Edge Exploitation and Cross-Campus Ransomware Impact
An adversary exploits a vulnerable internet-facing application to establish a foothold, moves laterally across campus network boundaries using compromised credentials, and deploys ransomware to sensitive research or student data.
Based on research by Rapid7 2026-10-01 12 steps · 5 queries T1021 T1078 T1190 T1486
Brief
Why fragmented networks hide threats 0AThe
Rapid7 article "Higher education is under siege, and fragmented security is making it harder to respond" (https://www.rapid7.com/blog/post/it-higher-education-under-siege-fragmented-security) describes a significant challenge for university SOCs. Decentralized IT departments often manage their own subnets and security stacks, creating visibility silos. This fragmentation allows an adversary to exploit a vulnerability in one department and move laterally across the campus network without triggering centralized alerts. 0A
How the hunt flows
0AThe first phase scopes the environment. The query identifies hosts running common edge software, such as Apache, Nginx, or VPN gateways. This provides the surface for potential exploitation. 0ANext, the hunt analyzes access patterns in parallel. One path stacks HTTP activity to find rare error paths that might indicate an exploit attempt. The other path identifies failed logon bursts across multiple hosts, which often signals a credential-based intrusion. 0AAn analyst then weighs these leads. By correlating web errors with authentication failures from the same source IP, the investigator determines if a suspect has breached the perimeter. 0AIf suspicious activity exists, the hunt moves to find the impact. It searches for administrative network traffic originating from the perimeter hosts, such as SSH or RDP. Simultaneously, it looks for high-volume file modifications involving ransomware extensions like crypt or locked. 0A
What the hunt cannot see
0ASeveral blind spots exist. If a campus does not have agents enrolled, the hunt cannot see activity in those legacy zones. The hunt also misses exploit payloads sent within encrypted HTTPS bodies, as it focuses on URI paths. Finally, if lateral movement occurs entirely within a single department's VLAN, network-based pivots may remain hidden. 0A
Steps
-
Identify exposed web services
Query · scopingIdentify hosts running web-facing software that frequently serves as an entry point for university intrusions.
reads hb_software_inventorysqlSELECT device_hostname, package_name, package_version FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%apache%' OR LOWER(package_name) LIKE '%nginx%' OR LOWER(package_name) LIKE '%exchange%' OR LOWER(package_name) LIKE '%vpn%')What a hit looks like. A list of hosts running common perimeter software. Silence indicates no such software is tracked in the inventory.
-
Unusual HTTP probing
Query · triageFind unusual HTTP requests to the identified perimeter hosts that may indicate exploitation of legacy systems or zero-day flaws.
reads hb_http_activitysqlSELECT device_hostname, url_path, status_code, src_endpoint_ip, COUNT(*) as request_count FROM hb_http_activity WHERE (status_code >= 400) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, url_path, status_code, src_endpoint_ip HAVING request_count < 20What a hit looks like. Rare HTTP error paths from a single source IP. Silence indicates no uncommon error activity on the perimeter.
-
Failed logon burst stacking
Query · baselineStack-count authentication failures by user and source IP to identify brute-force or credential-stuffing sequences that may precede campus-wide access.
reads hb_auth_signinsqlSELECT actor_user_name, src_endpoint_ip, COUNT(DISTINCT device_hostname) as host_count, COUNT(*) as fail_count, MIN(time) as first_seen FROM hb_auth_signin WHERE status_id = 2 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, src_endpoint_ip HAVING host_count <= 3 AND fail_count > 10What a hit looks like. A single IP or user account failing authentication repeatedly across multiple hosts or in high volume.
-
Weigh initial access evidence
Agent triageEvaluate the HTTP probes and authentication failures together to determine if an intrusion has likely begun.
-
Administrative lateral traffic
Query · enrichmentIdentify network connections using administrative protocols originating from perimeter hosts, signifying lateral movement toward sensitive zones.
reads hb_network_connectionsqlSELECT device_hostname, dst_endpoint_ip, dst_endpoint_port, process_name, COUNT(*) as conn_count, MIN(time) as first_seen FROM hb_network_connection WHERE direction = 'outbound' AND dst_endpoint_port IN (22, 445, 3389, 5985) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, dst_endpoint_ip, dst_endpoint_port, process_name HAVING conn_count < 10What a hit looks like. Rare administrative connections from web servers or VPN gateways to internal endpoints. Silence means no uncommon admin traffic was detected from the perimeter.
-
High-volume file modifications
Query · detection candidateIdentify processes modifying a massive number of files with ransomware-associated extensions across the fleet.
reads hb_file_activitysqlSELECT device_hostname, process_name, COUNT(DISTINCT file_path) as mod_count, MIN(time) as first_seen FROM hb_file_activity WHERE (activity_id = 3 OR activity_id = 5) AND (LOWER(file_path) LIKE '%.crypt%' OR LOWER(file_path) LIKE '%.locked%' OR LOWER(file_path) LIKE '%.enc%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name HAVING mod_count > 500What a hit looks like. A single process renaming or updating hundreds of files within a short window. Silence proves absence of mass encryption for the known extensions.
-
Triage ransomware progression
Agent triageSynthesize the evidence from the entire hunt to confirm a multi-stage intrusion from perimeter access to data impact.
-
Route on verdict
DecisionDirect the analyst based on the severity and confidence of the intrusion evidence.
-
Isolate impacted hosts
Response actionStop the spread of ransomware and lateral movement by isolating the beachhead and any encrypted hosts.
-
Incident review
Analyst taskConduct a deeper forensic review of the findings to identify the root cause and initial entry vector.
-
Close out and remediation
Analyst taskComplete the hunt and document findings to improve central visibility and cross-campus coordination.
Coverage
Scenario coverage
| Stage | Covered | How, or why not |
|---|---|---|
| Exploitation of Public-Facing Applications T1190 |
Yes | http-exploit-patterns |
| Suspicious Login Sequences T1078 |
Yes | failed-logon-bursts |
| Cross-Campus Lateral Movement T1021 |
Yes | lateral-movement-signals |
| Data Encryption for Impact T1486 |
Yes | mass-encryption-activity |
Blind spots
- Needs full agent enrollment across all campuses. Fragmentation means the hunt only sees campuses with enrolled agents, leaving a blind spot in less-resourced departments. It would answer whether the intrusion is occurring on unmanaged legacy campuses.
- Needs TLS decryption on the proxy or hb_http_activity with body data. Adversaries can bypass URI-only monitoring by using POST bodies or encrypted channels for exploitation. It would answer what specific exploit payload was delivered over HTTPS.
- Needs agent-to-agent network telemetry or flow logs. If network monitoring only sees cross-campus (inter-VLAN) traffic, movement within a department may remain invisible. It would answer whether lateral movement is happening within a single campus VLAN.
Parameters & data
Parameters
| Parameter | Type | Default | What it is |
|---|---|---|---|
lookback_days | number | 14 | Days of history to examine. |
scope_hosts | list[host] | — | Optional list of hosts identified as exposed or vulnerable to focus the hunt. |
Telemetry
| Source | Category | Telemetry |
|---|---|---|
| Endpoint telemetry (hb_ surfaces) | endpoint | endpoint |
| Identity / sign-in telemetry | identity | identity |
| Network telemetry | network | network |
| Web server / proxy logs | siem | network |
Source
---
analysis: A single rule may fire on a known ransomware file extension; this hunt pivots
from the initial web exploit through credential anomalies to lateral subnet traversal,
confirming the entire intrusion chain before the impact becomes irreversible.
blind_spots:
- id: agent-visibility-gap
question: whether the intrusion is occurring on unmanaged legacy campuses
requires: full agent enrollment across all campuses
risk: Fragmentation means the hunt only sees campuses with enrolled agents, leaving
a blind spot in less-resourced departments.
- id: encrypted-payload-content
question: what specific exploit payload was delivered over HTTPS
requires: TLS decryption on the proxy or hb_http_activity with body data
risk: Adversaries can bypass URI-only monitoring by using POST bodies or encrypted
channels for exploitation.
stage: initial-access-exploit
- id: intra-vlan-blind-spot
question: whether lateral movement is happening within a single campus VLAN
requires: agent-to-agent network telemetry or flow logs
risk: If network monitoring only sees cross-campus (inter-VLAN) traffic, movement
within a department may remain invisible.
stage: cross-campus-lateral-movement
coverage:
- stage: initial-access-exploit
status: covered
steps:
- http-exploit-patterns
- stage: suspicious-authentication-sequence
status: covered
steps:
- failed-logon-bursts
- stage: cross-campus-lateral-movement
status: covered
steps:
- lateral-movement-signals
- stage: ransomware-data-encryption
status: covered
steps:
- mass-encryption-activity
guardrails:
claims: no_unsupported
evidence: citation_required
missing_data: not_benign
telemetry: untrusted
hunt:
applicability: campaign-specific
handoff: promote-to-detection
justification: The fragmentation of university networks often hides cross-campus
attacks; this hunt identifies the early probes and the lateral progression that
precedes campus-wide ransomware deployment.
methodology: model-assisted
trigger: intel-report
hypothesis: An adversary exploits a vulnerable internet-facing application to establish
a foothold, moves laterally across campus network boundaries using compromised credentials,
and deploys ransomware to sensitive research or student data.
labels:
- hunt
- attack.t1190
- attack.t1078
- attack.t1021
- attack.t1486
- impact
- initial access
- lateral movement
name: Edge Exploitation and Cross-Campus Ransomware Impact
parameters:
lookback_days:
default: '14'
description: Days of history to examine.
from:
kind: article
observed: '2026-09-30'
ref: https://www.rapid7.com/blog/post/it-higher-education-under-siege-fragmented-security
type: number
scope_hosts:
default: []
description: Optional list of hosts identified as exposed or vulnerable to focus
the hunt.
from:
kind: manual
observed: '2026-09-30'
ref: hunt-designer
type: list[host]
provenance:
authors:
- name: Huntbase hunt generation
org: huntbase.io
generated:
by: huntbase-hunt-generation
from: https://www.rapid7.com/blog/post/it-higher-education-under-siege-fragmented-security
gates:
- dry-run
- lint
model: hb_google/gemini-3-flash-preview
rationale: Focus on perimeter web servers, VPN gateways, and known legacy research
platforms that lack centralized management. Use the list[host] parameter to narrow
the hunt to these specific assets if the inventory is large.
references:
- name: "Rapid7 \u2014 Higher education is under siege, and fragmented security is\
\ making it harder to respond"
url: https://www.rapid7.com/blog/post/it-higher-education-under-siege-fragmented-security
scenario:
stages:
- name: Exploitation of Public-Facing Applications
observables:
- exploitation of zero-day vulnerabilities
- attacks against internet-facing hosts
- unusual HTTP requests to web servers
- active exploitation of unpatched legacy systems
slug: initial-access-exploit
tactic: initial-access
techniques:
- T1190
- name: Suspicious Login Sequences
observables:
- suspicious login sequence across campuses
- anomalous authentication timing
- logins from unusual source IPs
- sequential authentication failures followed by success
slug: suspicious-authentication-sequence
tactic: initial-access
techniques:
- T1078
- name: Cross-Campus Lateral Movement
observables:
- network connections between distinct campus subnets
- remote activity moving toward research or financial environments
- use of internal network boundaries to bypass local security
slug: cross-campus-lateral-movement
tactic: lateral-movement
techniques:
- T1021
- name: Data Encryption for Impact
observables:
- high-volume file modification
- renaming of student and research records
- deployment of ransomware binaries
- interruption of teaching and administrative operations
slug: ransomware-data-encryption
tactic: impact
techniques:
- T1486
summary: Higher education institutions face a high volume of cyberattacks where
attackers exploit public-facing applications or vulnerable legacy systems to gain
initial access. Once inside, they utilize suspicious login sequences to move laterally
across fragmented campus networks, eventually deploying ransomware to encrypt
sensitive research, student, and financial data.
severity: medium
targets:
analyst:
name: Tier-2 analyst
role: analyst
endpoint:
category: endpoint
name: Endpoint telemetry (hb_ surfaces)
telemetry:
- endpoint
hunter:
agent: true
name: Hunt agent
identity:
category: identity
name: Identity / sign-in telemetry
telemetry:
- identity
network:
category: network
name: Network telemetry
telemetry:
- network
web:
category: siem
name: Web server / proxy logs
telemetry:
- network
tlp: clear
type: investigation
---
# Edge Exploitation and Cross-Campus Ransomware Impact
This hunt identifies the full lifecycle of an intrusion within fragmented university environments. It starts by scoping internet-facing software that may be vulnerable to exploitation, then pivots to identify suspicious HTTP probing and anomalous authentication sequences. In the second phase, it examines follow-on activity: lateral movement between distinct campus subnets and high-volume file modifications indicative of ransomware encryption. The phased flow allows an agent to weigh initial access evidence before correlating it with the eventual impact, addressing the visibility gaps that often exist in multi-campus institutions.
## find-vulnerable-perimeter
<!-- Identify exposed web services -->
Identify hosts running web-facing software that frequently serves as an entry point for university intrusions.
```sqlite target=endpoint role=scoping
~~~yaml
expected: A list of hosts running common perimeter software. Silence indicates no
such software is tracked in the inventory.
reads:
- device_hostname
- package_name
- package_version
silence: not_evidence_of_absence
source: hb_software_inventory
verified: dry-run
verified_at: '2026-10-01'
~~~
SELECT device_hostname, package_name, package_version FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%apache%' OR LOWER(package_name) LIKE '%nginx%' OR LOWER(package_name) LIKE '%exchange%' OR LOWER(package_name) LIKE '%vpn%')
```
## parallel-initial
<!-- Analyze access and authentication -->
parallel:
- → http-exploit-patterns
- → failed-logon-bursts
join: → triage-access-leads
## http-exploit-patterns
<!-- Unusual HTTP probing -->
Find unusual HTTP requests to the identified perimeter hosts that may indicate exploitation of legacy systems or zero-day flaws.
```sqlite target=web role=triage params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: Rare HTTP error paths from a single source IP. Silence indicates no uncommon
error activity on the perimeter.
reads:
- device_hostname
- url_path
- status_code
- src_endpoint_ip
- time
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-10-01'
~~~
SELECT device_hostname, url_path, status_code, src_endpoint_ip, COUNT(*) as request_count FROM hb_http_activity WHERE (status_code >= 400) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, url_path, status_code, src_endpoint_ip HAVING request_count < 20
```
## failed-logon-bursts
<!-- Failed logon burst stacking -->
Stack-count authentication failures by user and source IP to identify brute-force or credential-stuffing sequences that may precede campus-wide access.
```sqlite target=identity role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
compare: first_seen
window: '{{lookback_days}}d'
expected: A single IP or user account failing authentication repeatedly across multiple
hosts or in high volume.
prevalence:
by: device_hostname
key:
- actor_user_name
- src_endpoint_ip
rare_below: 3
reads:
- actor_user_name
- src_endpoint_ip
- device_hostname
- status_id
- time
silence: not_evidence_of_absence
source: hb_auth_signin
verified: dry-run
verified_at: '2026-10-01'
~~~
SELECT actor_user_name, src_endpoint_ip, COUNT(DISTINCT device_hostname) as host_count, COUNT(*) as fail_count, MIN(time) as first_seen FROM hb_auth_signin WHERE status_id = 2 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, src_endpoint_ip HAVING host_count <= 3 AND fail_count > 10
```
## triage-access-leads
<!-- Weigh initial access evidence -->
```agent target=hunter
cite: required
context:
- http-exploit-patterns
- failed-logon-bursts
max_iterations: 4
objective: Identify whether the combined HTTP probing and authentication patterns
indicate an active exploitation or credential-based intrusion attempt.
success_criteria: A verdict of malicious | suspicious | benign per source IP or user
account, citing the relevant logs.
tools:
- endpoint
- identity
- network
- web
```
## parallel-follow-on
<!-- Analyze lateral movement and impact -->
parallel:
- → lateral-movement-signals
- → mass-encryption-activity
join: → analyze-intrusion-chain
## lateral-movement-signals
<!-- Administrative lateral traffic -->
Identify network connections using administrative protocols originating from perimeter hosts, signifying lateral movement toward sensitive zones.
```sqlite target=network role=enrichment params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: Rare administrative connections from web servers or VPN gateways to internal
endpoints. Silence means no uncommon admin traffic was detected from the perimeter.
reads:
- device_hostname
- dst_endpoint_ip
- dst_endpoint_port
- process_name
- time
silence: not_evidence_of_absence
source: hb_network_connection
verified: dry-run
verified_at: '2026-10-01'
~~~
SELECT device_hostname, dst_endpoint_ip, dst_endpoint_port, process_name, COUNT(*) as conn_count, MIN(time) as first_seen FROM hb_network_connection WHERE direction = 'outbound' AND dst_endpoint_port IN (22, 445, 3389, 5985) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, dst_endpoint_ip, dst_endpoint_port, process_name HAVING conn_count < 10
```
## mass-encryption-activity
<!-- High-volume file modifications -->
Identify processes modifying a massive number of files with ransomware-associated extensions across the fleet.
```sqlite target=endpoint role=detection-candidate params=(lookback_days=lookback_days)
~~~yaml
baseline:
compare: first_seen
window: '{{lookback_days}}d'
expected: A single process renaming or updating hundreds of files within a short window.
Silence proves absence of mass encryption for the known extensions.
prevalence:
by: device_hostname
key:
- process_name
rare_below: 5
reads:
- device_hostname
- process_name
- file_path
- activity_id
- time
silence: evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-10-01'
~~~
SELECT device_hostname, process_name, COUNT(DISTINCT file_path) as mod_count, MIN(time) as first_seen FROM hb_file_activity WHERE (activity_id = 3 OR activity_id = 5) AND (LOWER(file_path) LIKE '%.crypt%' OR LOWER(file_path) LIKE '%.locked%' OR LOWER(file_path) LIKE '%.enc%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name HAVING mod_count > 500
```
## analyze-intrusion-chain
<!-- Triage ransomware progression -->
```agent target=hunter
cite: required
context:
- triage-access-leads
- lateral-movement-signals
- mass-encryption-activity
max_iterations: 6
objective: Correlate the suspicious access leads with the observed lateral movement
and high-volume file modification patterns to confirm a ransomware-style intrusion
chain.
success_criteria: A timeline of the intrusion from initial web probe or logon anomaly
to lateral movement and final file modification, citing specific rows.
tools:
- endpoint
- identity
- network
- web
```
## route-on-impact
<!-- Route on verdict -->
if~: "the analyze-intrusion-chain verdict is malicious or suspicious for at least one host" (confidence: high, judge=hunter)
then: → contain-impacted-host
indeterminate: → incident-investigation
unavailable: → incident-investigation (blind_spot: agent-visibility-gap)
else: → remediation-and-lessons
## contain-impacted-host
<!-- Isolate impacted hosts -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the hosts identified in the analyze-intrusion-chain verdict. Preserve memory and file system state for forensic analysis.
```
→ incident-investigation
## incident-investigation
<!-- Incident review -->
```manual target=analyst
Examine the processes and source IPs identified in the agent read. Verify the software versions potentially exploited on the perimeter hosts and the extent of data encryption.
```
→ remediation-and-lessons
## remediation-and-lessons
<!-- Close out and remediation -->
```manual target=analyst
Document the gaps in visibility between campuses. Recommend centralizing authentication monitoring and perimeter vulnerability scanning to prevent lateral movement from reaching sensitive subnets.
```
→ end
Run it
Take this hunt into your environment.
Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.
Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.