logo

Assessing suspicious Outlook rules: an exercise

ID: 1e88d8dc-8704-5f3d-aaa9-1fb9c702cff1

STIX ID: report--1e88d8dc-8704-5f3d-aaa9-1fb9c702cff1

Feed Name: Expel Blog

Date Published: 2024-01-16

Date Updated: 2026-04-27

Author: Peter Michalski

...
...

This guide trains analysts to spot malicious Outlook inbox rules by evaluating the logical association between rule names, conditions, and actions; it presents ten anonymized real examples with verdicts and reasoning, outlines heuristics (e.g., suspicious use of default folders, global delete rules, inconsistent naming), and gives investigation tips and caveats for accurate triage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.