That said, the column name does not make a lot of sense to us.
We believe the adversary exploited a recently vulnerability in Microsoft SharePoint tracked by , which is a remote code execution vulnerability used to compromise the server and eventually install a webshell.
When assigning permissions to a SharePoint site, the recommended approach is to add security groups to those SharePoint groups.