Potential Persistence Via Outlook LoadMacroProviderOnBoot Setting

 Original Source: [Sigma source]
Title: Potential Persistence Via Outlook LoadMacroProviderOnBoot Setting
Status: test
Description:Detects the modification of Outlook setting "LoadMacroProviderOnBoot" which if enabled allows the automatic loading of any configured VBA project/module
References:
  -https://speakerdeck.com/heirhabarov/hunting-for-persistence-via-microsoft-exchange-server-or-outlook?slide=53
  -https://www.linkedin.com/pulse/outlook-backdoor-using-vba-samir-b-/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2021-04-05
modified:2023-08-17
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.command-and-control'
  • -'attack.t1137'
  • -'attack.t1008'
  • -'attack.t1546'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection:
    TargetObject|endswith: '\Outlook\LoadMacroProviderOnBoot'
    Details|contains: '0x00000001'
  condition:selection
Falsepositives:
  -Unknown
Level: high