[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fMGCqik1n3Ncdo9nE3NVOfK3H6u7TBczE897neuoRfm0":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":49,"createdAt":49,"_status":48},608,"What defenses can organizations implement to detect or prevent hidden folder abuse in Exchange?","Organizations should monitor for unusual EWS activity, such as bulk folder creation or extended property changes, and enable mailbox auditing to track folder modifications. Regularly scanning mailboxes for folders with `PidTagAttributeHidden` set to `true` can also help. Additionally, restricting EWS access to only trusted applications and users reduces the attack surface, complementing techniques like those described in [Penetration Techniques - Accessing Internal File Shares via Exchange ActiveSync](\u002Fnews\u002Fpenetration-techniques-accessing-internal-file-shares-via-exchange-activesync).","\u003Cp>Organizations should monitor for unusual EWS activity, such as bulk folder creation or extended property changes, and enable mailbox auditing to track folder modifications. Regularly scanning mailboxes for folders with `PidTagAttributeHidden` set to `true` can also help. Additionally, restricting EWS access to only trusted applications and users reduces the attack surface, complementing techniques like those described in [Penetration Techniques - Accessing Internal File Shares via Exchange ActiveSync](\u002Fnews\u002Fpenetration-techniques-accessing-internal-file-shares-via-exchange-activesync).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-basics-hidden-folders-in-exchange-user-mailboxes\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-defenses-can-organizations-implement-to-detect-or-prevent-hidden-folder-abu-1777482843762","Exchange defense, hidden folder detection, EWS audit, mailbox auditing",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":45,"updatedAt":46,"createdAt":47,"_status":48},149,"Penetration Basics - Hidden Folders in Exchange User Mailboxes","penetration-basics-hidden-folders-in-exchange-user-mailboxes","Learn how to create, access, and delete hidden folders in Exchange mailboxes for penetration testing, with code examples and defense strategies.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For Exchange user mailboxes, hidden folders can be created by setting folder properties. Users cannot view the contents of hidden folders when logging in via OWA web pages or using Outlook.\u003C\u002Fp>\u003Cp>From a penetration testing perspective, we can utilize hidden folders to store important information, serving as a data channel for C2 communication.\u003C\u002Fp>\u003Cp>This article will introduce the usage of hidden folders, implement the creation, access, and deletion of hidden folders through programs, and provide defense recommendations based on exploitation ideas.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Principles of creating hidden folders\u003C\u002Fli>\u003Cli>Common operations for hidden folders\u003C\u002Fli>\u003Cli>Implementation code using EWS Managed API\u003C\u002Fli>\u003Cli>Implementation code using EWS SOAP XML messages\u003C\u002Fli>\u003Cli>Open-source code\u003C\u002Fli>\u003Cli>Defense and detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Principles of Creating Hidden Folders\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fexchange-web-services\u002Fhow-to-work-with-hidden-folders-by-using-ews-in-exchange\u003C\u002Fp>\u003Cp>For Exchange user mailboxes, when the extended property PidTagAttributeHidden (0x10F4000B) of a folder is set to true, the folder becomes invisible to the user.\u003C\u002Fp>\u003Cp>By default, an Exchange user mailbox includes several common folders, such as Inbox, Outbox, and Drafts. For a detailed list, refer to: https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fdotnet\u002Fapi\u002Fmicrosoft.exchange.webservices.data.wellknownfoldername?view=exchange-ews-api#Microsoft_Exchange_WebServices_Data_WellKnownFolderName_MsgFolderRoot\u003C\u002Fp>\u003Cp>We can create a folder under the root directory or any folder (e.g., Inbox), set its extended property PidTagAttributeHidden (0x10F4000B) to true, making it a hidden folder that is invisible to the user. Additionally, all emails within the hidden folder are also invisible to the user. Furthermore, the content of emails and attachments within the hidden folder remains invisible to the user. However, as long as we know the ID of the hidden folder, we can interact with the data programmatically.\u003C\u002Fp>\u003Cp>When interacting with data programmatically, the following operations need to be considered:\u003C\u002Fp>\u003Cp>(Here, taking the creation of a hidden folder under Inbox as an example)\u003C\u002Fp>\u003Cul>\u003Cli>Create a folder under Inbox\u003C\u002Fli>\u003Cli>View the list of folders under Inbox\u003C\u002Fli>\u003Cli>Create a hidden folder under Inbox\u003C\u002Fli>\u003Cli>View the list of hidden folders under Inbox\u003C\u002Fli>\u003Cli>View the list of emails under a specified folder (regardless of hidden attribute)\u003C\u002Fli>\u003Cli>Create an email under a specified folder (regardless of hidden attribute)\u003C\u002Fli>\u003Cli>Delete specified folder\u003C\u002Fli>\u003Cli>Add attachment to specified email\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Implementation code using EWS Managed API\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Create folder under Inbox\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>private static void CreateFolderofInbox(ExchangeService service)\u003Cbr>{\u003Cbr>                Folder folder = new Folder(service);\u003Cbr>                folder.DisplayName = \"Custom Folder\";\u003Cbr>                folder.Save(WellKnownFolderName.Inbox);\u003Cbr>                Console.WriteLine(\"[*] FolderId:\" + folder.Id);\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. View folder list under Inbox\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>private static void ListFolderofInbox(ExchangeService service)\u003Cbr>{\u003Cbr>                FindFoldersResults findResults = null;\u003Cbr>                FolderView view = new FolderView(int.MaxValue) { Traversal = FolderTraversal.Deep };\u003Cbr>                findResults = service.FindFolders(WellKnownFolderName.Inbox, view);\u003Cbr>                foreach (Folder folder in findResults.Folders)\u003Cbr>                {\u003Cbr>                    Console.WriteLine(\"\\r\\n\");\u003Cbr>                    Console.WriteLine(\"[*]DisplayName:{0}\", folder.DisplayName);\u003Cbr>                    Console.WriteLine(\"[*]Id:{0}\", folder.Id);\u003Cbr>                    Console.WriteLine(\"[*]TotalCount:{0}\", folder.TotalCount);\u003Cbr>                }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Create hidden folder under Inbox\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>private static void CreateHiddenFolderofInbox(ExchangeService service)\u003Cbr>{\u003Cbr>                Folder folder = new Folder(service);\u003Cbr>                folder.DisplayName = \"Custom Hidden Folder\";\u003Cbr>                folder.Save(WellKnownFolderName.Inbox);\u003Cbr>                Console.WriteLine(\"[*] Hidden FolderId:\" + folder.Id);\u003Cbr>                \u003Cbr>                \u002F\u002F Create an extended property definition for the PidTagAttributeHidden property.\u003Cbr>                ExtendedPropertyDefinition isHiddenProp = new ExtendedPropertyDefinition(0x10f4, MapiPropertyType.Boolean);\u003Cbr>                PropertySet propSet = new PropertySet(isHiddenProp);\u003Cbr>                \u002F\u002F Bind to a folder and retrieve the PidTagAttributeHidden property.\u003Cbr>                Folder folderhidden = Folder.Bind(service, folder.Id, propSet);\u003Cbr>                \u002F\u002F Set the PidTagAttributeHidden property to true.\u003Cbr>                folderhidden.SetExtendedProperty(isHiddenProp, true);\u003Cbr>                \u002F\u002F Save the changes.\u003Cbr>                folderhidden.Update();\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. View hidden folder list under Inbox\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>private static void ListHiddenFolderofInbox(ExchangeService service)\u003Cbr>{\u003Cbr>                \u002F\u002F Create an extended property definition for the PidTagAttributeHidden property.\u003Cbr>                ExtendedPropertyDefinition isHiddenProp = new ExtendedPropertyDefinition(0x10f4, MapiPropertyType.Boolean);\u003Cbr>                \u002F\u002F Create a folder view to retrieve up to 100 folders and \u003Cbr>                \u002F\u002F retrieve only the PidTagAttributeHidden and the display name.\u003Cbr>                FolderView folderView = new FolderView(100);\u003Cbr>                folderView.PropertySet = new PropertySet(isHiddenProp, FolderSchema.DisplayName);\u003Cbr>                \u002F\u002F Indicate a Traversal value of Deep, so that all subfolders are retrieved.\u003Cbr>                folderView.Traversal = FolderTraversal.Deep;\u003Cbr>                \u002F\u002F Find all hidden folders under the MsgFolderRoot.\u003Cbr>                \u002F\u002F This call results in a FindFolder call to EWS.\u003Cbr>                FindFoldersResults findFolder = service.FindFolders(WellKnownFolderName.Inbox,\u003Cbr>                        new SearchFilter.IsEqualTo(isHiddenProp, true), folderView);\u003Cbr>                \u002F\u002F Display the folder ID and display name of each hidden folder.\u003Cbr>                foreach (Folder folder in findFolder)\u003Cbr>                {\u003Cbr>                    Console.WriteLine(\"[*] DisplayName: {0}\", folder.DisplayName);\u003Cbr>                    Console.WriteLine(\"[*] FolderId: {0}\", folder.Id);\u003Cbr>                    Console.WriteLine(\"\\r\\n\");\u003Cbr>                }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>5. View email list in specified folder (regardless of hidden attributes)\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>private static void ListMailofFolder(FolderId folderId, ExchangeService service)\u003Cbr>{\u003Cbr>                IdString = folderId;\u003Cbr>                Folder Folders = Folder.Bind(service, IdString);\u003Cbr>                FindItemsResults\u003Citem> findResults = null;\u003Cbr>                ItemView view = new ItemView(int.MaxValue);\u003Cbr>                PropertySet itempropertyset = new PropertySet(BasePropertySet.FirstClassProperties);\u003Cbr>                itempropertyset.RequestedBodyType = BodyType.Text;\u003Cbr>                view.PropertySet = itempropertyset;\u003Cbr>                findResults = Folders.FindItems(view);\u003Cbr>                foreach (Item item in findResults.Items)\u003Cbr>                {\u003Cbr>                    Console.WriteLine(\"\\r\\n\");\u003Cbr>                    if (item.Subject != null)\u003Cbr>                    {\u003Cbr>                        Console.WriteLine(\"[*]Subject:{0}\", item.Subject);\u003Cbr>                    }\u003Cbr>                    else\u003Cbr>                    {\u003Cbr>                        Console.WriteLine(\"[*]Subject:\u003Cnull>\");\u003Cbr>                    }\u003Cbr>\u003Cbr>                    Console.WriteLine(\"[*]HasAttachments:{0}\", item.HasAttachments);\u003Cbr>                    if (item.HasAttachments)\u003Cbr>                    {\u003Cbr>                        EmailMessage message = EmailMessage.Bind(service, item.Id, new PropertySet(ItemSchema.Attachments));\u003Cbr>                        foreach (Attachment attachment in message.Attachments)\u003Cbr>                        {\u003Cbr>                            FileAttachment fileAttachment = attachment as FileAttachment;\u003Cbr>                            fileAttachment.Load();\u003Cbr>                            Console.WriteLine(\" - Attachments:{0}\", fileAttachment.Name);\u003Cbr>                        }\u003Cbr>                    }\u003Cbr>                    Console.WriteLine(\"[*]ItemId:{0}\", item.Id);\u003Cbr>                    Console.WriteLine(\"[*]DateTimeCreated:{0}\", item.DateTimeCreated);\u003Cbr>                    Console.WriteLine(\"[*]DateTimeReceived:{0}\", item.DateTimeReceived);\u003Cbr>                    Console.WriteLine(\"[*]DateTimeSent:{0}\", item.DateTimeSent);\u003Cbr>                    Console.WriteLine(\"[*]DisplayCc:{0}\", item.DisplayCc);\u003Cbr>                    Console.WriteLine(\"[*]DisplayTo:{0}\", item.DisplayTo);\u003Cbr>                    Console.WriteLine(\"[*]InReplyTo:{0}\", item.InReplyTo);\u003Cbr>                    Console.WriteLine(\"[*]Size:{0}\", item.Size);\u003Cbr>                    item.Load(itempropertyset);\u003Cbr>                    if (item.Body.ToString().Length &gt; 100)\u003Cbr>                    {\u003Cbr>                        item.Body = item.Body.ToString().Substring(0, 100);\u003Cbr>                        Console.WriteLine(\"[*]MessageBody(too big,only output 100):{0}\", item.Body);\u003Cbr>                    }\u003Cbr>                    else\u003Cbr>                    {\u003Cbr>                        Console.WriteLine(\"[*]MessageBody:{0}\", item.Body);\u003Cbr>                    }\u003Cbr>                }\u003Cbr>}\u003C\u002Fnull>\u003C\u002Fitem>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>6. Create an email in the specified folder (regardless of hidden attributes)\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>private static void CreateMail(FolderId folderId, ExchangeService service)\u003Cbr>{\u003Cbr>                EmailMessage msg = new EmailMessage(service);\u003Cbr>                msg.Subject = \"test mail\";               \u003Cbr>                msg.Save(folderId);\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>7. Add attachments to specified emails\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>private static void AddFileAttachment(ItemId id, string fileName, ExchangeService service)\u003Cbr>{\u003Cbr>                    EmailMessage message = EmailMessage.Bind(service, id);\u003Cbr>                    message.Attachments.AddFileAttachment(fileName);\u003Cbr>                    message.Update(ConflictResolutionMode.AlwaysOverwrite);\u003Cbr>                    Console.WriteLine(\"\\r\\n[+]AddAttachment success\");\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>8. Delete specified folder\u003C\u002Fh3>\u003Cp>EWS Managed API does not support direct deletion; it requires constructing SOAP packets in XML format\u003C\u002Fp>\u003Ch2>0x04 Implementation code using EWS SOAP XML messages\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>To save space, only the content within \u003Csoap:body> is introduced\u003C\u002Fsoap:body>\u003C\u002Fp>\u003Ch3>1. Create a folder under Inbox\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cm:createfolder>\u003Cbr>  \u003Cm:parentfolderid>\u003Cbr>    \u003Ct:distinguishedfolderid id=\"inbox\">\u003Cbr>  \u003C\u002Ft:distinguishedfolderid>\u003C\u002Fm:parentfolderid>\u003Cbr>  \u003Cm:folders>\u003Cbr>    \u003Ct:folder>\u003Cbr>      \u003Ct:displayname>{name}\u003C\u002Ft:displayname>\u003Cbr>    \u003C\u002Ft:folder>\u003Cbr>  \u003C\u002Fm:folders>\u003Cbr>\u003C\u002Fm:createfolder>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. View the folder list under Inbox\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cm:findfolder traversal=\"Deep\">\u003Cbr>  \u003Cm:foldershape>\u003Cbr>    \u003Ct:baseshape>AllProperties\u003C\u002Ft:baseshape>\u003Cbr>  \u003C\u002Fm:foldershape>\u003Cbr>  \u003Cm:indexedpagefolderview maxentriesreturned=\"2147483647\" offset=\"0\" basepoint=\"Beginning\">\u003Cbr>  \u003Cm:parentfolderids>\u003Cbr>    \u003Ct:distinguishedfolderid id=\"inbox\">\u003Cbr>  \u003C\u002Ft:distinguishedfolderid>\u003C\u002Fm:parentfolderids>\u003Cbr>\u003C\u002Fm:indexedpagefolderview>\u003C\u002Fm:findfolder>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Create a hidden folder under Inbox\u003C\u002Fh3>\u003Cp>Three data packets need to be sent here, in order: create folder, add hidden attribute, and update hidden attribute\u003C\u002Fp>\u003Cp>Create folder:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>   \u003Cm:createfolder>\u003Cbr>      \u003Cm:parentfolderid>\u003Cbr>        \u003Ct:distinguishedfolderid id=\"inbox\">\u003Cbr>      \u003C\u002Ft:distinguishedfolderid>\u003C\u002Fm:parentfolderid>\u003Cbr>      \u003Cm:folders>\u003Cbr>        \u003Ct:folder>\u003Cbr>          \u003Ct:displayname>{name}\u003C\u002Ft:displayname>\u003Cbr>        \u003C\u002Ft:folder>\u003Cbr>      \u003C\u002Fm:folders>\u003Cbr>    \u003C\u002Fm:createfolder>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Add hidden attribute:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cm:getfolder>\u003Cbr>  \u003Cm:foldershape>\u003Cbr>    \u003Ct:baseshape>IdOnly\u003C\u002Ft:baseshape>\u003Cbr>    \u003Ct:additionalproperties>\u003Cbr>      \u003Ct:extendedfielduri propertytag=\"4340\" propertytype=\"Boolean\">\u003Cbr>    \u003C\u002Ft:extendedfielduri>\u003C\u002Ft:additionalproperties>\u003Cbr>  \u003C\u002Fm:foldershape>\u003Cbr>  \u003Cm:folderids>\u003Cbr>    \u003Ct:folderid id=\"{id}\" changekey=\"{key}\">\u003Cbr>  \u003C\u002Ft:folderid>\u003C\u002Fm:folderids>\u003Cbr>\u003C\u002Fm:getfolder>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Update hidden property:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>   \u003Cm:updatefolder>\u003Cbr>      \u003Cm:folderchanges>\u003Cbr>        \u003Ct:folderchange>\u003Cbr>          \u003Ct:folderid id=\"{id}\" changekey=\"{key}\">\u003Cbr>          \u003Ct:updates>\u003Cbr>            \u003Ct:setfolderfield>\u003Cbr>              \u003Ct:extendedfielduri propertytag=\"4340\" propertytype=\"Boolean\">\u003Cbr>              \u003Ct:folder>\u003Cbr>                \u003Ct:extendedproperty>\u003Cbr>                  \u003Ct:extendedfielduri propertytag=\"4340\" propertytype=\"Boolean\">\u003Cbr>                  \u003Ct:value>true\u003C\u002Ft:value>\u003Cbr>                \u003C\u002Ft:extendedfielduri>\u003C\u002Ft:extendedproperty>\u003Cbr>              \u003C\u002Ft:folder>\u003Cbr>            \u003C\u002Ft:extendedfielduri>\u003C\u002Ft:setfolderfield>\u003Cbr>          \u003C\u002Ft:updates>\u003Cbr>        \u003C\u002Ft:folderid>\u003C\u002Ft:folderchange>\u003Cbr>      \u003C\u002Fm:folderchanges>\u003Cbr>    \u003C\u002Fm:updatefolder>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. View the list of hidden folders under Inbox\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>   \u003Cm:findfolder traversal=\"Deep\">\u003Cbr>      \u003Cm:foldershape>\u003Cbr>        \u003Ct:baseshape>IdOnly\u003C\u002Ft:baseshape>\u003Cbr>        \u003Ct:additionalproperties>\u003Cbr>          \u003Ct:extendedfielduri propertytag=\"4340\" propertytype=\"Boolean\">\u003Cbr>          \u003Ct:fielduri fielduri=\"folder:DisplayName\">\u003Cbr>        \u003C\u002Ft:fielduri>\u003C\u002Ft:extendedfielduri>\u003C\u002Ft:additionalproperties>\u003Cbr>      \u003C\u002Fm:foldershape>\u003Cbr>      \u003Cm:indexedpagefolderview maxentriesreturned=\"100\" offset=\"0\" basepoint=\"Beginning\">\u003Cbr>      \u003Cm:restriction>\u003Cbr>        \u003Ct:isequalto>\u003Cbr>          \u003Ct:extendedfielduri propertytag=\"4340\" propertytype=\"Boolean\">\u003Cbr>          \u003Ct:fielduriorconstant>\u003Cbr>            \u003Ct:constant value=\"true\">\u003Cbr>          \u003C\u002Ft:constant>\u003C\u002Ft:fielduriorconstant>\u003Cbr>        \u003C\u002Ft:extendedfielduri>\u003C\u002Ft:isequalto>\u003Cbr>      \u003C\u002Fm:restriction>\u003Cbr>      \u003Cm:parentfolderids>\u003Cbr>        \u003Ct:distinguishedfolderid id=\"inbox\">\u003Cbr>      \u003C\u002Ft:distinguishedfolderid>\u003C\u002Fm:parentfolderids>\u003Cbr>    \u003C\u002Fm:indexedpagefolderview>\u003C\u002Fm:findfolder>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>5. View the list of emails in the specified folder (regardless of hidden attributes)\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cm:finditem traversal=\"Shallow\">\u003Cbr>  \u003Cm:itemshape>\u003Cbr>    \u003Ct:baseshape>AllProperties\u003C\u002Ft:baseshape>\u003Cbr>    \u003Ct:bodytype>Text\u003C\u002Ft:bodytype>\u003Cbr>  \u003C\u002Fm:itemshape>\u003Cbr>  \u003Cm:indexedpageitemview maxentriesreturned=\"2147483647\" offset=\"0\" basepoint=\"Beginning\">\u003Cbr>  \u003Cm:parentfolderids>\u003Cbr>    \u003Ct:folderid id=\"{id}\">\u003Cbr>  \u003C\u002Ft:folderid>\u003C\u002Fm:parentfolderids>\u003Cbr>\u003C\u002Fm:indexedpageitemview>\u003C\u002Fm:finditem>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>6. Create an email in the specified folder (regardless of hidden attributes)\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cm:createitem messagedisposition=\"SaveOnly\">\u003Cbr>  \u003Cm:saveditemfolderid>\u003Cbr>    \u003Ct:folderid id=\"{id}\">\u003Cbr>  \u003C\u002Ft:folderid>\u003C\u002Fm:saveditemfolderid>\u003Cbr>  \u003Cm:items>\u003Cbr>    \u003Ct:message>\u003Cbr>      \u003Ct:subject>test mail\u003C\u002Ft:subject>\u003Cbr>    \u003C\u002Ft:message>\u003Cbr>  \u003C\u002Fm:items>\u003Cbr>\u003C\u002Fm:createitem>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>7. Add attachments to the specified email\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cm:createattachment>\u003Cbr>  \u003Cm:parentitemid id=\"{id}\" changekey=\"{key}\">\u003Cbr>  \u003Cm:attachments>\u003Cbr>    \u003Ct:fileattachment>\u003Cbr>      \u003Ct:name>{name}\u003C\u002Ft:name>\u003Cbr>      \u003Ct:content>{data}\u003C\u002Ft:content>\u003Cbr>    \u003C\u002Ft:fileattachment>\u003Cbr>  \u003C\u002Fm:attachments>\u003Cbr>\u003C\u002Fm:parentitemid>\u003C\u002Fm:createattachment>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>8. Delete specified folder\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cm:deleteitem deletetype=\"HardDelete\" xmlns=\"https:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\">\u003Cbr>  \u003Cm:itemids>\u003Cbr>    \u003Ct:itemid id=\"{id}\">\u003Cbr>  \u003C\u002Ft:itemid>\u003C\u002Fm:itemids>\u003Cbr>\u003C\u002Fm:deleteitem>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Open source code\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Using EWS Managed API\u003C\u002Fh3>\u003Cp>An open source project\u003C\u002Fp>\u003Cp>Usage example\u003C\u002Fp>\u003Cp>(1) Create hidden folder test1 under Inbox\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.exe -CerValidation No -ExchangeVersion Exchange2013_SP1 -u test1 -p test123! -ewsPath https:\u002F\u002Ftest.com\u002Fews\u002FExchange.asmx -Mode CreateHiddenFolderofInbox -Name test1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain the FolderId corresponding to the folder: AAMkADc4YjRlNDc1LWI0YjctNDEzZi1hNTQ5LWZkYWY0ZGZhZDM0NgAuAAAAAABEBlGH6URWQp6Nlg9RxLmyAQA1ZCfAg9a0Sq75no2JOzsqAAAAA1FUAAA=\u003C\u002Fp>\u003Cp>(2) View hidden folders under Inbox\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.exe -CerValidation No -ExchangeVersion Exchange2013_SP1 -u test1 -p test123! -ewsPath https:\u002F\u002Ftest.com\u002Fews\u002FExchange.asmx -Mode ListHiddenFolder -Folder Inbox\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3) Create a test email in the hidden folder test1\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.exe -CerValidation No -ExchangeVersion Exchange2013_SP1 -u test1 -p test123! -ewsPath https:\u002F\u002Ftest.com\u002Fews\u002FExchange.asmx -Mode CreateTestMail -Id AAMkADc4YjRlNDc1LWI0YjctNDEzZi1hNTQ5LWZkYWY0ZGZhZDM0NgAuAAAAAABEBlGH6URWQp6Nlg9RxLmyAQA1ZCfAg9a0Sq75no2JOzsqAAAAA1FUAAA=\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(4) View all emails in the hidden folder test1\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.exe -CerValidation No -ExchangeVersion Exchange2013_SP1 -u test1 -p test123! -ewsPath https:\u002F\u002Ftest.com\u002Fews\u002FExchange.asmx -Mode ListMailofFolder -Id AAMkADc4YjRlNDc1LWI0YjctNDEzZi1hNTQ5LWZkYWY0ZGZhZDM0NgAuAAAAAABEBlGH6URWQp6Nlg9RxLmyAQA1ZCfAg9a0Sq75no2JOzsqAAAAA1FUAAA=\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain the ItemId corresponding to the test email: AAMkADc4YjRlNDc1LWI0YjctNDEzZi1hNTQ5LWZkYWY0ZGZhZDM0NgBGAAAAAABEBlGH6URWQp6Nlg9RxLmyBwA1ZCfAg9a0Sq75no2JOzsqAAAAA1FUAAA1ZCfAg9a0Sq75no2JOzsqAAAAA1FVAAA=\u003C\u002Fp>\u003Cp>(5) Add an attachment to the test email\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.exe -CerValidation No -ExchangeVersion Exchange2013_SP1 -u test1 -p test123! -ewsPath https:\u002F\u002Ftest.com\u002Fews\u002FExchange.asmx -Mode AddAttachment -Id AAMkADc4YjRlNDc1LWI0YjctNDEzZi1hNTQ5LWZkYWY0ZGZhZDM0NgAuAAAAAABEBlGH6URWQp6Nlg9RxLmyAQA1ZCfAg9a0Sq75no2JOzsqAAAAA1FUAAA= -AttachmentFile c:\\test\\1.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(6) Read the content of the test email\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.exe -CerValidation No -ExchangeVersion Exchange2013_SP1 -u test1 -p test123! -ewsPath https:\u002F\u002Ftest.com\u002Fews\u002FExchange.asmx -Mode ViewMail -Id AAMkADc4YjRlNDc1LWI0YjctNDEzZi1hNTQ5LWZkYWY0ZGZhZDM0NgAuAAAAAABEBlGH6URWQp6Nlg9RxLmyAQA1ZCfAg9a0Sq75no2JOzsqAAAAA1FUAAA=\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(7) Save attachments from the test email\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.exe -CerValidation No -ExchangeVersion Exchange2013_SP1 -u test1 -p test123! -ewsPath https:\u002F\u002Ftest.com\u002Fews\u002FExchange.asmx -Mode SaveAttachment -Id AAMkADc4YjRlNDc1LWI0YjctNDEzZi1hNTQ5LWZkYWY0ZGZhZDM0NgAuAAAAAABEBlGH6URWQp6Nlg9RxLmyAQA1ZCfAg9a0Sq75no2JOzsqAAAAA1FUAAA=\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(8) Delete test email\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.exe -CerValidation No -ExchangeVersion Exchange2013_SP1 -u test1 -p test123! -ewsPath https:\u002F\u002Ftest.com\u002Fews\u002FExchange.asmx -Mode DeleteMail -Id AAMkADc4YjRlNDc1LWI0YjctNDEzZi1hNTQ5LWZkYWY0ZGZhZDM0NgAuAAAAAABEBlGH6URWQp6Nlg9RxLmyAQA1ZCfAg9a0Sq75no2JOzsqAAAAA1FUAAA=\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Using EWS SOAP XML message\u003C\u002Fh3>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>(1) Create hidden folder test2 under Inbox\u003C\u002Fp>\u003Cp>Create folder:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.py 192.168.1.1 443 plaintext test.com user1 password1 createfolderofinbox\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain Id: AAMkADc4YjRlNDc1LWI0YjctNDEzZi1hNTQ5LWZkYWY0ZGZhZDM0NgAuAAAAAABEBlGH6URWQp6Nlg9RxLmyAQA1ZCfAg9a0Sq75no2JOzsqAAAAA1U+AAA=, ChangeKey: AQAAABYAAAA1ZCfAg9a0Sq75no2JOzsqAAAAAGE\u002F\u003C\u002Fp>\u003Cp>Add hidden property:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.py 192.168.1.1 443 plaintext test.com user1 password1 SetHiddenPropertyType\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Update hidden property:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.py 192.168.1.1 443 plaintext test.com user1 password1 UpdateHiddenPropertyType\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) View hidden folders under Inbox\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.py 192.168.1.1 443 plaintext test.com user1 password1 listhiddenfolderofinbox\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3) Create test email under hidden folder test1\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.py 192.168.1.1 443 plaintext test.com user1 password1 createtestmail\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(4) View all emails in hidden folder test1\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.py 192.168.1.1 443 plaintext test.com user1 password1 listmailoffolder\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(5) Add attachment to test email\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.py 192.168.1.1 443 plaintext test.com user1 password1 createattachment\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(6) Read test email content\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.py 192.168.1.1 443 plaintext test.com user1 password1 getmail\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(7) Save attachments from test email\u003C\u002Fp>\u003Cp>Obtain attachment ID:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.py 192.168.1.1 443 plaintext test.com user1 password1 getattachment\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Save attachment:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.py 192.168.1.1 443 plaintext test.com user1 password1 saveattachment\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(8) Delete test email\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.py 192.168.1.1 443 plaintext test.com user1 password1 deletemail\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(9) Delete hidden folder test1 for test email\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.py 192.168.1.1 443 plaintext test.com user1 password1 deletefolder\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x06 Defense Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Check for hidden folders via program\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.exe -CerValidation No -ExchangeVersion Exchange2013_SP1 -u test1 -p test123! -ewsPath https:\u002F\u002Ftest.com\u002Fews\u002FExchange.asmx -Mode ListHiddenFolder -Folder Inbox\u003Cbr>\u003Cbr>ewsManage.py 192.168.1.1 443 plaintext test.com user1 password1 listhiddenfolderofinbox\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Check the last login time of email users\u003C\u002Fp>\u003Cp>Using Exchange Server PowerShell:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-MailboxDatabase | Get-MailboxStatistics |fl DisplayName,LastLogonTime\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>3. Check EWS access logs\u003C\u002Fp>\u003Cp>Default location: C:\\inetpub\\logs\\LogFiles\\W3SVC1, search for keyword \u002FEWS\u002FExchange.asmx\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the usage of hidden folders in Exchange user mailboxes, detailing methods for creating, accessing, and deleting hidden folders using EWS Managed API and EWS SOAP XML messages, along with the open-source tools ewsManage and ewsManage.py, and provides defense recommendations based on exploitation techniques.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",8,"published","2026-02-02T07:38:21.455Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"Exchange Hidden Folders: Penetration Testing & Defense Guide","Exchange hidden folders, EWS Managed API, penetration testing, data exfiltration, C2 communication, Exchange security, mailbox exploitation",false,[],{"docs":41,"hasNextPage":38},[4,42,43,44],607,606,605,{"title":30,"description":30,"image":30},"2026-07-24T02:07:21.819Z","2026-07-23T16:01:49.736Z","draft","2026-07-23T16:13:44.580Z"]