← All hunts high TLP:CLEAR

SharePoint Business Data Connectivity Service Exploitation

An attacker has exploited the SharePoint Business Data Connectivity service by uploading a malicious BDC model file to instantiate a .NET gadget chain, resulting in remote code execution within the IIS worker process context.

Based on research by Rapid7 2026-09-28 9 steps · 3 queries T1190

Brief

Vulnerability

ContextaThe team published a new hunt based on the Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520) (https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520). The analysis details an RCE vulnerability in the DbTypeReflector class within the Business Data Connectivity (BDC) service. Attackers use this flaw to instantiate malicious .NET gadget chains through the upload of specially crafted BDC model files.aa

HypothesisaThe adversary uploads a

Business Data Connectivity model file (.bdcm) containing a malicious .NET gadget chain, such as ObjectDataProvider, to achieve remote code execution within the context of the IIS worker process (w3wp.exe).aa

Scoping the

EstateaThe hunt begins by identifying vulnerable hosts through the hb_vulnerability_finding surface. The first query filters for servers currently flagged with CVE-2026-63520 or CVE-2026-55040 that do not have a suppressed status. This scoping step ensures the investigation focuses on SharePoint systems where the Business Data Connectivity service remains unpatched and susceptible to exploitation.aa

Monitoring Delivery and

ExecutionaThe hunt proceeds with a parallel search across network and process surfaces. One query monitors hb_http_activity for any requests involving the .bdcm file extension in either the URL path or query strings. These files transport the exploit payload. Since legitimate administrative updates to BDC models are infrequent, these requests provide a specific pivot point for investigating potential initial access attempts.aaSimultaneously, the hunt examines the hb_process_activity surface to identify rare child processes spawned by w3wp.exe. The SharePoint worker process typically maintains a predictable set of child processes related to health checks and internal tasks. This query baselines typical behavior and isolates instances where a shell, discovery tool, or unknown binary appears on three or fewer hosts. This helps identify the successful execution phase of the exploit chain.aa

Correlation and

TriageaAn automated triage agent evaluates the results from the scoping and search phases. The agent identifies hosts where a vulnerability finding, a BDC model upload, and a rare worker process child occur within a close temporal window. This correlation allows the hunt to settle on a verdict of exploitation by connecting the delivery of the exploit to its behavioral side effects. If the agent confirms these links, the hunt routes the host for immediate isolation.aa

Blind

SpotsaThis hunt cannot inspect encrypted HTTP traffic or the POST request bodies of BDC model uploads. Consequently, it cannot verify the specific .NET gadget chain within the XML file until the exploit triggers a process-level event. Additionally, the hunt misses failed exploit attempts if the environment does not ingest Microsoft SharePoint Unified Logging Service (ULS) logs, which would record internal class instantiation failures.aa

Beyond

DetectionaStandard detection rules often flag common web shell behavior but lack the context of the initial delivery vector. This hunt provides that context by identifying the specific Business Data Connectivity model traffic. By correlating the file delivery with the specific vulnerability status of the server, we reduce the false positive rate associated with general IIS process monitoring. If the hunt confirms a compromise, the practitioner should proceed to a forensic review of the recovered .bdcm files to validate the malicious .NET types used in the attack.

Steps

  1. Identify vulnerable SharePoint hosts

    Query · scoping

    Focus the hunt on hosts already flagged as vulnerable to the relevant SharePoint CVEs by scanning providers.

    reads hb_vulnerability_findingsql
    SELECT resource_uid, cve_uid, severity, status FROM hb_vulnerability_finding WHERE instr(',' || '{{vulnerability_ids}}' || ',', ',' || cve_uid || ',') > 0 AND status != 'suppressed'

    What a hit looks like. A list of resource IDs (hostnames) that have not yet been patched. Silence indicates no known vulnerable hosts in the scanner's inventory.

  2. Detect BDC model traffic

    Query · enrichment

    Find HTTP requests involving .bdcm files which transport the exploit payload.

    reads hb_http_activitysql
    SELECT device_hostname, url_path, url_query, src_endpoint_ip, time FROM hb_http_activity WHERE (LOWER(url_path) LIKE '%.bdcm%' OR LOWER(url_query) LIKE '%.bdcm%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. HTTP requests targeting BDC model paths. Silence means no .bdcm files were requested within the lookback period.

  3. Find rare w3wp.exe children

    Query · baseline

    Detect successful RCE by finding rare child processes spawned by the SharePoint IIS worker process.

    reads hb_process_activitysql
    SELECT LOWER(process_name) AS proc, COUNT(DISTINCT device_hostname) AS host_count, COUNT(*) AS total_runs, MIN(time) AS first_seen FROM hb_process_activity WHERE LOWER(parent_process_name) LIKE '%w3wp.exe%' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1 HAVING host_count <= 3

    What a hit looks like. Anomalous child processes such as shells, discovery tools, or unexpected binaries on a small number of hosts. Benign activity includes standard SharePoint health scripts.

  4. Triage exploitation evidence

    Agent triage

    The agent weighs the vulnerability status, file delivery evidence, and process behavior to identify hosts showing a complete exploit chain.

  5. Route based on verdict

    Decision

    Direct the response to host isolation if exploitation is confirmed.

  6. Isolate the impacted host

    Response action

    Prevent lateral movement and further command execution by isolating the compromised SharePoint server.

  7. Forensic artifact review

    Analyst task

    An analyst verifies the BDC model content to confirm the presence of malicious .NET gadget chains.

  8. Verify remediation

    Analyst task

    Ensure the estate is protected against this RCE vulnerability after the hunt.

Coverage

Scenario coverage

StageCoveredHow, or why not
SharePoint BDC Model Exploitation
T1190
Yes find-vulnerable-sharepoint, detect-bdcm-traffic, find-rare-iis-children
Arbitrary Command Execution via Gadget Chain
T1106
Out of scope Not examined by this hunt; belongs to a separate hunt.

Blind spots

  • Needs Decrypted HTTP traffic or POST request body inspection. Without inspecting the payload, the hunt cannot distinguish between a legitimate BDC model update and a malicious exploit file until execution occurs. It would answer What .NET types and gadget chains were actually contained within the BDC model XML?.
  • Needs Microsoft SharePoint Unified Logging Service (ULS) logs. The hunt relies on the side effects of successful exploitation (process execution) and may miss failed attempts or more stealthy gadget chains that do not spawn processes. It would answer Whether the DbTypeReflector class logged an instantiation failure or the specific .NET type being resolved..

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
lookback_daysnumber14Days of history to examine.
scope_hostslist[host]—Target hostnames for the hunt; leave empty to scan the entire estate.
vulnerability_idslist[string]CVE-2026-63520, CVE-2026-55040CVE identifiers associated with the SharePoint BDC vulnerability.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint
Web server / proxy logssiemnetwork

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: A standard detection rule might flag w3wp.exe spawning cmd.exe, but this
  hunt provides necessary context by identifying the delivery of Business Data Connectivity
  (.bdcm) models and scoping the search to hosts with known unpatched RCE vulnerabilities,
  reducing false positives from legitimate admin scripts.
blind_spots:
- id: encrypted-http-traffic
  question: What .NET types and gadget chains were actually contained within the BDC
    model XML?
  requires: Decrypted HTTP traffic or POST request body inspection
  risk: Without inspecting the payload, the hunt cannot distinguish between a legitimate
    BDC model update and a malicious exploit file until execution occurs.
  stage: initial-access-bdc-exploitation
- id: no-uls-logs
  question: Whether the DbTypeReflector class logged an instantiation failure or the
    specific .NET type being resolved.
  requires: Microsoft SharePoint Unified Logging Service (ULS) logs
  risk: The hunt relies on the side effects of successful exploitation (process execution)
    and may miss failed attempts or more stealthy gadget chains that do not spawn
    processes.
  stage: initial-access-bdc-exploitation
coverage:
- stage: initial-access-bdc-exploitation
  status: covered
  steps:
  - find-vulnerable-sharepoint
  - detect-bdcm-traffic
  - find-rare-iis-children
- reason: Not examined by this hunt; belongs to a separate hunt.
  stage: execution-gadget-chain-command
  status: out_of_scope
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: keep-as-periodic-hunt
  justification: Microsoft SharePoint servers often host sensitive corporate data;
    an unauthenticated RCE represents a direct threat to the confidentiality and integrity
    of that data within the internal network.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An attacker has exploited the SharePoint Business Data Connectivity service
  by uploading a malicious BDC model file to instantiate a .NET gadget chain, resulting
  in remote code execution within the IIS worker process context.
labels:
- hunt
- attack.t1190
name: SharePoint Business Data Connectivity Service Exploitation
parameters:
  lookback_days:
    default: '14'
    description: Days of history to examine.
    type: number
  scope_hosts:
    default: []
    description: Target hostnames for the hunt; leave empty to scan the entire estate.
    type: list[host]
  vulnerability_ids:
    default:
    - CVE-2026-63520
    - CVE-2026-55040
    description: CVE identifiers associated with the SharePoint BDC vulnerability.
    from:
      kind: article
      observed: '2026-08-24'
      ref: https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520
    type: list[string]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Scope the hunt to SharePoint Server Subscription Edition, SharePoint Server
  2019, or 2016. Target systems where the Business Data Connectivity (BDC) service
  is active.
references:
- name: 'Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)'
  url: https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520
related:
- hunt: iis-w3wp-shell-execution
  reason: Monitoring for shells spawned by w3wp.exe is a general behavioral hunt that
    covers many web exploits but lacks the specific context of BDC model delivery.
  relation: out-of-scope-alternative
scenario:
  stages:
  - name: SharePoint BDC Model Exploitation
    observables:
    - CVE-2026-63520
    - CVE-2026-55040
    - .bdcm model file upload
    - LobSystem Type="Database"
    - LobSystem Type="DotNetAssembly"
    - TypeName="System.Windows.Data.ObjectDataProvider"
    - TypeName="System.Diagnostics.Process"
    - TypeName="System.Diagnostics.ProcessStartInfo"
    slug: initial-access-bdc-exploitation
    tactic: initial-access
    techniques:
    - T1190
  - name: Arbitrary Command Execution via Gadget Chain
    observables:
    - Process.Start()
    - System.Windows.Data.ObjectDataProvider
    - System.Diagnostics.Process
    - System.Diagnostics.ProcessStartInfo
    - w3wp.exe spawning child processes
    - SharePoint Site service account privileges
    slug: execution-gadget-chain-command
    tactic: execution
    techniques:
    - T1106
  summary: Attackers exploit a remote code execution vulnerability in the Microsoft
    SharePoint Business Data Connectivity (BDC) subsystem by uploading malicious .bdcm
    model files. The exploit leverages an unrestricted .NET type instantiation flaw
    in the DbTypeReflector class to execute arbitrary commands via an ObjectDataProvider
    gadget chain under the context of the SharePoint service account.
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  web:
    category: siem
    name: Web server / proxy logs
    telemetry:
    - network
tlp: clear
type: investigation
---


# SharePoint Business Data Connectivity Service Exploitation

This hunt identifies exploitation of CVE-2026-63520, an RCE vulnerability in the SharePoint DbTypeReflector class. The attack involves the delivery of a Business Data Connectivity (BDC) model file (.bdcm) containing a .NET gadget chain like ObjectDataProvider. The hunt first scopes to hosts with known unpatched vulnerabilities, then concurrently searches for BDC model uploads and rare child processes spawned by the SharePoint worker process (w3wp.exe). An agent correlates the presence of the vulnerability, the file delivery, and anomalous process behavior to settle on a verdict.

## find-vulnerable-sharepoint
<!-- Identify vulnerable SharePoint hosts -->
Focus the hunt on hosts already flagged as vulnerable to the relevant SharePoint CVEs by scanning providers.

```sqlite target=endpoint role=scoping params=(vulnerability_ids=vulnerability_ids)
~~~yaml
expected: A list of resource IDs (hostnames) that have not yet been patched. Silence
  indicates no known vulnerable hosts in the scanner's inventory.
reads:
- resource_uid
- cve_uid
- severity
- status
silence: not_evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT resource_uid, cve_uid, severity, status FROM hb_vulnerability_finding WHERE instr(',' || '{{vulnerability_ids}}' || ',', ',' || cve_uid || ',') > 0 AND status != 'suppressed'
```

## parallel-threat-search
<!-- Search for delivery and execution -->
parallel:
- → detect-bdcm-traffic
- → find-rare-iis-children
join: → triage-exploitation

## detect-bdcm-traffic
<!-- Detect BDC model traffic -->
Find HTTP requests involving .bdcm files which transport the exploit payload.

```sqlite target=web role=enrichment params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: HTTP requests targeting BDC model paths. Silence means no .bdcm files were
  requested within the lookback period.
reads:
- device_hostname
- url_path
- url_query
- src_endpoint_ip
- time
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, url_path, url_query, src_endpoint_ip, time FROM hb_http_activity WHERE (LOWER(url_path) LIKE '%.bdcm%' OR LOWER(url_query) LIKE '%.bdcm%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## find-rare-iis-children
<!-- Find rare w3wp.exe children -->
Detect successful RCE by finding rare child processes spawned by the SharePoint IIS worker process.

```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: Anomalous child processes such as shells, discovery tools, or unexpected
  binaries on a small number of hosts. Benign activity includes standard SharePoint
  health scripts.
prevalence:
  by: device_hostname
  key:
  - proc
  rare_below: 4
reads:
- process_name
- device_hostname
- parent_process_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT LOWER(process_name) AS proc, COUNT(DISTINCT device_hostname) AS host_count, COUNT(*) AS total_runs, MIN(time) AS first_seen FROM hb_process_activity WHERE LOWER(parent_process_name) LIKE '%w3wp.exe%' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1 HAVING host_count <= 3
```

## triage-exploitation
<!-- Triage exploitation evidence -->
```agent target=hunter
cite: required
context:
- find-vulnerable-sharepoint
- detect-bdcm-traffic
- find-rare-iis-children
max_iterations: 4
objective: Determine if any host has been exploited using CVE-2026-63520 or CVE-2026-55040
  by correlating vulnerable status, BDC model uploads, and anomalous process execution.
success_criteria: A per-host verdict citing specific rows that demonstrate the exploit
  chain.
tools:
- endpoint
- web
```

## decision-on-compromise
<!-- Route based on verdict -->
if~: "the triage verdict is malicious for at least one host based on correlated file and process evidence" (confidence: high, judge=hunter)
then: → isolate-impacted-host
indeterminate: → forensic-artifact-review
unavailable: → forensic-artifact-review (blind_spot: encrypted-http-traffic)
else: → verify-remediation

## isolate-impacted-host
<!-- Isolate the impacted host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the identified host and preserve memory for forensic investigation of the w3wp.exe process.
```
→ forensic-artifact-review

## forensic-artifact-review
<!-- Forensic artifact review -->
```manual target=analyst
Retrieve the .bdcm file mentioned in the HTTP traffic from the SharePoint server or database; check the XML content for TypeName attributes referencing ObjectDataProvider, DotNetAssembly, or other unusual .NET types.
```
→ verify-remediation

## verify-remediation
<!-- Verify remediation -->
```manual target=analyst
Verify that Microsoft SharePoint security updates from August 2026 or later are applied to all servers in the estate.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.