Huntbase Hub
Threat hunts from this week's research.
Each hunt turns a piece of public threat research into something you can run: a hypothesis, the queries that test it, what a hit looks like, and what the hunt cannot see.
Want to run them against your own data? Sign up to Huntbase, free →
207 of 207 hunts
-
highResearch by Cisco Talos
AI-Integrated Malware Execution and Orchestration
Adversaries use AI frameworks or local runtimes for autonomous malware orchestration, detectable through cognitive artifacts like framework-specific imports, natural-language evasion strings, and outbound provider API traffic.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
highResearch by Rapid7
Citrix NetScaler Authentication Bypass and Exposure
An unauthenticated attacker has exploited CVE-2026-19490 on an internet-facing NetScaler appliance to bypass authentication and gain unauthorized remote access.
3 query1 analytic1 checkpoint2 taskinitial access -
highResearch by Rapid7
F5 BIG-IP APM OAuth RCE Exploitation
An unauthenticated attacker is exploiting a heap-based buffer overflow in F5 BIG-IP APM by sending crafted traffic to virtual servers configured with OAuth profiles to achieve code execution.
3 query2 analytic2 checkpoint1 action2 taskexecution · initial access -
high Part 2 of 2Research by Rapid7
Internal Coercion and Editor Persistence
An adversary is using rogue DHCPv6 services to perform DNS takeover for Kerberos relaying, or has established persistence via unauthorized Kate editor plugins on compromised hosts.
3 query1 analytic1 checkpoint1 action2 taskcredential access · execution · initial access -
high Part 1 of 2Research by Rapid7
Exploitation of Web-Facing GitLab and Langflow
An adversary is exploiting GitLab unauthenticated file reads or Langflow authenticated RCE to access repository secrets or execute code on the server host, starting from public-facing assets.
3 query1 analytic1 checkpoint1 action2 taskcredential access · execution · initial access -
highResearch by Sekoia
Exvicy ClickFix Social Engineering and PowerShell Execution
An adversary is using compromised WordPress sites to deliver Exvicy ClickFix lures that trick users into executing a PowerShell downloader via social engineering keyboard shortcuts.
4 query2 analytic1 checkpoint1 action2 taskcollection · command and control · execution -
highResearch by Cisco Talos
M365 Session Hijacking and Malware Execution
An adversary has bypassed MFA by stealing M365 session tokens via DocuSign-themed phishing, enabling them to execute malicious droppers and deploy ransomware across the fleet.
5 query2 analytic1 checkpoint1 action2 taskcredential access · execution · impact -
high Part 2 of 2Research by Cisco Talos
SSO Takeover and Data Impact
An adversary has bypassed SSO protections using stolen credentials and is now performing bulk data exfiltration or deploying ransomware across the environment.
3 query1 analytic1 checkpoint1 action2 taskcredential access · execution · impact -
high Part 1 of 2Research by Cisco Talos
Infostealer execution and browser credential harvesting
An adversary has successfully phished a user and executed an infostealer, which is now harvesting browser credentials and cookies from local SQLite databases for exfiltration.
5 query2 analytic2 checkpoint1 action2 taskcredential access · execution · impact -
medium Part 1 of 2Research by Cisco Talos
ClickFix Browser Injection and Extension Persistence
An intruder has used a social engineering lure to trick a user into manually injecting a JavaScript loader or installing a malicious Tampermonkey script that facilitates persistent cryptocurrency theft via the Google Visualization API.
5 query2 analytic1 checkpoint1 action2 taskcollection · command and control · execution -
highResearch by Cisco Talos
Microsoft Patch Tuesday September 2026 Exposure
An adversary is exploiting September 2026 zero-day or critical remote code execution vulnerabilities, such as those in DNS Server or the Windows Update Stack, to establish initial access or escalate privileges on unpatched systems.
3 query1 analytic1 checkpoint2 taskexecution · initial access · privilege escalation -
high Part 2 of 2Research by Cisco Talos
Autonomous AI Command-and-Control and Impact
An adversary is using autonomous AI-driven malware to orchestrate command-and-control decisions via LLM API calls, followed by high-volume data encryption for impact.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 1 of 2Research by Cisco Talos
Socially Engineered Endpoint Infection and Evasion
An attacker uses social engineering lures such as consultancy offers to trick users into running trojanised software that installs an EDR killer and steals credentials.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 2 of 2Research by Huntress
AI-Accelerated Post-Exploitation and Extortion
An intruder is using AI-driven automation to conduct rapid internal reconnaissance, steal AI service tokens, and triage sensitive files for extortion at machine speed.
3 query1 analytic1 checkpoint1 action2 taskcredential access · discovery · impact -
high Part 1 of 2Research by Huntress
Machine-Speed Perimeter and Identity Ingress
An automated attacker is exploiting unpatched perimeter services or using AI-refined phishing to compromise identities, resulting in successful sign-ins from rare geolocations that correlate with known gateway vulnerabilities.
3 query1 analytic1 checkpoint1 action2 taskcredential access · discovery · impact -
highResearch by Rapid7
SharePoint Business Data Connectivity Service Exploitation
An attacker has exploited the SharePoint Business Data Connectivity service by uploading a malicious BDC model file to instantiate a .NET gadget chain, resulting in remote code execution within the IIS worker process context.
3 query1 analytic1 checkpoint1 action2 taskexecution · initial access -
highResearch by Rapid7
Unauthenticated N-central Administrator Account Creation
An intruder has exploited a routing discrepancy between Envoy and Jetty in an N-central server to bypass authentication and create a new administrative account for persistence.
3 query2 analytic2 checkpoint1 action2 taskcredential access · initial access · persistence -
highResearch by Rapid7
Metasploit Framework Exploitation and Post-Exploitation
An intruder has leveraged one of sixteen new Metasploit modules to exploit a public-facing web application and establish persistence or conduct Kerberos authentication relaying.
5 query2 analytic1 checkpoint1 action2 taskcredential access · defense evasion · initial access -
highResearch by ESET Research
SparroWocky Backdoor and FamousSparrow APT Activity
An adversary has established a beachhead on a web-facing server using a trident loader scheme and is communicating with SparroWocky C2 infrastructure.
5 query2 analytic1 checkpoint1 action2 taskexecution · exfiltration · initial access -
highResearch by Sekoia
Gamaredon GammaLoad Intrusion Lifecycle
An adversary is using multi-stage VBScript loaders to maintain persistent access by caching C2 configuration in HKCU registry keys and executing payloads from Alternate Data Streams via scheduled tasks.
5 query2 analytic1 checkpoint1 action2 taskexecution · exfiltration · persistence -
high Part 2 of 2Research by Sekoia
ErrTraffic ClickFix PowerShell and Infostealer Activity
An intruder has tricked a user into running a PowerShell command via a ClickFix lure, which downloads an infostealer to harvest credentials and connect to blockchain-resolved C2 domains.
3 query1 analytic1 checkpoint1 action2 taskcollection · command and control · credential access -
high Part 1 of 2Research by Sekoia
ErrTraffic Infrastructure and Delivery Monitoring
An intruder has compromised WordPress servers to host the ErrTraffic framework, which currently resolves C2 via blockchain RPCs and serves ClickFix lures from specific JavaScript endpoints.
4 query1 analytic1 checkpoint1 action2 taskcollection · command and control · credential access -
high Part 2 of 2Research by Sekoia
APT28 Edge Hijacking and AI-Driven Exfiltration
An adversary has hijacked local DNS settings via compromised edge infrastructure and is using a rare, non-browser process to automate the harvesting of documents for exfiltration via AI APIs or high-port tunnels.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution -
high Part 1 of 2Research by Sekoia
APT28: Outlook and Print Spooler Exploitation
An adversary is exploiting unpatched Outlook or Print Spooler vulnerabilities to harvest NTLM credentials or escalate privileges, evidenced by outbound SMB connections to external IPs and rare child processes launched by the spooler service.
4 query2 analytic2 checkpoint1 action2 taskcommand and control · credential access · execution
No hunts match those filters.