
Purple team project exploiting CVE-2023-23397 Outlook NTLM leak with phishing delivery, plus Sigma/Wazuh detections mapped to MITRE ATT&CK for the attack chain.
Two halves of one project against the same Outlook NTLM-leak vulnerability (CVE-2023-23397):
FINAL_PROJECT_REPORT.pdf, walkthrough in FINAL_DEMO_VIDEO.mp4, slides in Presentation.pptx. Delivery scripts (send_malicious_email.py, malicious_email_url.py) and the phishing lure page (index.html) are included for reference.detection-engineering-lab/ — Sigma/Wazuh detections for every stage of that same attack chain, mapped to MITRE ATT&CK, each with a measured false-positive rate against a benign baseline, plus a small automation layer that summarizes daily alerts.Build log and task-by-task plan for the detection lab: Detection_Engineering_Project_Plan.md.
All of this ran against VMs I control (Windows 10 victim, Kali attacker) in an isolated lab — not against any real target.