Potential Persistence Via Outlook Form

 Original Source: [Sigma source]
Title: Potential Persistence Via Outlook Form
Status: test
Description:Detects the creation of a new Outlook form which can contain malicious code
References:
  -https://speakerdeck.com/heirhabarov/hunting-for-persistence-via-microsoft-exchange-server-or-outlook?slide=76
  -https://speakerdeck.com/heirhabarov/hunting-for-persistence-via-microsoft-exchange-server-or-outlook?slide=79
  -https://learn.microsoft.com/en-us/office/vba/outlook/concepts/outlook-forms/create-an-outlook-form
  -https://www.slipstick.com/developer/custom-form/clean-outlooks-forms-cache/
Author: Tobias Michalski (Nextron Systems)
Date: 2021-06-10
modified:2023-02-22
Tags:
  • -'attack.persistence'
  • -'attack.t1137.003'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection:
    Image|endswith: '\outlook.exe'
    TargetFilename|contains:
      -'\AppData\Local\Microsoft\FORMS\IPM'
      -'\Local Settings\Application Data\Microsoft\Forms'

  condition:selection
Falsepositives:
  -Legitimate use of outlook forms
Level: high