CVE-2025-53770 EXPLAINED: ToolShell RCE + Live SOC Analysis (Letsdefend SOC342)

🚀Cyber Security Certification Notes & Cheat Sheets
https://buymeacoffee.com/notescatalog/extras
🚀 Cyber Security Certification Notes (Another Link)
https://shop.motasem-notes.net/collections/cyber-security-study-notes
💡 Cyber Security Notes | Membership Access
https://buymeacoffee.com/notescatalog/membership
💡Certified Security Blue Team Level 1 Study Notes (Unofficial)
https://buymeacoffee.com/notescatalog/e/327370
💡Blue Team Cyber Security & SOC Analyst Study Notes
https://buymeacoffee.com/notescatalog/e/142868
🔥 Download FREE Cyber Security 101 Study Notes
https://buymeacoffee.com/notescatalog/e/290985
💡Video Writeup
https://motasem-notes.net/cve-2025-53770-explained-toolshell-rce-live-soc-analysis-letsdefend-soc342/
💡Brand collaborations and sponsorships
https://motasem-notes.net/advertise/
*****
The newly discovered CVE-2025-53770 ‘ToolShell’ vulnerability is wreaking havoc on Microsoft SharePoint servers. In this video, we explain how this exploit works, its global impact, and perform a SOC-style analysis using LetsDefend to demonstrate how to detect and investigate real-world attacks. Perfect for SOC analysts, cybersecurity students, and IT admins.
****
Store
https://buymeacoffee.com/notescatalog/extras
Patreon
https://www.patreon.com/motasemhamdan
Instagram
https://www.instagram.com/motasem.hamdan.official/
LinkedIn
[1]: https://www.linkedin.com/in/motasem-hamdan-7673289b/
[2]: https://www.linkedin.com/in/motasem-eldad-ha-bb42481b2/
Twitter
https://twitter.com/ManMotasem
Facebook
https://www.facebook.com/motasemhamdantty/
TikTok
https://www.tiktok.com/@motasemhamdan0
***
00: 00 – Introduction: SharePoint CVE-2025 TotalShell
00: 44 – Vulnerability Overview & Risk (CVSS 9.8)
01: 32 – Attack Sequence Breakdown
01: 37 – Crafted POST Request to ToolPane.aspx
02: 06 – Bypassing Authentication
02: 31 – Uploading Web Shell (SPInstall0.aspx)
02: 53 – Harvesting Keys for Payloads
03: 23 – Forging Payloads & Session Persistence
03: 54 – Security Patch Process
04: 03 – Rotate Machine Keys
04: 15 – Apply Security Patches
04: 35 – Post-Patch Key Rotation & Cleanup
05: 01 – Anti-Malware Scanning with Defender
05: 08 – SOC Alert Detection of Exploitation
05: 57 – Taking Ownership & Starting Investigation
06: 27 – Case Creation & Playbook Steps
07: 01 – Investigating Endpoint & Traffic
07: 55 – Destination IP Analysis
09: 17 – Identifying IIS Worker Process (w3wp)
10: 46 – Suspicious PowerShell Execution
11: 57 – Decoding Base64 Malicious Script
12: 58 – ASPX Script Harvesting Keys
13: 42 – Web Shell Deployment (SPInstall0.aspx)
14: 45 – Endpoint Security & Command History
15: 19 – ActiveX Object Downloading Payload
15: 55 – VirusTotal Confirms Malicious File
16: 36 – Confirming Malicious Traffic
17: 38 – Checking for Planned Pentest
18: 26 – Attack Direction: Internet → Company Network
19: 05 – Confirming Successful Exploitation
20: 15 – Retrieving Configuration Keys
21: 18 – Attack Success Confirmed
21: 26 – Containment: Isolating SharePoint Server
23: 04 – Adding IOCs: IPs, Hashes, URLs
24: 20 – Capturing Initial POST Request
25: 20 – Payload URL to Attacker’s Server
25: 44 – Tier 2 Escalation Justification
26: 07 – Writing Analyst Notes
27: 32 – Closing the Alert (True Positive)
28: 05 – Correcting Attack Type (Unsafe Deserialization → RCE)