{"id":"T1137.005","name":"Outlook Rules","url":"https://attack.mitre.org/techniques/T1137/005","tactics":["persistence"],"platforms":["Windows","Office Suite"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0095","stix_id":"x-mitre-detection-strategy--83a814c2-73ac-4942-84ad-704a272cd864","name":"Detect Persistence via Malicious Outlook Rules","url":"https://attack.mitre.org/detectionstrategies/DET0095","analytics":[{"id":"AN0263","stix_id":"x-mitre-analytic--22cba5f6-b3d5-4a1a-9275-ed7db0bd4c7c","name":"Analytic 0263","description":"Adversary uses a tool like Ruler or MFCMapi to create a malicious Outlook rule that triggers execution upon receipt of a crafted email. On email delivery, Outlook executes the rule, resulting in code execution (e.g., launching mshta.exe or PowerShell). Outlook spawns a non-standard child process, often unsanctioned, without user interaction.","url":"https://attack.mitre.org/detectionstrategies/DET0095#AN0263","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Application","channel":"Outlook rule execution failure or abnormal rule execution context","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"wineventlog-application"},{"name":"WinEventLog:PowerShell","channel":"PowerShell launched from outlook.exe or triggered without user invocation","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"wineventlog-powershell"}],"mutable_elements":[{"field":"ChildProcessName","description":"Outlook may spawn mshta.exe, powershell.exe, or wscript.exe depending on attacker payload"},{"field":"RuleTriggerCondition","description":"Rule execution may depend on message subject, sender, or message header content"},{"field":"ParentProcessName","description":"Legitimate Outlook activity should not spawn scripting or interpreter processes"},{"field":"TimeWindow","description":"Execution may occur with delay after message receipt or folder interaction"}],"live":true,"detection_strategies":["DET0095"],"techniques":["T1137.005"]},{"id":"AN0264","stix_id":"x-mitre-analytic--8c0c52d0-7357-4073-84fc-d262632d268f","name":"Analytic 0264","description":"Adversary adds a new Outlook rule with modified or obfuscated PR_RULE_MSG_NAME and PR_RULE_MSG_PROVIDER attributes using MFCMapi or Ruler. Rule is triggered when email arrives, executing embedded or external code. Mailbox audit logs or Unified Audit Log shows automated rule-triggered action without user interaction.","url":"https://attack.mitre.org/detectionstrategies/DET0095#AN0264","platforms":["Office Suite"],"log_source_references":[{"name":"m365:unified","channel":"Creation or modification of inbox rule outside of normal user behavior","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-unified"},{"name":"m365:messagetrace","channel":"Inbound email matches crafted rule trigger pattern tied to persistence logic","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"m365-messagetrace"}],"mutable_elements":[{"field":"AuditPolicyScope","description":"Mailbox rule changes may not be captured unless advanced audit logging is enabled"},{"field":"RuleProviderName","description":"Malicious rules may use spoofed or non-standard PR_RULE_MSG_PROVIDER values"},{"field":"TriggerSubjectKeywords","description":"Triggering emails may contain uncommon but benign-looking subjects"},{"field":"UserContext","description":"Target user account may be inactive or high-value (e.g., VIP, service account)"}],"live":true,"detection_strategies":["DET0095"],"techniques":["T1137.005"]}],"live":true,"version":"1.0","techniques":["T1137.005"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}