{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Internal network coercion via DHCPv6/IPv6 is a critical credential-access vector that is often overlooked in traditional network monitoring. Detecting the rare rogue services and the prerequisite vulnerability provides a proactive defense against Kerberos relay attacks."
      },
      "name": "Internal Coercion and Editor Persistence",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1190",
        "attack.t1021.001"
      ],
      "series": {
        "slug": "metasploit-wrap-up-belgian-waffles-chocolates-and-modules-frites",
        "index": 2,
        "title": "Metasploit Wrap Up: Belgian Waffles, Chocolates, and\u2026Modules-Frites?",
        "total": 2
      },
      "related": [
        {
          "hunt": "gitlab-file-read-cve-2026-85706",
          "reason": "GitLab exploitation is a perimeter access vector handled by its own hunt.",
          "relation": "out-of-scope-alternative"
        },
        {
          "hunt": "exploitation-web-facing-gitlab-langflow",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "network": {
          "name": "Network telemetry",
          "category": "network",
          "telemetry": [
            "network"
          ]
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "This is a hunt because it uses fleet-wide prevalence to distinguish authorized network services from rogue protocol spoofers and correlates them with specific editor plugin persistence that standard EDR rules often miss.",
      "coverage": [
        {
          "stage": "ipv6-dns-takeover-coercion",
          "steps": [
            "scope-vulnerable-hosts",
            "rare-network-activity"
          ],
          "status": "covered"
        },
        {
          "stage": "rdp-anomalous-interaction",
          "steps": [
            "rare-network-activity"
          ],
          "status": "covered"
        },
        {
          "stage": "kate-plugin-persistence",
          "steps": [
            "kate-persistence"
          ],
          "status": "covered"
        },
        {
          "stage": "gitlab-unauthenticated-file-read",
          "reason": "Belongs to another part of the 'Metasploit Wrap Up: Belgian Waffles, Chocolates, and\u2026Modules-Frites?' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "langflow-authenticated-rce",
          "reason": "Belongs to another part of the 'Metasploit Wrap Up: Belgian Waffles, Chocolates, and\u2026Modules-Frites?' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "GitLab Unauthenticated Arbitrary File Read",
            "slug": "gitlab-unauthenticated-file-read",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "CVE-2026-85706",
              "HTTP requests to GitLab repository commits APIs",
              "HTTP requests to GitLab repository files APIs",
              "Module: gather/gitlab_file_read_cve_2026_85706",
              "Affected GitLab versions 18.7 up to 19.3.2"
            ]
          },
          {
            "name": "Langflow AI Authenticated RCE",
            "slug": "langflow-authenticated-rce",
            "tactic": "execution",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "CVE-2026-18729",
              "Authenticated HTTP requests to Langflow custom components",
              "Arbitrary Python code execution via Langflow process",
              "Module: multi/http/langflow_auth_rce_cve_2026_18729",
              "Langflow versions 1.11.1 and below"
            ]
          },
          {
            "name": "IPv6 DNS Takeover Coercion",
            "slug": "ipv6-dns-takeover-coercion",
            "tactic": "credential-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "CVE-2026-20929",
              "Rogue DHCPv6 server activity on UDP port 547",
              "Rogue IPv6 Router Advertisements (RA)",
              "Kerberos authentication relay attempts",
              "Module: spoof/dhcp/dhcpv6_dns_takeover",
              "Module: spoof/ipv6/ipv6_ra_dns_takeover"
            ]
          },
          {
            "name": "Anomalous RDP Interaction",
            "slug": "rdp-anomalous-interaction",
            "tactic": "lateral-movement",
            "techniques": [
              "T1021.001"
            ],
            "observables": [
              "Unexpected size RDP packets and responses",
              "Anomalous Remote Interactive logons",
              "RDP connections to internal assets on port 3389"
            ]
          },
          {
            "name": "Kate Plugin Persistence",
            "slug": "kate-plugin-persistence",
            "tactic": "persistence",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "Writes to Kate editor plugin directories",
              "New plugin configuration files for Kate editor",
              "Module: multi/persistence/kate_plugin"
            ]
          }
        ],
        "summary": "Recent Metasploit updates introduced exploitation modules for unauthenticated file read in GitLab (CVE-2026-85706) and authenticated RCE in Langflow AI (CVE-2026-18729). The release also features native IPv6 DNS takeover modules for Kerberos relay attacks and a new persistence mechanism targeting the Kate text editor."
      },
      "severity": "high",
      "rationale": "The hunt focuses on systems vulnerable to CVE-2026-20929 as they are the primary targets for the network coercion module. Behavioral queries are then filtered to these hosts to detect active exploitation.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary is using rogue DHCPv6 services to perform DNS takeover for Kerberos relaying, or has established persistence via unauthorized Kate editor plugins on compromised hosts.",
      "parameters": {
        "cve_id": {
          "from": {
            "ref": "rapid7-metasploit-wrapup-2026-09",
            "kind": "article",
            "observed": "2026-09-25"
          },
          "type": "string",
          "default": "CVE-2026-20929",
          "description": "The Windows HTTP.sys vulnerability used for coercion."
        },
        "scope_hosts": {
          "from": {
            "ref": "Analyst scoping",
            "kind": "manual"
          },
          "type": "list[host]",
          "default": [],
          "description": "List of hostnames from the scoping step to focus behavioral analysis; leave empty to hunt across the entire estate."
        },
        "lookback_days": {
          "from": {
            "ref": "Standard lookback window",
            "kind": "manual"
          },
          "type": "number",
          "default": "14",
          "description": "Days of historical telemetry to examine."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-belgian-waffles-chocolates-and-modules-frites",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-belgian-waffles-chocolates-and-modules-frites",
          "name": "Metasploit Wrap Up: Belgian Waffles, Chocolates, and\u2026Modules-Frites?"
        }
      ],
      "blind_spots": [
        {
          "id": "no-endpoint-telemetry",
          "risk": "A rogue DHCPv6 server on an unmanaged device can still poison the network, but this hunt only detects the server-side behavior if the attacker uses an enrolled host.",
          "stage": "ipv6-dns-takeover-coercion",
          "question": "Are there rogue services running on non-enrolled hosts?",
          "requires": "Endpoint agent coverage"
        },
        {
          "id": "no-kerberos-relay-visibility",
          "risk": "The hunt detects the coercion setup (the rogue DNS) but cannot confirm if a relay successfuly occurred without AD-specific authentication telemetry.",
          "stage": "ipv6-dns-takeover-coercion",
          "question": "Was a Kerberos relay attack actually performed?",
          "requires": "Domain Controller authentication logs"
        }
      ]
    },
    "name": "Internal Coercion and Editor Persistence",
    "description": "This hunt identifies internal network protocol abuse and application-specific persistence following the Metasploit September 2026 update. It first scopes systems vulnerable to the HTTP.sys coercion vector (CVE-2026-20929) and then searches in parallel for rare network activity on DHCPv6 (UDP 547) or RDP (3389) ports, and unauthorized file activity in Kate editor plugin directories. An agent weighs these behavioral signals to distinguish rogue services and persistence mechanisms from legitimate administrative activity."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "metasploit-wrap-up-belgian-waffles-chocolates-and-modules-frites",
          "index": 2,
          "title": "Metasploit Wrap Up: Belgian Waffles, Chocolates, and\u2026Modules-Frites?",
          "total": 2
        },
        "coverage": [
          {
            "stage": "ipv6-dns-takeover-coercion",
            "steps": [
              "scope-vulnerable-hosts",
              "rare-network-activity"
            ],
            "status": "covered"
          },
          {
            "stage": "rdp-anomalous-interaction",
            "steps": [
              "rare-network-activity"
            ],
            "status": "covered"
          },
          {
            "stage": "kate-plugin-persistence",
            "steps": [
              "kate-persistence"
            ],
            "status": "covered"
          },
          {
            "stage": "gitlab-unauthenticated-file-read",
            "reason": "Belongs to another part of the 'Metasploit Wrap Up: Belgian Waffles, Chocolates, and\u2026Modules-Frites?' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "langflow-authenticated-rce",
            "reason": "Belongs to another part of the 'Metasploit Wrap Up: Belgian Waffles, Chocolates, and\u2026Modules-Frites?' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary is using rogue DHCPv6 services to perform DNS takeover for Kerberos relaying, or has established persistence via unauthorized Kate editor plugins on compromised hosts.",
        "blind_spots": [
          {
            "id": "no-endpoint-telemetry",
            "risk": "A rogue DHCPv6 server on an unmanaged device can still poison the network, but this hunt only detects the server-side behavior if the attacker uses an enrolled host.",
            "stage": "ipv6-dns-takeover-coercion",
            "question": "Are there rogue services running on non-enrolled hosts?",
            "requires": "Endpoint agent coverage"
          },
          {
            "id": "no-kerberos-relay-visibility",
            "risk": "The hunt detects the coercion setup (the rogue DNS) but cannot confirm if a relay successfuly occurred without AD-specific authentication telemetry.",
            "stage": "ipv6-dns-takeover-coercion",
            "question": "Was a Kerberos relay attack actually performed?",
            "requires": "Domain Controller authentication logs"
          }
        ],
        "scoping_notes": "The hunt focuses on systems vulnerable to CVE-2026-20929 as they are the primary targets for the network coercion module. Behavioral queries are then filtered to these hosts to detect active exploitation.",
        "beyond_detection": "This is a hunt because it uses fleet-wide prevalence to distinguish authorized network services from rogue protocol spoofers and correlates them with specific editor plugin persistence that standard EDR rules often miss."
      }
    },
    {
      "id": "scope-vulnerable-hosts",
      "type": "query",
      "label": "Identify vulnerable hosts",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_uid, resource_uid, severity, collected_at FROM hb_vulnerability_finding WHERE cve_uid = '{{cve_id}}' AND status != 'suppressed'",
        "surface": "hb_vulnerability_finding",
        "description": "Locate systems susceptible to HTTP.sys privilege elevation which allows the network coercion described in the research.",
        "expected_signal": "A list of host identifiers currently vulnerable to the coercion vector. Silence indicates the estate is patched against this specific exploit."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify vulnerable hosts",
        "reads": [
          "device_uid",
          "resource_uid",
          "severity",
          "collected_at"
        ],
        "source": "hb_vulnerability_finding",
        "target": "endpoint",
        "content": "SELECT device_uid, resource_uid, severity, collected_at FROM hb_vulnerability_finding WHERE cve_uid = '{{cve_id}}' AND status != 'suppressed'",
        "silence": "not_evidence_of_absence",
        "expected": "A list of host identifiers currently vulnerable to the coercion vector. Silence indicates the estate is patched against this specific exploit.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "rare-network-activity",
      "type": "query",
      "label": "Rare network activity on sensitive ports",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "network",
        "content": "SELECT device_hostname, process_name, dst_endpoint_port, COUNT(*) AS connections, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_network_connection WHERE (dst_endpoint_port = 547 OR dst_endpoint_port = 3389) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name, dst_endpoint_port",
        "surface": "hb_network_connection",
        "description": "Find processes listening on or initiating connections on DHCPv6 (547) and RDP (3389) ports.",
        "expected_signal": "Anomalous processes using DHCPv6 or RDP on systems that do not usually provide these services. Silence in a complete log indicates the absence of this specific network coercion."
      },
      "parents": [
        {
          "id": "scope-vulnerable-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare network activity on sensitive ports",
        "reads": [
          "device_hostname",
          "process_name",
          "dst_endpoint_port",
          "time"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT device_hostname, process_name, dst_endpoint_port, COUNT(*) AS connections, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_network_connection WHERE (dst_endpoint_port = 547 OR dst_endpoint_port = 3389) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name, dst_endpoint_port",
        "silence": "evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Anomalous processes using DHCPv6 or RDP on systems that do not usually provide these services. Silence in a complete log indicates the absence of this specific network coercion.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_name",
            "dst_endpoint_port"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "kate-persistence",
      "type": "query",
      "label": "Kate editor plugin persistence",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, file_path, file_name, process_name, actor_user_name, time FROM hb_file_activity WHERE (LOWER(file_path) LIKE '%/kate/plugins/%' OR LOWER(file_path) LIKE '%\\\\kate\\\\plugins\\\\%') AND activity_id = 1 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_file_activity",
        "description": "Detect rare file creations in Kate editor plugin directories used for multi-platform persistence.",
        "expected_signal": "Creation of new plugin files by unexpected processes. Benign results include legitimate plugin installations by the user."
      },
      "parents": [
        {
          "id": "scope-vulnerable-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Kate editor plugin persistence",
        "reads": [
          "device_hostname",
          "file_path",
          "file_name",
          "process_name",
          "actor_user_name",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, file_path, file_name, process_name, actor_user_name, time FROM hb_file_activity WHERE (LOWER(file_path) LIKE '%/kate/plugins/%' OR LOWER(file_path) LIKE '%\\\\kate\\\\plugins\\\\%') AND activity_id = 1 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Creation of new plugin files by unexpected processes. Benign results include legitimate plugin installations by the user.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "file_path"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "triage-findings",
      "type": "analytic",
      "label": "Triage behavioral evidence",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "network"
        ],
        "context": [
          "scope-vulnerable-hosts",
          "rare-network-activity",
          "kate-persistence"
        ],
        "objective": "Determine if any host vulnerable to CVE-2026-20929 shows evidence of rogue DHCPv6/RDP activity or unauthorized Kate plugin persistence. Identify if the same process is responsible for the network listener and any file writes.",
        "description": "Weigh the vulnerability state, rare network activity, and file persistence together to identify active intrusion.",
        "max_iterations": 5,
        "expected_signal": "A per-host verdict citing specific processes, ports, and file paths.",
        "success_criteria": "A verdict of malicious, suspicious, or benign for each host, citing relevant rows from the behavioral queries."
      },
      "parents": [
        {
          "id": "rare-network-activity",
          "kind": "merge"
        },
        {
          "id": "kate-persistence",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-verdict",
      "type": "checkpoint",
      "label": "Route on verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage verdict is malicious for any host exhibiting rogue DHCPv6 listeners or unauthorized editor plugins",
        "condition": "the triage verdict is malicious for any host exhibiting rogue DHCPv6 listeners or unauthorized editor plugins",
        "blind_spot": "no-endpoint-telemetry",
        "confidence": "high",
        "description": "Route the hunt to containment if malicious activity is confirmed.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-findings"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate host",
      "config": {
        "target": "endpoint",
        "description": "Isolate the compromised host to stop rogue network protocol spoofing and prevent lateral movement.",
        "instructions": "Isolate the host immediately. Terminate the process identified as a rogue DHCPv6 or RDP listener.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "manual-review",
      "type": "task",
      "label": "Analyst forensic review",
      "config": {
        "assignee": "analyst",
        "description": "Verify the agent's verdict and examine the identified plugin or listener process.",
        "instructions": "Inspect the file contents in the Kate plugin directory. Verify if the process listening on port 547 or 3389 matches an authorized network management tool."
      },
      "parents": [
        {
          "id": "route-verdict",
          "branch": "default"
        },
        {
          "id": "route-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "remediate-vulnerability",
      "type": "task",
      "label": "Remediate HTTP.sys vulnerability",
      "config": {
        "assignee": "analyst",
        "description": "Patch the underlying vulnerability used as a coercion vector.",
        "instructions": "Apply the latest Windows updates to all hosts identified in the scoping step to mitigate CVE-2026-20929."
      },
      "parents": [
        {
          "id": "route-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "manual-review"
        }
      ]
    }
  ]
}