This brief describes the detection of GET requests to the spinstall0.aspx webshell, commonly deployed after exploiting CVE-2025-53770 in Microsoft SharePoint, indicating potential command execution, data exfiltration, or credential harvesting.
PoC
sharepoint
webshell
cve-2025-53770
t1190
t1505.003
t1552
2r
3t
1c
updated