LoFP LoFP / t1137

t1137

TitleTags
a legitimate vba for outlook is usually configured interactively via outlook.exe.
administrative activity
administrative scripts
legitimate add-ins
legitimate addin installation
legitimate use of outlook forms
loading a user environment from a backup or a domain controller
rare legitimate automation or third-party tools may create inbox rules with non-alphanumeric names. validate against known messaging workflows and approved admin scripts before escalating.
synchronization of templates
unknown
unlikely
user genuinely creates a vb macro for their email