CVE-2025-53770 - SharePoint ToolShell
WebShell Discovery from w3wp.exe
CQL · Falcon Next-Gen SIEMCopy query
// CVE-2025-53770 - WebShell Discovery from w3wp.exe
correlate(
cmd: {
#event_simpleName=ProcessRollup2 event_platform=Win FileName="cmd.exe" ParentBaseFileName="w3wp.exe"
} include: [aid, ComputerName, TargetProcessId, ParentBaseFileName, FileName, CommandLine],
pwsh: {
#event_simpleName=ProcessRollup2 event_platform=Win FileName="powershell.exe"
| aid <=> cmd.aid
| ParentProcessId <=> cmd.TargetProcessId
} include: [aid, ComputerName, TargetProcessId, ParentBaseFileName, FileName, CommandLine],
aspx: {
#event_simpleName=/^(NewScriptWritten|WebScriptFileWritten)$/ event_platform=Win FileName=/\.aspx/i
| aid <=> cmd.aid
| ContextProcessId <=> pwsh.TargetProcessId
} include: [aid, ComputerName, TargetFileName],
sequence=true, within=5m)Falcon has native detection/prevention capabilities for this attack sequence. The following looks for:
w3wp.exe --> cmd.exe --> powershell.exe --> .aspx file write
cve_2025_53770___sharepoint_toolshell.yml
T1190, T1620
CrowdStrike
Detection
Endpoint
Insight
2025-10-29
2025-10-29
