Microsoft has announced a significant security upgrade for Exchange Server and SharePoint Server through integration with the Windows Antimalware Scan Interface (AMSI), providing critical protection for these business-critical systems that are frequent targets for cyberattacks.
Exchange Server and SharePoint Server represent “crown jewels” for many organizations, making them prime targets for sophisticated threat actors.
The new AMSI integration offers an essential layer of defense by intercepting and preventing harmful web requests before they reach vulnerable backend endpoints.
“This integration becomes especially important when attackers attempt to exploit security vulnerabilities, particularly zero-days,” Microsoft emphasized in their announcement.
“With AMSI integrated, these malicious attempts are detected and blocked in real-time, offering a critical defense mechanism while organizations work on installing official patches and updates.”
The AMSI implementation functions as a security filter module within the Internet Information Services (IIS) pipeline, leveraging SPRequesterFilteringModule for SharePoint and HttpRequestFilteringModule for Exchange.
This architectural approach enables inspection of incoming HTTP requests at the onBeginRequest stage, before authentication and authorization phases occur.
When malicious activity is detected, the system automatically returns an HTTP 400 Bad Request response, effectively terminating the attack attempt before execution.
Recent improvements have significantly expanded AMSI’s protective capabilities. While initial implementations only scanned request headers, newer versions now inspect complete request bodies as well.
This advancement proves crucial for detecting sophisticated attacks embedded within payload content rather than headers alone.
“These enhanced security controls are not enabled by default, making it crucial for organizations to assess for stronger protection,” Microsoft warned.
The AMSI integration provides defense against numerous attack methodologies, including:
One detection example highlights how AMSI identified suspicious PowerShell activity:
This query helps security teams identify potential malicious processes executed by the IIS worker process.
Microsoft recommends organizations take immediate steps to activate AMSI protection:
The enhanced AMSI integration is complemented by Microsoft’s broader security ecosystem, including Microsoft Defender Antivirus, Microsoft Defender for Endpoint, and Microsoft Security Copilot, providing comprehensive threat detection across the environment.
“Keeping these servers safe from these advanced attacks is of utmost importance,” Microsoft advised in their security guidance, emphasizing the critical nature of these business systems and the sophisticated threats they continue to face.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…