Possible ToolShell SharePoint Exploitation via ToolPane.aspx (via webserver)

PremiumReviewedSigma · High · v1
Category
webserver
Author
HuntRule
Published
2026-10-11
Updated
2026-10-11

ATT&CK techniques

Initial Access → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects POST requests to the SharePoint ToolPane.aspx endpoint carrying the crafted parameters and SignOut.aspx referer used in the ToolShell exploit chain. ToolShell abused a set of SharePoint vulnerabilities to reach unauthenticated remote code execution on internet-facing servers. This request pattern is an early indicator of exploitation before any implant is dropped.

Related detections9 linkedT1190 — drag to rearrange
Possible PAN-OS Auth Bypass via Double-Encoded Path Traversal to ztp_gate (CVE-2025-0108)
Malicious TBK DVR Command Injection via device.rsp Endpoint
Possible Apache Struts2 OGNL Content-Type Exploitation CVE-2017-5638 (via webserver)
Suspicious Reconnaissance and Payload Download by Node Web Process
Suspicious Command Shell Spawned by MSSQL Server Process Indicating Webshell
Malicious PowerShell UrlDecode Payload Spawned by SQL Server after FortiClient EMS Exploitation
Suspicious NKAbuse Implant Staging under StoreService Config Directory (via file_event)
Possible xrdp RCE Exploitation via ts_info_utf16_in Buffer Overflow (via application)
Malicious n8n Expression Sandbox Escape child_process Payload
Possible ToolShell SharePoint Exploitation via ToolPane.aspx (via webserver)
Pivot detection · T1190 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.