kevmap

TechniquesT1137.003 › AN0086

AN0086 Analytic 0086

Office Suite · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Outlook form execution upon message receipt or client launch results in automated code execution within user session. Form definitions deviate from standard templates and include script logic or COM object calls embedded in form fields.</p>
Detects
T1137.003 Outlook Forms
Part of
DET0029 Detect Persistence via Outlook Custom Forms Triggered by Malicious Email

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
m365:unifiedUnusual form activity within Outlook client, including load of non-default formsDC0038 Application Log Content
m365:messagetraceInbound email triggers execution of mailbox-stored custom formDC0064 Command Execution

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
AuditPolicyScopeNot all tenants may enable audit logs of custom form activity or COM component usage in Office
MessageSenderAnomalyThresholdRuler-style delivery may come from external accounts with forged headers or low reputation
FormExecutionRateFrequency of form triggers may be anomalously high compared to baseline Outlook usage