Windows Registry Changes to Outlook Security Settings

Alerts on registry updates to Outlook security configuration keys on Windows, excluding direct Outlook.exe changes.

FreeReviewedSigma · Medium · v1
Product
windows
Category
registry_set
Author
frack113 (SigmaHQ), DRL 1.1
Published
2021-12-28
Updated
2026-07-30

ATT&CK techniques

Persistence
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags modifications to Windows registry values under the Microsoft Office Outlook security settings path. Attackers may change these settings to weaken email handling or security controls, enabling further persistence or easier delivery of malicious content. The detection relies on registry set events and matches target registry paths containing both the Office and Outlook\Security subkeys while excluding updates performed by Outlook.EXE from the Office installation directories.

Related detections9 linkedT1137 — drag to rearrange
Suspicious Office Application Spawning Mshta With Remote HTA
Malicious NotDoor Outlook VBA Persistence via VbaProject.OTM Deployment (via process_creation)
Malicious NotDoor Outlook Macro Auto-Execution Enablement via Registry (via registry_set)
Office Persistence via WLL Add-in Dropped to Word STARTUP Folder
Windows Registry Changes for Outlook Task/Note Reminder Trigger
Windows: Suspicious Outlook VbaProject.OTM Macro File Created
Windows Office Startup Folder File Drop for Persistence via Office Documents
Windows Registry: IE ZoneMap Domain Zone Change via ZoneMap\Domains
Windows Registry Set to Hide File Extensions via Explorer Advanced Keys
Windows Registry Changes to Outlook Security Settings
Pivot detection · T1137 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.