Microsoft Exchange Autodiscover Credential Harvest for 2026-07-31

Last Updated: 00:00 UTC

Requests to /Autodiscover/Autodiscover.xml harvest Exchange credentials from Outlook clients that auto-negotiate mail settings. Any host responding to this path can capture NTLM or Basic auth credentials. Also used in ProxyLogon reconnaissance.

CVE References

CVE-2021-26855

MITRE ATT&CK

Tactic: Credential Access (TA0006)
Technique: T1114.002 — Remote Email Collection

Observed URIs

Attackers by Country

United States of America: 1
United States of America1100.0%

IP Address : ASN : City/Provider

  • 45.61.176.77 : AS53667 frantech solutions : United States of America
Share on: