{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Public Metasploit module releases lower the bar for opportunistic attackers. Proactively hunting for these artifacts ensures the estate is protected against known exploit code."
      },
      "name": "Metasploit 2026: External Recon and Web Exploitation",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1190"
      ],
      "series": {
        "slug": "metasploit-wrap-up-payloads-and-exploits-and-scanners-oh-my",
        "index": 1,
        "title": "Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!",
        "total": 2
      },
      "related": [
        {
          "hunt": "metasploit-payload-execution-and-persistence",
          "reason": "This hunt focuses on initial reconnaissance and unauthenticated exploitation; the post-compromise stages are handled separately.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "network": {
          "name": "Network telemetry",
          "category": "network",
          "telemetry": [
            "network"
          ]
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "This hunt correlates known vulnerability inventory with behavioral traffic patterns like SCADA protocol usage, which is often not monitored by standard security rules.",
      "coverage": [
        {
          "stage": "vulnerability-scanning-and-reconnaissance",
          "steps": [
            "identify-vulnerable-assets",
            "scada-fingerprinting-traffic"
          ],
          "status": "covered"
        },
        {
          "stage": "exploit-public-facing-web-applications",
          "steps": [
            "web-exploitation-attempts",
            "triage-signals"
          ],
          "status": "covered"
        },
        {
          "stage": "remote-command-execution-and-payloads",
          "reason": "Belongs to another part of the 'Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "lateral-movement-smb-winrm",
          "reason": "Belongs to another part of the 'Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "persistence-via-process-creation",
          "reason": "Belongs to another part of the 'Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Protocol and Application Fingerprinting",
            "slug": "vulnerability-scanning-and-reconnaissance",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "opc.tcp://",
              "/ccm/system/dialogs/file/usage/",
              "CVE-2026-0265",
              "CVE-2026-16232",
              "CVE-2026-6826"
            ]
          },
          {
            "name": "Exploitation of Web Vulnerabilities",
            "slug": "exploit-public-facing-web-applications",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "ulap.php",
              "file://localhost/etc/passwd",
              "X-Spip-Filtre",
              "CVE-2026-3576",
              "CVE-2026-59774",
              "CVE-2026-9082",
              "CVE-2026-66066"
            ]
          },
          {
            "name": "Authenticated Execution and Payloads",
            "slug": "remote-command-execution-and-payloads",
            "tactic": "execution",
            "techniques": [
              "T1059.001"
            ],
            "observables": [
              "PSRP-backed PowerShell session",
              "MIPS64 exec payload",
              "CVE-2026-19681",
              "CVE-2026-21820",
              "CVE-2026-56274"
            ]
          },
          {
            "name": "Lateral Movement via SMB and WinRM",
            "slug": "lateral-movement-smb-winrm",
            "tactic": "lateral-movement",
            "techniques": [
              "T1021.002"
            ],
            "observables": [
              "windows/smb/psexec aarch64",
              "winrm_login with SessionType PSRP"
            ]
          },
          {
            "name": "Persistence via CreateProcess",
            "slug": "persistence-via-process-creation",
            "tactic": "persistence",
            "techniques": [
              "T1059.001"
            ],
            "observables": [
              "Metasploit persistence modules using create_process instead of cmd_exec"
            ]
          }
        ],
        "summary": "This Metasploit update details a range of exploit and scanner modules targeting vulnerabilities in web platforms (Forgejo, WordPress, Drupal, SPIP), networking hardware (PAN-OS, Check Point), and SCADA protocols. The framework has been enhanced to support remote execution via PSRP-backed PowerShell sessions, cross-platform SMB movement on aarch64, and improved persistence through native process creation."
      },
      "severity": "high",
      "rationale": "Prioritize web servers hosting WordPress or Concrete CMS, and SCADA control systems. If no vulnerability findings are current, expand the HTTP query to all external-facing assets.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary is using recently released Metasploit scanner and exploit modules to fingerprint organization SCADA infrastructure or exploit unauthenticated vulnerabilities in public-facing web applications.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "List of hostnames from the scoping step to focus the hunt on; leave empty for fleet-wide."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "metasploit_cves": {
          "from": {
            "ref": "metasploit-wrap-up-aug-2026",
            "kind": "article",
            "observed": "2026-08-28"
          },
          "type": "list[string]",
          "default": [
            "CVE-2026-0265",
            "CVE-2026-16232",
            "CVE-2026-3576",
            "CVE-2026-6826",
            "CVE-2026-9082",
            "CVE-2026-59774"
          ],
          "description": "CVEs targeted by the new Metasploit modules."
        },
        "suspicious_paths": {
          "from": {
            "ref": "metasploit-wrap-up-aug-2026",
            "kind": "article",
            "observed": "2026-08-28"
          },
          "type": "list[path]",
          "default": [
            "/ulap.php pulp-ajax-proxy",
            "/ccm/system/dialogs/file/usage/",
            "/ccm/system/dialogs/file/usage"
          ],
          "description": "Sensitive URL paths associated with the reported vulnerabilities."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-payloads-exploits-scanners",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-payloads-exploits-scanners",
          "name": "Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!"
        }
      ],
      "blind_spots": [
        {
          "id": "incomplete-telemetry",
          "risk": "A scanning host not enrolled in telemetry will not appear in network or HTTP logs.",
          "stage": "vulnerability-scanning-and-reconnaissance",
          "question": "Are there scanning attempts from unmanaged internal devices?",
          "requires": "hb_http_activity and hb_network_connection from perimeter devices"
        },
        {
          "id": "http-header-blindness",
          "risk": "The SPIP RCE targets specific HTTP headers which are not fully normalized in the current surface, leading to potential misses.",
          "stage": "exploit-public-facing-web-applications",
          "question": "Was the SPIP X-Spip-Filtre header used in the attack?",
          "requires": "hb_http_activity with header visibility"
        }
      ]
    },
    "name": "Metasploit 2026: External Recon and Web Exploitation",
    "description": "This hunt targets the initial access and reconnaissance phases following the release of new Metasploit modules for CVE-2026-3576, CVE-2026-0265, and others. It first identifies hosts known to be vulnerable to these specific CVEs, then fanned out to investigate HTTP and network telemetry for active probing. An agent evaluates whether observed traffic patterns, such as LFI attempts or rare SCADA protocol connections, indicate a successful intrusion."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "metasploit-wrap-up-payloads-and-exploits-and-scanners-oh-my",
          "index": 1,
          "title": "Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!",
          "total": 2
        },
        "coverage": [
          {
            "stage": "vulnerability-scanning-and-reconnaissance",
            "steps": [
              "identify-vulnerable-assets",
              "scada-fingerprinting-traffic"
            ],
            "status": "covered"
          },
          {
            "stage": "exploit-public-facing-web-applications",
            "steps": [
              "web-exploitation-attempts",
              "triage-signals"
            ],
            "status": "covered"
          },
          {
            "stage": "remote-command-execution-and-payloads",
            "reason": "Belongs to another part of the 'Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "lateral-movement-smb-winrm",
            "reason": "Belongs to another part of the 'Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "persistence-via-process-creation",
            "reason": "Belongs to another part of the 'Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary is using recently released Metasploit scanner and exploit modules to fingerprint organization SCADA infrastructure or exploit unauthenticated vulnerabilities in public-facing web applications.",
        "blind_spots": [
          {
            "id": "incomplete-telemetry",
            "risk": "A scanning host not enrolled in telemetry will not appear in network or HTTP logs.",
            "stage": "vulnerability-scanning-and-reconnaissance",
            "question": "Are there scanning attempts from unmanaged internal devices?",
            "requires": "hb_http_activity and hb_network_connection from perimeter devices"
          },
          {
            "id": "http-header-blindness",
            "risk": "The SPIP RCE targets specific HTTP headers which are not fully normalized in the current surface, leading to potential misses.",
            "stage": "exploit-public-facing-web-applications",
            "question": "Was the SPIP X-Spip-Filtre header used in the attack?",
            "requires": "hb_http_activity with header visibility"
          }
        ],
        "scoping_notes": "Prioritize web servers hosting WordPress or Concrete CMS, and SCADA control systems. If no vulnerability findings are current, expand the HTTP query to all external-facing assets.",
        "beyond_detection": "This hunt correlates known vulnerability inventory with behavioral traffic patterns like SCADA protocol usage, which is often not monitored by standard security rules."
      }
    },
    {
      "id": "identify-vulnerable-assets",
      "type": "query",
      "label": "Identify vulnerable assets",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT d.hostname, f.cve_uid, f.severity, f.title, f.affected_package_name, f.affected_package_version FROM hb_vulnerability_finding AS f JOIN hb_devices AS d ON f.device_uid = d.device_uid WHERE instr(',' || '{{metasploit_cves}}' || ',', ',' || f.cve_uid || ',') > 0 AND f.status != 'suppressed'",
        "surface": "hb_vulnerability_finding",
        "description": "Locate assets currently known to be vulnerable to the Metasploit modules' target CVEs and retrieve their hostnames for subsequent filtering.",
        "expected_signal": "Hosts with high-severity findings matching the CVE list. Silence means no known exposures exist in the inventory."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify vulnerable assets",
        "reads": [
          "device_uid",
          "cve_uid",
          "severity",
          "title",
          "affected_package_name",
          "affected_package_version"
        ],
        "source": "hb_vulnerability_finding",
        "target": "endpoint",
        "content": "SELECT d.hostname, f.cve_uid, f.severity, f.title, f.affected_package_name, f.affected_package_version FROM hb_vulnerability_finding AS f JOIN hb_devices AS d ON f.device_uid = d.device_uid WHERE instr(',' || '{{metasploit_cves}}' || ',', ',' || f.cve_uid || ',') > 0 AND f.status != 'suppressed'",
        "silence": "not_evidence_of_absence",
        "expected": "Hosts with high-severity findings matching the CVE list. Silence means no known exposures exist in the inventory.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "web-exploitation-attempts",
      "type": "query",
      "label": "Web exploitation attempts",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "web",
        "content": "SELECT device_hostname, src_endpoint_ip, url_path, url_query, status_code, user_agent, time FROM hb_http_activity WHERE (instr(',' || '{{suspicious_paths}}' || ',', ',' || LOWER(url_path) || ',') > 0 OR LOWER(url_query) LIKE '%file://%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_http_activity",
        "description": "Identify HTTP requests targeting AJAX proxies or vulnerable controllers with LFI patterns to detect active exploitation.",
        "expected_signal": "Requests to ulap.php or Concrete CMS paths, especially with file:// schemes in parameters. Silence means no probes were captured."
      },
      "parents": [
        {
          "id": "identify-vulnerable-assets"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Web exploitation attempts",
        "reads": [
          "device_hostname",
          "src_endpoint_ip",
          "url_path",
          "url_query",
          "status_code",
          "user_agent",
          "time"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT device_hostname, src_endpoint_ip, url_path, url_query, status_code, user_agent, time FROM hb_http_activity WHERE (instr(',' || '{{suspicious_paths}}' || ',', ',' || LOWER(url_path) || ',') > 0 OR LOWER(url_query) LIKE '%file://%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Requests to ulap.php or Concrete CMS paths, especially with file:// schemes in parameters. Silence means no probes were captured.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "scada-fingerprinting-traffic",
      "type": "query",
      "label": "SCADA protocol fingerprinting",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "network",
        "content": "SELECT device_hostname, dst_endpoint_ip, dst_endpoint_port, COUNT(DISTINCT src_endpoint_ip) AS unique_sources, MIN(time) AS first_seen FROM hb_network_connection WHERE dst_endpoint_port = 4840 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, dst_endpoint_ip, dst_endpoint_port HAVING unique_sources < 5",
        "surface": "hb_network_connection",
        "description": "Detect rare connections to OPC-UA binary transport ports on scoped hosts to identify unauthorized SCADA scanning.",
        "expected_signal": "Connections to port 4840 from unexpected sources. Silence means no OPC-UA scanning was observed."
      },
      "parents": [
        {
          "id": "identify-vulnerable-assets"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "SCADA protocol fingerprinting",
        "reads": [
          "device_hostname",
          "dst_endpoint_ip",
          "dst_endpoint_port",
          "src_endpoint_ip",
          "time"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT device_hostname, dst_endpoint_ip, dst_endpoint_port, COUNT(DISTINCT src_endpoint_ip) AS unique_sources, MIN(time) AS first_seen FROM hb_network_connection WHERE dst_endpoint_port = 4840 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, dst_endpoint_ip, dst_endpoint_port HAVING unique_sources < 5",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Connections to port 4840 from unexpected sources. Silence means no OPC-UA scanning was observed.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "dst_endpoint_ip"
          ],
          "rare_below": 5
        },
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "triage-signals",
      "type": "analytic",
      "label": "Triage vulnerabilities and traffic",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "network",
          "web"
        ],
        "context": [
          "identify-vulnerable-assets",
          "web-exploitation-attempts",
          "scada-fingerprinting-traffic"
        ],
        "objective": "Determine if the HTTP or network traffic suggests successful exploitation of the identified vulnerabilities.",
        "description": "Evaluate if the observed traffic on vulnerable hosts indicates successful exploitation.",
        "max_iterations": 3,
        "expected_signal": "A per-host verdict linking the vulnerability to the observed behavior.",
        "success_criteria": "A verdict citing malicious traffic to a host with a matching CVE finding."
      },
      "parents": [
        {
          "id": "web-exploitation-attempts",
          "kind": "merge"
        },
        {
          "id": "scada-fingerprinting-traffic",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "evaluate-compromise",
      "type": "checkpoint",
      "label": "Evaluate compromise",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "The triage verdict is malicious for at least one host",
        "condition": "The triage verdict is malicious for at least one host",
        "blind_spot": "incomplete-telemetry",
        "confidence": "high",
        "description": "Route to remediation if exploitation is confirmed by the triage agent.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-signals"
        }
      ]
    },
    {
      "id": "isolate-endpoint",
      "type": "action",
      "label": "Isolate affected host",
      "config": {
        "target": "endpoint",
        "description": "Halt further exploitation on confirmed compromised hosts by isolating them from the network.",
        "instructions": "Isolate the host and initiate the incident response process for initial access.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "evaluate-compromise",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-manual-review",
      "type": "task",
      "label": "Analyst manual review",
      "config": {
        "assignee": "analyst",
        "description": "Verify the agent's findings and assess the payload content in HTTP queries manually.",
        "instructions": "Review the full url_query for LFI patterns and verify if the status_code was 200 on vulnerable hosts."
      },
      "parents": [
        {
          "id": "evaluate-compromise",
          "branch": "default"
        },
        {
          "id": "evaluate-compromise",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-endpoint"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out hunt",
      "config": {
        "assignee": "analyst",
        "description": "Finalize findings and record recommendations for detection engineering and vulnerability management.",
        "instructions": "Report any missing patches identified in the scoping step and tuning recommendations for the HTTP detection candidate."
      },
      "parents": [
        {
          "id": "evaluate-compromise",
          "branch": "on_refutes"
        },
        {
          "id": "analyst-manual-review"
        }
      ]
    }
  ]
}