Tag
medium
advisory
Persistence via Malicious Microsoft Outlook VBA Template
2 rules 1 TTPAttackers establish persistence by installing a malicious VBA template in Microsoft Outlook, triggering scripts upon application startup by modifying the VBAProject.OTM file, detected by monitoring for unauthorized file modifications.
Outlook
persistence
vba
windows
2r
1t
medium
advisory
Outlook Security Settings Registry Modification
2 rules 1 TTPAttackers modify Outlook security settings via registry changes to enable malicious mail rules and bypass security controls, potentially leading to persistence and data compromise.
Microsoft Outlook
persistence
registry_modification
outlook
email
2r
1t
high
advisory
Outlook Dialogs Disabled by Unusual Process
2 rules 1 TTPThe detection identifies the modification of the Windows Registry key 'PONT_STRING' under Outlook Options by a process other than Outlook.exe, potentially indicating malware activity such as NotDoor.
Outlook +3
registry_modification
malware
notdoor
2r
1t