Windows Registry Persistence via VSTO Add-ins in Microsoft Office

Flags registry writes that register VSTO/Office add-ins for Outlook, Word, Excel, or PowerPoint persistence on Windows.

FreeReviewedSigma · Medium · v1
Product
windows
Category
registry_set
Author
Bhabesh Raj (SigmaHQ), DRL 1.1
Published
2021-01-10
Updated
2026-07-30

ATT&CK techniques

Persistence
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule identifies persistence attempts where an Office add-in registered through Visual Studio Tools for Office (VSTO) appears in registry locations used by Outlook, Word, Excel, and PowerPoint add-ins. Attackers may use VSTO-style add-ins to execute code on Office startup and maintain long-term access. It relies on registry set telemetry for matching target registry paths related to Office/VSTO add-in inclusion, while excluding common installer and integration binaries to reduce benign installation noise.

Related detections3 linkedT1137.006 — drag to rearrange
Windows Registry: Excel Options Run Entry Point for XLL Add-in Persistence
PowerShell Script Blocks Register Malicious XLL via Office COM Automation on Windows
Windows Office Startup Add-In Persistence via .wll/.xll/.xlam
Windows Registry Persistence via VSTO Add-ins in Microsoft Office
Pivot detection · T1137.006 · 3 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.