Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
LetsDefend-SOC342-CVE-2025-53770-SharePoint-ToolShell-Auth-Bypass-andRCE-EventID-320 — Step-by-step walkthrough of a LetsDefend SOC342 lab analyzing CVE-2025-53770 SharePoint ToolShell auth bypass and RCE, including attack chain, forensic analysis, and containment actions. | Kitploit
Tools/GitHubGitHub/victormbogu1/letsdefend-soc342-cve-2025-53770-sharepoint-toolshell-auth-bypass-andrce-eventid-320
Vulnerability AnalysisExploitationWeb Application ExploitationForensicsCTFPenetration TestingLearning & EducationIncident ResponseLabs & Practice
GitHubvictormbogu1/letsdefend-soc342-cve-2025-53770-sharepoint-toolshell-auth-bypass-andrce-eventid-320

LetsDefend-SOC342-CVE-2025-53770-SharePoint-ToolShell-Auth-Bypass-andRCE-EventID-320

Step-by-step walkthrough of a LetsDefend SOC342 lab analyzing CVE-2025-53770 SharePoint ToolShell auth bypass and RCE, including attack chain, forensic analysis, and containment actions.

View Repository
190 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🧠 LetsDefend SharePoint Zero-Day Analysis (ToolShell - SOC342-CVE-2025-53770)

📘 Introduction

I investigated a SharePoint zero-day called ToolShell (CVE-2025-53770) in the LetsDefend cyber lab.
The exercise mimicked a real-world zero-day RCE attack where a malicious POST request bypassed authentication, executed PowerShell to steal MachineKeySection keys, compiled payload.exe, and dropped a malicious web shell (spinstall0.aspx).
This README documents the attack process, forensic steps, containment actions, and lessons learned.


⚙️ Lab Overview

FieldDetails
PlatformLetsDefend Cyber Range
TargetSharePoint Server (SharePoint01)
CVECVE-2025-53770
ObjectiveAnalyze RCE, practice detection & containment
Tools UsedWindows PowerShell, VirusTotal, AbuseIPDB, Talosintelligence, LetsDefend Log Management, LetsDefend Endpoint Security, Base64 Decoder, LetsDefend Threat Intel

🚨 The Alert

A critical alert flagged suspicious activity targeting ToolPane.aspx in SharePoint with a large payload and spoofed Referer.
This correlates with CVE-2025-53770, a zero-day vulnerability allowing unauthenticated RCE via crafted POST requests.

Nat_Created Nat_Created

🚨 Alert Breakdown — SOC342: CVE-2025-53770 SharePoint ToolShell Auth Bypass & RCE


🔴 Critical

What it is: The severity level assigned to this alert — highest and most urgent.
Why it matters: Indicates this event could lead to full system compromise (RCE). Treat as top-priority: isolate and investigate immediately.


🕒 Jul 22, 2025 — 01:07 PM

What it is: The timestamp when the alert was triggered.
Why it matters: Use it to locate logs, correlate related events, and build a timeline (search ± few minutes or hours).


⭐ SOC342 — CVE-2025-53770 SharePoint ToolShell Auth Bypass and RCE (Rule)

What it is: The detection rule or signature that fired, describing the matched condition (ToolShell exploit attempt).
Why it matters: Identifies what attack pattern was detected — useful for hunting similar cases (e.g., unauthenticated POSTs to admin pages or potential webshell uploads).


🧩 320 (EventID)

What it is: Numeric identifier for this specific alert instance or rule (vendor-defined).
Why it matters: Helps with tracking, filtering, and referencing this alert in tickets or reports.


🌐 Web Attack (Category)

What it is: High-level classification — this alert targets web infrastructure.
Why it matters: Routes incident to the web/SharePoint/infra team and applies web-specific playbooks.


👤 Level: Security Analyst

What it is: Analyst role or escalation level expected to handle the alert.
Why it matters: Indicates this is not a Tier-1 alert — requires a Security Analyst (experienced responder) for immediate action.


🖥️ Hostname: SharePoint01

What it is: Name of the affected host (target or origin of the activity).
Why it matters: This is the primary containment target — isolate, collect evidence, and monitor this system first.


🌍 Source IP Address: 107.191.58.76

What it is: The IP sending the suspicious request (attacker or proxy).
Why it matters: Block it at the firewall/WAF, search for other hits from it, and check ownership/geo info. Note: IPs can be spoofed or part of botnets.


🧭 Destination IP Address: 172.16.20.17

What it is: The internal target IP (SharePoint01).
Why it matters: Confirms which internal system was targeted — map it to hostname and review internal access paths/firewall rules.


📬 HTTP Request Method: POST

What it is: The HTTP verb used — client sent data to the server.
Why it matters: POSTs to admin endpoints are suspicious when unauthenticated or large — they can carry exploit payloads or webshells.


📎 Requested URL:

/_layouts/15/ToolPane.aspx?DisplayMode=Edit&a=/ToolPane.aspx
What it is: The exact targeted web path and parameters.
Why it matters: This is a SharePoint admin/layout endpoint — commonly abused by attackers for auth bypass or code uploads. Hunt for other requests to the same path.


🧠 User-Agent:

Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0
What it is: The browser string reported by the client.
Why it matters: Often spoofed by attackers to look legitimate — can help filter logs, but don’t rely on it for attribution.


🔗 Referer:

/_layouts/SignOut.aspx
What it is: HTTP header claiming the request came from SharePoint’s sign-out page.
Why it matters: Spoofed referers are suspicious — may be used to bypass checks or mimic normal traffic. Compare with legitimate navigation flows.


📦 Content-Length: 7699

What it is: Size of the HTTP request body (in bytes).
Why it matters: A large POST body to an admin endpoint suggests a serialized exploit or file upload. Look for other POSTs of similar size to same URL.


⚠️ Alert Trigger Reason

Text: Suspicious unauthenticated POST request targeting ToolPane.aspx with large payload size and spoofed referer — indicative of CVE-2025-53770 exploitation.
What it is: Rule explanation summarizing the matched behavior.
Why it matters: Describes exactly why the alert fired — verify whether the request was unauthenticated, what payload was sent, and if it matches known exploit patterns.


🚧 Device Action: Allowed

What it is: Indicates the protecting device’s response (e.g., WAF/firewall).
Why it matters: Since it was allowed, the attack reached the host — treat as potential compromise.
Immediate actions:

  • Block source IP (107.191.58.76)
  • Enable blocking rules
  • Investigate destination host (SharePoint01)
  • Tune WAF/firewall to block future requests with similar patterns.

🔎 Summary:
This alert reflects an unauthenticated exploit attempt exploiting ToolPane.aspx (SharePoint RCE CVE-2025-53770). The POST request contained a large payload and spoofed referer, consistent with ToolShell zero-day exploitation behavior. Because the device allowed the request, assume possible compromise until proven otherwise. 🟥 Severity: Critical


Quick checks (1–3 minutes)

  1. Search IIS/WAF for POSTs to ToolPane.aspx (around 2025-07-22 13:07):
    Select-String -Path "C:\inetpub\logs\LogFiles\**\*.log" -Pattern "/_layouts/15/ToolPane.aspx" | Out-File .\IIS_ToolPane_hits.txt

  2. Pull full POST body from WAF/proxy or packet capture and save to forensic share.

  3. Look for new/modified ASPX in webroot (webshells):
    Get-ChildItem "C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\**\*.aspx" -Recurse | Sort LastWriteTime -Desc | Select FullName,LastWriteTime

  4. Block attacker & isolate host: block 107.191.58.76 at perimeter/WAF and move SharePoint01 to quarantine (or restrict egress).

Do not delete suspected files — make forensic copies first.

Download Tool