{
  "node_id": "mitre-attack-t1221-template-injection",
  "title": "MITRE ATT&CK T1221: Template Injection (Enterprise Tactic TA0005 - Defense Evasion)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE ATT&CK T1221 (Template Injection) is an Enterprise Defense Evasion technique. Adversaries may create or modify references in user document templates to conceal malicious code or force authentication attempts. For example, Microsoft's Office Open XML (OOXML) specification defines an XML-based format for Office documents (.docx, xlsx, .pptx) to replace older binary formats (.doc, .xls, .ppt). OOXML files are packed together ZIP archives compromised of various XML files, referred to as parts, containing properties that collectively define how a document is rendered. Affected platforms: Windows. MITRE-documented mitigations include M1049 Antivirus/Antimalware, M1031 Network Intrusion Prevention, M1017 User Training, M1042 Disable or Remove Feature or Program. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CA-07, CM-02, CM-06, CM-07, CM-08, RA-05, SC-07, SC-44.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_d3fend"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-cybersecurity-framework-2-0",
    "iso-27001-2022",
    "nist-sp-800-53-r5",
    "cis-controls-v8",
    "mitre-attack-framework-v14"
  ],
  "primary_citations_count": 7
}