Ruler

S0358

Tool.View on attack.mitre.org

About this tool

Ruler is a tool to abuse Microsoft Exchange services. It is publicly available on GitHub and the tool is executed via the command line. The creators of Ruler have also released a defensive tool, NotRuler, to detect its usage.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1087.003
Email Account

Ruler can be used to enumerate Exchange users and dump the GAL.

T1137.003
Outlook Forms

Ruler can be used to automate the abuse of Outlook Forms to establish persistence.

T1137.004
Outlook Home Page

Ruler can be used to automate the abuse of Outlook Home Pages to establish persistence.

T1137.005
Outlook Rules

Ruler can be used to automate the abuse of Outlook Rules to establish persistence.

Groups that use it1

Campaigns0

None recorded.

References2

  1. SensePost NotRuler Open source
    SensePost. (2017, September 21). NotRuler - The opposite of Ruler, provides blue teams with the ability to detect Ruler usage against Exchange. Retrieved February 4, 2019.
  2. SensePost Ruler GitHub Open source
    SensePost. (2016, August 18). Ruler: A tool to abuse Exchange services. Retrieved February 4, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.