Outlook Forms

T1137.003

Sub-technique of T1137 Office Application Startup.View on attack.mitre.org

About this technique

Adversaries may abuse Microsoft Outlook forms to obtain persistence on a compromised system. Outlook forms are used as templates for presentation and functionality in Outlook messages. Custom Outlook forms can be created that will execute code when a specifically crafted email is sent by an adversary utilizing the same custom Outlook form.

Once malicious forms have been added to the user’s mailbox, they will be loaded when Outlook is started. Malicious forms will execute when an adversary sends a specifically crafted email to the user.

Detection rules1

Rules on DetectionCode tagged with T1137.003.

Sigma1

RuleLevelLog source
Potential Persistence Via Outlook Formhighwindows / file_event

Splunk0

No Splunk rules are mapped to this technique yet.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples1

Software1

Used byProcedure example
ToolRuler

Ruler can be used to automate the abuse of Outlook Forms to establish persistence.

References1

  1. SensePost Outlook Forms Open source
    Stalmans, E. (2017, April 28). Outlook Forms and Shells. Retrieved February 4, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.