CVE-2021-26858 Exchange Exploitation
Description
Detects possible successful exploitation for vulnerability described in CVE-2021-26858 by looking for creation of non-standard files on disk by Exchange Server’s Unified Messaging service which could indicate dropping web shells or other malicious content
Query · sigma
selection: Image|endswith: UMWorkerProcess.exe filter: TargetFilename|endswith: - CacheCleanup.bin - .txt - .LOG - .cfg - cleanup.bin condition: selection and not filter
Known false positives
- Unknown