Exchange Mailbox 'Default' User Granted Owner Folder Permission (TA488 OWAReaper
Detects modifications to Microsoft Exchange mailbox folder permissions where the 'Default' user is granted 'Owner' access. This activity, which may involve operations such as 'UpdateFolder', 'Add-MailboxFolderPermission', or 'Set-MailboxFolderPermission', is a known server-side persistence mechanism. By granting 'Owner' rights to the 'Default' user, an attacker can bypass standard authentication and device-level controls to access mailbox contents, often following initial exploitation such as OWA XSS.
Sigma

