Vendor: Microsoft

April 15, 2026 · View on GitHub

Product: Microsoft Exchange

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
1295415847
Use-CaseActivity Types/ParsersMITRE ATT&CK® TTPContent
Abnormal Authentication & Accessapp-activity
microsoft-exchange-json-email-receive-incoming
microsoft-exchange-csv-app-notification-hadiscard
microsoft-exchange-csv-app-notification-agentresubmit
microsoft-exchange-csv-app-notification-agentdefer
microsoft-exchange-csv-app-notification-agentinfo
microsoft-exchange-csv-app-notification-routingexpand
microsoft-exchange-csv-app-notification-routingtransfer
microsoft-exchange-csv-app-notification-processmeetingmessage
microsoft-exchange-csv-app-notification-success-smtpfail
microsoft-exchange-csv-app-notification-routingdrop
microsoft-exchange-csv-app-notification-dsn
microsoft-exchange-csv-app-notification-routing
microsoft-exchange-csv-app-notification-routingduplicateredirect
microsoft-exchange-csv-app-notification-transfer
microsoft-exchange-csv-app-notification-success-storedriver
microsoft-exchange-csv-app-notification-redirecting
microsoft-exchange-csv-app-notification-smtpharedirect
microsoft-exchange-csv-app-notification-success-safetynetresubmit
microsoft-exchange-csv-app-notification-smtpharedirectfail
microsoft-exchange-csv-app-notification-smtpdefer
microsoft-exchange-csv-app-notification-success-queuetransfer
microsoft-exchange-csv-app-notification-success-routingsuppressed
microsoft-exchange-csv-app-notification-success-queueresubmit
microsoft-exchange-str-app-activity-success-isaweblog
microsoft-o365-cef-app-file-success-modifiedproperties
microsoft-o365-sk4-app-activity-success-softdelete
microsoft-exchange-sk4-app-activity-success-harddelete
microsoft-o365-cef-app-file-success-modifiedproperties

app-login
microsoft-exchange-csv-app-authentication-success-server
microsoft-exchange-kv-app-login-success-serverexchange

authentication-successful
microsoft-exchange-kv-app-authentication-success-exserver
T1078 - Valid Accounts
T1133 - External Remote Services
  • 12 Rules
  • 4 Models
Account Manipulationapp-activity
microsoft-exchange-json-email-receive-incoming
microsoft-exchange-csv-app-notification-hadiscard
microsoft-exchange-csv-app-notification-agentresubmit
microsoft-exchange-csv-app-notification-agentdefer
microsoft-exchange-csv-app-notification-agentinfo
microsoft-exchange-csv-app-notification-routingexpand
microsoft-exchange-csv-app-notification-routingtransfer
microsoft-exchange-csv-app-notification-processmeetingmessage
microsoft-exchange-csv-app-notification-success-smtpfail
microsoft-exchange-csv-app-notification-routingdrop
microsoft-exchange-csv-app-notification-dsn
microsoft-exchange-csv-app-notification-routing
microsoft-exchange-csv-app-notification-routingduplicateredirect
microsoft-exchange-csv-app-notification-transfer
microsoft-exchange-csv-app-notification-success-storedriver
microsoft-exchange-csv-app-notification-redirecting
microsoft-exchange-csv-app-notification-smtpharedirect
microsoft-exchange-csv-app-notification-success-safetynetresubmit
microsoft-exchange-csv-app-notification-smtpharedirectfail
microsoft-exchange-csv-app-notification-smtpdefer
microsoft-exchange-csv-app-notification-success-queuetransfer
microsoft-exchange-csv-app-notification-success-routingsuppressed
microsoft-exchange-csv-app-notification-success-queueresubmit
microsoft-exchange-str-app-activity-success-isaweblog
microsoft-o365-cef-app-file-success-modifiedproperties
microsoft-o365-sk4-app-activity-success-softdelete
microsoft-exchange-sk4-app-activity-success-harddelete
microsoft-o365-cef-app-file-success-modifiedproperties
T1098 - Account Manipulation
T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
  • 3 Rules
  • 1 Models
Ransomwareapp-login
microsoft-exchange-csv-app-authentication-success-server
microsoft-exchange-kv-app-login-success-serverexchange

authentication-successful
microsoft-exchange-kv-app-authentication-success-exserver
T1078 - Valid Accounts
  • 1 Rules
Next Page -->>

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
External Remote Services

Valid Accounts

Exploit Public Fasing Application

External Remote Services

Valid Accounts

Account Manipulation

Account Manipulation: Exchange Email Delegate Permissions

Valid Accounts

Exploitation for Privilege Escalation

Obfuscated Files or Information: Indicator Removal from Tools

Valid Accounts

Obfuscated Files or Information

Email Collection

Email Collection: Email Forwarding Rule

Proxy: Multi-hop Proxy

Proxy

Exfiltration Over Alternative Protocol

Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol