TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Black Hills InfoSec

Attacking Exchange with MailSniper

BHIS · 2016-10-03 · Read original ↗

ATT&CK techniques detected

4 predictions
T1110.003Password Spraying
98%
“##name - password fall2016 - outfile global - address - list. txt if exchange version is 2013 it should look something like this : after obtaining the full email list you can then feed that back into password spraying attacks where you will likely gain more valid credentials. spe…”
T1110.003Password Spraying
95%
“##ke - passwordsprayowa import the module into a powershell version 3 session then run something like this : invoke - passwordsprayowa - exchhostname mail. domain. com - userlist. \ userlist. txt - password fall2016 - threads 15 - outfile owa - sprayed - creds. txt to use invoke …”
T1589.002Email Addresses
82%
“attacking exchange with mailsniper attacking exchange with mailsniper beau bullock / / i ’ ve added in a few modules to mailsniper that will assist in remote attacks against organizations that are hosting an externally facing exchange server ( owa or ews ). specifically, the modu…”
T1087.003Email Account
44%
“attacking exchange with mailsniper attacking exchange with mailsniper beau bullock / / i ’ ve added in a few modules to mailsniper that will assist in remote attacks against organizations that are hosting an externally facing exchange server ( owa or ews ). specifically, the modu…”

Summary

Beau Bullock // I’ve added in a few modules to MailSniper that will assist in remote attacks against organizations that are hosting an externally facing Exchange server (OWA or EWS). Specifically, […]

The post Attacking Exchange with MailSniper appeared first on Black Hills Information Security, Inc..