{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "The release of new Metasploit modules lowers the bar for exploiting these specific vulnerabilities. Proactively hunting for these behaviors ensures detection of intrusions that bypass static signatures."
      },
      "name": "Local Escalation and Persistence via Metasploit Modules",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1068",
        "attack.t1556",
        "attack.t1574.002",
        "attack.t1518.001",
        "discovery",
        "execution",
        "initial access",
        "persistence",
        "privilege escalation"
      ],
      "series": {
        "slug": "metasploit-wrap-up-a-collection-of-what-can-only-be-called-eclectic-modules",
        "index": 2,
        "title": "Metasploit Wrap Up: A Collection of What Can Only Be Called Eclectic Modules",
        "total": 2
      },
      "related": [
        {
          "hunt": "unauthenticated-rce-web-services",
          "reason": "This hunt focuses on post-exploitation local activity; initial access via web service exploits is covered in a sibling hunt.",
          "relation": "out-of-scope-alternative"
        },
        {
          "hunt": "metasploit-rce-aarch64-payload-delivery",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A single rule might flag the exploit name, but this hunt combines vulnerability state, stack-counted module prevalence, and process behavioral analysis (like on_disk = 0) to provide a complete picture of the post-exploitation phase.",
      "coverage": [
        {
          "stage": "linux-local-privilege-escalation",
          "steps": [
            "exploit-behavior"
          ],
          "status": "covered"
        },
        {
          "stage": "persistence-via-auth-and-config",
          "steps": [
            "rare-pam-modules",
            "exploit-behavior"
          ],
          "status": "covered"
        },
        {
          "stage": "security-software-discovery",
          "steps": [
            "exploit-behavior"
          ],
          "status": "covered"
        },
        {
          "stage": "unauthenticated-rce-web-services",
          "reason": "Belongs to another part of the 'Metasploit Wrap Up: A Collection of What Can Only Be Called Eclectic Modules' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "windows-aarch64-payload-fetch",
          "reason": "Belongs to another part of the 'Metasploit Wrap Up: A Collection of What Can Only Be Called Eclectic Modules' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Unauthenticated RCE in Web and LLM Services",
            "slug": "unauthenticated-rce-web-services",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "POST requests to /validate endpoint with exec_globals parameter (Langflow)",
              "Modification of FFMPEG Executable Path settings in dizqueTV",
              "Requests to MCP test REST endpoints in LiteLLM proxy",
              "Struts BeanUtils exploitation against N-able N-central"
            ]
          },
          {
            "name": "Windows AArch64 Payload Fetching",
            "slug": "windows-aarch64-payload-fetch",
            "tactic": "execution",
            "techniques": [
              "T1105",
              "T1059"
            ],
            "observables": [
              "Execution of cmd/windows/http/aarch64/exec",
              "Execution of cmd/windows/tftp/aarch64/shell_reverse_tcp",
              "Command-line file transfers via FTP, HTTP, HTTPS, or TFTP on AArch64 Windows systems"
            ]
          },
          {
            "name": "Linux Local Privilege Escalation",
            "slug": "linux-local-privilege-escalation",
            "tactic": "privilege-escalation",
            "techniques": [
              "T1068"
            ],
            "observables": [
              "Exploitation of snap-confine TOCTOU race condition (CVE-2026-3888)",
              "DirtyClone exploit execution (CVE-2026-43503)",
              "Execution as root inside OpenCTI API containers via safeEjs sandbox escape"
            ]
          },
          {
            "name": "Persistence via PAM and Config Tampering",
            "slug": "persistence-via-auth-and-config",
            "tactic": "persistence",
            "techniques": [
              "T1556",
              "T1574.002"
            ],
            "observables": [
              "Upload of malicious .so files into the Linux PAM authentication chain",
              "Path traversal exploitation in Ollama auto-update mechanism (CVE-2026-42249)"
            ]
          },
          {
            "name": "Security Software Discovery",
            "slug": "security-software-discovery",
            "tactic": "discovery",
            "techniques": [
              "T1518.001"
            ],
            "observables": [
              "Execution of post/linux/gather/enum_protections",
              "Automated enumeration of AV/EDR protections on the target system"
            ]
          }
        ],
        "summary": "This campaign involves the exploitation of unauthenticated remote code execution vulnerabilities in LLM-related services and IPTV servers, followed by the delivery of fetch-based payloads to Windows AArch64 systems. Attackers then perform local privilege escalation on Linux systems and establish persistence through configuration tampering or malicious authentication modules."
      },
      "severity": "high",
      "rationale": "Focus on Linux servers running snapd and Windows machines running Ollama. Use the vulnerability scoping step to identify high-priority targets first.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary escalates Linux privileges via snap-confine or DirtyClone and establishes persistence through PAM backdoors or Ollama auto-update tampering.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Optional list of hostnames to focus the hunt; leave empty for all hosts."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-a-collection-of-what-can-only-be-called-eclectic-modules",
          "gates": [
            "dry-run",
            "lint",
            "critic"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-a-collection-of-what-can-only-be-called-eclectic-modules",
          "name": "Rapid7 \u2014 Metasploit Wrap Up: A Collection of What Can Only Be Called Eclectic Modules"
        }
      ],
      "blind_spots": [
        {
          "id": "no-file-telemetry",
          "risk": "A module on disk that hasn't been loaded yet will be missed by the prevalence check on hb_module_activity.",
          "stage": "persistence-via-auth-and-config",
          "question": "Was a malicious PAM module uploaded but not yet loaded into a process?",
          "requires": "hb_file_activity with deep scan"
        },
        {
          "id": "no-script-content",
          "risk": "If the Metasploit module discovery logic is executed via an existing interpreter without unique command line arguments, hb_process_activity might miss it.",
          "stage": "security-software-discovery",
          "question": "Is the enumeration module running entirely in memory without spawning new processes?",
          "requires": "hb_script_activity with full block capture"
        }
      ]
    },
    "name": "Local Escalation and Persistence via Metasploit Modules",
    "description": "The adversary uses Metasploit modules to move from a beachhead to full control. This hunt identifies vulnerable systems using vulnerability discovery data and then looks for behavioral signals: the query identifies rare PAM modules loaded into the authentication chain and process activity associated with Linux privilege escalation. An agent weighs the evidence to identify compromised hosts where an attacker transitioned to root or established persistent access."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "metasploit-wrap-up-a-collection-of-what-can-only-be-called-eclectic-modules",
          "index": 2,
          "title": "Metasploit Wrap Up: A Collection of What Can Only Be Called Eclectic Modules",
          "total": 2
        },
        "coverage": [
          {
            "stage": "linux-local-privilege-escalation",
            "steps": [
              "exploit-behavior"
            ],
            "status": "covered"
          },
          {
            "stage": "persistence-via-auth-and-config",
            "steps": [
              "rare-pam-modules",
              "exploit-behavior"
            ],
            "status": "covered"
          },
          {
            "stage": "security-software-discovery",
            "steps": [
              "exploit-behavior"
            ],
            "status": "covered"
          },
          {
            "stage": "unauthenticated-rce-web-services",
            "reason": "Belongs to another part of the 'Metasploit Wrap Up: A Collection of What Can Only Be Called Eclectic Modules' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "windows-aarch64-payload-fetch",
            "reason": "Belongs to another part of the 'Metasploit Wrap Up: A Collection of What Can Only Be Called Eclectic Modules' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary escalates Linux privileges via snap-confine or DirtyClone and establishes persistence through PAM backdoors or Ollama auto-update tampering.",
        "blind_spots": [
          {
            "id": "no-file-telemetry",
            "risk": "A module on disk that hasn't been loaded yet will be missed by the prevalence check on hb_module_activity.",
            "stage": "persistence-via-auth-and-config",
            "question": "Was a malicious PAM module uploaded but not yet loaded into a process?",
            "requires": "hb_file_activity with deep scan"
          },
          {
            "id": "no-script-content",
            "risk": "If the Metasploit module discovery logic is executed via an existing interpreter without unique command line arguments, hb_process_activity might miss it.",
            "stage": "security-software-discovery",
            "question": "Is the enumeration module running entirely in memory without spawning new processes?",
            "requires": "hb_script_activity with full block capture"
          }
        ],
        "scoping_notes": "Focus on Linux servers running snapd and Windows machines running Ollama. Use the vulnerability scoping step to identify high-priority targets first.",
        "beyond_detection": "A single rule might flag the exploit name, but this hunt combines vulnerability state, stack-counted module prevalence, and process behavioral analysis (like on_disk = 0) to provide a complete picture of the post-exploitation phase."
      }
    },
    {
      "id": "scope-vulnerable-hosts",
      "type": "query",
      "label": "Scope vulnerable hosts",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_uid, cve_uid, affected_package_name, severity_id, title FROM hb_vulnerability_finding WHERE cve_uid IN ('CVE-2026-3888', 'CVE-2026-43503', 'CVE-2026-42249')",
        "surface": "hb_vulnerability_finding",
        "description": "Identify hosts with known vulnerabilities targeted by the new Metasploit modules to focus the behavioral queries.",
        "expected_signal": "Rows identify hosts running vulnerable versions of snapd, Ollama, or relevant Linux kernels. Silence means no known vulnerable systems were reported."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Scope vulnerable hosts",
        "reads": [
          "device_uid",
          "cve_uid",
          "affected_package_name",
          "severity_id",
          "title"
        ],
        "source": "hb_vulnerability_finding",
        "target": "endpoint",
        "content": "SELECT device_uid, cve_uid, affected_package_name, severity_id, title FROM hb_vulnerability_finding WHERE cve_uid IN ('CVE-2026-3888', 'CVE-2026-43503', 'CVE-2026-42249')",
        "silence": "not_evidence_of_absence",
        "expected": "Rows identify hosts running vulnerable versions of snapd, Ollama, or relevant Linux kernels. Silence means no known vulnerable systems were reported.",
        "verified": "dry-run",
        "verified_at": "2026-10-10"
      }
    },
    {
      "id": "rare-pam-modules",
      "type": "query",
      "label": "Identify rare PAM modules",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT module_path, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_module_activity WHERE (LOWER(module_path) LIKE '/lib/security/%.so' OR LOWER(module_path) LIKE '/usr/lib/security/%.so') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY module_path HAVING hosts <= 2 ORDER BY hosts ASC",
        "surface": "hb_module_activity",
        "description": "Find potentially malicious .so files loaded into the Linux authentication chain that indicate a PAM backdoor.",
        "expected_signal": "A module path seen on only one or two hosts. Genuine PAM modules should be present across the fleet; a backdoor will appear unique to the target."
      },
      "parents": [
        {
          "id": "scope-vulnerable-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Identify rare PAM modules",
        "reads": [
          "module_path",
          "device_hostname",
          "time"
        ],
        "source": "hb_module_activity",
        "target": "endpoint",
        "content": "SELECT module_path, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_module_activity WHERE (LOWER(module_path) LIKE '/lib/security/%.so' OR LOWER(module_path) LIKE '/usr/lib/security/%.so') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY module_path HAVING hosts <= 2 ORDER BY hosts ASC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A module path seen on only one or two hosts. Genuine PAM modules should be present across the fleet; a backdoor will appear unique to the target.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "module_path"
          ],
          "rare_below": 2
        },
        "verified_at": "2026-10-10"
      }
    },
    {
      "id": "exploit-behavior",
      "type": "query",
      "label": "Hunt for exploit execution and discovery",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, user_name, on_disk, time FROM hb_process_activity WHERE (LOWER(process_cmd_line) LIKE '%snap-confine%' OR LOWER(process_cmd_line) LIKE '%dirtyclone%' OR LOWER(process_cmd_line) LIKE '%enum_protections%' OR LOWER(process_cmd_line) LIKE '%ollama%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') ORDER BY time DESC",
        "surface": "hb_process_activity",
        "description": "Detect the execution of LPE exploits, security software discovery, and Ollama configuration changes.",
        "expected_signal": "Processes mentioning exploit names or the Metasploit discovery module. Transition of these processes to root or processes with on_disk = 0 are high-confidence indicators."
      },
      "parents": [
        {
          "id": "scope-vulnerable-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Hunt for exploit execution and discovery",
        "reads": [
          "device_hostname",
          "process_name",
          "process_cmd_line",
          "user_name",
          "on_disk",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, user_name, on_disk, time FROM hb_process_activity WHERE (LOWER(process_cmd_line) LIKE '%snap-confine%' OR LOWER(process_cmd_line) LIKE '%dirtyclone%' OR LOWER(process_cmd_line) LIKE '%enum_protections%' OR LOWER(process_cmd_line) LIKE '%ollama%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') ORDER BY time DESC",
        "silence": "not_evidence_of_absence",
        "expected": "Processes mentioning exploit names or the Metasploit discovery module. Transition of these processes to root or processes with on_disk = 0 are high-confidence indicators.",
        "verified": "dry-run",
        "verified_at": "2026-10-10"
      }
    },
    {
      "id": "triage-findings",
      "type": "analytic",
      "label": "Triage results",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "scope-vulnerable-hosts",
          "rare-pam-modules",
          "exploit-behavior"
        ],
        "objective": "Determine if any host shows a combination of vulnerability exposure, rare PAM modules, and exploit-related process activity indicative of privilege escalation or persistence.",
        "description": "Analyze the findings from the scoping and behavioral queries to identify compromised hosts.",
        "max_iterations": 5,
        "success_criteria": "A verdict of malicious, suspicious, or benign per host with cited evidence from the process and module logs."
      },
      "parents": [
        {
          "id": "rare-pam-modules",
          "kind": "merge"
        },
        {
          "id": "exploit-behavior",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route based on agent verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage verdict is malicious for at least one host based on exploit execution or unauthorized PAM modules",
        "condition": "the triage verdict is malicious for at least one host based on exploit execution or unauthorized PAM modules",
        "blind_spot": "no-file-telemetry",
        "confidence": "high",
        "description": "Direct the workflow based on the risk identified by the triage agent.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-findings"
        }
      ]
    },
    {
      "id": "isolate-endpoint",
      "type": "action",
      "label": "Isolate the host",
      "config": {
        "target": "endpoint",
        "description": "Contain the threat on identified malicious hosts.",
        "instructions": "Isolate the compromised host from the network to prevent lateral movement or further persistence installation.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "forensic-investigation",
      "type": "task",
      "label": "Conduct manual forensics",
      "config": {
        "assignee": "analyst",
        "description": "Confirm the extent of the compromise and the nature of the persistence mechanism.",
        "instructions": "Perform a deep dive on the isolated host. Collect the rare PAM module if present, analyze the process tree leading to root transition, and check for any additional persistence mechanisms like cron jobs."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-endpoint"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Finalize hunt",
      "config": {
        "assignee": "analyst",
        "description": "Conclude the hunt and record outcomes for tuning.",
        "instructions": "Document the findings, update vulnerability management records, and determine if the detection-candidate process query should be promoted to a standing alert."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "forensic-investigation"
        }
      ]
    }
  ]
}