LoFP LoFP / this will alert on legitimate macro usage as well, additional tuning is required

Techniques

Sample rules

Windows Registry Trust Record Modification

Description

Alerts on trust record modification within the registry, indicating usage of macros

Detection logic

condition: selection
selection:
  TargetObject|contains: \Security\Trusted Documents\TrustRecords