What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For an on-premises SharePoint farm, start by reviewing IIS and upstream HTTP logs for unusual POST requests to /_layouts/15/ToolPane.aspx, then correlate them with SharePoint layout-file changes, IIS worker-process activity, Defender alerts, and network events. A suspicious request or missing web-shell file alone cannot confirm or rule out compromise. Microsoft says the vulnerabilities covered by its ToolShell guidance affected on-premises SharePoint Server, not SharePoint Online in Microsoft 365 (Microsoft customer guidance).

Confirm the environment and set the investigation window

ToolShell refers to a sequence of SharePoint Server vulnerabilities and related exploitation. CERT-EU reports that Microsoft disclosed CVE-2025-49704 and CVE-2025-49706 on July 8, 2025, and detected active exploitation of a variation on July 18. Further investigation identified CVE-2025-53770 and CVE-2025-53771, which bypassed the earlier updates. Microsoft characterized CVE-2025-53770 as an authentication bypass and remote code execution vulnerability, and CVE-2025-53771 as path traversal (CERT-EU chronology).

First establish whether the systems in scope are on-premises SharePoint servers. Microsoft’s guidance listed SharePoint Server Subscription Edition, 2019, and 2016 among versions for which it published updates at the time of that guidance. Support status and update applicability can change, so check current Microsoft guidance against the farm’s exact version and patch level.

Identify every SharePoint server and IIS site in the farm. Set a review window that begins before the earliest suspicious request or alert and continues through the period when exposed credentials, keys, or network access could have been used. Preserve, rather than overwrite, the relevant telemetry:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • IIS W3C access logs and any retained request bodies.
  • Firewall, reverse-proxy, HTTP gateway, and other upstream access records.
  • Endpoint process, file, and security-product telemetry.
  • Defender alerts and relevant DNS, network-session, and server logs.

The Canadian Centre for Cyber Security’s incident analysis used firewall and HTTP access-log snapshots to trace activity to its beginning. Its investigators also needed host and network evidence and analyzed custom payloads loaded in process memory (Canadian Centre for Cyber Security incident analysis).

Start with suspicious ToolPane requests

Prioritize unusual HTTP POST requests to /_layouts/15/ToolPane.aspx. MITRE’s campaign record describes crafted POST requests to this endpoint as part of the activity (MITRE ATT&CK campaign record).

For each candidate request, capture and compare the fields your logs retain:

  • Timestamp, source and destination, URI, and HTTP status.
  • User agent, request size, and request body if available.
  • Referrer values, including empty or unusual values.
  • Nearby requests from the same source and activity on the destination server.

Compare the requests with the farm’s normal traffic. Empty or spoofed Referrer values can be relevant in reported web-shell activity, but no individual header establishes exploitation. Correlate IIS records with upstream firewall and proxy logs: in the Canadian Centre’s investigated incident, HTTPS access and exfiltration were observed, while compromised network devices obscured origin IP addresses. That makes an IP-only search an unreliable primary test.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Look for unexpected files in SharePoint layout directories

Search the relevant SharePoint TEMPLATELAYOUTS locations on every in-scope server for unexpected files, including names Microsoft identifies in its published Defender XDR hunting guidance:

  • spinstall and spupdate
  • SpLogoutLayout and SP.UI.TitleView
  • queryruleaddtool and ClientId

Give spinstall0.aspx particular attention: Microsoft identifies it as an artifact indicating successful post-exploitation of CVE-2025-53770. For each finding, preserve its path, creation and modification times, hash, and available file-event details; identify the process and account associated with its creation. These names are hunt leads, not an exhaustive signature set. Microsoft’s July 22, 2025 threat-intelligence article, updated July 23, includes hunting guidance and queries (Microsoft threat-intelligence article).

Correlate files with IIS process and Defender evidence

Review process telemetry around the suspicious request and any file changes. Microsoft’s hunt looks for w3wp.exe spawning cmd.exe or PowerShell with encoded-command indicators such as EncodedCommand or -ec. Candidate encoded strings are decoded and checked for shell names and SharePoint layout paths.

For each candidate, inspect the full process tree, command line, account, timestamp, and destination connections. Also review file-event queries for suspicious files created by PowerShell, and compare those events with the request timeline and Defender alerts. An alert title by itself is not proof; validate it against the server, process, file, and network evidence.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
  • Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
  • Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
  • Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)

Microsoft’s customer advisory names these Defender detections:

  • Exploit:Script/SuspSignoutReq.A
  • Trojan:Win32/HijackSharePointServer.A
  • Exploit:Script/SuspSignoutReqBody.A
  • Trojan:PowerShell/MachineKeyFinder.DA!amsi

It also describes alert titles related to possible web-shell installation, possible exploitation of SharePoint server vulnerabilities, suspicious IIS worker-process behavior, and an IIS worker process loading a suspicious .NET assembly. Detection names and availability may change; check the current Defender portal and Microsoft alert documentation.

Do not stop at disk artifacts or spawned shells

The absence of spinstall0.aspx, a variant of that file, or an IIS-spawned PowerShell process does not clear a server. In the Canadian Centre’s investigated incident, neither the file nor an IIS-spawned PowerShell process was seen. Instead, the actor used custom .NET payloads loaded directly into IIS process memory.

The incident analysis described modules that intercepted web requests, extracted cryptographic configuration, read the SAM database, performed SMB reconnaissance, crawled filesystems, and queried LDAP. Expand the hunt when the evidence warrants it:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Review IIS process anomalies and unexpected assemblies or modules, including memory-focused endpoint detections where available.
  • Check for unusual SMB connections, LDAP queries, and activity on adjacent IIS or internal servers.
  • Correlate these events with HTTP access and DNS or network-session records.

The same investigation documented lateral movement and HTTPS exfiltration. Treat activity beyond the SharePoint host as a possibility to investigate, not as a sequence every ToolShell intrusion necessarily follows.

Use indicators and campaign behavior with dates and context

Microsoft’s July 2025 threat-intelligence article provides examples of historical domains, IP addresses, file hashes, and Defender or Sentinel queries. Pivot on those indicators in available DNS, network-session, web-session, and file-event data, recording each indicator’s source and date in case notes. A match should be assessed against current Microsoft guidance and your organization’s threat intelligence; the article’s historical indicators are not, by themselves, confirmation that infrastructure remains active or that a match is attributable to this activity.

MITRE’s campaign entry records behaviors including exploitation of public-facing applications, encoded PowerShell and command-shell use, web shells, collection of machine-key data, lateral movement, and ransomware activity. Use these behaviors to widen a hunt when server evidence supports doing so; do not assume every behavior occurred in a particular incident.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Assess evidence by stage and confidence

A useful case timeline separates the initial request from subsequent host changes and broader activity. The table below is a triage aid, not a substitute for validating evidence in context.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Attack stage Useful telemetry How to interpret it
Initial request IIS, firewall, proxy, or gateway records A suspicious POST to ToolPane.aspx is a high-value lead; corroborate it with host or network evidence.
File or process changes SharePoint layout paths, endpoint file and process events, Defender alerts Unexpected files or IIS worker-process behavior strengthen suspicion when their time and origin correlate with the request.
Post-exploitation Process, module or memory detections, DNS and network sessions Look for evidence beyond a disk web shell, including suspicious in-memory IIS activity.
Lateral movement or collection SMB, LDAP, adjacent-server, and outbound network records Assess whether activity reached other systems or involved collection and exfiltration.

Keep logging coverage and indicator age in view. Missing telemetry limits what can be concluded; a single weak indicator warrants investigation, while independent, time-correlated evidence across HTTP, endpoint, and network sources supports a stronger compromise assessment.

Patch, harden, and recover the farm

Microsoft’s response guidance recommends supported on-premises SharePoint versions, current security updates, endpoint protection, and correctly configured AMSI. Where HTTP request-body scanning is available, Microsoft recommends AMSI Full Mode. If AMSI cannot be enabled before updating, Microsoft advises isolating the server from the internet where possible, or restricting unauthenticated traffic through an authenticated VPN, proxy, or gateway.

Microsoft also recommends rotating SharePoint ASP.NET machine keys and restarting IIS on all SharePoint servers after the relevant changes. Its guidance includes the PowerShell commands Set-SPMachineKey and Update-SPMachineKey for generating and deploying keys. Follow the current Microsoft instructions for the farm’s version and account for every server; do not treat a change on a single host as a farm-wide update.

If evidence indicates compromise, preserve relevant logs and endpoint evidence, assess the full farm and connected systems, and use your organization’s incident-response process to determine scope and recovery. Include checks for persistence, exposed keys, credential misuse, and lateral movement in the investigation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.