FORENSIA

ATT&CK · T1137.002 · sub-technique

Office Test

Tactics: persistence

About

Adversaries may abuse the Microsoft Office "Office Test" Registry key to obtain persistence on a compromised system. An Office Test Registry location exists that allows a user to specify an arbitrary DLL that will be executed every time an Office application is started. This Registry key is thought to be used by Microsoft to load DLLs for testing and debugging purposes while developing Office applications. This Registry key is not created by default during an Office installation. There exist user and global Registry keys for the Office Test feature, such as: * <code>HKEY_CURRENT_USER\Software\Microsoft\Office test\Special\Perf</code> * <code>HKEY_LOCAL_MACHINE\Software\Microsoft\Office test\Special\Perf</code> Adversaries may add this Registry key and specify a malicious DLL that will be executed whenever an Office application, such as Word or Excel, is started.

Platforms: Windows, Office SuiteParent: T1137 Office Application StartupMITRE ATT&CK ↗

Used by actors

1 known groups

Software

0 malware/tools implement this

None mapped.

Corpus indicators tagged with this technique

0 indicators in the corpus carry T1137.002.

No corpus indicators are tagged with this technique yet.