Windows Persistence Attempt Using Outlook.exe to Create Outlook Forms Cache

Flags Outlook (outlook.exe) form file activity targeting local FORMS directories often used for persistence.

FreeReviewedSigma · High · v2
Product
windows
Category
file_event
Author
Tobias Michalski (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2021-06-10
Updated
2026-07-31

ATT&CK techniques

Persistence
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies creation or writing of files related to Outlook forms by observing file events where outlook.exe is the initiating process and the target path is under the Outlook Forms cache directories. Attackers can use Outlook forms to persist malicious functionality within the user’s Outlook environment. The detection relies on Windows file event telemetry capturing the process image path (outlook.exe) and the target filename or directory being written.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.