Execution
T1203 office_exploit_crash: Microsoft Office process crashes (failed exploitation of a vulnerability is possible)
T1204.002 office_com_load: Microsoft Office loads COM DLL files (indicator of COM usage in macros)
Defense Evasion
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
Discovery
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
Other
yara_rules: Static rules
unexpected_exception: Unexpected exception
test_check_service: Starts services