Outlook Rules

T1137.005

Sub-technique of T1137 Office Application Startup.View on attack.mitre.org

About this technique

Adversaries may abuse Microsoft Outlook rules to obtain persistence on a compromised system. Outlook rules allow a user to define automated behavior to manage email messages. A benign rule might, for example, automatically move an email to a particular folder in Outlook if it contains specific words from a specific sender. Malicious Outlook rules can be created that can trigger code execution when an adversary sends a specifically crafted email to that user.

Once malicious rules have been added to the user’s mailbox, they will be loaded when Outlook is started. Malicious rules will execute when an adversary sends a specifically crafted email to the user.

Detection rules0

Rules on DetectionCode tagged with T1137.005.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples1

Software1

Used byProcedure example
ToolRuler

Ruler can be used to automate the abuse of Outlook Rules to establish persistence.

References1

  1. SilentBreak Outlook Rules Open source
    Landers, N. (2015, December 4). Malicious Outlook Rules. Retrieved February 4, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.