Detecting SharePoint Server Exploitation: Defender XDR and Sentinel Hunting Queries
Retrospective: this article looks back at events from July 2025, written in 2026 with the benefit of hindsight.
SharePoint Server exploitation leaves traces in web logs, file system changes and process activity. These detections target behaviors seen in ToolShell and similar attacks.
Signals worth watching
- New
.aspxfiles in SharePoint layouts directories (for example, under...\TEMPLATE\LAYOUTS\). w3wp.exespawningcmd.exeorpowershell.exewith encoded commands.- Requests to SharePoint endpoints associated with the exploit (for example, unusual POST requests to
ToolPane.aspxwith suspicious referers, as described in Microsoft and CISA guidance). - Access to or extraction of machine key configuration.
- Outbound connections from SharePoint servers to unfamiliar hosts.
- Defender alerts for SharePoint exploitation.
Where the data lives
- Defender for Endpoint on SharePoint servers.
- IIS logs.
- SharePoint ULS logs.
- Network logs.
A starting query
New ASPX files in SharePoint directories:
DeviceFileEvents
| where FolderPath has @"\Web Server Extensions\" and FolderPath has @"\TEMPLATE\LAYOUTS\"
| where FileName endswith ".aspx" and ActionType == "FileCreated"
| project Timestamp, DeviceName, FolderPath, FileName, InitiatingProcessFileName
Suspicious IIS worker processes:
DeviceProcessEvents
| where InitiatingProcessFileName =~ "w3wp.exe"
| where FileName in~ ("cmd.exe", "powershell.exe") and ProcessCommandLine has_any ("-enc", "EncodedCommand")
| project Timestamp, DeviceName, ProcessCommandLine
Response
- Isolate the server.
- Remove malicious files.
- Rotate machine keys and restart IIS.
- Investigate lateral movement and data access.
- ToolShell (July 2025): On-Prem SharePoint Zero-Days Exploited Worldwide Incident Teardowns
- How to Migrate or Isolate On-Premises SharePoint Servers How-To & Hardening
- CIO Brief: On-Prem SharePoint Is Now a Liability CIO Briefings