{"id":"T1137.003","name":"Outlook Forms","url":"https://attack.mitre.org/techniques/T1137/003","tactics":["persistence"],"platforms":["Windows","Office Suite"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0029","stix_id":"x-mitre-detection-strategy--75281b94-735d-4051-b400-a42205783af9","name":"Detect Persistence via Outlook Custom Forms Triggered by Malicious Email","url":"https://attack.mitre.org/detectionstrategies/DET0029","analytics":[{"id":"AN0085","stix_id":"x-mitre-analytic--48cc1694-568f-4602-96e4-cbbe099c6dae","name":"Analytic 0085","description":"Adversary uses a tool like Ruler to insert a malicious custom form into the user's Outlook mailbox. The form is designed to auto-execute on Outlook startup or on receipt of a specially crafted email. This results in child processes launched from outlook.exe and possibly network connections or payload loading.","url":"https://attack.mitre.org/detectionstrategies/DET0029#AN0085","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Application","channel":"Outlook errors loading or processing custom form templates","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"wineventlog-application"},{"name":"WinEventLog:PowerShell","channel":"Execution of Microsoft script to enumerate custom forms in Outlook mailbox","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"wineventlog-powershell"}],"mutable_elements":[{"field":"FormStorageLocation","description":"Malicious forms may be stored in various user-specific locations in the Outlook mailbox (e.g., IPM.Note class)"},{"field":"ChildProcessName","description":"Child process spawned by outlook.exe may vary (e.g., powershell.exe, rundll32.exe, mshta.exe)"},{"field":"TimeWindow","description":"Form-triggered execution may happen immediately upon Outlook startup or with delay after crafted message arrival"},{"field":"OutlookVersion","description":"Form behavior and error logs may vary across Outlook 2013, 2016, and M365 builds"},{"field":"UserContext","description":"Attack may target only specific users; contextual correlation needed for account baselining"}],"live":true,"detection_strategies":["DET0029"],"techniques":["T1137.003"]},{"id":"AN0086","stix_id":"x-mitre-analytic--73ec21b3-5679-44a9-bac3-943060bed786","name":"Analytic 0086","description":"Outlook form execution upon message receipt or client launch results in automated code execution within user session. Form definitions deviate from standard templates and include script logic or COM object calls embedded in form fields.","url":"https://attack.mitre.org/detectionstrategies/DET0029#AN0086","platforms":["Office Suite"],"log_source_references":[{"name":"m365:unified","channel":"Unusual form activity within Outlook client, including load of non-default forms","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-unified"},{"name":"m365:messagetrace","channel":"Inbound email triggers execution of mailbox-stored custom form","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"m365-messagetrace"}],"mutable_elements":[{"field":"AuditPolicyScope","description":"Not all tenants may enable audit logs of custom form activity or COM component usage in Office"},{"field":"MessageSenderAnomalyThreshold","description":"Ruler-style delivery may come from external accounts with forged headers or low reputation"},{"field":"FormExecutionRate","description":"Frequency of form triggers may be anomalously high compared to baseline Outlook usage"}],"live":true,"detection_strategies":["DET0029"],"techniques":["T1137.003"]}],"live":true,"version":"1.0","techniques":["T1137.003"]}],"sigma_rules":[{"id":"c3edc6a5-d9d4-48d8-930e-aab518390917","title":"Potential Persistence Via Outlook Form","author":"Tobias Michalski (Nextron Systems)","status":"test","level":"high","date":"2021-06-10","modified":"2023-02-22","description":"Detects the creation of a new Outlook form which can contain malicious code","references":["https://speakerdeck.com/heirhabarov/hunting-for-persistence-via-microsoft-exchange-server-or-outlook?slide=76","https://speakerdeck.com/heirhabarov/hunting-for-persistence-via-microsoft-exchange-server-or-outlook?slide=79","https://learn.microsoft.com/en-us/office/vba/outlook/concepts/outlook-forms/create-an-outlook-form","https://www.slipstick.com/developer/custom-form/clean-outlooks-forms-cache/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.persistence","attack.t1137.003"],"path":"rules/windows/file/file_event/file_event_win_office_outlook_newform.yml","techniques":["T1137.003"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}