OWA Credential Harvesting — Brute Force 401s or Post-Auth Mailbox Harvest
This rule detects potential brute force attacks against Microsoft Exchange Outlook Web App (OWA) by monitoring for a high volume of 401 Unauthorized status codes from non-internal IP addresses. It also correlates these authentication events with subsequent post-authentication actions, specifically identifying mailbox logins followed by mailbox searching or export requests, which may indicate account compromise and unauthorized data collection or exfiltration.
Splunk (SPL)

