title: Potential SharePoint ToolShell CVE-2025-53770 Exploitation - File Create id: ba479447-721f-42a9-9af2-6dcd517bbdb3 status: experimental description: | Detects the creation of file such as spinstall0.aspx which may indicate successful exploitation of CVE-2025-53770. CVE-2025-53770 is a zero-day vulnerability in SharePoint that allows remote code execution. references: - https://research.eye.security/sharepoint-under-siege/ - https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/ - https://unit42.paloaltonetworks.com/microsoft-sharepoint-cve-2025-49704-cve-2025-49706-cve-2025-53770/ author: Swachchhanda Shrawan Poudel (Nextron Systems) date: 2025-07-21 modified: 2025-07-24 tags: - attack.initial-access - attack.t1190 - cve.2025-53770 - detection.emerging-threats logsource: product: windows category: file_event detection: selection: TargetFilename|startswith: - 'C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\' - 'C:\Program Files (x86)\Common Files\Microsoft Shared\Web Server Extensions\' TargetFilename|contains: - '\15\TEMPLATE\LAYOUTS\' - '\16\TEMPLATE\LAYOUTS\' TargetFilename|endswith: - '\spinstall.aspx' - '\spinstall?.aspx' - '\debug_dev.js' condition: selection falsepositives: - Unknown level: critical