APT28 CVE-2023-23397 Outlook SMB NTLMv2 Hash Relay to External IP

Detects instances where the Outlook process (OUTLOOK.EXE) initiates a network connection via port 445 (SMB) to an IP address that is not part of the internal private network ranges. This activity is highly anomalous for an email client and may indicate exploitation, data exfiltration, or attempts to relay NTLM credentials to a remote malicious SMB server.