For the complete documentation index, see llms.txt. This page is also available as Markdown.

Mailbox Client Access Setting (CAS) changed

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Requires one of the following data sources: Windows Event Collector OR XDR Agent with eXtended Threat Hunting (XTH)

ATT&CK Tactic

Collection (TA0009)

ATT&CK Technique

Data Staged: Local Data Staging (T1074.001)

Severity

Medium

Description

An attacker may use PowerShell to change the Client Access Settings (CAS) for a mailbox, hence gaining access to the data.

Attacker's Goals

Gain access to the data in the compromised mailbox.

Investigative actions

  • Examine the PowerShell command to identify which mailbox's access setting has been modified.

  • Verify that the change in the client access setting was executed by a trusted source.

Was this helpful?