Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0177 — Detect Persistence via Outlook Home Page Exploitation
DET0177

Detect Persistence via Outlook Home Page Exploitation

2 analytic(s) · 1 technique(s) detected

Analytics

2
AN0502 Analytic 0502
Windows

Adversary uses a tool like Ruler to configure a malicious Outlook folder Home Page that loads a remote or embedded HTML payload upon folder interaction. Execution chain begins with Outlook launching, a specific folder being accessed, and a suspicious child process being spawned or COM-based execution invoked.

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=7 WinEventLog:Application Outlook logs indicating failure to load or render HTML page in Home Page view WinEventLog:PowerShell Execution of PowerShell script to enumerate or remove malicious Home Page folder config
[TargetFolder] Home Page can be configured on any folder like Calendar, Inbox, or custom folders
[HTMLPayloadLocation] The Home Page URL may point to internal or external content, hosted on trusted or unknown domains
[ChildProcessName] Execution may result in launch of scripting hosts (e.g., mshta.exe, wscript.exe) from outlook.exe
[TimeWindow] Execution may occur only when the specific folder is accessed after launch, not immediately at startup
[FormViewBehavior] Behavior may vary if the folder's form view is customized or suppressed via GPO
AN0503 Analytic 0503
Office Suite

Malicious HTML or script is rendered as a Home Page for a specific Outlook folder. Outlook accesses that folder, loads remote content, and executes embedded JavaScript or ActiveX/COM logic resulting in unauthorized actions or local execution.

m365:unified Folder configuration updated with external or HTML-formatted Home Page via Set-MailboxFolder m365:messagetrace Inbound email triggering Outlook to auto-access folder tied to malicious Home Page
[AuditPolicyScope] Home Page customization may not be audited unless detailed message or folder auditing is enabled
[FolderAccessRate] Anomalous access to folders not usually interacted with can signal triggering of malicious view
[ExternalURLAllowlist] Mail clients may restrict remote Home Page content unless domain is explicitly allowed

Detected Techniques

1

Details

MITRE ID
DET0177
STIX ID
x-mitre-detection-strategy--e55f4e4b-80c0-4a2b-8202-659d29bbba33
Analytics
2
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.