and if youre lucky, sometimetimes you catch one that may be actually interesting, possibly being used by an active malicious actor / campaign
"GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1"
never seen that one before, but I bet its working for SOMEONE out there