Detecting Exchange Server Exploitation: Defender XDR and Sentinel Hunting Queries
Exchange Server exploitation typically results in web shells and suspicious processes spawned by IIS worker processes. These are the key detections.
Insights
Articles in Detection & Response.
Exchange Server exploitation typically results in web shells and suspicious processes spawned by IIS worker processes. These are the key detections.
Exposed administrator credentials are often used soon after discovery. Detecting both the exposure and the misuse helps you respond before damage spreads.
A compromised third-party integration can access your tenant with the app's permissions. These detections focus on unusual behavior by third-party apps.
Golden SAML attacks forge tokens with a stolen AD FS signing certificate, letting attackers sign in to Microsoft 365 as anyone. These detections help...
Attackers who compromise applications or service principals can access data across a tenant without user sign-ins. Detecting credential and permission...
Attacks on Active Directory — including Zerologon exploitation, DCSync and Kerberos abuse — leave specific traces. Microsoft Defender for Identity and...
Attackers who social-engineer employees often go straight for administrative tools. Detecting unusual admin access helps you catch them before they act.
Illicit consent grants give attackers persistent access to Microsoft 365 data. Detecting them quickly is essential because password resets don't remove them.
You can't monitor a SaaS vendor's internal systems, but you can monitor signals that indicate rising risk — and your own exposure if something goes wrong.
Meeting disruption and eavesdropping are rare, but when they happen in sensitive meetings the impact is high. These detections help you spot unusual meeting...
Guest accounts and broad Teams access can quietly expose sensitive data. These detections highlight risky guest activity and sharing.
Data exposures from cloud servers and databases often go unnoticed until data appears for sale. These detections help you spot exposure and unusual data...
Exposed databases are often found by internet scanners within hours. Detecting public exposure — and unexpected access — quickly is critical.
Attackers exploiting VPN and remote access appliances often look like legitimate users. Detection focuses on suspicious sessions and what happens after them.
Stolen AWS API keys are frequently used for reconnaissance, data theft and resource abuse. These detections help you spot misuse quickly.
The Capital One attack path — SSRF to the metadata service, then stolen role credentials used to read data — leaves traces in CloudTrail and GuardDuty if...
Even with patches, exposed RDP invites brute force, credential stuffing and exploitation. Detecting both the exposure and attacks against it is essential...
A compromised help desk account — or a manipulated help desk agent — can reset credentials across your organization. Detecting unusual support activity...
Password spray attacks distribute attempts to avoid detection. Combining Entra ID's built-in detections with your own queries gives you the best chance of...
Marriott's attackers stayed inside Starwood's network for about four years. Long-dwell intruders are quiet by design. Hunting for them means looking for...
Token theft lets an attacker act as a user without their password or MFA. Detection focuses on tokens being used in ways that don't match the device and...
SMS codes can be intercepted through SIM swaps and phishing. You often can't see the interception itself, but you can detect what happens next: a sign-in...
OAuth apps with excessive permissions can read mail and files across your tenant without a password. Detecting risky consent grants is a core identity...
Password spraying tries a small number of common passwords against many accounts, staying below lockout thresholds. Detecting it requires looking across...