Suspicious Microsoft Office template

Detects when attackers drop macro-enabled files in specific folders to trigger their execution every time the victim user opens an Office application.

Back to all rules