Huntbase Hub · All hunts

Threat hunts for SharePoint

2 hunts covering SharePoint, each with a hypothesis, the queries that test it and what the hunt cannot see.

2 hunts

  1. high
    Research by Rapid7

    SharePoint Business Data Connectivity Service Exploitation

    An attacker has exploited the SharePoint Business Data Connectivity service by uploading a malicious BDC model file to instantiate a .NET gadget chain, resulting in remote code execution within the IIS worker process context.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2019-1257 · CVE-2026-55040
  2. high Part 1 of 2
    Research by Huntress

    Sideloaded AppX OAuth Token Theft

    An adversary has enabled Developer Mode and sideloaded a malicious AppX package to abuse WWAHost.exe, allowing them to capture MFA-compliant OAuth tokens via a legitimate Microsoft login dialog.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · defense evasion · execution