Detecting Exchange Zero-Day: Defender XDR and Sentinel Hunting Queries
Retrospective: this article looks back at events from September 2022, written in 2026 with the benefit of hindsight.
Even after patching, exploited Exchange servers may still be compromised. These detections focus on post-exploitation behaviors common to ProxyNotShell and similar attacks.
Signals worth watching
- Remote PowerShell sessions to Exchange from non-admin accounts.
w3wp.exe(MSExchangePowerShellAppPool) spawning unexpected processes.- New web shells in Exchange or IIS directories.
- Autodiscover requests containing
powershellwith unusual patterns. - Creation of scheduled tasks or new local accounts on Exchange servers.
- Defender for Endpoint alerts referencing Exchange exploitation.
Where the data lives
- IIS logs (HttpProxy logs for autodiscover and PowerShell endpoints).
- Defender for Endpoint process and file events.
- Windows event logs (PowerShell operational logs).
A starting query
Processes launched by Exchange PowerShell app pools:
DeviceProcessEvents
| where InitiatingProcessFileName =~ "w3wp.exe"
| where InitiatingProcessCommandLine has "MSExchangePowerShellAppPool"
| where FileName !in~ ("conhost.exe", "csc.exe", "cvtres.exe")
| project Timestamp, DeviceName, FileName, ProcessCommandLine
Response
- Apply patches and confirm mitigations are in place.
- Hunt for web shells and remove them.
- Check for new accounts, mailbox permissions and transport rules.
- Reset credentials of accounts used in the attack.
- Disable remote PowerShell for non-admin users.
- ProxyNotShell (Sept 2022): The Third Major Exchange Zero-Day Wave Incident Teardowns
- How to Decommission the Last Exchange Server in a Hybrid Deployment How-To & Hardening
- CIO Brief: When to Finally Leave On-Prem Exchange CIO Briefings