Potential Persistence Via Outlook Today Page

 Original Source: [Sigma source]
Title: Potential Persistence Via Outlook Today Page
Status: test
Description:Detects potential persistence activity via outlook today page. An attacker can set a custom page to execute arbitrary code and link to it via the registry values "URL" and "UserDefinedUrl".
References:
  -https://speakerdeck.com/heirhabarov/hunting-for-persistence-via-microsoft-exchange-server-or-outlook?slide=74
  -https://trustedsec.com/blog/specula-turning-outlook-into-a-c2-with-one-registry-change
Author: Tobias Michalski (Nextron Systems), David Bertho (@dbertho) & Eirik Sveen (@0xSV1), Storebrand
Date: 2021-06-10
modified:2024-08-07
Tags:
  • -'attack.persistence'
  • -'attack.defense-impairment'
  • -'attack.t1112'
Logsource:
  • product: windows
  • category: registry_set
Detection:
  selection_main:
    TargetObject|contains|all:
      -'Software\Microsoft\Office\'
      -'\Outlook\Today\'

  selection_value_stamp:
    TargetObject|endswith: '\Stamp'
    Details: 'DWORD (0x00000001)'
  selection_value_url:
    TargetObject|endswith:
      -'\URL'
      -'\UserDefinedUrl'

  filter_main_office:
    Image|startswith:
      -'C:\Program Files\Common Files\Microsoft Shared\ClickToRun\'
      -'C:\Program Files\Common Files\Microsoft Shared\ClickToRun\Updates\'

    Image|endswith: '\OfficeClickToRun.exe'
  condition:selection_main and 1 of selection_value_* and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: high