Skip to content
← LibraryTechnique entry
M365-EWS-EXFILCollection

Exchange Web Services (EWS) Exfil

Use an OAuth-token to query EWS / Graph for entire mailboxes — bypasses many DLP that focus on Outlook clients.

§ Where this technique fits

M365-EWS-EXFIL is catalogued under the Collection tactic of the offensive-security kill-chain. It appears in 8 approved dossiers in the registry, typically at step 5.1 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    AAD Token Cache Exfil
    M365-TOKEN-EXFIL · Credential Access
    seen 1×
  2. 02
    Conversation Hijacking / Reply-Chain Attack
    EM-CONVERSATION-HIJACK · Initial Access
    seen 1×
  3. 03
    Mailbox Forwarding Rule
    M365-MAILBOX-FORWARD · Collection
    seen 1×