Exchange PowerShell Snap-Ins Usage

 Original Source: [Sigma source]
Title: Exchange PowerShell Snap-Ins Usage
Status: test
Description:Detects adding and using Exchange PowerShell snap-ins to export mailbox data. As seen used by HAFNIUM and APT27
References:
  -https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/
  -https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/
  -https://www.intrinsec.com/apt27-analysis/
Author: FPT.EagleEye, Nasreddine Bencherchali (Nextron Systems)
Date: 2021-03-03
modified:2023-03-24
Tags:
  • -'attack.execution'
  • -'attack.t1059.001'
  • -'attack.collection'
  • -'attack.t1114'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    - Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
    - OriginalFileName:
      - 'PowerShell.EXE'
      - 'pwsh.dll'
  selection_cli:
    CommandLine|contains: 'Add-PSSnapin'
  selection_module:
    CommandLine|contains:
      -'Microsoft.Exchange.Powershell.Snapin'
      -'Microsoft.Exchange.Management.PowerShell.SnapIn'

  filter_msiexec:
    ParentImage: 'C:\Windows\System32\msiexec.exe'
    CommandLine|contains: '$exserver=Get-ExchangeServer ([Environment]::MachineName) -ErrorVariable exerr 2> $null'
  condition:all of selection_* and not 1 of filter_*
Falsepositives:
  -Unknown
Level: high