Compliance Node Overview
MITRE ATT&CK T1137.006 (Add-ins) is an Enterprise Persistence sub-technique of T1137 (Office Application Startup). Adversaries may abuse Microsoft Office add-ins to obtain persistence on a compromised system. Office add-ins can be used to add functionality to Office programs. There are different types of add-ins that can be used by the various Office products; including Word/Excel add-in Libraries (WLL/XLL), VBA add-ins, Office Component Object Model (COM) add-ins, automation add-ins, VBA Editor (VBE), Visual Studio Tools for Office (VSTO) add-ins, and Outlook add-ins. Affected platforms: Windows, Office Suite. MITRE-documented mitigations include M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-06, AC-10, AC-17, CM-02, CM-06, CM-08, RA-05, SC-18.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1137/006/
SHA-256 integrity: 360b6b5d1e4d91410e4871b4d916b7219f8b626b1aed3b44559e08b160bd79bb
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1137.006: Add-ins (https://attack.mitre.org/techniques/T1137/006/)
- MITRE ATT&CK Tactic TA0003: Persistence (https://attack.mitre.org/tactics/TA0003/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access