Windows File Access to Outlook Unistore Data by Uncommon Processes

Alerts when unusual processes access Outlook Unistore (data and UnistoreDB store.vol) file locations on Windows.

FreeUnreviewedSigmalowv1
title: Windows File Access to Outlook Unistore Data by Uncommon Processes
id: 65a5d102-5094-4418-8a20-eca5789db9ad
status: test
description: This rule flags file access on Windows targeting Outlook Mail data stored under the AppData\Local\Comms\Unistore\data directory and the UnistoreDB store.vol file. Attackers may use these artifacts to collect or manipulate mailbox-related information for credential theft or theft of stored content. The detection relies on file access telemetry that includes the accessed FileName and the initiating process Image, using allowlisted process paths to reduce expected benign activity. Baseline is required to identify what is truly uncommon in the environment.
references:
  - https://darkdefender.medium.com/windows-10-mail-app-forensics-39025f5418d2
  - https://github.com/redcanaryco/atomic-red-team/blob/58496ee3306e6e42a7054d36a94e6eb561ee3081/atomics/T1070.008/T1070.008.md#atomic-test-4---copy-and-modify-mailbox-data-on-windows
  - https://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/file/file_access/file_access_win_office_outlook_mail_credential.yml
author: frack113, Huntrule Team
date: 2024-05-10
modified: 2024-07-29
tags:
  - attack.stealth
  - attack.t1070.008
  - detection.threat-hunting
logsource:
  category: file_access
  product: windows
  definition: "Requirements: Microsoft-Windows-Kernel-File ETW provider"
detection:
  selection_unistore:
    FileName|contains: \AppData\Local\Comms\Unistore\data
  selection_unistoredb:
    FileName|endswith: \AppData\Local\Comms\UnistoreDB\store.vol
  filter_main_system:
    Image: System
  filter_main_generic:
    Image|startswith:
      - C:\Program Files (x86)\
      - C:\Program Files\
      - C:\Windows\system32\
      - C:\Windows\SysWOW64\
  filter_optional_defender:
    Image|startswith: C:\ProgramData\Microsoft\Windows Defender\
    Image|endswith:
      - \MpCopyAccelerator.exe
      - \MsMpEng.exe
  filter_optional_thor:
    Image|endswith:
      - \thor64.exe
      - \thor.exe
  condition: 1 of selection_* and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
  - Antivirus, Anti-Spyware, Anti-Malware Software
  - Backup software
  - Legitimate software installed on partitions other than "C:\"
  - Searching software such as "everything.exe"
level: low
license: DRL-1.1
related:
  - id: fc3e237f-2fef-406c-b90d-b3ae7e02fa8f
    type: derived

What it detects

This rule flags file access on Windows targeting Outlook Mail data stored under the AppData\Local\Comms\Unistore\data directory and the UnistoreDB store.vol file. Attackers may use these artifacts to collect or manipulate mailbox-related information for credential theft or theft of stored content. The detection relies on file access telemetry that includes the accessed FileName and the initiating process Image, using allowlisted process paths to reduce expected benign activity. Baseline is required to identify what is truly uncommon in the environment.

Known false positives

  • Antivirus, Anti-Spyware, Anti-Malware Software
  • Backup software
  • Legitimate software installed on partitions other than "C:\"
  • Searching software such as "everything.exe"

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.