Compliance Node Overview
MITRE ATT&CK T1137.001 (Office Template Macros) is an Enterprise Persistence sub-technique of T1137 (Office Application Startup). Adversaries may abuse Microsoft Office templates to obtain persistence on a compromised system. Microsoft Office contains templates that are part of common Office applications and are used to customize styles. The base templates within the application are used each time an application starts. Office Visual Basic for Applications (VBA) macros can be inserted into the base template and used to execute code when the respective Office application starts in order to obtain persistence. Affected platforms: Windows, Office Suite. MITRE-documented mitigations include M1040 Behavior Prevention on Endpoint, M1042 Disable or Remove Feature or Program. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-06, AC-10, AC-17, CM-02, CM-06, CM-08, RA-05, SC-18.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1137/001/
SHA-256 integrity: f94397c546d7156ac96884159f5b9c51a7aadcac991be8e9924a8fda69fac776
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1137.001: Office Template Macros (https://attack.mitre.org/techniques/T1137/001/)
- MITRE ATT&CK Tactic TA0003: Persistence (https://attack.mitre.org/tactics/TA0003/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.