Adversaries may abuse the Microsoft Office "Office Test" Registry key to obtain persistence on a compromised system. An Office Test Registry location exists that allows a user to specify an arbitrary DLL that will be executed every time an Office application is started. This Registry key is thought to be used by Microsoft to load DLLs for testing and debugging purposes while developing Office applications. This Registry key is not created by default during an Office installation.(Citation: Hexacorn Office Test)(Citation: Palo Alto Office Test Sofacy) There exist user and global Registry keys for the Office Test feature, such as: * HKEY_CURRENT_USER\Software\Microsoft\Office test\Special\Perf * HKEY_LOCAL_MACHINE\Software\Microsoft\Office test\Special\Perf Adversaries may add this Registry key and specify a malicious DLL that will be executed whenever an Office application, such as Word or Excel, is started.

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is blocked by Software Configuration
is blocked by Detect Persistence via Office Test Registry DLL Injection
is blocked by Behavior Prevention on Endpoint
is blocked by Access Restriction For Change
is blocked by Secure Baseline Configurations
is blocked by Phishing & Spam Protection
is blocked by Mobile Code
is blocked by Least Privilege
is blocked by Concurrent Session Control
is blocked by Permitted Actions Without Identification or Authorization
is blocked by Detonation Chambers (Sandboxes)
is blocked by Remote Access
Impressum Deutsch Englisch