Detecting Exchange Server RCE: Defender XDR and Sentinel Hunting Queries
Retrospective: this article looks back at events from August 2021, written in 2026 with the benefit of hindsight.
Remote code execution against Exchange servers leaves traces in IIS logs, process activity and the file system. These detections complement patching.
Signals worth watching
- Requests to
/autodiscover/autodiscover.jsoncontaining suspicious paths or@characters followed by PowerShell endpoints — a pattern associated with ProxyShell. - New mailbox export requests or
New-MailboxExportRequestcmdlets not run by known admins. .aspxor.aspx-like files appearing in Exchange web folders.- Exchange processes spawning shells or downloading tools.
- Creation of new accounts or role assignments on Exchange servers.
Where the data lives
- IIS logs on Exchange servers.
- MSExchange Management event logs (cmdlet auditing).
- Defender for Endpoint process and file events.
A starting query
Mailbox export requests:
DeviceProcessEvents
| where ProcessCommandLine has "New-MailboxExportRequest"
| project Timestamp, DeviceName, AccountName, ProcessCommandLine
Combine with Exchange admin audit logs, which record cmdlets run against the organization.
IIS log hunting
Search IIS logs for requests to the autodiscover endpoint that include powershell in the URL, and for POST requests to unusual .aspx files.
Response
- Isolate and patch.
- Remove web shells and review mailbox exports.
- Run Microsoft's Exchange on-premises mitigation and scanning tools where applicable.
- Reset credentials and check Active Directory for changes.
- ProxyShell (Aug 2021): Exchange Server Exploited Again Incident Teardowns
- How to Build an Emergency Patching Process for Internet-Facing Servers How-To & Hardening
- CIO Brief: Repeated Exchange Zero-Days — A Signal to Move to the Cloud CIO Briefings