Skip to content

Conversation

RavenTait
Copy link
Contributor

Details

Four Detections based around the Outlook Macro techniques associated with NotDoor Malware

  • Windows Outlook Macro Security Modified
  • Windows Outlook Macro Created by Suspicious Process
  • Windows Outlook LoadMacroProviderOnBoot Persistence
  • Windows Outlook Dialogs Disabled from Unusual Process

One story for NotDoor Malware

Checklist

  • Validate name matches <platform>_<mitre att&ck technique>_<short description> nomenclature
  • CI/CD jobs passed ✔️
  • Validated SPL logic.
  • Validated tags, description, and how to implement.
  • Verified references match analytic.
  • Confirm updates to lookups are handled properly.

@patel-bhavin patel-bhavin added this to the v5.14.0 milestone Sep 15, 2025
@patel-bhavin
Copy link
Contributor

:shipit:

@patel-bhavin patel-bhavin merged commit d4e6bae into develop Sep 15, 2025
4 checks passed
@patel-bhavin patel-bhavin deleted the notdoor_outlook_macros branch September 15, 2025 19:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants