Windows Exchange Management: Set-OabVirtualDirectory after ProxyLogon exploitation

Flags Exchange management command lines invoking Set-OabVirtualDirectory with suspicious external URL/script injection patterns.

FreeReviewedSigma · Critical · v2
Product
windows
Service
msexchange-management
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2021-08-09
Updated
2026-07-31

ATT&CK techniques

Resource Dev
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule matches command-line patterns consistent with a PowerShell Set-OabVirtualDirectory invocation that includes specific external URL and malicious page-load content markers. Attackers can use this behavior to modify Exchange virtual directory settings as part of post-exploitation activity following ProxyLogon. It relies on Windows msexchange-management telemetry capturing the executed command text and parameter substrings such as eval(request) and embedded script indicators.

Related detections9 linkedT1587.001 — drag to rearrange
Windows PUA CsExec Execution via Process Creation
Windows Office Startup Folder File Creation with Uncommon Extension
Windows: Executable Creates Executable via File Creation Events
Windows PsExec/PAExec Command-Line Flags Escalating to LOCAL SYSTEM
Windows Browser Process Creating VHD/VHDX Files via Download
Windows Process Creation: Detects Volume Shadow Copy Listing via vssadmin
Windows Process Creation: PsExec/PAExec Flags Indicating SYSTEM Execution
Windows Process Creation Matching Mustang Panda Dropper Command-Line and winwsh.exe
Windows Formbook-style process execution deleting dropped payloads from AppData Temp via cmd
Windows Exchange Management: Set-OabVirtualDirectory after ProxyLogon exploitation
Pivot detection · T1587.001 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.