Techniques › T1137 › AN1117
AN1117 Analytic 1117
Office Suite · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Startup-based persistence mechanisms within Microsoft Office Suite like template macros and home page redirects being configured through internal automation or client-side settings.</p>
- Detects
- T1137 Office Application Startup
- Part of
- DET0398 Detect Office Startup-Based Persistence via Macros, Forms, and Registry Hooks
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| m365:unified | Set-Mailbox, Set-InboxRule, Set-MailboxFolderPermission | DC0010 User Account Modification |
| m365:mailboxaudit | Outlook rule creation or custom form deployment | DC0038 Application Log Content |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
RuleAction | Identify rule actions that execute scripts, forward emails externally, or start external content |
MailboxTarget | Focus on users with sensitive roles or shared mailboxes |
TimeWindow | Detect persistence artifacts created shortly after credential access or login from an unusual location |