Windows: Outlook querying WebClient/LanmanWorkstation registry network provider keys

Flags Outlook.exe querying HKLM\SYSTEM\Services WebClient/LanmanWorkstation NetworkProvider registry values.

FreeReviewedSigma · Critical · v5
Product
windows
Service
security
Author
Robert Lee @quantum_cookie (SigmaHQ), DRL 1.1
Published
2023-03-16
Updated
2026-07-31

What it detects

This rule identifies Windows events where Outlook initiates access to registry keys associated with WebClient and LanmanWorkstation network providers. Attackers may use Outlook-driven behavior as part of a workflow that includes querying these configuration points during exploitation attempts. The detection relies on Windows security telemetry for registry object access (Event IDs 4656 and 4663) including the process name ending with OUTLOOK.EXE and the accessed registry object path and access mask for querying values.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.