%3CLINGO-SUB%20id%3D%22lingo-sub-1487410%22%20slang%3D%22en-US%22%3EImproving%20defenses%20against%20Exchange%20server%20compromise%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1487410%22%20slang%3D%22en-US%22%3E%3CP%3EExchange%20servers%20are%20high-value%20targets%20for%20attackers.%20If%20compromised%2C%20Exchange%20servers%20provide%20a%20unique%20environment%20that%20could%20allow%20attackers%20to%20perform%20various%20tasks%20using%20the%20same%20built-in%20tools%20or%20scripts%20that%20admins%20use%20for%20maintenance.%26nbsp%3BThis%20is%20exacerbated%20by%20the%20fact%20that%20Exchange%20servers%20have%20traditionally%20lacked%20antivirus%20solutions%2C%20network%20protection%2C%20the%20latest%20security%20updates%2C%20and%20proper%20security%20configuration%2C%20often%20intentionally%2C%20due%20to%20the%20misguided%20notion%20that%20these%20protections%20interfere%20with%20normal%20Exchange%20functions.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIn%20April%2C%20Exchange-specific%20behavior-based%20detections%20in%20Microsoft%20Defender%20ATP%20showed%20attackers%20operating%20on%20on-premises%20Exchange%20servers%20using%20deployed%20web%20shells.%20The%20attacks%20used%20multiple%20fileless%20techniques%2C%20adding%20another%20layer%20of%20complexity%20to%20detecting%20and%20resolving%20the%20threats%2C%20and%20demonstrating%20how%20behavior-based%20detections%20are%20key%20to%20protecting%20organizations.%3C%2FP%3E%0A%3CDIV%20id%3D%22tinyMceEditorEric%20Avena_0%22%20class%3D%22mceNonEditable%20lia-copypaste-placeholder%22%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Exchange-servers-attack-chain-2.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F200858i19B1A6B5E81F04A8%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22Exchange-servers-attack-chain-2.png%22%20alt%3D%22Exchange-servers-attack-chain-2.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E-ERR%3AREF-NOT-FOUND-Behavior-based%20blocking%20and%20containment%20capabilities%20in%20Microsoft%20Defender%20ATP%20stop%20many%20of%20the%20malicious%20activities%20associated%20with%20Exchange%20server%20attacks.%20In%20addition%2C%20endpoint%20detection%20and%20response%20(EDR)%20sensors%20provide%20visibility%20into%20other%20suspicious%20and%20malicious%20activities%20on%20Exchange%20servers.%20Detections%20are%20reported%20as%20alerts.%20The%20-ERR%3AREF-NOT-FOUND-new%20alert%20page%20presents%20data%20in%20an%20investigation-driven%20approach%20meant%20to%20empower%20SecOps%20teams%20to%20easily%20investigate%20and%20take%20actions.%3C%2FP%3E%0A%3CDIV%20id%3D%22tinyMceEditorEric%20Avena_1%22%20class%3D%22mceNonEditable%20lia-copypaste-placeholder%22%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Possible%20IIS%20web%20shell.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F200859iA61C50547C797391%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22Possible%20IIS%20web%20shell.png%22%20alt%3D%22Possible%20IIS%20web%20shell.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ETo%20get%20more%20guidance%20on%20improving%20defenses%20against%20Exchange%20server%20compromise%2C%20read%20%3CSTRONG%3E-ERR%3AREF-NOT-FOUND-Defending%20Exchange%20servers%20under%20attack%3C%2FSTRONG%3E.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-1487410%22%20slang%3D%22en-US%22%3E%3CP%3ESecuring%20Exchange%20servers%20is%20one%20of%20the%20most%20important%20things%20defenders%20can%20do%20to%20limit%20organizational%20exposure%20to%20attacks.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Exchange-servers-attack-chain-tech-comm.png%22%20style%3D%22width%3A%20370px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F200862i743AF812D3BDDFCC%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22Exchange-servers-attack-chain-tech-comm.png%22%20alt%3D%22Exchange-servers-attack-chain-tech-comm.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1487410%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EBehavioral%20blocking%20and%20containment%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Microsoft

Exchange servers are high-value targets for attackers. If compromised, Exchange servers provide a unique environment that could allow attackers to perform various tasks using the same built-in tools or scripts that admins use for maintenance. This is exacerbated by the fact that Exchange servers have traditionally lacked antivirus solutions, network protection, the latest security updates, and proper security configuration, often intentionally, due to the misguided notion that these protections interfere with normal Exchange functions.

 

In April, Exchange-specific behavior-based detections in Microsoft Defender ATP showed attackers operating on on-premises Exchange servers using deployed web shells. The attacks used multiple fileless techniques, adding another layer of complexity to detecting and resolving the threats, and demonstrating how behavior-based detections are key to protecting organizations.

 

Exchange-servers-attack-chain-2.png

 

Behavior-based blocking and containment capabilities in Microsoft Defender ATP stop many of the malicious activities associated with Exchange server attacks. In addition, endpoint detection and response (EDR) sensors provide visibility into other suspicious and malicious activities on Exchange servers. Detections are reported as alerts. The new alert page presents data in an investigation-driven approach meant to empower SecOps teams to easily investigate and take actions.

 

Possible IIS web shell.png

 

To get more guidance on improving defenses against Exchange server compromise, read Defending Exchange servers under attack.