Microsoft 365Detection & ResponseRetrospectives

Detecting Exchange Server Exploitation: Defender XDR and Sentinel Hunting Queries

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from March 2021, written in 2026 with the benefit of hindsight.

Exchange Server exploitation typically results in web shells and suspicious processes spawned by IIS worker processes. These are the key detections.

Signals worth watching

  • The IIS worker process (w3wp.exe) or Exchange processes (UMWorkerProcess.exe) spawning cmd.exe, powershell.exe or other unusual processes.
  • New .aspx files in Exchange web directories (for example under inetpub\wwwroot\aspnet_client or the Exchange FrontEnd\HttpProxy folders).
  • Suspicious requests in IIS logs to autodiscover or ECP endpoints matching published exploitation patterns.
  • LSASS memory access from Exchange servers.
  • Exports of mailboxes via PowerShell (New-MailboxExportRequest) not initiated by admins.

Where the data lives

  • Defender for Endpoint on Exchange servers.
  • IIS logs and Exchange logs (forwarded to Sentinel).
  • Windows event logs (MSExchange Management for cmdlet usage).

A starting query

DeviceProcessEvents
| where InitiatingProcessFileName in~ ("w3wp.exe", "UMWorkerProcess.exe")
| where FileName in~ ("cmd.exe", "powershell.exe", "pwsh.exe", "rundll32.exe", "certutil.exe")
| project Timestamp, DeviceName, InitiatingProcessFileName, FileName, ProcessCommandLine

File creation in web directories

DeviceFileEvents
| where FolderPath has_any (@"\inetpub\wwwroot\", @"\FrontEnd\HttpProxy\")
| where FileName endswith ".aspx" and ActionType == "FileCreated"

Response

  1. Isolate the server.
  2. Remove web shells and other persistence; consider rebuilding.
  3. Review mailbox exports and mail access.
  4. Reset credentials used on the server, and check Active Directory for new accounts or changes.
detect exchange server exploitationProxyLogon2021

More on this story