{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "CVE-2026-76461 is actively exploited in the wild as a zero-day and allows unauthenticated root command execution on critical email infrastructure."
      },
      "name": "Cisco Secure Email Gateway SQLi Exploitation",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1190",
        "attack.t1566",
        "attack.t1059",
        "execution",
        "initial access"
      ],
      "related": [
        {
          "hunt": "email-gateway-persistence",
          "reason": "Exploitation may lead to the installation of persistence mechanisms inside the appliance software.",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A simple detection rule on 'COPY TO PROGRAM' in process command lines is easily evaded by shell obfuscation; this hunt combines version-based scoping, fleet prevalence, and parent-child process relationships to identify exploitation results.",
      "coverage": [
        {
          "stage": "vulnerability-identification",
          "steps": [
            "identify-vulnerable-appliances"
          ],
          "status": "covered"
        },
        {
          "stage": "exploit-delivery-crafted-email",
          "reason": "Exploit delivery occurs inside the SMTP protocol stream, which is not visible on standard process or network surfaces.",
          "status": "not_visible"
        },
        {
          "stage": "arbitrary-command-execution",
          "steps": [
            "rare-process-baseline",
            "detect-sqli-command-artifacts"
          ],
          "status": "covered"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Identification of Vulnerable Appliances",
            "slug": "vulnerability-identification",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "CVE-2026-76461",
              "Cisco AsyncOS 15.5",
              "Cisco AsyncOS 16.0",
              "Cisco AsyncOS 16.5"
            ]
          },
          {
            "name": "Unauthenticated Exploit via Crafted Email",
            "slug": "exploit-delivery-crafted-email",
            "tactic": "initial-access",
            "techniques": [
              "T1190",
              "T1566"
            ],
            "observables": [
              "specially crafted email",
              "SMTP traffic on port 25"
            ]
          },
          {
            "name": "Root-Level Command Execution",
            "slug": "arbitrary-command-execution",
            "tactic": "execution",
            "techniques": [
              "T1059"
            ],
            "observables": [
              "COPY.*TO PROGRAM",
              "root-level arbitrary commands",
              "grep -i \"COPY.*TO PROGRAM\" mail_logs"
            ]
          }
        ],
        "summary": "CVE-2026-76461 is a critical SQL injection vulnerability in Cisco Secure Email Gateway that allows unauthenticated, remote attackers to execute arbitrary commands with root privileges. Exploitation is achieved by sending a specially crafted email through the gateway, which triggers a malicious SQL statement such as 'COPY TO PROGRAM' during email processing. This vulnerability was exploited as a zero-day in September 2026 before patches were available."
      },
      "severity": "high",
      "rationale": "Scope to the Cisco Secure Email Gateway footprint using the software inventory and vulnerability findings; prioritize assets with active CVE findings.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An unauthenticated attacker has exploited CVE-2026-76461 by sending a crafted email to a Cisco Secure Email Gateway, resulting in root-level command execution from a database process.",
      "parameters": {
        "scope_hosts": {
          "from": {
            "ref": "default",
            "kind": "manual",
            "observed": "2026-09-15"
          },
          "type": "list[host]",
          "default": [],
          "description": "Hostnames identified as vulnerable in the first step; leave empty to hunt all hosts."
        },
        "lookback_days": {
          "from": {
            "ref": "default",
            "kind": "manual",
            "observed": "2026-09-15"
          },
          "type": "number",
          "default": "14",
          "description": "Number of days of history to examine."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild",
          "name": "Rapid7 \u2014 CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild"
        }
      ],
      "blind_spots": [
        {
          "id": "appliance-visibility-gap",
          "risk": "The hunt detects the process outcome, but the most definitive proof resides in logs not always ingested as hb_ events.",
          "stage": "arbitrary-command-execution",
          "question": "Does the appliance internal mail log contain the SQL statement?",
          "requires": "appliance native logs (mail_logs)"
        }
      ]
    },
    "name": "Cisco Secure Email Gateway SQLi Exploitation",
    "description": "This hunt identifies Cisco Secure Email Gateway appliances running vulnerable AsyncOS versions and monitors for behavioral indicators of SQL injection exploitation. The attack uses a PostgreSQL-specific command (COPY TO PROGRAM) to achieve root-level execution. Because this occurs inside the appliance's mail processing pipeline, the hunt focuses on identifying rare process execution patterns and parent-child anomalies on vulnerable hosts."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "coverage": [
          {
            "stage": "vulnerability-identification",
            "steps": [
              "identify-vulnerable-appliances"
            ],
            "status": "covered"
          },
          {
            "stage": "exploit-delivery-crafted-email",
            "reason": "Exploit delivery occurs inside the SMTP protocol stream, which is not visible on standard process or network surfaces.",
            "status": "not_visible"
          },
          {
            "stage": "arbitrary-command-execution",
            "steps": [
              "rare-process-baseline",
              "detect-sqli-command-artifacts"
            ],
            "status": "covered"
          }
        ],
        "rationale": "An unauthenticated attacker has exploited CVE-2026-76461 by sending a crafted email to a Cisco Secure Email Gateway, resulting in root-level command execution from a database process.",
        "blind_spots": [
          {
            "id": "appliance-visibility-gap",
            "risk": "The hunt detects the process outcome, but the most definitive proof resides in logs not always ingested as hb_ events.",
            "stage": "arbitrary-command-execution",
            "question": "Does the appliance internal mail log contain the SQL statement?",
            "requires": "appliance native logs (mail_logs)"
          }
        ],
        "scoping_notes": "Scope to the Cisco Secure Email Gateway footprint using the software inventory and vulnerability findings; prioritize assets with active CVE findings.",
        "beyond_detection": "A simple detection rule on 'COPY TO PROGRAM' in process command lines is easily evaded by shell obfuscation; this hunt combines version-based scoping, fleet prevalence, and parent-child process relationships to identify exploitation results."
      }
    },
    {
      "id": "identify-vulnerable-appliances",
      "type": "query",
      "label": "Identify Vulnerable Cisco Appliances",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_hostname, package_name, package_version FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%asyncos%' OR LOWER(package_name) LIKE '%ironport%') AND (package_version LIKE '15.5%' OR package_version LIKE '16.0%' OR package_version LIKE '16.5%') UNION SELECT resource_uid AS device_hostname, affected_package_name AS package_name, affected_package_version AS package_version FROM hb_vulnerability_finding WHERE cve_uid = 'CVE-2026-76461'",
        "surface": "hb_software_inventory",
        "description": "CVE-2026-76461 is actively exploited in the wild as a zero-day and allows unauthenticated root command execution on affected appliances; the hunt identifies vulnerable assets through software and vulnerability inventory.",
        "expected_signal": "A list of hostnames and versions. Rows from hb_vulnerability_finding prioritize assets already identified by scanners."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify Vulnerable Cisco Appliances",
        "reads": [
          "device_hostname",
          "package_name",
          "package_version"
        ],
        "source": "hb_software_inventory",
        "target": "endpoint",
        "content": "SELECT device_hostname, package_name, package_version FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%asyncos%' OR LOWER(package_name) LIKE '%ironport%') AND (package_version LIKE '15.5%' OR package_version LIKE '16.0%' OR package_version LIKE '16.5%') UNION SELECT resource_uid AS device_hostname, affected_package_name AS package_name, affected_package_version AS package_version FROM hb_vulnerability_finding WHERE cve_uid = 'CVE-2026-76461'",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hostnames and versions. Rows from hb_vulnerability_finding prioritize assets already identified by scanners.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "rare-process-baseline",
      "type": "query",
      "label": "Rare Processes on Vulnerable Appliances",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT process_name, process_cmd_line, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_name, process_cmd_line HAVING host_count <= 2 ORDER BY host_count ASC",
        "surface": "hb_process_activity",
        "description": "The hunt stacks process execution on identified Cisco hosts to find unique attacker-driven commands while excluding fleet-wide noise.",
        "expected_signal": "Rare command lines that appear on only one or two Cisco appliances; these often represent the second stage of exploitation."
      },
      "parents": [
        {
          "id": "identify-vulnerable-appliances"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare Processes on Vulnerable Appliances",
        "reads": [
          "process_name",
          "process_cmd_line",
          "device_hostname",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT process_name, process_cmd_line, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_name, process_cmd_line HAVING host_count <= 2 ORDER BY host_count ASC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Rare command lines that appear on only one or two Cisco appliances; these often represent the second stage of exploitation.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_name",
            "process_cmd_line"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "detect-sqli-command-artifacts",
      "type": "query",
      "label": "Detect SQLi Command Execution Artifacts",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, parent_process_name, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_cmd_line) LIKE '%copy%to%program%' OR LOWER(process_cmd_line) LIKE '%/tmp/%' OR LOWER(process_cmd_line) LIKE '%/dev/shm/%' OR LOWER(parent_process_name) LIKE '%postgres%' OR LOWER(parent_process_name) LIKE '%mail%') AND (LOWER(process_name) LIKE '%sh' OR LOWER(process_name) LIKE '%bash' OR LOWER(process_name) LIKE '%nc' OR LOWER(process_name) LIKE '%python%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "The query searches for PostgreSQL COPY TO PROGRAM exploitation artifacts and staging in world-writable directories.",
        "expected_signal": "Shells spawned by database or mail processes, or command lines containing SQL injection artifacts."
      },
      "parents": [
        {
          "id": "rare-process-baseline"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Detect SQLi Command Execution Artifacts",
        "reads": [
          "device_hostname",
          "process_name",
          "process_cmd_line",
          "parent_process_name",
          "user_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, parent_process_name, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_cmd_line) LIKE '%copy%to%program%' OR LOWER(process_cmd_line) LIKE '%/tmp/%' OR LOWER(process_cmd_line) LIKE '%/dev/shm/%' OR LOWER(parent_process_name) LIKE '%postgres%' OR LOWER(parent_process_name) LIKE '%mail%') AND (LOWER(process_name) LIKE '%sh' OR LOWER(process_name) LIKE '%bash' OR LOWER(process_name) LIKE '%nc' OR LOWER(process_name) LIKE '%python%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Shells spawned by database or mail processes, or command lines containing SQL injection artifacts.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "triage-exposure",
      "type": "analytic",
      "label": "Evaluate Exposure and Exploitation",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "identify-vulnerable-appliances",
          "rare-process-baseline",
          "detect-sqli-command-artifacts"
        ],
        "objective": "Determine if any host identified in the scoping query has exhibited process activity consistent with CVE-2026-76461 exploitation.",
        "description": "The agent correlates identified vulnerable versions with rare or anomalous process activity to find exploitation.",
        "max_iterations": 5,
        "expected_signal": "A per-host verdict citing evidence of compromise.",
        "success_criteria": "A list of hosts with a malicious, suspicious, or benign verdict citing specific rows."
      },
      "parents": [
        {
          "id": "detect-sqli-command-artifacts"
        }
      ]
    },
    {
      "id": "route-by-verdict",
      "type": "checkpoint",
      "label": "Route Based on Verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage verdict is malicious or suspicious for at least one host",
        "condition": "the triage verdict is malicious or suspicious for at least one host",
        "blind_spot": "appliance-visibility-gap",
        "confidence": "high",
        "description": "Route to remediation if exploitation is found, otherwise close.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-exposure"
        }
      ]
    },
    {
      "id": "remediation-review",
      "type": "task",
      "label": "Remediation and Incident Review",
      "config": {
        "assignee": "analyst",
        "description": "Perform emergency patching and investigate identified hosts for deeper compromise.",
        "instructions": "1. Prioritize emergency upgrades for all hosts identified in the scoping query.\n2. For hosts with suspicious activity, run grep -i 'COPY.*TO PROGRAM' mail_logs on the appliance.\n3. Inspect any shell activity spawned from postgres processes for persistence."
      },
      "parents": [
        {
          "id": "route-by-verdict",
          "branch": "on_supports"
        },
        {
          "id": "route-by-verdict",
          "branch": "default"
        },
        {
          "id": "route-by-verdict",
          "branch": "on_unavailable"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close Out",
      "config": {
        "assignee": "analyst",
        "description": "Record findings and ensure vulnerable appliances are scheduled for routine patching if no exploitation was found.",
        "instructions": "Confirm no anomalous activity was detected and track any remaining vulnerable appliances for the next maintenance window."
      },
      "parents": [
        {
          "id": "route-by-verdict",
          "branch": "on_refutes"
        }
      ]
    }
  ]
}