// MITRE ATT&CK
T1137.005 · Outlook Rules
Sub-technique of T1137 · Office Application Startup.
Adversaries may abuse Microsoft Outlook rules to obtain persistence on a compromised system. Outlook rules allow a user to define automated behavior to manage email messages. A benign rule might, for example, automatically move an email to a particular folder in Outlook if it contains specific words...
How to detect & mitigate it
Detecting Outlook Rules starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Related techniques
T1037
Boot or Logon Initialization Scripts T1543
Create or Modify System Process T1133
External Remote Services T1547
Boot or Logon Autostart Execution T1547.014
Active Setup T1176.001
Browser Extensions T1543.003
Windows Service T1137
Office Application Startup
Boot or Logon Initialization Scripts T1543
Create or Modify System Process T1133
External Remote Services T1547
Boot or Logon Autostart Execution T1547.014
Active Setup T1176.001
Browser Extensions T1543.003
Windows Service T1137
Office Application Startup
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.