Microsoft Exchange Autodiscover Credential Harvest for 2026-07-26
Jul 26, 2026
WebExploit
Last Updated: 12:00 UTC
Requests to /Autodiscover/Autodiscover.xml harvest Exchange credentials from Outlook clients that auto-negotiate mail settings. Any host responding to this path can capture NTLM or Basic auth credentials. Also used in ProxyLogon reconnaissance.
CVE References
MITRE ATT&CK
Tactic: Credential Access (TA0006)
Technique: T1114.002 — Remote Email Collection
Observed URIs
Attackers by Country
| United States of America | 1 | 100.0% |