Adversaries may abuse Microsoft transport agents to establish persistent access to systems. Microsoft Exchange transport agents can operate on email messages passing through the transport pipeline to perform various tasks such as filtering spam, filtering malicious attachments, journaling, or adding a corporate signature to the end of all outgoing emails.(Citation: Microsoft TransportAgent Jun 2016)(Citation: ESET LightNeuron May 2019) Transport agents can be written by application developers and then compiled to .NET assemblies that are subsequently registered with the Exchange server. Transport agents will be invoked during a specified stage of email processing and carry out developer defined tasks. Adversaries may register a malicious transport agent to provide a persistence mechanism in Exchange Server that can be triggered by adversary-specified email events.(Citation: ESET LightNeuron May 2019) Though a malicious transport agent may be invoked for all emails passing through the Exchange transport pipeline, the agent can be configured to only carry out specific tasks in response to adversary defined criteria. For example, the transport agent may only carry out an action like copying in-transit attachments and saving them for later exfiltration if the recipient email address matches an entry on a list provided by the adversary.

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is blocked by Privileged Account Management
is blocked by Detection Strategy for T1505.002 - Transport Agent Abuse (Windows/Linux)
is blocked by Audit
is blocked by Code Signing
is blocked by Asset Inventories
is blocked by Provenance
is blocked by Access Restriction For Change
is blocked by Secure Baseline Configurations
is blocked by User-Installed Software
is blocked by Continuous Monitoring
is blocked by Transmission of Cybersecurity & Data Protection Attributes
is blocked by Cybersecurity & Data Protection Attributes
is blocked by Endpoint File Integrity Monitoring (FIM)
is blocked by Separation of Duties (SoD)
is blocked by Identification & Authentication for Organizational Users
is blocked by Account Management
is blocked by Access Enforcement
is blocked by Least Privilege
is blocked by Non-Persistence
is blocked by Security, Compliance & Resilience Testing Throughout Development
is blocked by Product Tampering and Counterfeiting (PTC)
is blocked by Developer Configuration Management
is blocked by Acquisition Strategies, Tools & Methods
is blocked by Vulnerability Scanning
Impressum Deutsch Englisch