Skip to content

Commit 7fed789

Browse files
Merge branch 'master' into add-wscript-startup-detection
2 parents 8a2a4e8 + 3c24078 commit 7fed789

File tree

34 files changed

+2718
-1983
lines changed

34 files changed

+2718
-1983
lines changed

.github/latest_archiver_output.md

Lines changed: 565 additions & 563 deletions
Large diffs are not rendered by default.

rules/windows/powershell/powershell_script/posh_ps_exchange_mailbox_smpt_forwarding_rule.yml renamed to deprecated/windows/posh_ps_exchange_mailbox_smpt_forwarding_rule.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,12 @@
11
title: Suspicious PowerShell Mailbox SMTP Forward Rule
22
id: 15b7abbb-8b40-4d01-9ee2-b51994b1d474
3-
status: test
3+
status: deprecated
44
description: Detects usage of the powerShell Set-Mailbox Cmdlet to set-up an SMTP forwarding rule.
55
references:
66
- https://m365internals.com/2022/10/07/hunting-in-on-premises-exchange-server-logs/
77
author: Nasreddine Bencherchali (Nextron Systems)
88
date: 2022-10-26
9+
modified: 2026-03-01
910
tags:
1011
- attack.exfiltration
1112
logsource:

0 commit comments

Comments
 (0)