Unusual Access to Windows Outlook Unistore Mail Data by Non-Standard Processes

Alerts when unusual processes access Outlook Unistore (data and UnistoreDB store.vol) file locations on Windows.

FreeReviewedSigma · Low · v5
Product
windows
Category
file_access
Author
frack113 (SigmaHQ), DRL 1.1
Published
2024-05-10
Updated
2026-07-31

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies file access attempts to Windows Outlook mail storage locations under AppData\Local\Comms\Unistore\data and UnistoreDB\store.vol when performed by uncommon process images. Such access may indicate attempts to copy or manipulate mailbox data for credential theft or other data collection. It relies on Windows file access telemetry (Kernel File ETW) that includes the accessing process path and the targeted FileName, using image allow-filters and Defender/Thor exclusions to reduce noise.

Related detections2 linkedT1070.008 — drag to rearrange
Suspicious Teams Message Soft Delete by Agent Identity via M365 Audit
Windows PowerShell Script Accessing Windows MailApp MailBox Data Path
Unusual Access to Windows Outlook Unistore Mail Data by Non-Standard Processes
Pivot detection · T1070.008 · 2 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.