I've got a testing engagement next week, that covers lots of technologies. One type of server we will be testing that we normally do not test is an Exchange server. As of today, the DISA checklist is in draft. That will help us out. However, while searching for further guidance, I came across CISecuritiy's benchmark page. They have a page dedicated to Exchange and it appears that they had a tool at one time, but there is no longer a link to the tool.
Does anyone have a tool that will run against an Exchange Server looking at Exchange specific issues? Certainly, the server will have Gold Disk, Oval and Retina run against it looking for vulnerabilities, but I'm looking for something more targeted.