Skip to content

Latest commit

 

History

History
29 lines (22 loc) · 905 Bytes

MATCH-S00756.md

File metadata and controls

29 lines (22 loc) · 905 Bytes

Rules: Outlook Homepage Modification

Description

Detects modifications to the Microsoft Outlook Homepage. Outlook Homepage is a legacy feature that can be leveraged by an adversary to insert malicious code and establish persistence.

Additional Details

Detail Value
Type Templated Match
Category Persistence
Apply Risk to Entities device_hostname
Signal Name Outlook Homepage Modification
Summary Expression Outlook Homepage Modification detected on host: {{device_hostname}}
Score/Severity Static: 3
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0003, _mitreAttackTechnique:T1137, _mitreAttackTechnique:T1137.004

Vendors and Products

Fields Used

Origin Field
Normalized Schema changeTarget
Normalized Schema device_hostname