MailSniper: Exchange Mailbox Search for Penetration Tests
MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It can be used as a non-administrative user to search their own email, or by an administrator to search the mailboxes of every user in a domain.
At a glance
- What is it?
- MailSniper is a PowerShell tool that searches Exchange mailboxes for terms like passwords and credentials, either in your own mailbox or, with the ApplicationImpersonation role, across an entire domain. It ships as a single script with no installer.
- Who is it for?
- MailSniper fits red teams and Exchange administrators who already hold valid credentials and need to find what a mailbox contains. It does not fit anyone without authorization over the target mailboxes, and it is not a mail archiving or compliance tool.
- Can I use it commercially?
- Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 10 days ago.
- What is it written in?
- Mainly PowerShell, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 26, 2026, and from our analysis. They are not legal advice.
Editorial analysis
The Problem MailSniper Solves in an Exchange Environment
Mailboxes hold the material that makes a penetration test succeed: passwords pasted into messages, credentials shared between colleagues, network diagrams attached to project threads. Reading that by hand does not scale past one mailbox, and Exchange Web Services (EWS) is not a friendly interface for ad hoc queries. MailSniper wraps EWS in PowerShell functions that take a search term and return matching messages.
The README frames two audiences. A non-administrative user runs Invoke-SelfSearch against their own mailbox, which the project describes as useful for privilege escalation after credentials are obtained or for locating sensitive data as a non-admin. An Exchange administrator runs Invoke-GlobalMailSearch, which grants the ApplicationImpersonation role to a chosen account so that account can read every other domain user's mailbox. The distinction matters: the first needs nothing beyond a valid mailbox, the second needs administrative rights over the Exchange organization, at least long enough to grant the role.
How the Impersonation Search Flow Works
Invoke-GlobalMailSearch is the more involved of the two functions, and the README describes its sequence plainly. The function connects to the Exchange server, prompts for administrative credentials (a member of Exchange Organization Administrators or Organization Management), and sets up a PowerShell remoting session with that server. Inside that session it grants the ApplicationImpersonation role to the account named in ImpersonationAccount. It then builds a list of all mailboxes in the Exchange database and connects to EWS as that impersonation account.
From there it pulls a number of emails from each mailbox and searches their subject and body. The default term list is "*password*","*creds*","*credentials*". The default is 100 of the latest emails per mailbox, which is a real constraint: older messages are not examined unless MailsPerUser is raised. By default only the Inbox folder is searched; passing 'all' to the Folder parameter extends the search to all folders and subfolders. Results can be written to a CSV with OutputCsv.
Invoke-SelfSearch follows a shorter path. It autodiscovers the Exchange server from the mailbox address, connects over EWS, and searches the current user's mailbox with the same default terms. A Remote switch opens a credential prompt for reaching an EWS service from the internet. Attachments are not read unless CheckAttachments is set, and attachment search covers .bat, .htm, .msg, .pdf, .txt, .ps1, .doc and .xls files, which can be downloaded with DownloadDir.
Running MailSniper: Install and First Search
There is no package manager step and no installer. The repository holds three top-level entries: LICENSE, MailSniper.ps1 and README.md. Getting the tool means obtaining MailSniper.ps1 and running it in a PowerShell session on a host that can reach the Exchange server. The README does not document a gallery install, so treat the script itself as the distribution.
A first self-search looks like this, taken from the README:
Invoke-SelfSearch -Mailbox [email protected]This connects to the Exchange server autodiscovered from the address and searches the latest 100 messages in that mailbox for the default terms. The reader should expect matches printed to the console unless OutputCsv is supplied.
The domain-wide search is the same shape but requires the administrator prompt and the impersonation grant:
Invoke-GlobalMailSearch -ImpersonationAccount current-username -ExchHostname Exch01 -OutputCsv global-email-search.csvAfter the administrative credentials are entered, the script grants ApplicationImpersonation to current-username, enumerates the domain's email addresses, and writes matches to global-email-search.csv. Two parameters are worth setting on the first run: MailsPerUser if 100 messages per mailbox is too shallow, and Folder with 'all' if the target material is likely filed outside the Inbox. The README also lists ExchangeVersion, which defaults to Exchange2010, and EmailList, a text file of addresses to search one per line, as a way to narrow a broad sweep.
Where MailSniper Breaks Down
The ApplicationImpersonation grant is the sharp edge. It is a persistent change to the Exchange organization, and the README describes granting it, not revoking it. Nothing in the documented parameters covers cleanup, so the operator has to remove the role through Exchange tooling afterwards. On an engagement where changes must be reverted and logged, that is a step the tool does not manage for you.
The search itself is shallow by design. One hundred messages per mailbox, Inbox only, subject and body only unless CheckAttachments is set. A mailbox where the sensitive thread sits in a subfolder from two years ago will return nothing, and the operator may read that as a clean result. Regex searches override the Terms flag rather than combining with it, so you choose one mode. Attachment scanning is limited to the eight extensions the README lists; a .docx or .zip attachment is outside that set. Finally, the default ExchangeVersion of Exchange2010 means a modern deployment may need that parameter adjusted, and the README does not spell out which versions are supported.
MailSniper Compared with Exchange Content Search
The native alternative is Exchange's own eDiscovery and content search tooling, driven from the Exchange admin center or PowerShell. The difference is who holds the authority. Native content search runs under Exchange's own role model, with search and hold workflows, and it is the sanctioned path for an administrator who needs to find messages across mailboxes. MailSniper takes a different route: it borrows the ApplicationImpersonation role so that an ordinary account can read other mailboxes through EWS, which is exactly what makes it useful in an offensive engagement where you hold a compromised account and want to blend in with normal EWS traffic.
That same design makes it the wrong tool for compliance work. A legal hold or a records request needs audit trails and retention semantics that MailSniper does not implement; it searches and writes a CSV. The README's own framing supports this split, describing the tool as a penetration testing tool rather than an administrative one. If you are on the defensive side and want to know what an attacker would see, running MailSniper with your own credentials is a reasonable way to reproduce the view.
Licence and Maintenance Costs
MailSniper is MIT licensed, with the LICENSE file at the repository root. MIT permits use, modification and redistribution provided the copyright notice and permission notice are retained. That is permissive enough for internal red team use and for incorporating the script into another tool, but it comes with no warranty, and the licence does not address what you may do to the systems you point it at. Authorization for the mailboxes you search is a separate question from the software licence.
The last push to the default branch was on 2026-09-21, and the repository is not archived. There are no retrieved releases, so there is no versioned artifact to pin; upgrading means pulling the current MailSniper.ps1. That has a practical consequence for anyone using it repeatedly: without releases, there is no changelog to read between runs, and a parameter's behaviour can change without a version number to notice. Keeping a copy of the script you validated, and diffing it against the repository before the next engagement, is a cheaper habit than re-reading the README each time.
Editorial conclusion
MailSniper fits red teams and Exchange administrators who already hold valid credentials and need to find what a mailbox contains. It does not fit anyone without authorization over the target mailboxes, and it is not a mail archiving or compliance tool. Before running it, confirm the Exchange version you are pointing at, since the script defaults to Exchange2010, and confirm whether you want only the Inbox or all folders, because the default search covers the Inbox alone.
Frequently asked questions
What is MailSniper used for?
It is a penetration testing tool that searches email in a Microsoft Exchange environment for specific terms such as passwords, insider intel or network architecture information. It can search your own mailbox as a non-administrative user, or every user's mailbox in a domain as an administrator.
How do I install MailSniper?
The repository contains MailSniper.ps1, README.md and LICENSE, and the README documents no installer or package manager step. You obtain the script and run its functions in a PowerShell session that can reach the Exchange server.
What is the difference between Invoke-SelfSearch and Invoke-GlobalMailSearch?
Invoke-SelfSearch connects to Exchange over EWS and searches the current user's own mailbox. Invoke-GlobalMailSearch grants the ApplicationImpersonation role to a specified account, enumerates the domain's mailboxes, and searches each of them using that role, which requires Exchange administrative credentials.
Does MailSniper search email attachments?
Only when the CheckAttachments option is set. The README states it searches attachments with the extensions .bat, .htm, .msg, .pdf, .txt, .ps1, .doc and .xls, and that those attachments can be downloaded by specifying the DownloadDir option.
Which Exchange version does MailSniper connect to by default?
The ExchangeVersion parameter defaults to Exchange2010 according to the README's options list for both Invoke-GlobalMailSearch and Invoke-SelfSearch. The README does not document which other versions are supported.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/dafthack-mailsniper)