{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "The release of sixteen new Metasploit modules, including multiple zero-day exploits and persistence techniques, creates an immediate threat window that periodic scanning cannot close; a hunt provides behavioral verification of security."
      },
      "name": "Metasploit Framework Exploitation and Post-Exploitation",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1190",
        "attack.t1557.001",
        "attack.t1547.001",
        "attack.t1547.003",
        "attack.t1497.001"
      ],
      "related": [
        {
          "hunt": "metasploit-auxiliary-scanner-detection",
          "reason": "This hunt focuses on successful exploitation and post-exploitation; general Metasploit scanner activity is a broader behavioral hunt.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "network": {
          "name": "Network telemetry",
          "category": "network",
          "telemetry": [
            "network"
          ]
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "While a single rule might detect a web shell, this hunt correlates that shell with URI patterns, rare registry persistence, and Kerberos relaying across multiple surfaces, providing the context needed to confirm a high-confidence intrusion rather than a benign alert.",
      "coverage": [
        {
          "stage": "initial-access-web-exploitation",
          "steps": [
            "web-exploitation-patterns",
            "suspicious-web-children"
          ],
          "status": "covered"
        },
        {
          "stage": "credential-access-kerberos-relay",
          "steps": [
            "smb-auth-relay"
          ],
          "status": "covered"
        },
        {
          "stage": "persistence-registry-modification",
          "steps": [
            "persistence-mechanisms"
          ],
          "status": "covered"
        },
        {
          "stage": "evasion-sandbox-detection",
          "reason": "The linux/x64/sandbox_gate performs runtime checks that are too transient for process snapshots; requires live instrumentation.",
          "status": "not_visible"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Exploitation of Public-Facing Applications",
            "slug": "initial-access-web-exploitation",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "CVE-2026-20079",
              "CVE-2026-83549",
              "CVE-2026-63077",
              "CVE-2026-19295",
              "CVE-2026-23744",
              "CVE-2026-82078",
              "CVE-2026-48558",
              "CVE-2026-75604",
              "CVE-2025-66516",
              "URL path: /api/mcp/connect",
              "URL path: /action=session",
              "JSP payload delivery",
              "PHP code storage in session variables",
              "cmsSnmpTrap.sh command injection"
            ]
          },
          {
            "name": "ESC8 Kerberos Authentication Relay",
            "slug": "credential-access-kerberos-relay",
            "tactic": "credential-access",
            "techniques": [
              "T1557.001"
            ],
            "observables": [
              "CVE-2026-20929",
              "SMB2 AP-REQ capture",
              "Relay to AD CS Web Enrollment over HTTP",
              "Metasploit module: server/relay/esc8_kerberos"
            ]
          },
          {
            "name": "Registry-Based Persistence",
            "slug": "persistence-registry-modification",
            "tactic": "persistence",
            "techniques": [
              "T1547.001",
              "T1547.003"
            ],
            "observables": [
              "Registry Key: HKLM\\System\\CurrentControlSet\\Control\\BootVerificationProgram",
              "Registry Key: HKLM\\System\\CurrentControlSet\\Services\\W32Time\\TimeProviders",
              "Custom Time Provider DLL registration"
            ]
          },
          {
            "name": "Sandbox Environment Detection",
            "slug": "evasion-sandbox-detection",
            "tactic": "defense-evasion",
            "techniques": [
              "T1497.001"
            ],
            "observables": [
              "Linux x64 runtime environment checks",
              "Metasploit module: linux/x64/sandbox_gate"
            ]
          }
        ],
        "summary": "The September 2026 Metasploit update introduces sixteen new modules, including high-impact RCE exploits for Cisco, PaperCut, and TeamCity, alongside an ESC8 Kerberos relay capability for AD CS. The campaign encompasses initial exploitation via public-facing vulnerabilities, followed by advanced post-exploitation persistence and sandbox evasion techniques."
      },
      "severity": "high",
      "rationale": "Start with internet-facing assets identified in the vulnerability scan as exposed to the target CVEs. Focus on the Cisco FMC, SonicWall SMA, and JetBrains TeamCity hosts first.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An intruder has leveraged one of sixteen new Metasploit modules to exploit a public-facing web application and establish persistence or conduct Kerberos authentication relaying.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Target hosts to filter the hunt."
        },
        "web_parents": {
          "type": "list[string]",
          "default": [
            "httpd",
            "nginx",
            "w3wp.exe",
            "node.exe",
            "python",
            "apache2"
          ],
          "description": "Common web server process names."
        },
        "exploit_uris": {
          "type": "list[string]",
          "default": [
            "/api/mcp/connect",
            "action=session",
            "spip.php",
            "workplace",
            "TeamCity/agent",
            "fmc"
          ],
          "description": "URI patterns or strings targeted by the Metasploit modules."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "shell_binaries": {
          "type": "list[string]",
          "default": [
            "cmd.exe",
            "powershell.exe",
            "sh",
            "bash",
            "zsh"
          ],
          "description": "Shell binaries often used in RCE payloads."
        },
        "vulnerable_cves": {
          "from": {
            "ref": "https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-goes-to-sixteen",
            "kind": "article",
            "observed": "2026-09-11"
          },
          "type": "list[string]",
          "default": [
            "CVE-2025-66516",
            "CVE-2025-54988",
            "CVE-2026-19295",
            "CVE-2026-20079",
            "CVE-2026-63077",
            "CVE-2026-23744",
            "CVE-2026-82078",
            "CVE-2026-48558",
            "CVE-2026-75604",
            "CVE-2026-83549"
          ],
          "description": "CVEs identified in the Metasploit update."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-goes-to-sixteen",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-goes-to-sixteen",
          "name": "Rapid7 \u2014 Metasploit Wrap Up: This One Goes to Sixteen!"
        }
      ],
      "blind_spots": [
        {
          "id": "no-endpoint-telemetry",
          "risk": "An unmanaged server being exploited will only show HTTP traffic, making the confirmation of RCE difficult.",
          "question": "whether a shell was spawned on an unmanaged server",
          "requires": "endpoint agent installation on all web servers"
        },
        {
          "id": "smb-over-vpn",
          "risk": "Outbound network connections might be masked by internal VPN traffic, hiding the Kerberos relay attempt.",
          "stage": "credential-access-kerberos-relay",
          "question": "whether SMB relay occurred over a VPN tunnel",
          "requires": "VPN traffic logs or endpoint network visibility"
        }
      ]
    },
    "name": "Metasploit Framework Exploitation and Post-Exploitation",
    "description": "This hunt targets the release of sixteen new Metasploit modules, many of which exploit high-profile CVEs in Cisco, SonicWall, TeamCity, and PaperCut. The hunt follows a phased approach: first, it identifies vulnerable hosts and triages initial access indicators like targeted HTTP URI paths and anomalous process spawning from web servers. Second, it pivots to identify follow-on post-exploitation activity, specifically searching for rare registry-based persistence via BootVerificationProgram or TimeProviders and identifying outbound SMB traffic from servers, which may indicate Kerberos relay coercion. Two agents evaluate the chain to distinguish between scanning noise and successful compromise."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "coverage": [
          {
            "stage": "initial-access-web-exploitation",
            "steps": [
              "web-exploitation-patterns",
              "suspicious-web-children"
            ],
            "status": "covered"
          },
          {
            "stage": "credential-access-kerberos-relay",
            "steps": [
              "smb-auth-relay"
            ],
            "status": "covered"
          },
          {
            "stage": "persistence-registry-modification",
            "steps": [
              "persistence-mechanisms"
            ],
            "status": "covered"
          },
          {
            "stage": "evasion-sandbox-detection",
            "reason": "The linux/x64/sandbox_gate performs runtime checks that are too transient for process snapshots; requires live instrumentation.",
            "status": "not_visible"
          }
        ],
        "rationale": "An intruder has leveraged one of sixteen new Metasploit modules to exploit a public-facing web application and establish persistence or conduct Kerberos authentication relaying.",
        "blind_spots": [
          {
            "id": "no-endpoint-telemetry",
            "risk": "An unmanaged server being exploited will only show HTTP traffic, making the confirmation of RCE difficult.",
            "question": "whether a shell was spawned on an unmanaged server",
            "requires": "endpoint agent installation on all web servers"
          },
          {
            "id": "smb-over-vpn",
            "risk": "Outbound network connections might be masked by internal VPN traffic, hiding the Kerberos relay attempt.",
            "stage": "credential-access-kerberos-relay",
            "question": "whether SMB relay occurred over a VPN tunnel",
            "requires": "VPN traffic logs or endpoint network visibility"
          }
        ],
        "scoping_notes": "Start with internet-facing assets identified in the vulnerability scan as exposed to the target CVEs. Focus on the Cisco FMC, SonicWall SMA, and JetBrains TeamCity hosts first.",
        "beyond_detection": "While a single rule might detect a web shell, this hunt correlates that shell with URI patterns, rare registry persistence, and Kerberos relaying across multiple surfaces, providing the context needed to confirm a high-confidence intrusion rather than a benign alert."
      }
    },
    {
      "id": "scope-vulnerable-hosts",
      "type": "query",
      "label": "Scope vulnerable hosts",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_uid, cve_uid, severity, affected_package_name FROM hb_vulnerability_finding WHERE instr(',' || '{{vulnerable_cves}}' || ',', ',' || cve_uid || ',') > 0",
        "surface": "hb_vulnerability_finding",
        "description": "Identify hosts in the estate that have been identified as vulnerable to the CVEs mentioned in the report.",
        "expected_signal": "A list of hosts currently exposed to the Metasploit exploits. Silence indicates the estate is patched."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Scope vulnerable hosts",
        "reads": [
          "device_uid",
          "cve_uid",
          "severity",
          "affected_package_name"
        ],
        "source": "hb_vulnerability_finding",
        "target": "endpoint",
        "content": "SELECT device_uid, cve_uid, severity, affected_package_name FROM hb_vulnerability_finding WHERE instr(',' || '{{vulnerable_cves}}' || ',', ',' || cve_uid || ',') > 0",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hosts currently exposed to the Metasploit exploits. Silence indicates the estate is patched.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "web-exploitation-patterns",
      "type": "query",
      "label": "Web exploitation URI patterns",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "web",
        "content": "SELECT device_hostname, url_path, url_query, src_endpoint_ip, user_agent, time FROM hb_http_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{exploit_uris}}' || ',', ',' || url_path || ',') > 0 OR instr(LOWER(url_query), 'action=session') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_http_activity",
        "description": "Match HTTP requests against known targeted URIs for the new Metasploit modules.",
        "expected_signal": "Requests to specific management or vulnerable endpoints. High volume from external IPs indicates scanning or exploitation."
      },
      "parents": [
        {
          "id": "scope-vulnerable-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Web exploitation URI patterns",
        "reads": [
          "device_hostname",
          "url_path",
          "url_query",
          "src_endpoint_ip",
          "user_agent",
          "time"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT device_hostname, url_path, url_query, src_endpoint_ip, user_agent, time FROM hb_http_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{exploit_uris}}' || ',', ',' || url_path || ',') > 0 OR instr(LOWER(url_query), 'action=session') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Requests to specific management or vulnerable endpoints. High volume from external IPs indicates scanning or exploitation.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "suspicious-web-children",
      "type": "query",
      "label": "Suspicious web server children",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, parent_process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND instr(',' || '{{web_parents}}' || ',', ',' || LOWER(parent_process_name) || ',') > 0 AND instr(',' || '{{shell_binaries}}' || ',', ',' || LOWER(process_name) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Detect web server processes spawning shells or interpreters, indicating successful remote code execution.",
        "expected_signal": "A web server spawning a shell (e.g., cmd.exe, /bin/sh). This is the definitive signal of successful RCE."
      },
      "parents": [
        {
          "id": "scope-vulnerable-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Suspicious web server children",
        "reads": [
          "device_hostname",
          "process_name",
          "parent_process_name",
          "process_cmd_line",
          "user_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, parent_process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND instr(',' || '{{web_parents}}' || ',', ',' || LOWER(parent_process_name) || ',') > 0 AND instr(',' || '{{shell_binaries}}' || ',', ',' || LOWER(process_name) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "A web server spawning a shell (e.g., cmd.exe, /bin/sh). This is the definitive signal of successful RCE.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "initial-access-agent",
      "type": "analytic",
      "label": "Initial access agent triage",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "network",
          "web"
        ],
        "context": [
          "scope-vulnerable-hosts",
          "web-exploitation-patterns",
          "suspicious-web-children"
        ],
        "objective": "Determine if any host shows evidence of successful web exploitation based on HTTP traffic and process anomalies.",
        "description": "Identify successful exploitation from early signals.",
        "max_iterations": 3,
        "expected_signal": "Confirmed compromise vs scanning noise.",
        "success_criteria": "A per-host verdict of compromised | suspicious | scanning, citing the shell command line or specific HTTP path."
      },
      "parents": [
        {
          "id": "web-exploitation-patterns",
          "kind": "merge"
        },
        {
          "id": "suspicious-web-children",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "persistence-mechanisms",
      "type": "query",
      "label": "Registry-based persistence mechanisms",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT device_hostname, reg_target, reg_value_data, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_registry_activity WHERE (LOWER(reg_target) LIKE '%\\bootverificationprogram%' OR LOWER(reg_target) LIKE '%\\timeproviders%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY reg_target, reg_value_data HAVING host_count <= 3",
        "surface": "hb_registry_activity",
        "description": "Find modifications to BootVerificationProgram or TimeProviders registry keys which are used by new Metasploit modules.",
        "expected_signal": "Rarely modified persistence keys pointing to non-standard binaries or DLLs. Baseline filters out environment-standard values."
      },
      "parents": [
        {
          "id": "initial-access-agent"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Registry-based persistence mechanisms",
        "reads": [
          "device_hostname",
          "reg_target",
          "reg_value_data",
          "time"
        ],
        "source": "hb_registry_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, reg_target, reg_value_data, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_registry_activity WHERE (LOWER(reg_target) LIKE '%\\bootverificationprogram%' OR LOWER(reg_target) LIKE '%\\timeproviders%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY reg_target, reg_value_data HAVING host_count <= 3",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Rarely modified persistence keys pointing to non-standard binaries or DLLs. Baseline filters out environment-standard values.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "reg_target",
            "reg_value_data"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "smb-auth-relay",
      "type": "query",
      "label": "SMB authentication relay attempts",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "network",
        "content": "SELECT device_hostname, src_endpoint_ip, dst_endpoint_ip, process_name, time FROM hb_network_connection WHERE dst_endpoint_port = 445 AND direction = 'outbound' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_network_connection",
        "description": "Detect outbound SMB connections from web servers, indicating coerced authentication for credential relaying.",
        "expected_signal": "Outbound SMB (445) from a server that normally only serves HTTP. This is highly suspicious of credential coercion."
      },
      "parents": [
        {
          "id": "initial-access-agent"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "SMB authentication relay attempts",
        "reads": [
          "device_hostname",
          "src_endpoint_ip",
          "dst_endpoint_ip",
          "process_name",
          "time"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT device_hostname, src_endpoint_ip, dst_endpoint_ip, process_name, time FROM hb_network_connection WHERE dst_endpoint_port = 445 AND direction = 'outbound' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Outbound SMB (445) from a server that normally only serves HTTP. This is highly suspicious of credential coercion.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "final-triage-agent",
      "type": "analytic",
      "label": "Final post-exploitation agent",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "network",
          "web"
        ],
        "context": [
          "initial-access-agent",
          "persistence-mechanisms",
          "smb-auth-relay"
        ],
        "objective": "Combine the evidence of initial access with the persistence and relay indicators to confirm a full attack chain.",
        "description": "Correlate full chain evidence.",
        "max_iterations": 6,
        "expected_signal": "Confirmed intrusion chain.",
        "success_criteria": "A confirmed breach verdict citing the progression from web exploit to persistent access or relaying."
      },
      "parents": [
        {
          "id": "persistence-mechanisms",
          "kind": "merge"
        },
        {
          "id": "smb-auth-relay",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-verdict",
      "type": "checkpoint",
      "label": "Route verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the final-triage-agent verdict is malicious for any host",
        "condition": "the final-triage-agent verdict is malicious for any host",
        "blind_spot": "no-endpoint-telemetry",
        "confidence": "high",
        "description": "Route on confirmed compromise.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "final-triage-agent"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate host",
      "config": {
        "target": "endpoint",
        "description": "Contain compromise.",
        "instructions": "Isolate the compromised host from the network and revoke any active credentials associated with the session.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Analyst forensic review",
      "config": {
        "assignee": "analyst",
        "description": "Manual verification.",
        "instructions": "Review the agent's findings. Specifically, verify the registry modifications and the source of the outbound SMB connections. Determine if the shell execution on the web server was authorized maintenance or an actual breach."
      },
      "parents": [
        {
          "id": "route-verdict",
          "branch": "default"
        },
        {
          "id": "route-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out",
      "config": {
        "assignee": "analyst",
        "description": "Wrap up hunt and document.",
        "instructions": "Record the findings and update the vulnerability status for the identified hosts. If no breach was found, use the scoping results to prioritize patching the vulnerable assets."
      },
      "parents": [
        {
          "id": "route-verdict",
          "branch": "on_refutes"
        }
      ]
    }
  ]
}