hunt-sharepoint

Detect SharePoint Server vulnerabilities including SOAP authentication bypasses and ToolShell chains.

13|2|Updated Jun 1, 2026
One-click install
npx skills add https://github.com/pdparchitect/rook --skill hunt-sharepoint-pdparchitect
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: hunt-sharepoint
Source: https://github.com/pdparchitect/rook/tree/main/skills/hunt-sharepoint
Command: npx skills add https://github.com/pdparchitect/rook --skill hunt-sharepoint-pdparchitect

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill addresses the difficulty of identifying critical vulnerabilities in complex, often legacy, Microsoft SharePoint on-premise environments that are frequently left unpatched and exposed.

Core Features & Use Cases

  • Automated Fingerprinting: Identifies SharePoint versions and patch levels to map against known CVEs.
  • Vulnerability Probing: Detects critical flaws like ToolShell (CVE-2025-53770), legacy SOAP login bypasses, and NTLM information leaks.
  • Use Case: During a security assessment, use this skill to rapidly audit an internet-facing SharePoint farm for unpatched EoL vulnerabilities and misconfigured authentication endpoints without manual tool chaining.

Quick Start

Use the hunt-sharepoint skill to perform a full security audit on the target SharePoint farm at the provided URL.

Frequently Asked Questions about hunt-sharepoint

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I scan a SharePoint server for CVE vulnerabilities?

Detect SharePoint authentication bypass vulnerabilities by probing legacy SOAP login endpoints for bypass flaws and identifying misconfigured authentication endpoints. This autonomously validates legacy SOAP authentication bypasses during security assessments.

What is the best way to audit legacy SharePoint Server security?

Audit SharePoint Server security by automating reconnaissance across versions from 2013 to Subscription Edition. This identifies EoL exposure, validates ToolShell precondition chains, and detects misconfigurations in internet-facing farms.

Does this SharePoint security audit support Subscription Edition?

Yes, this SharePoint security audit supports Subscription Edition. It operates across diverse SharePoint versions from 2013 to Subscription Edition to map known CVEs and detect NTLM information leaks.

How do I check a SharePoint farm for CVE-2025-53770 exposure?

Check SharePoint farms for CVE-2025-53770 exposure by probing for the ToolShell vulnerability during automated reconnaissance. This validates precondition chains to detect critical flaws in on-premise environments.

Can I detect NTLM information leaks in SharePoint automatically?

Yes, you can detect NTLM information leaks in SharePoint automatically. The automated vulnerability probing identifies NTLM leaks alongside legacy SOAP login bypasses and ToolShell vulnerabilities during authorized offensive security engagements.