Suspicious Microsoft Office template
Detects when attackers drop macro-enabled files in specific folders to trigger their execution every time the victim user opens an Office application.
- Platform: Windows
- Severity: High
- MITRE Tactic: Persistence
- MITRE Techniques: T1137, T1137.001