For the complete documentation index, see llms.txt. This page is also available as Markdown.

PowerShell used to remove mailbox export request logs

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Requires one of the following data sources: Windows Event Collector OR XDR Agent with eXtended Threat Hunting (XTH)

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

Command and Scripting Interpreter: PowerShell (T1059.001)

Severity

High

Description

An attacker may use PowerShell to remove evidence of an export request for a mailbox as part of the clean-up stage.

Attacker's Goals

Remove evidence for mailbox export commands.

Investigative actions

  • Examine the PowerShell command to identify which mailbox has been compromised.

  • Investigate the host that executes the command for potential further exploitation.

Was this helpful?