Microsoft Office adds a value to autostart Registry key
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (T1547.001)
Severity
Low
Description
Microsoft Office adds a value to a registry entry (run keys, startup folders) to establish persistence.
Attacker's Goals
Gain persistence on the host using the Window's autostart Mechanism.
Investigative actions
Check the registry key and determine what process it'll run.
Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.
PreviousMicrosoft Configuration Manager device registration and policy request
NextMicrosoft Office injects code into a process
Was this helpful?
