[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3JMf37wgfwKJ94sytz-jwZzmn0QCCUCxSZdqSvHkkLo":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},81,"What is the main difference between exporting emails via a remote PSSession and directly on the Exchange server using a local snap-in?","When exporting directly on the Exchange server (local snap-in), you do not need to assign the user to the \"Mailbox Import Export\" role group; the local administrator often has sufficient privileges. The snap-in is loaded with `Add-PSSnapin Microsoft.Exchange.Management.PowerShell.SnapIn` (or version-specific like `Microsoft.Exchange.Management.PowerShell.E2010` for Exchange 2010). In contrast, remote PSSession requires explicit role assignment because the session doesn't automatically inherit full permissions.","\u003Cp>When exporting directly on the Exchange server (local snap-in), you do not need to assign the user to the &quot;Mailbox Import Export&quot; role group; the local administrator often has sufficient privileges. The snap-in is loaded with `Add-PSSnapin Microsoft.Exchange.Management.PowerShell.SnapIn` (or version-specific like `Microsoft.Exchange.Management.PowerShell.E2010` for Exchange 2010). In contrast, remote PSSession requires explicit role assignment because the session doesn&#39;t automatically inherit full permissions.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-basics-searching-and-exporting-emails-from-exchange-servers\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-the-main-difference-between-exporting-emails-via-a-remote-pssession-and--1777485259242","local snap-in, remote PSSession, role assignment, Exchange version snap-in",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},21,"Penetration Basics - Searching and Exporting Emails from Exchange Servers","penetration-basics-searching-and-exporting-emails-from-exchange-servers","Learn how to search and export emails from Exchange servers using PowerShell scripts for penetration testing. Includes methods for email management and export.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, if we obtain administrative privileges on an Exchange server, the next step is to search and export emails from it. This article will introduce two common methods, open-source four PowerShell scripts, and share details on script development.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Two methods for managing emails on an Exchange server\u003C\u002Fli>\u003Cli>Two methods for exporting emails\u003C\u002Fli>\u003Cli>Two methods for searching emails\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The methods introduced in this article are all PowerShell commands\u003C\u002Fp>\u003Ch2>0x02 Two Methods for Managing Emails on an Exchange Server\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. First, connect to the Exchange server using PSSession, then remotely manage emails\u003C\u002Fh3>\u003Cp>Command to connect to an Exchange server using PSSession:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$User = \"test\\administrator\"\u003Cbr>$Pass = ConvertTo-SecureString -AsPlainText DomainAdmin123! -Force\u003Cbr>$Credential = New-Object System.Management.Automation.PSCredential -ArgumentList $User,$Pass\u003Cbr>$Session = New-PSSession -ConfigurationName Microsoft.Exchange -ConnectionUri http:\u002F\u002FExchange01.test.com\u002FPowerShell\u002F -Authentication Kerberos -Credential $Credential\u003Cbr>Import-PSSession $Session -AllowClobber\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Additional notes:\u003C\u002Fp>\u003Cp>View PSSession:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-PSSession\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Disconnect PSSession:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-PSSession $Session\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test command (get all mailbox users):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Mailbox\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Commands to manage mail directly on the Exchange server\u003C\u002Fh3>\u003Cp>Test command (get names of all mailbox users):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-PSSnapin Microsoft.Exchange.Management.PowerShell.SnapIn;\u003Cbr>Get-Mailbox\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The management snap-in names vary across different Exchange versions:\u003C\u002Fp>\u003Cul>\u003Cli>Exchange 2007:\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Add-PSSnapin Microsoft.Exchange.Management.PowerShell.Admin;\u003C\u002Fp>\u003Cul>\u003Cli>Exchange 2010:\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Add-PSSnapin Microsoft.Exchange.Management.PowerShell.E2010;\u003C\u002Fp>\u003Cul>\u003Cli>Exchange 2013 &amp; 2016:\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Add-PSSnapin Microsoft.Exchange.Management.PowerShell.SnapIn;\u003C\u002Fp>\u003Ch3>Supplement: Common commands for managing Exchange mailboxes\u003C\u002Fh3>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fpowershell\u002Fmodule\u002Fexchange\u002F?view=exchange-ps\u003C\u002Fp>\u003Ch4>(1) Retrieve all mailbox user names:\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Mailbox -ResultSize unlimited\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>By default, 1000 users are displayed. Adding -ResultSize unlimited retrieves all users.\u003C\u002Fp>\u003Ch4>(2) Retrieve information for all mailboxes, including message count and last mailbox access time\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Mailbox | Get-MailboxStatistics\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Retrieve all OUs\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-OrganizationalUnit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(4) Obtain send\u002Freceive email information through message tracking logs\u003C\u002Fh4>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fpowershell\u002Fmodule\u002Fexchange\u002Fmail-flow\u002Fget-messagetrackinglog?view=exchange-ps\u003C\u002Fp>\u003Cp>Default message tracking log location: %ExchangeInstallPath%TransportRoles\\Logs\\MessageTracking\u003C\u002Fp>\u003Cp>View all email information (including sender, recipient, and subject) sent by test1@test.com from 9:00 on January 1, 2019 to present:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-MessageTrackingLog -Start \"01\u002F11\u002F2019 09:00:00\" -Sender \"test1@test.com\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The returned results are messy, containing multiple events:\u003C\u002Fp>\u003Cul>\u003Cli>DSN\u003C\u002Fli>\u003Cli>Defer\u003C\u002Fli>\u003Cli>Deliver\u003C\u002Fli>\u003Cli>Send\u003C\u002Fli>\u003Cli>Receive\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Filter only sent events to make the returned results more concise:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-MessageTrackingLog -EventID send -Start \"01\u002F11\u002F2019 09:00:00\" -Sender \"test1@test.com\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Script to count the number of emails sent and received daily:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgallery.technet.microsoft.com\u002Foffice\u002Ff2af711e-defd-476d-896e-8053aa964bc5\u002Fview\u002FDiscussions\u003C\u002Fp>\u003Cp>Need to modify the start time and add the command to load the Exchange PowerShell management snap-in\u003C\u002Fp>\u003Ch2>0x03 Two Methods for Exporting Emails\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Using PSSession to establish a connection and export emails\u003C\u002Fh3>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fpowershell\u002Fmodule\u002Fexchange\u002Fmailboxes\u002Fnew-mailboxexportrequest?view=exchange-ps\u003C\u002Fp>\u003Ch4>(1) Add the user to the role group \"Mailbox Import Export\"\u003C\u002Fh4>\u003Cp>Here, using the user administrator as an example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-ManagementRoleAssignment –Role \"Mailbox Import Export\" –User Administrator\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Supplement: Removed command\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-ManagementRoleAssignment -Identity \"Mailbox Import Export-Administrator\" -Confirm:$false\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Verify after addition:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-ManagementRoleAssignment –Role \"Mailbox Import Export\"|fl user\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Restart PowerShell\u003C\u002Fh4>\u003Cp>Otherwise, the New-MailboxExportRequest command cannot be used\u003C\u002Fp>\u003Ch4>(3) Export emails and save\u003C\u002Fh4>\u003Cp>Three examples are provided here\u003C\u002Fp>\u003Cp>1. Export all emails of a specified user and save to c:\\test on the Exchange server\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$User = \"test1\"\u003Cbr>New-MailboxExportRequest -mailbox $User -FilePath (\"\\\\localhost\\c$\\test\\\"+$User+\".pst\")\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Filter emails containing the word 'pass' in the body for a specified user and save to c:\\test on the Exchange server\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$User = \"test1\"\u003Cbr>New-MailboxExportRequest -mailbox $User -ContentFilter {(body -like \"*pass*\")} -FilePath (\"\\\\localhost\\c$\\test\\\"+$User+\".pst\")\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>3. Export all emails and save to c:\\test on the Exchange server\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Mailbox -OrganizationalUnit Users -Resultsize unlimited |%{New-MailboxexportRequest -mailbox $_.name -FilePath (\"\\\\localhost\\c$\\test\\\"+($_.name)+\".pst\")}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After export, the export request records are automatically saved, with a default retention of 30 days\u003C\u002Fp>\u003Cp>If you do not want to save export requests, you can add the parameter -CompletedRequestAgeLimit 0\u003C\u002Fp>\u003Cp>Supplement: Regarding operations related to export requests\u003C\u002Fp>\u003Cp>View email export requests:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-MailboxExportRequest\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Delete a specific export request:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-MailboxExportRequest -RequestQueue \"Mailbox Database 2057988509\" -RequestGuid 650f52ec-722b-47bb-8e73-d16a17c32129 -Confirm:$false\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-MailboxExportRequest -Identity 'test.com\u002FUsers\u002Ftest1\\MailboxExport' -Confirm:$false\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Matching parameters are obtained from the results of Get-MailboxExportRequest|fl\u003C\u002Fp>\u003Cp>Delete all export requests:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-MailboxExportRequest|Remove-MailboxExportRequest -Confirm:$false\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>In summary, the implementation code for exporting specific emails (containing the word 'pass' in the body) of user test1 to the Exchange server's c:\\test has been uploaded to GitHub, with the address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>UsePSSessionToExportMailfromExchange -User \"administrator\" -Password \"DomainAdmin123!\" -MailBox \"test1\" -ExportPath \"\\\\Exchange01.test.com\\c$\\test\\\" -ConnectionUri \"http:\u002F\u002FExchange01.test.com\u002FPowerShell\u002F\" -Filter \"{`\"(body -like `\"*pass*`\")`\"}\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The process is as follows:\u003C\u002Fp>\u003Cp>1. Use PSSession to connect to the Exchange server\u003C\u002Fp>\u003Cp>2. Determine whether the user used has been added to the role group \"Mailbox Import Export\"\u003C\u002Fp>\u003Cp>If not added, the user needs to be added\u003C\u002Fp>\u003Cp>3. Export emails and save them to c:\\test on the Exchange server in PST format\u003C\u002Fp>\u003Cp>4. If a user was newly added, they will be removed from the role group \"Mailbox Import Export\"\u003C\u002Fp>\u003Cp>5. Clear the PSSession\u003C\u002Fp>\u003Cp>The exported PST file can be opened using Outlook\u003C\u002Fp>\u003Ch3>2. Directly export emails on the Exchange server\u003C\u002Fh3>\u003Ch4>(1) Add the management snap-in\u003C\u002Fh4>\u003Cp>The names of the management snap-ins vary by Exchange version:\u003C\u002Fp>\u003Cul>\u003Cli>Exchange 2007:\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Add-PSSnapin Microsoft.Exchange.Management.PowerShell.Admin;\u003C\u002Fp>\u003Cul>\u003Cli>Exchange 2010:\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Add-PSSnapin Microsoft.Exchange.Management.PowerShell.E2010;\u003C\u002Fp>\u003Cul>\u003Cli>Exchange 2013 &amp; 2016:\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Add-PSSnapin Microsoft.Exchange.Management.PowerShell.SnapIn;\u003C\u002Fp>\u003Cp>No need to consider role groups, emails can be exported directly\u003C\u002Fp>\u003Ch4>(2) Export emails\u003C\u002Fh4>\u003Cp>Export emails for user test1, save to c:\\test on the Exchange server:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-PSSnapin Microsoft.Exchange.Management.PowerShell.SnapIn;\u003Cbr>$User = \"test1\"\u003Cbr>New-MailboxexportRequest -mailbox $User -FilePath (\"\\\\localhost\\c$\\test\\\"+$User+\".pst\")\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Referring to the functionality in 1, the implementation code for exporting specific emails (containing the word 'pass' in the body) for user test1 to c:\\test on the Exchange server has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Parameters as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>DirectExportMailfromExchange -MailBox \"test1\" -ExportPath \"\\\\localhost\\c$\\test\\\" -Filter \"{`\"(body -like `\"*pass*`\")`\"}\" -Version 2013\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Specify the Exchange version required\u003C\u002Fp>\u003Cp>The process is as follows:\u003C\u002Fp>\u003Cp>1. Add the management snap-in\u003C\u002Fp>\u003Cp>2. Export emails and save them to c:\\test on the Exchange server in PST format\u003C\u002Fp>\u003Cp>The exported PST file can be opened with Outlook\u003C\u002Fp>\u003Ch2>0x04 Two Methods for Searching Emails\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Use PSSession to establish a connection and search for emails\u003C\u002Fh3>\u003Cp>The basic process is similar to exporting emails, with the difference being that the role group \"Mailbox Import Export\" needs to be replaced with \"Mailbox Search\"\u003C\u002Fp>\u003Cp>The implementation code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Search for emails containing the word 'pass' from user test1 and save them to the out2 folder of user test2 with the following parameters:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>UsePSSessionToSearchMailfromExchange -User \"administrator\" -Password \"DomainAdmin123!\" -MailBox \"test1\" -ConnectionUri \"http:\u002F\u002FExchange01.test.com\u002FPowerShell\u002F\" -Filter \"*pass*\" -TargetMailbox \"test2\" -TargetFolder \"out2\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The exported results are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019781789_0_8b821f2da7.jpeg\">\u003C\u002Fp>\u003Cp>Search for all emails containing the word 'pass' and save them to the outAll folder of user test2, with the following parameters:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>UsePSSessionToSearchMailfromExchange -User \"administrator\" -Password \"DomainAdmin123!\" -MailBox \"All\" -ConnectionUri \"http:\u002F\u002FExchange01.test.com\u002FPowerShell\u002F\" -Filter \"*pass*\" -TargetMailbox \"test2\" -TargetFolder \"outAll\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The exported results are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019793294_1_1b2cfc930e.jpeg\">\u003C\u002Fp>\u003Ch3>2. Directly search for emails on the Exchange server\u003C\u002Fh3>\u003Cp>The basic process is similar to exporting emails, with some differences in specific commands\u003C\u002Fp>\u003Cp>The implementation code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Search for emails containing the word 'pass' from user test1 and save them to the out2 folder of user test2, with the following parameters:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>DirectSearchMailfromExchange -MailBox \"test1\" -Filter \"*pass*\" -TargetMailbox \"test2\" -TargetFolder \"out2\" -Version 2013\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Search for all emails containing the word 'pass' and save them to the outAll folder of user test2, with the following parameters:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>DirectSearchMailfromExchange -MailBox \"All\" -Filter \"*pass*\" -TargetMailbox \"test2\" -TargetFolder \"outAll\" -Version 2013\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Supplement 1: Common commands for searching emails\u003C\u002Fh3>\u003Cp>(1) Enumerate all mailbox users and display the count of emails containing the keyword 'pass'\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Mailbox|Search-Mailbox -SearchQuery \"*pass*\" -EstimateResultOnly\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Search mailbox user test1, display the number of emails containing the keyword pass\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Search-Mailbox -Identity test1 -SearchQuery \"*pass*\" -EstimateResultOnly\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the example below, the count is 4\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019802160_2_f1590c4009.jpeg\">\u003C\u002Fp>\u003Cp>(3) Enumerate all mailbox users, export emails containing the keyword pass to user test2's folder out (without saving logs):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Mailbox|Search-Mailbox -SearchQuery \"*pass*\" -TargetMailbox \"test2\" -TargetFolder \"out\" -LogLevel Suppress\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(4) Search mailbox user test1, export emails containing the keyword pass to user test2's folder out (without saving logs):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Search-Mailbox -Identity test1 -SearchQuery \"*pass*\" -TargetMailbox \"test2\" -TargetFolder \"out\" -LogLevel Suppress\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Supplement 2: Search emails via ECP\u003C\u002Fh3>\u003Cp>Log in to ECP, add the current user to the Discovery Management group\u003C\u002Fp>\u003Cp>Refresh the page\u003C\u002Fp>\u003Cp>Select compliance management -&gt; in-place eDiscovery &amp; hold\u003C\u002Fp>\u003Cp>For specific operation details, refer to: https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fsecurity-and-compliance\u002Fin-place-ediscovery\u002Fin-place-ediscovery?redirectedfrom=MSDN#roles\u003C\u002Fp>\u003Ch3>Supplement 3: Add an administrator user via command line\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>powershell -c \"Add-PSSnapin Microsoft.Exchange.Management.PowerShell.SnapIn;$pwd=convertto-securestring Password123 -asplaintext -force;New-Mailbox -UserPrincipalName testuser1@test.com -OrganizationalUnit test.com\u002FUsers -Alias testuser1 -Name testuser1 -DisplayName testuser1 -Password $pwd;Add-RoleGroupMember \\\"Organization Management\\\" -Member testuser1 -BypassSecurityGroupManagerCheck\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces two methods for managing Exchange emails: directly invoking management units on the Exchange server and using PSSession to establish connections for remote email management. It details corresponding methods for exporting and searching emails, shares four open-source PowerShell scripts, and discusses script development specifics.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, if we obtain administrative privileges on an Exchange server, the next step is to search and export emails from it. This article will introduce two common methods, open-source four PowerShell scripts, and share details on script development.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Two methods for managing emails on an Exchange server\u003C\u002Fli>\u003Cli>Two methods for exporting emails\u003C\u002Fli>\u003Cli>Two methods for searching emails\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The methods introduced in this article are all PowerShell commands\u003C\u002Fp>\u003Ch2>0x02 Two Methods for Managing Emails on an Exchange Server\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. First, connect to the Exchange server using PSSession, then remotely manage emails\u003C\u002Fh3>\u003Cp>Command to connect to an Exchange server using PSSession:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$User = \"test\\administrator\"\u003Cbr>$Pass = ConvertTo-SecureString -AsPlainText DomainAdmin123! -Force\u003Cbr>$Credential = New-Object System.Management.Automation.PSCredential -ArgumentList $User,$Pass\u003Cbr>$Session = New-PSSession -ConfigurationName Microsoft.Exchange -ConnectionUri http:\u002F\u002FExchange01.test.com\u002FPowerShell\u002F -Authentication Kerberos -Credential $Credential\u003Cbr>Import-PSSession $Session -AllowClobber\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Additional notes:\u003C\u002Fp>\u003Cp>View PSSession:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-PSSession\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Disconnect PSSession:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-PSSession $Session\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test command (get all mailbox users):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Mailbox\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Commands to manage mail directly on the Exchange server\u003C\u002Fh3>\u003Cp>Test command (get names of all mailbox users):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-PSSnapin Microsoft.Exchange.Management.PowerShell.SnapIn;\u003Cbr>Get-Mailbox\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The management snap-in names vary across different Exchange versions:\u003C\u002Fp>\u003Cul>\u003Cli>Exchange 2007:\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Add-PSSnapin Microsoft.Exchange.Management.PowerShell.Admin;\u003C\u002Fp>\u003Cul>\u003Cli>Exchange 2010:\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Add-PSSnapin Microsoft.Exchange.Management.PowerShell.E2010;\u003C\u002Fp>\u003Cul>\u003Cli>Exchange 2013 &amp; 2016:\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Add-PSSnapin Microsoft.Exchange.Management.PowerShell.SnapIn;\u003C\u002Fp>\u003Ch3>Supplement: Common commands for managing Exchange mailboxes\u003C\u002Fh3>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fpowershell\u002Fmodule\u002Fexchange\u002F?view=exchange-ps\u003C\u002Fp>\u003Ch4>(1) Retrieve all mailbox user names:\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Mailbox -ResultSize unlimited\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>By default, 1000 users are displayed. Adding -ResultSize unlimited retrieves all users.\u003C\u002Fp>\u003Ch4>(2) Retrieve information for all mailboxes, including message count and last mailbox access time\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Mailbox | Get-MailboxStatistics\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Retrieve all OUs\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-OrganizationalUnit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(4) Obtain send\u002Freceive email information through message tracking logs\u003C\u002Fh4>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fpowershell\u002Fmodule\u002Fexchange\u002Fmail-flow\u002Fget-messagetrackinglog?view=exchange-ps\u003C\u002Fp>\u003Cp>Default message tracking log location: %ExchangeInstallPath%TransportRoles\\Logs\\MessageTracking\u003C\u002Fp>\u003Cp>View all email information (including sender, recipient, and subject) sent by test1@test.com from 9:00 on January 1, 2019 to present:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-MessageTrackingLog -Start \"01\u002F11\u002F2019 09:00:00\" -Sender \"test1@test.com\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The returned results are messy, containing multiple events:\u003C\u002Fp>\u003Cul>\u003Cli>DSN\u003C\u002Fli>\u003Cli>Defer\u003C\u002Fli>\u003Cli>Deliver\u003C\u002Fli>\u003Cli>Send\u003C\u002Fli>\u003Cli>Receive\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Filter only sent events to make the returned results more concise:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-MessageTrackingLog -EventID send -Start \"01\u002F11\u002F2019 09:00:00\" -Sender \"test1@test.com\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Script to count the number of emails sent and received daily:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgallery.technet.microsoft.com\u002Foffice\u002Ff2af711e-defd-476d-896e-8053aa964bc5\u002Fview\u002FDiscussions\u003C\u002Fp>\u003Cp>Need to modify the start time and add the command to load the Exchange PowerShell management snap-in\u003C\u002Fp>\u003Ch2>0x03 Two Methods for Exporting Emails\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Using PSSession to establish a connection and export emails\u003C\u002Fh3>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fpowershell\u002Fmodule\u002Fexchange\u002Fmailboxes\u002Fnew-mailboxexportrequest?view=exchange-ps\u003C\u002Fp>\u003Ch4>(1) Add the user to the role group \"Mailbox Import Export\"\u003C\u002Fh4>\u003Cp>Here, using the user administrator as an example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-ManagementRoleAssignment –Role \"Mailbox Import Export\" –User Administrator\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Supplement: Removed command\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-ManagementRoleAssignment -Identity \"Mailbox Import Export-Administrator\" -Confirm:$false\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Verify after addition:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-ManagementRoleAssignment –Role \"Mailbox Import Export\"|fl user\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Restart PowerShell\u003C\u002Fh4>\u003Cp>Otherwise, the New-MailboxExportRequest command cannot be used\u003C\u002Fp>\u003Ch4>(3) Export emails and save\u003C\u002Fh4>\u003Cp>Three examples are provided here\u003C\u002Fp>\u003Cp>1. Export all emails of a specified user and save to c:\\test on the Exchange server\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$User = \"test1\"\u003Cbr>New-MailboxExportRequest -mailbox $User -FilePath (\"\\\\localhost\\c$\\test\\\"+$User+\".pst\")\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Filter emails containing the word 'pass' in the body for a specified user and save to c:\\test on the Exchange server\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$User = \"test1\"\u003Cbr>New-MailboxExportRequest -mailbox $User -ContentFilter {(body -like \"*pass*\")} -FilePath (\"\\\\localhost\\c$\\test\\\"+$User+\".pst\")\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>3. Export all emails and save to c:\\test on the Exchange server\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Mailbox -OrganizationalUnit Users -Resultsize unlimited |%{New-MailboxexportRequest -mailbox $_.name -FilePath (\"\\\\localhost\\c$\\test\\\"+($_.name)+\".pst\")}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After export, the export request records are automatically saved, with a default retention of 30 days\u003C\u002Fp>\u003Cp>If you do not want to save export requests, you can add the parameter -CompletedRequestAgeLimit 0\u003C\u002Fp>\u003Cp>Supplement: Regarding operations related to export requests\u003C\u002Fp>\u003Cp>View email export requests:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-MailboxExportRequest\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Delete a specific export request:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-MailboxExportRequest -RequestQueue \"Mailbox Database 2057988509\" -RequestGuid 650f52ec-722b-47bb-8e73-d16a17c32129 -Confirm:$false\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-MailboxExportRequest -Identity 'test.com\u002FUsers\u002Ftest1\\MailboxExport' -Confirm:$false\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Matching parameters are obtained from the results of Get-MailboxExportRequest|fl\u003C\u002Fp>\u003Cp>Delete all export requests:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-MailboxExportRequest|Remove-MailboxExportRequest -Confirm:$false\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>In summary, the implementation code for exporting specific emails (containing the word 'pass' in the body) of user test1 to the Exchange server's c:\\test has been uploaded to GitHub, with the address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>UsePSSessionToExportMailfromExchange -User \"administrator\" -Password \"DomainAdmin123!\" -MailBox \"test1\" -ExportPath \"\\\\Exchange01.test.com\\c$\\test\\\" -ConnectionUri \"http:\u002F\u002FExchange01.test.com\u002FPowerShell\u002F\" -Filter \"{`\"(body -like `\"*pass*`\")`\"}\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The process is as follows:\u003C\u002Fp>\u003Cp>1. Use PSSession to connect to the Exchange server\u003C\u002Fp>\u003Cp>2. Determine whether the user used has been added to the role group \"Mailbox Import Export\"\u003C\u002Fp>\u003Cp>If not added, the user needs to be added\u003C\u002Fp>\u003Cp>3. Export emails and save them to c:\\test on the Exchange server in PST format\u003C\u002Fp>\u003Cp>4. If a user was newly added, they will be removed from the role group \"Mailbox Import Export\"\u003C\u002Fp>\u003Cp>5. Clear the PSSession\u003C\u002Fp>\u003Cp>The exported PST file can be opened using Outlook\u003C\u002Fp>\u003Ch3>2. Directly export emails on the Exchange server\u003C\u002Fh3>\u003Ch4>(1) Add the management snap-in\u003C\u002Fh4>\u003Cp>The names of the management snap-ins vary by Exchange version:\u003C\u002Fp>\u003Cul>\u003Cli>Exchange 2007:\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Add-PSSnapin Microsoft.Exchange.Management.PowerShell.Admin;\u003C\u002Fp>\u003Cul>\u003Cli>Exchange 2010:\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Add-PSSnapin Microsoft.Exchange.Management.PowerShell.E2010;\u003C\u002Fp>\u003Cul>\u003Cli>Exchange 2013 &amp; 2016:\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Add-PSSnapin Microsoft.Exchange.Management.PowerShell.SnapIn;\u003C\u002Fp>\u003Cp>No need to consider role groups, emails can be exported directly\u003C\u002Fp>\u003Ch4>(2) Export emails\u003C\u002Fh4>\u003Cp>Export emails for user test1, save to c:\\test on the Exchange server:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-PSSnapin Microsoft.Exchange.Management.PowerShell.SnapIn;\u003Cbr>$User = \"test1\"\u003Cbr>New-MailboxexportRequest -mailbox $User -FilePath (\"\\\\localhost\\c$\\test\\\"+$User+\".pst\")\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Referring to the functionality in 1, the implementation code for exporting specific emails (containing the word 'pass' in the body) for user test1 to c:\\test on the Exchange server has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Parameters as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>DirectExportMailfromExchange -MailBox \"test1\" -ExportPath \"\\\\localhost\\c$\\test\\\" -Filter \"{`\"(body -like `\"*pass*`\")`\"}\" -Version 2013\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Specify the Exchange version required\u003C\u002Fp>\u003Cp>The process is as follows:\u003C\u002Fp>\u003Cp>1. Add the management snap-in\u003C\u002Fp>\u003Cp>2. Export emails and save them to c:\\test on the Exchange server in PST format\u003C\u002Fp>\u003Cp>The exported PST file can be opened with Outlook\u003C\u002Fp>\u003Ch2>0x04 Two Methods for Searching Emails\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Use PSSession to establish a connection and search for emails\u003C\u002Fh3>\u003Cp>The basic process is similar to exporting emails, with the difference being that the role group \"Mailbox Import Export\" needs to be replaced with \"Mailbox Search\"\u003C\u002Fp>\u003Cp>The implementation code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Search for emails containing the word 'pass' from user test1 and save them to the out2 folder of user test2 with the following parameters:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>UsePSSessionToSearchMailfromExchange -User \"administrator\" -Password \"DomainAdmin123!\" -MailBox \"test1\" -ConnectionUri \"http:\u002F\u002FExchange01.test.com\u002FPowerShell\u002F\" -Filter \"*pass*\" -TargetMailbox \"test2\" -TargetFolder \"out2\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The exported results are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019781789_0_8b821f2da7-1.jpeg\">\u003C\u002Fp>\u003Cp>Search for all emails containing the word 'pass' and save them to the outAll folder of user test2, with the following parameters:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>UsePSSessionToSearchMailfromExchange -User \"administrator\" -Password \"DomainAdmin123!\" -MailBox \"All\" -ConnectionUri \"http:\u002F\u002FExchange01.test.com\u002FPowerShell\u002F\" -Filter \"*pass*\" -TargetMailbox \"test2\" -TargetFolder \"outAll\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The exported results are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019793294_1_1b2cfc930e-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Directly search for emails on the Exchange server\u003C\u002Fh3>\u003Cp>The basic process is similar to exporting emails, with some differences in specific commands\u003C\u002Fp>\u003Cp>The implementation code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Search for emails containing the word 'pass' from user test1 and save them to the out2 folder of user test2, with the following parameters:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>DirectSearchMailfromExchange -MailBox \"test1\" -Filter \"*pass*\" -TargetMailbox \"test2\" -TargetFolder \"out2\" -Version 2013\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Search for all emails containing the word 'pass' and save them to the outAll folder of user test2, with the following parameters:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>DirectSearchMailfromExchange -MailBox \"All\" -Filter \"*pass*\" -TargetMailbox \"test2\" -TargetFolder \"outAll\" -Version 2013\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Supplement 1: Common commands for searching emails\u003C\u002Fh3>\u003Cp>(1) Enumerate all mailbox users and display the count of emails containing the keyword 'pass'\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Mailbox|Search-Mailbox -SearchQuery \"*pass*\" -EstimateResultOnly\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Search mailbox user test1, display the number of emails containing the keyword pass\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Search-Mailbox -Identity test1 -SearchQuery \"*pass*\" -EstimateResultOnly\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the example below, the count is 4\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019802160_2_f1590c4009-1.jpeg\">\u003C\u002Fp>\u003Cp>(3) Enumerate all mailbox users, export emails containing the keyword pass to user test2's folder out (without saving logs):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Mailbox|Search-Mailbox -SearchQuery \"*pass*\" -TargetMailbox \"test2\" -TargetFolder \"out\" -LogLevel Suppress\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(4) Search mailbox user test1, export emails containing the keyword pass to user test2's folder out (without saving logs):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Search-Mailbox -Identity test1 -SearchQuery \"*pass*\" -TargetMailbox \"test2\" -TargetFolder \"out\" -LogLevel Suppress\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Supplement 2: Search emails via ECP\u003C\u002Fh3>\u003Cp>Log in to ECP, add the current user to the Discovery Management group\u003C\u002Fp>\u003Cp>Refresh the page\u003C\u002Fp>\u003Cp>Select compliance management -&gt; in-place eDiscovery &amp; hold\u003C\u002Fp>\u003Cp>For specific operation details, refer to: https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fsecurity-and-compliance\u002Fin-place-ediscovery\u002Fin-place-ediscovery?redirectedfrom=MSDN#roles\u003C\u002Fp>\u003Ch3>Supplement 3: Add an administrator user via command line\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>powershell -c \"Add-PSSnapin Microsoft.Exchange.Management.PowerShell.SnapIn;$pwd=convertto-securestring Password123 -asplaintext -force;New-Mailbox -UserPrincipalName testuser1@test.com -OrganizationalUnit test.com\u002FUsers -Alias testuser1 -Name testuser1 -DisplayName testuser1 -Password $pwd;Add-RoleGroupMember \\\"Organization Management\\\" -Member testuser1 -BypassSecurityGroupManagerCheck\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces two methods for managing Exchange emails: directly invoking management units on the Exchange server and using PSSession to establish connections for remote email management. It details corresponding methods for exporting and searching emails, shares four open-source PowerShell scripts, and discusses script development specifics.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1743,"Onedaysec",7,"published","2026-02-02T08:20:05.024Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Exchange Server Email Search & Export for Penetration Testing","Exchange server, email export, PowerShell scripts, penetration testing, email search, PSSession, Exchange management",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46,47],82,80,79,78,{"title":39,"description":39,"image":39},"2026-07-24T15:37:15.570Z","2026-07-23T16:00:58.713Z","draft","2026-07-23T16:03:27.366Z"]