AN0130
Analytic 0130
Windows
Detection focuses on processes that attempt to locate, access, or exfiltrate local Outlook data files (.pst/.ost) using file system access, native Windows utilities (e.g., PowerShell, WMI), or remote access tools with file browsing capabilities. The behavior chain includes directory enumeration, file access, optional compression or staging, and network transfer.
WinEventLog:Security
EventCode=4663, 4670, 4656
WinEventLog:Sysmon
EventCode=1
WinEventLog:Sysmon
EventCode=11
WinEventLog:Sysmon
EventCode=3, 22
[TargetFilePathPattern]
Regex or wildcard patterns for sensitive Outlook file paths (.ost/.pst) depending on organizational deployment.
[TimeWindow]
Timeframe used to correlate related file access, process creation, and exfiltration events.
[UserContext]
Limit detection to user accounts not normally interacting with Outlook file locations (e.g., service accounts, low-privileged users).
[ProcessAllowList]
Filter known legitimate Outlook-accessing processes to reduce false positives.