Ruler — Malware Profile

Ruler is a tool to abuse Microsoft Exchange services. It is publicly available on GitHub and the tool is executed via the command line. The creators of Ruler have also released a defensive tool, NotRuler, to detect its usage.

MITRE ATT&CK techniques (4)

Attributed threat actors

Read the full analysis on IntelFusions