SwiftOnSecurity / sysmon-config

Sysmon configuration file template with default high-quality event tracing
4.68k stars 1.69k forks source link

Outlook Webview URL changes #154

Open humpalum opened 3 years ago

humpalum commented 3 years ago

Matches registry events that changes the URL value for the WebView of Outlook which could enable persistence for hackers.

Ref: https://speakerdeck.com/heirhabarov/hunting-for-persistence-via-microsoft-exchange-server-or-outlook?slide=70