LoFP LoFP / legitimate installations of exchange transportagents. assemblypath is a good indicator for this.

Techniques

Sample rules

MSExchange Transport Agent Installation

Description

Detects the Installation of a Exchange Transport Agent

Detection logic

condition: selection
selection:
  CommandLine|contains: Install-TransportAgent

MSExchange Transport Agent Installation - Builtin

Description

Detects the Installation of a Exchange Transport Agent

Detection logic

condition: selection
selection:
- Install-TransportAgent

Failed MSExchange Transport Agent Installation

Description

Detects a failed installation of a Exchange Transport Agent

Detection logic

condition: selection
selection:
  Data|contains: Install-TransportAgent
  EventID: 6