Skip to main content
Back to all walkthroughs
Room Icon

Exchange Online Monitoring

Max room.

Learn about attacks leveraging Exchange Online and how to detect them in a SOC.

medium

60 min

1,693

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

Email is a critical communication channel in any organisation, which makes it a prime target for attackers. Once a mailbox is compromised, attackers can read emails, exfiltrate sensitive data, and even weaponise the account to launch different campaigns. This room will explore how attackers abuse Microsoft Exchange Online post-compromise and how analysts can detect these attacks using .

Learning Objectives

  • Understand how Exchange Online generates logs and where to find them
  • Identify suspicious mailbox rules creation and email forwarding
  • Detect phishing campaigns launched from compromised mailboxes
  • Use message trace and audit logs to scope an incident
  • Investigate a real-world Exchange Online compromise

Prerequisites

Lab Access

Start the lab by clicking the Start Lab Machine button below. You will then have access to the Splunk Web Interface. Please wait 4-5 minutes for the Splunk instance to launch. To access Splunk, please wait for the  to start and follow this link:

The tasks that require working in Splunk have their own index and log datasets, so ensure you filter for the correct index and task number to answer the questions properly. The indices are given at the end of each practical task.

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting the Lab Machine, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Lab machine
Status:Off
Answer the questions below

I am ready to start!