Windows File Access to Outlook Unistore Data by Uncommon Processes
Alerts when unusual processes access Outlook Unistore (data and UnistoreDB store.vol) file locations on Windows.
FreeUnreviewedSigmalowv1
windows-file-access-to-outlook-unistore-data-by-uncommon-processes-fc3e237f
title: Windows File Access to Outlook Unistore Data by Uncommon Processes
id: 65a5d102-5094-4418-8a20-eca5789db9ad
status: test
description: This rule flags file access on Windows targeting Outlook Mail data stored under the AppData\Local\Comms\Unistore\data directory and the UnistoreDB store.vol file. Attackers may use these artifacts to collect or manipulate mailbox-related information for credential theft or theft of stored content. The detection relies on file access telemetry that includes the accessed FileName and the initiating process Image, using allowlisted process paths to reduce expected benign activity. Baseline is required to identify what is truly uncommon in the environment.
references:
- https://darkdefender.medium.com/windows-10-mail-app-forensics-39025f5418d2
- https://github.com/redcanaryco/atomic-red-team/blob/58496ee3306e6e42a7054d36a94e6eb561ee3081/atomics/T1070.008/T1070.008.md#atomic-test-4---copy-and-modify-mailbox-data-on-windows
- https://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/file/file_access/file_access_win_office_outlook_mail_credential.yml
author: frack113, Huntrule Team
date: 2024-05-10
modified: 2024-07-29
tags:
- attack.stealth
- attack.t1070.008
- detection.threat-hunting
logsource:
category: file_access
product: windows
definition: "Requirements: Microsoft-Windows-Kernel-File ETW provider"
detection:
selection_unistore:
FileName|contains: \AppData\Local\Comms\Unistore\data
selection_unistoredb:
FileName|endswith: \AppData\Local\Comms\UnistoreDB\store.vol
filter_main_system:
Image: System
filter_main_generic:
Image|startswith:
- C:\Program Files (x86)\
- C:\Program Files\
- C:\Windows\system32\
- C:\Windows\SysWOW64\
filter_optional_defender:
Image|startswith: C:\ProgramData\Microsoft\Windows Defender\
Image|endswith:
- \MpCopyAccelerator.exe
- \MsMpEng.exe
filter_optional_thor:
Image|endswith:
- \thor64.exe
- \thor.exe
condition: 1 of selection_* and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- Antivirus, Anti-Spyware, Anti-Malware Software
- Backup software
- Legitimate software installed on partitions other than "C:\"
- Searching software such as "everything.exe"
level: low
license: DRL-1.1
related:
- id: fc3e237f-2fef-406c-b90d-b3ae7e02fa8f
type: derived
What it detects
This rule flags file access on Windows targeting Outlook Mail data stored under the AppData\Local\Comms\Unistore\data directory and the UnistoreDB store.vol file. Attackers may use these artifacts to collect or manipulate mailbox-related information for credential theft or theft of stored content. The detection relies on file access telemetry that includes the accessed FileName and the initiating process Image, using allowlisted process paths to reduce expected benign activity. Baseline is required to identify what is truly uncommon in the environment.
Known false positives
- Antivirus, Anti-Spyware, Anti-Malware Software
- Backup software
- Legitimate software installed on partitions other than "C:\"
- Searching software such as "everything.exe"
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.