Malicious Outlook Rules in Action
ID: 32554668-b49a-5fa6-83b7-4092c7aaab63
STIX ID: report--32554668-b49a-5fa6-83b7-4092c7aaab63
Feed Name: Black Hills Infosec Blog
Threat Score
This blog post explains how to achieve a remote shell using a malicious Outlook rule during pentests, including a Python3 requirement for rulz.py, guidance for setting up a read-only WebDAV server for payload hosting, tips for configuring an Empire listener, and operational advice (e.g., closing local Outlook before sending). It links to additional detailed posts and resources for implementation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
