NotRuler Logo

NotRuler

NotRuler is a tool for Exchange Admins to detect client-side Outlook rules and VBScript enabled forms, aiding in the detection of attacks created through Ruler.

94
Visit website
Compare
Compare
0
MCPThe entire cybersecurity market, one prompt awayTry MCP Access

NotRuler Description

NotRuler is a tool that allows Exchange Admins to remotely interact with Exchange servers to detect client-side Outlook rules and VBScript enabled forms, aiding in the detection of attacks created through Ruler. It provides the ability to query Exchange mailboxes, check for compromise, extract stager addresses for malicious rules, extract VBScript used in forms, and check for 'homepage' and extract URLs. The tool has compiled binaries for Linux, OSX, and Windows, with information on setting up from source available in the getting-started guide. NotRuler operates in two modes: Rules to check for client-side rules, Forms to check for VBScript enabled forms, and Homepage to check for a custom homepage.

NotRuler FAQ

Common questions about NotRuler including features, pricing, alternatives, and user reviews.

NotRuler is NotRuler is a tool for Exchange Admins to detect client-side Outlook rules and VBScript enabled forms, aiding in the detection of attacks created through Ruler.. It is a Security Operations solution designed to help security teams with Rules, Attack Detection, Microsoft 365.

Have more questions? Browse our categories or search for specific tools.

ALTERNATIVES

MailXaminer Email Decryption Logo

Decrypts S/MIME & OpenPGP emails from PST/OST/EDB for forensic analysis.

0
libesedb Logo

A library for accessing and parsing Extensible Storage Engine (ESE) Database Files used by Microsoft applications like Windows Search, Exchange, and Active Directory for forensic analysis purposes.

0
Untitled Goose Tool Logo

A robust and flexible hunt and incident response tool for investigating AzureAD, Azure, and M365 environments.

0
im0rtp3's Yara rule repository Logo

A collection of Yara rules licensed under the DRL 1.1 License.

0

Stay Updated with Mandos Brief

Get strategic cybersecurity insights in your inbox