
Summary
The rule titled 'Trust Access Disable For VBApplications' is designed to detect changes made to the Windows registry that disable trust access for Visual Basic for Applications (VBA) in Microsoft Office applications. Specifically, it monitors the registry key for 'AccessVBOM' located at '\Security\AccessVBOM'. When this key is set to a value of '1' (DWORD 0x00000001), it allows macros to run without the usual security warnings, thereby enabling attackers to deploy malicious macros unnoticed. The detection relies on changes to the registry which can indicate a security breach, particularly in cases involving macro-based malware. By detecting this registry modification, organizations can mitigate risks associated with running untrusted VBA macros, particularly those that could lead to data breaches or system compromises. The rule is presently in 'test' status, indicative of an ongoing evaluation phase, and is categorized under high severity, emphasizing the potential risk posed by such attacks.
Categories
- Windows
- Endpoint
- Infrastructure
Data Sources
- Windows Registry
Created: 2020-05-22