{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Active exploitation of a CVSS 9.8 vulnerability in SD-WAN management infrastructure constitutes a critical risk to network integrity and traffic privacy."
      },
      "name": "Cisco SD-WAN Manager API Authentication Bypass",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1190",
        "attack.t1078.001",
        "initial access"
      ],
      "related": [
        {
          "hunt": "cisco-sd-wan-vdaemon-bypass",
          "reason": "CVE-2026-20127 and CVE-2026-20182 affect the vdaemon peering service rather than the Manager API authentication path.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        },
        "identity": {
          "name": "Identity / sign-in telemetry",
          "category": "identity",
          "telemetry": [
            "identity"
          ]
        }
      },
      "analysis": "A simple detection rule may alert on '%6a_security_check', but this hunt uses a gated flow to pivot between URL patterns, software inventory context, and administrative login anomalies to differentiate true exploitation from scanner noise.",
      "coverage": [
        {
          "stage": "exposure-discovery",
          "steps": [
            "scoping-vulnerable-inventory"
          ],
          "status": "covered"
        },
        {
          "stage": "api-authentication-bypass",
          "steps": [
            "lead-encoded-auth-requests",
            "prevalence-of-encoded-uris"
          ],
          "status": "covered"
        },
        {
          "stage": "administrative-session-access",
          "steps": [
            "reserved-account-activity"
          ],
          "status": "covered"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Internet-Exposed Vulnerable SD-WAN Manager",
            "slug": "exposure-discovery",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "Cisco Catalyst SD-WAN Manager",
              "Vulnerable software versions 20.9.x, 20.12.x, 20.15.x, 20.18.x",
              "Internet-exposed management ports"
            ]
          },
          {
            "name": "URL-Encoded API Bypass",
            "slug": "api-authentication-bypass",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "HTTP POST /%6a_security_check",
              "URL encoded j_security_check path",
              "Encoded characters in API authentication URI"
            ]
          },
          {
            "name": "Admin Access via Reserved Accounts",
            "slug": "administrative-session-access",
            "tactic": "initial-access",
            "techniques": [
              "T1078.001"
            ],
            "observables": [
              "Usernames starting with viptela-reserved-",
              "Execution of request admin-tech command",
              "Privileged administrative access to vManage API"
            ]
          }
        ],
        "summary": "Remote unauthenticated attackers exploit CVE-2026-76504 in internet-facing Cisco Catalyst SD-WAN Manager instances by using URL-encoded paths to bypass API authentication rules. Successful exploitation grants administrative privileges, typically identified by authentication logs using reserved system usernames and the potential execution of diagnostic commands."
      },
      "severity": "high",
      "rationale": "Focus on internet-facing Cisco SD-WAN Manager instances. Use the results of the software inventory step to narrow subsequent triage to confirmed vulnerable versions.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An attacker is bypassing authentication on an internet-exposed Cisco Catalyst SD-WAN Manager by using URL-encoded characters in the j_security_check path, gaining administrative access through reserved system accounts.",
      "parameters": {
        "scope_hosts": {
          "from": {
            "ref": "scoping-input",
            "kind": "manual",
            "observed": "2026-09-30"
          },
          "type": "list[host]",
          "default": [],
          "description": "Optional list of hostnames to focus the impact triage; leave empty to check the whole estate."
        },
        "lookback_days": {
          "from": {
            "ref": "hunt-standard",
            "kind": "manual",
            "observed": "2026-09-30"
          },
          "type": "number",
          "default": "14",
          "description": "Days of activity to examine."
        },
        "reserved_user_prefix": {
          "from": {
            "ref": "rapid7-cve-2026-76504",
            "kind": "article",
            "observed": "2026-09-30"
          },
          "type": "string",
          "default": "viptela-reserved-",
          "description": "User prefix used by system processes that is hijacked during exploitation."
        },
        "auth_endpoint_pattern": {
          "from": {
            "ref": "rapid7-cve-2026-76504",
            "kind": "article",
            "observed": "2026-09-30"
          },
          "type": "string",
          "default": "security_check",
          "description": "Path fragment common to the SD-WAN authentication endpoint."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.rapid7.com/blog/post/etr-critical-cisco-catalyst-sd-wan-manager-api-authentication-bypass-exploited-in-the-wild-cve-2026-76504",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.rapid7.com/blog/post/etr-critical-cisco-catalyst-sd-wan-manager-api-authentication-bypass-exploited-in-the-wild-cve-2026-76504",
          "name": "Rapid7 \u2014 Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)"
        }
      ],
      "blind_spots": [
        {
          "id": "no-http-visibility",
          "risk": "Attackers can use various hex-encoded representations for characters; without full URI normalization before logging, the hunt might miss obfuscated requests.",
          "stage": "api-authentication-bypass",
          "question": "whether an attacker used multiple layers of encoding or a character not covered by simple LIKE patterns",
          "requires": "hb_http_activity with URI decoding"
        },
        {
          "id": "appliance-visibility-gap",
          "risk": "Most SD-WAN appliances do not support third-party agents; visibility is limited to what the management API logs and the network fabric record.",
          "stage": "administrative-session-access",
          "question": "whether the 'request admin-tech' command was executed locally",
          "requires": "Endpoint agent on the SD-WAN appliance OS"
        }
      ]
    },
    "name": "Cisco SD-WAN Manager API Authentication Bypass",
    "description": "This hunt follows a gated flow to identify exploitation of CVE-2026-76504. The hunt first searches for anomalous URL-encoded HTTP POST requests targeting the SD-WAN authentication endpoint. If suspicious activity is confirmed, the hunt fans out to verify host vulnerability, check the prevalence of the encoded URI across the fleet, and detect logins from reserved viptela-reserved- accounts. An agent then synthesizes this evidence to identify confirmed compromises."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "coverage": [
          {
            "stage": "exposure-discovery",
            "steps": [
              "scoping-vulnerable-inventory"
            ],
            "status": "covered"
          },
          {
            "stage": "api-authentication-bypass",
            "steps": [
              "lead-encoded-auth-requests",
              "prevalence-of-encoded-uris"
            ],
            "status": "covered"
          },
          {
            "stage": "administrative-session-access",
            "steps": [
              "reserved-account-activity"
            ],
            "status": "covered"
          }
        ],
        "rationale": "An attacker is bypassing authentication on an internet-exposed Cisco Catalyst SD-WAN Manager by using URL-encoded characters in the j_security_check path, gaining administrative access through reserved system accounts.",
        "blind_spots": [
          {
            "id": "no-http-visibility",
            "risk": "Attackers can use various hex-encoded representations for characters; without full URI normalization before logging, the hunt might miss obfuscated requests.",
            "stage": "api-authentication-bypass",
            "question": "whether an attacker used multiple layers of encoding or a character not covered by simple LIKE patterns",
            "requires": "hb_http_activity with URI decoding"
          },
          {
            "id": "appliance-visibility-gap",
            "risk": "Most SD-WAN appliances do not support third-party agents; visibility is limited to what the management API logs and the network fabric record.",
            "stage": "administrative-session-access",
            "question": "whether the 'request admin-tech' command was executed locally",
            "requires": "Endpoint agent on the SD-WAN appliance OS"
          }
        ],
        "scoping_notes": "Focus on internet-facing Cisco SD-WAN Manager instances. Use the results of the software inventory step to narrow subsequent triage to confirmed vulnerable versions.",
        "beyond_detection": "A simple detection rule may alert on '%6a_security_check', but this hunt uses a gated flow to pivot between URL patterns, software inventory context, and administrative login anomalies to differentiate true exploitation from scanner noise."
      }
    },
    {
      "id": "lead-encoded-auth-requests",
      "type": "query",
      "label": "Encoded API Authentication Requests",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "web",
        "content": "SELECT device_hostname, src_endpoint_ip, http_method, url_path, user_agent, time FROM hb_http_activity WHERE http_method = 'POST' AND LOWER(url_path) LIKE '%#%%' ESCAPE '#' AND LOWER(url_path) LIKE '%' || LOWER('{{auth_endpoint_pattern}}') || '%' AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_http_activity",
        "description": "Identify potential authentication bypass attempts using URL encoding in the security check URI.",
        "expected_signal": "A request with an encoded character in the path (e.g., %6a for j). Silence proves no such requests were logged during the window."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Encoded API Authentication Requests",
        "reads": [
          "device_hostname",
          "http_method",
          "src_endpoint_ip",
          "time",
          "url_path",
          "user_agent"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT device_hostname, src_endpoint_ip, http_method, url_path, user_agent, time FROM hb_http_activity WHERE http_method = 'POST' AND LOWER(url_path) LIKE '%#%%' ESCAPE '#' AND LOWER(url_path) LIKE '%' || LOWER('{{auth_endpoint_pattern}}') || '%' AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "evidence_of_absence",
        "expected": "A request with an encoded character in the path (e.g., %6a for j). Silence proves no such requests were logged during the window.",
        "verified": "dry-run",
        "verified_at": "2026-10-01"
      }
    },
    {
      "id": "evaluate-lead",
      "type": "analytic",
      "label": "Evaluate Bypass Lead",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity",
          "web"
        ],
        "context": [
          "lead-encoded-auth-requests"
        ],
        "objective": "Determine if the URL encoded path segments represent attempts to bypass the API authentication rules.",
        "description": "Verify if the expensive follow-on queries are warranted based on the lead verdict.",
        "max_iterations": 3,
        "expected_signal": "A verdict per host on the maliciousness of the URI pattern.",
        "success_criteria": "A per-host verdict citing the specific HTTP request rows."
      },
      "parents": [
        {
          "id": "lead-encoded-auth-requests"
        }
      ]
    },
    {
      "id": "gate-on-bypass",
      "type": "checkpoint",
      "label": "Gate: Suspected Bypass Found?",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the evaluate-lead verdict is malicious or suspicious for at least one host",
        "condition": "the evaluate-lead verdict is malicious or suspicious for at least one host",
        "blind_spot": "no-http-visibility",
        "confidence": "high",
        "description": "Verify if the expensive follow-on queries are warranted based on the lead verdict.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "evaluate-lead"
        }
      ]
    },
    {
      "id": "scoping-vulnerable-inventory",
      "type": "query",
      "label": "Vulnerable Software Inventory",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_hostname, package_name, package_version, vendor_name FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%sd-wan manager%' OR LOWER(package_name) LIKE '%vmanage%') AND (package_version LIKE '20.9%' OR package_version LIKE '20.12%' OR package_version LIKE '20.15%' OR package_version LIKE '20.18%' OR package_version LIKE '26.1%')",
        "surface": "hb_software_inventory",
        "description": "Confirm the targeted hosts are running vulnerable Cisco Catalyst SD-WAN Manager versions.",
        "expected_signal": "Identification of vulnerable appliances. Absence means either the software is patched or not present."
      },
      "parents": [
        {
          "id": "gate-on-bypass",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Vulnerable Software Inventory",
        "reads": [
          "device_hostname",
          "package_name",
          "package_version",
          "vendor_name"
        ],
        "source": "hb_software_inventory",
        "target": "endpoint",
        "content": "SELECT device_hostname, package_name, package_version, vendor_name FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%sd-wan manager%' OR LOWER(package_name) LIKE '%vmanage%') AND (package_version LIKE '20.9%' OR package_version LIKE '20.12%' OR package_version LIKE '20.15%' OR package_version LIKE '20.18%' OR package_version LIKE '26.1%')",
        "silence": "not_evidence_of_absence",
        "expected": "Identification of vulnerable appliances. Absence means either the software is patched or not present.",
        "verified": "dry-run",
        "verified_at": "2026-10-01"
      }
    },
    {
      "id": "prevalence-of-encoded-uris",
      "type": "query",
      "label": "Prevalence of Encoded URI Paths",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "web",
        "content": "SELECT url_path, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_http_activity WHERE url_path LIKE '%#%%' ESCAPE '#' AND url_path LIKE '%' || LOWER('{{auth_endpoint_pattern}}') || '%' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY url_path",
        "surface": "hb_http_activity",
        "description": "Stack-count the encoded URI paths across the fleet to highlight outliers.",
        "expected_signal": "Encoded paths seen on only a few hosts indicate targeted exploitation attempts."
      },
      "parents": [
        {
          "id": "gate-on-bypass",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Prevalence of Encoded URI Paths",
        "reads": [
          "device_hostname",
          "time",
          "url_path"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT url_path, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_http_activity WHERE url_path LIKE '%#%%' ESCAPE '#' AND url_path LIKE '%' || LOWER('{{auth_endpoint_pattern}}') || '%' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY url_path",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Encoded paths seen on only a few hosts indicate targeted exploitation attempts.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "url_path"
          ],
          "rare_below": 2
        },
        "verified_at": "2026-10-01"
      }
    },
    {
      "id": "reserved-account-activity",
      "type": "query",
      "label": "Reserved Account Sign-ins",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "identity",
        "content": "SELECT device_hostname, actor_user_name, src_endpoint_ip, activity_name, status_id, time FROM hb_auth_signin WHERE (LOWER(actor_user_name) LIKE LOWER('{{reserved_user_prefix}}') || '%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_auth_signin",
        "description": "Search for sign-in activity using reserved accounts on hosts where a bypass attempt was detected.",
        "expected_signal": "A successful sign-in by a reserved user. Silence does not rule out exploitation if the attacker used a different account."
      },
      "parents": [
        {
          "id": "gate-on-bypass",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Reserved Account Sign-ins",
        "reads": [
          "activity_name",
          "actor_user_name",
          "device_hostname",
          "src_endpoint_ip",
          "status_id",
          "time"
        ],
        "source": "hb_auth_signin",
        "target": "identity",
        "content": "SELECT device_hostname, actor_user_name, src_endpoint_ip, activity_name, status_id, time FROM hb_auth_signin WHERE (LOWER(actor_user_name) LIKE LOWER('{{reserved_user_prefix}}') || '%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "A successful sign-in by a reserved user. Silence does not rule out exploitation if the attacker used a different account.",
        "verified": "dry-run",
        "verified_at": "2026-10-01"
      }
    },
    {
      "id": "triage-compromise",
      "type": "analytic",
      "label": "Triage Compromise Verdict",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity",
          "web"
        ],
        "context": [
          "evaluate-lead",
          "scoping-vulnerable-inventory",
          "prevalence-of-encoded-uris",
          "reserved-account-activity"
        ],
        "objective": "Confirm active exploitation by correlating encoded URI bypasses with vulnerable software versions and subsequent reserved account logons.",
        "description": "Determine if the bypass attempts resulted in a confirmed administrative compromise.",
        "max_iterations": 5,
        "expected_signal": "A high-confidence verdict of compromise for at least one SD-WAN Manager.",
        "success_criteria": "A verdict of malicious for any host showing both the bypass lead and subsequent reserved account usage."
      },
      "parents": [
        {
          "id": "scoping-vulnerable-inventory",
          "kind": "merge"
        },
        {
          "id": "prevalence-of-encoded-uris",
          "kind": "merge"
        },
        {
          "id": "reserved-account-activity",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-final-verdict",
      "type": "checkpoint",
      "label": "Route Final Verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage-compromise verdict is malicious for at least one host",
        "condition": "the triage-compromise verdict is malicious for at least one host",
        "blind_spot": "appliance-visibility-gap",
        "confidence": "high",
        "description": "Direct the workflow based on the confirmation of compromise.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-compromise"
        }
      ]
    },
    {
      "id": "isolate-compromised-host",
      "type": "action",
      "label": "Isolate Compromised Host",
      "config": {
        "target": "endpoint",
        "description": "Immediately restrict network access to the compromised SD-WAN Manager to prevent further malicious activity.",
        "instructions": "Isolate the identified SD-WAN Manager host from the network and revoke any active administrative sessions associated with the attacker's source IP.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-final-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "manual-forensics-review",
      "type": "task",
      "label": "Manual Forensics and Log Review",
      "config": {
        "assignee": "analyst",
        "description": "Perform a deep-dive investigation into the appliance logs as recommended by Cisco.",
        "instructions": "Log into the affected SD-WAN Manager and review /var/log/nms/containers/service-proxy/serviceproxy-access.log for encoded characters in the j_security_check path. Check /var/log/nms/vmanage-server.log for viptela-reserved- accounts and use the 'request admin-tech' command to generate diagnostic files."
      },
      "parents": [
        {
          "id": "gate-on-bypass",
          "branch": "default"
        },
        {
          "id": "gate-on-bypass",
          "branch": "on_unavailable"
        },
        {
          "id": "route-final-verdict",
          "branch": "default"
        },
        {
          "id": "route-final-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "route-final-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "isolate-compromised-host"
        }
      ]
    },
    {
      "id": "close-out-report",
      "type": "task",
      "label": "Hunt Close-out and Patching",
      "config": {
        "assignee": "analyst",
        "description": "Document the findings and ensure emergency patching is scheduled for vulnerable instances.",
        "instructions": "Summarize the hosts examined and any compromises found. Ensure all identified vulnerable SD-WAN Managers are scheduled for upgrade to a fixed release (e.g., 20.15.6.1 or 20.18.4.1)."
      },
      "parents": [
        {
          "id": "gate-on-bypass",
          "branch": "on_refutes"
        },
        {
          "id": "manual-forensics-review"
        }
      ]
    }
  ]
}