Detecting HAFNIUM Exchange Server Zero-Day Activity in Splunk
Detecting HAFNIUM and Exchange Zero-Day Activity in Splunk. Here we will give you some hot-off-the-press searches to help find some of the HAFNIUM badness derived from the Volexity and Microsoft blogs. If we have coverage for these searches in ESCU, we call them out further below in the MITRE ATT&CK section.