[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2d0guIvfHIoBijGTdl1TmggQ273x29c6aLipL0GTwlU":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},666,"How do I compile the mapi_tool code for different .NET versions?","The `mapi_tool` is written in C# and can be compiled using the .NET `csc.exe` compiler. For .NET 3.5, use: `C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\csc.exe mapi_tool.cs \u002Fr:Microsoft.Office.Interop.Outlook.dll`. For .NET 4.0 or higher, use the path for `v4.0.30319` instead. Ensure the referenced `Microsoft.Office.Interop.Outlook.dll` matches the installed Outlook version; sample DLLs for Office 2010 and 2013 are provided in the repository.","\u003Cp>The `mapi_tool` is written in C# and can be compiled using the .NET `csc.exe` compiler. For .NET 3.5, use: `C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\csc.exe mapi_tool.cs \u002Fr:Microsoft.Office.Interop.Outlook.dll`. For .NET 4.0 or higher, use the path for `v4.0.30319` instead. Ensure the referenced `Microsoft.Office.Interop.Outlook.dll` matches the installed Outlook version; sample DLLs for Office 2010 and 2013 are provided in the repository.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Foutlook-mapi-development-guide\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-do-i-compile-the-mapi_tool-code-for-different-net-versions-1777482724961","compilation, mapi_tool, csc.exe, .NET 3.5, .NET 4.0, Outlook DLL",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},165,"Outlook MAPI Development Guide","outlook-mapi-development-guide","Learn to use Outlook MAPI for accessing Outlook resources, reading emails, and extending applications with C# code examples and open-source tools.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Outlook MAPI provides a set of interfaces for accessing Outlook, used to extend the development of Outlook applications. This article will introduce the basic usage of Outlook MAPI and open-source an implementation code of Outlook MAPI called mapi_tool to facilitate subsequent secondary development.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Basic Knowledge\u003C\u002Fli>\u003Cli>Using Outlook MAPI to Access Outlook Resources\u003C\u002Fli>\u003Cli>Open-Source Code mapi_tool\u003C\u002Fli>\u003Cli>Features of mapi_tool\u003C\u002Fli>\u003Cli>Exploitation Ideas in Various Environments\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basic Knowledge\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Foffice\u002Fclient-developer\u002Foutlook\u002Fmapi\u002Foutlook-mapi-reference\u003C\u002Fp>\u003Cp>Prerequisites for using Outlook MAPI: Requires installation of the Outlook client\u003C\u002Fp>\u003Cp>Differences between Outlook MAPI and EWS:\u003C\u002Fp>\u003Cul>\u003Cli>Outlook MAPI is used to access resources within the Outlook client\u003C\u002Fli>\u003Cli>EWS is used to access resources within the Exchange server\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For usage of EWS, refer to the previous article 'Exchange Web Service (EWS) Development Guide'\u003C\u002Fp>\u003Cp>User emails in the Outlook client are stored in files with the .ost extension, synchronized with the database in the Exchange server\u003C\u002Fp>\u003Cp>Default save location for .ost files: %LOCALAPPDATA%\\Microsoft\\Outlook\\\u003C\u002Fp>\u003Cp>MAPI mainly includes the following three functions:\u003C\u002Fp>\u003Cul>\u003Cli>Address Books, setting parameters such as E-mail type and protocol\u003C\u002Fli>\u003Cli>Transport, sending and receiving files\u003C\u002Fli>\u003Cli>Message Store, handling sending, receiving, and other information\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Accessing Outlook Resources Using Outlook MAPI\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Install the Outlook client and configure parameters\u003C\u002Fh3>\u003Ch3>2. Launch the Outlook client for user login\u003C\u002Fh3>\u003Ch3>3. Develop a program using C Sharp to implement the functionality of reading inbox emails\u003C\u002Fh3>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fdotnet\u002Fapi\u002Fmicrosoft.office.interop.outlook?view=outlook-pia\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Foffice\u002Fvba\u002Fapi\u002Foutlook.namespace\u003C\u002Fp>\u003Cp>Development environment: VS2015\u003C\u002Fp>\u003Cp>Create a new project, select Console Application, reference file: Microsoft.Office.Interop.Outlook.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After installing the Outlook client, Microsoft.Office.Interop.Outlook.dll can be obtained under C:\\Windows\\assembly\\GAC_MSIL\\Microsoft.Office.Interop.Outlook\\\u003C\u002Fp>\u003Cp>Microsoft.Office.Interop.Outlook.dll must match the version of Outlook\u003C\u002Fp>\u003Cp>In the file properties of Microsoft.Office.Interop.Outlook.dll - Details - Product name corresponds to the supported Outlook version, Product version corresponds to the specific Outlook version, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017273058_0_0ac0060e40.jpeg\">\u003C\u002Fp>\u003Cp>For the specific Outlook version corresponding to Product version, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002FExchange\u002Fnew-features\u002Fbuild-numbers-and-release-dates?redirectedfrom=MSDN&amp;view=exchserver-2019\u003C\u002Fp>\u003Cp>C Sharp code example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using Microsoft.Office.Interop.Outlook;\u003Cbr>namespace ConsoleApplication3\u003Cbr>{\u003Cbr>    class Program\u003Cbr>    {\u003Cbr>        static void Main(string[] args)\u003Cbr>        {\u003Cbr>            Microsoft.Office.Interop.Outlook.Application app = new Microsoft.Office.Interop.Outlook.Application();\u003Cbr>            Microsoft.Office.Interop.Outlook.NameSpace ns = app.GetNamespace(\"MAPI\");\u003Cbr>            Microsoft.Office.Interop.Outlook.MAPIFolder inbox = ns.GetDefaultFolder(Microsoft.Office.Interop.Outlook.OlDefaultFolders.olFolderInbox);\u003Cbr>            Microsoft.Office.Interop.Outlook.Items items = inbox.Items;\u003Cbr>            Console.WriteLine(\"Size:\" + inbox.Items.Count);\u003Cbr>            foreach (var item in items)\u003Cbr>            {\u003Cbr>                var mail = item as Microsoft.Office.Interop.Outlook.MailItem;\u003Cbr>                if (mail != null)\u003Cbr>                {\u003Cbr>                    if(mail.UnRead==true)\u003Cbr>                        Console.WriteLine(\"[+] UnRead Mail\");\u003Cbr>                    else\u003Cbr>                        Console.WriteLine(\"[+] Mail\");\u003Cbr>                    Console.WriteLine(\"[*] Subject:\" + mail.Subject);\u003Cbr>                    Console.WriteLine(\"[*] From:\" + mail.SenderName);\u003Cbr>                    Console.WriteLine(\"[*] To:\" + mail.To);\u003Cbr>                    Console.WriteLine(\"[*] CC:\" + mail.CC);\u003Cbr>                    Console.WriteLine(\"[*] ReceivedTime:\" + mail.ReceivedTime);\u003Cbr>                    if(mail.Attachments.Count&gt;0)\u003Cbr>                    {\u003Cbr>                        Console.WriteLine(\"[&gt;] Attachments:\" + mail.Attachments.Count);\u003Cbr>                        Microsoft.Office.Interop.Outlook.Attachments attachments = mail.Attachments;\u003Cbr>                        foreach (Microsoft.Office.Interop.Outlook.Attachment att in attachments)\u003Cbr>                        {\u003Cbr>                            Console.WriteLine(\"    Name:\" + att.FileName);\u003Cbr>                        }\u003Cbr>                    }\u003Cbr>                    Console.WriteLine(\"[*] Body:\\r\\n\" + mail.Body);\u003Cbr>                    Console.WriteLine(\"[*] OutlookVersion:\" + mail.OutlookVersion);\u003Cbr>                    Console.WriteLine(\"[*] EntryID:\" + mail.EntryID);\u003Cbr>                }\u003Cbr>            }\u003Cbr>        }\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After code execution, it will enumerate emails in the inbox and output the following content:\u003C\u002Fp>\u003Cul>\u003Cli>Number of inbox emails\u003C\u002Fli>\u003Cli>Read status\u003C\u002Fli>\u003Cli>Subject\u003C\u002Fli>\u003Cli>Sender\u003C\u002Fli>\u003Cli>Recipient\u003C\u002Fli>\u003Cli>CC\u003C\u002Fli>\u003Cli>Receipt time\u003C\u002Fli>\u003Cli>Attachment name\u003C\u002Fli>\u003Cli>Body content\u003C\u002Fli>\u003Cli>Outlook version\u003C\u002Fli>\u003Cli>EntryID\u003C\u002Fli>\u003C\u002Ful>\u003Cp>After code execution, the Outlook client will display a warning as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017292913_1_8f377791c0.jpeg\">\u003C\u002Fp>\u003Cp>After selecting 'Allow', inbox information is successfully obtained as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017325314_2_8a5df381a9.jpeg\">\u003C\u002Fp>\u003Cp>Reason for the pop-up warning: The antivirus software on the current system is inactive or expired.\u003C\u002Fp>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsupport.microsoft.com\u002Fen-us\u002Fhelp\u002F3189806\u002Fa-program-is-trying-to-send-an-e-mail-message-on-your-behalf-warning-i\u003C\u002Fp>\u003Ch4>Two methods to disable the warning:\u003C\u002Fh4>\u003Cp>1. Enable and update the antivirus software\u003C\u002Fp>\u003Cp>2. Modify the registry to disable the warning\u003C\u002Fp>\u003Cp>Registry location: HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Office\\\u003Cx.0>\\Outlook\\Security\u003C\u002Fx.0>\u003C\u002Fp>\u003Cp>Registry location for 32-bit Office installed on a 64-bit operating system: HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Office\\\u003Cx.0>\\Outlook\\Security\u003C\u002Fx.0>\u003C\u002Fp>\u003Cp>\u003Cx.0> should match the Office version, e.g., 14.0 for Office 2010, 15.0 for Office 2013\u003C\u002Fx.0>\u003C\u002Fp>\u003Cp>Registry entry: ObjectModelGuard, Type: REG_DWORD, Value: 2\u003C\u002Fp>\u003Ch4>Details to note when using:\u003C\u002Fh4>\u003Cp>1. The referenced Microsoft.Exchange.WebServices.dll must match the version of the Outlook client\u003C\u002Fp>\u003Cp>2. Under default configuration, some operations will not trigger a warning\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Cul>\u003Cli>List the number of emails in the inbox\u003C\u002Fli>\u003Cli>List email subjects\u003C\u002Fli>\u003Cli>List email receipt times\u003C\u002Fli>\u003Cli>List email attachment names\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>3. If the Outlook client is not running in the background\u003C\u002Fh4>\u003Cp>The program can read resources from the current Outlook client, but after obtaining resources, a prompt box will appear requesting credentials, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017376230_3_f739386c4f.jpeg\">\u003C\u002Fp>\u003Cp>If 'Remember credentials' is selected, subsequent operations will not require credential input. For usage of credentials, refer to the previous article 'Penetration Techniques - Obtaining Information from Credential Manager in Windows'\u003C\u002Fp>\u003Ch2>0x04 Open-source implementation code mapi_tool\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Code repository: An open-source project\u003C\u002Fp>\u003Cp>Regarding compilation, to increase versatility, the code supports compilation using csc.exe\u003C\u002Fp>\u003Cp>Supports .Net 3.5 or higher versions. Compilation command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\csc.exe mapi_tool.cs \u002Fr:Microsoft.Office.Interop.Outlook.dll\u003Cbr>or\u003Cbr>C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe mapi_tool.cs \u002Fr:Microsoft.Office.Interop.Outlook.dll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>For testing purposes, I have uploaded Microsoft.Office.Interop.Outlook.dll from Office 2010 and Microsoft.Office.Interop.Outlook.dll from Office 2013.\u003C\u002Fp>\u003Cp>In terms of functionality implementation, a distinction is made regarding whether security prompts are displayed.\u003C\u002Fp>\u003Cp>Features that do not trigger security prompts:\u003C\u002Fp>\u003Cul>\u003Cli>Retrieve the length of emails in all folders.\u003C\u002Fli>\u003Cli>Retrieve configuration information, including CurrentProfileName, ExchangeMailboxServerName, ExchangeMailboxServerVersion.\u003C\u002Fli>\u003Cli>List emails at a specified location, including email subject, receipt time, file names of attachments, and EntryID.\u003C\u002Fli>\u003Cli>List unread emails at a specified location, including email subject, receipt time, file names of attachments, and EntryID.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Features that trigger security prompts:\u003C\u002Fp>\u003Cul>\u003Cli>Retrieve configuration information, including Account-DisplayName, Account-SmtpAddress, Account-AutoDiscoverXml, Account-AccountType.\u003C\u002Fli>\u003Cli>Retrieve contact information.\u003C\u002Fli>\u003Cli>Retrieve GlobalAddress.\u003C\u002Fli>\u003Cli>List emails at a specified location, including email subject, sender, recipient, CC, receipt time, file names of attachments, body content, Outlook version, and EntryID.\u003C\u002Fli>\u003Cli>List unread emails at a specified location, including email subject, sender, recipient, CC, receipt time, file names of attachments, body content, Outlook version, and EntryID.\u003C\u002Fli>\u003Cli>Save attachments from a specified email.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>In code development, the following details need to be noted:\u003C\u002Fp>\u003Col>\u003Cli>Absolute path must be used when saving attachments\u003C\u002Fli>\u003Cli>When obtaining the contact list, the array starting position is 1, not 0\u003C\u002Fli>\u003Cli>When obtaining configuration information, the array starting position is 1, not 0\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x05 Exploitation Approaches in Multiple Environments\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Running Outlook Client\u003C\u002Fh3>\u003Cp>mapi_tool can access resources of the Outlook client; certain operations may trigger security prompts\u003C\u002Fp>\u003Cp>Two methods to disable security prompts:\u003C\u002Fp>\u003Cul>\u003Cli>Enable and update antivirus software\u003C\u002Fli>\u003Cli>Modify registry to disable warnings\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>Method to export all email information from Outlook client:\u003C\u002Fh4>\u003Cp>(1) Obtain ost file\u003C\u002Fp>\u003Cp>Default save location for ost files: %LOCALAPPDATA%\\Microsoft\\Outlook\\\u003C\u002Fp>\u003Cp>Cannot copy directly; prompted that file is in use\u003C\u002Fp>\u003Cp>Can use Joe Bialek's NinjaCopy to copy files that are in use\u003C\u002Fp>\u003Cp>(2) Convert ost file to pst file\u003C\u002Fp>\u003Cp>There are many tools, here is one: Advanced Exchange Recovery\u003C\u002Fp>\u003Cp>(3) Import pst file into Outlook client\u003C\u002Fp>\u003Ch3>2. Outlook client is not started\u003C\u002Fh3>\u003Cp>mapi_tool can be used to access resources of the Outlook client, certain operations may trigger security prompts\u003C\u002Fp>\u003Cp>If performing operations that require interaction with the server, such as obtaining configuration information, a prompt will appear requesting credentials. If the credential manager already stores the corresponding credentials, no prompt will appear\u003C\u002Fp>\u003Cp>Command to view saved credentials:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cmdkey \u002Flist\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Method to export all email information from Outlook client:\u003C\u002Fh4>\u003Cp>(1) Obtain ost file\u003C\u002Fp>\u003Cp>Can directly copy the ost file\u003C\u002Fp>\u003Cp>(2) Convert ost file to pst file\u003C\u002Fp>\u003Cp>Same method as above\u003C\u002Fp>\u003Cp>(3) Import pst file into Outlook client\u003C\u002Fp>\u003Cp>Same method as above\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method of accessing Outlook resources using Outlook MAPI, along with the open-source code mapi_tool, facilitating subsequent secondary development.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Outlook MAPI provides a set of interfaces for accessing Outlook, used to extend the development of Outlook applications. This article will introduce the basic usage of Outlook MAPI and open-source an implementation code of Outlook MAPI called mapi_tool to facilitate subsequent secondary development.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Basic Knowledge\u003C\u002Fli>\u003Cli>Using Outlook MAPI to Access Outlook Resources\u003C\u002Fli>\u003Cli>Open-Source Code mapi_tool\u003C\u002Fli>\u003Cli>Features of mapi_tool\u003C\u002Fli>\u003Cli>Exploitation Ideas in Various Environments\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basic Knowledge\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Foffice\u002Fclient-developer\u002Foutlook\u002Fmapi\u002Foutlook-mapi-reference\u003C\u002Fp>\u003Cp>Prerequisites for using Outlook MAPI: Requires installation of the Outlook client\u003C\u002Fp>\u003Cp>Differences between Outlook MAPI and EWS:\u003C\u002Fp>\u003Cul>\u003Cli>Outlook MAPI is used to access resources within the Outlook client\u003C\u002Fli>\u003Cli>EWS is used to access resources within the Exchange server\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For usage of EWS, refer to the previous article 'Exchange Web Service (EWS) Development Guide'\u003C\u002Fp>\u003Cp>User emails in the Outlook client are stored in files with the .ost extension, synchronized with the database in the Exchange server\u003C\u002Fp>\u003Cp>Default save location for .ost files: %LOCALAPPDATA%\\Microsoft\\Outlook\\\u003C\u002Fp>\u003Cp>MAPI mainly includes the following three functions:\u003C\u002Fp>\u003Cul>\u003Cli>Address Books, setting parameters such as E-mail type and protocol\u003C\u002Fli>\u003Cli>Transport, sending and receiving files\u003C\u002Fli>\u003Cli>Message Store, handling sending, receiving, and other information\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Accessing Outlook Resources Using Outlook MAPI\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Install the Outlook client and configure parameters\u003C\u002Fh3>\u003Ch3>2. Launch the Outlook client for user login\u003C\u002Fh3>\u003Ch3>3. Develop a program using C Sharp to implement the functionality of reading inbox emails\u003C\u002Fh3>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fdotnet\u002Fapi\u002Fmicrosoft.office.interop.outlook?view=outlook-pia\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Foffice\u002Fvba\u002Fapi\u002Foutlook.namespace\u003C\u002Fp>\u003Cp>Development environment: VS2015\u003C\u002Fp>\u003Cp>Create a new project, select Console Application, reference file: Microsoft.Office.Interop.Outlook.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After installing the Outlook client, Microsoft.Office.Interop.Outlook.dll can be obtained under C:\\Windows\\assembly\\GAC_MSIL\\Microsoft.Office.Interop.Outlook\\\u003C\u002Fp>\u003Cp>Microsoft.Office.Interop.Outlook.dll must match the version of Outlook\u003C\u002Fp>\u003Cp>In the file properties of Microsoft.Office.Interop.Outlook.dll - Details - Product name corresponds to the supported Outlook version, Product version corresponds to the specific Outlook version, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017273058_0_0ac0060e40-1.jpeg\">\u003C\u002Fp>\u003Cp>For the specific Outlook version corresponding to Product version, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002FExchange\u002Fnew-features\u002Fbuild-numbers-and-release-dates?redirectedfrom=MSDN&amp;view=exchserver-2019\u003C\u002Fp>\u003Cp>C Sharp code example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using Microsoft.Office.Interop.Outlook;\u003Cbr>namespace ConsoleApplication3\u003Cbr>{\u003Cbr>    class Program\u003Cbr>    {\u003Cbr>        static void Main(string[] args)\u003Cbr>        {\u003Cbr>            Microsoft.Office.Interop.Outlook.Application app = new Microsoft.Office.Interop.Outlook.Application();\u003Cbr>            Microsoft.Office.Interop.Outlook.NameSpace ns = app.GetNamespace(\"MAPI\");\u003Cbr>            Microsoft.Office.Interop.Outlook.MAPIFolder inbox = ns.GetDefaultFolder(Microsoft.Office.Interop.Outlook.OlDefaultFolders.olFolderInbox);\u003Cbr>            Microsoft.Office.Interop.Outlook.Items items = inbox.Items;\u003Cbr>            Console.WriteLine(\"Size:\" + inbox.Items.Count);\u003Cbr>            foreach (var item in items)\u003Cbr>            {\u003Cbr>                var mail = item as Microsoft.Office.Interop.Outlook.MailItem;\u003Cbr>                if (mail != null)\u003Cbr>                {\u003Cbr>                    if(mail.UnRead==true)\u003Cbr>                        Console.WriteLine(\"[+] UnRead Mail\");\u003Cbr>                    else\u003Cbr>                        Console.WriteLine(\"[+] Mail\");\u003Cbr>                    Console.WriteLine(\"[*] Subject:\" + mail.Subject);\u003Cbr>                    Console.WriteLine(\"[*] From:\" + mail.SenderName);\u003Cbr>                    Console.WriteLine(\"[*] To:\" + mail.To);\u003Cbr>                    Console.WriteLine(\"[*] CC:\" + mail.CC);\u003Cbr>                    Console.WriteLine(\"[*] ReceivedTime:\" + mail.ReceivedTime);\u003Cbr>                    if(mail.Attachments.Count&gt;0)\u003Cbr>                    {\u003Cbr>                        Console.WriteLine(\"[&gt;] Attachments:\" + mail.Attachments.Count);\u003Cbr>                        Microsoft.Office.Interop.Outlook.Attachments attachments = mail.Attachments;\u003Cbr>                        foreach (Microsoft.Office.Interop.Outlook.Attachment att in attachments)\u003Cbr>                        {\u003Cbr>                            Console.WriteLine(\"    Name:\" + att.FileName);\u003Cbr>                        }\u003Cbr>                    }\u003Cbr>                    Console.WriteLine(\"[*] Body:\\r\\n\" + mail.Body);\u003Cbr>                    Console.WriteLine(\"[*] OutlookVersion:\" + mail.OutlookVersion);\u003Cbr>                    Console.WriteLine(\"[*] EntryID:\" + mail.EntryID);\u003Cbr>                }\u003Cbr>            }\u003Cbr>        }\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After code execution, it will enumerate emails in the inbox and output the following content:\u003C\u002Fp>\u003Cul>\u003Cli>Number of inbox emails\u003C\u002Fli>\u003Cli>Read status\u003C\u002Fli>\u003Cli>Subject\u003C\u002Fli>\u003Cli>Sender\u003C\u002Fli>\u003Cli>Recipient\u003C\u002Fli>\u003Cli>CC\u003C\u002Fli>\u003Cli>Receipt time\u003C\u002Fli>\u003Cli>Attachment name\u003C\u002Fli>\u003Cli>Body content\u003C\u002Fli>\u003Cli>Outlook version\u003C\u002Fli>\u003Cli>EntryID\u003C\u002Fli>\u003C\u002Ful>\u003Cp>After code execution, the Outlook client will display a warning as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017292913_1_8f377791c0-1.jpeg\">\u003C\u002Fp>\u003Cp>After selecting 'Allow', inbox information is successfully obtained as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017325314_2_8a5df381a9-1.jpeg\">\u003C\u002Fp>\u003Cp>Reason for the pop-up warning: The antivirus software on the current system is inactive or expired.\u003C\u002Fp>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsupport.microsoft.com\u002Fen-us\u002Fhelp\u002F3189806\u002Fa-program-is-trying-to-send-an-e-mail-message-on-your-behalf-warning-i\u003C\u002Fp>\u003Ch4>Two methods to disable the warning:\u003C\u002Fh4>\u003Cp>1. Enable and update the antivirus software\u003C\u002Fp>\u003Cp>2. Modify the registry to disable the warning\u003C\u002Fp>\u003Cp>Registry location: HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Office\\\u003Cx.0>\\Outlook\\Security\u003C\u002Fx.0>\u003C\u002Fp>\u003Cp>Registry location for 32-bit Office installed on a 64-bit operating system: HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Office\\\u003Cx.0>\\Outlook\\Security\u003C\u002Fx.0>\u003C\u002Fp>\u003Cp>\u003Cx.0> should match the Office version, e.g., 14.0 for Office 2010, 15.0 for Office 2013\u003C\u002Fx.0>\u003C\u002Fp>\u003Cp>Registry entry: ObjectModelGuard, Type: REG_DWORD, Value: 2\u003C\u002Fp>\u003Ch4>Details to note when using:\u003C\u002Fh4>\u003Cp>1. The referenced Microsoft.Exchange.WebServices.dll must match the version of the Outlook client\u003C\u002Fp>\u003Cp>2. Under default configuration, some operations will not trigger a warning\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Cul>\u003Cli>List the number of emails in the inbox\u003C\u002Fli>\u003Cli>List email subjects\u003C\u002Fli>\u003Cli>List email receipt times\u003C\u002Fli>\u003Cli>List email attachment names\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>3. If the Outlook client is not running in the background\u003C\u002Fh4>\u003Cp>The program can read resources from the current Outlook client, but after obtaining resources, a prompt box will appear requesting credentials, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017376230_3_f739386c4f-1.jpeg\">\u003C\u002Fp>\u003Cp>If 'Remember credentials' is selected, subsequent operations will not require credential input. For usage of credentials, refer to the previous article 'Penetration Techniques - Obtaining Information from Credential Manager in Windows'\u003C\u002Fp>\u003Ch2>0x04 Open-source implementation code mapi_tool\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Code repository: An open-source project\u003C\u002Fp>\u003Cp>Regarding compilation, to increase versatility, the code supports compilation using csc.exe\u003C\u002Fp>\u003Cp>Supports .Net 3.5 or higher versions. Compilation command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\csc.exe mapi_tool.cs \u002Fr:Microsoft.Office.Interop.Outlook.dll\u003Cbr>or\u003Cbr>C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe mapi_tool.cs \u002Fr:Microsoft.Office.Interop.Outlook.dll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>For testing purposes, I have uploaded Microsoft.Office.Interop.Outlook.dll from Office 2010 and Microsoft.Office.Interop.Outlook.dll from Office 2013.\u003C\u002Fp>\u003Cp>In terms of functionality implementation, a distinction is made regarding whether security prompts are displayed.\u003C\u002Fp>\u003Cp>Features that do not trigger security prompts:\u003C\u002Fp>\u003Cul>\u003Cli>Retrieve the length of emails in all folders.\u003C\u002Fli>\u003Cli>Retrieve configuration information, including CurrentProfileName, ExchangeMailboxServerName, ExchangeMailboxServerVersion.\u003C\u002Fli>\u003Cli>List emails at a specified location, including email subject, receipt time, file names of attachments, and EntryID.\u003C\u002Fli>\u003Cli>List unread emails at a specified location, including email subject, receipt time, file names of attachments, and EntryID.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Features that trigger security prompts:\u003C\u002Fp>\u003Cul>\u003Cli>Retrieve configuration information, including Account-DisplayName, Account-SmtpAddress, Account-AutoDiscoverXml, Account-AccountType.\u003C\u002Fli>\u003Cli>Retrieve contact information.\u003C\u002Fli>\u003Cli>Retrieve GlobalAddress.\u003C\u002Fli>\u003Cli>List emails at a specified location, including email subject, sender, recipient, CC, receipt time, file names of attachments, body content, Outlook version, and EntryID.\u003C\u002Fli>\u003Cli>List unread emails at a specified location, including email subject, sender, recipient, CC, receipt time, file names of attachments, body content, Outlook version, and EntryID.\u003C\u002Fli>\u003Cli>Save attachments from a specified email.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>In code development, the following details need to be noted:\u003C\u002Fp>\u003Col>\u003Cli>Absolute path must be used when saving attachments\u003C\u002Fli>\u003Cli>When obtaining the contact list, the array starting position is 1, not 0\u003C\u002Fli>\u003Cli>When obtaining configuration information, the array starting position is 1, not 0\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x05 Exploitation Approaches in Multiple Environments\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Running Outlook Client\u003C\u002Fh3>\u003Cp>mapi_tool can access resources of the Outlook client; certain operations may trigger security prompts\u003C\u002Fp>\u003Cp>Two methods to disable security prompts:\u003C\u002Fp>\u003Cul>\u003Cli>Enable and update antivirus software\u003C\u002Fli>\u003Cli>Modify registry to disable warnings\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>Method to export all email information from Outlook client:\u003C\u002Fh4>\u003Cp>(1) Obtain ost file\u003C\u002Fp>\u003Cp>Default save location for ost files: %LOCALAPPDATA%\\Microsoft\\Outlook\\\u003C\u002Fp>\u003Cp>Cannot copy directly; prompted that file is in use\u003C\u002Fp>\u003Cp>Can use Joe Bialek's NinjaCopy to copy files that are in use\u003C\u002Fp>\u003Cp>(2) Convert ost file to pst file\u003C\u002Fp>\u003Cp>There are many tools, here is one: Advanced Exchange Recovery\u003C\u002Fp>\u003Cp>(3) Import pst file into Outlook client\u003C\u002Fp>\u003Ch3>2. Outlook client is not started\u003C\u002Fh3>\u003Cp>mapi_tool can be used to access resources of the Outlook client, certain operations may trigger security prompts\u003C\u002Fp>\u003Cp>If performing operations that require interaction with the server, such as obtaining configuration information, a prompt will appear requesting credentials. If the credential manager already stores the corresponding credentials, no prompt will appear\u003C\u002Fp>\u003Cp>Command to view saved credentials:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cmdkey \u002Flist\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Method to export all email information from Outlook client:\u003C\u002Fh4>\u003Cp>(1) Obtain ost file\u003C\u002Fp>\u003Cp>Can directly copy the ost file\u003C\u002Fp>\u003Cp>(2) Convert ost file to pst file\u003C\u002Fp>\u003Cp>Same method as above\u003C\u002Fp>\u003Cp>(3) Import pst file into Outlook client\u003C\u002Fp>\u003Cp>Same method as above\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method of accessing Outlook resources using Outlook MAPI, along with the open-source code mapi_tool, facilitating subsequent secondary development.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",830,"Onedaysec",6,"published","2026-02-02T07:38:21.454Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Outlook MAPI Development Guide: Access & Extend Outlook Apps","Outlook MAPI, C# development, email access, .ost files, Outlook client, MAPI functions, mapi_tool, Exchange integration",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46,47],665,664,663,662,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.003Z","2026-07-23T16:01:56.240Z","draft","2026-07-23T16:14:04.704Z"]