Title:Suspicious MSExchangeMailboxReplication ASPX Write Status:test Description:Detects suspicious activity in which the MSExchangeMailboxReplication process writes .asp and .apsx files to disk, which could be a sign of ProxyShell exploitation References: -https://redcanary.com/blog/blackbyte-ransomware/ Author: Florian Roth (Nextron Systems) Date: 2022-02-25 modified:None Tags: