← All hunts high TLP:CLEAR Part 1 of 2

Metasploit 2026: External Recon and Web Exploitation

An adversary is using recently released Metasploit scanner and exploit modules to fingerprint organization SCADA infrastructure or exploit unauthenticated vulnerabilities in public-facing web applications.

Based on research by Rapid7 2026-09-28 9 steps · 3 queries T1190

Brief

Why Now

The Rapid7 "Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!" (https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-payloads-exploits-scanners) highlights new scanner and exploit modules targeting unauthenticated web vulnerabilities and industrial control systems. These public releases lower the barrier for opportunistic actors to scan and exploit organizational infrastructure.

How the Hunt Flows

The first step queries the vulnerability inventory to list every host matching specific CVEs like CVE-2026-3576 and CVE-2026-0265. This scoping phase narrows the focus to assets where these Metasploit modules are effective. In the next phase, the hunt runs parallel queries across HTTP and network surfaces. One query monitors for suspicious URL paths associated with Concrete CMS and AJAX proxies, looking specifically for file-based protocols in parameters. Simultaneously, another query checks for rare network connections on port 4840 to identify unauthorized OPC-UA binary transport traffic. A triage agent then evaluates the collected telemetry against the vulnerability findings. It confirms whether the observed traffic patterns indicate a successful intrusion by linking the exploit attempts to hosts known to be vulnerable. Finally, the hunt routes confirmed malicious activity to an automated isolation task. This halts the adversary's progress while an analyst manually reviews the full payload content and status codes to finalize the incident response.

Blind Spots

This hunt relies on managed endpoint and network telemetry. It cannot see scanning attempts originating from or targeting unmanaged devices that do not report to the central logs. Furthermore, specific exploit patterns like the SPIP RCE target HTTP headers that are not always normalized in the current telemetry surface, creating a gap in coverage for those specific techniques.

In this series

Steps

  1. Identify vulnerable assets

    Query · scoping

    Locate assets currently known to be vulnerable to the Metasploit modules' target CVEs and retrieve their hostnames for subsequent filtering.

    reads hb_vulnerability_findingsql
    SELECT d.hostname, f.cve_uid, f.severity, f.title, f.affected_package_name, f.affected_package_version FROM hb_vulnerability_finding AS f JOIN hb_devices AS d ON f.device_uid = d.device_uid WHERE instr(',' || '{{metasploit_cves}}' || ',', ',' || f.cve_uid || ',') > 0 AND f.status != 'suppressed'

    What a hit looks like. Hosts with high-severity findings matching the CVE list. Silence means no known exposures exist in the inventory.

  2. Web exploitation attempts

    Query · detection candidate

    Identify HTTP requests targeting AJAX proxies or vulnerable controllers with LFI patterns to detect active exploitation.

    reads hb_http_activitysql
    SELECT device_hostname, src_endpoint_ip, url_path, url_query, status_code, user_agent, time FROM hb_http_activity WHERE (instr(',' || '{{suspicious_paths}}' || ',', ',' || LOWER(url_path) || ',') > 0 OR LOWER(url_query) LIKE '%file://%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Requests to ulap.php or Concrete CMS paths, especially with file:// schemes in parameters. Silence means no probes were captured.

  3. SCADA protocol fingerprinting

    Query · baseline

    Detect rare connections to OPC-UA binary transport ports on scoped hosts to identify unauthorized SCADA scanning.

    reads hb_network_connectionsql
    SELECT device_hostname, dst_endpoint_ip, dst_endpoint_port, COUNT(DISTINCT src_endpoint_ip) AS unique_sources, MIN(time) AS first_seen FROM hb_network_connection WHERE dst_endpoint_port = 4840 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, dst_endpoint_ip, dst_endpoint_port HAVING unique_sources < 5

    What a hit looks like. Connections to port 4840 from unexpected sources. Silence means no OPC-UA scanning was observed.

  4. Triage vulnerabilities and traffic

    Agent triage

    Evaluate if the observed traffic on vulnerable hosts indicates successful exploitation.

  5. Evaluate compromise

    Decision

    Route to remediation if exploitation is confirmed by the triage agent.

  6. Isolate affected host

    Response action

    Halt further exploitation on confirmed compromised hosts by isolating them from the network.

  7. Analyst manual review

    Analyst task

    Verify the agent's findings and assess the payload content in HTTP queries manually.

  8. Close out hunt

    Analyst task

    Finalize findings and record recommendations for detection engineering and vulnerability management.

Coverage

Scenario coverage

StageCoveredHow, or why not
Protocol and Application Fingerprinting
T1190
Yes identify-vulnerable-assets, scada-fingerprinting-traffic
Exploitation of Web Vulnerabilities
T1190
Yes web-exploitation-attempts, triage-signals
Authenticated Execution and Payloads
T1059.001
Out of scope Belongs to another part of the 'Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!' series.
Lateral Movement via SMB and WinRM
T1021.002
Out of scope Belongs to another part of the 'Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!' series.
Persistence via CreateProcess
T1059.001
Out of scope Belongs to another part of the 'Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!' series.

Blind spots

  • Needs hb_http_activity and hb_network_connection from perimeter devices. A scanning host not enrolled in telemetry will not appear in network or HTTP logs. It would answer Are there scanning attempts from unmanaged internal devices?.
  • Needs hb_http_activity with header visibility. The SPIP RCE targets specific HTTP headers which are not fully normalized in the current surface, leading to potential misses. It would answer Was the SPIP X-Spip-Filtre header used in the attack?.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
lookback_daysnumber14Days of history to examine.
metasploit_cveslist[string]CVE-2026-0265, CVE-2026-16232, CVE-2026-3576, CVE-2026-6826, CVE-2026-9082, CVE-2026-59774CVEs targeted by the new Metasploit modules.
scope_hostslist[host]—List of hostnames from the scoping step to focus the hunt on; leave empty for fleet-wide.
suspicious_pathslist[path]/ulap.php pulp-ajax-proxy, /ccm/system/dialogs/file/usage/, /ccm/system/dialogs/file/usageSensitive URL paths associated with the reported vulnerabilities.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint
Network telemetrynetworknetwork
Web server / proxy logssiemnetwork

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: This hunt correlates known vulnerability inventory with behavioral traffic
  patterns like SCADA protocol usage, which is often not monitored by standard security
  rules.
blind_spots:
- id: incomplete-telemetry
  question: Are there scanning attempts from unmanaged internal devices?
  requires: hb_http_activity and hb_network_connection from perimeter devices
  risk: A scanning host not enrolled in telemetry will not appear in network or HTTP
    logs.
  stage: vulnerability-scanning-and-reconnaissance
- id: http-header-blindness
  question: Was the SPIP X-Spip-Filtre header used in the attack?
  requires: hb_http_activity with header visibility
  risk: The SPIP RCE targets specific HTTP headers which are not fully normalized
    in the current surface, leading to potential misses.
  stage: exploit-public-facing-web-applications
coverage:
- stage: vulnerability-scanning-and-reconnaissance
  status: covered
  steps:
  - identify-vulnerable-assets
  - scada-fingerprinting-traffic
- stage: exploit-public-facing-web-applications
  status: covered
  steps:
  - web-exploitation-attempts
  - triage-signals
- reason: 'Belongs to another part of the ''Metasploit Wrap Up: Payloads and Exploits,
    and Scanners, Oh my!'' series.'
  stage: remote-command-execution-and-payloads
  status: out_of_scope
- reason: 'Belongs to another part of the ''Metasploit Wrap Up: Payloads and Exploits,
    and Scanners, Oh my!'' series.'
  stage: lateral-movement-smb-winrm
  status: out_of_scope
- reason: 'Belongs to another part of the ''Metasploit Wrap Up: Payloads and Exploits,
    and Scanners, Oh my!'' series.'
  stage: persistence-via-process-creation
  status: out_of_scope
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: promote-to-detection
  justification: Public Metasploit module releases lower the bar for opportunistic
    attackers. Proactively hunting for these artifacts ensures the estate is protected
    against known exploit code.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An adversary is using recently released Metasploit scanner and exploit
  modules to fingerprint organization SCADA infrastructure or exploit unauthenticated
  vulnerabilities in public-facing web applications.
labels:
- hunt
- attack.t1190
name: 'Metasploit 2026: External Recon and Web Exploitation'
parameters:
  lookback_days:
    default: '14'
    description: Days of history to examine.
    type: number
  metasploit_cves:
    default:
    - CVE-2026-0265
    - CVE-2026-16232
    - CVE-2026-3576
    - CVE-2026-6826
    - CVE-2026-9082
    - CVE-2026-59774
    description: CVEs targeted by the new Metasploit modules.
    from:
      kind: article
      observed: '2026-08-28'
      ref: metasploit-wrap-up-aug-2026
    type: list[string]
  scope_hosts:
    default: []
    description: List of hostnames from the scoping step to focus the hunt on; leave
      empty for fleet-wide.
    type: list[host]
  suspicious_paths:
    default:
    - /ulap.php pulp-ajax-proxy
    - /ccm/system/dialogs/file/usage/
    - /ccm/system/dialogs/file/usage
    description: Sensitive URL paths associated with the reported vulnerabilities.
    from:
      kind: article
      observed: '2026-08-28'
      ref: metasploit-wrap-up-aug-2026
    type: list[path]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-payloads-exploits-scanners
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Prioritize web servers hosting WordPress or Concrete CMS, and SCADA control
  systems. If no vulnerability findings are current, expand the HTTP query to all
  external-facing assets.
references:
- name: 'Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!'
  url: https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-payloads-exploits-scanners
related:
- hunt: metasploit-payload-execution-and-persistence
  reason: This hunt focuses on initial reconnaissance and unauthenticated exploitation;
    the post-compromise stages are handled separately.
  relation: out-of-scope-alternative
scenario:
  stages:
  - name: Protocol and Application Fingerprinting
    observables:
    - opc.tcp://
    - /ccm/system/dialogs/file/usage/
    - CVE-2026-0265
    - CVE-2026-16232
    - CVE-2026-6826
    slug: vulnerability-scanning-and-reconnaissance
    tactic: initial-access
    techniques:
    - T1190
  - name: Exploitation of Web Vulnerabilities
    observables:
    - ulap.php
    - file://localhost/etc/passwd
    - X-Spip-Filtre
    - CVE-2026-3576
    - CVE-2026-59774
    - CVE-2026-9082
    - CVE-2026-66066
    slug: exploit-public-facing-web-applications
    tactic: initial-access
    techniques:
    - T1190
  - name: Authenticated Execution and Payloads
    observables:
    - PSRP-backed PowerShell session
    - MIPS64 exec payload
    - CVE-2026-19681
    - CVE-2026-21820
    - CVE-2026-56274
    slug: remote-command-execution-and-payloads
    tactic: execution
    techniques:
    - T1059.001
  - name: Lateral Movement via SMB and WinRM
    observables:
    - windows/smb/psexec aarch64
    - winrm_login with SessionType PSRP
    slug: lateral-movement-smb-winrm
    tactic: lateral-movement
    techniques:
    - T1021.002
  - name: Persistence via CreateProcess
    observables:
    - Metasploit persistence modules using create_process instead of cmd_exec
    slug: persistence-via-process-creation
    tactic: persistence
    techniques:
    - T1059.001
  summary: This Metasploit update details a range of exploit and scanner modules targeting
    vulnerabilities in web platforms (Forgejo, WordPress, Drupal, SPIP), networking
    hardware (PAN-OS, Check Point), and SCADA protocols. The framework has been enhanced
    to support remote execution via PSRP-backed PowerShell sessions, cross-platform
    SMB movement on aarch64, and improved persistence through native process creation.
series:
  index: 1
  slug: metasploit-wrap-up-payloads-and-exploits-and-scanners-oh-my
  title: 'Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!'
  total: 2
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  network:
    category: network
    name: Network telemetry
    telemetry:
    - network
  web:
    category: siem
    name: Web server / proxy logs
    telemetry:
    - network
tlp: clear
type: investigation
---


# Metasploit 2026: External Recon and Web Exploitation

This hunt targets the initial access and reconnaissance phases following the release of new Metasploit modules for CVE-2026-3576, CVE-2026-0265, and others. It first identifies hosts known to be vulnerable to these specific CVEs, then fanned out to investigate HTTP and network telemetry for active probing. An agent evaluates whether observed traffic patterns, such as LFI attempts or rare SCADA protocol connections, indicate a successful intrusion.

## identify-vulnerable-assets
<!-- Identify vulnerable assets -->
Locate assets currently known to be vulnerable to the Metasploit modules' target CVEs and retrieve their hostnames for subsequent filtering.

```sqlite target=endpoint role=scoping params=(metasploit_cves=metasploit_cves)
~~~yaml
expected: Hosts with high-severity findings matching the CVE list. Silence means no
  known exposures exist in the inventory.
reads:
- device_uid
- cve_uid
- severity
- title
- affected_package_name
- affected_package_version
silence: not_evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT d.hostname, f.cve_uid, f.severity, f.title, f.affected_package_name, f.affected_package_version FROM hb_vulnerability_finding AS f JOIN hb_devices AS d ON f.device_uid = d.device_uid WHERE instr(',' || '{{metasploit_cves}}' || ',', ',' || f.cve_uid || ',') > 0 AND f.status != 'suppressed'
```

## corroborate-activity
<!-- Corroborate with traffic logs -->
parallel:
- → web-exploitation-attempts
- → scada-fingerprinting-traffic
join: → triage-signals

## web-exploitation-attempts
<!-- Web exploitation attempts -->
Identify HTTP requests targeting AJAX proxies or vulnerable controllers with LFI patterns to detect active exploitation.

```sqlite target=web role=detection-candidate params=(suspicious_paths=suspicious_paths, scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: Requests to ulap.php or Concrete CMS paths, especially with file:// schemes
  in parameters. Silence means no probes were captured.
reads:
- device_hostname
- src_endpoint_ip
- url_path
- url_query
- status_code
- user_agent
- time
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, src_endpoint_ip, url_path, url_query, status_code, user_agent, time FROM hb_http_activity WHERE (instr(',' || '{{suspicious_paths}}' || ',', ',' || LOWER(url_path) || ',') > 0 OR LOWER(url_query) LIKE '%file://%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## scada-fingerprinting-traffic
<!-- SCADA protocol fingerprinting -->
Detect rare connections to OPC-UA binary transport ports on scoped hosts to identify unauthorized SCADA scanning.

```sqlite target=network role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: Connections to port 4840 from unexpected sources. Silence means no OPC-UA
  scanning was observed.
prevalence:
  by: device_hostname
  key:
  - dst_endpoint_ip
  rare_below: 5
reads:
- device_hostname
- dst_endpoint_ip
- dst_endpoint_port
- src_endpoint_ip
- time
silence: not_evidence_of_absence
source: hb_network_connection
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, dst_endpoint_ip, dst_endpoint_port, COUNT(DISTINCT src_endpoint_ip) AS unique_sources, MIN(time) AS first_seen FROM hb_network_connection WHERE dst_endpoint_port = 4840 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, dst_endpoint_ip, dst_endpoint_port HAVING unique_sources < 5
```

## triage-signals
<!-- Triage vulnerabilities and traffic -->
```agent target=hunter
cite: required
context:
- identify-vulnerable-assets
- web-exploitation-attempts
- scada-fingerprinting-traffic
max_iterations: 3
objective: Determine if the HTTP or network traffic suggests successful exploitation
  of the identified vulnerabilities.
success_criteria: A verdict citing malicious traffic to a host with a matching CVE
  finding.
tools:
- endpoint
- network
- web
```

## evaluate-compromise
<!-- Evaluate compromise -->
if~: "The triage verdict is malicious for at least one host" (confidence: high, judge=hunter)
then: → isolate-endpoint
indeterminate: → analyst-manual-review
unavailable: → analyst-manual-review (blind_spot: incomplete-telemetry)
else: → close-out

## isolate-endpoint
<!-- Isolate affected host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host and initiate the incident response process for initial access.
```
→ analyst-manual-review

## analyst-manual-review
<!-- Analyst manual review -->
```manual target=analyst
Review the full url_query for LFI patterns and verify if the status_code was 200 on vulnerable hosts.
```
→ close-out

## close-out
<!-- Close out hunt -->
```manual target=analyst
Report any missing patches identified in the scoping step and tuning recommendations for the HTTP detection candidate.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.