PowerShell used to remove mailbox export request logs
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Windows Event Collector OR XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
Command and Scripting Interpreter: PowerShell (T1059.001)
Severity
High
Description
An attacker may use PowerShell to remove evidence of an export request for a mailbox as part of the clean-up stage.
Attacker's Goals
Remove evidence for mailbox export commands.
Investigative actions
Examine the PowerShell command to identify which mailbox has been compromised.
Investigate the host that executes the command for potential further exploitation.
PreviousPowerShell used to export mailbox contents
NextPrivileged certificate request via certificate template
Was this helpful?
