# sensepost/ruler

A tool to abuse Exchange services

Repository: https://github.com/sensepost/ruler
Canonical: https://ross.abutalabs.com/products/sensepost-ruler
Language: Go
License: NOASSERTION
License Family: other
Topics: mapi, exchange, shells, pentesting
Last push: 2024-06-10T11:03:07+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 3667, "days_push": 814, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2313, forks 358 (observed 2026-08-28T04:06:36.645467+00:00)

## What it is
Ruler is a Go-based command-line tool for interacting with and abusing Microsoft Exchange servers via MAPI/HTTP or RPC/HTTP. It enables offensive operations such as user enumeration, GAL dumping, and remote shell execution through malicious Outlook rules, forms, or home pages.

## Use cases
- abuse exchange server to get a remote shell
- enumerate valid exchange user accounts
- dump the global address list from exchange
- execute vbscript through outlook forms
- create malicious mail rules for persistence
- brute force exchange user credentials
- pass the hash against exchange mapi

## When to choose
- you are doing authorized penetration testing or red team engagements against Exchange environments
- you need to demonstrate Outlook client-side attack vectors like rules, forms, or homepage persistence
- you want a Go tool with cross-platform binaries for MAPI interaction

## When to avoid
- you need a defensive or auditing tool rather than an offensive one
- your target is not Microsoft Exchange or Outlook
- you require a permissively licensed tool - it is licensed CC BY-NC-SA (non-commercial)
- you need actively developed features - the project is largely in maintenance mode

## Facets
- artifact type: cli-tool
- maturity: maintenance
- function: penetration-testing, security, email, http-client
- domain: penetration-testing, security, email
- platform: windows, cli, go
- tags: exchange, mapi, outlook, red-team, offensive-security, pentesting, linux, macos

## Member repositories
- sensepost/ruler (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:36.645467+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:39:29.305951+00:00, confidence not recorded.
  - readme: https://github.com/sensepost/ruler (fetched 2026-08-28T04:06:36.645467+00:00, sha 0dff76e777f4)
- Data as of 2026-08-30T08:39:29.467469+00:00.
