{"id":"T1221","name":"Template Injection","url":"https://attack.mitre.org/techniques/T1221","tactics":["stealth"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0566","stix_id":"x-mitre-detection-strategy--481a55d3-5f23-4428-9438-0220eab78678","name":"Template Injection Detection - Windows","url":"https://attack.mitre.org/detectionstrategies/DET0566","analytics":[{"id":"AN1564","stix_id":"x-mitre-analytic--dea5f6cc-d3bb-404b-8aab-f7366988a96e","name":"Analytic 1564","description":"Detection of Office or document viewer processes (e.g., winword.exe) initiating network connections to remote templates or executing scripts due to manipulated template references (e.g., embedded in .docx, .rtf, or .dotm files), followed by suspicious child process creation (e.g., PowerShell).","url":"https://attack.mitre.org/detectionstrategies/DET0566#AN1564","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TemplateURLPatterns","description":"Can be tuned to flag known bad domains or external resources in template fields."},{"field":"ParentProcess","description":"May be environment-specific; typically Word, Excel, PowerPoint."},{"field":"TimeWindow","description":"Correlation window for process + network activity."},{"field":"ChildProcessAnomalyThreshold","description":"Trigger when document-spawned child process deviates from expected profile."}],"live":true,"detection_strategies":["DET0566"],"techniques":["T1221"]}],"live":true,"version":"1.0","techniques":["T1221"]}],"sigma_rules":[{"id":"2d9403d5-7927-46b7-8216-37ab7c9ec5e3","title":"Suspicious Set Value of MSDT in Registry (CVE-2022-30190)","author":"Sittikorn S","status":"test","level":"medium","date":"2020-05-31","modified":"2023-08-17","description":"Detects set value ms-msdt MSProtocol URI scheme in Registry that could be an attempt to exploit CVE-2022-30190.","references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30190","https://msrc-blog.microsoft.com/2022/05/30/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.stealth","attack.t1221","detection.emerging-threats"],"path":"rules-emerging-threats/2022/Exploits/CVE-2022-30190/registry_set_exploit_cve_2022_30190_msdt_follina.yml","techniques":["T1221"],"cves":[]},{"id":"ada3bc4f-f0fd-42b9-ba91-e105e8af7342","title":"Server Side Template Injection Strings","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-06-14","modified":null,"description":"Detects SSTI attempts sent via GET requests in access logs","references":["https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection","https://github.com/payloadbox/ssti-payloads"],"logsource":{"category":"webserver"},"tags":["attack.stealth","attack.t1221"],"path":"rules/web/webserver_generic/web_ssti_in_access_logs.yml","techniques":["T1221"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2024-23692","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2023-22527","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2022-22954","state":"mapped","mapping_types":["exploitation_technique"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}