216.73.217.22

Ruler

The MITRE Corporation · Published 04/02/2019 19:27 · Modified 27/03/2026 01:07

Essential information

Confidence
100/100
Published
04/02/2019 19:27
Modified
27/03/2026 01:07
Revoked
No
Author / Source
The MITRE Corporation
Related entities
4 attack patterns (mitre), 1 intrusion sets (apt)

Description

[Ruler](https://attack.mitre.org/software/S0358) is a tool to abuse Microsoft Exchange services. It is publicly available on GitHub and the tool is executed via the command line. The creators of [Ruler](https://attack.mitre.org/software/S0358) have also released a defensive tool, NotRuler, to detect its usage.(Citation: SensePost Ruler GitHub)(Citation: SensePost NotRuler)

Marking (TLP)

Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.

External references