Detection and response for the actively exploited ProxyShell vulnerabilities
ID: 81a865d3-d6a3-52cc-9a35-62d866288d4e
STIX ID: report--81a865d3-d6a3-52cc-9a35-62d866288d4e
Feed Name: Elastic Security Labs
Threat Score
On August 21, 2021 CISA warned of active exploitation of ProxyShell Exchange vulnerabilities (CVE-2021-31207, CVE-2021-34473, CVE-2021-34523) that attackers chain to compromise unpatched Microsoft Exchange servers; security vendors and researchers observed post-exploitation activity including ransomware deployment, and Elastic Security published IoCs and telemetry details for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
