APT28 NotDoor Outlook Macro Security Bypass via Registry

Detects modifications to the Outlook Security registry key, specifically setting the 'Level' value to '1'. This configuration (often associated with 'OutlookSecurityMode' or related programmatic access policies) can be used by adversaries to bypass security prompts when accessing the Outlook Object Model, allowing malicious scripts or applications to interact with Outlook to send emails, harvest contacts, or access attachments without user intervention.