Microsoft 365Detection & ResponseRetrospectives

Detecting Exchange Server RCE: Defender XDR and Sentinel Hunting Queries

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from August 2021, written in 2026 with the benefit of hindsight.

Remote code execution against Exchange servers leaves traces in IIS logs, process activity and the file system. These detections complement patching.

Signals worth watching

  • Requests to /autodiscover/autodiscover.json containing suspicious paths or @ characters followed by PowerShell endpoints — a pattern associated with ProxyShell.
  • New mailbox export requests or New-MailboxExportRequest cmdlets not run by known admins.
  • .aspx or .aspx-like files appearing in Exchange web folders.
  • Exchange processes spawning shells or downloading tools.
  • Creation of new accounts or role assignments on Exchange servers.

Where the data lives

  • IIS logs on Exchange servers.
  • MSExchange Management event logs (cmdlet auditing).
  • Defender for Endpoint process and file events.

A starting query

Mailbox export requests:

DeviceProcessEvents
| where ProcessCommandLine has "New-MailboxExportRequest"
| project Timestamp, DeviceName, AccountName, ProcessCommandLine

Combine with Exchange admin audit logs, which record cmdlets run against the organization.

IIS log hunting

Search IIS logs for requests to the autodiscover endpoint that include powershell in the URL, and for POST requests to unusual .aspx files.

Response

  1. Isolate and patch.
  2. Remove web shells and review mailbox exports.
  3. Run Microsoft's Exchange on-premises mitigation and scanning tools where applicable.
  4. Reset credentials and check Active Directory for changes.
detect exchange server rceProxyShell2021

More on this story