{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "The fragmentation of university networks often hides cross-campus attacks; this hunt identifies the early probes and the lateral progression that precedes campus-wide ransomware deployment."
      },
      "name": "Edge Exploitation and Cross-Campus Ransomware Impact",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1190",
        "attack.t1078",
        "attack.t1021",
        "attack.t1486",
        "impact",
        "initial access",
        "lateral movement"
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "network": {
          "name": "Network telemetry",
          "category": "network",
          "telemetry": [
            "network"
          ]
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        },
        "identity": {
          "name": "Identity / sign-in telemetry",
          "category": "identity",
          "telemetry": [
            "identity"
          ]
        }
      },
      "analysis": "A single rule may fire on a known ransomware file extension; this hunt pivots from the initial web exploit through credential anomalies to lateral subnet traversal, confirming the entire intrusion chain before the impact becomes irreversible.",
      "coverage": [
        {
          "stage": "initial-access-exploit",
          "steps": [
            "http-exploit-patterns"
          ],
          "status": "covered"
        },
        {
          "stage": "suspicious-authentication-sequence",
          "steps": [
            "failed-logon-bursts"
          ],
          "status": "covered"
        },
        {
          "stage": "cross-campus-lateral-movement",
          "steps": [
            "lateral-movement-signals"
          ],
          "status": "covered"
        },
        {
          "stage": "ransomware-data-encryption",
          "steps": [
            "mass-encryption-activity"
          ],
          "status": "covered"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Exploitation of Public-Facing Applications",
            "slug": "initial-access-exploit",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "exploitation of zero-day vulnerabilities",
              "attacks against internet-facing hosts",
              "unusual HTTP requests to web servers",
              "active exploitation of unpatched legacy systems"
            ]
          },
          {
            "name": "Suspicious Login Sequences",
            "slug": "suspicious-authentication-sequence",
            "tactic": "initial-access",
            "techniques": [
              "T1078"
            ],
            "observables": [
              "suspicious login sequence across campuses",
              "anomalous authentication timing",
              "logins from unusual source IPs",
              "sequential authentication failures followed by success"
            ]
          },
          {
            "name": "Cross-Campus Lateral Movement",
            "slug": "cross-campus-lateral-movement",
            "tactic": "lateral-movement",
            "techniques": [
              "T1021"
            ],
            "observables": [
              "network connections between distinct campus subnets",
              "remote activity moving toward research or financial environments",
              "use of internal network boundaries to bypass local security"
            ]
          },
          {
            "name": "Data Encryption for Impact",
            "slug": "ransomware-data-encryption",
            "tactic": "impact",
            "techniques": [
              "T1486"
            ],
            "observables": [
              "high-volume file modification",
              "renaming of student and research records",
              "deployment of ransomware binaries",
              "interruption of teaching and administrative operations"
            ]
          }
        ],
        "summary": "Higher education institutions face a high volume of cyberattacks where attackers exploit public-facing applications or vulnerable legacy systems to gain initial access. Once inside, they utilize suspicious login sequences to move laterally across fragmented campus networks, eventually deploying ransomware to encrypt sensitive research, student, and financial data."
      },
      "severity": "medium",
      "rationale": "Focus on perimeter web servers, VPN gateways, and known legacy research platforms that lack centralized management. Use the list[host] parameter to narrow the hunt to these specific assets if the inventory is large.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary exploits a vulnerable internet-facing application to establish a foothold, moves laterally across campus network boundaries using compromised credentials, and deploys ransomware to sensitive research or student data.",
      "parameters": {
        "scope_hosts": {
          "from": {
            "ref": "hunt-designer",
            "kind": "manual",
            "observed": "2026-09-30"
          },
          "type": "list[host]",
          "default": [],
          "description": "Optional list of hosts identified as exposed or vulnerable to focus the hunt."
        },
        "lookback_days": {
          "from": {
            "ref": "https://www.rapid7.com/blog/post/it-higher-education-under-siege-fragmented-security",
            "kind": "article",
            "observed": "2026-09-30"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.rapid7.com/blog/post/it-higher-education-under-siege-fragmented-security",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.rapid7.com/blog/post/it-higher-education-under-siege-fragmented-security",
          "name": "Rapid7 \u2014 Higher education is under siege, and fragmented security is making it harder to respond"
        }
      ],
      "blind_spots": [
        {
          "id": "agent-visibility-gap",
          "risk": "Fragmentation means the hunt only sees campuses with enrolled agents, leaving a blind spot in less-resourced departments.",
          "question": "whether the intrusion is occurring on unmanaged legacy campuses",
          "requires": "full agent enrollment across all campuses"
        },
        {
          "id": "encrypted-payload-content",
          "risk": "Adversaries can bypass URI-only monitoring by using POST bodies or encrypted channels for exploitation.",
          "stage": "initial-access-exploit",
          "question": "what specific exploit payload was delivered over HTTPS",
          "requires": "TLS decryption on the proxy or hb_http_activity with body data"
        },
        {
          "id": "intra-vlan-blind-spot",
          "risk": "If network monitoring only sees cross-campus (inter-VLAN) traffic, movement within a department may remain invisible.",
          "stage": "cross-campus-lateral-movement",
          "question": "whether lateral movement is happening within a single campus VLAN",
          "requires": "agent-to-agent network telemetry or flow logs"
        }
      ]
    },
    "name": "Edge Exploitation and Cross-Campus Ransomware Impact",
    "description": "This hunt identifies the full lifecycle of an intrusion within fragmented university environments. It starts by scoping internet-facing software that may be vulnerable to exploitation, then pivots to identify suspicious HTTP probing and anomalous authentication sequences. In the second phase, it examines follow-on activity: lateral movement between distinct campus subnets and high-volume file modifications indicative of ransomware encryption. The phased flow allows an agent to weigh initial access evidence before correlating it with the eventual impact, addressing the visibility gaps that often exist in multi-campus institutions."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "coverage": [
          {
            "stage": "initial-access-exploit",
            "steps": [
              "http-exploit-patterns"
            ],
            "status": "covered"
          },
          {
            "stage": "suspicious-authentication-sequence",
            "steps": [
              "failed-logon-bursts"
            ],
            "status": "covered"
          },
          {
            "stage": "cross-campus-lateral-movement",
            "steps": [
              "lateral-movement-signals"
            ],
            "status": "covered"
          },
          {
            "stage": "ransomware-data-encryption",
            "steps": [
              "mass-encryption-activity"
            ],
            "status": "covered"
          }
        ],
        "rationale": "An adversary exploits a vulnerable internet-facing application to establish a foothold, moves laterally across campus network boundaries using compromised credentials, and deploys ransomware to sensitive research or student data.",
        "blind_spots": [
          {
            "id": "agent-visibility-gap",
            "risk": "Fragmentation means the hunt only sees campuses with enrolled agents, leaving a blind spot in less-resourced departments.",
            "question": "whether the intrusion is occurring on unmanaged legacy campuses",
            "requires": "full agent enrollment across all campuses"
          },
          {
            "id": "encrypted-payload-content",
            "risk": "Adversaries can bypass URI-only monitoring by using POST bodies or encrypted channels for exploitation.",
            "stage": "initial-access-exploit",
            "question": "what specific exploit payload was delivered over HTTPS",
            "requires": "TLS decryption on the proxy or hb_http_activity with body data"
          },
          {
            "id": "intra-vlan-blind-spot",
            "risk": "If network monitoring only sees cross-campus (inter-VLAN) traffic, movement within a department may remain invisible.",
            "stage": "cross-campus-lateral-movement",
            "question": "whether lateral movement is happening within a single campus VLAN",
            "requires": "agent-to-agent network telemetry or flow logs"
          }
        ],
        "scoping_notes": "Focus on perimeter web servers, VPN gateways, and known legacy research platforms that lack centralized management. Use the list[host] parameter to narrow the hunt to these specific assets if the inventory is large.",
        "beyond_detection": "A single rule may fire on a known ransomware file extension; this hunt pivots from the initial web exploit through credential anomalies to lateral subnet traversal, confirming the entire intrusion chain before the impact becomes irreversible."
      }
    },
    {
      "id": "find-vulnerable-perimeter",
      "type": "query",
      "label": "Identify exposed web services",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_hostname, package_name, package_version FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%apache%' OR LOWER(package_name) LIKE '%nginx%' OR LOWER(package_name) LIKE '%exchange%' OR LOWER(package_name) LIKE '%vpn%')",
        "surface": "hb_software_inventory",
        "description": "Identify hosts running web-facing software that frequently serves as an entry point for university intrusions.",
        "expected_signal": "A list of hosts running common perimeter software. Silence indicates no such software is tracked in the inventory."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify exposed web services",
        "reads": [
          "device_hostname",
          "package_name",
          "package_version"
        ],
        "source": "hb_software_inventory",
        "target": "endpoint",
        "content": "SELECT device_hostname, package_name, package_version FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%apache%' OR LOWER(package_name) LIKE '%nginx%' OR LOWER(package_name) LIKE '%exchange%' OR LOWER(package_name) LIKE '%vpn%')",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hosts running common perimeter software. Silence indicates no such software is tracked in the inventory.",
        "verified": "dry-run",
        "verified_at": "2026-10-01"
      }
    },
    {
      "id": "http-exploit-patterns",
      "type": "query",
      "label": "Unusual HTTP probing",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "web",
        "content": "SELECT device_hostname, url_path, status_code, src_endpoint_ip, COUNT(*) as request_count FROM hb_http_activity WHERE (status_code >= 400) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, url_path, status_code, src_endpoint_ip HAVING request_count < 20",
        "surface": "hb_http_activity",
        "description": "Find unusual HTTP requests to the identified perimeter hosts that may indicate exploitation of legacy systems or zero-day flaws.",
        "expected_signal": "Rare HTTP error paths from a single source IP. Silence indicates no uncommon error activity on the perimeter."
      },
      "parents": [
        {
          "id": "find-vulnerable-perimeter"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Unusual HTTP probing",
        "reads": [
          "device_hostname",
          "url_path",
          "status_code",
          "src_endpoint_ip",
          "time"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT device_hostname, url_path, status_code, src_endpoint_ip, COUNT(*) as request_count FROM hb_http_activity WHERE (status_code >= 400) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, url_path, status_code, src_endpoint_ip HAVING request_count < 20",
        "silence": "not_evidence_of_absence",
        "expected": "Rare HTTP error paths from a single source IP. Silence indicates no uncommon error activity on the perimeter.",
        "verified": "dry-run",
        "verified_at": "2026-10-01"
      }
    },
    {
      "id": "failed-logon-bursts",
      "type": "query",
      "label": "Failed logon burst stacking",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "identity",
        "content": "SELECT actor_user_name, src_endpoint_ip, COUNT(DISTINCT device_hostname) as host_count, COUNT(*) as fail_count, MIN(time) as first_seen FROM hb_auth_signin WHERE status_id = 2 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, src_endpoint_ip HAVING host_count <= 3 AND fail_count > 10",
        "surface": "hb_auth_signin",
        "description": "Stack-count authentication failures by user and source IP to identify brute-force or credential-stuffing sequences that may precede campus-wide access.",
        "expected_signal": "A single IP or user account failing authentication repeatedly across multiple hosts or in high volume."
      },
      "parents": [
        {
          "id": "find-vulnerable-perimeter"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Failed logon burst stacking",
        "reads": [
          "actor_user_name",
          "src_endpoint_ip",
          "device_hostname",
          "status_id",
          "time"
        ],
        "source": "hb_auth_signin",
        "target": "identity",
        "content": "SELECT actor_user_name, src_endpoint_ip, COUNT(DISTINCT device_hostname) as host_count, COUNT(*) as fail_count, MIN(time) as first_seen FROM hb_auth_signin WHERE status_id = 2 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, src_endpoint_ip HAVING host_count <= 3 AND fail_count > 10",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A single IP or user account failing authentication repeatedly across multiple hosts or in high volume.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "actor_user_name",
            "src_endpoint_ip"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-10-01"
      }
    },
    {
      "id": "triage-access-leads",
      "type": "analytic",
      "label": "Weigh initial access evidence",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity",
          "network",
          "web"
        ],
        "context": [
          "http-exploit-patterns",
          "failed-logon-bursts"
        ],
        "objective": "Identify whether the combined HTTP probing and authentication patterns indicate an active exploitation or credential-based intrusion attempt.",
        "description": "Evaluate the HTTP probes and authentication failures together to determine if an intrusion has likely begun.",
        "max_iterations": 4,
        "expected_signal": "A verdict confirming suspicious initial access activity.",
        "success_criteria": "A verdict of malicious | suspicious | benign per source IP or user account, citing the relevant logs."
      },
      "parents": [
        {
          "id": "http-exploit-patterns",
          "kind": "merge"
        },
        {
          "id": "failed-logon-bursts",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "lateral-movement-signals",
      "type": "query",
      "label": "Administrative lateral traffic",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "network",
        "content": "SELECT device_hostname, dst_endpoint_ip, dst_endpoint_port, process_name, COUNT(*) as conn_count, MIN(time) as first_seen FROM hb_network_connection WHERE direction = 'outbound' AND dst_endpoint_port IN (22, 445, 3389, 5985) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, dst_endpoint_ip, dst_endpoint_port, process_name HAVING conn_count < 10",
        "surface": "hb_network_connection",
        "description": "Identify network connections using administrative protocols originating from perimeter hosts, signifying lateral movement toward sensitive zones.",
        "expected_signal": "Rare administrative connections from web servers or VPN gateways to internal endpoints. Silence means no uncommon admin traffic was detected from the perimeter."
      },
      "parents": [
        {
          "id": "triage-access-leads"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Administrative lateral traffic",
        "reads": [
          "device_hostname",
          "dst_endpoint_ip",
          "dst_endpoint_port",
          "process_name",
          "time"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT device_hostname, dst_endpoint_ip, dst_endpoint_port, process_name, COUNT(*) as conn_count, MIN(time) as first_seen FROM hb_network_connection WHERE direction = 'outbound' AND dst_endpoint_port IN (22, 445, 3389, 5985) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, dst_endpoint_ip, dst_endpoint_port, process_name HAVING conn_count < 10",
        "silence": "not_evidence_of_absence",
        "expected": "Rare administrative connections from web servers or VPN gateways to internal endpoints. Silence means no uncommon admin traffic was detected from the perimeter.",
        "verified": "dry-run",
        "verified_at": "2026-10-01"
      }
    },
    {
      "id": "mass-encryption-activity",
      "type": "query",
      "label": "High-volume file modifications",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, COUNT(DISTINCT file_path) as mod_count, MIN(time) as first_seen FROM hb_file_activity WHERE (activity_id = 3 OR activity_id = 5) AND (LOWER(file_path) LIKE '%.crypt%' OR LOWER(file_path) LIKE '%.locked%' OR LOWER(file_path) LIKE '%.enc%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name HAVING mod_count > 500",
        "surface": "hb_file_activity",
        "description": "Identify processes modifying a massive number of files with ransomware-associated extensions across the fleet.",
        "expected_signal": "A single process renaming or updating hundreds of files within a short window. Silence proves absence of mass encryption for the known extensions."
      },
      "parents": [
        {
          "id": "triage-access-leads"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "High-volume file modifications",
        "reads": [
          "device_hostname",
          "process_name",
          "file_path",
          "activity_id",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, COUNT(DISTINCT file_path) as mod_count, MIN(time) as first_seen FROM hb_file_activity WHERE (activity_id = 3 OR activity_id = 5) AND (LOWER(file_path) LIKE '%.crypt%' OR LOWER(file_path) LIKE '%.locked%' OR LOWER(file_path) LIKE '%.enc%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name HAVING mod_count > 500",
        "silence": "evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A single process renaming or updating hundreds of files within a short window. Silence proves absence of mass encryption for the known extensions.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_name"
          ],
          "rare_below": 5
        },
        "verified_at": "2026-10-01"
      }
    },
    {
      "id": "analyze-intrusion-chain",
      "type": "analytic",
      "label": "Triage ransomware progression",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity",
          "network",
          "web"
        ],
        "context": [
          "triage-access-leads",
          "lateral-movement-signals",
          "mass-encryption-activity"
        ],
        "objective": "Correlate the suspicious access leads with the observed lateral movement and high-volume file modification patterns to confirm a ransomware-style intrusion chain.",
        "description": "Synthesize the evidence from the entire hunt to confirm a multi-stage intrusion from perimeter access to data impact.",
        "max_iterations": 6,
        "expected_signal": "A comprehensive timeline of the attack per host.",
        "success_criteria": "A timeline of the intrusion from initial web probe or logon anomaly to lateral movement and final file modification, citing specific rows."
      },
      "parents": [
        {
          "id": "lateral-movement-signals",
          "kind": "merge"
        },
        {
          "id": "mass-encryption-activity",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-impact",
      "type": "checkpoint",
      "label": "Route on verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the analyze-intrusion-chain verdict is malicious or suspicious for at least one host",
        "condition": "the analyze-intrusion-chain verdict is malicious or suspicious for at least one host",
        "blind_spot": "agent-visibility-gap",
        "confidence": "high",
        "description": "Direct the analyst based on the severity and confidence of the intrusion evidence.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "analyze-intrusion-chain"
        }
      ]
    },
    {
      "id": "contain-impacted-host",
      "type": "action",
      "label": "Isolate impacted hosts",
      "config": {
        "target": "endpoint",
        "description": "Stop the spread of ransomware and lateral movement by isolating the beachhead and any encrypted hosts.",
        "instructions": "Isolate the hosts identified in the analyze-intrusion-chain verdict. Preserve memory and file system state for forensic analysis.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-impact",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "incident-investigation",
      "type": "task",
      "label": "Incident review",
      "config": {
        "assignee": "analyst",
        "description": "Conduct a deeper forensic review of the findings to identify the root cause and initial entry vector.",
        "instructions": "Examine the processes and source IPs identified in the agent read. Verify the software versions potentially exploited on the perimeter hosts and the extent of data encryption."
      },
      "parents": [
        {
          "id": "route-on-impact",
          "branch": "default"
        },
        {
          "id": "route-on-impact",
          "branch": "on_unavailable"
        },
        {
          "id": "contain-impacted-host"
        }
      ]
    },
    {
      "id": "remediation-and-lessons",
      "type": "task",
      "label": "Close out and remediation",
      "config": {
        "assignee": "analyst",
        "description": "Complete the hunt and document findings to improve central visibility and cross-campus coordination.",
        "instructions": "Document the gaps in visibility between campuses. Recommend centralizing authentication monitoring and perimeter vulnerability scanning to prevent lateral movement from reaching sensitive subnets."
      },
      "parents": [
        {
          "id": "route-on-impact",
          "branch": "on_refutes"
        },
        {
          "id": "incident-investigation"
        }
      ]
    }
  ]
}