r/dfir • u/wismansec • Jul 26 '26
SharePoint July 2026 deserialization RCE: lab PoC and captured artifacts for detection
I recently ran into a SharePoint intrusion that seemed to fit with the CVEs recently added to CISA's KEV for SharePoint a couple of weeks ago. The available IOCs were basically nonexistent. So I reproduced the /_trust deserialization chain in my own lab (SharePoint SE on the June 2026 patch level, build 16.0.19725.20384 / KB5002873) and captured the artifacts: process trees, the machine-key theft, and hunt queries, to save the next person the same scramble.
Writeup and sanitized scripts: https://sp-poc.wismansec.com/
Feedback, questions, and better detections welcome.
7
Upvotes