exchange-owa-attack
Installation
SKILL.md
Exchange/OWA Attack Skill
Exchange Outlook Web Access reconnaissance covering endpoint mapping, NTLM Type-2 metadata, authentication controls, and version evidence. Password or lockout testing requires explicit authorization and approved identities.
When to Use
- Target has
owa.,mail.,webmail.,exchange., orautodiscover.subdomains. - crt.sh reveals Exchange-related SAN names (
mail.domain.com,autodiscover.domain.com). - Port 443 returns NTLM
WWW-Authenticate: NegotiateorWWW-Authenticate: NTLM. - After
subdomain-enumerationdiscovers mail-related hosts. - After
port-service-discoveryfinds HTTPS on port 443 with Exchange fingerprints.
Prerequisites
terminalwith curl, python3.- Target Exchange/OWA URL.
- For password spray: list of usernames (from recon) and password candidates.