Internal Coercion and Editor Persistence
An adversary is using rogue DHCPv6 services to perform DNS takeover for Kerberos relaying, or has established persistence via unauthorized Kate editor plugins on compromised hosts.
Based on research by Rapid7 2026-09-28 9 steps · 3 queries T1021.001 T1190
Brief
Why this hunt matters 100% 500 1000 1200 1500 2000 2500 3000 3500 4000 4500 5000 5500 6000 6500 7000 7500 8000 8500 9000 9500 10000 10500 11000 11500 12000 12500 13000 13500 14000 14500 15000 15500 16000 16500 17000 17500 18000 18500 19000 19500 20000 20500 21000 21500 22000 22500 23000 23500 24000 24500 25000 25500 26000 26500 27000 27500 28000 28500 29000 29500 30000 30500 31000 31500 32000 32500 33000 33500 34000 34500 35000 35500 36000 36500 37000 37500 38000 38500 39000 39500 40000 40500 41000 41500 42000 42500 43000 43500 44000 44500 45000 45500 46000 46500 47000 47500 48000 48500 49000 49500 50000 50500 51000 51500 52000 52500 53000 53500 54000 54500 55000 55500 56000 56500 57000 57500 58000 58500 59000 59500 60000 60500 61000 61500 62000 62500 63000 63500 64000 64500 65000 65500 66000 66500 67000 67500 68000 68500 69000 69500 70000 70500 71000 71500 72000 72500 73000 73500 74000 74500 75000 75500 76000 76500 77000 77500 78000 78500 79000 79500 80000 80500 81000 81500 82000 82500 83000 83500 84000 84500 85000 85500 86000 86500 87000 87500 88000 88500 89000 89500 90000 90500 91000 91500 92000 92500 93000 93500 94000 94500 95000 95500 96000 96500 97000 97500 98000 98500 99000 99500 100000 100500 101000 101500 102000 102500 103000 103500 104000 104500 105000 105500 106000 106500 107000 107500 108000 108500 109000 109500 110000 110500 111000 111500 112000 112500 113000 113500 114000 114500 115000 115500 116000 116500 117000 117500 118000 118500 119000 119500 120000 120500 121000 121500 122000 122500 123000 123500 124000 124500 125000 125500 126000 126500 127000 127500 128000 128500 129000 129500 130000 130500 131000 131500 132000 132500 133000 133500 134000 134500 135000 135500 136000 136500 137000 137500 138000 138500 139000 139500 140000 140500 141000 141500 142000 142500 143000 143500 144000 144500 145000 145500 146000 146500 147000 147500 148000 148500 149000 149500 150000 150500 151000 151500 152000 152500 153000 153500 154000 154500 155000 155500 156000 156500 157000 157500 158000 158500 159000 159500 160000 160500 161000 161500 162000 162500 163000 163500 164000 164500 165000 165500 166000 166500 167000 167500 168000 168500 169000 169500 170000 170500 171000 171500 172000 172500 173000 173500 174000 174500 175000 175500 176000 176500 177000 177500 178000 178500 179000 179500 180000 180500 181000 181500 182000 182500 183000 183500 184000 184500 185000 185500 186000 186500 187000 187500 188000 188500 189000 189500 190000 190500 191000 191500 192000 192500 193000 193500 194000 194500 195000 195500 196000 196500 197000 197500 198000 198500 199000 199500 200000 200500 201000 201500 202000 202500 203000 203500 204000 204500 205000 205500 206000 206500 207000 207500 208000 208500 209000 209500 210000 210500 211000 211500 212000 212500 213000 213500 214000 214500 215000 215500 216000 216500 217000 217500 218000 218500 219000 219500 220000 220500 221000 221500 222000 222500 223000 223500 224000 224500 225000 225500 226000 226500 227000 227500 228000 228500 229000 229500 230000 230500 231000 231500 232000 232500 233000 233500 234000 234500 235000 235500 236000 236500 237000 237500 238000 238500 239000 239500 240000 240500 241000 241500 242000 242500 243000 243500 244000 244500 245000 245500 246000 246500 247000 247500 248000 248500 249000 249500 250000 250500 251000 251500 252000 252500 253000 253500 254000 254500 255000 255500 256000 256500 257000 257500 258000 258500 259000 259500 260000 260500 261000 261500 262000 262500 263000 263500 264000 264500 265000 265500 266000 266500 267000 267500 268000 268500 269000 269500 270000 270500 271000 271500 272000 272500 273000 273500 274000 274500 275000 275500 276000 276500 277000 277500 278000 278500 279000 279500 280000 280500 281000 281500 282000 282500 283000 283500 284000 284500 285000 285500 286000 286500 287000 287500 288000 288500 289000 289500 290000 290500 291000 291500 292000 292500 293000 293500 294000 294500 295000 295500 296000 296500 297000 297500 298000 298500 299000 299500 300000 300500 301000 301500 302000 302500 303000 303500 304000 304500 305000 305500 306000 306500 307000 307500 308000 308500 309000 309500 310000 310500 311000 311500 312000 312500 313000 313500 314000 314500 315000 315500 316000 316500 317000 317500 318000 318500 319000 319500 320000 320500 321000 321500 322000 322500 323000 323500 324000 324500 325000 325500 326000 326500 327000 327500 328000 328500 329000 329500 330000 330500 331000 331500 332000 332500 333000 333500 334000 334500 335000 335500 336000 336500 337000 337500 338000 338500 339000 339500 340000 340500 341000 341500 342000 342500 343000 343500 344000 344500 345000 345500 346000 346500 347000 347500 348000 348500 349000 349500 350000 350500 351000 351500 352000 352500 353000 353500 354000 354500 355000 355500 356000 356500 357000 357500 358000 358500 359000 359500 360000 360500 361000 361500 362000 362500 363000 363500 364000 364500 365000 365500 366000 366500 367000 367500 368000 368500 369000 369500 370000 370500 371000 371500 372000 372500 373000 373500 374000 374500 375000 375500 376000 376500 377000 377500 378000 378500 379000 379500 380000 380500 381000 381500 382000 382500 383000 383500 384000 384500 385000 385500 386000 386500 387000 387500 388000 388500 389000 389500 390000 390500 391000 391500 392000 392500 393000 393500 394000 394500 395000 395500 396000 396500 397000 397500 398000 398500 399000 399500 400000 400500 401000 401500 402000 402500 403000 403500 404000 404500 405000 405500 406000 406500 407000 407500 408000 408500 409000 409500 410000 410500 411000 411500 412000 412500 413000 413500 414000 414500 415000 415500 416000 416500 417000 417500 418000 418500 419000 419500 420000 420500 421000 421500 422000 422500 423000 423500 424000 424500 425000 425500 426000 426500 427000 427500 428000 428500 429000 429500 430000 430500 431000 431500 432000 432500 433000 433500 434000 434500 435000 435500 436000 436500 437000 437500 438000 438500 439000 439500 440000 440500 441000 441500 442000 442500 443000 443500 444000 444500 445000 445500 446000 446500 447000 447500 448000 448500 449000 449500 450000 450500 451000 451500 452000 452500 453000 453500 454000 454500 455000 455500 456000 456500 457000 457500 458000 458500 459000 459500 460000 460500 461000 461500 462000 462500 463000 463500 464000 464500 465000 465500 466000 466500 467000 467500 468000 468500 469000 469500 470000 470500 471000 471500 472000 472500 473000 473500 474000 474500 475000 475500 476000 476500 477000 477500 478000 478500 479000 479500 480000 480500 481000 481500 482000 482500 483000 483500 484000 484500 485000 485500 486000 486500 487000 487500 488000 488500 489000 489500 490000 490500 491000 491500 492000 492500 493000 493500 494000 494500 495000 495500 496000 496500 497000 497500 498000 498500 499000 499500 500000 500500 501000 501500 502000 502500 503000 503500 504000 504500 505000 505500 506000 506500 507000 507500 508000 508500 509000 509500 510000 510500 511000 511500 512000 512500 513000 513500 514000 514500 515000 515500 516000 516500 517000 517500 518000 518500 519000 519500 520000 520500 521000 521500 522000 522500 523000 523500 524000 524500 525000 525500 526000 526500 527000 527500 528000 528500 529000 529500 530000 530500 531000 531500 532000 532500 533000 533500 534000 534500 535000 535500 536000 536500 537000 537500 538000 538500 539000 539500 540000 540500 541000 541500 542000 542500 543000 543500 544000 544500 545000 545500 546000 546500 547000 547500 548000 548500 549000 549500 550000 550500 551000 551500 552000 552500 553000 553500 554000 554500 555000 555500 556000 556500 557000 557500 558000 558500 559000 559500 560000 560500 561000 561500 562000 562500 563000 563500 564000 564500 565000 565500 566000 566500 567000 567500 568000 568500 569000 569500 570000 570500 571000 571500 572000 572500 573000 573500 574000 574500 575000 575500 576000 576500 577000 577500 578000 578500 579000 579500 580000 580500 581000 581500 582000 582500 583000 583500 584000 584500 585000 585500 586000 586500 587000 587500 588000 588500 589000 589500 590000 590500 591000 591500 592000 592500 593000 593500 594000 594500 595000 595500 596000 596500 597000 597500 598000 598500 599000 599500 600000 600500 601000 601500 602000 602500 603000 603500 604000 604500 605000 605500 606000 606500 607000 607500 608000 608500 609000 609500 610000 610500 611000 611500 612000 612500 613000 613500 614000 614500 615000 615500 616000 616500 617000 617500 618000 618500 619000 619500 620000 620500 621000 621500 622000 622500 623000 623500 624000 624500 625000 625500 626000 626500 627000 627500 628000 628500 629000 629500 630000 630500 631000 631500 632000 632500 633000 633500 634000 634500 635000 635500 636000 636500 637000 637500 638000 638500 639000 639500 640000 640500 641000 641500 642000 642500 643000 643500 644000 644500 645000 645500 646000 646500 647000 647500 648000 648500 649000 649500 650000 650500 651000 651500 652000 652500 653000 653500 654000 654500 655000 655500 656000 656500 657000 657500 658000 658500 659000 659500 660000 660500 661000 661500 662000 662500 663000 663500 664000 664500 665000 665500 666000 666500 667000 667500 668000 668500 669000 669500 670000 670500 671000 671500 672000 672500 673000 673500 674000 674500 675000 675500 676000 676500 677000 677500 678000 678500 679000 679500 680000 680500 681000 681500 682000 682500 683000 683500 684000 684500 685000 685500 686000 686500 687000 687500 688000 688500 689000 689500 690000 690500 691000 691500 692000 692500 693000 693500 694000 694500 695000 695500 696000 696500 697000 697500 698000 698500 699000 699500 700000 700500 701000 701500 702000 702500 703000 703500 704000 704500 705000 705500 706000 706500 707000 707500 708000 708500 709000 709500 710000 710500 711000 711500 712000 712500 713000 713500 714000 714500 715000 715500 716000 716500 717000 717500 718000 718500 719000 719500 720000 720500 721000 721500 722000 722500 723000 723500 724000 724500 725000 725500 726000 726500 727000 727500 728000 728500 729000 729500 730000 730500 731000 731500 732000 732500 733000 733500 734000 734500 735000 735500 736000 736500 737000 737500 738000 738500 739000 739500 740000 740500 741000 741500 742000 742500 743000 743500 744000 744500 745000 745500 746000 746500 747000 747500 748000 748500 749000 749500 750000 750500 751000 751500 752000 752500 753000 753500 754000 754500 755000 755500 756000 756500 757000 757500 758000 758500 759000 759500 760000 760500 761000 761500 762000 762500 763000 763500 764000 764500 765000 765500 766000 766500 767000 767500 768000 768500 769000 769500 770000 770500 771000 771500 772000 772500 773000 773500 774000 774500 775000 775500 776000 776500 777000 777500 778000 778500 779000 779500 780000 780500 781000 781500 782000 782500 783000 783500 784000 784500 785000 785500 786000 786500 787000 787500 788000 788500 789000 789500 790000 790500 791000 791500 792000 792500 793000 793500 794000 794500 795000 795500 796000 796500 797000 797500 798000 798500 799000 799500 800000 800500 801000 801500 802000 802500 803000 803500 804000 804500 805000 805500 806000 806500 807000 807500 808000 808500 809000 809500 810000 810500 811000 811500 812000 812500 813000 813500 814000 814500 815000 815500 816000 816500 817000 817500 818000 818500 819000 819500 820000 820500 821000 821500 822000 822500 823000 823500 824000 824500 825000 825500 826000 826500 827000 827500 828000 828500 829000 829500 830000 830500 831000 831500 832000 832500 833000 833500 834000 834500 835000 835500 836000 836500 837000 837500 838000 838500 839000 839500 840000 840500 841000 841500 842000 842500 843000 843500 844000 844500 845000 845500 846000 846500 847000 847500 848000 848500 849000 849500 850000 850500 851000 851500 852000 852500 853000 853500 854000 854500 855000 855500 856000 856500 857000 857500 858000 858500 859000 859500 860000 860500 861000 861500 862000 862500 863000 863500 864000 864500 865000 865500 866000 866500 867000 867500 868000 868500 869000 869500 870000 870500 871000 871500 872000 872500 873000 873500 874000 874500 875000 875500 876000 876500 877000 877500 878000 878500 879000 879500 880000 880500 881000 881500 882000 882500 883000 883500 884000 884500 885000 885500 886000 886500 887000 887500 888000 888500 889000 889500 890000 890500 891000 891500 892000 892500 893000 893500 894000 894500 895000 895500 896000 896500 897000 897500 898000 898500 899000 899500 900000 900500 901000 901500 902000 902500 903000 903500 904000 904500 905000 905500 906000 906500 907000 907500 908000 908500 909000 909500 910000 910500 911000 911500 912000 912500 913000 913500 914000 914500 915000 915500 916000 916500 917000 917500 918000 918500 919000 919500 920000 920500 921000 921500 922000 922500 923000 923500 924000 924500 925000 925500 926000 926500 927000 927500 928000 928500 929000 929500 930000 930500 931000 931500 932000 932500 933000 933500 934000 934500 935000 935500 936000 936500 937000 937500 938000 938500 939000 939500 940000 940500 941000 941500 942000 942500 943000 943500 944000 944500 945000 945500 946000 946500 947000 947500 948000 948500 949000 949500 950000 950500 951000 951500 952000 952500 953000 953500 954000 954500 955000 955500 956000 956500 957000 957500 958000 958500 959000 959500 960000 960500 961000 961500 962000 962500 963000 963500 964000 964500 965000 965500 966000 966500 967000 967500 968000 968500 969000 969500 970000 970500 971000 971500 972000 972500 973000 973500 974000 974500 975000 975500 976000 976500 977000 977500 978000 978500 979000 979500 980000 980500 981000 981500 982000 982500 983000 983500 984000 984500 985000 985500 986000 986500 987000 987500 988000 988500 989000 989500 990000 99500 100000
The Metasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites? (https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-belgian-waffles-chocolates-and-modules-frites) research introduced modules that facilitate internal network coercion and cross-platform persistence. Specifically, an IPv6 DNS takeover module allows adversaries to perform Kerberos relaying with high efficiency. This hunt identifies the artifacts and behaviors associated with these techniques.
Scoping Vulnerable Hosts
The hunt begins by identifying hosts vulnerable to CVE-2026-20929. This Windows HTTP.sys vulnerability provides the coercion vector needed to trigger outbound authentication as described in the research. Focusing on these systems prioritizes the most likely targets for relay attacks and reduces noise across the estate.
Analyzing Network Behavior
The second phase searches for rare network activity on the identified hosts or across the entire fleet. The hunt identifies processes listening on UDP port 547 (DHCPv6) or initiating connections on TCP port 3389 (RDP). While RDP is common, rogue DHCPv6 listeners are rare on typical workstations. The query isolates processes that lack a historical baseline for these sensitive ports.
Detecting Editor Persistence
In parallel, the hunt examines file activity in Kate editor plugin directories. Kate is a popular multi-platform text editor. Adversaries use its plugin architecture to hide malicious code that runs when a user opens the editor. The hunt searches the file activity surface for new plugin files created by unexpected or non-system processes.
Triage and Evidence Correlation
An agent or analyst triages the findings by weighing the vulnerability state, network anomalies, and file writes. If a host vulnerable to CVE-2026-20929 shows a rare DHCPv6 listener or a new Kate plugin, the hunt marks it for investigation. The triage step looks for evidence that the same process handles both the network listener and the persistence mechanism.
Blind Spots
This hunt relies on endpoint telemetry from enrolled hosts. A rogue DHCPv6 server running on an unmanaged device still poisons the network but remains invisible to this search. Additionally, the hunt identifies the coercion setup and persistence but cannot confirm if a Kerberos relay successfully occurred. Confirming a successful relay requires authentication logs from Domain Controllers.
How to Run the Hunt
This hunt is an open hunt.md playbook. You can import it into Huntbase or any hunt.md-aware runtime. The playbook scopes the estate, runs the parallel behavioral queries, and routes findings to a triage step. Users should manually review any identified Kate plugins to verify if they are legitimate administrative tools.
In this series
Steps
-
Identify vulnerable hosts
Query · scopingLocate systems susceptible to HTTP.sys privilege elevation which allows the network coercion described in the research.
reads hb_vulnerability_findingsqlSELECT device_uid, resource_uid, severity, collected_at FROM hb_vulnerability_finding WHERE cve_uid = '{{cve_id}}' AND status != 'suppressed'What a hit looks like. A list of host identifiers currently vulnerable to the coercion vector. Silence indicates the estate is patched against this specific exploit.
-
Rare network activity on sensitive ports
Query · baselineFind processes listening on or initiating connections on DHCPv6 (547) and RDP (3389) ports.
reads hb_network_connectionsqlSELECT device_hostname, process_name, dst_endpoint_port, COUNT(*) AS connections, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_network_connection WHERE (dst_endpoint_port = 547 OR dst_endpoint_port = 3389) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name, dst_endpoint_portWhat a hit looks like. Anomalous processes using DHCPv6 or RDP on systems that do not usually provide these services. Silence in a complete log indicates the absence of this specific network coercion.
-
Kate editor plugin persistence
Query · detection candidateDetect rare file creations in Kate editor plugin directories used for multi-platform persistence.
reads hb_file_activitysqlSELECT device_hostname, file_path, file_name, process_name, actor_user_name, time FROM hb_file_activity WHERE (LOWER(file_path) LIKE '%/kate/plugins/%' OR LOWER(file_path) LIKE '%\\kate\\plugins\\%') AND activity_id = 1 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. Creation of new plugin files by unexpected processes. Benign results include legitimate plugin installations by the user.
-
Triage behavioral evidence
Agent triageWeigh the vulnerability state, rare network activity, and file persistence together to identify active intrusion.
-
Route on verdict
DecisionRoute the hunt to containment if malicious activity is confirmed.
-
Isolate host
Response actionIsolate the compromised host to stop rogue network protocol spoofing and prevent lateral movement.
-
Analyst forensic review
Analyst taskVerify the agent's verdict and examine the identified plugin or listener process.
-
Remediate HTTP.sys vulnerability
Analyst taskPatch the underlying vulnerability used as a coercion vector.
Coverage
Scenario coverage
| Stage | Covered | How, or why not |
|---|---|---|
| IPv6 DNS Takeover Coercion T1190 |
Yes | scope-vulnerable-hosts, rare-network-activity |
| Anomalous RDP Interaction T1021.001 |
Yes | rare-network-activity |
| Kate Plugin Persistence T1190 |
Yes | kate-persistence |
| GitLab Unauthenticated Arbitrary File Read T1190 |
Out of scope | Belongs to another part of the 'Metasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites?' series. |
| Langflow AI Authenticated RCE T1190 |
Out of scope | Belongs to another part of the 'Metasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites?' series. |
Blind spots
- Needs Endpoint agent coverage. A rogue DHCPv6 server on an unmanaged device can still poison the network, but this hunt only detects the server-side behavior if the attacker uses an enrolled host. It would answer Are there rogue services running on non-enrolled hosts?.
- Needs Domain Controller authentication logs. The hunt detects the coercion setup (the rogue DNS) but cannot confirm if a relay successfuly occurred without AD-specific authentication telemetry. It would answer Was a Kerberos relay attack actually performed?.
Parameters & data
Parameters
| Parameter | Type | Default | What it is |
|---|---|---|---|
cve_id | string | CVE-2026-20929 | The Windows HTTP.sys vulnerability used for coercion. |
lookback_days | number | 14 | Days of historical telemetry to examine. |
scope_hosts | list[host] | — | List of hostnames from the scoping step to focus behavioral analysis; leave empty to hunt across the entire estate. |
Telemetry
| Source | Category | Telemetry |
|---|---|---|
| Endpoint telemetry (hb_ surfaces) | endpoint | endpoint |
| Network telemetry | network | network |
Source
---
analysis: This is a hunt because it uses fleet-wide prevalence to distinguish authorized
network services from rogue protocol spoofers and correlates them with specific
editor plugin persistence that standard EDR rules often miss.
blind_spots:
- id: no-endpoint-telemetry
question: Are there rogue services running on non-enrolled hosts?
requires: Endpoint agent coverage
risk: A rogue DHCPv6 server on an unmanaged device can still poison the network,
but this hunt only detects the server-side behavior if the attacker uses an enrolled
host.
stage: ipv6-dns-takeover-coercion
- id: no-kerberos-relay-visibility
question: Was a Kerberos relay attack actually performed?
requires: Domain Controller authentication logs
risk: The hunt detects the coercion setup (the rogue DNS) but cannot confirm if
a relay successfuly occurred without AD-specific authentication telemetry.
stage: ipv6-dns-takeover-coercion
coverage:
- stage: ipv6-dns-takeover-coercion
status: covered
steps:
- scope-vulnerable-hosts
- rare-network-activity
- stage: rdp-anomalous-interaction
status: covered
steps:
- rare-network-activity
- stage: kate-plugin-persistence
status: covered
steps:
- kate-persistence
- reason: "Belongs to another part of the 'Metasploit Wrap Up: Belgian Waffles, Chocolates,\
\ and\u2026Modules-Frites?' series."
stage: gitlab-unauthenticated-file-read
status: out_of_scope
- reason: "Belongs to another part of the 'Metasploit Wrap Up: Belgian Waffles, Chocolates,\
\ and\u2026Modules-Frites?' series."
stage: langflow-authenticated-rce
status: out_of_scope
guardrails:
claims: no_unsupported
evidence: citation_required
missing_data: not_benign
telemetry: untrusted
hunt:
applicability: campaign-specific
handoff: promote-to-detection
justification: Internal network coercion via DHCPv6/IPv6 is a critical credential-access
vector that is often overlooked in traditional network monitoring. Detecting the
rare rogue services and the prerequisite vulnerability provides a proactive defense
against Kerberos relay attacks.
methodology: model-assisted
trigger: intel-report
hypothesis: An adversary is using rogue DHCPv6 services to perform DNS takeover for
Kerberos relaying, or has established persistence via unauthorized Kate editor plugins
on compromised hosts.
labels:
- hunt
- attack.t1190
- attack.t1021.001
name: Internal Coercion and Editor Persistence
parameters:
cve_id:
default: CVE-2026-20929
description: The Windows HTTP.sys vulnerability used for coercion.
from:
kind: article
observed: '2026-09-25'
ref: rapid7-metasploit-wrapup-2026-09
type: string
lookback_days:
default: '14'
description: Days of historical telemetry to examine.
from:
kind: manual
ref: Standard lookback window
type: number
scope_hosts:
default: []
description: List of hostnames from the scoping step to focus behavioral analysis;
leave empty to hunt across the entire estate.
from:
kind: manual
ref: Analyst scoping
type: list[host]
provenance:
authors:
- name: Huntbase hunt generation
org: huntbase.io
generated:
by: huntbase-hunt-generation
from: https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-belgian-waffles-chocolates-and-modules-frites
gates:
- dry-run
- lint
model: hb_google/gemini-3-flash-preview
rationale: The hunt focuses on systems vulnerable to CVE-2026-20929 as they are the
primary targets for the network coercion module. Behavioral queries are then filtered
to these hosts to detect active exploitation.
references:
- name: "Metasploit Wrap Up: Belgian Waffles, Chocolates, and\u2026Modules-Frites?"
url: https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-belgian-waffles-chocolates-and-modules-frites
related:
- hunt: gitlab-file-read-cve-2026-85706
reason: GitLab exploitation is a perimeter access vector handled by its own hunt.
relation: out-of-scope-alternative
- hunt: exploitation-web-facing-gitlab-langflow
relation: follows
scenario:
stages:
- name: GitLab Unauthenticated Arbitrary File Read
observables:
- CVE-2026-85706
- HTTP requests to GitLab repository commits APIs
- HTTP requests to GitLab repository files APIs
- 'Module: gather/gitlab_file_read_cve_2026_85706'
- Affected GitLab versions 18.7 up to 19.3.2
slug: gitlab-unauthenticated-file-read
tactic: initial-access
techniques:
- T1190
- name: Langflow AI Authenticated RCE
observables:
- CVE-2026-18729
- Authenticated HTTP requests to Langflow custom components
- Arbitrary Python code execution via Langflow process
- 'Module: multi/http/langflow_auth_rce_cve_2026_18729'
- Langflow versions 1.11.1 and below
slug: langflow-authenticated-rce
tactic: execution
techniques:
- T1190
- name: IPv6 DNS Takeover Coercion
observables:
- CVE-2026-20929
- Rogue DHCPv6 server activity on UDP port 547
- Rogue IPv6 Router Advertisements (RA)
- Kerberos authentication relay attempts
- 'Module: spoof/dhcp/dhcpv6_dns_takeover'
- 'Module: spoof/ipv6/ipv6_ra_dns_takeover'
slug: ipv6-dns-takeover-coercion
tactic: credential-access
techniques:
- T1190
- name: Anomalous RDP Interaction
observables:
- Unexpected size RDP packets and responses
- Anomalous Remote Interactive logons
- RDP connections to internal assets on port 3389
slug: rdp-anomalous-interaction
tactic: lateral-movement
techniques:
- T1021.001
- name: Kate Plugin Persistence
observables:
- Writes to Kate editor plugin directories
- New plugin configuration files for Kate editor
- 'Module: multi/persistence/kate_plugin'
slug: kate-plugin-persistence
tactic: persistence
techniques:
- T1190
summary: Recent Metasploit updates introduced exploitation modules for unauthenticated
file read in GitLab (CVE-2026-85706) and authenticated RCE in Langflow AI (CVE-2026-18729).
The release also features native IPv6 DNS takeover modules for Kerberos relay
attacks and a new persistence mechanism targeting the Kate text editor.
series:
index: 2
slug: metasploit-wrap-up-belgian-waffles-chocolates-and-modules-frites
title: "Metasploit Wrap Up: Belgian Waffles, Chocolates, and\u2026Modules-Frites?"
total: 2
severity: high
targets:
analyst:
name: Tier-2 analyst
role: analyst
endpoint:
category: endpoint
name: Endpoint telemetry (hb_ surfaces)
telemetry:
- endpoint
hunter:
agent: true
name: Hunt agent
network:
category: network
name: Network telemetry
telemetry:
- network
tlp: clear
type: investigation
---
# Internal Coercion and Editor Persistence
This hunt identifies internal network protocol abuse and application-specific persistence following the Metasploit September 2026 update. It first scopes systems vulnerable to the HTTP.sys coercion vector (CVE-2026-20929) and then searches in parallel for rare network activity on DHCPv6 (UDP 547) or RDP (3389) ports, and unauthorized file activity in Kate editor plugin directories. An agent weighs these behavioral signals to distinguish rogue services and persistence mechanisms from legitimate administrative activity.
## scope-vulnerable-hosts
<!-- Identify vulnerable hosts -->
Locate systems susceptible to HTTP.sys privilege elevation which allows the network coercion described in the research.
```sqlite target=endpoint role=scoping params=(cve_id=cve_id)
~~~yaml
expected: A list of host identifiers currently vulnerable to the coercion vector.
Silence indicates the estate is patched against this specific exploit.
reads:
- device_uid
- resource_uid
- severity
- collected_at
silence: not_evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_uid, resource_uid, severity, collected_at FROM hb_vulnerability_finding WHERE cve_uid = '{{cve_id}}' AND status != 'suppressed'
```
## behavioral-fan-out
<!-- Analyze behavior in parallel -->
parallel:
- → rare-network-activity
- → kate-persistence
join: → triage-findings
## rare-network-activity
<!-- Rare network activity on sensitive ports -->
Find processes listening on or initiating connections on DHCPv6 (547) and RDP (3389) ports.
```sqlite target=network role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
compare: first_seen
window: '{{lookback_days}}d'
expected: Anomalous processes using DHCPv6 or RDP on systems that do not usually provide
these services. Silence in a complete log indicates the absence of this specific
network coercion.
prevalence:
by: device_hostname
key:
- process_name
- dst_endpoint_port
rare_below: 3
reads:
- device_hostname
- process_name
- dst_endpoint_port
- time
silence: evidence_of_absence
source: hb_network_connection
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, process_name, dst_endpoint_port, COUNT(*) AS connections, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_network_connection WHERE (dst_endpoint_port = 547 OR dst_endpoint_port = 3389) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name, dst_endpoint_port
```
## kate-persistence
<!-- Kate editor plugin persistence -->
Detect rare file creations in Kate editor plugin directories used for multi-platform persistence.
```sqlite target=endpoint role=detection-candidate params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
compare: first_seen
window: '{{lookback_days}}d'
expected: Creation of new plugin files by unexpected processes. Benign results include
legitimate plugin installations by the user.
prevalence:
by: device_hostname
key:
- file_path
rare_below: 3
reads:
- device_hostname
- file_path
- file_name
- process_name
- actor_user_name
- time
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, file_path, file_name, process_name, actor_user_name, time FROM hb_file_activity WHERE (LOWER(file_path) LIKE '%/kate/plugins/%' OR LOWER(file_path) LIKE '%\\kate\\plugins\\%') AND activity_id = 1 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```
## triage-findings
<!-- Triage behavioral evidence -->
```agent target=hunter
cite: required
context:
- scope-vulnerable-hosts
- rare-network-activity
- kate-persistence
max_iterations: 5
objective: Determine if any host vulnerable to CVE-2026-20929 shows evidence of rogue
DHCPv6/RDP activity or unauthorized Kate plugin persistence. Identify if the same
process is responsible for the network listener and any file writes.
success_criteria: A verdict of malicious, suspicious, or benign for each host, citing
relevant rows from the behavioral queries.
tools:
- endpoint
- network
```
## route-verdict
<!-- Route on verdict -->
if~: "the triage verdict is malicious for any host exhibiting rogue DHCPv6 listeners or unauthorized editor plugins" (confidence: high, judge=hunter)
then: → isolate-host
indeterminate: → manual-review
unavailable: → manual-review (blind_spot: no-endpoint-telemetry)
else: → remediate-vulnerability
## isolate-host
<!-- Isolate host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host immediately. Terminate the process identified as a rogue DHCPv6 or RDP listener.
```
→ manual-review
## manual-review
<!-- Analyst forensic review -->
```manual target=analyst
Inspect the file contents in the Kate plugin directory. Verify if the process listening on port 547 or 3389 matches an authorized network management tool.
```
→ remediate-vulnerability
## remediate-vulnerability
<!-- Remediate HTTP.sys vulnerability -->
```manual target=analyst
Apply the latest Windows updates to all hosts identified in the scoping step to mitigate CVE-2026-20929.
```
→ end
Run it
Take this hunt into your environment.
Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.
Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.