SharePoint Webshell Drop via w3wp.exe – Possible CVE-2026-63520 / CVE-2026-55040 RCE Chain Exploitation
This rule Hunts Microsoft Defender for Endpoint DeviceFileEvents for .aspx/.ashx/.asmx files created by w3wp.exe (the IIS worker process) inside SharePoint-specific directories (wss\VirtualDirectories, Web Server Extensions, TEMPLATE\LAYOUTS, App_Code, App_Web, \bin\) — a classic webshell-drop pattern used once an attacker has already gained code execution on the server. It excludes benign SYSTEM/TrustedInstaller writes of default.aspx/upgrade.aspx to cut noise from normal patching/upgrade activity. This is a post-exploitation signature — it doesn't detect the exploit itself, only the artifact an attacker typically drops afterward. CVE-2026-63520 An unauthenticated remote-code-execution flaw in SharePoint Server's Business Connectivity Services, caused by unsafe .NET type instantiation, disclosed jointly by Rapid7 and Microsoft. It lets an attacker execute arbitrary code with the privileges of the SharePoint site's service account. It's the second half of a two-part chain — combined with the earlier CVE-2026-55040 (disclosed the prior month), it enables full unauthenticated RCE. As of disclosure there was no public PoC and no observed exploitation, though Microsoft rated it "exploitation more likely," and CVSS attack complexity is high, meaning reliably chaining both CVEs takes real effort. Since no exploitation artifacts for this CVE chain are public yet, this rule is a generic SharePoint webshell hunt tagged to the CVEs for tracking -- it's not a signature of the BCS exploitation primitive itself.
Microsoft Sentinel (KQL)

