← All hunts medium TLP:CLEAR

Edge Exploitation and Cross-Campus Ransomware Impact

An adversary exploits a vulnerable internet-facing application to establish a foothold, moves laterally across campus network boundaries using compromised credentials, and deploys ransomware to sensitive research or student data.

Based on research by Rapid7 2026-10-01 12 steps · 5 queries T1021 T1078 T1190 T1486

Brief

Why fragmented networks hide threats 0AThe

Rapid7 article "Higher education is under siege, and fragmented security is making it harder to respond" (https://www.rapid7.com/blog/post/it-higher-education-under-siege-fragmented-security) describes a significant challenge for university SOCs. Decentralized IT departments often manage their own subnets and security stacks, creating visibility silos. This fragmentation allows an adversary to exploit a vulnerability in one department and move laterally across the campus network without triggering centralized alerts. 0A

How the hunt flows

0AThe first phase scopes the environment. The query identifies hosts running common edge software, such as Apache, Nginx, or VPN gateways. This provides the surface for potential exploitation. 0ANext, the hunt analyzes access patterns in parallel. One path stacks HTTP activity to find rare error paths that might indicate an exploit attempt. The other path identifies failed logon bursts across multiple hosts, which often signals a credential-based intrusion. 0AAn analyst then weighs these leads. By correlating web errors with authentication failures from the same source IP, the investigator determines if a suspect has breached the perimeter. 0AIf suspicious activity exists, the hunt moves to find the impact. It searches for administrative network traffic originating from the perimeter hosts, such as SSH or RDP. Simultaneously, it looks for high-volume file modifications involving ransomware extensions like crypt or locked. 0A

What the hunt cannot see

0ASeveral blind spots exist. If a campus does not have agents enrolled, the hunt cannot see activity in those legacy zones. The hunt also misses exploit payloads sent within encrypted HTTPS bodies, as it focuses on URI paths. Finally, if lateral movement occurs entirely within a single department's VLAN, network-based pivots may remain hidden. 0A

Steps

  1. Identify exposed web services

    Query · scoping

    Identify hosts running web-facing software that frequently serves as an entry point for university intrusions.

    reads hb_software_inventorysql
    SELECT device_hostname, package_name, package_version FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%apache%' OR LOWER(package_name) LIKE '%nginx%' OR LOWER(package_name) LIKE '%exchange%' OR LOWER(package_name) LIKE '%vpn%')

    What a hit looks like. A list of hosts running common perimeter software. Silence indicates no such software is tracked in the inventory.

  2. Unusual HTTP probing

    Query · triage

    Find unusual HTTP requests to the identified perimeter hosts that may indicate exploitation of legacy systems or zero-day flaws.

    reads hb_http_activitysql
    SELECT device_hostname, url_path, status_code, src_endpoint_ip, COUNT(*) as request_count FROM hb_http_activity WHERE (status_code >= 400) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, url_path, status_code, src_endpoint_ip HAVING request_count < 20

    What a hit looks like. Rare HTTP error paths from a single source IP. Silence indicates no uncommon error activity on the perimeter.

  3. Failed logon burst stacking

    Query · baseline

    Stack-count authentication failures by user and source IP to identify brute-force or credential-stuffing sequences that may precede campus-wide access.

    reads hb_auth_signinsql
    SELECT actor_user_name, src_endpoint_ip, COUNT(DISTINCT device_hostname) as host_count, COUNT(*) as fail_count, MIN(time) as first_seen FROM hb_auth_signin WHERE status_id = 2 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, src_endpoint_ip HAVING host_count <= 3 AND fail_count > 10

    What a hit looks like. A single IP or user account failing authentication repeatedly across multiple hosts or in high volume.

  4. Weigh initial access evidence

    Agent triage

    Evaluate the HTTP probes and authentication failures together to determine if an intrusion has likely begun.

  5. Administrative lateral traffic

    Query · enrichment

    Identify network connections using administrative protocols originating from perimeter hosts, signifying lateral movement toward sensitive zones.

    reads hb_network_connectionsql
    SELECT device_hostname, dst_endpoint_ip, dst_endpoint_port, process_name, COUNT(*) as conn_count, MIN(time) as first_seen FROM hb_network_connection WHERE direction = 'outbound' AND dst_endpoint_port IN (22, 445, 3389, 5985) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, dst_endpoint_ip, dst_endpoint_port, process_name HAVING conn_count < 10

    What a hit looks like. Rare administrative connections from web servers or VPN gateways to internal endpoints. Silence means no uncommon admin traffic was detected from the perimeter.

  6. High-volume file modifications

    Query · detection candidate

    Identify processes modifying a massive number of files with ransomware-associated extensions across the fleet.

    reads hb_file_activitysql
    SELECT device_hostname, process_name, COUNT(DISTINCT file_path) as mod_count, MIN(time) as first_seen FROM hb_file_activity WHERE (activity_id = 3 OR activity_id = 5) AND (LOWER(file_path) LIKE '%.crypt%' OR LOWER(file_path) LIKE '%.locked%' OR LOWER(file_path) LIKE '%.enc%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name HAVING mod_count > 500

    What a hit looks like. A single process renaming or updating hundreds of files within a short window. Silence proves absence of mass encryption for the known extensions.

  7. Triage ransomware progression

    Agent triage

    Synthesize the evidence from the entire hunt to confirm a multi-stage intrusion from perimeter access to data impact.

  8. Route on verdict

    Decision

    Direct the analyst based on the severity and confidence of the intrusion evidence.

  9. Isolate impacted hosts

    Response action

    Stop the spread of ransomware and lateral movement by isolating the beachhead and any encrypted hosts.

  10. Incident review

    Analyst task

    Conduct a deeper forensic review of the findings to identify the root cause and initial entry vector.

  11. Close out and remediation

    Analyst task

    Complete the hunt and document findings to improve central visibility and cross-campus coordination.

Coverage

Scenario coverage

StageCoveredHow, or why not
Exploitation of Public-Facing Applications
T1190
Yes http-exploit-patterns
Suspicious Login Sequences
T1078
Yes failed-logon-bursts
Cross-Campus Lateral Movement
T1021
Yes lateral-movement-signals
Data Encryption for Impact
T1486
Yes mass-encryption-activity

Blind spots

  • Needs full agent enrollment across all campuses. Fragmentation means the hunt only sees campuses with enrolled agents, leaving a blind spot in less-resourced departments. It would answer whether the intrusion is occurring on unmanaged legacy campuses.
  • Needs TLS decryption on the proxy or hb_http_activity with body data. Adversaries can bypass URI-only monitoring by using POST bodies or encrypted channels for exploitation. It would answer what specific exploit payload was delivered over HTTPS.
  • Needs agent-to-agent network telemetry or flow logs. If network monitoring only sees cross-campus (inter-VLAN) traffic, movement within a department may remain invisible. It would answer whether lateral movement is happening within a single campus VLAN.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
lookback_daysnumber14Days of history to examine.
scope_hostslist[host]—Optional list of hosts identified as exposed or vulnerable to focus the hunt.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint
Identity / sign-in telemetryidentityidentity
Network telemetrynetworknetwork
Web server / proxy logssiemnetwork

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: A single rule may fire on a known ransomware file extension; this hunt pivots
  from the initial web exploit through credential anomalies to lateral subnet traversal,
  confirming the entire intrusion chain before the impact becomes irreversible.
blind_spots:
- id: agent-visibility-gap
  question: whether the intrusion is occurring on unmanaged legacy campuses
  requires: full agent enrollment across all campuses
  risk: Fragmentation means the hunt only sees campuses with enrolled agents, leaving
    a blind spot in less-resourced departments.
- id: encrypted-payload-content
  question: what specific exploit payload was delivered over HTTPS
  requires: TLS decryption on the proxy or hb_http_activity with body data
  risk: Adversaries can bypass URI-only monitoring by using POST bodies or encrypted
    channels for exploitation.
  stage: initial-access-exploit
- id: intra-vlan-blind-spot
  question: whether lateral movement is happening within a single campus VLAN
  requires: agent-to-agent network telemetry or flow logs
  risk: If network monitoring only sees cross-campus (inter-VLAN) traffic, movement
    within a department may remain invisible.
  stage: cross-campus-lateral-movement
coverage:
- stage: initial-access-exploit
  status: covered
  steps:
  - http-exploit-patterns
- stage: suspicious-authentication-sequence
  status: covered
  steps:
  - failed-logon-bursts
- stage: cross-campus-lateral-movement
  status: covered
  steps:
  - lateral-movement-signals
- stage: ransomware-data-encryption
  status: covered
  steps:
  - mass-encryption-activity
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: promote-to-detection
  justification: The fragmentation of university networks often hides cross-campus
    attacks; this hunt identifies the early probes and the lateral progression that
    precedes campus-wide ransomware deployment.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An adversary exploits a vulnerable internet-facing application to establish
  a foothold, moves laterally across campus network boundaries using compromised credentials,
  and deploys ransomware to sensitive research or student data.
labels:
- hunt
- attack.t1190
- attack.t1078
- attack.t1021
- attack.t1486
- impact
- initial access
- lateral movement
name: Edge Exploitation and Cross-Campus Ransomware Impact
parameters:
  lookback_days:
    default: '14'
    description: Days of history to examine.
    from:
      kind: article
      observed: '2026-09-30'
      ref: https://www.rapid7.com/blog/post/it-higher-education-under-siege-fragmented-security
    type: number
  scope_hosts:
    default: []
    description: Optional list of hosts identified as exposed or vulnerable to focus
      the hunt.
    from:
      kind: manual
      observed: '2026-09-30'
      ref: hunt-designer
    type: list[host]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.rapid7.com/blog/post/it-higher-education-under-siege-fragmented-security
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Focus on perimeter web servers, VPN gateways, and known legacy research
  platforms that lack centralized management. Use the list[host] parameter to narrow
  the hunt to these specific assets if the inventory is large.
references:
- name: "Rapid7 \u2014 Higher education is under siege, and fragmented security is\
    \ making it harder to respond"
  url: https://www.rapid7.com/blog/post/it-higher-education-under-siege-fragmented-security
scenario:
  stages:
  - name: Exploitation of Public-Facing Applications
    observables:
    - exploitation of zero-day vulnerabilities
    - attacks against internet-facing hosts
    - unusual HTTP requests to web servers
    - active exploitation of unpatched legacy systems
    slug: initial-access-exploit
    tactic: initial-access
    techniques:
    - T1190
  - name: Suspicious Login Sequences
    observables:
    - suspicious login sequence across campuses
    - anomalous authentication timing
    - logins from unusual source IPs
    - sequential authentication failures followed by success
    slug: suspicious-authentication-sequence
    tactic: initial-access
    techniques:
    - T1078
  - name: Cross-Campus Lateral Movement
    observables:
    - network connections between distinct campus subnets
    - remote activity moving toward research or financial environments
    - use of internal network boundaries to bypass local security
    slug: cross-campus-lateral-movement
    tactic: lateral-movement
    techniques:
    - T1021
  - name: Data Encryption for Impact
    observables:
    - high-volume file modification
    - renaming of student and research records
    - deployment of ransomware binaries
    - interruption of teaching and administrative operations
    slug: ransomware-data-encryption
    tactic: impact
    techniques:
    - T1486
  summary: Higher education institutions face a high volume of cyberattacks where
    attackers exploit public-facing applications or vulnerable legacy systems to gain
    initial access. Once inside, they utilize suspicious login sequences to move laterally
    across fragmented campus networks, eventually deploying ransomware to encrypt
    sensitive research, student, and financial data.
severity: medium
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  identity:
    category: identity
    name: Identity / sign-in telemetry
    telemetry:
    - identity
  network:
    category: network
    name: Network telemetry
    telemetry:
    - network
  web:
    category: siem
    name: Web server / proxy logs
    telemetry:
    - network
tlp: clear
type: investigation
---


# Edge Exploitation and Cross-Campus Ransomware Impact

This hunt identifies the full lifecycle of an intrusion within fragmented university environments. It starts by scoping internet-facing software that may be vulnerable to exploitation, then pivots to identify suspicious HTTP probing and anomalous authentication sequences. In the second phase, it examines follow-on activity: lateral movement between distinct campus subnets and high-volume file modifications indicative of ransomware encryption. The phased flow allows an agent to weigh initial access evidence before correlating it with the eventual impact, addressing the visibility gaps that often exist in multi-campus institutions.

## find-vulnerable-perimeter
<!-- Identify exposed web services -->
Identify hosts running web-facing software that frequently serves as an entry point for university intrusions.

```sqlite target=endpoint role=scoping
~~~yaml
expected: A list of hosts running common perimeter software. Silence indicates no
  such software is tracked in the inventory.
reads:
- device_hostname
- package_name
- package_version
silence: not_evidence_of_absence
source: hb_software_inventory
verified: dry-run
verified_at: '2026-10-01'
~~~
SELECT device_hostname, package_name, package_version FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%apache%' OR LOWER(package_name) LIKE '%nginx%' OR LOWER(package_name) LIKE '%exchange%' OR LOWER(package_name) LIKE '%vpn%')
```

## parallel-initial
<!-- Analyze access and authentication -->
parallel:
- → http-exploit-patterns
- → failed-logon-bursts
join: → triage-access-leads

## http-exploit-patterns
<!-- Unusual HTTP probing -->
Find unusual HTTP requests to the identified perimeter hosts that may indicate exploitation of legacy systems or zero-day flaws.

```sqlite target=web role=triage params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: Rare HTTP error paths from a single source IP. Silence indicates no uncommon
  error activity on the perimeter.
reads:
- device_hostname
- url_path
- status_code
- src_endpoint_ip
- time
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-10-01'
~~~
SELECT device_hostname, url_path, status_code, src_endpoint_ip, COUNT(*) as request_count FROM hb_http_activity WHERE (status_code >= 400) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, url_path, status_code, src_endpoint_ip HAVING request_count < 20
```

## failed-logon-bursts
<!-- Failed logon burst stacking -->
Stack-count authentication failures by user and source IP to identify brute-force or credential-stuffing sequences that may precede campus-wide access.

```sqlite target=identity role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: A single IP or user account failing authentication repeatedly across multiple
  hosts or in high volume.
prevalence:
  by: device_hostname
  key:
  - actor_user_name
  - src_endpoint_ip
  rare_below: 3
reads:
- actor_user_name
- src_endpoint_ip
- device_hostname
- status_id
- time
silence: not_evidence_of_absence
source: hb_auth_signin
verified: dry-run
verified_at: '2026-10-01'
~~~
SELECT actor_user_name, src_endpoint_ip, COUNT(DISTINCT device_hostname) as host_count, COUNT(*) as fail_count, MIN(time) as first_seen FROM hb_auth_signin WHERE status_id = 2 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, src_endpoint_ip HAVING host_count <= 3 AND fail_count > 10
```

## triage-access-leads
<!-- Weigh initial access evidence -->
```agent target=hunter
cite: required
context:
- http-exploit-patterns
- failed-logon-bursts
max_iterations: 4
objective: Identify whether the combined HTTP probing and authentication patterns
  indicate an active exploitation or credential-based intrusion attempt.
success_criteria: A verdict of malicious | suspicious | benign per source IP or user
  account, citing the relevant logs.
tools:
- endpoint
- identity
- network
- web
```

## parallel-follow-on
<!-- Analyze lateral movement and impact -->
parallel:
- → lateral-movement-signals
- → mass-encryption-activity
join: → analyze-intrusion-chain

## lateral-movement-signals
<!-- Administrative lateral traffic -->
Identify network connections using administrative protocols originating from perimeter hosts, signifying lateral movement toward sensitive zones.

```sqlite target=network role=enrichment params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: Rare administrative connections from web servers or VPN gateways to internal
  endpoints. Silence means no uncommon admin traffic was detected from the perimeter.
reads:
- device_hostname
- dst_endpoint_ip
- dst_endpoint_port
- process_name
- time
silence: not_evidence_of_absence
source: hb_network_connection
verified: dry-run
verified_at: '2026-10-01'
~~~
SELECT device_hostname, dst_endpoint_ip, dst_endpoint_port, process_name, COUNT(*) as conn_count, MIN(time) as first_seen FROM hb_network_connection WHERE direction = 'outbound' AND dst_endpoint_port IN (22, 445, 3389, 5985) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, dst_endpoint_ip, dst_endpoint_port, process_name HAVING conn_count < 10
```

## mass-encryption-activity
<!-- High-volume file modifications -->
Identify processes modifying a massive number of files with ransomware-associated extensions across the fleet.

```sqlite target=endpoint role=detection-candidate params=(lookback_days=lookback_days)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: A single process renaming or updating hundreds of files within a short window.
  Silence proves absence of mass encryption for the known extensions.
prevalence:
  by: device_hostname
  key:
  - process_name
  rare_below: 5
reads:
- device_hostname
- process_name
- file_path
- activity_id
- time
silence: evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-10-01'
~~~
SELECT device_hostname, process_name, COUNT(DISTINCT file_path) as mod_count, MIN(time) as first_seen FROM hb_file_activity WHERE (activity_id = 3 OR activity_id = 5) AND (LOWER(file_path) LIKE '%.crypt%' OR LOWER(file_path) LIKE '%.locked%' OR LOWER(file_path) LIKE '%.enc%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name HAVING mod_count > 500
```

## analyze-intrusion-chain
<!-- Triage ransomware progression -->
```agent target=hunter
cite: required
context:
- triage-access-leads
- lateral-movement-signals
- mass-encryption-activity
max_iterations: 6
objective: Correlate the suspicious access leads with the observed lateral movement
  and high-volume file modification patterns to confirm a ransomware-style intrusion
  chain.
success_criteria: A timeline of the intrusion from initial web probe or logon anomaly
  to lateral movement and final file modification, citing specific rows.
tools:
- endpoint
- identity
- network
- web
```

## route-on-impact
<!-- Route on verdict -->
if~: "the analyze-intrusion-chain verdict is malicious or suspicious for at least one host" (confidence: high, judge=hunter)
then: → contain-impacted-host
indeterminate: → incident-investigation
unavailable: → incident-investigation (blind_spot: agent-visibility-gap)
else: → remediation-and-lessons

## contain-impacted-host
<!-- Isolate impacted hosts -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the hosts identified in the analyze-intrusion-chain verdict. Preserve memory and file system state for forensic analysis.
```
→ incident-investigation

## incident-investigation
<!-- Incident review -->
```manual target=analyst
Examine the processes and source IPs identified in the agent read. Verify the software versions potentially exploited on the perimeter hosts and the extent of data encryption.
```
→ remediation-and-lessons

## remediation-and-lessons
<!-- Close out and remediation -->
```manual target=analyst
Document the gaps in visibility between campuses. Recommend centralizing authentication monitoring and perimeter vulnerability scanning to prevent lateral movement from reaching sensitive subnets.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.