Macro Enabled In A Potentially Suspicious Document

 Original Source: [Sigma source]
Title: Macro Enabled In A Potentially Suspicious Document
Status: test
Description:Detects registry changes to Office trust records where the path is located in a potentially suspicious location
References:
  -https://twitter.com/inversecos/status/1494174785621819397
  -Internal Research
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2023-06-21
modified:2023-08-17
Tags:
  • -'attack.persistence'
  • -'attack.defense-impairment'
  • -'attack.t1112'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection_value:
    TargetObject|contains: '\Security\Trusted Documents\TrustRecords'
  selection_paths:
    TargetObject|contains:
      -'/AppData/Local/Microsoft/Windows/INetCache/'
      -'/AppData/Local/Temp/'
      -'/PerfLogs/'
      -'C:/Users/Public/'
      -'file:///D:/'
      -'file:///E:/'

  condition:all of selection_*
Falsepositives:
  -Unlikely
Level: high