Mailbox Client Access Setting (CAS) changed
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Windows Event Collector OR XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Collection (TA0009)
ATT&CK Technique
Data Staged: Local Data Staging (T1074.001)
Severity
Medium
Description
An attacker may use PowerShell to change the Client Access Settings (CAS) for a mailbox, hence gaining access to the data.
Attacker's Goals
Gain access to the data in the compromised mailbox.
Investigative actions
Examine the PowerShell command to identify which mailbox's access setting has been modified.
Verify that the change in the client access setting was executed by a trusted source.
PreviousMachine account was added to a domain admins group
NextMailbox enumeration activity by Azure application
Was this helpful?
