216.73.216.226

T1137.005: Outlook Rules

View on MITRE ATT&CK The MITRE Corporation · Published 07/11/2019 21:00 · Modified 27/03/2026 01:09

Essential information

MITRE technique ID
T1137.005
Confidence
100/100
Revoked
No
Published
07/11/2019 21:00
Modified
27/03/2026 01:09
Author / Source
The MITRE Corporation

Aliases

T1137.005

Platforms

windows Office Suite

Description

Adversaries may abuse Microsoft Outlook rules to obtain persistence on a compromised system. Outlook rules allow a user to define automated behavior to manage email messages. A benign rule might, for example, automatically move an email to a particular folder in Outlook if it contains specific words from a specific sender. Malicious Outlook rules can be created that can trigger code execution when an adversary sends a specifically crafted email to that user.(Citation: SilentBreak Outlook Rules) Once malicious rules have been added to the user’s mailbox, they will be loaded when Outlook is started. Malicious rules will execute when an adversary sends a specifically crafted email to the user.(Citation: SilentBreak Outlook Rules)

Kill chain phases

Kill chainPhase
mitre-attack persistence

Marking (TLP)

TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.

External references