diff --git a/rules/windows/image_load/image_load_office_outlook_outlvba.yml b/rules/windows/image_load/image_load_office_outlook_outlvba.yml index b05efb86c..0b7865d02 100644 --- a/rules/windows/image_load/image_load_office_outlook_outlvba.yml +++ b/rules/windows/image_load/image_load_office_outlook_outlvba.yml @@ -1,7 +1,7 @@ -title: Macro Enabled DLL Loaded Via Office Applications -id: ff0f2b05-09db-4095-b96d-1b75ca24894a +title: Microsoft VBA For Outlook Addin Loaded Via Outlook +id: 9a0b8719-cd3c-4f0a-90de-765a4cb3f5ed status: test -description: Detects any assembly DLL being loaded by an Office Product +description: Detects outlvba (Microsoft VBA for Outlook Addin) DLL being loaded by the outlook process references: - https://speakerdeck.com/heirhabarov/hunting-for-persistence-via-microsoft-exchange-server-or-outlook?slide=58 author: Nasreddine Bencherchali (Nextron Systems)