This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Potential Persistence Via Outlook Today Page
Original Source:
[Sigma source]
Title:
Potential Persistence Via Outlook Today Page
Status:
test
Description:
Detects potential persistence activity via outlook today page. An attacker can set a custom page to execute arbitrary code and link to it via the registry values "URL" and "UserDefinedUrl".
References:
-https://speakerdeck.com/heirhabarov/hunting-for-persistence-via-microsoft-exchange-server-or-outlook?slide=74
-https://trustedsec.com/blog/specula-turning-outlook-into-a-c2-with-one-registry-change
Author:
Tobias Michalski (Nextron Systems), David Bertho (@dbertho) & Eirik Sveen (@0xSV1), Storebrand
Date:
2021-06-10
modified:
2024-08-07
Tags:
-'attack.persistence'
-'attack.defense-impairment'
-'attack.t1112'
Logsource:
product: windows
category: registry_set
Detection:
selection_main:
TargetObject|contains|all
:
-'Software\Microsoft\Office\'
-'\Outlook\Today\'
selection_value_stamp:
TargetObject|endswith
:
'\Stamp'
Details
:
'DWORD (0x00000001)'
selection_value_url:
TargetObject|endswith
:
-'\URL'
-'\UserDefinedUrl'
filter_main_office:
Image|startswith
:
-'C:\Program Files\Common Files\Microsoft Shared\ClickToRun\'
-'C:\Program Files\Common Files\Microsoft Shared\ClickToRun\Updates\'
Image|endswith
:
'\OfficeClickToRun.exe'
condition
:
selection_main and 1 of selection_value_* and not 1 of filter_main_*
Falsepositives:
-Unknown
Level:
high