logo

Malicious Outlook Rules in Action

ID: 32554668-b49a-5fa6-83b7-4092c7aaab63

STIX ID: report--32554668-b49a-5fa6-83b7-4092c7aaab63

Feed Name: Black Hills Infosec Blog

Threat Score
60/100

Date Published: 2016-11-29

Date Updated: 2026-04-27

Author: BHIS

...
...

This blog post explains how to achieve a remote shell using a malicious Outlook rule during pentests, including a Python3 requirement for rulz.py, guidance for setting up a read-only WebDAV server for payload hosting, tips for configuring an Empire listener, and operational advice (e.g., closing local Outlook before sending). It links to additional detailed posts and resources for implementation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.