On-premises Microsoft Exchange sits at the intersection of the perimeter and Active Directory: it is internet-exposed (OWA, EWS, ActiveSync, Autodiscover), it authenticates every user, and it holds high privileges in AD by design (historically write access over the domain object). That combination makes it one of the most productive targets in a Windows estate: a foothold on Exchange, or even just coercing it, often leads straight to Domain Admin, and its mailboxes are a trove on their own.
Why Exchange matters to an attacker#
- It is externally reachable, so enumeration and password spraying work from the internet with no prior access.
- It runs privileged in AD: the Exchange servers and groups hold powerful rights, so compromising Exchange (or relaying its machine account) reaches the domain.
- It has suffered pre-authentication RCE chains (ProxyLogon, ProxyShell, ProxyNotShell) that give SYSTEM on the server directly.
- Its mailboxes contain credentials, internal intel, and the ability to send as trusted users.
Pages#
- Enumeration: finding users and the Global Address List through Autodiscover, OWA, and EWS.
- Password spraying: guessing credentials against OWA, EWS, and ActiveSync.
- RCE chains: ProxyLogon, ProxyShell, and ProxyNotShell pre-auth to SYSTEM.
- PrivExchange: coercing Exchange to authenticate and relaying it to Active Directory.
- Mailbox access: reading and impersonating mailboxes after compromise.