Skip to content

Commit 1d18758

Browse files
committed
shelly
1 parent 5385a64 commit 1d18758

File tree

2 files changed

+18
-0
lines changed

2 files changed

+18
-0
lines changed
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
author: Michael Haag, Splunk
2+
id: cb9b2601-efc9-11eb-926b-550bf0943fbb
3+
date: '2025-07-20'
4+
description: Generation of attack data related to CVE-2025-53770 (ToolShell) showing file creation of the malicious spinstall0.aspx web shell in SharePoint layouts directories.
5+
environment: attack_range
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.003/sharepoint_webshell/sysmon_spinstall0.log
8+
sourcetypes:
9+
- XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
10+
references:
11+
- https://attack.mitre.org/techniques/T1505/003
12+
- https://research.eye.security/sharepoint-under-siege/
13+
- https://cybersecuritynews.com/sharepoint-0-day-rce-vulnerability-exploited/
14+
- https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/
15+
- https://www.cisa.gov/news-events/alerts/2025/07/20/microsoft-releases-guidance-exploitation-sharepoint-vulnerability-cve-2025-53770
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:b3684dddf3739d07917b8bd1f278e907f0a37cefb3d1c84e92ead65ab4197128
3+
size 6401

0 commit comments

Comments
 (0)