-
Triage
-
Microsoft
-
Rapid7
-
CrowdStrike
-
FireEye
-
Microsoft
-
365-Defender-Hunting-Queries
-
IOC Feed
-
https://github.com/microsoft/CSS-Exchange/blob/main/Security/src/Test-ProxyLogon.ps1
-
-
CERT-LV
-
Neo23x0
-
Unit221b
-
Trustedsec
-
Microsoft
-
jsdryan
-
Rapid7
-
https://msrc-blog.microsoft.com/2021/03/02/multiple-security-updates-released-for-exchange-server/
- CVE-2021-26855
CVE-2021-26857
CVE-2021-26858
CVE-2021-27065
- CVE-2021-26855
-
CVE-2021-26855
-
CVE-2021-27065
-
https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/
-
TTP
-
Command & Control
-
Exfiltration
- MEGA
-
Execution
-
-