Potential SharePoint ToolShell CVE-2025-53770 Exploitation - File Create — Detection Rule
Detects the creation of file such as spinstall0.aspx which may indicate successful exploitation of CVE-2025-53770. CVE-2025-53770 is a zero-day vulnerability in SharePoint that allows remote code execution.