What is MAPI OVER HTTP and how is it related to Autodiscover in penetration testing?
MAPI OVER HTTP is the default communication protocol between Outlook and Exchange 2016, replacing RPC OVER HTTP. After completing NTLM authentication via Autodiscover, you can use MAPI OVER HTTP to access Exchange mail resources, such as reading emails or the Global Address List. Tools like `ruler` support some MAPI OVER HTTP functions. This protocol is essential for post-exploitation activities after obtaining credentials, as highlighted in Penetration Basics - Using Exchange Autodiscover.
MAPI OVER HTTPRPC OVER HTTPExchange 2016rulerpost-exploitation