Potential Persistence Via Outlook Home Page

 Original Source: [Sigma source]
Title: Potential Persistence Via Outlook Home Page
Status: test
Description:Detects potential persistence activity via outlook home page. An attacker can set a home page to achieve code execution and persistence by editing the WebView registry keys.
References:
  -https://speakerdeck.com/heirhabarov/hunting-for-persistence-via-microsoft-exchange-server-or-outlook?slide=70
  -https://support.microsoft.com/en-us/topic/outlook-home-page-feature-is-missing-in-folder-properties-d207edb7-aa02-46c5-b608-5d9dbed9bd04?ui=en-us&rs=en-us&ad=us
  -https://trustedsec.com/blog/specula-turning-outlook-into-a-c2-with-one-registry-change
Author: Tobias Michalski (Nextron Systems), David Bertho (@dbertho) & Eirik Sveen (@0xSV1), Storebrand
Date: 2021-06-09
modified:2024-08-07
Tags:
  • -'attack.persistence'
  • -'attack.defense-impairment'
  • -'attack.t1112'
Logsource:
  • product: windows
  • category: registry_set
Detection:
  selection:
    TargetObject|contains|all:
      -'\Software\Microsoft\Office\'
      -'\Outlook\WebView\'

    TargetObject|endswith: '\URL'
  condition:selection
Falsepositives:
  -Unknown
Level: high