Potential SharePoint ToolShell CVE-2025-53770 Exploitation Indicators — Detection Rule

Detects potential exploitation of CVE-2025-53770 by identifying indicators such as suspicious command lines discovered in Post-Exploitation activities. CVE-2025-53770 is a zero-day vulnerability in SharePoint that allows remote code execution.

Read the full analysis on IntelFusions