Techniques › T1137.003 › AN0086
AN0086 Analytic 0086
Office Suite · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Outlook form execution upon message receipt or client launch results in automated code execution within user session. Form definitions deviate from standard templates and include script logic or COM object calls embedded in form fields.</p>
- Detects
- T1137.003 Outlook Forms
- Part of
- DET0029 Detect Persistence via Outlook Custom Forms Triggered by Malicious Email
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| m365:unified | Unusual form activity within Outlook client, including load of non-default forms | DC0038 Application Log Content |
| m365:messagetrace | Inbound email triggers execution of mailbox-stored custom form | DC0064 Command Execution |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
AuditPolicyScope | Not all tenants may enable audit logs of custom form activity or COM component usage in Office |
MessageSenderAnomalyThreshold | Ruler-style delivery may come from external accounts with forged headers or low reputation |
FormExecutionRate | Frequency of form triggers may be anomalously high compared to baseline Outlook usage |