Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If your on-premises SharePoint Server may have been compromised, treat it as an active security incident—not a patching task. Preserve evidence, determine how far the attacker got, contain access and exposed credentials, remove persistence, and recover only from a verified clean state. Patching closes vulnerabilities; it does not prove that an attacker already inside has been removed.

1. Start incident response and preserve evidence

Activate your organization’s incident-response plan and assign an incident owner. Record a timeline that includes discovery, suspected exposure, changes already made, patching, and response actions. Coordinate responders before cleanup or other changes that could alter the system.

Preserve relevant logs and system state before remediation when feasible. The Cyber Security Agency of Singapore (CSA) advises identifying the incident’s scope without prematurely changing system state, because changes can destroy forensic evidence. For a high-value server or an investigation requiring deeper analysis, CSA recommends making a full disk image for offline review of deleted files, filesystem timelines, and other artifacts. See its July 24, 2025 remediation guide, which addresses CVE-2025-53770 and CVE-2025-53771.

2. Investigate the farm and connected systems

Centralize logs and establish a timeline

Collect and centralize IIS logs, SharePoint Unified Logging Service (ULS) logs, and Windows Security, Application, and System logs. Include PowerShell Script Block Logging and Sysmon logs where available. Correlate events across SharePoint servers and connected systems to look for activity before and after the suspected intrusion.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Synology DS423 Family & Business Backup - Secure File Sharing, Photo Vault & Video Surveillance (4-Bay Diskless NAS)
  • Secure private cloud - Safely access and share files and media from anywhere, and keep friends, partners, or collaborators on the same page
  • Comprehensive data protection - Back up your media and documents to multiple destinations, and leverage snapshots to protect against malware
  • Versatile video surveillance - Protect your home or business with intuitive monitoring, archiving, and analysis tools for up to 30 IP cameras (need to purchase camera license separetly)
  • File Server - Replace expensive SharePoint or Dropbox with local file sharing, team folders and permission contro
  • Ransomware-Resistant Backup - Protect against malware with immutable snapshots, versioned files and multi-destination backup strategies

Search for threat-hunting leads

For the 2025 ToolShell vulnerabilities covered by the CSA guide, investigation leads include suspicious POST requests to /_layouts/15/ToolPane.aspx?DisplayMode=Edit with a Referer header of /_layouts/SignOut.aspx, followed by GET requests to web shells such as spinstall0.aspx and variants. Look for anomalous requests from known malicious IP addresses, web shells in SharePoint TEMPLATELAYOUTS directories, and files such as debug_dev.js. These are leads to investigate, not proof that every compromise will contain those indicators.

Microsoft’s July 2025 analysis also describes observed activity involving theft of ASP.NET machine-key data, scheduled-task persistence, suspicious IIS component loading, access to LSASS, lateral movement, and ransomware deployment. CISA’s alert reviewed October 4, 2026 calls for monitoring suspicious IIS worker-process activity, web shells, anomalous requests, and machine-key access, and lists AMSI and Defender Antivirus detection names. Check the linked advisories for the applicable versions and current context: indicators from the 2025 activity are not a complete set for later incidents, and finding none of them does not establish that a farm is clean.

3. Contain attacker access and movement

Restrict communication where appropriate

Block known malicious IP addresses, domains, and file hashes at the relevant network controls. Assess whether a compromised or reasonably suspected host needs network isolation to stop command-and-control or lateral movement. Balance containment against business continuity and evidence-preservation needs.

CSA specifically recommends disconnecting a server from public and internal networks when patching is not possible or the installation is an end-of-support version. That advice is conditional; it is not a blanket instruction to disconnect every SharePoint farm during every incident.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Address credentials based on exposure

If credential dumping is suspected, identify and reset credentials that may have been exposed. CSA prioritizes SharePoint service accounts, server local administrator accounts, and domain administrative accounts that may have logged on to the compromised server. Extend the investigation to connected systems and identities when evidence points to lateral movement; reset accounts in a targeted, coordinated way.

4. Close the entry path and remove persistence

Patch and harden the on-premises farm

Use a supported SharePoint Server version and install the latest security updates applicable to it. CISA’s alert reports active exploitation against supported on-premises SharePoint Server versions involving CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164. In that alert, CVE-2026-55040 and CVE-2026-58644 are described as newly disclosed potential risks not then known to be exploited. Because vulnerability status changes, check the live CISA alert and the vendor guidance for your exact version before deciding which updates and procedures apply.

CISA also recommends verifying that patches installed successfully, enabling AMSI integration for every SharePoint web application (Full Mode where feasible), and monitoring for suspicious activity. Reduce direct internet exposure; if external access is necessary, use an authenticated Layer 7 reverse proxy or equivalent application-layer control. Restrict external access to Central Administration and limit farm and database communications to required systems.

Remove persistence before rotating keys

For the 2025 vulnerabilities covered in Microsoft’s analysis, Microsoft recommends enabling AMSI and Defender Antivirus, deploying Defender for Endpoint or an equivalent, rotating SharePoint ASP.NET machine keys, and restarting IIS on all SharePoint servers after updates or AMSI enablement. CISA adds an important sequencing caution: first find and remediate artifacts that could steal keys, then rotate the keys, or an attacker may steal the replacement keys. Confirm the current Microsoft and CISA procedure for the incident’s specific vulnerability and SharePoint version before carrying out a rotation or restart.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

5. Rebuild or restore from a verified clean state

Routine cleanup and patching may leave hidden backdoors, rootkits, or system modifications behind. CSA strongly recommends fully rebuilding a compromised system. If rebuilding is not feasible, its alternative is restoration from a known-good, uncompromised backup that predates the intrusion and has been verified clean.

Recovery option What the guidance establishes Key condition or limitation
Full rebuild CSA strongly recommends this approach to remove hidden persistence that routine cleanup could miss. Plan for the organization’s recovery point, recovery time, and recovery level objectives. The cited CSA guide does not state a downtime figure.
Restore a backup CSA presents this as an alternative when rebuilding is not feasible. The backup must predate the intrusion and be verified clean. Microsoft’s recovery documentation does not establish that a backup is clean merely because it can be restored.

Plan the restoration around the organization’s recovery point, recovery time, and recovery level objectives. Microsoft documents farm restoration through Central Administration or PowerShell in its SharePoint Server farm restore guidance. A configuration-only backup cannot restore content databases together with configuration, and SQL Server tools alone cannot restore the complete farm. Microsoft recommends configuring a recovery farm for site and item recovery. Consult its backup and recovery planning guidance when selecting a recovery method.

6. Validate before returning to normal service

After rebuilding or restoring, validate the farm and its connected systems before normal operations resume. Confirm that the applicable security updates and controls are in place, review the restored environment for suspicious activity, and continue monitoring for signs of renewed access. A successful restore or a completed patch installation is not, by itself, evidence that the environment is free of attacker persistence.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.