1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1137.003 Outlook Forms — Detection Rules

Detection workspace for T1137.003 Outlook Forms: 1 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

No exact concept selected.

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0029 Detect Persistence via Outlook Custom Forms Triggered by Malicious Email

AN0085 Analytic 0085

Adversary uses a tool like Ruler to insert a malicious custom form into the user's Outlook mailbox. The form is designed to auto-execute on Outlook startup or on receipt of a specially crafted email. This results in child processes launched from outlook.exe and possibly network connections or payload loading.

AN0086 Analytic 0086

Outlook form execution upon message receipt or client launch results in automated code execution within user session. Form definitions deviate from standard templates and include script logic or COM object calls embedded in form fields.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1137.003 simulation workspace

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.