APT28 CVE-2023-23397 Outlook SMB NTLMv2 Hash Relay to External IP

Detects instances where the Outlook process (OUTLOOK.EXE) initiates a network connection over SMB (port 445) to an external, non-private IP address. This behavior is highly suspicious as Microsoft Outlook should typically not be performing direct SMB connections to external systems, and this is often indicative of an adversary attempting to leverage malicious documents or templates to perform credential harvesting via NTLM relay or SMB authentication captures.