← All hunts high TLP:CLEAR Part 2 of 2

Local Escalation and Persistence via Metasploit Modules

An adversary escalates Linux privileges via snap-confine or DirtyClone and establishes persistence through PAM backdoors or Ollama auto-update tampering.

Based on research by Rapid7 2026-10-10 9 steps · 3 queries T1068 T1518.001 T1556 T1574.002

Brief

The release of new Metasploit modules often signals a shift from sophisticated exploitation to broader adoption by various threat actors. The recent Rapid7 Metasploit Wrap Up (https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-a-collection-of-what-can-only-be-called-eclectic-modules) highlights several modules targeting Linux environments, specifically focusing on local privilege escalation and persistence. This hunt addresses the risk of an adversary moving from initial access to full system control. We focus on the behavior of modules that exploit CVE-2026-3888 in snap-confine and CVE-2026-42249, which targets the Linux kernel. We also look for persistence mechanisms involving PAM backdoors and Ollama configuration tampering.

Scoping and Vulnerability Discovery

The hunt begins with a scoping phase using the hb_vulnerability_finding surface. We identify systems running vulnerable versions of snapd and Ollama, as well as those with kernels susceptible to the DirtyClone exploit. This step filters the fleet, allowing analysts to focus on hosts where the Metasploit modules are functionally viable. This narrowing of scope reduces the noise in subsequent behavioral queries and identifies the most likely targets for initial triage.

Identifying Persistence via PAM

Once scoped, we pivot to the hb_module_activity surface. A common persistence technique involves adding a rogue module to /lib/security/. This hunt identifies every .so file loaded by an authentication process and counts its prevalence across the environment. We look for modules that appear on only a handful of machines. In a standardized environment, authentication modules are uniform; a rare module in the security path often indicates a custom backdoor installed by an adversary to bypass or log credentials.

Monitoring Exploit Execution

We then look for the actual execution of the LPE modules using the hb_process_activity surface. The query scans for process names and command lines associated with snap-confine, dirtyclone, and the Metasploit 'enum_protections' discovery module. We specifically watch for processes where the on_disk flag is false, indicating fileless execution, or where a process suddenly changes its effective user ID to root from an unexpected parent. These behavioral signals provide high-confidence evidence of an active exploitation attempt.

Blind Spots and Limitations

This hunt cannot detect every persistence attempt. If an adversary places a malicious PAM module on the filesystem but the system does not load it into an active process, the hb_module_activity query will miss it. Additionally, if the adversary performs discovery using built-in shell commands or custom scripts that do not match the specific Metasploit module strings, they might evade the process-based detection. This hunt is designed to find known Metasploit-driven patterns rather than every possible manual LPE technique.

How to Run the Hunt

This hunt is provided as a hunt.md playbook. This open format allows you to import the entire logic into Huntbase or any compatible runtime that recognizes the hunt.md schema. Running the playbook automates the scoping, parallel data gathering, and initial triage, providing a prioritized list of hosts for forensic investigation.

In this series

Steps

  1. Scope vulnerable hosts

    Query · scoping

    Identify hosts with known vulnerabilities targeted by the new Metasploit modules to focus the behavioral queries.

    reads hb_vulnerability_findingsql
    SELECT device_uid, cve_uid, affected_package_name, severity_id, title FROM hb_vulnerability_finding WHERE cve_uid IN ('CVE-2026-3888', 'CVE-2026-43503', 'CVE-2026-42249')

    What a hit looks like. Rows identify hosts running vulnerable versions of snapd, Ollama, or relevant Linux kernels. Silence means no known vulnerable systems were reported.

  2. Identify rare PAM modules

    Query · baseline

    Find potentially malicious .so files loaded into the Linux authentication chain that indicate a PAM backdoor.

    reads hb_module_activitysql
    SELECT module_path, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_module_activity WHERE (LOWER(module_path) LIKE '/lib/security/%.so' OR LOWER(module_path) LIKE '/usr/lib/security/%.so') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY module_path HAVING hosts <= 2 ORDER BY hosts ASC

    What a hit looks like. A module path seen on only one or two hosts. Genuine PAM modules should be present across the fleet; a backdoor will appear unique to the target.

  3. Hunt for exploit execution and discovery

    Query · detection candidate

    Detect the execution of LPE exploits, security software discovery, and Ollama configuration changes.

    reads hb_process_activitysql
    SELECT device_hostname, process_name, process_cmd_line, user_name, on_disk, time FROM hb_process_activity WHERE (LOWER(process_cmd_line) LIKE '%snap-confine%' OR LOWER(process_cmd_line) LIKE '%dirtyclone%' OR LOWER(process_cmd_line) LIKE '%enum_protections%' OR LOWER(process_cmd_line) LIKE '%ollama%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') ORDER BY time DESC

    What a hit looks like. Processes mentioning exploit names or the Metasploit discovery module. Transition of these processes to root or processes with on_disk = 0 are high-confidence indicators.

  4. Triage results

    Agent triage

    Analyze the findings from the scoping and behavioral queries to identify compromised hosts.

  5. Route based on agent verdict

    Decision

    Direct the workflow based on the risk identified by the triage agent.

  6. Isolate the host

    Response action

    Contain the threat on identified malicious hosts.

  7. Conduct manual forensics

    Analyst task

    Confirm the extent of the compromise and the nature of the persistence mechanism.

  8. Finalize hunt

    Analyst task

    Conclude the hunt and record outcomes for tuning.

Coverage

Scenario coverage

StageCoveredHow, or why not
Linux Local Privilege Escalation
T1068
Yes exploit-behavior
Persistence via PAM and Config Tampering
T1556 · T1574.002
Yes rare-pam-modules, exploit-behavior
Security Software Discovery
T1518.001
Yes exploit-behavior
Unauthenticated RCE in Web and LLM Services
T1190
Out of scope Belongs to another part of the 'Metasploit Wrap Up: A Collection of What Can Only Be Called Eclectic Modules' series.
Windows AArch64 Payload Fetching
T1105 · T1059
Out of scope Belongs to another part of the 'Metasploit Wrap Up: A Collection of What Can Only Be Called Eclectic Modules' series.

Blind spots

  • Needs hb_file_activity with deep scan. A module on disk that hasn't been loaded yet will be missed by the prevalence check on hb_module_activity. It would answer Was a malicious PAM module uploaded but not yet loaded into a process?.
  • Needs hb_script_activity with full block capture. If the Metasploit module discovery logic is executed via an existing interpreter without unique command line arguments, hb_process_activity might miss it. It would answer Is the enumeration module running entirely in memory without spawning new processes?.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
lookback_daysnumber14Days of history to examine.
scope_hostslist[host]—Optional list of hostnames to focus the hunt; leave empty for all hosts.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: A single rule might flag the exploit name, but this hunt combines vulnerability
  state, stack-counted module prevalence, and process behavioral analysis (like on_disk
  = 0) to provide a complete picture of the post-exploitation phase.
blind_spots:
- id: no-file-telemetry
  question: Was a malicious PAM module uploaded but not yet loaded into a process?
  requires: hb_file_activity with deep scan
  risk: A module on disk that hasn't been loaded yet will be missed by the prevalence
    check on hb_module_activity.
  stage: persistence-via-auth-and-config
- id: no-script-content
  question: Is the enumeration module running entirely in memory without spawning
    new processes?
  requires: hb_script_activity with full block capture
  risk: If the Metasploit module discovery logic is executed via an existing interpreter
    without unique command line arguments, hb_process_activity might miss it.
  stage: security-software-discovery
coverage:
- stage: linux-local-privilege-escalation
  status: covered
  steps:
  - exploit-behavior
- stage: persistence-via-auth-and-config
  status: covered
  steps:
  - rare-pam-modules
  - exploit-behavior
- stage: security-software-discovery
  status: covered
  steps:
  - exploit-behavior
- reason: 'Belongs to another part of the ''Metasploit Wrap Up: A Collection of What
    Can Only Be Called Eclectic Modules'' series.'
  stage: unauthenticated-rce-web-services
  status: out_of_scope
- reason: 'Belongs to another part of the ''Metasploit Wrap Up: A Collection of What
    Can Only Be Called Eclectic Modules'' series.'
  stage: windows-aarch64-payload-fetch
  status: out_of_scope
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: promote-to-detection
  justification: The release of new Metasploit modules lowers the bar for exploiting
    these specific vulnerabilities. Proactively hunting for these behaviors ensures
    detection of intrusions that bypass static signatures.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An adversary escalates Linux privileges via snap-confine or DirtyClone
  and establishes persistence through PAM backdoors or Ollama auto-update tampering.
labels:
- hunt
- attack.t1068
- attack.t1556
- attack.t1574.002
- attack.t1518.001
- discovery
- execution
- initial access
- persistence
- privilege escalation
name: Local Escalation and Persistence via Metasploit Modules
parameters:
  lookback_days:
    default: '14'
    description: Days of history to examine.
    type: number
  scope_hosts:
    default: []
    description: Optional list of hostnames to focus the hunt; leave empty for all
      hosts.
    type: list[host]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-a-collection-of-what-can-only-be-called-eclectic-modules
    gates:
    - dry-run
    - lint
    - critic
    model: hb_google/gemini-3-flash-preview
rationale: Focus on Linux servers running snapd and Windows machines running Ollama.
  Use the vulnerability scoping step to identify high-priority targets first.
references:
- name: "Rapid7 \u2014 Metasploit Wrap Up: A Collection of What Can Only Be Called\
    \ Eclectic Modules"
  url: https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-a-collection-of-what-can-only-be-called-eclectic-modules
related:
- hunt: unauthenticated-rce-web-services
  reason: This hunt focuses on post-exploitation local activity; initial access via
    web service exploits is covered in a sibling hunt.
  relation: out-of-scope-alternative
- hunt: metasploit-rce-aarch64-payload-delivery
  relation: follows
scenario:
  stages:
  - name: Unauthenticated RCE in Web and LLM Services
    observables:
    - POST requests to /validate endpoint with exec_globals parameter (Langflow)
    - Modification of FFMPEG Executable Path settings in dizqueTV
    - Requests to MCP test REST endpoints in LiteLLM proxy
    - Struts BeanUtils exploitation against N-able N-central
    slug: unauthenticated-rce-web-services
    tactic: initial-access
    techniques:
    - T1190
  - name: Windows AArch64 Payload Fetching
    observables:
    - Execution of cmd/windows/http/aarch64/exec
    - Execution of cmd/windows/tftp/aarch64/shell_reverse_tcp
    - Command-line file transfers via FTP, HTTP, HTTPS, or TFTP on AArch64 Windows
      systems
    slug: windows-aarch64-payload-fetch
    tactic: execution
    techniques:
    - T1105
    - T1059
  - name: Linux Local Privilege Escalation
    observables:
    - Exploitation of snap-confine TOCTOU race condition (CVE-2026-3888)
    - DirtyClone exploit execution (CVE-2026-43503)
    - Execution as root inside OpenCTI API containers via safeEjs sandbox escape
    slug: linux-local-privilege-escalation
    tactic: privilege-escalation
    techniques:
    - T1068
  - name: Persistence via PAM and Config Tampering
    observables:
    - Upload of malicious .so files into the Linux PAM authentication chain
    - Path traversal exploitation in Ollama auto-update mechanism (CVE-2026-42249)
    slug: persistence-via-auth-and-config
    tactic: persistence
    techniques:
    - T1556
    - T1574.002
  - name: Security Software Discovery
    observables:
    - Execution of post/linux/gather/enum_protections
    - Automated enumeration of AV/EDR protections on the target system
    slug: security-software-discovery
    tactic: discovery
    techniques:
    - T1518.001
  summary: This campaign involves the exploitation of unauthenticated remote code
    execution vulnerabilities in LLM-related services and IPTV servers, followed by
    the delivery of fetch-based payloads to Windows AArch64 systems. Attackers then
    perform local privilege escalation on Linux systems and establish persistence
    through configuration tampering or malicious authentication modules.
series:
  index: 2
  slug: metasploit-wrap-up-a-collection-of-what-can-only-be-called-eclectic-modules
  title: 'Metasploit Wrap Up: A Collection of What Can Only Be Called Eclectic Modules'
  total: 2
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
tlp: clear
type: investigation
---


# Local Escalation and Persistence via Metasploit Modules

The adversary uses Metasploit modules to move from a beachhead to full control. This hunt identifies vulnerable systems using vulnerability discovery data and then looks for behavioral signals: the query identifies rare PAM modules loaded into the authentication chain and process activity associated with Linux privilege escalation. An agent weighs the evidence to identify compromised hosts where an attacker transitioned to root or established persistent access.

## scope-vulnerable-hosts
<!-- Scope vulnerable hosts -->
Identify hosts with known vulnerabilities targeted by the new Metasploit modules to focus the behavioral queries.

```sqlite target=endpoint role=scoping
~~~yaml
expected: Rows identify hosts running vulnerable versions of snapd, Ollama, or relevant
  Linux kernels. Silence means no known vulnerable systems were reported.
reads:
- device_uid
- cve_uid
- affected_package_name
- severity_id
- title
silence: not_evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-10-10'
~~~
SELECT device_uid, cve_uid, affected_package_name, severity_id, title FROM hb_vulnerability_finding WHERE cve_uid IN ('CVE-2026-3888', 'CVE-2026-43503', 'CVE-2026-42249')
```

## parallel-hunt
<!-- Gather behavioral evidence -->
parallel:
- → rare-pam-modules
- → exploit-behavior
join: → triage-findings

## rare-pam-modules
<!-- Identify rare PAM modules -->
Find potentially malicious .so files loaded into the Linux authentication chain that indicate a PAM backdoor.

```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: A module path seen on only one or two hosts. Genuine PAM modules should
  be present across the fleet; a backdoor will appear unique to the target.
prevalence:
  by: device_hostname
  key:
  - module_path
  rare_below: 2
reads:
- module_path
- device_hostname
- time
silence: not_evidence_of_absence
source: hb_module_activity
verified: dry-run
verified_at: '2026-10-10'
~~~
SELECT module_path, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_module_activity WHERE (LOWER(module_path) LIKE '/lib/security/%.so' OR LOWER(module_path) LIKE '/usr/lib/security/%.so') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY module_path HAVING hosts <= 2 ORDER BY hosts ASC
```

## exploit-behavior
<!-- Hunt for exploit execution and discovery -->
Detect the execution of LPE exploits, security software discovery, and Ollama configuration changes.

```sqlite target=endpoint role=detection-candidate params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: Processes mentioning exploit names or the Metasploit discovery module. Transition
  of these processes to root or processes with on_disk = 0 are high-confidence indicators.
reads:
- device_hostname
- process_name
- process_cmd_line
- user_name
- on_disk
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-10-10'
~~~
SELECT device_hostname, process_name, process_cmd_line, user_name, on_disk, time FROM hb_process_activity WHERE (LOWER(process_cmd_line) LIKE '%snap-confine%' OR LOWER(process_cmd_line) LIKE '%dirtyclone%' OR LOWER(process_cmd_line) LIKE '%enum_protections%' OR LOWER(process_cmd_line) LIKE '%ollama%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') ORDER BY time DESC
```

## triage-findings
<!-- Triage results -->
```agent target=hunter
cite: required
context:
- scope-vulnerable-hosts
- rare-pam-modules
- exploit-behavior
max_iterations: 5
objective: Determine if any host shows a combination of vulnerability exposure, rare
  PAM modules, and exploit-related process activity indicative of privilege escalation
  or persistence.
success_criteria: A verdict of malicious, suspicious, or benign per host with cited
  evidence from the process and module logs.
tools:
- endpoint
```

## route-on-verdict
<!-- Route based on agent verdict -->
if~: "the triage verdict is malicious for at least one host based on exploit execution or unauthorized PAM modules" (confidence: high, judge=hunter)
then: → isolate-endpoint
indeterminate: → forensic-investigation
unavailable: → forensic-investigation (blind_spot: no-file-telemetry)
else: → close-out

## isolate-endpoint
<!-- Isolate the host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the compromised host from the network to prevent lateral movement or further persistence installation.
```
→ forensic-investigation

## forensic-investigation
<!-- Conduct manual forensics -->
```manual target=analyst
Perform a deep dive on the isolated host. Collect the rare PAM module if present, analyze the process tree leading to root transition, and check for any additional persistence mechanisms like cron jobs.
```
→ close-out

## close-out
<!-- Finalize hunt -->
```manual target=analyst
Document the findings, update vulnerability management records, and determine if the detection-candidate process query should be promoted to a standing alert.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, critic, then reviewed by a person.