Zimbra GetScratchCodesRequest SOAP Call to Steal 2FA Recovery Codes
Detects anomalous SOAP requests to 'GetScratchCodesRequest' within the 'zimbraSync' or 'zimbraAccount' namespaces in Zimbra logs. This activity is indicative of credential harvesting attempts, specifically the exfiltration of 2FA recovery scratch codes, often associated with the ZimReaper/Ulej payload used by threat actors.
Microsoft Sentinel (KQL)

