kevmap

TechniquesT1221 › AN1564

AN1564 Analytic 1564

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detection of Office or document viewer processes (e.g., winword.exe) initiating network connections to remote templates or executing scripts due to manipulated template references (e.g., embedded in .docx, .rtf, or .dotm files), followed by suspicious child process creation (e.g., PowerShell).</p>
Detects
T1221 Template Injection
Part of
DET0566 Template Injection Detection - Windows

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SysmonEventCode=1DC0032 Process Creation
WinEventLog:SysmonEventCode=3, 22DC0082 Network Connection Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
TemplateURLPatternsCan be tuned to flag known bad domains or external resources in template fields.
ParentProcessMay be environment-specific; typically Word, Excel, PowerPoint.
TimeWindowCorrelation window for process + network activity.
ChildProcessAnomalyThresholdTrigger when document-spawned child process deviates from expected profile.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2022-22954VMware Workspace ONE Access and Identity ManagerMapped
CVE-2023-22527Atlassian Confluence Data Center and ServerMapped
CVE-2024-23692Rejetto HTTP File ServerMapped