Detection rules › Sigma

Potential Persistence Via Outlook LoadMacroProviderOnBoot Setting

Severity
high
Author
Nasreddine Bencherchali (Nextron Systems)
Source
upstream

Detects the modification of Outlook setting "LoadMacroProviderOnBoot" which if enabled allows the automatic loading of any configured VBA project/module

MITRE ATT&CK coverage

TacticTechniques
PersistenceT1137 Office Application Startup, T1546 Event Triggered Execution
Privilege EscalationT1546 Event Triggered Execution
Command & ControlT1008 Fallback Channels

Event coverage

ProviderEvent IDTitle
Sysmon13RegistryEvent (Value Set)

Stages and Predicates

Stage 1: selection

Details|contains: 0x00000001
TargetObject|endswith: '\Outlook\LoadMacroProviderOnBoot'

Indicators

Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.

FieldKindValues
Detailsmatch
  • 0x00000001 corpus 2 (sigma 2)
TargetObjectends_with
  • \Outlook\LoadMacroProviderOnBoot