Bugging Microsoft Files: Part 1 – Docx Files using Microsoft Word
ID: f5957478-cf45-521f-8bc6-20e3f245f8ff
STIX ID: report--f5957478-cf45-521f-8bc6-20e3f245f8ff
Feed Name: Black Hills Infosec Blog
This post details a technique to create "honey-docs" using native .docx files by inserting an IncludePicture field that points to a remote image URL (with 'Data not stored with document' enabled) so the document will request the image each time it is opened, enabling tracking of file openings. The guide provides step-by-step instructions for Word 2013, advises placing the tracker in the header/footer and resizing the image to be unobtrusive, and notes follow-up posts on weaponizing .xlsx files and removing Office metadata.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
