Abusing Exchange Mailbox Permissions with MailSniper
ID: f22e37c8-79c2-5153-8edb-d47bbec4b23e
STIX ID: report--f22e37c8-79c2-5153-8edb-d47bbec4b23e
Feed Name: Black Hills Infosec Blog
Threat Score
This report describes how Outlook/Exchange mailbox folder permissions (notably the "Default" entry) can be mistakenly set to allow organization-wide access, and shows how the MailSniper tool can enumerate and read such mailboxes across on-prem Exchange and Office365 using Invoke-OpenInboxFinder and a modified Invoke-SelfSearch; it includes examples, usage instructions, and remediation recommendations such as auditing mailbox permissions and applying GPO restrictions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
