Windows: Registry change disabling MacroRuntimeScanScope runtime macro scanning

Flags Office registry updates that set MacroRuntimeScanScope to 0x00000000, disabling runtime scanning for enabled macros.

FreeReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-10-25
Updated
2026-07-30

What it detects

This rule identifies modifications to the MacroRuntimeScanScope registry key under Microsoft Office common security settings with a value of DWORD 0x00000000. Disabling runtime scanning of enabled macros can help attackers reduce security visibility and detection of malicious Office macro behavior. It relies on Windows registry set telemetry that captures the TargetObject path and the written Details value.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.