Metasploit Framework Exploitation and Post-Exploitation
An intruder has leveraged one of sixteen new Metasploit modules to exploit a public-facing web application and establish persistence or conduct Kerberos authentication relaying.
Based on research by Rapid7 2026-09-28 12 steps · 5 queries T1190 T1497.001 T1547.001 T1547.003 T1557.001
Brief
Why this hunt
Rapid7 recently detailed sixteen new modules in their article Metasploit Wrap Up: This One Goes to Sixteen! (https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-goes-to-sixteen). These modules target vulnerabilities in Cisco FMC, SonicWall SMA, and JetBrains TeamCity, among others. While vulnerability scanners find the exposure, this hunt provides the behavioral verification to confirm if an adversary successfully used these tools. Security teams need to move beyond simple scanning to identify active exploitation in real-time.
How the Hunt Flows
The hunt begins by scoping the estate. It queries the hb_vulnerability_finding surface to list hosts exposed to the specific CVEs mentioned in the Metasploit release. This phase focuses the subsequent, more resource-intensive queries on the most likely targets, such as internet-facing management appliances. By narrowing the scope, we reduce the processing time for the rest of the hunt. Next, the hunt triages initial access signals in parallel. It searches the hb_http_activity surface for specific HTTP URI paths and query strings associated with the new modules. At the same time, it looks for web server processes like nginx, apache2, or w3wp.exe spawning shell binaries in the hb_process_activity surface. An automated agent evaluates these signals to separate benign scanning from successful remote code execution. This dual-track approach ensures we catch both the attempt and the result. The third phase pivots to post-exploitation activity. It monitors the hb_registry_activity surface for rare modifications to specific registry keys used by Metasploit for persistence. These include the BootVerificationProgram and TimeProviders keys. The hunt uses a prevalence check to filter out environment-standard values and highlight only rare changes. Simultaneously, it checks the hb_network_connection surface for outbound SMB traffic from web servers. Such traffic often indicates an attempt to coerce authentication for a Kerberos relay attack. Finally, a second agent correlates the entire chain. By linking a specific web exploit URI to a shell spawn and subsequent persistence, the hunt provides a high-confidence verdict. The analyst then reviews the evidence to confirm the breach.
What the Hunt Cannot See
The hunt relies on endpoint telemetry for process and registry visibility. If an unmanaged server is exploited, the hunt only sees the HTTP traffic. This makes confirming a successful shell spawn difficult without direct host access. Additionally, if the adversary conducts SMB relaying over an established VPN tunnel, the outbound network connection might be masked by internal VPN traffic. This hides the Kerberos relay attempt from standard network logs. The linux/x64/sandbox_gate module also performs runtime checks that are too transient for process snapshots and require live instrumentation to detect.
Steps
-
Scope vulnerable hosts
Query · scopingIdentify hosts in the estate that have been identified as vulnerable to the CVEs mentioned in the report.
reads hb_vulnerability_findingsqlSELECT device_uid, cve_uid, severity, affected_package_name FROM hb_vulnerability_finding WHERE instr(',' || '{{vulnerable_cves}}' || ',', ',' || cve_uid || ',') > 0What a hit looks like. A list of hosts currently exposed to the Metasploit exploits. Silence indicates the estate is patched.
-
Web exploitation URI patterns
Query · triageMatch HTTP requests against known targeted URIs for the new Metasploit modules.
reads hb_http_activitysqlSELECT device_hostname, url_path, url_query, src_endpoint_ip, user_agent, time FROM hb_http_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{exploit_uris}}' || ',', ',' || url_path || ',') > 0 OR instr(LOWER(url_query), 'action=session') > 0) AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. Requests to specific management or vulnerable endpoints. High volume from external IPs indicates scanning or exploitation.
-
Suspicious web server children
Query · detection candidateDetect web server processes spawning shells or interpreters, indicating successful remote code execution.
reads hb_process_activitysqlSELECT device_hostname, process_name, parent_process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND instr(',' || '{{web_parents}}' || ',', ',' || LOWER(parent_process_name) || ',') > 0 AND instr(',' || '{{shell_binaries}}' || ',', ',' || LOWER(process_name) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. A web server spawning a shell (e.g., cmd.exe, /bin/sh). This is the definitive signal of successful RCE.
-
Initial access agent triage
Agent triageIdentify successful exploitation from early signals.
-
Registry-based persistence mechanisms
Query · baselineFind modifications to BootVerificationProgram or TimeProviders registry keys which are used by new Metasploit modules.
reads hb_registry_activitysqlSELECT device_hostname, reg_target, reg_value_data, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_registry_activity WHERE (LOWER(reg_target) LIKE '%\bootverificationprogram%' OR LOWER(reg_target) LIKE '%\timeproviders%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY reg_target, reg_value_data HAVING host_count <= 3What a hit looks like. Rarely modified persistence keys pointing to non-standard binaries or DLLs. Baseline filters out environment-standard values.
-
SMB authentication relay attempts
Query · triageDetect outbound SMB connections from web servers, indicating coerced authentication for credential relaying.
reads hb_network_connectionsqlSELECT device_hostname, src_endpoint_ip, dst_endpoint_ip, process_name, time FROM hb_network_connection WHERE dst_endpoint_port = 445 AND direction = 'outbound' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. Outbound SMB (445) from a server that normally only serves HTTP. This is highly suspicious of credential coercion.
-
Final post-exploitation agent
Agent triageCorrelate full chain evidence.
-
Route verdict
DecisionRoute on confirmed compromise.
-
Isolate host
Response actionContain compromise.
-
Analyst forensic review
Analyst taskManual verification.
-
Close out
Analyst taskWrap up hunt and document.
Coverage
Scenario coverage
| Stage | Covered | How, or why not |
|---|---|---|
| Exploitation of Public-Facing Applications T1190 |
Yes | web-exploitation-patterns, suspicious-web-children |
| ESC8 Kerberos Authentication Relay T1557.001 |
Yes | smb-auth-relay |
| Registry-Based Persistence T1547.001 · T1547.003 |
Yes | persistence-mechanisms |
| Sandbox Environment Detection T1497.001 |
Not visible | The linux/x64/sandbox_gate performs runtime checks that are too transient for process snapshots; requires live instrumentation. |
Blind spots
- Needs endpoint agent installation on all web servers. An unmanaged server being exploited will only show HTTP traffic, making the confirmation of RCE difficult. It would answer whether a shell was spawned on an unmanaged server.
- Needs VPN traffic logs or endpoint network visibility. Outbound network connections might be masked by internal VPN traffic, hiding the Kerberos relay attempt. It would answer whether SMB relay occurred over a VPN tunnel.
Parameters & data
Parameters
| Parameter | Type | Default | What it is |
|---|---|---|---|
exploit_uris | list[string] | /api/mcp/connect, action=session, spip.php, workplace, TeamCity/agent, fmc | URI patterns or strings targeted by the Metasploit modules. |
lookback_days | number | 14 | Days of history to examine. |
scope_hosts | list[host] | — | Target hosts to filter the hunt. |
shell_binaries | list[string] | cmd.exe, powershell.exe, sh, bash, zsh | Shell binaries often used in RCE payloads. |
vulnerable_cves | list[string] | CVE-2025-66516, CVE-2025-54988, CVE-2026-19295, CVE-2026-20079, CVE-2026-63077, CVE-2026-23744, CVE-2026-82078, CVE-2026-48558, CVE-2026-75604, CVE-2026-83549 | CVEs identified in the Metasploit update. |
web_parents | list[string] | httpd, nginx, w3wp.exe, node.exe, python, apache2 | Common web server process names. |
Telemetry
| Source | Category | Telemetry |
|---|---|---|
| Endpoint telemetry (hb_ surfaces) | endpoint | endpoint |
| Network telemetry | network | network |
| Web server / proxy logs | siem | network |
Source
---
analysis: While a single rule might detect a web shell, this hunt correlates that
shell with URI patterns, rare registry persistence, and Kerberos relaying across
multiple surfaces, providing the context needed to confirm a high-confidence intrusion
rather than a benign alert.
blind_spots:
- id: no-endpoint-telemetry
question: whether a shell was spawned on an unmanaged server
requires: endpoint agent installation on all web servers
risk: An unmanaged server being exploited will only show HTTP traffic, making the
confirmation of RCE difficult.
- id: smb-over-vpn
question: whether SMB relay occurred over a VPN tunnel
requires: VPN traffic logs or endpoint network visibility
risk: Outbound network connections might be masked by internal VPN traffic, hiding
the Kerberos relay attempt.
stage: credential-access-kerberos-relay
coverage:
- stage: initial-access-web-exploitation
status: covered
steps:
- web-exploitation-patterns
- suspicious-web-children
- stage: credential-access-kerberos-relay
status: covered
steps:
- smb-auth-relay
- stage: persistence-registry-modification
status: covered
steps:
- persistence-mechanisms
- reason: The linux/x64/sandbox_gate performs runtime checks that are too transient
for process snapshots; requires live instrumentation.
stage: evasion-sandbox-detection
status: not_visible
guardrails:
claims: no_unsupported
evidence: citation_required
missing_data: not_benign
telemetry: untrusted
hunt:
applicability: campaign-specific
handoff: promote-to-detection
justification: The release of sixteen new Metasploit modules, including multiple
zero-day exploits and persistence techniques, creates an immediate threat window
that periodic scanning cannot close; a hunt provides behavioral verification of
security.
methodology: model-assisted
trigger: intel-report
hypothesis: An intruder has leveraged one of sixteen new Metasploit modules to exploit
a public-facing web application and establish persistence or conduct Kerberos authentication
relaying.
labels:
- hunt
- attack.t1190
- attack.t1557.001
- attack.t1547.001
- attack.t1547.003
- attack.t1497.001
name: Metasploit Framework Exploitation and Post-Exploitation
parameters:
exploit_uris:
default:
- /api/mcp/connect
- action=session
- spip.php
- workplace
- TeamCity/agent
- fmc
description: URI patterns or strings targeted by the Metasploit modules.
type: list[string]
lookback_days:
default: '14'
description: Days of history to examine.
type: number
scope_hosts:
default: []
description: Target hosts to filter the hunt.
type: list[host]
shell_binaries:
default:
- cmd.exe
- powershell.exe
- sh
- bash
- zsh
description: Shell binaries often used in RCE payloads.
type: list[string]
vulnerable_cves:
default:
- CVE-2025-66516
- CVE-2025-54988
- CVE-2026-19295
- CVE-2026-20079
- CVE-2026-63077
- CVE-2026-23744
- CVE-2026-82078
- CVE-2026-48558
- CVE-2026-75604
- CVE-2026-83549
description: CVEs identified in the Metasploit update.
from:
kind: article
observed: '2026-09-11'
ref: https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-goes-to-sixteen
type: list[string]
web_parents:
default:
- httpd
- nginx
- w3wp.exe
- node.exe
- python
- apache2
description: Common web server process names.
type: list[string]
provenance:
authors:
- name: Huntbase hunt generation
org: huntbase.io
generated:
by: huntbase-hunt-generation
from: https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-goes-to-sixteen
gates:
- dry-run
- lint
model: hb_google/gemini-3-flash-preview
rationale: Start with internet-facing assets identified in the vulnerability scan
as exposed to the target CVEs. Focus on the Cisco FMC, SonicWall SMA, and JetBrains
TeamCity hosts first.
references:
- name: "Rapid7 \u2014 Metasploit Wrap Up: This One Goes to Sixteen!"
url: https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-goes-to-sixteen
related:
- hunt: metasploit-auxiliary-scanner-detection
reason: This hunt focuses on successful exploitation and post-exploitation; general
Metasploit scanner activity is a broader behavioral hunt.
relation: out-of-scope-alternative
scenario:
stages:
- name: Exploitation of Public-Facing Applications
observables:
- CVE-2026-20079
- CVE-2026-83549
- CVE-2026-63077
- CVE-2026-19295
- CVE-2026-23744
- CVE-2026-82078
- CVE-2026-48558
- CVE-2026-75604
- CVE-2025-66516
- 'URL path: /api/mcp/connect'
- 'URL path: /action=session'
- JSP payload delivery
- PHP code storage in session variables
- cmsSnmpTrap.sh command injection
slug: initial-access-web-exploitation
tactic: initial-access
techniques:
- T1190
- name: ESC8 Kerberos Authentication Relay
observables:
- CVE-2026-20929
- SMB2 AP-REQ capture
- Relay to AD CS Web Enrollment over HTTP
- 'Metasploit module: server/relay/esc8_kerberos'
slug: credential-access-kerberos-relay
tactic: credential-access
techniques:
- T1557.001
- name: Registry-Based Persistence
observables:
- 'Registry Key: HKLM\System\CurrentControlSet\Control\BootVerificationProgram'
- 'Registry Key: HKLM\System\CurrentControlSet\Services\W32Time\TimeProviders'
- Custom Time Provider DLL registration
slug: persistence-registry-modification
tactic: persistence
techniques:
- T1547.001
- T1547.003
- name: Sandbox Environment Detection
observables:
- Linux x64 runtime environment checks
- 'Metasploit module: linux/x64/sandbox_gate'
slug: evasion-sandbox-detection
tactic: defense-evasion
techniques:
- T1497.001
summary: The September 2026 Metasploit update introduces sixteen new modules, including
high-impact RCE exploits for Cisco, PaperCut, and TeamCity, alongside an ESC8
Kerberos relay capability for AD CS. The campaign encompasses initial exploitation
via public-facing vulnerabilities, followed by advanced post-exploitation persistence
and sandbox evasion techniques.
severity: high
targets:
analyst:
name: Tier-2 analyst
role: analyst
endpoint:
category: endpoint
name: Endpoint telemetry (hb_ surfaces)
telemetry:
- endpoint
hunter:
agent: true
name: Hunt agent
network:
category: network
name: Network telemetry
telemetry:
- network
web:
category: siem
name: Web server / proxy logs
telemetry:
- network
tlp: clear
type: investigation
---
# Metasploit Framework Exploitation and Post-Exploitation
This hunt targets the release of sixteen new Metasploit modules, many of which exploit high-profile CVEs in Cisco, SonicWall, TeamCity, and PaperCut. The hunt follows a phased approach: first, it identifies vulnerable hosts and triages initial access indicators like targeted HTTP URI paths and anomalous process spawning from web servers. Second, it pivots to identify follow-on post-exploitation activity, specifically searching for rare registry-based persistence via BootVerificationProgram or TimeProviders and identifying outbound SMB traffic from servers, which may indicate Kerberos relay coercion. Two agents evaluate the chain to distinguish between scanning noise and successful compromise.
## scope-vulnerable-hosts
<!-- Scope vulnerable hosts -->
Identify hosts in the estate that have been identified as vulnerable to the CVEs mentioned in the report.
```sqlite target=endpoint role=scoping params=(vulnerable_cves=vulnerable_cves)
~~~yaml
expected: A list of hosts currently exposed to the Metasploit exploits. Silence indicates
the estate is patched.
reads:
- device_uid
- cve_uid
- severity
- affected_package_name
silence: not_evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_uid, cve_uid, severity, affected_package_name FROM hb_vulnerability_finding WHERE instr(',' || '{{vulnerable_cves}}' || ',', ',' || cve_uid || ',') > 0
```
## initial-access-triage
<!-- Triage initial access -->
parallel:
- → web-exploitation-patterns
- → suspicious-web-children
join: → initial-access-agent
## web-exploitation-patterns
<!-- Web exploitation URI patterns -->
Match HTTP requests against known targeted URIs for the new Metasploit modules.
```sqlite target=web role=triage params=(scope_hosts=scope_hosts, exploit_uris=exploit_uris, lookback_days=lookback_days)
~~~yaml
expected: Requests to specific management or vulnerable endpoints. High volume from
external IPs indicates scanning or exploitation.
reads:
- device_hostname
- url_path
- url_query
- src_endpoint_ip
- user_agent
- time
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, url_path, url_query, src_endpoint_ip, user_agent, time FROM hb_http_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{exploit_uris}}' || ',', ',' || url_path || ',') > 0 OR instr(LOWER(url_query), 'action=session') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```
## suspicious-web-children
<!-- Suspicious web server children -->
Detect web server processes spawning shells or interpreters, indicating successful remote code execution.
```sqlite target=endpoint role=detection-candidate params=(scope_hosts=scope_hosts, web_parents=web_parents, shell_binaries=shell_binaries, lookback_days=lookback_days)
~~~yaml
expected: A web server spawning a shell (e.g., cmd.exe, /bin/sh). This is the definitive
signal of successful RCE.
reads:
- device_hostname
- process_name
- parent_process_name
- process_cmd_line
- user_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, process_name, parent_process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND instr(',' || '{{web_parents}}' || ',', ',' || LOWER(parent_process_name) || ',') > 0 AND instr(',' || '{{shell_binaries}}' || ',', ',' || LOWER(process_name) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')
```
## initial-access-agent
<!-- Initial access agent triage -->
```agent target=hunter
cite: required
context:
- scope-vulnerable-hosts
- web-exploitation-patterns
- suspicious-web-children
max_iterations: 3
objective: Determine if any host shows evidence of successful web exploitation based
on HTTP traffic and process anomalies.
success_criteria: A per-host verdict of compromised | suspicious | scanning, citing
the shell command line or specific HTTP path.
tools:
- endpoint
- network
- web
```
## post-exploitation-triage
<!-- Post-exploitation triage -->
parallel:
- → persistence-mechanisms
- → smb-auth-relay
join: → final-triage-agent
## persistence-mechanisms
<!-- Registry-based persistence mechanisms -->
Find modifications to BootVerificationProgram or TimeProviders registry keys which are used by new Metasploit modules.
```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days)
~~~yaml
baseline:
compare: first_seen
window: '{{lookback_days}}d'
expected: Rarely modified persistence keys pointing to non-standard binaries or DLLs.
Baseline filters out environment-standard values.
prevalence:
by: device_hostname
key:
- reg_target
- reg_value_data
rare_below: 3
reads:
- device_hostname
- reg_target
- reg_value_data
- time
silence: not_evidence_of_absence
source: hb_registry_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, reg_target, reg_value_data, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_registry_activity WHERE (LOWER(reg_target) LIKE '%\bootverificationprogram%' OR LOWER(reg_target) LIKE '%\timeproviders%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY reg_target, reg_value_data HAVING host_count <= 3
```
## smb-auth-relay
<!-- SMB authentication relay attempts -->
Detect outbound SMB connections from web servers, indicating coerced authentication for credential relaying.
```sqlite target=network role=triage params=(scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: Outbound SMB (445) from a server that normally only serves HTTP. This is
highly suspicious of credential coercion.
reads:
- device_hostname
- src_endpoint_ip
- dst_endpoint_ip
- process_name
- time
silence: not_evidence_of_absence
source: hb_network_connection
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, src_endpoint_ip, dst_endpoint_ip, process_name, time FROM hb_network_connection WHERE dst_endpoint_port = 445 AND direction = 'outbound' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```
## final-triage-agent
<!-- Final post-exploitation agent -->
```agent target=hunter
cite: required
context:
- initial-access-agent
- persistence-mechanisms
- smb-auth-relay
max_iterations: 6
objective: Combine the evidence of initial access with the persistence and relay indicators
to confirm a full attack chain.
success_criteria: A confirmed breach verdict citing the progression from web exploit
to persistent access or relaying.
tools:
- endpoint
- network
- web
```
## route-verdict
<!-- Route verdict -->
if~: "the final-triage-agent verdict is malicious for any host" (confidence: high, judge=hunter)
then: → isolate-host
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: no-endpoint-telemetry)
else: → close-out
## isolate-host
<!-- Isolate host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the compromised host from the network and revoke any active credentials associated with the session.
```
→ analyst-review
## analyst-review
<!-- Analyst forensic review -->
```manual target=analyst
Review the agent's findings. Specifically, verify the registry modifications and the source of the outbound SMB connections. Determine if the shell execution on the web server was authorized maintenance or an actual breach.
```
→ end
## close-out
<!-- Close out -->
```manual target=analyst
Record the findings and update the vulnerability status for the identified hosts. If no breach was found, use the scoping results to prioritize patching the vulnerable assets.
```
→ end
Run it
Take this hunt into your environment.
Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.
Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.