Log sources › m365:exchange
m365:exchange
Inverted view: what can be detected if this is the log you have. Office Suite, Windows
12
channels
12
analytics
11
techniques
6
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
Admin Audit Logs, Transport Rules |
DC0038 Application Log Content | AN0740 | 1 |
Cmdlet - New-InboxRule |
DC0070 Cloud Service Metadata | AN1589 | 1 |
External sender message followed by user action involving links or attachments |
DC0038 Application Log Content | AN2033 | 1 |
FailedLogin |
DC0002 User Account Authentication | AN1342 | 1 |
Get-RoleGroup, Get-DistributionGroup |
DC0064 Command Execution | AN0696 | 1 |
Logon failure |
DC0002 User Account Authentication | AN1269 | 1 |
MailDelivery: High-frequency delivery of messages or attachments to a single recipient |
DC0038 Application Log Content | AN1010 | 1 |
Mailbox access using SAML token without corresponding MFA event |
DC0007 Web Credential Usage | AN0422 | 1 |
MessageTrace logs |
DC0038 Application Log Content | AN1312 | 1 |
New-InboxRule: Automation that triggers abnormal forwarding or external link generation |
DC0038 Application Log Content | AN1054 | 1 |
Remove-InboxRule, Clear-Mailbox |
DC0012 Scheduled Job Modification | AN0525 | 1 |
Transport Rule Modification |
DC0038 Application Log Content | AN0737 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1069.003 Cloud Groups | discovery | 1 | 0 |
| T1070 Indicator Removal | stealth | 20 | 3 |
| T1070.008 Clear Mailbox Data | stealth | 2 | 0 |
| T1110.003 Password Spraying | credential access | 0 | 0 |
| T1110.004 Credential Stuffing | credential access | 0 | 0 |
| T1114 Email Collection | collection | 4 | 3 |
| T1114.003 Email Forwarding Rule | collection | 6 | 0 |
| T1606.002 SAML Tokens | credential access | 0 | 0 |
| T1648 Serverless Execution | execution | 0 | 0 |
| T1667 Email Bombing | impact | 0 | 0 |
| T1684 Social Engineering | stealth | 0 | 0 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2020-0688 | Microsoft Exchange Server | T1114 | Mapped |
| CVE-2021-45382 | D-Link Multiple Routers | T1070 | Mapped |
| CVE-2022-41128 | Microsoft Windows | T1070 | Mapped |
| CVE-2023-1389 | TP-Link Archer AX21 | T1070 | Mapped |
| CVE-2024-27443 | Synacor Zimbra Collaboration Suite (ZCS) | T1114 | Mapped |
| CVE-2024-42009 | Roundcube Webmail | T1114 | Mapped |