1200KM / detection
T1137.006 Add-ins — Detection Rules
Detection workspace for T1137.006 Add-ins: 4 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Potential Persistence Via Microsoft Office Add-In · test · high · {"category":"file_event","product":"windows"}
- Code Executed Via Office Add-in XLL File · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Potential Persistence Via Visual Studio Tools for Office · test · medium · {"category":"registry_set","product":"windows"}
- Potential Persistence Via Excel Add-in - Registry · test · high · {"product":"windows","category":"registry_set"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0050 Detect Persistence via Malicious Office Add-ins
AN0137 Analytic 0137
An adversary writes or drops a malicious Office Add-in (e.g., WLL, XLL, COM) to a trusted directory or modifies registry keys to load malicious add-ins on Office application launch. Upon user opening Word or Excel, the add-in is automatically loaded, triggering execution of the payload, often spawning scripting engines or anomalous child processes.
AN0138 Analytic 0138
Malicious Office add-ins loaded via VSTO, COM, or VBA auto-load paths. Upon launch of Word/Excel/Outlook, the add-in executes code without user action. Add-in resides in trusted directory or registered via Office COM/VBE subsystem. Behavior includes unsigned add-in execution, anomalous load context, or add-in spawning interpreter process.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1137.006 simulation workspace
- Application Log Content · DC0038
- Command Execution · DC0064
- File Creation · DC0039
- File Modification · DC0061
- Process Creation · DC0032
- Windows Registry Key Modification · DC0063
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.