{"id":"T1137.001","name":"Office Template Macros","url":"https://attack.mitre.org/techniques/T1137/001","tactics":["persistence"],"platforms":["Office Suite","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0519","stix_id":"x-mitre-detection-strategy--e04f7ddf-6a1e-4731-afd6-5edb74f4c624","name":"Detect Persistence via Office Template Macro Injection or Registry Hijack","url":"https://attack.mitre.org/detectionstrategies/DET0519","analytics":[{"id":"AN1436","stix_id":"x-mitre-analytic--85b4c967-56bc-4990-b3e2-7e40f3ef1852","name":"Analytic 1436","description":"Adversaries inject VBA macros into Office templates such as Normal.dotm or Personal.xlsb or redirect Office template load path via registry key (GlobalDotName) to gain persistence. Template macros trigger execution of malicious code on application startup.","url":"https://attack.mitre.org/detectionstrategies/DET0519#AN1436","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=15","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=13, 14","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Microsoft-Office-Alerts","channel":"Office application warning or alert on macro execution from template","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"wineventlog-microsoft-office-alerts"}],"mutable_elements":[{"field":"TemplatePath","description":"Path to Normal.dotm, Personal.xlsb, or Excel/Word startup templates may vary by Office version and user"},{"field":"RegistryPath","description":"GlobalDotName or equivalent registry keys may differ across Office versions or deployments"},{"field":"TimeWindow","description":"Office process creation and macro execution timing after system or user login"},{"field":"UserContext","description":"May be scoped to high-value users or those with access to sensitive templates"}],"live":true,"detection_strategies":["DET0519"],"techniques":["T1137.001"]},{"id":"AN1437","stix_id":"x-mitre-analytic--17bc7c97-7322-4619-84c5-50e45aa6627d","name":"Analytic 1437","description":"Malicious VBA macros embedded in base templates like Normal.dotm or Personal.xlsb are automatically loaded and executed at startup. Template path may be hijacked to load a remote or attacker-controlled template via GlobalDotName registry setting.","url":"https://attack.mitre.org/detectionstrategies/DET0519#AN1437","platforms":["Office Suite"],"log_source_references":[{"name":"m365:unified","channel":"Set-Mailbox, Set-MailboxPolicy, Set-TrustedLocation","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"m365-unified"}],"mutable_elements":[{"field":"TemplateSource","description":"Macros may be embedded in local user templates or retrieved from shared network paths"},{"field":"MacroSecurityLevel","description":"Macro execution policy (disabled, warn, enabled) varies by tenant or user configuration"}],"live":true,"detection_strategies":["DET0519"],"techniques":["T1137.001"]}],"live":true,"version":"1.0","techniques":["T1137.001"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}