Outlook EnableUnsafeClientMailRules Setting Enabled

 Original Source: [Sigma source]
Title: Outlook EnableUnsafeClientMailRules Setting Enabled
Status: test
Description:Detects an attacker trying to enable the outlook security setting "EnableUnsafeClientMailRules" which allows outlook to run applications or execute macros
References:
  -https://www.fireeye.com/blog/threat-research/2018/12/overruled-containing-a-potentially-destructive-adversary.html
  -https://speakerdeck.com/heirhabarov/hunting-for-persistence-via-microsoft-exchange-server-or-outlook?slide=44
  -https://support.microsoft.com/en-us/topic/how-to-control-the-rule-actions-to-start-an-application-or-run-a-macro-in-outlook-2016-and-outlook-2013-e4964b72-173c-959d-5d7b-ead562979048
Author: Markus Neis, Nasreddine Bencherchali (Nextron Systems)
Date: 2018-12-27
modified:2023-02-09
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1059'
  • -'attack.t1202'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|contains: '\Outlook\Security\EnableUnsafeClientMailRules'
  condition:selection
Falsepositives:
  -Unknown
Level: high