T1137.006 - Add-ins
Sub-technique
Tattiche:
Persistence
Persistence
Piattaforme:
Windows Office Suite
Windows Office Suite
Rilevamento:
Not specified
Not specified
Description:
Adversaries may abuse Microsoft Office add-ins to obtain persistence on a compromised system. Office add-ins can be used to add functionality to Office programs. (Citation: Microsoft Office Add-ins) There are different types of add-ins that can be used by the various Office products; including Word/Excel add-in Libraries (WLL/XLL), VBA add-ins, Office Component Object Model (COM) add-ins, automation add-ins, VBA Editor (VBE), Visual Studio Tools for Office (VSTO) add-ins, and Outlook add-ins. (Citation: MRWLabs Office Persistence Add-ins)(Citation: FireEye Mail CDS 2018)
Add-ins can be used to obtain persistence because they can be set to execute code when an Office application starts.
Add-ins can be used to obtain persistence because they can be set to execute code when an Office application starts.
Usato da Attori (1)
Malware (3)
Metadata
| MITRE ID: | T1137.006 |
| STIX ID: | attack-pattern--34f1d81d-fe88-... |
| Piattaforme: | Windows, Office Suite |
| Created: | 13/01/2026 17:48 |
| Updated: | 06/03/2026 04:00 |