Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0095 — Detect Persistence via Malicious Outlook Rules
DET0095

Detect Persistence via Malicious Outlook Rules

2 analytic(s) · 1 technique(s) detected

Analytics

2
AN0263 Analytic 0263
Windows

Adversary uses a tool like Ruler or MFCMapi to create a malicious Outlook rule that triggers execution upon receipt of a crafted email. On email delivery, Outlook executes the rule, resulting in code execution (e.g., launching mshta.exe or PowerShell). Outlook spawns a non-standard child process, often unsanctioned, without user interaction.

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=7 WinEventLog:Application Outlook rule execution failure or abnormal rule execution context WinEventLog:PowerShell PowerShell launched from outlook.exe or triggered without user invocation
[ChildProcessName] Outlook may spawn mshta.exe, powershell.exe, or wscript.exe depending on attacker payload
[RuleTriggerCondition] Rule execution may depend on message subject, sender, or message header content
[ParentProcessName] Legitimate Outlook activity should not spawn scripting or interpreter processes
[TimeWindow] Execution may occur with delay after message receipt or folder interaction
AN0264 Analytic 0264
Office Suite

Adversary adds a new Outlook rule with modified or obfuscated PR_RULE_MSG_NAME and PR_RULE_MSG_PROVIDER attributes using MFCMapi or Ruler. Rule is triggered when email arrives, executing embedded or external code. Mailbox audit logs or Unified Audit Log shows automated rule-triggered action without user interaction.

m365:unified Creation or modification of inbox rule outside of normal user behavior m365:messagetrace Inbound email matches crafted rule trigger pattern tied to persistence logic
[AuditPolicyScope] Mailbox rule changes may not be captured unless advanced audit logging is enabled
[RuleProviderName] Malicious rules may use spoofed or non-standard PR_RULE_MSG_PROVIDER values
[TriggerSubjectKeywords] Triggering emails may contain uncommon but benign-looking subjects
[UserContext] Target user account may be inactive or high-value (e.g., VIP, service account)

Detected Techniques

1

Details

MITRE ID
DET0095
STIX ID
x-mitre-detection-strategy--83a814c2-73ac-4942-84ad-704a272cd864
Analytics
2
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.