ET INFO Microsoft Exchange Server MRSProxy NTLM Authentication
Sourceet/open
Fileemerging-info.rules
CreatedAugust 28, 2026
UpdatedAugust 28, 2026
Classificationattempted-user
alert http any any -> $HOME_NET any (msg:"ET INFO Microsoft Exchange Server MRSProxy NTLM Authentication"; flow:established,to_server ; flowbits:set,ET.MSExchange.CVE-2026-62911 ; flowbits:noalert; http.uri; content:"/Microsoft.Exchange.MailboxReplicationService.ProxyService"; fast_pattern; http.header; to_lowercase; content:"authorization|3a 20|negotiate|20|"; classtype:attempted-user; sid:2071830; rev:1; metadata:affected_product Microsoft_Exchange, tls_state TLSDecrypt, created_at 2026_08_28, deployment Perimeter, deployment Internal, confidence High, signature_severity Informational, updated_at 2026_08_28;)
Metadata
affected productMicrosoft_Exchange
tls stateTLSDecrypt
created at2026_08_28
deploymentInternal
confidenceHigh
signature severityInformational
updated at2026_08_28
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!