[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fgoMLuPMC5o-drDfwY-7IlGDehC6MFK6l6fQWw5tix_o":3},{"article":4,"iocs":36,"watch_terms":40},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":10,"url":11,"image_url":10,"published_at":12,"ingested_at":13,"relevance_score":14,"entities":15,"category_id":16,"category":17,"article_tags":20},"24d43283-6fae-419e-a791-a9ef2053dceb","\"On the Exchange email server, the threat actor used a legitimate Windows executable, SystemSetti...","on-the-exchange-email-server-the-threat-actor-used-a-legitimate-windows-executab","\"On the Exchange email server, the threat actor used a legitimate Windows executable, SystemSettingsAdminFlows.exe, which allows users to customize or configure the system settings to user’s preference. This LOLBIN was used to disable Windows... \"\n\nReport: https:\u002F\u002Ft.co\u002FMdbthjk2PA https:\u002F\u002Ft.co\u002FhA0JFuj98M","A threat actor compromised an Exchange email server using SystemSettingsAdminFlows.exe, a legitimate Windows executable, as a living-off-the-land binary (LOLBIN) to disable Windows security features. This technique demonstrates hands-on-keyboard post-exploitation activity aimed at establishing persistence and evading detection on a compromised mail server.",null,"https:\u002F\u002Fx.com\u002FTheDFIRReport\u002Fstatus\u002F2033524965782196520","2026-03-17T07:01:10.667+00:00","2026-03-16T13:00:06.362078+00:00",7,[],"c5eccf7c-abbc-4bd3-bbed-e6da5cba8e73",{"id":16,"icon":10,"name":18,"slug":19},"Incident Response","incident-response",[21,26,31],{"category":22},{"id":23,"icon":10,"name":24,"slug":25},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":27},{"id":28,"icon":10,"name":29,"slug":30},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":32},{"id":33,"icon":10,"name":34,"slug":35},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[37],{"type":30,"value":38,"context":39},"SystemSettingsAdminFlows.exe","Legitimate Windows executable abused as LOLBIN for lateral movement and security feature disablement on compromised Exchange server",[]]