Suspicious Copy of Outlook OST Email Data File for Exfiltration

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-05-26
Updated
2026-08-28

ATT&CK techniques

Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects copying of an Outlook OST offline data file, a collection step used by the ToddyCat APT before extracting messages with XstExport. The attackers used xcopy to duplicate the .ost mailbox cache to a .ost2 file so its contents could be parsed offline. Copying a locked mailbox data file is a strong indicator of local email collection ahead of exfiltration.

Related detections3 linkedT1114.001 — drag to rearrange
Suspicious Outlook Security Manager DLL Load for Mail Harvesting (via image_load)
Malicious Outlook Process Memory Dump via procdump
Windows PowerShell Script Block Local Email Collection via Outlook COM Automation
Suspicious Copy of Outlook OST Email Data File for Exfiltration
Pivot detection · T1114.001 · 3 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.