📘
DFIR
Ctrl
k
Copy
Windows
Forensics
Event Logs
Exchange
Pwned by the Mail Carrier - SpecterOps
SpecterOps
client side only rule
Message Trace
How to Tell Which Transport Rule Was Applied to an Email Message
Practical 365
Search-MailboxAuditLog (ExchangePowerShell)
MicrosoftLearn
Mailbox audit logging in Exchange Server
MicrosoftLearn
Log Files:
Web Logs:
C:\Program Files\Microsoft\Exchange Server\V15\Logging\HttpProxy
Previous
Kerberos
Next
GPOs and OUs
Last updated
1 year ago
Message Trace
Log Files: