Ruler

MITRE
Malware Type:
Tool
First seen:
Unknown
Last seen:
Unknown
Details:

[Ruler](https://attack.mitre.org/software/S0358) is a tool to abuse Microsoft Exchange services. It is publicly available on GitHub and the tool is executed via the command line. The creators of [Ruler](https://attack.mitre.org/software/S0358) have also released a defensive tool, NotRuler, to detect its usage.(Citation: SensePost Ruler GitHub)(Citation: SensePost NotRuler)

Associated Techniques (4)
ID ATT&CK Tactics
T1087.003 Email Account -
T1137.003 Outlook Forms -
T1137.004 Outlook Home Page -
T1137.005 Outlook Rules -
Used by Actors (1)
Metadata
ID: 744
Created: 13/01/2026 17:48
Updated: 06/03/2026 16:00