Outlook Task/Note Reminder Received
Last updated on:
In this page
About the rule
Rule Type
Standard
Rule Description
Detects changes to the registry values related to outlook that indicates that a reminder was triggered for a Note or Task item. This could be a sign of exploitation of CVE-2023-23397. Further investigation is required to determine the success of an exploitation.
Severity
Attention
Rule Requirement
Criteria
Action1: actionname = "Registry value modified" AND ((OBJECTNAME contains "\SOFTWARE\Microsoft\Office" AND OBJECTNAME contains "\Outlook") OR ((OBJECTNAME endswith "\SOFTWARE\Microsoft\Office" AND isExist(OBJECTVALUENAME)) OR (OBJECTNAME endswith "\Outlook" AND isExist(OBJECTVALUENAME)))) AND (OBJECTNAME contains "\Tasks\,\Notes" OR ((OBJECTNAME endswith "\Tasks" AND isExist(OBJECTVALUENAME)) OR (OBJECTNAME endswith "\Notes" AND isExist(OBJECTVALUENAME)))) select Action1.HOSTNAME,Action1.MESSAGE,Action1.OBJECTNAME,Action1.PROCESSNAME,Action1.PREVVAL,Action1.CHANGES
Detection
Execution Mode
realtime
Log Sources
Windows
Author
Nasreddine Bencherchali (Nextron Systems)


