Step-by-step walkthrough of a LetsDefend SOC342 lab analyzing CVE-2025-53770 SharePoint ToolShell auth bypass and RCE, including attack chain, forensic analysis, and containment actions.
I investigated a SharePoint zero-day called ToolShell (CVE-2025-53770) in the LetsDefend cyber lab.
The exercise mimicked a real-world zero-day RCE attack where a malicious POST request bypassed authentication, executed PowerShell to steal MachineKeySection keys, compiled payload.exe, and dropped a malicious web shell (spinstall0.aspx).
This README documents the attack process, forensic steps, containment actions, and lessons learned.
| Field | Details |
|---|---|
| Platform | LetsDefend Cyber Range |
| Target | SharePoint Server (SharePoint01) |
| CVE | CVE-2025-53770 |
| Objective | Analyze RCE, practice detection & containment |
| Tools Used | Windows PowerShell, VirusTotal, AbuseIPDB, Talosintelligence, LetsDefend Log Management, LetsDefend Endpoint Security, Base64 Decoder, LetsDefend Threat Intel |
A critical alert flagged suspicious activity targeting ToolPane.aspx in SharePoint with a large payload and spoofed Referer.
This correlates with CVE-2025-53770, a zero-day vulnerability allowing unauthenticated RCE via crafted POST requests.

What it is: The severity level assigned to this alert — highest and most urgent.
Why it matters: Indicates this event could lead to full system compromise (RCE). Treat as top-priority: isolate and investigate immediately.
What it is: The timestamp when the alert was triggered.
Why it matters: Use it to locate logs, correlate related events, and build a timeline (search ± few minutes or hours).
What it is: The detection rule or signature that fired, describing the matched condition (ToolShell exploit attempt).
Why it matters: Identifies what attack pattern was detected — useful for hunting similar cases (e.g., unauthenticated POSTs to admin pages or potential webshell uploads).
What it is: Numeric identifier for this specific alert instance or rule (vendor-defined).
Why it matters: Helps with tracking, filtering, and referencing this alert in tickets or reports.
What it is: High-level classification — this alert targets web infrastructure.
Why it matters: Routes incident to the web/SharePoint/infra team and applies web-specific playbooks.
What it is: Analyst role or escalation level expected to handle the alert.
Why it matters: Indicates this is not a Tier-1 alert — requires a Security Analyst (experienced responder) for immediate action.
What it is: Name of the affected host (target or origin of the activity).
Why it matters: This is the primary containment target — isolate, collect evidence, and monitor this system first.
What it is: The IP sending the suspicious request (attacker or proxy).
Why it matters: Block it at the firewall/WAF, search for other hits from it, and check ownership/geo info. Note: IPs can be spoofed or part of botnets.
What it is: The internal target IP (SharePoint01).
Why it matters: Confirms which internal system was targeted — map it to hostname and review internal access paths/firewall rules.
What it is: The HTTP verb used — client sent data to the server.
Why it matters: POSTs to admin endpoints are suspicious when unauthenticated or large — they can carry exploit payloads or webshells.
/_layouts/15/ToolPane.aspx?DisplayMode=Edit&a=/ToolPane.aspx
What it is: The exact targeted web path and parameters.
Why it matters: This is a SharePoint admin/layout endpoint — commonly abused by attackers for auth bypass or code uploads. Hunt for other requests to the same path.
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0
What it is: The browser string reported by the client.
Why it matters: Often spoofed by attackers to look legitimate — can help filter logs, but don’t rely on it for attribution.
/_layouts/SignOut.aspx
What it is: HTTP header claiming the request came from SharePoint’s sign-out page.
Why it matters: Spoofed referers are suspicious — may be used to bypass checks or mimic normal traffic. Compare with legitimate navigation flows.
7699What it is: Size of the HTTP request body (in bytes).
Why it matters: A large POST body to an admin endpoint suggests a serialized exploit or file upload. Look for other POSTs of similar size to same URL.
Text: Suspicious unauthenticated POST request targeting ToolPane.aspx with large payload size and spoofed referer — indicative of CVE-2025-53770 exploitation.
What it is: Rule explanation summarizing the matched behavior.
Why it matters: Describes exactly why the alert fired — verify whether the request was unauthenticated, what payload was sent, and if it matches known exploit patterns.
What it is: Indicates the protecting device’s response (e.g., WAF/firewall).
Why it matters: Since it was allowed, the attack reached the host — treat as potential compromise.
Immediate actions:
107.191.58.76)SharePoint01)🔎 Summary:
This alert reflects an unauthenticated exploit attempt exploiting ToolPane.aspx (SharePoint RCE CVE-2025-53770). The POST request contained a large payload and spoofed referer, consistent with ToolShell zero-day exploitation behavior. Because the device allowed the request, assume possible compromise until proven otherwise. 🟥 Severity: Critical
Search IIS/WAF for POSTs to ToolPane.aspx (around 2025-07-22 13:07):
Select-String -Path "C:\inetpub\logs\LogFiles\**\*.log" -Pattern "/_layouts/15/ToolPane.aspx" | Out-File .\IIS_ToolPane_hits.txt
Pull full POST body from WAF/proxy or packet capture and save to forensic share.
Look for new/modified ASPX in webroot (webshells):
Get-ChildItem "C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\**\*.aspx" -Recurse | Sort LastWriteTime -Desc | Select FullName,LastWriteTime
Block attacker & isolate host: block 107.191.58.76 at perimeter/WAF and move SharePoint01 to quarantine (or restrict egress).
Do not delete suspected files — make forensic copies first.