{"id":"295a59c1-7b79-4b47-a930-df12c15fc9c2","title":"Windows Registry Trust Record Modification","description":"Alerts on trust record modification within the registry, indicating usage of macros","author":"Antonlovesdnb, Trent Liffick (@tliffick)","status":"test","level":"medium","date":"2020-02-19","modified":"2023-06-21","tags":["attack.initial-access","attack.t1566.001"],"technique_ids":["T1566.001"],"logsource":{"category":"registry_event","product":"windows"},"falsepositives":["This will alert on legitimate macro usage as well, additional tuning is required"],"references":["https://outflank.nl/blog/2018/01/16/hunting-for-evil-detect-macros-being-executed/","http://az4n6.blogspot.com/2016/02/more-on-trust-records-macros-and.html","https://twitter.com/inversecos/status/1494174785621819397"],"source_path":"rules/windows/registry/registry_event/registry_event_office_trust_record_modification.yml","source_sha256":"e0254dae57ac8f94aea57e2288e0ca8eeb88ec0e126a5c46628dfb61edc6aab4","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/registry/registry_event/registry_event_office_trust_record_modification.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Windows Registry Trust Record Modification\nid: 295a59c1-7b79-4b47-a930-df12c15fc9c2\nrelated:\n    - id: a166f74e-bf44-409d-b9ba-ea4b2dd8b3cd\n      type: similar\nstatus: test\ndescription: Alerts on trust record modification within the registry, indicating usage of macros\nreferences:\n    - https://outflank.nl/blog/2018/01/16/hunting-for-evil-detect-macros-being-executed/\n    - http://az4n6.blogspot.com/2016/02/more-on-trust-records-macros-and.html\n    - https://twitter.com/inversecos/status/1494174785621819397\nauthor: Antonlovesdnb, Trent Liffick (@tliffick)\ndate: 2020-02-19\nmodified: 2023-06-21\ntags:\n    - attack.initial-access\n    - attack.t1566.001\nlogsource:\n    category: registry_event\n    product: windows\ndetection:\n    selection:\n        TargetObject|contains: '\\Security\\Trusted Documents\\TrustRecords'\n    condition: selection\nfalsepositives:\n    - This will alert on legitimate macro usage as well, additional tuning is required\nlevel: medium\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1566.001","id":"T1566.001","name":"Spearphishing Attachment","page":"techniques/enterprise/T1566.001/"}],"data_path":"data/detection-rules/295a59c1-7b79-4b47-a930-df12c15fc9c2.json","kind":"sigma"}
