ToolShell six months on: SharePoint on-prem detection that holds up in the index
A defender-oriented look at the SharePoint ToolShell chain (CVE-2025-53770 / 53771) — what the telemetry actually looks like in a real SIEM, where the first round of tuning breaks, and which assumptions about your SharePoint farm change the answer.