---
analysis: This hunt correlates known vulnerability inventory with behavioral traffic
  patterns like SCADA protocol usage, which is often not monitored by standard security
  rules.
blind_spots:
- id: incomplete-telemetry
  question: Are there scanning attempts from unmanaged internal devices?
  requires: hb_http_activity and hb_network_connection from perimeter devices
  risk: A scanning host not enrolled in telemetry will not appear in network or HTTP
    logs.
  stage: vulnerability-scanning-and-reconnaissance
- id: http-header-blindness
  question: Was the SPIP X-Spip-Filtre header used in the attack?
  requires: hb_http_activity with header visibility
  risk: The SPIP RCE targets specific HTTP headers which are not fully normalized
    in the current surface, leading to potential misses.
  stage: exploit-public-facing-web-applications
coverage:
- stage: vulnerability-scanning-and-reconnaissance
  status: covered
  steps:
  - identify-vulnerable-assets
  - scada-fingerprinting-traffic
- stage: exploit-public-facing-web-applications
  status: covered
  steps:
  - web-exploitation-attempts
  - triage-signals
- reason: 'Belongs to another part of the ''Metasploit Wrap Up: Payloads and Exploits,
    and Scanners, Oh my!'' series.'
  stage: remote-command-execution-and-payloads
  status: out_of_scope
- reason: 'Belongs to another part of the ''Metasploit Wrap Up: Payloads and Exploits,
    and Scanners, Oh my!'' series.'
  stage: lateral-movement-smb-winrm
  status: out_of_scope
- reason: 'Belongs to another part of the ''Metasploit Wrap Up: Payloads and Exploits,
    and Scanners, Oh my!'' series.'
  stage: persistence-via-process-creation
  status: out_of_scope
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: promote-to-detection
  justification: Public Metasploit module releases lower the bar for opportunistic
    attackers. Proactively hunting for these artifacts ensures the estate is protected
    against known exploit code.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An adversary is using recently released Metasploit scanner and exploit
  modules to fingerprint organization SCADA infrastructure or exploit unauthenticated
  vulnerabilities in public-facing web applications.
labels:
- hunt
- attack.t1190
name: 'Metasploit 2026: External Recon and Web Exploitation'
parameters:
  lookback_days:
    default: '14'
    description: Days of history to examine.
    type: number
  metasploit_cves:
    default:
    - CVE-2026-0265
    - CVE-2026-16232
    - CVE-2026-3576
    - CVE-2026-6826
    - CVE-2026-9082
    - CVE-2026-59774
    description: CVEs targeted by the new Metasploit modules.
    from:
      kind: article
      observed: '2026-08-28'
      ref: metasploit-wrap-up-aug-2026
    type: list[string]
  scope_hosts:
    default: []
    description: List of hostnames from the scoping step to focus the hunt on; leave
      empty for fleet-wide.
    type: list[host]
  suspicious_paths:
    default:
    - /ulap.php pulp-ajax-proxy
    - /ccm/system/dialogs/file/usage/
    - /ccm/system/dialogs/file/usage
    description: Sensitive URL paths associated with the reported vulnerabilities.
    from:
      kind: article
      observed: '2026-08-28'
      ref: metasploit-wrap-up-aug-2026
    type: list[path]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-payloads-exploits-scanners
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Prioritize web servers hosting WordPress or Concrete CMS, and SCADA control
  systems. If no vulnerability findings are current, expand the HTTP query to all
  external-facing assets.
references:
- name: 'Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!'
  url: https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-payloads-exploits-scanners
related:
- hunt: metasploit-payload-execution-and-persistence
  reason: This hunt focuses on initial reconnaissance and unauthenticated exploitation;
    the post-compromise stages are handled separately.
  relation: out-of-scope-alternative
scenario:
  stages:
  - name: Protocol and Application Fingerprinting
    observables:
    - opc.tcp://
    - /ccm/system/dialogs/file/usage/
    - CVE-2026-0265
    - CVE-2026-16232
    - CVE-2026-6826
    slug: vulnerability-scanning-and-reconnaissance
    tactic: initial-access
    techniques:
    - T1190
  - name: Exploitation of Web Vulnerabilities
    observables:
    - ulap.php
    - file://localhost/etc/passwd
    - X-Spip-Filtre
    - CVE-2026-3576
    - CVE-2026-59774
    - CVE-2026-9082
    - CVE-2026-66066
    slug: exploit-public-facing-web-applications
    tactic: initial-access
    techniques:
    - T1190
  - name: Authenticated Execution and Payloads
    observables:
    - PSRP-backed PowerShell session
    - MIPS64 exec payload
    - CVE-2026-19681
    - CVE-2026-21820
    - CVE-2026-56274
    slug: remote-command-execution-and-payloads
    tactic: execution
    techniques:
    - T1059.001
  - name: Lateral Movement via SMB and WinRM
    observables:
    - windows/smb/psexec aarch64
    - winrm_login with SessionType PSRP
    slug: lateral-movement-smb-winrm
    tactic: lateral-movement
    techniques:
    - T1021.002
  - name: Persistence via CreateProcess
    observables:
    - Metasploit persistence modules using create_process instead of cmd_exec
    slug: persistence-via-process-creation
    tactic: persistence
    techniques:
    - T1059.001
  summary: This Metasploit update details a range of exploit and scanner modules targeting
    vulnerabilities in web platforms (Forgejo, WordPress, Drupal, SPIP), networking
    hardware (PAN-OS, Check Point), and SCADA protocols. The framework has been enhanced
    to support remote execution via PSRP-backed PowerShell sessions, cross-platform
    SMB movement on aarch64, and improved persistence through native process creation.
series:
  index: 1
  slug: metasploit-wrap-up-payloads-and-exploits-and-scanners-oh-my
  title: 'Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!'
  total: 2
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  network:
    category: network
    name: Network telemetry
    telemetry:
    - network
  web:
    category: siem
    name: Web server / proxy logs
    telemetry:
    - network
tlp: clear
type: investigation
---


# Metasploit 2026: External Recon and Web Exploitation

This hunt targets the initial access and reconnaissance phases following the release of new Metasploit modules for CVE-2026-3576, CVE-2026-0265, and others. It first identifies hosts known to be vulnerable to these specific CVEs, then fanned out to investigate HTTP and network telemetry for active probing. An agent evaluates whether observed traffic patterns, such as LFI attempts or rare SCADA protocol connections, indicate a successful intrusion.

## identify-vulnerable-assets
<!-- Identify vulnerable assets -->
Locate assets currently known to be vulnerable to the Metasploit modules' target CVEs and retrieve their hostnames for subsequent filtering.

```sqlite target=endpoint role=scoping params=(metasploit_cves=metasploit_cves)
~~~yaml
expected: Hosts with high-severity findings matching the CVE list. Silence means no
  known exposures exist in the inventory.
reads:
- device_uid
- cve_uid
- severity
- title
- affected_package_name
- affected_package_version
silence: not_evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT d.hostname, f.cve_uid, f.severity, f.title, f.affected_package_name, f.affected_package_version FROM hb_vulnerability_finding AS f JOIN hb_devices AS d ON f.device_uid = d.device_uid WHERE instr(',' || '{{metasploit_cves}}' || ',', ',' || f.cve_uid || ',') > 0 AND f.status != 'suppressed'
```

## corroborate-activity
<!-- Corroborate with traffic logs -->
parallel:
- → web-exploitation-attempts
- → scada-fingerprinting-traffic
join: → triage-signals

## web-exploitation-attempts
<!-- Web exploitation attempts -->
Identify HTTP requests targeting AJAX proxies or vulnerable controllers with LFI patterns to detect active exploitation.

```sqlite target=web role=detection-candidate params=(suspicious_paths=suspicious_paths, scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: Requests to ulap.php or Concrete CMS paths, especially with file:// schemes
  in parameters. Silence means no probes were captured.
reads:
- device_hostname
- src_endpoint_ip
- url_path
- url_query
- status_code
- user_agent
- time
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, src_endpoint_ip, url_path, url_query, status_code, user_agent, time FROM hb_http_activity WHERE (instr(',' || '{{suspicious_paths}}' || ',', ',' || LOWER(url_path) || ',') > 0 OR LOWER(url_query) LIKE '%file://%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## scada-fingerprinting-traffic
<!-- SCADA protocol fingerprinting -->
Detect rare connections to OPC-UA binary transport ports on scoped hosts to identify unauthorized SCADA scanning.

```sqlite target=network role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: Connections to port 4840 from unexpected sources. Silence means no OPC-UA
  scanning was observed.
prevalence:
  by: device_hostname
  key:
  - dst_endpoint_ip
  rare_below: 5
reads:
- device_hostname
- dst_endpoint_ip
- dst_endpoint_port
- src_endpoint_ip
- time
silence: not_evidence_of_absence
source: hb_network_connection
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, dst_endpoint_ip, dst_endpoint_port, COUNT(DISTINCT src_endpoint_ip) AS unique_sources, MIN(time) AS first_seen FROM hb_network_connection WHERE dst_endpoint_port = 4840 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, dst_endpoint_ip, dst_endpoint_port HAVING unique_sources < 5
```

## triage-signals
<!-- Triage vulnerabilities and traffic -->
```agent target=hunter
cite: required
context:
- identify-vulnerable-assets
- web-exploitation-attempts
- scada-fingerprinting-traffic
max_iterations: 3
objective: Determine if the HTTP or network traffic suggests successful exploitation
  of the identified vulnerabilities.
success_criteria: A verdict citing malicious traffic to a host with a matching CVE
  finding.
tools:
- endpoint
- network
- web
```

## evaluate-compromise
<!-- Evaluate compromise -->
if~: "The triage verdict is malicious for at least one host" (confidence: high, judge=hunter)
then: → isolate-endpoint
indeterminate: → analyst-manual-review
unavailable: → analyst-manual-review (blind_spot: incomplete-telemetry)
else: → close-out

## isolate-endpoint
<!-- Isolate affected host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host and initiate the incident response process for initial access.
```
→ analyst-manual-review

## analyst-manual-review
<!-- Analyst manual review -->
```manual target=analyst
Review the full url_query for LFI patterns and verify if the status_code was 200 on vulnerable hosts.
```
→ close-out

## close-out
<!-- Close out hunt -->
```manual target=analyst
Report any missing patches identified in the scoping step and tuning recommendations for the HTTP detection candidate.
```
→ end
