logo

NotRuler – Turning Offence into Defence

ID: c2bf9f5a-3503-5094-9d8b-e55a12277a08

STIX ID: report--c2bf9f5a-3503-5094-9d8b-e55a12277a08

Feed Name: SensePost Blog

Date Published: 2017-10-02

Date Updated: 2026-04-29

...
...

This post introduces NotRuler, an open-source defensive utility to detect Ruler-based abuse of Microsoft Exchange/Outlook by enumerating and parsing client-side rules, custom forms (including VBScript), and homepages across mailboxes (with optional admin impersonation), and provides practical IOCs and detection tips—such as the distinctive 'Ruler' User-Agent and NTLM workstation strings and relevant Windows authentication event IDs—alongside notes on Microsoft mitigations and MFA, enabling responders to identify and triage potential Ruler backdoors at scale.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.