Adversary uses a tool like Ruler to insert a malicious custom form into the user's Outlook mailbox. The form is designed to auto-execute on Outlook startup or on receipt of a specially crafted email. This results in child processes launched from outlook.exe and possibly network connections or payload loading.
WinEventLog:Sysmon
EventCode=1
WinEventLog:Sysmon
EventCode=7
WinEventLog:Application
Outlook errors loading or processing custom form templates
WinEventLog:PowerShell
Execution of Microsoft script to enumerate custom forms in Outlook mailbox
[FormStorageLocation]
Malicious forms may be stored in various user-specific locations in the Outlook mailbox (e.g., IPM.Note class)
[ChildProcessName]
Child process spawned by outlook.exe may vary (e.g., powershell.exe, rundll32.exe, mshta.exe)
[TimeWindow]
Form-triggered execution may happen immediately upon Outlook startup or with delay after crafted message arrival
[OutlookVersion]
Form behavior and error logs may vary across Outlook 2013, 2016, and M365 builds
[UserContext]
Attack may target only specific users; contextual correlation needed for account baselining