Windows Registry: Excel Options Run Entry Point for XLL Add-in Persistence

Flags registry writes that reference an Excel XLL add-in via a '/R ' command under Excel Options.

FreeReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
frack113 (SigmaHQ), DRL 1.1
Published
2023-01-15
Updated
2026-07-30

ATT&CK techniques

Persistence
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule identifies registry modifications under the Microsoft Office Excel options path where the value data starts with '/R ' and ends with '.xll', indicating an Excel add-in (XLL) intended for automatic execution at Excel startup. Attackers may use an XLL to establish persistence through Office by leveraging Excel’s add-in loading behavior. The detection relies on Windows registry set telemetry that records the TargetObject and Details fields, including the command-like value contents.

Related detections3 linkedT1137.006 — drag to rearrange
PowerShell Script Blocks Register Malicious XLL via Office COM Automation on Windows
Windows Registry Persistence via VSTO Add-ins in Microsoft Office
Windows Office Startup Add-In Persistence via .wll/.xll/.xlam
Windows Registry: Excel Options Run Entry Point for XLL Add-in Persistence
Pivot detection · T1137.006 · 3 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.