Microsoft 365Detection & ResponseRetrospectives

Detecting SharePoint Server Exploitation: Defender XDR and Sentinel Hunting Queries

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from July 2025, written in 2026 with the benefit of hindsight.

SharePoint Server exploitation leaves traces in web logs, file system changes and process activity. These detections target behaviors seen in ToolShell and similar attacks.

Signals worth watching

  • New .aspx files in SharePoint layouts directories (for example, under ...\TEMPLATE\LAYOUTS\).
  • w3wp.exe spawning cmd.exe or powershell.exe with encoded commands.
  • Requests to SharePoint endpoints associated with the exploit (for example, unusual POST requests to ToolPane.aspx with suspicious referers, as described in Microsoft and CISA guidance).
  • Access to or extraction of machine key configuration.
  • Outbound connections from SharePoint servers to unfamiliar hosts.
  • Defender alerts for SharePoint exploitation.

Where the data lives

  • Defender for Endpoint on SharePoint servers.
  • IIS logs.
  • SharePoint ULS logs.
  • Network logs.

A starting query

New ASPX files in SharePoint directories:

DeviceFileEvents
| where FolderPath has @"\Web Server Extensions\" and FolderPath has @"\TEMPLATE\LAYOUTS\"
| where FileName endswith ".aspx" and ActionType == "FileCreated"
| project Timestamp, DeviceName, FolderPath, FileName, InitiatingProcessFileName

Suspicious IIS worker processes:

DeviceProcessEvents
| where InitiatingProcessFileName =~ "w3wp.exe"
| where FileName in~ ("cmd.exe", "powershell.exe") and ProcessCommandLine has_any ("-enc", "EncodedCommand")
| project Timestamp, DeviceName, ProcessCommandLine

Response

  1. Isolate the server.
  2. Remove malicious files.
  3. Rotate machine keys and restart IIS.
  4. Investigate lateral movement and data access.
detect sharepoint server exploitationToolShell2025

More on this story