Tools for Detection of Compromise of Microsoft Exchange Server Vulnerabilities

Health Sector Cybersecurity Coordination Center (HC3)

Analyst Note

March 8, 2021

TLP: White

Report: 202103081700

Executive Summary

Microsoft released patches for four Exchange Server zero-day vulnerabilities on March 2, 2021. They are being actively and aggressively exploited by sophisticated state-sponsored threat actors who have a history of targeting healthcare organizations. Sinc ethe release of the patches, several tools have been released which can aid in detecting exploitation as well as persistent access backdoors knows to be used in these attacks. There tools should be considered as part of an overall defense strategy. This analyst note is a follow-up to the note we released on March 3.

See the PDF for the full Analyst Note.