---
analysis: A standard detection rule might flag w3wp.exe spawning cmd.exe, but this
  hunt provides necessary context by identifying the delivery of Business Data Connectivity
  (.bdcm) models and scoping the search to hosts with known unpatched RCE vulnerabilities,
  reducing false positives from legitimate admin scripts.
blind_spots:
- id: encrypted-http-traffic
  question: What .NET types and gadget chains were actually contained within the BDC
    model XML?
  requires: Decrypted HTTP traffic or POST request body inspection
  risk: Without inspecting the payload, the hunt cannot distinguish between a legitimate
    BDC model update and a malicious exploit file until execution occurs.
  stage: initial-access-bdc-exploitation
- id: no-uls-logs
  question: Whether the DbTypeReflector class logged an instantiation failure or the
    specific .NET type being resolved.
  requires: Microsoft SharePoint Unified Logging Service (ULS) logs
  risk: The hunt relies on the side effects of successful exploitation (process execution)
    and may miss failed attempts or more stealthy gadget chains that do not spawn
    processes.
  stage: initial-access-bdc-exploitation
coverage:
- stage: initial-access-bdc-exploitation
  status: covered
  steps:
  - find-vulnerable-sharepoint
  - detect-bdcm-traffic
  - find-rare-iis-children
- reason: Not examined by this hunt; belongs to a separate hunt.
  stage: execution-gadget-chain-command
  status: out_of_scope
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: keep-as-periodic-hunt
  justification: Microsoft SharePoint servers often host sensitive corporate data;
    an unauthenticated RCE represents a direct threat to the confidentiality and integrity
    of that data within the internal network.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An attacker has exploited the SharePoint Business Data Connectivity service
  by uploading a malicious BDC model file to instantiate a .NET gadget chain, resulting
  in remote code execution within the IIS worker process context.
labels:
- hunt
- attack.t1190
name: SharePoint Business Data Connectivity Service Exploitation
parameters:
  lookback_days:
    default: '14'
    description: Days of history to examine.
    type: number
  scope_hosts:
    default: []
    description: Target hostnames for the hunt; leave empty to scan the entire estate.
    type: list[host]
  vulnerability_ids:
    default:
    - CVE-2026-63520
    - CVE-2026-55040
    description: CVE identifiers associated with the SharePoint BDC vulnerability.
    from:
      kind: article
      observed: '2026-08-24'
      ref: https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520
    type: list[string]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Scope the hunt to SharePoint Server Subscription Edition, SharePoint Server
  2019, or 2016. Target systems where the Business Data Connectivity (BDC) service
  is active.
references:
- name: 'Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)'
  url: https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520
related:
- hunt: iis-w3wp-shell-execution
  reason: Monitoring for shells spawned by w3wp.exe is a general behavioral hunt that
    covers many web exploits but lacks the specific context of BDC model delivery.
  relation: out-of-scope-alternative
scenario:
  stages:
  - name: SharePoint BDC Model Exploitation
    observables:
    - CVE-2026-63520
    - CVE-2026-55040
    - .bdcm model file upload
    - LobSystem Type="Database"
    - LobSystem Type="DotNetAssembly"
    - TypeName="System.Windows.Data.ObjectDataProvider"
    - TypeName="System.Diagnostics.Process"
    - TypeName="System.Diagnostics.ProcessStartInfo"
    slug: initial-access-bdc-exploitation
    tactic: initial-access
    techniques:
    - T1190
  - name: Arbitrary Command Execution via Gadget Chain
    observables:
    - Process.Start()
    - System.Windows.Data.ObjectDataProvider
    - System.Diagnostics.Process
    - System.Diagnostics.ProcessStartInfo
    - w3wp.exe spawning child processes
    - SharePoint Site service account privileges
    slug: execution-gadget-chain-command
    tactic: execution
    techniques:
    - T1106
  summary: Attackers exploit a remote code execution vulnerability in the Microsoft
    SharePoint Business Data Connectivity (BDC) subsystem by uploading malicious .bdcm
    model files. The exploit leverages an unrestricted .NET type instantiation flaw
    in the DbTypeReflector class to execute arbitrary commands via an ObjectDataProvider
    gadget chain under the context of the SharePoint service account.
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  web:
    category: siem
    name: Web server / proxy logs
    telemetry:
    - network
tlp: clear
type: investigation
---


# SharePoint Business Data Connectivity Service Exploitation

This hunt identifies exploitation of CVE-2026-63520, an RCE vulnerability in the SharePoint DbTypeReflector class. The attack involves the delivery of a Business Data Connectivity (BDC) model file (.bdcm) containing a .NET gadget chain like ObjectDataProvider. The hunt first scopes to hosts with known unpatched vulnerabilities, then concurrently searches for BDC model uploads and rare child processes spawned by the SharePoint worker process (w3wp.exe). An agent correlates the presence of the vulnerability, the file delivery, and anomalous process behavior to settle on a verdict.

## find-vulnerable-sharepoint
<!-- Identify vulnerable SharePoint hosts -->
Focus the hunt on hosts already flagged as vulnerable to the relevant SharePoint CVEs by scanning providers.

```sqlite target=endpoint role=scoping params=(vulnerability_ids=vulnerability_ids)
~~~yaml
expected: A list of resource IDs (hostnames) that have not yet been patched. Silence
  indicates no known vulnerable hosts in the scanner's inventory.
reads:
- resource_uid
- cve_uid
- severity
- status
silence: not_evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT resource_uid, cve_uid, severity, status FROM hb_vulnerability_finding WHERE instr(',' || '{{vulnerability_ids}}' || ',', ',' || cve_uid || ',') > 0 AND status != 'suppressed'
```

## parallel-threat-search
<!-- Search for delivery and execution -->
parallel:
- → detect-bdcm-traffic
- → find-rare-iis-children
join: → triage-exploitation

## detect-bdcm-traffic
<!-- Detect BDC model traffic -->
Find HTTP requests involving .bdcm files which transport the exploit payload.

```sqlite target=web role=enrichment params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: HTTP requests targeting BDC model paths. Silence means no .bdcm files were
  requested within the lookback period.
reads:
- device_hostname
- url_path
- url_query
- src_endpoint_ip
- time
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, url_path, url_query, src_endpoint_ip, time FROM hb_http_activity WHERE (LOWER(url_path) LIKE '%.bdcm%' OR LOWER(url_query) LIKE '%.bdcm%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## find-rare-iis-children
<!-- Find rare w3wp.exe children -->
Detect successful RCE by finding rare child processes spawned by the SharePoint IIS worker process.

```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: Anomalous child processes such as shells, discovery tools, or unexpected
  binaries on a small number of hosts. Benign activity includes standard SharePoint
  health scripts.
prevalence:
  by: device_hostname
  key:
  - proc
  rare_below: 4
reads:
- process_name
- device_hostname
- parent_process_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT LOWER(process_name) AS proc, COUNT(DISTINCT device_hostname) AS host_count, COUNT(*) AS total_runs, MIN(time) AS first_seen FROM hb_process_activity WHERE LOWER(parent_process_name) LIKE '%w3wp.exe%' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1 HAVING host_count <= 3
```

## triage-exploitation
<!-- Triage exploitation evidence -->
```agent target=hunter
cite: required
context:
- find-vulnerable-sharepoint
- detect-bdcm-traffic
- find-rare-iis-children
max_iterations: 4
objective: Determine if any host has been exploited using CVE-2026-63520 or CVE-2026-55040
  by correlating vulnerable status, BDC model uploads, and anomalous process execution.
success_criteria: A per-host verdict citing specific rows that demonstrate the exploit
  chain.
tools:
- endpoint
- web
```

## decision-on-compromise
<!-- Route based on verdict -->
if~: "the triage verdict is malicious for at least one host based on correlated file and process evidence" (confidence: high, judge=hunter)
then: → isolate-impacted-host
indeterminate: → forensic-artifact-review
unavailable: → forensic-artifact-review (blind_spot: encrypted-http-traffic)
else: → verify-remediation

## isolate-impacted-host
<!-- Isolate the impacted host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the identified host and preserve memory for forensic investigation of the w3wp.exe process.
```
→ forensic-artifact-review

## forensic-artifact-review
<!-- Forensic artifact review -->
```manual target=analyst
Retrieve the .bdcm file mentioned in the HTTP traffic from the SharePoint server or database; check the XML content for TypeName attributes referencing ObjectDataProvider, DotNetAssembly, or other unusual .NET types.
```
→ verify-remediation

## verify-remediation
<!-- Verify remediation -->
```manual target=analyst
Verify that Microsoft SharePoint security updates from August 2026 or later are applied to all servers in the estate.
```
→ end
