{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "CVE-2026-94127 allows unauthenticated RCE on the perimeter. F5 BIG-IP systems are critical infrastructure that mediate access to internal resources; a single compromise provides a bridgehead into the entire internal network."
      },
      "name": "F5 BIG-IP APM OAuth RCE Exploitation",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1190"
      ],
      "related": [
        {
          "hunt": "f5-tmui-control-plane-rce",
          "reason": "This hunt focuses on the APM data plane; exploitation of the TMUI management interface is a separate attack surface.",
          "relation": "sibling"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "network": {
          "name": "Network telemetry",
          "category": "network",
          "telemetry": [
            "network"
          ]
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A standard detection rule would only alert on the presence of a CVE finding. This hunt combines vulnerability state with behavioral analysis of the data plane\u2014HTTP path anomalies and outbound connection prevalence\u2014to find active exploitation that vulnerability scanners cannot see.",
      "coverage": [
        {
          "stage": "vulnerability-assessment-f5",
          "steps": [
            "vulnerability-lead"
          ],
          "status": "covered"
        },
        {
          "stage": "exploit-crafted-traffic-oauth",
          "steps": [
            "http-traffic-analysis"
          ],
          "status": "covered"
        },
        {
          "stage": "post-exploit-network-activity",
          "steps": [
            "outbound-connection-baseline"
          ],
          "status": "covered"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Identification of Vulnerable F5 BIG-IP Instances",
            "slug": "vulnerability-assessment-f5",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "CVE-2026-94127",
              "BIG-IP 21.1.0",
              "BIG-IP 17.5.0",
              "BIG-IP 17.1.0",
              "F5 BIG-IP APM",
              "OAuth profile configured",
              "APM access policy configured"
            ]
          },
          {
            "name": "Unauthenticated RCE via Crafted OAuth Traffic",
            "slug": "exploit-crafted-traffic-oauth",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "specifically crafted traffic",
              "unauthenticated network access to virtual server",
              "heap-based buffer overflow attack"
            ]
          },
          {
            "name": "Post-Exploitation Network Activity",
            "slug": "post-exploit-network-activity",
            "tactic": "execution",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "remote code execution",
              "outbound network connections from BIG-IP data plane"
            ]
          }
        ],
        "summary": "An unauthenticated attacker can exploit a critical heap-based buffer overflow in F5 BIG-IP Access Policy Manager (APM) via CVE-2026-94127. Exploitation requires a virtual server with both an APM access policy and an OAuth profile and allows for remote code execution (RCE) on the device's data plane."
      },
      "severity": "high",
      "rationale": "Start with internet-facing F5 BIG-IP appliances. Use vulnerability scanner data (Wiz, Inspector) to quickly narrow down to devices missing the September 2026 hotfixes.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An unauthenticated attacker is exploiting a heap-based buffer overflow in F5 BIG-IP APM by sending crafted traffic to virtual servers configured with OAuth profiles to achieve code execution.",
      "parameters": {
        "cve_id": {
          "from": {
            "ref": "rapid7",
            "kind": "article",
            "observed": "2026-09-23"
          },
          "type": "string",
          "default": "CVE-2026-94127",
          "description": "Target CVE identifier for F5 BIG-IP APM."
        },
        "oauth_paths": {
          "type": "list[path]",
          "default": [
            "/oauth/token",
            "/oauth/authorize",
            "/f5-oauth/token",
            "/f5-oauth/authorize"
          ],
          "description": "Standard OAuth paths for BIG-IP APM likely to be targeted by exploitation traffic."
        },
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Specific hostnames identified as vulnerable to focus the behavioral analysis."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine for vulnerability findings and behavioral traffic."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.rapid7.com/blog/post/etr-cve-2026-94127-critical-unauthenticated-rce-in-f5-big-ip-apm",
          "gates": [
            "dry-run",
            "lint",
            "critic"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.rapid7.com/blog/post/etr-cve-2026-94127-critical-unauthenticated-rce-in-f5-big-ip-apm",
          "name": "Rapid7 \u2014 CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM"
        }
      ],
      "blind_spots": [
        {
          "id": "missing-vulnerability-data",
          "risk": "A newly deployed or unmanaged F5 appliance may not appear in hb_vulnerability_finding, causing the hunt to terminate early.",
          "stage": "vulnerability-assessment-f5",
          "question": "Are all F5 devices currently being scanned by vulnerability management tools?",
          "requires": "recent vulnerability scan against network appliances"
        },
        {
          "id": "incomplete-appliance-telemetry",
          "risk": "If only high-level flow data is available without HTTP-level detail, the crafted traffic required for exploitation cannot be identified.",
          "stage": "exploit-crafted-traffic-oauth",
          "question": "Does the environment capture the URL query parameters and full paths of traffic reaching the APM?",
          "requires": "decrypted HTTP traffic logs from the F5 data plane"
        }
      ]
    },
    "name": "F5 BIG-IP APM OAuth RCE Exploitation",
    "description": "This hunt targets the exploitation of CVE-2026-94127, a critical RCE vulnerability in F5 BIG-IP APM. The vulnerability requires a specific configuration: a virtual server with both an APM access policy and an OAuth profile. This hunt uses a gated flow, first identifying vulnerable F5 appliances via vulnerability scan results. If vulnerable hosts are present, it performs a fan-out to examine HTTP traffic for OAuth-related anomalies and identifies rare outbound network connections from those appliances that may indicate a successful shell callback or data exfiltration."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "coverage": [
          {
            "stage": "vulnerability-assessment-f5",
            "steps": [
              "vulnerability-lead"
            ],
            "status": "covered"
          },
          {
            "stage": "exploit-crafted-traffic-oauth",
            "steps": [
              "http-traffic-analysis"
            ],
            "status": "covered"
          },
          {
            "stage": "post-exploit-network-activity",
            "steps": [
              "outbound-connection-baseline"
            ],
            "status": "covered"
          }
        ],
        "rationale": "An unauthenticated attacker is exploiting a heap-based buffer overflow in F5 BIG-IP APM by sending crafted traffic to virtual servers configured with OAuth profiles to achieve code execution.",
        "blind_spots": [
          {
            "id": "missing-vulnerability-data",
            "risk": "A newly deployed or unmanaged F5 appliance may not appear in hb_vulnerability_finding, causing the hunt to terminate early.",
            "stage": "vulnerability-assessment-f5",
            "question": "Are all F5 devices currently being scanned by vulnerability management tools?",
            "requires": "recent vulnerability scan against network appliances"
          },
          {
            "id": "incomplete-appliance-telemetry",
            "risk": "If only high-level flow data is available without HTTP-level detail, the crafted traffic required for exploitation cannot be identified.",
            "stage": "exploit-crafted-traffic-oauth",
            "question": "Does the environment capture the URL query parameters and full paths of traffic reaching the APM?",
            "requires": "decrypted HTTP traffic logs from the F5 data plane"
          }
        ],
        "scoping_notes": "Start with internet-facing F5 BIG-IP appliances. Use vulnerability scanner data (Wiz, Inspector) to quickly narrow down to devices missing the September 2026 hotfixes.",
        "beyond_detection": "A standard detection rule would only alert on the presence of a CVE finding. This hunt combines vulnerability state with behavioral analysis of the data plane\u2014HTTP path anomalies and outbound connection prevalence\u2014to find active exploitation that vulnerability scanners cannot see."
      }
    },
    {
      "id": "vulnerability-lead",
      "type": "query",
      "label": "Identify Vulnerable F5 Instances",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT resource_uid, cve_uid, severity, status, collected_at FROM hb_vulnerability_finding WHERE cve_uid = '{{cve_id}}' AND status != 'suppressed' AND collected_at >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_vulnerability_finding",
        "description": "Identify any F5 appliances in the inventory that have an active vulnerability finding for CVE-2026-94127.",
        "expected_signal": "Rows identify appliances by resource_uid that are susceptible to the exploit. Silence proves absence of scanned vulnerable instances for the given window."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify Vulnerable F5 Instances",
        "reads": [
          "resource_uid",
          "cve_uid",
          "severity",
          "status",
          "collected_at"
        ],
        "source": "hb_vulnerability_finding",
        "target": "endpoint",
        "content": "SELECT resource_uid, cve_uid, severity, status, collected_at FROM hb_vulnerability_finding WHERE cve_uid = '{{cve_id}}' AND status != 'suppressed' AND collected_at >= datetime('now', '-{{lookback_days}} days')",
        "silence": "evidence_of_absence",
        "expected": "Rows identify appliances by resource_uid that are susceptible to the exploit. Silence proves absence of scanned vulnerable instances for the given window.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "assess-vulnerability-risk",
      "type": "analytic",
      "label": "Assess Vulnerability Lead",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "network",
          "web"
        ],
        "context": [
          "vulnerability-lead"
        ],
        "objective": "Determine if any F5 devices are confirmed vulnerable and list their identifiers for follow-up analysis.",
        "description": "Evaluate the risk from the lead query to decide if behavioral investigation is warranted.",
        "max_iterations": 3,
        "expected_signal": "A verdict on the existence and severity of vulnerable F5 systems in the estate.",
        "success_criteria": "A list of potentially compromised hosts or a clean bill of health."
      },
      "parents": [
        {
          "id": "vulnerability-lead"
        }
      ]
    },
    {
      "id": "gate-on-vulnerability",
      "type": "checkpoint",
      "label": "Gate on Vulnerability Status",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the assess-vulnerability-risk verdict identifies at least one vulnerable appliance",
        "condition": "the assess-vulnerability-risk verdict identifies at least one vulnerable appliance",
        "blind_spot": "missing-vulnerability-data",
        "confidence": "high",
        "description": "Route the hunt based on the presence of vulnerable systems.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "assess-vulnerability-risk"
        }
      ]
    },
    {
      "id": "http-traffic-analysis",
      "type": "query",
      "label": "Analyze OAuth HTTP Traffic",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "web",
        "content": "SELECT device_hostname, src_endpoint_ip, url_path, url_query, status_code, time FROM hb_http_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{oauth_paths}}' || ',', ',' || LOWER(url_path) || ',') > 0 OR LOWER(url_path) LIKE '%/oauth%' OR LOWER(url_path) LIKE '%/f5-oauth%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_http_activity",
        "description": "Search for abnormal HTTP requests targeting OAuth endpoints on vulnerable F5 appliances.",
        "expected_signal": "Clusters of requests to OAuth endpoints, especially those resulting in server errors or originating from unexpected external IPs. Silence means no suspicious OAuth traffic was recorded."
      },
      "parents": [
        {
          "id": "gate-on-vulnerability",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Analyze OAuth HTTP Traffic",
        "reads": [
          "device_hostname",
          "src_endpoint_ip",
          "url_path",
          "url_query",
          "status_code",
          "time"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT device_hostname, src_endpoint_ip, url_path, url_query, status_code, time FROM hb_http_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{oauth_paths}}' || ',', ',' || LOWER(url_path) || ',') > 0 OR LOWER(url_path) LIKE '%/oauth%' OR LOWER(url_path) LIKE '%/f5-oauth%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Clusters of requests to OAuth endpoints, especially those resulting in server errors or originating from unexpected external IPs. Silence means no suspicious OAuth traffic was recorded.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "outbound-connection-baseline",
      "type": "query",
      "label": "Baseline Rare Outbound Connections",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "network",
        "content": "SELECT dst_endpoint_ip, dst_endpoint_port, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_network_connection WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND direction = 'outbound' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_ip, dst_endpoint_port HAVING hosts <= 3 ORDER BY hosts ASC",
        "surface": "hb_network_connection",
        "description": "Identify rare outbound destinations from the appliance data plane which could indicate RCE impact.",
        "expected_signal": "Individual appliances connecting to unique external IP/port pairs not seen across the rest of the F5 fleet. Silence implies the appliances are following standard traffic patterns."
      },
      "parents": [
        {
          "id": "gate-on-vulnerability",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Baseline Rare Outbound Connections",
        "reads": [
          "dst_endpoint_ip",
          "dst_endpoint_port",
          "device_hostname",
          "direction",
          "time"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT dst_endpoint_ip, dst_endpoint_port, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_network_connection WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND direction = 'outbound' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_ip, dst_endpoint_port HAVING hosts <= 3 ORDER BY hosts ASC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Individual appliances connecting to unique external IP/port pairs not seen across the rest of the F5 fleet. Silence implies the appliances are following standard traffic patterns.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "dst_endpoint_ip",
            "dst_endpoint_port"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "triage-exploitation",
      "type": "analytic",
      "label": "Triage Exploitation Evidence",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "network",
          "web"
        ],
        "context": [
          "assess-vulnerability-risk",
          "http-traffic-analysis",
          "outbound-connection-baseline"
        ],
        "objective": "Determine if any vulnerable F5 instance shows signs of active exploitation citing specific rows from the HTTP and network connections queries.",
        "description": "Synthesize the vulnerability status, suspicious traffic, and rare network egress into a high-confidence verdict.",
        "max_iterations": 5,
        "expected_signal": "A verdict of malicious or suspicious for any appliance showing multiple signals of compromise.",
        "success_criteria": "A per-host verdict citing specific evidence from all context steps."
      },
      "parents": [
        {
          "id": "http-traffic-analysis",
          "kind": "merge"
        },
        {
          "id": "outbound-connection-baseline",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-evidence",
      "type": "checkpoint",
      "label": "Route on Exploitation Verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage-exploitation verdict is malicious for at least one vulnerable host",
        "condition": "the triage-exploitation verdict is malicious for at least one vulnerable host",
        "blind_spot": "incomplete-appliance-telemetry",
        "confidence": "high",
        "description": "Decide whether to isolate the appliance or perform further manual review based on the triage verdict.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-exploitation"
        }
      ]
    },
    {
      "id": "isolate-appliance",
      "type": "action",
      "label": "Isolate F5 Appliance",
      "config": {
        "target": "endpoint",
        "description": "Sever the network path for the compromised appliance to prevent lateral movement or exfiltration.",
        "instructions": "Isolate the compromised F5 BIG-IP appliance at the switch or network security group level. Disable the affected APM virtual servers immediately.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-evidence",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Review Appliance Logs and Configuration",
      "config": {
        "assignee": "analyst",
        "description": "Manually verify the presence of a vulnerable configuration (APM Access Policy + OAuth Profile) and check for process-level evidence of exploitation.",
        "instructions": "Review the BIG-IP configuration to confirm if an APM Access Policy and an OAuth Profile are assigned to the target virtual server. Check /var/log/tmm and /var/log/apm for SIGSEGV crashes or memory errors that correspond with the timing of suspicious traffic."
      },
      "parents": [
        {
          "id": "gate-on-vulnerability",
          "branch": "default"
        },
        {
          "id": "gate-on-vulnerability",
          "branch": "on_unavailable"
        },
        {
          "id": "route-on-evidence",
          "branch": "default"
        },
        {
          "id": "route-on-evidence",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-appliance"
        }
      ]
    },
    {
      "id": "final-close-out",
      "type": "task",
      "label": "Final Close-out",
      "config": {
        "assignee": "analyst",
        "description": "Ensure vulnerable but unexploited systems are patched and document the hunt results.",
        "instructions": "Document the findings. For any appliance identified as vulnerable but not exploited, apply the F5 hotfix immediately. If exploitation was confirmed, initiate the Incident Response protocol."
      },
      "parents": [
        {
          "id": "gate-on-vulnerability",
          "branch": "on_refutes"
        },
        {
          "id": "route-on-evidence",
          "branch": "on_refutes"
        },
        {
          "id": "analyst-review"
        }
      ]
    }
  ]
}