Book a demo call with us
Cross icon
Email

Microsoft Exchange

Microsoft's email server platform (on-premise and cloud via Microsoft 365) used by organizations to manage email communications. It generates email activity logs and is a key data source for phishing investigation and email-based threat detection.

Microsoft Exchange

What is Microsoft Exchange?

Microsoft Exchange is Microsoft's email platform, available both as an on-premise server deployment and as a cloud service through Microsoft 365. It is the email backbone for a large proportion of enterprise organizations, processing millions of messages daily and generating detailed message trace logs, transport rule events, and mailbox audit records. For security teams, Exchange logs are the primary data source for phishing investigations: they show exactly which users received a malicious email, whether it was clicked, whether forwarding rules were created by an attacker, and whether any data was exfiltrated through email channels. Exchange also integrates with Microsoft Defender for Office 365, which adds sandboxing and detonation capabilities for attachments and URLs, layering threat intelligence on top of the raw message flow data.

How does Microsoft Exchange work with Qevlar?

Qevlar integrates with Microsoft Exchange to investigate email-based threats as part of automated alert triage. When a phishing campaign or a business email compromise scenario is detected, Qevlar can query Exchange to identify all affected mailboxes, trace the delivery path of malicious messages, and determine whether any attacker-created forwarding rules remain active.

Want to help your analysts focus on the most critical alerts?

Frequently asked questions

What is Microsoft Exchange?

bar
bar

Microsoft Exchange is Microsoft's email platform, available on-premise and via Microsoft 365. It generates message-trace logs, transport-rule events and mailbox audit records — the primary data source for phishing and business email compromise investigations.

What can you do with Microsoft Exchange in Qevlar?

bar
bar

Qevlar can query Exchange to investigate email-based threats automatically — identifying every affected mailbox, tracing the delivery path of a malicious message and checking for attacker-created forwarding rules.

Does Qevlar investigate phishing reports automatically?

bar
bar

Yes. When a phishing campaign or BEC scenario is detected, Qevlar determines the full scope of delivery and engagement across mailboxes without manual mailbox-by-mailbox review.

Can Qevlar work alongside Microsoft Defender for Office 365?

bar
bar

Yes. Qevlar combines Exchange message data with Defender for Office 365 verdicts and the wider Microsoft stack to build a complete picture of an email threat.

Other integrations