← All hunts high TLP:CLEAR

Metasploit Framework Exploitation and Post-Exploitation

An intruder has leveraged one of sixteen new Metasploit modules to exploit a public-facing web application and establish persistence or conduct Kerberos authentication relaying.

Based on research by Rapid7 2026-09-28 12 steps · 5 queries T1190 T1497.001 T1547.001 T1547.003 T1557.001

Brief

Why this hunt

Rapid7 recently detailed sixteen new modules in their article Metasploit Wrap Up: This One Goes to Sixteen! (https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-goes-to-sixteen). These modules target vulnerabilities in Cisco FMC, SonicWall SMA, and JetBrains TeamCity, among others. While vulnerability scanners find the exposure, this hunt provides the behavioral verification to confirm if an adversary successfully used these tools. Security teams need to move beyond simple scanning to identify active exploitation in real-time.

How the Hunt Flows

The hunt begins by scoping the estate. It queries the hb_vulnerability_finding surface to list hosts exposed to the specific CVEs mentioned in the Metasploit release. This phase focuses the subsequent, more resource-intensive queries on the most likely targets, such as internet-facing management appliances. By narrowing the scope, we reduce the processing time for the rest of the hunt. Next, the hunt triages initial access signals in parallel. It searches the hb_http_activity surface for specific HTTP URI paths and query strings associated with the new modules. At the same time, it looks for web server processes like nginx, apache2, or w3wp.exe spawning shell binaries in the hb_process_activity surface. An automated agent evaluates these signals to separate benign scanning from successful remote code execution. This dual-track approach ensures we catch both the attempt and the result. The third phase pivots to post-exploitation activity. It monitors the hb_registry_activity surface for rare modifications to specific registry keys used by Metasploit for persistence. These include the BootVerificationProgram and TimeProviders keys. The hunt uses a prevalence check to filter out environment-standard values and highlight only rare changes. Simultaneously, it checks the hb_network_connection surface for outbound SMB traffic from web servers. Such traffic often indicates an attempt to coerce authentication for a Kerberos relay attack. Finally, a second agent correlates the entire chain. By linking a specific web exploit URI to a shell spawn and subsequent persistence, the hunt provides a high-confidence verdict. The analyst then reviews the evidence to confirm the breach.

What the Hunt Cannot See

The hunt relies on endpoint telemetry for process and registry visibility. If an unmanaged server is exploited, the hunt only sees the HTTP traffic. This makes confirming a successful shell spawn difficult without direct host access. Additionally, if the adversary conducts SMB relaying over an established VPN tunnel, the outbound network connection might be masked by internal VPN traffic. This hides the Kerberos relay attempt from standard network logs. The linux/x64/sandbox_gate module also performs runtime checks that are too transient for process snapshots and require live instrumentation to detect.

Steps

  1. Scope vulnerable hosts

    Query · scoping

    Identify hosts in the estate that have been identified as vulnerable to the CVEs mentioned in the report.

    reads hb_vulnerability_findingsql
    SELECT device_uid, cve_uid, severity, affected_package_name FROM hb_vulnerability_finding WHERE instr(',' || '{{vulnerable_cves}}' || ',', ',' || cve_uid || ',') > 0

    What a hit looks like. A list of hosts currently exposed to the Metasploit exploits. Silence indicates the estate is patched.

  2. Web exploitation URI patterns

    Query · triage

    Match HTTP requests against known targeted URIs for the new Metasploit modules.

    reads hb_http_activitysql
    SELECT device_hostname, url_path, url_query, src_endpoint_ip, user_agent, time FROM hb_http_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{exploit_uris}}' || ',', ',' || url_path || ',') > 0 OR instr(LOWER(url_query), 'action=session') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Requests to specific management or vulnerable endpoints. High volume from external IPs indicates scanning or exploitation.

  3. Suspicious web server children

    Query · detection candidate

    Detect web server processes spawning shells or interpreters, indicating successful remote code execution.

    reads hb_process_activitysql
    SELECT device_hostname, process_name, parent_process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND instr(',' || '{{web_parents}}' || ',', ',' || LOWER(parent_process_name) || ',') > 0 AND instr(',' || '{{shell_binaries}}' || ',', ',' || LOWER(process_name) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. A web server spawning a shell (e.g., cmd.exe, /bin/sh). This is the definitive signal of successful RCE.

  4. Initial access agent triage

    Agent triage

    Identify successful exploitation from early signals.

  5. Registry-based persistence mechanisms

    Query · baseline

    Find modifications to BootVerificationProgram or TimeProviders registry keys which are used by new Metasploit modules.

    reads hb_registry_activitysql
    SELECT device_hostname, reg_target, reg_value_data, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_registry_activity WHERE (LOWER(reg_target) LIKE '%\bootverificationprogram%' OR LOWER(reg_target) LIKE '%\timeproviders%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY reg_target, reg_value_data HAVING host_count <= 3

    What a hit looks like. Rarely modified persistence keys pointing to non-standard binaries or DLLs. Baseline filters out environment-standard values.

  6. SMB authentication relay attempts

    Query · triage

    Detect outbound SMB connections from web servers, indicating coerced authentication for credential relaying.

    reads hb_network_connectionsql
    SELECT device_hostname, src_endpoint_ip, dst_endpoint_ip, process_name, time FROM hb_network_connection WHERE dst_endpoint_port = 445 AND direction = 'outbound' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Outbound SMB (445) from a server that normally only serves HTTP. This is highly suspicious of credential coercion.

  7. Final post-exploitation agent

    Agent triage

    Correlate full chain evidence.

  8. Route verdict

    Decision

    Route on confirmed compromise.

  9. Isolate host

    Response action

    Contain compromise.

  10. Analyst forensic review

    Analyst task

    Manual verification.

  11. Close out

    Analyst task

    Wrap up hunt and document.

Coverage

Scenario coverage

StageCoveredHow, or why not
Exploitation of Public-Facing Applications
T1190
Yes web-exploitation-patterns, suspicious-web-children
ESC8 Kerberos Authentication Relay
T1557.001
Yes smb-auth-relay
Registry-Based Persistence
T1547.001 · T1547.003
Yes persistence-mechanisms
Sandbox Environment Detection
T1497.001
Not visible The linux/x64/sandbox_gate performs runtime checks that are too transient for process snapshots; requires live instrumentation.

Blind spots

  • Needs endpoint agent installation on all web servers. An unmanaged server being exploited will only show HTTP traffic, making the confirmation of RCE difficult. It would answer whether a shell was spawned on an unmanaged server.
  • Needs VPN traffic logs or endpoint network visibility. Outbound network connections might be masked by internal VPN traffic, hiding the Kerberos relay attempt. It would answer whether SMB relay occurred over a VPN tunnel.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
exploit_urislist[string]/api/mcp/connect, action=session, spip.php, workplace, TeamCity/agent, fmcURI patterns or strings targeted by the Metasploit modules.
lookback_daysnumber14Days of history to examine.
scope_hostslist[host]—Target hosts to filter the hunt.
shell_binarieslist[string]cmd.exe, powershell.exe, sh, bash, zshShell binaries often used in RCE payloads.
vulnerable_cveslist[string]CVE-2025-66516, CVE-2025-54988, CVE-2026-19295, CVE-2026-20079, CVE-2026-63077, CVE-2026-23744, CVE-2026-82078, CVE-2026-48558, CVE-2026-75604, CVE-2026-83549CVEs identified in the Metasploit update.
web_parentslist[string]httpd, nginx, w3wp.exe, node.exe, python, apache2Common web server process names.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint
Network telemetrynetworknetwork
Web server / proxy logssiemnetwork

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: While a single rule might detect a web shell, this hunt correlates that
  shell with URI patterns, rare registry persistence, and Kerberos relaying across
  multiple surfaces, providing the context needed to confirm a high-confidence intrusion
  rather than a benign alert.
blind_spots:
- id: no-endpoint-telemetry
  question: whether a shell was spawned on an unmanaged server
  requires: endpoint agent installation on all web servers
  risk: An unmanaged server being exploited will only show HTTP traffic, making the
    confirmation of RCE difficult.
- id: smb-over-vpn
  question: whether SMB relay occurred over a VPN tunnel
  requires: VPN traffic logs or endpoint network visibility
  risk: Outbound network connections might be masked by internal VPN traffic, hiding
    the Kerberos relay attempt.
  stage: credential-access-kerberos-relay
coverage:
- stage: initial-access-web-exploitation
  status: covered
  steps:
  - web-exploitation-patterns
  - suspicious-web-children
- stage: credential-access-kerberos-relay
  status: covered
  steps:
  - smb-auth-relay
- stage: persistence-registry-modification
  status: covered
  steps:
  - persistence-mechanisms
- reason: The linux/x64/sandbox_gate performs runtime checks that are too transient
    for process snapshots; requires live instrumentation.
  stage: evasion-sandbox-detection
  status: not_visible
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: promote-to-detection
  justification: The release of sixteen new Metasploit modules, including multiple
    zero-day exploits and persistence techniques, creates an immediate threat window
    that periodic scanning cannot close; a hunt provides behavioral verification of
    security.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An intruder has leveraged one of sixteen new Metasploit modules to exploit
  a public-facing web application and establish persistence or conduct Kerberos authentication
  relaying.
labels:
- hunt
- attack.t1190
- attack.t1557.001
- attack.t1547.001
- attack.t1547.003
- attack.t1497.001
name: Metasploit Framework Exploitation and Post-Exploitation
parameters:
  exploit_uris:
    default:
    - /api/mcp/connect
    - action=session
    - spip.php
    - workplace
    - TeamCity/agent
    - fmc
    description: URI patterns or strings targeted by the Metasploit modules.
    type: list[string]
  lookback_days:
    default: '14'
    description: Days of history to examine.
    type: number
  scope_hosts:
    default: []
    description: Target hosts to filter the hunt.
    type: list[host]
  shell_binaries:
    default:
    - cmd.exe
    - powershell.exe
    - sh
    - bash
    - zsh
    description: Shell binaries often used in RCE payloads.
    type: list[string]
  vulnerable_cves:
    default:
    - CVE-2025-66516
    - CVE-2025-54988
    - CVE-2026-19295
    - CVE-2026-20079
    - CVE-2026-63077
    - CVE-2026-23744
    - CVE-2026-82078
    - CVE-2026-48558
    - CVE-2026-75604
    - CVE-2026-83549
    description: CVEs identified in the Metasploit update.
    from:
      kind: article
      observed: '2026-09-11'
      ref: https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-goes-to-sixteen
    type: list[string]
  web_parents:
    default:
    - httpd
    - nginx
    - w3wp.exe
    - node.exe
    - python
    - apache2
    description: Common web server process names.
    type: list[string]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-goes-to-sixteen
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Start with internet-facing assets identified in the vulnerability scan
  as exposed to the target CVEs. Focus on the Cisco FMC, SonicWall SMA, and JetBrains
  TeamCity hosts first.
references:
- name: "Rapid7 \u2014 Metasploit Wrap Up: This One Goes to Sixteen!"
  url: https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-goes-to-sixteen
related:
- hunt: metasploit-auxiliary-scanner-detection
  reason: This hunt focuses on successful exploitation and post-exploitation; general
    Metasploit scanner activity is a broader behavioral hunt.
  relation: out-of-scope-alternative
scenario:
  stages:
  - name: Exploitation of Public-Facing Applications
    observables:
    - CVE-2026-20079
    - CVE-2026-83549
    - CVE-2026-63077
    - CVE-2026-19295
    - CVE-2026-23744
    - CVE-2026-82078
    - CVE-2026-48558
    - CVE-2026-75604
    - CVE-2025-66516
    - 'URL path: /api/mcp/connect'
    - 'URL path: /action=session'
    - JSP payload delivery
    - PHP code storage in session variables
    - cmsSnmpTrap.sh command injection
    slug: initial-access-web-exploitation
    tactic: initial-access
    techniques:
    - T1190
  - name: ESC8 Kerberos Authentication Relay
    observables:
    - CVE-2026-20929
    - SMB2 AP-REQ capture
    - Relay to AD CS Web Enrollment over HTTP
    - 'Metasploit module: server/relay/esc8_kerberos'
    slug: credential-access-kerberos-relay
    tactic: credential-access
    techniques:
    - T1557.001
  - name: Registry-Based Persistence
    observables:
    - 'Registry Key: HKLM\System\CurrentControlSet\Control\BootVerificationProgram'
    - 'Registry Key: HKLM\System\CurrentControlSet\Services\W32Time\TimeProviders'
    - Custom Time Provider DLL registration
    slug: persistence-registry-modification
    tactic: persistence
    techniques:
    - T1547.001
    - T1547.003
  - name: Sandbox Environment Detection
    observables:
    - Linux x64 runtime environment checks
    - 'Metasploit module: linux/x64/sandbox_gate'
    slug: evasion-sandbox-detection
    tactic: defense-evasion
    techniques:
    - T1497.001
  summary: The September 2026 Metasploit update introduces sixteen new modules, including
    high-impact RCE exploits for Cisco, PaperCut, and TeamCity, alongside an ESC8
    Kerberos relay capability for AD CS. The campaign encompasses initial exploitation
    via public-facing vulnerabilities, followed by advanced post-exploitation persistence
    and sandbox evasion techniques.
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  network:
    category: network
    name: Network telemetry
    telemetry:
    - network
  web:
    category: siem
    name: Web server / proxy logs
    telemetry:
    - network
tlp: clear
type: investigation
---


# Metasploit Framework Exploitation and Post-Exploitation

This hunt targets the release of sixteen new Metasploit modules, many of which exploit high-profile CVEs in Cisco, SonicWall, TeamCity, and PaperCut. The hunt follows a phased approach: first, it identifies vulnerable hosts and triages initial access indicators like targeted HTTP URI paths and anomalous process spawning from web servers. Second, it pivots to identify follow-on post-exploitation activity, specifically searching for rare registry-based persistence via BootVerificationProgram or TimeProviders and identifying outbound SMB traffic from servers, which may indicate Kerberos relay coercion. Two agents evaluate the chain to distinguish between scanning noise and successful compromise.

## scope-vulnerable-hosts
<!-- Scope vulnerable hosts -->
Identify hosts in the estate that have been identified as vulnerable to the CVEs mentioned in the report.

```sqlite target=endpoint role=scoping params=(vulnerable_cves=vulnerable_cves)
~~~yaml
expected: A list of hosts currently exposed to the Metasploit exploits. Silence indicates
  the estate is patched.
reads:
- device_uid
- cve_uid
- severity
- affected_package_name
silence: not_evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_uid, cve_uid, severity, affected_package_name FROM hb_vulnerability_finding WHERE instr(',' || '{{vulnerable_cves}}' || ',', ',' || cve_uid || ',') > 0
```

## initial-access-triage
<!-- Triage initial access -->
parallel:
- → web-exploitation-patterns
- → suspicious-web-children
join: → initial-access-agent

## web-exploitation-patterns
<!-- Web exploitation URI patterns -->
Match HTTP requests against known targeted URIs for the new Metasploit modules.

```sqlite target=web role=triage params=(scope_hosts=scope_hosts, exploit_uris=exploit_uris, lookback_days=lookback_days)
~~~yaml
expected: Requests to specific management or vulnerable endpoints. High volume from
  external IPs indicates scanning or exploitation.
reads:
- device_hostname
- url_path
- url_query
- src_endpoint_ip
- user_agent
- time
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, url_path, url_query, src_endpoint_ip, user_agent, time FROM hb_http_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{exploit_uris}}' || ',', ',' || url_path || ',') > 0 OR instr(LOWER(url_query), 'action=session') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## suspicious-web-children
<!-- Suspicious web server children -->
Detect web server processes spawning shells or interpreters, indicating successful remote code execution.

```sqlite target=endpoint role=detection-candidate params=(scope_hosts=scope_hosts, web_parents=web_parents, shell_binaries=shell_binaries, lookback_days=lookback_days)
~~~yaml
expected: A web server spawning a shell (e.g., cmd.exe, /bin/sh). This is the definitive
  signal of successful RCE.
reads:
- device_hostname
- process_name
- parent_process_name
- process_cmd_line
- user_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, process_name, parent_process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND instr(',' || '{{web_parents}}' || ',', ',' || LOWER(parent_process_name) || ',') > 0 AND instr(',' || '{{shell_binaries}}' || ',', ',' || LOWER(process_name) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')
```

## initial-access-agent
<!-- Initial access agent triage -->
```agent target=hunter
cite: required
context:
- scope-vulnerable-hosts
- web-exploitation-patterns
- suspicious-web-children
max_iterations: 3
objective: Determine if any host shows evidence of successful web exploitation based
  on HTTP traffic and process anomalies.
success_criteria: A per-host verdict of compromised | suspicious | scanning, citing
  the shell command line or specific HTTP path.
tools:
- endpoint
- network
- web
```

## post-exploitation-triage
<!-- Post-exploitation triage -->
parallel:
- → persistence-mechanisms
- → smb-auth-relay
join: → final-triage-agent

## persistence-mechanisms
<!-- Registry-based persistence mechanisms -->
Find modifications to BootVerificationProgram or TimeProviders registry keys which are used by new Metasploit modules.

```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: Rarely modified persistence keys pointing to non-standard binaries or DLLs.
  Baseline filters out environment-standard values.
prevalence:
  by: device_hostname
  key:
  - reg_target
  - reg_value_data
  rare_below: 3
reads:
- device_hostname
- reg_target
- reg_value_data
- time
silence: not_evidence_of_absence
source: hb_registry_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, reg_target, reg_value_data, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_registry_activity WHERE (LOWER(reg_target) LIKE '%\bootverificationprogram%' OR LOWER(reg_target) LIKE '%\timeproviders%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY reg_target, reg_value_data HAVING host_count <= 3
```

## smb-auth-relay
<!-- SMB authentication relay attempts -->
Detect outbound SMB connections from web servers, indicating coerced authentication for credential relaying.

```sqlite target=network role=triage params=(scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: Outbound SMB (445) from a server that normally only serves HTTP. This is
  highly suspicious of credential coercion.
reads:
- device_hostname
- src_endpoint_ip
- dst_endpoint_ip
- process_name
- time
silence: not_evidence_of_absence
source: hb_network_connection
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, src_endpoint_ip, dst_endpoint_ip, process_name, time FROM hb_network_connection WHERE dst_endpoint_port = 445 AND direction = 'outbound' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## final-triage-agent
<!-- Final post-exploitation agent -->
```agent target=hunter
cite: required
context:
- initial-access-agent
- persistence-mechanisms
- smb-auth-relay
max_iterations: 6
objective: Combine the evidence of initial access with the persistence and relay indicators
  to confirm a full attack chain.
success_criteria: A confirmed breach verdict citing the progression from web exploit
  to persistent access or relaying.
tools:
- endpoint
- network
- web
```

## route-verdict
<!-- Route verdict -->
if~: "the final-triage-agent verdict is malicious for any host" (confidence: high, judge=hunter)
then: → isolate-host
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: no-endpoint-telemetry)
else: → close-out

## isolate-host
<!-- Isolate host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the compromised host from the network and revoke any active credentials associated with the session.
```
→ analyst-review

## analyst-review
<!-- Analyst forensic review -->
```manual target=analyst
Review the agent's findings. Specifically, verify the registry modifications and the source of the outbound SMB connections. Determine if the shell execution on the web server was authorized maintenance or an actual breach.
```
→ end

## close-out
<!-- Close out -->
```manual target=analyst
Record the findings and update the vulnerability status for the identified hosts. If no breach was found, use the scoping results to prioritize patching the vulnerable assets.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.