What problem does it solve?
SharePoint on-prem farms (SP2013/2016/2019/SubEdition) often expose dangerous misconfigurations and legacy vectors that attackers or red-team operators can exploit. This Skill provides structured discovery, risk mapping, and practical steps to identify anonymous endpoint exposure, ToolShell preconditions, NTLM topology leaks, and custom-branding module surfaces.
Core Features & Use Cases
- Anonymous endpoint enumeration across /_layouts/15, /_vti_bin, /_api, and /_catalogs/ to map version, surface exposure, and preconditions.
- ToolShell precondition chain testing (CVE-2025-53770) to validate potential RCE surfaces in legacy SP2013 and later.
- SafeControl reflection reconnaissance via Picker.aspx to enumerate reachable classes for post-exploitation chaining.
- NTLM Type-2 topology disclosure to understand AD forest relationships and attacker recon.
- Custom-branding module discovery to assess ongoing maintenance and exposure.
Quick Start
Run an anonymous scan against a target SharePoint on-prem farm to enumerate endpoints, verify ToolShell preconditions, and identify potential NTLM topology signals.