SharePoint ToolShell CVE-2025-53770 Exploitation - Web IIS — Detection Rule

Detects access to vulnerable SharePoint components potentially being exploited in CVE-2025-53770 through IIS web server logs. CVE-2025-53770 is a zero-day vulnerability in SharePoint that allows remote code execution.

Read the full analysis on IntelFusions