ProxyLogon: Responding to Exchange Server Exploitation
Microsoft disclosed multiple on-premises Exchange Server vulnerabilities in March 2021, including CVE-2021-26855. CISA issued emergency guidance as attackers exploited vulnerable servers and deployed web shells.
The campaign established an important response sequence: patching stops the known entry path, but organizations must still determine whether exploitation occurred before the update.
The mail server was an entry point and evidence source
Exchange servers are internet-facing, identity-connected, and rich in sensitive communication. Web shells could provide persistent remote access even after the original vulnerability was fixed.
Responders needed to preserve IIS, Exchange, Windows, endpoint, identity, and network evidence while applying emergency updates. Rebuilding too quickly could erase information needed to scope the incident.
Patch, hunt, and scope in parallel
Identify every on-premises Exchange server, including hybrids and older instances, and apply supported updates. Run current vendor and government detection tools, but do not rely on a single negative scan as proof of no compromise.
If web shells or related activity are found, isolate safely, collect evidence, rotate exposed credentials, and investigate mailbox, directory, endpoint, and network access. Rebuild from trusted media when integrity cannot be established.
- Differentiate Exchange Online from on-premises Exchange.
- A web shell can survive vulnerability remediation.
- Use multiple evidence sources and detection methods.
- Plan email continuity before isolating a mail server.
Put the lesson into practice
- Inventory on-premises Exchange exposure and versions.
- Preserve evidence and apply current updates.
- Run vendor and CISA hunting procedures.
- Escalate positive findings into full incident response.
- Validate service and monitor closely after recovery.
Related Outfaze guidance
- Patch management
- Email security
- Vulnerability assessment
- Managed detection and response
- Digital forensics and incident response
