kevmap

TechniquesT1137.004 › AN0503

AN0503 Analytic 0503

Office Suite · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Malicious HTML or script is rendered as a Home Page for a specific Outlook folder. Outlook accesses that folder, loads remote content, and executes embedded JavaScript or ActiveX/COM logic resulting in unauthorized actions or local execution.</p>
Detects
T1137.004 Outlook Home Page
Part of
DET0177 Detect Persistence via Outlook Home Page Exploitation

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
m365:unifiedFolder configuration updated with external or HTML-formatted Home Page via Set-MailboxFolderDC0038 Application Log Content
m365:messagetraceInbound email triggering Outlook to auto-access folder tied to malicious Home PageDC0064 Command Execution

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
AuditPolicyScopeHome Page customization may not be audited unless detailed message or folder auditing is enabled
FolderAccessRateAnomalous access to folders not usually interacted with can signal triggering of malicious view
ExternalURLAllowlistMail clients may restrict remote Home Page content unless domain is explicitly allowed