Outlook EnableUnsafeClientMailRules Setting Enabled - Registry

Last updated on:

About the rule

Rule Type

Standard

Rule Description

Detects an attacker trying to enable the outlook security setting "EnableUnsafeClientMailRules" which allows outlook to run applications or execute macros

Severity

Trouble

Rule Requirement

Criteria

Action1: actionname = "Registry value modified" AND (OBJECTNAME endswith "\Outlook\Security\EnableUnsafeClientMailRules" OR (OBJECTNAME endswith "\Outlook\Security" AND OBJECTVALUENAME = "EnableUnsafeClientMailRules")) AND (INFORMATION = "DWORD (0x00000001)" OR (CHANGES = 1 AND NEWTYPE = "REG_DWORD")) select Action1.HOSTNAME,Action1.MESSAGE,Action1.OBJECTNAME,Action1.PROCESSNAME,Action1.PREVVAL,Action1.CHANGES

Detection

Execution Mode

realtime

Log Sources

Windows

Author

Nasreddine Bencherchali (Nextron Systems)