{"id":"T1137.004","name":"Outlook Home Page","url":"https://attack.mitre.org/techniques/T1137/004","tactics":["persistence"],"platforms":["Windows","Office Suite"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0177","stix_id":"x-mitre-detection-strategy--e55f4e4b-80c0-4a2b-8202-659d29bbba33","name":"Detect Persistence via Outlook Home Page Exploitation","url":"https://attack.mitre.org/detectionstrategies/DET0177","analytics":[{"id":"AN0502","stix_id":"x-mitre-analytic--5ce49e4b-a67f-46ea-b48d-f08f7b942fb4","name":"Analytic 0502","description":"Adversary uses a tool like Ruler to configure a malicious Outlook folder Home Page that loads a remote or embedded HTML payload upon folder interaction. Execution chain begins with Outlook launching, a specific folder being accessed, and a suspicious child process being spawned or COM-based execution invoked.","url":"https://attack.mitre.org/detectionstrategies/DET0177#AN0502","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Application","channel":"Outlook logs indicating failure to load or render HTML page in Home Page view","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"wineventlog-application"},{"name":"WinEventLog:PowerShell","channel":"Execution of PowerShell script to enumerate or remove malicious Home Page folder config","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"wineventlog-powershell"}],"mutable_elements":[{"field":"TargetFolder","description":"Home Page can be configured on any folder like Calendar, Inbox, or custom folders"},{"field":"HTMLPayloadLocation","description":"The Home Page URL may point to internal or external content, hosted on trusted or unknown domains"},{"field":"ChildProcessName","description":"Execution may result in launch of scripting hosts (e.g., mshta.exe, wscript.exe) from outlook.exe"},{"field":"TimeWindow","description":"Execution may occur only when the specific folder is accessed after launch, not immediately at startup"},{"field":"FormViewBehavior","description":"Behavior may vary if the folder's form view is customized or suppressed via GPO"}],"live":true,"detection_strategies":["DET0177"],"techniques":["T1137.004"]},{"id":"AN0503","stix_id":"x-mitre-analytic--616755c6-e83d-46ce-ad76-ac706074a575","name":"Analytic 0503","description":"Malicious HTML or script is rendered as a Home Page for a specific Outlook folder. Outlook accesses that folder, loads remote content, and executes embedded JavaScript or ActiveX/COM logic resulting in unauthorized actions or local execution.","url":"https://attack.mitre.org/detectionstrategies/DET0177#AN0503","platforms":["Office Suite"],"log_source_references":[{"name":"m365:unified","channel":"Folder configuration updated with external or HTML-formatted Home Page via Set-MailboxFolder","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-unified"},{"name":"m365:messagetrace","channel":"Inbound email triggering Outlook to auto-access folder tied to malicious Home Page","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"m365-messagetrace"}],"mutable_elements":[{"field":"AuditPolicyScope","description":"Home Page customization may not be audited unless detailed message or folder auditing is enabled"},{"field":"FolderAccessRate","description":"Anomalous access to folders not usually interacted with can signal triggering of malicious view"},{"field":"ExternalURLAllowlist","description":"Mail clients may restrict remote Home Page content unless domain is explicitly allowed"}],"live":true,"detection_strategies":["DET0177"],"techniques":["T1137.004"]}],"live":true,"version":"1.0","techniques":["T1137.004"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}