Windows Office Macro File Creation from Browser or Email Client
Flags Windows creation of macro-enabled Office files (.docm/.xlsm/.pptm) initiated by common browsers or email clients.
- Product
- windows
- Category
- file_event
- Author
- Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2022-01-23
- Updated
- 2026-07-31
ATT&CK techniques
Initial AccessRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags the creation of macro-enabled Office files (.docm, .dotm, .xlsm, .xltm, .potm, .pptm) when the activity is initiated by common browsers or email clients on Windows. Attackers may use downloaded or attached macro documents to establish initial access or deliver malicious payloads, making these file creation events an important early signal. The detection relies on Windows file event telemetry that includes the creating process path and the target filename (including :Zone indicators).
Reporting behind it
- github.comhttps://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1566.001/T1566.001.md
- learn.microsoft.comhttps://learn.microsoft.com/en-us/deployoffice/compat/office-file-format-reference
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_office_macro_files_downloaded.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Office Macro File Creation from Browser or Email Client
id: 9052bbe4-5000-4314-99f2-3b6597bdf932
related:
- id: 91174a41-dc8f-401b-be89-7bfc140612a0
type: similar
- id: 0e29e3a7-1ad8-40aa-b691-9f82ecd33d66
type: derived
status: test
description: This rule flags the creation of macro-enabled Office files (.docm, .dotm, .xlsm, .xltm, .potm, .pptm) when the activity is initiated by common browsers or email clients on Windows. Attackers may use downloaded or attached macro documents to establish initial access or deliver malicious payloads, making these file creation events an important early signal. The detection relies on Windows file event telemetry that includes the creating process path and the target filename (including :Zone indicators).
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1566.001/T1566.001.md
- https://learn.microsoft.com/en-us/deployoffice/compat/office-file-format-reference
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_office_macro_files_downloaded.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-01-23
modified: 2025-10-29
tags:
- attack.initial-access
- attack.t1566.001
logsource:
category: file_event
product: windows
detection:
selection_processes:
Image|endswith:
- \RuntimeBroker.exe
- \outlook.exe
- \thunderbird.exe
- \brave.exe
- \chrome.exe
- \firefox.exe
- \iexplore.exe
- \maxthon.exe
- \MicrosoftEdge.exe
- \msedge.exe
- \msedgewebview2.exe
- \opera.exe
- \safari.exe
- \seamonkey.exe
- \vivaldi.exe
- \whale.exe
selection_ext:
- TargetFilename|endswith:
- .docm
- .dotm
- .xlsm
- .xltm
- .potm
- .pptm
- TargetFilename|contains:
- .docm:Zone
- .dotm:Zone
- .xlsm:Zone
- .xltm:Zone
- .potm:Zone
- .pptm:Zone
condition: all of selection_*
falsepositives:
- Legitimate macro files downloaded from the internet
- Legitimate macro files sent as attachments via emails
level: low
license: DRL-1.1