{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "The September 2026 Patch Tuesday involves nearly 1,000 vulnerabilities, including two zero-day elevation of privilege flaws. Verifying that these have not been exploited before the patch cycle completes is critical for ensuring environmental integrity."
      },
      "name": "Microsoft Patch Tuesday September 2026 Exposure",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1190",
        "attack.t1572",
        "attack.t1068",
        "attack.t1203"
      ],
      "related": [
        {
          "hunt": "azure-cosmos-db-spoofing-bypass",
          "reason": "Exploitation of Azure Cosmos DB (CVE-2026-69857) requires Azure-native activity logs, which were not in scope for this endpoint-focused hunt.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A simple detection rule flags a single CVE hit. This hunt pivots between vulnerability findings and a host-behavioural baseline, asking whether exposed hosts exhibit the specific child-shell patterns and rare process deployments that follow successful exploitation of these flaws.",
      "coverage": [
        {
          "stage": "initial-access-remote-services",
          "steps": [
            "vuln-finding-scoping",
            "service-child-behaviour"
          ],
          "status": "covered"
        },
        {
          "stage": "execution-malicious-media-and-office",
          "steps": [
            "vuln-finding-scoping",
            "service-child-behaviour"
          ],
          "status": "covered"
        },
        {
          "stage": "privilege-escalation-zero-day",
          "steps": [
            "vuln-finding-scoping",
            "rare-process-baseline"
          ],
          "status": "covered"
        },
        {
          "stage": "initial-access-cloud-and-database",
          "reason": "Azure Cosmos DB and Spring Cloud Azure exploitation require cloud control-plane telemetry not listed as a source.",
          "status": "not_visible"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Exploitation of Remote Network Services",
            "slug": "initial-access-remote-services",
            "tactic": "initial-access",
            "techniques": [
              "T1190",
              "T1572"
            ],
            "observables": [
              "DNS Server (port 53)",
              "Routing and Remote Access Service (RRAS)",
              "Secure Socket Tunneling Protocol (SSTP) (port 443)",
              "Windows Kerberos (port 88)",
              "DHCP Server (ports 67, 68)",
              "Reliable Multicast Transport Driver (RMCAST)",
              "CVE-2026-69730",
              "CVE-2026-69676",
              "CVE-2026-73009",
              "CVE-2026-69852"
            ]
          },
          {
            "name": "Client-Side Exploitation via Office and Media",
            "slug": "execution-malicious-media-and-office",
            "tactic": "execution",
            "techniques": [
              "T1203"
            ],
            "observables": [
              "excel.exe",
              "winword.exe",
              "outlook.exe",
              "skype.exe",
              "wmplayer.exe",
              "Microsoft Excel (CVE-2026-81948)",
              "Microsoft Word (CVE-2026-81952)",
              "Microsoft Office Outlook (CVE-2026-78525)",
              "Windows Media Player (CVE-2026-70203)"
            ]
          },
          {
            "name": "Local Privilege Escalation and Zero-Day Exploitation",
            "slug": "privilege-escalation-zero-day",
            "tactic": "privilege-escalation",
            "techniques": [
              "T1068"
            ],
            "observables": [
              "Windows Update Stack (CVE-2026-81963)",
              "Advanced Local Procedure Call (ALPC) (CVE-2026-85880)",
              "Windows Hello (CVE-2026-81354)",
              "Secure Kernel Mode (CVE-2026-69501)",
              "Windows Virtualization-Based Security (VBS) (CVE-2026-83501)"
            ]
          },
          {
            "name": "Cloud Infrastructure and Database Bypass",
            "slug": "initial-access-cloud-and-database",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "Azure Cosmos DB (CVE-2026-69857)",
              "Spring Cloud Azure (CVE-2026-69854)",
              "Microsoft SQL Server (CVE-2026-67631)",
              "Microsoft Dynamics 365 On-Premises (CVE-2026-65772)"
            ]
          }
        ],
        "summary": "The September 2026 Microsoft Patch Tuesday includes nearly 1,000 vulnerabilities, featuring zero-day privilege escalation flaws in the Windows Update Stack and ALPC alongside critical remote code execution risks in DNS, Kerberos, and RRAS. These vulnerabilities provide multiple paths for attackers to gain initial access via remote services or malicious media before escalating to system-level privileges."
      },
      "severity": "high",
      "rationale": "The hunt starts with wide coverage using hb_vulnerability_finding for critical CVEs. It prioritizes Domain Controllers (DNS), SQL Servers, and workstations with unpatched Office applications. The results populate a list of hosts for more expensive behavioural analysis.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary is exploiting September 2026 zero-day or critical remote code execution vulnerabilities, such as those in DNS Server or the Windows Update Stack, to establish initial access or escalate privileges on unpatched systems.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Optional list of hostnames to focus the hunt on; if empty, examines the full estate."
        },
        "target_cves": {
          "from": {
            "ref": "https://blog.talosintelligence.com/microsoft-patch-tuesday-for-september-2026/",
            "kind": "article",
            "observed": "2026-09-08"
          },
          "type": "list[string]",
          "default": [
            "CVE-2026-81963",
            "CVE-2026-85880",
            "CVE-2026-69730",
            "CVE-2026-67631",
            "CVE-2026-69852",
            "CVE-2026-72957"
          ],
          "description": "Critical and exploited-in-the-wild CVEs from the September advisory."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "shell_interpreters": {
          "from": {
            "ref": "Common post-exploitation tools",
            "kind": "manual",
            "observed": "2026-09-08"
          },
          "type": "list[string]",
          "default": [
            "cmd.exe",
            "powershell.exe",
            "pwsh.exe",
            "scrcons.exe",
            "wscript.exe",
            "cscript.exe"
          ],
          "description": "Common shell and script interpreters used in post-exploitation."
        },
        "vulnerable_parents": {
          "from": {
            "ref": "September 2026 Vulnerability List",
            "kind": "manual",
            "observed": "2026-09-08"
          },
          "type": "list[string]",
          "default": [
            "dns.exe",
            "sqlservr.exe",
            "winword.exe",
            "excel.exe",
            "outlook.exe",
            "skype.exe",
            "wmplayer.exe"
          ],
          "description": "Processes associated with the September vulnerabilities that might spawn child shells."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://blog.talosintelligence.com/microsoft-patch-tuesday-for-september-2026/",
          "gates": [
            "dry-run",
            "lint",
            "critic"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://blog.talosintelligence.com/microsoft-patch-tuesday-for-september-2026/",
          "name": "Talos \u2014 Microsoft Patch Tuesday for September 2026"
        }
      ],
      "blind_spots": [
        {
          "id": "incomplete-vuln-telemetry",
          "risk": "Unmanaged systems could serve as a beachhead without being scoped by the initial query.",
          "stage": "initial-access-remote-services",
          "question": "Which unmanaged systems remain vulnerable but are not reporting to hb_vulnerability_finding?",
          "requires": "Complete coverage of vulnerability scanning agents"
        },
        {
          "id": "short-lived-processes",
          "risk": "Short-lived elevation of privilege payloads might be missed if they complete their task before the next process inventory collection.",
          "stage": "privilege-escalation-zero-day",
          "question": "Did an exploit process run and exit between snapshot intervals?",
          "requires": "Continuous process event logs (Sysmon) rather than snapshots"
        }
      ]
    },
    "name": "Microsoft Patch Tuesday September 2026 Exposure",
    "description": "This hunt identifies exposure and potential exploitation following the September 2026 Microsoft Patch Tuesday. It focuses on the zero-day elevation of privilege in the Windows Update Stack (CVE-2026-81963) and critical remote code execution flaws in infrastructure services like DNS (CVE-2026-69730) and SQL Server (CVE-2026-67631). The hunt scopes the estate using vulnerability telemetry, establishes a process baseline to identify rare binaries on exposed hosts, and hunts for behavioural indicators like shell execution from high-privilege service parents."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "coverage": [
          {
            "stage": "initial-access-remote-services",
            "steps": [
              "vuln-finding-scoping",
              "service-child-behaviour"
            ],
            "status": "covered"
          },
          {
            "stage": "execution-malicious-media-and-office",
            "steps": [
              "vuln-finding-scoping",
              "service-child-behaviour"
            ],
            "status": "covered"
          },
          {
            "stage": "privilege-escalation-zero-day",
            "steps": [
              "vuln-finding-scoping",
              "rare-process-baseline"
            ],
            "status": "covered"
          },
          {
            "stage": "initial-access-cloud-and-database",
            "reason": "Azure Cosmos DB and Spring Cloud Azure exploitation require cloud control-plane telemetry not listed as a source.",
            "status": "not_visible"
          }
        ],
        "rationale": "An adversary is exploiting September 2026 zero-day or critical remote code execution vulnerabilities, such as those in DNS Server or the Windows Update Stack, to establish initial access or escalate privileges on unpatched systems.",
        "blind_spots": [
          {
            "id": "incomplete-vuln-telemetry",
            "risk": "Unmanaged systems could serve as a beachhead without being scoped by the initial query.",
            "stage": "initial-access-remote-services",
            "question": "Which unmanaged systems remain vulnerable but are not reporting to hb_vulnerability_finding?",
            "requires": "Complete coverage of vulnerability scanning agents"
          },
          {
            "id": "short-lived-processes",
            "risk": "Short-lived elevation of privilege payloads might be missed if they complete their task before the next process inventory collection.",
            "stage": "privilege-escalation-zero-day",
            "question": "Did an exploit process run and exit between snapshot intervals?",
            "requires": "Continuous process event logs (Sysmon) rather than snapshots"
          }
        ],
        "scoping_notes": "The hunt starts with wide coverage using hb_vulnerability_finding for critical CVEs. It prioritizes Domain Controllers (DNS), SQL Servers, and workstations with unpatched Office applications. The results populate a list of hosts for more expensive behavioural analysis.",
        "beyond_detection": "A simple detection rule flags a single CVE hit. This hunt pivots between vulnerability findings and a host-behavioural baseline, asking whether exposed hosts exhibit the specific child-shell patterns and rare process deployments that follow successful exploitation of these flaws."
      }
    },
    {
      "id": "vuln-finding-scoping",
      "type": "query",
      "label": "Vulnerability scope for September CVEs",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_uid, cve_uid, affected_package_name, affected_package_version, severity FROM hb_vulnerability_finding WHERE instr(',' || '{{target_cves}}' || ',', ',' || cve_uid || ',') > 0",
        "surface": "hb_vulnerability_finding",
        "description": "Identify which hosts have been flagged with the high-priority CVEs from the September 2026 advisory.",
        "expected_signal": "A list of vulnerable devices. Silence indicates no scanned assets currently match the high-priority CVE list."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Vulnerability scope for September CVEs",
        "reads": [
          "device_uid",
          "cve_uid",
          "affected_package_name",
          "affected_package_version",
          "severity"
        ],
        "source": "hb_vulnerability_finding",
        "target": "endpoint",
        "content": "SELECT device_uid, cve_uid, affected_package_name, affected_package_version, severity FROM hb_vulnerability_finding WHERE instr(',' || '{{target_cves}}' || ',', ',' || cve_uid || ',') > 0",
        "silence": "not_evidence_of_absence",
        "expected": "A list of vulnerable devices. Silence indicates no scanned assets currently match the high-priority CVE list.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "rare-process-baseline",
      "type": "query",
      "label": "Rare process baseline on exposed hosts",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT process_path, process_cmd_line, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_path, process_cmd_line HAVING host_count <= 2 ORDER BY host_count ASC",
        "surface": "hb_process_activity",
        "description": "Identify unusual process executions on hosts currently known to be vulnerable, which may indicate payload delivery.",
        "expected_signal": "A list of processes seen on only one or two hosts. Silence suggests a consistent software baseline across unpatched systems."
      },
      "parents": [
        {
          "id": "vuln-finding-scoping"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare process baseline on exposed hosts",
        "reads": [
          "process_path",
          "process_cmd_line",
          "device_hostname",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT process_path, process_cmd_line, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_path, process_cmd_line HAVING host_count <= 2 ORDER BY host_count ASC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A list of processes seen on only one or two hosts. Silence suggests a consistent software baseline across unpatched systems.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_path"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "service-child-behaviour",
      "type": "query",
      "label": "Exploitation behaviour from vulnerable services",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, parent_process_name, process_name, process_cmd_line, user_name, integrity_level, time FROM hb_process_activity WHERE (instr(',' || '{{vulnerable_parents}}' || ',', ',' || LOWER(parent_process_name) || ',') > 0 OR (LOWER(parent_process_name) = 'svchost.exe' AND LOWER(parent_process_cmd_line) LIKE '%rras%')) AND instr(',' || '{{shell_interpreters}}' || ',', ',' || LOWER(process_name) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Find behavioural evidence of RCE or EoP where high-privilege service processes or Office apps spawn interpreters.",
        "expected_signal": "Rows showing a shell spawned from a vulnerable parent process like dns.exe or outlook.exe. This is high-confidence evidence of exploitation."
      },
      "parents": [
        {
          "id": "rare-process-baseline"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Exploitation behaviour from vulnerable services",
        "reads": [
          "device_hostname",
          "parent_process_name",
          "process_name",
          "process_cmd_line",
          "user_name",
          "integrity_level",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, parent_process_name, process_name, process_cmd_line, user_name, integrity_level, time FROM hb_process_activity WHERE (instr(',' || '{{vulnerable_parents}}' || ',', ',' || LOWER(parent_process_name) || ',') > 0 OR (LOWER(parent_process_name) = 'svchost.exe' AND LOWER(parent_process_cmd_line) LIKE '%rras%')) AND instr(',' || '{{shell_interpreters}}' || ',', ',' || LOWER(process_name) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "evidence_of_absence",
        "expected": "Rows showing a shell spawned from a vulnerable parent process like dns.exe or outlook.exe. This is high-confidence evidence of exploitation.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "exposure-triage",
      "type": "analytic",
      "label": "Triage exposure and behaviour",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "vuln-finding-scoping",
          "rare-process-baseline",
          "service-child-behaviour"
        ],
        "objective": "Determine if any host flagged with critical September 2026 vulnerabilities exhibits suspicious process activity, citing rows from the baseline and behaviour queries.",
        "description": "Evaluate whether the identified vulnerable hosts show signs of exploitation based on rare processes or suspicious child activity.",
        "max_iterations": 3,
        "expected_signal": "A verdict for each host correlating its vulnerability status with observed behavioural anomalies.",
        "success_criteria": "A per-host verdict of exposed-benign | exposed-suspicious | potentially-exploited."
      },
      "parents": [
        {
          "id": "service-child-behaviour"
        }
      ]
    },
    {
      "id": "exploitation-decision",
      "type": "checkpoint",
      "label": "Route on evidence of exploitation",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage verdict identifies potentially-exploited or exposed-suspicious activity on at least one host",
        "condition": "the triage verdict identifies potentially-exploited or exposed-suspicious activity on at least one host",
        "blind_spot": "incomplete-vuln-telemetry",
        "confidence": "high",
        "description": "Route to remediation review if exploitation is likely, otherwise close out the exposure hunt.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "exposure-triage"
        }
      ]
    },
    {
      "id": "remediation-task",
      "type": "task",
      "label": "Remediation and vulnerability review",
      "config": {
        "assignee": "analyst",
        "description": "Review findings for hosts showing potential exploitation and coordinate patching and verification.",
        "instructions": "Review the agent's findings for the identified hosts. Confirm with the vulnerability management team whether the September 2026 patches have been applied. If the rare process activity or child-shell findings are verified as malicious, escalate to the incident response team and follow the standard isolation playbook. Document any findings that represent authorized administrative tools to tune future runs."
      },
      "parents": [
        {
          "id": "exploitation-decision",
          "branch": "on_supports"
        },
        {
          "id": "exploitation-decision",
          "branch": "default"
        },
        {
          "id": "exploitation-decision",
          "branch": "on_unavailable"
        }
      ]
    },
    {
      "id": "close-out-task",
      "type": "task",
      "label": "Close out exposure hunt",
      "config": {
        "assignee": "analyst",
        "description": "Finalize the hunt results and document the overall exposure level for the September updates.",
        "instructions": "Summarize the total count of vulnerable hosts versus those showing suspicious behaviour. Record any gaps in vulnerability scanning coverage identified during the hunt. Submit a final report to the patch management team to verify the closure of critical exposure windows."
      },
      "parents": [
        {
          "id": "exploitation-decision",
          "branch": "on_refutes"
        },
        {
          "id": "remediation-task"
        }
      ]
    }
  ]
}