APT28 NotDoor Outlook PONT_STRING Registry Modified by Non-Outlook Process
Detects unauthorized processes modifying the registry value 'PONT_STRING' within the Outlook Options General key. This registry value controls the display of content download warnings in Microsoft Outlook. Modifying this key from a non-Outlook process is a technique used by threat actors, such as APT28, to bypass security warnings and facilitate the execution of malicious payloads or content within Outlook.
Microsoft Sentinel (KQL)

