Rules: Outlook Form Creation
Detects Outlook Form creation. Outlook forms can be used to execute code on a compromised machine and establish persistence.
Detail | Value |
---|---|
Type | Templated Match |
Category | Persistence |
Apply Risk to Entities | device_hostname |
Signal Name | Outlook Form Creation |
Summary Expression | Observed Outlook Form creation on host: {{device_hostname}} |
Score/Severity | Static: 1 |
Enabled by Default | True |
Prototype | True |
Tags | _mitreAttackTactic:TA0003, _mitreAttackTechnique:T1137, _mitreAttackTechnique:T1137.003 |
Origin | Field |
---|---|
Normalized Schema | baseImage |
Normalized Schema | changeTarget |
Normalized Schema | device_hostname |