
End-to-end SOC incident analysis and threat hunting playbook targeting Microsoft SharePoint privilege escalation (CVE-2023-29375) using SIEM logs, firewall data, and threat intel.
An in-depth security investigation of a critical exploit and enumeration attempt targeting a Microsoft SharePoint server.
172.16.17.233:443 (HTTPS)39.91.166.222python-requests/2.28.1
SOC227) identifying automated enumeration and privilege escalation attempts against SharePoint API endpoints utilizing a Python-based script (python-requests/2.28.1)./_api/web/siteusers/web/siteusers resulted in an HTTP 404 (Not Found) response (Response Size: 1453 bytes)./_api/web/currentuser resulted in an HTTP 200 (OK) response (Response Size: 1071 bytes), indicating successful session context retrieval by the attacker.
39.91.166.222) on VirusTotal confirmed it is flagged by multiple security vendors as malicious (Associated with ASN 4837, China Unicom).