Unusual Access to Windows Outlook Unistore Mail Data by Non-Standard Processes

Alerts when unusual processes access Outlook Unistore (data and UnistoreDB store.vol) file locations on Windows.

FreeReviewedSigma · Low · v5
Product
windows
Category
file_access
Author
frack113 (SigmaHQ), DRL 1.1
Published
2024-05-10
Updated
2026-07-31
title: Unusual Access to Windows Outlook Unistore Mail Data by Non-Standard Processes
id: 65a5d102-5094-4418-8a20-eca5789db9ad
status: test
description: This rule identifies file access attempts to Windows Outlook mail storage locations under AppData\Local\Comms\Unistore\data and UnistoreDB\store.vol when performed by uncommon process images. Such access may indicate attempts to copy or manipulate mailbox data for credential theft or other data collection. It relies on Windows file access telemetry (Kernel File ETW) that includes the accessing process path and the targeted FileName, using image allow-filters and Defender/Thor exclusions to reduce noise.
references:
  - https://darkdefender.medium.com/windows-10-mail-app-forensics-39025f5418d2
  - https://github.com/redcanaryco/atomic-red-team/blob/58496ee3306e6e42a7054d36a94e6eb561ee3081/atomics/T1070.008/T1070.008.md#atomic-test-4---copy-and-modify-mailbox-data-on-windows
  - https://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/file/file_access/file_access_win_office_outlook_mail_credential.yml
author: frack113, Huntrule Team
date: 2024-05-10
modified: 2024-07-29
tags:
  - attack.stealth
  - attack.t1070.008
  - detection.threat-hunting
logsource:
  category: file_access
  product: windows
  definition: "Requirements: Microsoft-Windows-Kernel-File ETW provider"
detection:
  selection_unistore:
    FileName|contains: \AppData\Local\Comms\Unistore\data
  selection_unistoredb:
    FileName|endswith: \AppData\Local\Comms\UnistoreDB\store.vol
  filter_main_system:
    Image: System
  filter_main_generic:
    Image|startswith:
      - C:\Program Files (x86)\
      - C:\Program Files\
      - C:\Windows\system32\
      - C:\Windows\SysWOW64\
  filter_optional_defender:
    Image|startswith: C:\ProgramData\Microsoft\Windows Defender\
    Image|endswith:
      - \MpCopyAccelerator.exe
      - \MsMpEng.exe
  filter_optional_thor:
    Image|endswith:
      - \thor64.exe
      - \thor.exe
  condition: 1 of selection_* and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
  - Antivirus, Anti-Spyware, Anti-Malware Software
  - Backup software
  - Legitimate software installed on partitions other than "C:\"
  - Searching software such as "everything.exe"
level: low
license: DRL-1.1
related:
  - id: fc3e237f-2fef-406c-b90d-b3ae7e02fa8f
    type: derived