logo

Stopping attacks against on-premises Exchange Server and SharePoint Server with AMSI

ID: e8ce9331-3ed6-5d63-9153-f5ec3504f523

STIX ID: report--e8ce9331-3ed6-5d63-9153-f5ec3504f523

Feed Name: Microsoft Security

Threat Score
75/100

Date Published: 2025-04-09

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft describes active, high-impact exploitation techniques targeting on-premises Exchange and SharePoint servers—including SSRF (ProxyShell/ProxyNotShell), NTLM relay, web shells, EWS-based mailbox exfiltration, insecure deserialization and BDC-based RCE—while introducing AMSI request-body scanning as a defensive layer, providing detections, mitigation guidance, and hunting queries to help SecOps detect and remediate these attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.