Microsoft IOC Detection Tool for Exchange Server Vulnerabilities

Read Time46 Second

Cybersecurity and Infrastructure Security Agency (CISA) - Defend Today, Secure Tomorrow

Microsoft IOC Detection Tool for Exchange Server Vulnerabilities
03/06/2021 09:05 AM EST

Original release date: March 6, 2021
Microsoft has released an updated script that scans Exchange log files for indicators of compromise (IOCs) associated with the vulnerabilities disclosed on March 2, 2021.

CISA is aware of widespread domestic and international exploitation of these vulnerabilities and strongly recommends organizations run the Test-ProxyLogon.ps1 script—as soon as possible—to help determine whether their systems are compromised. For additional information on the script, see Microsoft’s blog HAFNIUM targeting Exchange Servers with 0-day exploits.

For more information about these vulnerabilities and how to defend against their exploitation, see:

Microsoft Advisory: Multiple Security Updates Released for Exchange Server
Microsoft Blog: HAFNIUM targeting Exchange Servers with 0-day exploits
Microsoft GitHub Repository: CSS-Exchange
CISA Alert: Mitigate Microsoft Exchange Server Vulnerabilities
CISA Emergency Directive 21-02: Mitigate Microsoft Exchange On-Premises Product Vulnerabilities

This site uses Akismet to reduce spam. Learn how your comment data is processed.