exchange-owa-attack

Installation
SKILL.md

Exchange/OWA Attack Skill

Exchange Outlook Web Access reconnaissance covering endpoint mapping, NTLM Type-2 metadata, authentication controls, and version evidence. Password or lockout testing requires explicit authorization and approved identities.

When to Use

  • Target has owa., mail., webmail., exchange., or autodiscover. subdomains.
  • crt.sh reveals Exchange-related SAN names (mail.domain.com, autodiscover.domain.com).
  • Port 443 returns NTLM WWW-Authenticate: Negotiate or WWW-Authenticate: NTLM.
  • After subdomain-enumeration discovers mail-related hosts.
  • After port-service-discovery finds HTTPS on port 443 with Exchange fingerprints.

Prerequisites

  • terminal with curl, python3.
  • Target Exchange/OWA URL.
  • For password spray: list of usernames (from recon) and password candidates.
Installs
11
GitHub Stars
1.2K
First Seen
Jul 9, 2026
exchange-owa-attack — uphiago/recon-skills