---
analysis: A single rule may fire on a known ransomware file extension; this hunt pivots
  from the initial web exploit through credential anomalies to lateral subnet traversal,
  confirming the entire intrusion chain before the impact becomes irreversible.
blind_spots:
- id: agent-visibility-gap
  question: whether the intrusion is occurring on unmanaged legacy campuses
  requires: full agent enrollment across all campuses
  risk: Fragmentation means the hunt only sees campuses with enrolled agents, leaving
    a blind spot in less-resourced departments.
- id: encrypted-payload-content
  question: what specific exploit payload was delivered over HTTPS
  requires: TLS decryption on the proxy or hb_http_activity with body data
  risk: Adversaries can bypass URI-only monitoring by using POST bodies or encrypted
    channels for exploitation.
  stage: initial-access-exploit
- id: intra-vlan-blind-spot
  question: whether lateral movement is happening within a single campus VLAN
  requires: agent-to-agent network telemetry or flow logs
  risk: If network monitoring only sees cross-campus (inter-VLAN) traffic, movement
    within a department may remain invisible.
  stage: cross-campus-lateral-movement
coverage:
- stage: initial-access-exploit
  status: covered
  steps:
  - http-exploit-patterns
- stage: suspicious-authentication-sequence
  status: covered
  steps:
  - failed-logon-bursts
- stage: cross-campus-lateral-movement
  status: covered
  steps:
  - lateral-movement-signals
- stage: ransomware-data-encryption
  status: covered
  steps:
  - mass-encryption-activity
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: promote-to-detection
  justification: The fragmentation of university networks often hides cross-campus
    attacks; this hunt identifies the early probes and the lateral progression that
    precedes campus-wide ransomware deployment.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An adversary exploits a vulnerable internet-facing application to establish
  a foothold, moves laterally across campus network boundaries using compromised credentials,
  and deploys ransomware to sensitive research or student data.
labels:
- hunt
- attack.t1190
- attack.t1078
- attack.t1021
- attack.t1486
- impact
- initial access
- lateral movement
name: Edge Exploitation and Cross-Campus Ransomware Impact
parameters:
  lookback_days:
    default: '14'
    description: Days of history to examine.
    from:
      kind: article
      observed: '2026-09-30'
      ref: https://www.rapid7.com/blog/post/it-higher-education-under-siege-fragmented-security
    type: number
  scope_hosts:
    default: []
    description: Optional list of hosts identified as exposed or vulnerable to focus
      the hunt.
    from:
      kind: manual
      observed: '2026-09-30'
      ref: hunt-designer
    type: list[host]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.rapid7.com/blog/post/it-higher-education-under-siege-fragmented-security
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Focus on perimeter web servers, VPN gateways, and known legacy research
  platforms that lack centralized management. Use the list[host] parameter to narrow
  the hunt to these specific assets if the inventory is large.
references:
- name: "Rapid7 \u2014 Higher education is under siege, and fragmented security is\
    \ making it harder to respond"
  url: https://www.rapid7.com/blog/post/it-higher-education-under-siege-fragmented-security
scenario:
  stages:
  - name: Exploitation of Public-Facing Applications
    observables:
    - exploitation of zero-day vulnerabilities
    - attacks against internet-facing hosts
    - unusual HTTP requests to web servers
    - active exploitation of unpatched legacy systems
    slug: initial-access-exploit
    tactic: initial-access
    techniques:
    - T1190
  - name: Suspicious Login Sequences
    observables:
    - suspicious login sequence across campuses
    - anomalous authentication timing
    - logins from unusual source IPs
    - sequential authentication failures followed by success
    slug: suspicious-authentication-sequence
    tactic: initial-access
    techniques:
    - T1078
  - name: Cross-Campus Lateral Movement
    observables:
    - network connections between distinct campus subnets
    - remote activity moving toward research or financial environments
    - use of internal network boundaries to bypass local security
    slug: cross-campus-lateral-movement
    tactic: lateral-movement
    techniques:
    - T1021
  - name: Data Encryption for Impact
    observables:
    - high-volume file modification
    - renaming of student and research records
    - deployment of ransomware binaries
    - interruption of teaching and administrative operations
    slug: ransomware-data-encryption
    tactic: impact
    techniques:
    - T1486
  summary: Higher education institutions face a high volume of cyberattacks where
    attackers exploit public-facing applications or vulnerable legacy systems to gain
    initial access. Once inside, they utilize suspicious login sequences to move laterally
    across fragmented campus networks, eventually deploying ransomware to encrypt
    sensitive research, student, and financial data.
severity: medium
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  identity:
    category: identity
    name: Identity / sign-in telemetry
    telemetry:
    - identity
  network:
    category: network
    name: Network telemetry
    telemetry:
    - network
  web:
    category: siem
    name: Web server / proxy logs
    telemetry:
    - network
tlp: clear
type: investigation
---


# Edge Exploitation and Cross-Campus Ransomware Impact

This hunt identifies the full lifecycle of an intrusion within fragmented university environments. It starts by scoping internet-facing software that may be vulnerable to exploitation, then pivots to identify suspicious HTTP probing and anomalous authentication sequences. In the second phase, it examines follow-on activity: lateral movement between distinct campus subnets and high-volume file modifications indicative of ransomware encryption. The phased flow allows an agent to weigh initial access evidence before correlating it with the eventual impact, addressing the visibility gaps that often exist in multi-campus institutions.

## find-vulnerable-perimeter
<!-- Identify exposed web services -->
Identify hosts running web-facing software that frequently serves as an entry point for university intrusions.

```sqlite target=endpoint role=scoping
~~~yaml
expected: A list of hosts running common perimeter software. Silence indicates no
  such software is tracked in the inventory.
reads:
- device_hostname
- package_name
- package_version
silence: not_evidence_of_absence
source: hb_software_inventory
verified: dry-run
verified_at: '2026-10-01'
~~~
SELECT device_hostname, package_name, package_version FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%apache%' OR LOWER(package_name) LIKE '%nginx%' OR LOWER(package_name) LIKE '%exchange%' OR LOWER(package_name) LIKE '%vpn%')
```

## parallel-initial
<!-- Analyze access and authentication -->
parallel:
- → http-exploit-patterns
- → failed-logon-bursts
join: → triage-access-leads

## http-exploit-patterns
<!-- Unusual HTTP probing -->
Find unusual HTTP requests to the identified perimeter hosts that may indicate exploitation of legacy systems or zero-day flaws.

```sqlite target=web role=triage params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: Rare HTTP error paths from a single source IP. Silence indicates no uncommon
  error activity on the perimeter.
reads:
- device_hostname
- url_path
- status_code
- src_endpoint_ip
- time
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-10-01'
~~~
SELECT device_hostname, url_path, status_code, src_endpoint_ip, COUNT(*) as request_count FROM hb_http_activity WHERE (status_code >= 400) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, url_path, status_code, src_endpoint_ip HAVING request_count < 20
```

## failed-logon-bursts
<!-- Failed logon burst stacking -->
Stack-count authentication failures by user and source IP to identify brute-force or credential-stuffing sequences that may precede campus-wide access.

```sqlite target=identity role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: A single IP or user account failing authentication repeatedly across multiple
  hosts or in high volume.
prevalence:
  by: device_hostname
  key:
  - actor_user_name
  - src_endpoint_ip
  rare_below: 3
reads:
- actor_user_name
- src_endpoint_ip
- device_hostname
- status_id
- time
silence: not_evidence_of_absence
source: hb_auth_signin
verified: dry-run
verified_at: '2026-10-01'
~~~
SELECT actor_user_name, src_endpoint_ip, COUNT(DISTINCT device_hostname) as host_count, COUNT(*) as fail_count, MIN(time) as first_seen FROM hb_auth_signin WHERE status_id = 2 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, src_endpoint_ip HAVING host_count <= 3 AND fail_count > 10
```

## triage-access-leads
<!-- Weigh initial access evidence -->
```agent target=hunter
cite: required
context:
- http-exploit-patterns
- failed-logon-bursts
max_iterations: 4
objective: Identify whether the combined HTTP probing and authentication patterns
  indicate an active exploitation or credential-based intrusion attempt.
success_criteria: A verdict of malicious | suspicious | benign per source IP or user
  account, citing the relevant logs.
tools:
- endpoint
- identity
- network
- web
```

## parallel-follow-on
<!-- Analyze lateral movement and impact -->
parallel:
- → lateral-movement-signals
- → mass-encryption-activity
join: → analyze-intrusion-chain

## lateral-movement-signals
<!-- Administrative lateral traffic -->
Identify network connections using administrative protocols originating from perimeter hosts, signifying lateral movement toward sensitive zones.

```sqlite target=network role=enrichment params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: Rare administrative connections from web servers or VPN gateways to internal
  endpoints. Silence means no uncommon admin traffic was detected from the perimeter.
reads:
- device_hostname
- dst_endpoint_ip
- dst_endpoint_port
- process_name
- time
silence: not_evidence_of_absence
source: hb_network_connection
verified: dry-run
verified_at: '2026-10-01'
~~~
SELECT device_hostname, dst_endpoint_ip, dst_endpoint_port, process_name, COUNT(*) as conn_count, MIN(time) as first_seen FROM hb_network_connection WHERE direction = 'outbound' AND dst_endpoint_port IN (22, 445, 3389, 5985) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, dst_endpoint_ip, dst_endpoint_port, process_name HAVING conn_count < 10
```

## mass-encryption-activity
<!-- High-volume file modifications -->
Identify processes modifying a massive number of files with ransomware-associated extensions across the fleet.

```sqlite target=endpoint role=detection-candidate params=(lookback_days=lookback_days)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: A single process renaming or updating hundreds of files within a short window.
  Silence proves absence of mass encryption for the known extensions.
prevalence:
  by: device_hostname
  key:
  - process_name
  rare_below: 5
reads:
- device_hostname
- process_name
- file_path
- activity_id
- time
silence: evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-10-01'
~~~
SELECT device_hostname, process_name, COUNT(DISTINCT file_path) as mod_count, MIN(time) as first_seen FROM hb_file_activity WHERE (activity_id = 3 OR activity_id = 5) AND (LOWER(file_path) LIKE '%.crypt%' OR LOWER(file_path) LIKE '%.locked%' OR LOWER(file_path) LIKE '%.enc%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name HAVING mod_count > 500
```

## analyze-intrusion-chain
<!-- Triage ransomware progression -->
```agent target=hunter
cite: required
context:
- triage-access-leads
- lateral-movement-signals
- mass-encryption-activity
max_iterations: 6
objective: Correlate the suspicious access leads with the observed lateral movement
  and high-volume file modification patterns to confirm a ransomware-style intrusion
  chain.
success_criteria: A timeline of the intrusion from initial web probe or logon anomaly
  to lateral movement and final file modification, citing specific rows.
tools:
- endpoint
- identity
- network
- web
```

## route-on-impact
<!-- Route on verdict -->
if~: "the analyze-intrusion-chain verdict is malicious or suspicious for at least one host" (confidence: high, judge=hunter)
then: → contain-impacted-host
indeterminate: → incident-investigation
unavailable: → incident-investigation (blind_spot: agent-visibility-gap)
else: → remediation-and-lessons

## contain-impacted-host
<!-- Isolate impacted hosts -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the hosts identified in the analyze-intrusion-chain verdict. Preserve memory and file system state for forensic analysis.
```
→ incident-investigation

## incident-investigation
<!-- Incident review -->
```manual target=analyst
Examine the processes and source IPs identified in the agent read. Verify the software versions potentially exploited on the perimeter hosts and the extent of data encryption.
```
→ remediation-and-lessons

## remediation-and-lessons
<!-- Close out and remediation -->
```manual target=analyst
Document the gaps in visibility between campuses. Recommend centralizing authentication monitoring and perimeter vulnerability scanning to prevent lateral movement from reaching sensitive subnets.
```
→ end
