Bidda Sovereign Intelligence · 10,085 Verified Nodes · 39 Sovereign Pillars

MITRE ATT&CK T1137.004: Outlook Home Page (Enterprise Tactic TA0003 - Persistence)

MITRE ATT&CK T1137.004 (Outlook Home Page) is an Enterprise Persistence sub-technique of T1137 (Office Application Startup). Adversaries may abuse…

What MITRE ATT&CK T1137.004: Outlook Home Page (Enterprise Tactic TA0003 - Persistence) requires

MITRE ATT&CK T1137.004 (Outlook Home Page) is an Enterprise Persistence sub-technique of T1137 (Office Application Startup). Adversaries may abuse Microsoft Outlook's Home Page feature to obtain persistence on a compromised system. Outlook Home Page is a legacy feature used to customize the presentation of Outlook folders. This feature allows for an internal or external URL to be loaded and presented whenever a folder is opened. A malicious HTML page can be crafted that will execute code when loaded by Outlook Home Page. Once malicious home pages have been added to the user's mailbox, they will be loaded when Outlook is started. Affected platforms: Windows, Office Suite. MITRE-documented mitigations include M1051 Update Software, M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-06, AC-10, AC-17, CM-02, CM-06, CM-08, RA-05, SC-18.

Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:

Primary source: https://attack.mitre.org/techniques/T1137/004/

SHA-256 integrity: c7e1487a98ee861e3665d9232c115bb62e68855bb6c1317ec599d89502058af6

Primary Citations — 7 traced to source

  • MITRE ATT&CK Technique T1137.004: Outlook Home Page (https://attack.mitre.org/techniques/T1137/004/)
  • MITRE ATT&CK Tactic TA0003: Persistence (https://attack.mitre.org/tactics/TA0003/)

+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.