For the complete documentation index, see llms.txt. This page is also available as Markdown.

PowerShell used to export mailbox contents

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Requires one of the following data sources: Windows Event Collector OR XDR Agent with eXtended Threat Hunting (XTH)

ATT&CK Tactic

Collection (TA0009)

ATT&CK Technique

Data Staged: Local Data Staging (T1074.001)

Severity

Medium

Description

An attacker may use PowerShell to export the contents of a mailbox as part of the data staging before exfiltration.

Attacker's Goals

Export the content of a mailbox, preparing for data exfiltration.

Investigative actions

  • Examine the PowerShell command to identify which mailbox has been exported.

  • Verify that this command was executed by a trusted source.

Was this helpful?