Elastic medium stable kql

Potential VIEWSTATE RCE Attempt on SharePoint/IIS

Detects potential remote code execution (RCE) attempts targeting IIS web servers running SharePoint via malicious VIEWSTATE payloads in HTTP POST requests. Attackers may exploit insecure deserialization in the VIEWSTATE parameter to execute arbitrary code. This rule identifies suspicious requests containing VIEWSTATE data and other indicators of exploitation, specifically those associated with the Toolshell exploit chain. Toolshell leverages vulnerabilities (CVE-2025-53770 and CVE-2025-53771) for initial access, enabling adversaries to deploy a webshell, steal machine keys, sign VIEWSTATE payloads offline, and subsequently send signed payloads to the server to achieve code execution.

View Source

Detection Logic

data_stream.dataset : "network_traffic.http" and
    network.direction: "ingress" and
    http.request.method: "POST" and
    http.request.referrer: *SignOut.aspx and
    http.request.body.content: *__VIEWSTATE=* and
    http.request.body.bytes >= 500 and
    http.response.headers.server: Microsoft-IIS*

Field Validations

Loading…

Comments (0)

Loading comments...