SharePoint ToolShell Exploitation (CVE-2025-53770/53771)

Detects activity associated with the SharePoint ToolShell exploitation chain, specifically monitoring the w3wp.exe process for spawning suspicious child processes like cmd.exe or powershell.exe, and the creation of unexpected .aspx files within the SharePoint LAYOUTS directory.