exe
      - \thunderbird.exe
      - \brave.exe
      - \chrome.exe
      - \firefox.exe
      - \iexplore.exe
      - \maxthon.exe
      - \MicrosoftEdge.exe
      - \msedge.exe
      - \msedgewebview2.exe
      - \opera.exe
      - \safari.exe
      - \seamonkey.exe
      - \vivaldi.exe
      - \whale.exe
  selection_ext:
    - TargetFilename|endswith:
        - .docm
        - .dotm
        - .xlsm
        - .xltm
        - .potm
        - .pptm
    - TargetFilename|contains:
        - .docm:Zone
        - .dotm:Zone
        - .xlsm:Zone
        - .xltm:Zone
        - .potm:Zone
        - .pptm:Zone
  condition: all of selection_*
falsepositives:
  - Legitimate macro files downloaded from the internet
  - Legitimate macro files sent as attachments via emails
level: low
license: DRL-1.1