[Guest Diary] Hunting for SharePoint In-Memory ToolShell Payloads, (Tue, Dec 2nd)
ID: 86b5c7a6-a8ba-5f31-b41b-c35c49805c7c
STIX ID: report--86b5c7a6-a8ba-5f31-b41b-c35c49805c7c
Feed Name: SANS ISC Diary
This guest-hunting diary documents detection and analysis of the ToolShell SharePoint exploit chain (CVE-2025-53770/53771). It demonstrates using Zeek logs and PCAP analysis (DaemonLogger, mergecap, Wireshark) to identify malicious POST requests to ToolPane.aspx, extract and decode the CompressedDataTable payload, and reveal in-memory .NET DLLs (e.g., osvmhdfl.dll, jlaneafi.dll) and encoded PowerShell used for reconnaissance and exfiltration, plus scanner payloads and relevant IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
