Teams should look for suspicious Exchange and IIS Worker processes, unexpected web shell activity, and IOC matches in recent alert history. Endpoint visibility on the Exchange host is important because zero-day activity may not be obvious from patch status alone. If detections are weak, the safest assumption is that behavioral monitoring needs to be tightened before the issue is fully understood.
What Active Exchange Compromise Looks Like on the Host
An on-premises Exchange server that is already under active attack often shows host-level signs before the compromise is fully understood. The most important clue is unusual process behaviour, especially Exchange and IIS worker activity that does not match normal mail flow, administrative work, or scheduled maintenance. For a comparable pattern of real-world compromise, see The 52 NHI breaches Report and the related 52 NHI Breaches Analysis, which show how compromise often becomes visible through abnormal execution paths and follow-on abuse rather than through obvious patch indicators.
Web shell activity is another high-signal indicator because Exchange is a common target for attacker persistence once initial access is gained. Suspicious files, unexpected script execution, or new web-accessible artefacts under Exchange or IIS directories should be treated as compromise indicators, not just maintenance noise. If your monitoring can only tell you that the server is running a vulnerable build, that is not enough to rule out live exploitation.
Recent detection history matters as much as live telemetry. IOC matches, repeated blocked requests, or prior alerts tied to the Exchange host can show that the server has already been probed or partially accessed. CISA threat advisories and the CISA Known Exploited Vulnerabilities Catalog are useful references when you need to understand whether the issue aligns with currently exploited Exchange attack patterns, while the CISA cyber threat advisories page provides the broader advisory context that often accompanies active exploitation.
Risk and Threat Considerations
The risk is that an Exchange server can be functionally compromised before defenders see a clear outage or a failed login pattern. Attackers favour Exchange because it can provide mail access, internal visibility, and a path to broader lateral movement, so the appearance of normal service does not mean the host is safe. If web shell placement or suspicious worker-process behaviour is present, treat the server as potentially persistent-access compromised.
Failure mechanism: Attackers commonly use server-side code execution, web shell deployment, or abuse of exposed services to hide inside normal IIS and Exchange execution paths, which can make routine patch status and service health misleading.
Impact: The likely consequences are mailbox access, credential theft, internal reconnaissance, and movement into adjacent systems, with the possibility that the Exchange host becomes a long-lived foothold rather than a one-time intrusion.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS Control 8 — Audit Log Management | Exchange attack signs are often first seen in logs and alert history. |
| CIS Control 10 — Malware Defenses | Web shells and post-exploitation payloads require malicious code detection on the host. | |
| CIS Control 17 — Incident Response Management | Active attack indicators on Exchange require rapid containment and escalation. | |
| Recommendation — Correlate IIS, Exchange, and endpoint logs to detect active exploitation quickly. Scan the Exchange host for web shells and suspicious script activity. Trigger incident response when host behaviour suggests live compromise. | ||
| NIST CSF 2.0 | DE.CM — Continuous Monitoring | The question depends on detecting abnormal host and alert behaviour in time to act. |
| RS.AN — Analysis | Signs of attack must be analysed to separate false positives from active compromise. | |
| RS.MI — Mitigation | Once active attack is suspected, containment and remediation are required. | |
| Recommendation — Monitor Exchange host processes and detections continuously for compromise indicators. Analyse process anomalies, web shells, and IOC hits as potential compromise chains. Contain the Exchange server before expanding investigation to adjacent systems. | ||
| MITRE ATT&CK | T1505.003 — Server Software Component: Web Shell | Web shells are a core sign of active Exchange compromise and persistence. |
| T1059 — Command and Scripting Interpreter | Suspicious script execution is a common indicator of post-exploitation on servers. | |
| T1071.001 — Web Protocols | Attackers often blend malicious traffic into normal web protocol activity on Exchange. | |
| Recommendation — Hunt for web shell artefacts and unexpected server-side execution on Exchange. Flag abnormal script interpreters and command execution on the Exchange host. Inspect web protocol activity for attacker staging and command delivery. | ||
Practitioner Guidance
What to verify: Confirm whether the suspicious processes are expected for the server’s current load, patching, and administrative activity. A one-off anomaly is less important than repeated abnormal IIS worker behaviour, unexplained script execution, or evidence that the same host has already triggered multiple detections.
What to prioritise: Treat endpoint visibility on the Exchange host as a first-order control, not a nice-to-have. If telemetry is sparse, prioritise host investigation and containment before assuming the absence of alerts means the absence of compromise.
Decision rule: If the host shows web shell indicators, repeated IOC matches, or process behaviour that does not align with known Exchange operations, assume active attacker presence until proven otherwise and escalate to incident response.
Practitioner takeaway: On Exchange, patch level is a weak reassurance signal; the real decision point is whether host telemetry can explain the behaviour you are seeing well enough to rule out live attacker persistence.
Related resources from NHI Mgmt Group
- What are the signs that an F5 management environment may be under active attack?
- What are the signs that a certificate abuse attack is already active in Active Directory?
- What are the signs that a file transfer vulnerability may already be under active exploitation?
- Why do Active Directory migrations often expose security risks that teams thought were already under control?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 19, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org