Windows Registry Persistence via Office Test Startup Key

Flags registry changes to a Windows Office test startup key that may enable auto-execution of an arbitrary DLL.

FreeReviewedSigma · Medium · v1
Product
windows
Category
registry_event
Author
omkar72 (SigmaHQ), DRL 1.1
Published
2020-10-25
Updated
2026-07-30

ATT&CK techniques

Persistence
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects creation or modification of a specific Windows registry path associated with “Office test” startup behavior under Office. By storing an attacker-controlled reference in this location, malware can arrange for an arbitrary DLL to execute automatically when an Office application starts. The detection relies on registry event telemetry and matches the TargetObject path containing the expected subkey segment.

Related detections2 linkedT1137.002 — drag to rearrange
Suspicious Microsoft Office Test Persistence Key Creation (via registry_set)
macOS Office Apps Spawning Shell or Scripting Processes
Windows Registry Persistence via Office Test Startup Key
Pivot detection · T1137.002 · 2 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.