NotRuler – Turning Offence into Defence
ID: c2bf9f5a-3503-5094-9d8b-e55a12277a08
STIX ID: report--c2bf9f5a-3503-5094-9d8b-e55a12277a08
Feed Name: SensePost Blog
This post introduces NotRuler, an open-source defensive utility to detect Ruler-based abuse of Microsoft Exchange/Outlook by enumerating and parsing client-side rules, custom forms (including VBScript), and homepages across mailboxes (with optional admin impersonation), and provides practical IOCs and detection tips—such as the distinctive 'Ruler' User-Agent and NTLM workstation strings and relevant Windows authentication event IDs—alongside notes on Microsoft mitigations and MFA, enabling responders to identify and triage potential Ruler backdoors at scale.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
