- Tactics
- Persistence
- Platforms
- Windows, Office Suite
- Reference
- attack.mitre.org/techniques/T1137.003
Description
Adversaries may abuse Microsoft Outlook forms to obtain persistence on a compromised system. Outlook forms are used as templates for presentation and functionality in Outlook messages. Custom Outlook forms can be created that will execute code when a specifically crafted email is sent by an adversary utilizing the same custom Outlook form.(Citation: SensePost Outlook Forms)
Once malicious forms have been added to the user’s mailbox, they will be loaded when Outlook is started. Malicious forms will execute when an adversary sends a specifically crafted email to the user.(Citation: SensePost Outlook Forms)
How GTK Cyber trains on this
GTK Cyber's Threat Hunting with Data Science course teaches you to build machine-learning detections for techniques like this across the MITRE ATT&CK framework, including the Persistence tactic this technique falls under. Practitioner-led, focused on real detections, not memorizing technique IDs.
Related techniques
- T1037 - Boot or Logon Initialization Scripts
- T1053 - Scheduled Task/Job
- T1078 - Valid Accounts
- T1098 - Account Manipulation
- T1112 - Modify Registry
- T1133 - External Remote Services
- T1136 - Create Account
- T1137 - Office Application Startup
- T1176 - Software Extensions
- T1197 - BITS Jobs
- T1205 - Traffic Signaling
- T1505 - Server Software Component