{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "NetScaler appliances are high-value perimeter targets; an unauthenticated bypass (CVE-2026-19490) allows direct internal access, making a negative result a critical security requirement."
      },
      "name": "Citrix NetScaler Authentication Bypass and Exposure",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1190",
        "attack.t1133"
      ],
      "related": [
        {
          "hunt": "citrix-netscaler-shell-exploitation",
          "reason": "This hunt focuses on the authentication bypass; post-exploitation shell activity on the underlying Linux OS requires different telemetry surfaces.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        },
        "identity": {
          "name": "Identity / sign-in telemetry",
          "category": "identity",
          "telemetry": [
            "identity"
          ]
        }
      },
      "analysis": "A standard signature-based detection for this CVE might be evaded by minor adjustments in the exploit payload; this hunt instead looks for the behavioral aftermath\u2014successful, rare authentications and anomalous web patterns on vulnerable perimeter systems.",
      "coverage": [
        {
          "stage": "vulnerable-service-exposure",
          "steps": [
            "identify-vulnerable-netscaler"
          ],
          "status": "covered"
        },
        {
          "stage": "authentication-bypass-exploitation",
          "steps": [
            "suspicious-web-access-patterns"
          ],
          "status": "covered"
        },
        {
          "stage": "external-remote-access",
          "steps": [
            "rare-auth-source-ips"
          ],
          "status": "covered"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Exposed Vulnerable NetScaler Service",
            "slug": "vulnerable-service-exposure",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "NetScaler ADC versions prior to 14.1-73.32",
              "NetScaler Gateway versions prior to 13.1-63.21",
              "NetScaler ADC FIPS",
              "NetScaler ADC NDcPP"
            ]
          },
          {
            "name": "NetScaler Authentication Bypass",
            "slug": "authentication-bypass-exploitation",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "Unauthenticated remote network access",
              "SAML action configuration (add authentication samlAction)",
              "VPN vserver configuration (add vpn vserver)",
              "Auth vserver configuration (add authentication vserver)"
            ]
          },
          {
            "name": "Unauthorized External Remote Access",
            "slug": "external-remote-access",
            "tactic": "initial-access",
            "techniques": [
              "T1133"
            ],
            "observables": [
              "Successful gateway login without valid credential record",
              "Bypassed authentication session via SAML"
            ]
          }
        ],
        "summary": "Attackers can bypass authentication on Citrix NetScaler ADC and NetScaler Gateway appliances via CVE-2026-19490, a critical vulnerability affecting systems configured with SAML or VPN virtual servers. This allows unauthenticated remote access to the perimeter device, providing a foothold for initial access into the corporate network."
      },
      "severity": "high",
      "rationale": "Focus on internet-exposed appliances first by cross-referencing vulnerability scans with external asset inventory. Use the hostnames from the vulnerability findings to populate the scope_hosts parameter for the behavioral queries.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An unauthenticated attacker has exploited CVE-2026-19490 on an internet-facing NetScaler appliance to bypass authentication and gain unauthorized remote access.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "List of hostnames or resource IDs for the identified vulnerable NetScaler appliances."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.rapid7.com/blog/post/etr-cve-2026-19490-critical-vulnerability-affecting-citrix-netscaler-adc-and-netscaler-gateway",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.rapid7.com/blog/post/etr-cve-2026-19490-critical-vulnerability-affecting-citrix-netscaler-adc-and-netscaler-gateway",
          "name": "Rapid7 \u2014 CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway"
        }
      ],
      "blind_spots": [
        {
          "id": "missing-appliance-telemetry",
          "risk": "If logs are not centralized, the prevalence and behavioral queries will return zero results even if exploitation is occurring.",
          "stage": "authentication-bypass-exploitation",
          "question": "Are the appliances configured to forward HTTP and authentication logs?",
          "requires": "Syslog ingestion from NetScaler to hb_http_activity and hb_auth_signin"
        },
        {
          "id": "ephemeral-auth-sessions",
          "risk": "If the bypass occurs purely at the protocol level (e.g., SAML assertion injection) and the appliance does not log it as a standard 'logon', the auth prevalence query will miss it.",
          "stage": "external-remote-access",
          "question": "Can the bypass establish a session without a recorded logon event?",
          "requires": "hb_auth_signin session tracking"
        }
      ]
    },
    "name": "Citrix NetScaler Authentication Bypass and Exposure",
    "description": "This hunt identifies Citrix NetScaler ADC and Gateway appliances vulnerable to CVE-2026-19490 and evaluates signs of exploitation. It first scopes the estate using vulnerability findings for the specific CVE. It then analyzes authentication patterns and HTTP traffic targeting sensitive SAML and VPN endpoints on those systems to identify rare source IPs and anomalous access that indicate a successful authentication bypass."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "coverage": [
          {
            "stage": "vulnerable-service-exposure",
            "steps": [
              "identify-vulnerable-netscaler"
            ],
            "status": "covered"
          },
          {
            "stage": "authentication-bypass-exploitation",
            "steps": [
              "suspicious-web-access-patterns"
            ],
            "status": "covered"
          },
          {
            "stage": "external-remote-access",
            "steps": [
              "rare-auth-source-ips"
            ],
            "status": "covered"
          }
        ],
        "rationale": "An unauthenticated attacker has exploited CVE-2026-19490 on an internet-facing NetScaler appliance to bypass authentication and gain unauthorized remote access.",
        "blind_spots": [
          {
            "id": "missing-appliance-telemetry",
            "risk": "If logs are not centralized, the prevalence and behavioral queries will return zero results even if exploitation is occurring.",
            "stage": "authentication-bypass-exploitation",
            "question": "Are the appliances configured to forward HTTP and authentication logs?",
            "requires": "Syslog ingestion from NetScaler to hb_http_activity and hb_auth_signin"
          },
          {
            "id": "ephemeral-auth-sessions",
            "risk": "If the bypass occurs purely at the protocol level (e.g., SAML assertion injection) and the appliance does not log it as a standard 'logon', the auth prevalence query will miss it.",
            "stage": "external-remote-access",
            "question": "Can the bypass establish a session without a recorded logon event?",
            "requires": "hb_auth_signin session tracking"
          }
        ],
        "scoping_notes": "Focus on internet-exposed appliances first by cross-referencing vulnerability scans with external asset inventory. Use the hostnames from the vulnerability findings to populate the scope_hosts parameter for the behavioral queries.",
        "beyond_detection": "A standard signature-based detection for this CVE might be evaded by minor adjustments in the exploit payload; this hunt instead looks for the behavioral aftermath\u2014successful, rare authentications and anomalous web patterns on vulnerable perimeter systems."
      }
    },
    {
      "id": "identify-vulnerable-netscaler",
      "type": "query",
      "label": "Identify vulnerable NetScaler appliances",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_uid, resource_uid, severity, collected_at FROM hb_vulnerability_finding WHERE cve_uid = 'CVE-2026-19490' AND status = 'unresolved'",
        "surface": "hb_vulnerability_finding",
        "description": "Find systems with active, unresolved findings for CVE-2026-19490.",
        "expected_signal": "Rows identify specific vulnerable appliances. No rows means no confirmed vulnerabilities are present in the vulnerability management data."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify vulnerable NetScaler appliances",
        "reads": [
          "device_uid",
          "resource_uid",
          "severity",
          "collected_at"
        ],
        "source": "hb_vulnerability_finding",
        "target": "endpoint",
        "content": "SELECT device_uid, resource_uid, severity, collected_at FROM hb_vulnerability_finding WHERE cve_uid = 'CVE-2026-19490' AND status = 'unresolved'",
        "silence": "not_evidence_of_absence",
        "expected": "Rows identify specific vulnerable appliances. No rows means no confirmed vulnerabilities are present in the vulnerability management data.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "rare-auth-source-ips",
      "type": "query",
      "label": "Prevalence of successful authentication by source IP",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "identity",
        "content": "SELECT src_endpoint_ip, COUNT(DISTINCT device_hostname) AS host_count, COUNT(*) AS login_events, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_auth_signin WHERE (LOWER(metadata_product) LIKE '%citrix%' OR LOWER(provider) LIKE '%citrix%') AND status_id = 1 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY src_endpoint_ip HAVING host_count <= 2 ORDER BY host_count ASC, login_events DESC",
        "surface": "hb_auth_signin",
        "description": "Identify rare external IP addresses successfully authenticating to NetScaler services, which may indicate bypassed authentication.",
        "expected_signal": "Source IPs that have only successfully logged into one or two appliances stand out from regular corporate VPN users."
      },
      "parents": [
        {
          "id": "identify-vulnerable-netscaler"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Prevalence of successful authentication by source IP",
        "reads": [
          "src_endpoint_ip",
          "device_hostname",
          "time",
          "status_id",
          "metadata_product",
          "provider"
        ],
        "source": "hb_auth_signin",
        "target": "identity",
        "content": "SELECT src_endpoint_ip, COUNT(DISTINCT device_hostname) AS host_count, COUNT(*) AS login_events, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_auth_signin WHERE (LOWER(metadata_product) LIKE '%citrix%' OR LOWER(provider) LIKE '%citrix%') AND status_id = 1 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY src_endpoint_ip HAVING host_count <= 2 ORDER BY host_count ASC, login_events DESC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Source IPs that have only successfully logged into one or two appliances stand out from regular corporate VPN users.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "src_endpoint_ip"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "suspicious-web-access-patterns",
      "type": "query",
      "label": "Anomalous web access to SAML and VPN endpoints",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "web",
        "content": "SELECT device_hostname, url_path, url_query, src_endpoint_ip, user_agent, status_code, time FROM hb_http_activity WHERE (LOWER(url_path) LIKE '%/logon/%' OR LOWER(url_path) LIKE '%/saml/%' OR LOWER(url_path) LIKE '%/vpn/%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') ORDER BY time DESC",
        "surface": "hb_http_activity",
        "description": "Identify unusual HTTP request patterns targeting sensitive NetScaler authentication and gateway paths.",
        "expected_signal": "Access to SAML or VPN endpoints from IPs identified as rare in the prevalence step, or requests that return successful status codes without typical precursor sessions."
      },
      "parents": [
        {
          "id": "rare-auth-source-ips"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Anomalous web access to SAML and VPN endpoints",
        "reads": [
          "device_hostname",
          "url_path",
          "url_query",
          "src_endpoint_ip",
          "user_agent",
          "status_code",
          "time"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT device_hostname, url_path, url_query, src_endpoint_ip, user_agent, status_code, time FROM hb_http_activity WHERE (LOWER(url_path) LIKE '%/logon/%' OR LOWER(url_path) LIKE '%/saml/%' OR LOWER(url_path) LIKE '%/vpn/%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') ORDER BY time DESC",
        "silence": "not_evidence_of_absence",
        "expected": "Access to SAML or VPN endpoints from IPs identified as rare in the prevalence step, or requests that return successful status codes without typical precursor sessions.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "agent-triage",
      "type": "analytic",
      "label": "Examine exposure and traffic for exploitation signs",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity",
          "web"
        ],
        "context": [
          "identify-vulnerable-netscaler",
          "rare-auth-source-ips",
          "suspicious-web-access-patterns"
        ],
        "objective": "Determine if CVE-2026-19490 has been exploited by evaluating anomalous access to vulnerable NetScaler appliances.",
        "description": "Correlate vulnerability presence with rare authentication sources and HTTP traffic to confirm exploitation.",
        "max_iterations": 5,
        "expected_signal": "A per-host verdict citing specific rows that align a rare source IP with sensitive endpoint access on a vulnerable appliance.",
        "success_criteria": "A clear verdict of malicious, suspicious, or benign for each host in scope."
      },
      "parents": [
        {
          "id": "suspicious-web-access-patterns"
        }
      ]
    },
    {
      "id": "exploitation-decision",
      "type": "checkpoint",
      "label": "Route based on exploitation verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the agent-triage verdict is malicious or suspicious for at least one host",
        "condition": "the agent-triage verdict is malicious or suspicious for at least one host",
        "blind_spot": "missing-appliance-telemetry",
        "confidence": "high",
        "description": "Direct the workflow based on whether evidence of an authentication bypass was found.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "agent-triage"
        }
      ]
    },
    {
      "id": "remediation-task",
      "type": "task",
      "label": "Remediation and Incident Response Review",
      "config": {
        "assignee": "analyst",
        "description": "Analyze confirmed compromises and ensure all vulnerable appliances are patched.",
        "instructions": "1. Confirm that all NetScaler appliances identified in the scoping step are updated to at least the fixed versions (14.1-73.32 or 13.1-63.21). 2. For hosts with malicious activity, verify if SAML configurations were tampered with. 3. Review internal access logs from the compromised appliance IPs to determine lateral movement."
      },
      "parents": [
        {
          "id": "exploitation-decision",
          "branch": "on_supports"
        },
        {
          "id": "exploitation-decision",
          "branch": "default"
        },
        {
          "id": "exploitation-decision",
          "branch": "on_unavailable"
        }
      ]
    },
    {
      "id": "close-out-task",
      "type": "task",
      "label": "Close out hunt",
      "config": {
        "assignee": "analyst",
        "description": "Record findings and update the exposure profile.",
        "instructions": "Document the resolution of the vulnerability findings. Ensure any suspicious source IPs identified are added to watchlists for future monitoring."
      },
      "parents": [
        {
          "id": "exploitation-decision",
          "branch": "on_refutes"
        },
        {
          "id": "remediation-task"
        }
      ]
    }
  ]
}