Windows Registry: Outlook Macro Security Level Set to Enable All Macros

Detects Outlook macro warning bypass by setting the Outlook security level registry value to enable all macros.

FreeReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
@ScoubiMtl (SigmaHQ), DRL 1.1
Published
2021-04-05
Updated
2026-07-30

ATT&CK techniques

Persistence → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. Exfiltration

  11. Impact

What it detects

This rule flags registry changes to the Outlook security level key when the setting value indicates that all macros are enabled without warning. Disabling macro prompts can help attackers execute malicious Office macros with reduced user interaction. The detection relies on registry set telemetry, specifically matching the target Outlook security level path and the macro security value.

Related detections9 linkedT1137 — drag to rearrange
Windows: Suspicious Outlook VbaProject.OTM Macro File Created
Windows Persistence: Outlook LoadMacroProviderOnBoot Registry Setting Modification
Windows: New Outlook VBAProject OTM Macro File Created
Suspicious Office Application Spawning Mshta With Remote HTA
AdminSDHolder Permissions Changed for Persistence (via security)
Malicious NotDoor Outlook VBA Persistence via VbaProject.OTM Deployment (via process_creation)
Malicious NotDoor Outlook Macro Auto-Execution Enablement via Registry (via registry_set)
Suspicious Persistence via Shell Script Dropped in profile.d Directory (via file_event)
Office Persistence via WLL Add-in Dropped to Word STARTUP Folder
Windows Registry: Outlook Macro Security Level Set to Enable All Macros
Pivot detection · T1137 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.