kevmap

Log sources › m365:exchange

m365:exchange

Inverted view: what can be detected if this is the log you have. Office Suite, Windows

12
channels
12
analytics
11
techniques
6
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
Admin Audit Logs, Transport Rules DC0038 Application Log Content AN0740 1
Cmdlet - New-InboxRule DC0070 Cloud Service Metadata AN1589 1
External sender message followed by user action involving links or attachments DC0038 Application Log Content AN2033 1
FailedLogin DC0002 User Account Authentication AN1342 1
Get-RoleGroup, Get-DistributionGroup DC0064 Command Execution AN0696 1
Logon failure DC0002 User Account Authentication AN1269 1
MailDelivery: High-frequency delivery of messages or attachments to a single recipient DC0038 Application Log Content AN1010 1
Mailbox access using SAML token without corresponding MFA event DC0007 Web Credential Usage AN0422 1
MessageTrace logs DC0038 Application Log Content AN1312 1
New-InboxRule: Automation that triggers abnormal forwarding or external link generation DC0038 Application Log Content AN1054 1
Remove-InboxRule, Clear-Mailbox DC0012 Scheduled Job Modification AN0525 1
Transport Rule Modification DC0038 Application Log Content AN0737 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1069.003 Cloud Groupsdiscovery10
T1070 Indicator Removalstealth203
T1070.008 Clear Mailbox Datastealth20
T1110.003 Password Sprayingcredential access00
T1110.004 Credential Stuffingcredential access00
T1114 Email Collectioncollection43
T1114.003 Email Forwarding Rulecollection60
T1606.002 SAML Tokenscredential access00
T1648 Serverless Executionexecution00
T1667 Email Bombingimpact00
T1684 Social Engineeringstealth00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2020-0688Microsoft Exchange Server T1114 Mapped
CVE-2021-45382D-Link Multiple Routers T1070 Mapped
CVE-2022-41128Microsoft Windows T1070 Mapped
CVE-2023-1389TP-Link Archer AX21 T1070 Mapped
CVE-2024-27443Synacor Zimbra Collaboration Suite (ZCS) T1114 Mapped
CVE-2024-42009Roundcube Webmail T1114 Mapped