Office Application Startup: Outlook Rules T1137.005
Tactic: Persistence
Adversaries may abuse Microsoft Outlook rules to obtain persistence on a compromised system. Outlook rules allow a user to define automated behavior to manage email messages. A benign rule might, for example, automatically move an email to a particular folder in Outlook if it contains specific words from a specific sender. Malicious Outlook rules can be created that can trigger code execution when an adversary sends a specifically crafted email to that user.
Authoring guide
These 3 rules share fields, values, and exclusions.
Fields filtered most (12 distinct)
These fields appear most often in rule filters.
Top indicator values (30 distinct)
These values appear most often in rule predicates.
Rules under this technique
These vendors publish rules tagged with this technique.
Platform: Microsoft 365