Microsoft Word Add-In Loaded — Detection Rule

Detects Microsoft Word loading an Add-In (.wll) file which can be used by threat actors for initial access or persistence.

Read the full analysis on IntelFusions