LoFP LoFP / very common in environments that rely heavily on macro documents

Techniques

Sample rules

Office Macro File Creation

Description

Detects the creation of a new office macro files on the systems

Detection logic

condition: selection
selection:
  TargetFilename|endswith:
  - .docm
  - .dotm
  - .xlsm
  - .xltm
  - .potm
  - .pptm