{"id":"T1559.002","name":"Dynamic Data Exchange","url":"https://attack.mitre.org/techniques/T1559/002","tactics":["execution"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0504","stix_id":"x-mitre-detection-strategy--3f3ebc58-fff0-4083-bc5c-ee7308026a20","name":"Detect Abuse of Dynamic Data Exchange (T1559.002)","url":"https://attack.mitre.org/detectionstrategies/DET0504","analytics":[{"id":"AN1393","stix_id":"x-mitre-analytic--d9383849-c91c-4eef-88a0-97c2454ca1af","name":"Analytic 1393","description":"Detects anomalous use of Dynamic Data Exchange (DDE) for code execution, such as Office applications (WINWORD.EXE, EXCEL.EXE) spawning command interpreters, or loading unusual modules through DDEAUTO/DDE formulas. Correlates suspicious parent-child process relationships, registry keys enabling DDE, and module loads inconsistent with normal Office usage.","url":"https://attack.mitre.org/detectionstrategies/DET0504#AN1393","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=4663, 4670, 4656","data_component":"DC0050","data_component_name":"Windows Registry Key Access","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"AllowedParentChildPairs","description":"Define legitimate parent-child relationships for Office processes to reduce false positives."},{"field":"TimeWindow","description":"Threshold for correlating Office process creation with subsequent command execution via DDE."},{"field":"SuspiciousDLLList","description":"Maintain allow/block list of DLLs that Office is expected to load."}],"live":true,"detection_strategies":["DET0504"],"techniques":["T1559.002"]}],"live":true,"version":"1.0","techniques":["T1559.002"]}],"sigma_rules":[{"id":"63647769-326d-4dde-a419-b925cc0caf42","title":"Enable Microsoft Dynamic Data Exchange","author":"frack113","status":"test","level":"medium","date":"2022-02-26","modified":"2023-08-17","description":"Enable Dynamic Data Exchange protocol (DDE) in all supported editions of Microsoft Word or Excel.","references":["https://msrc.microsoft.com/update-guide/vulnerability/ADV170021"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.execution","attack.t1559.002"],"path":"rules/windows/registry/registry_set/registry_set_office_enable_dde.yml","techniques":["T1559.002"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}