Vendor: Microsoft
November 7, 2023 · View on GitHub
Product: Exchange
| Rules | Models | MITRE ATT&CK® TTPs | Event Types | Parsers |
|---|---|---|---|---|
| 138 | 63 | 11 | 9 | 9 |
MITRE ATT&CK® Framework for Enterprise
| Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
|---|---|---|---|---|---|---|---|---|---|---|---|
| External Remote Services Valid Accounts Exploit Public Fasing Application | External Remote Services Valid Accounts Account Manipulation Account Manipulation: Exchange Email Delegate Permissions | Valid Accounts | Valid Accounts | Email Collection Email Collection: Email Forwarding Rule | Proxy: Multi-hop Proxy Application Layer Protocol Proxy | Exfiltration Over Alternative Protocol Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol Automated Exfiltration |