← All hunts high TLP:CLEAR Part 1 of 2

Perimeter Vulnerabilities and Identity Access Abuse

An adversary is exploiting a memory overflow in Citrix NetScaler to gain initial access or disrupt services, while simultaneously abusing lawful identity access to perform high-volume, unauthorized searches against sensitive record systems.

Based on research by Cisco Talos 2026-10-09 10 steps · 3 queries T1078 T1190 T1530

Brief

Perimeter Risks and Data Access

Security teams recently observed a pattern of perimeter exploitation followed by the abuse of lawful data access. The research from Talos — Making sure the checks get printed highlights how adversaries move from technical vulnerabilities to behavioral abuse. This hunt addresses this shift by looking for the technical residue of an exploit and the subsequent misuse of search interfaces.

Scoping the Perimeter

The hunt begins by identifying every Citrix NetScaler instance across the managed environment. It queries software inventory surfaces to locate these appliances by vendor name and package description. This scoping phase ensures the rest of the hunt focuses on the relevant attack surface and provides a baseline for where technical instability might manifest.

Identifying Technical and Behavioral Signals

The second phase runs two parallel assessments. First, it monitors NetScaler hosts for HTTP 500 errors and service crashes. A memory overflow exploit often causes the underlying web service to fail or restart, leaving a trail of server-side errors on specific URL paths.

Simultaneously, the hunt audits cloud API activity for anomalous search behavior. It looks for identities that perform over 100 search, read, or list operations within a short window. While many users perform these actions legitimately, a massive spike from a single IP address often indicates automated data extraction or account abuse.

Correlating the Findings

The triage phase brings these two disparate signals together. An analyst or an automated agent reviews the temporal proximity between a NetScaler service crash and a surge in identity search calls. When a perimeter device fails and an account immediately begins harvesting data, the likelihood of a successful intrusion is high. This correlation identifies the "why" behind a service failure that might otherwise be dismissed as a routine IT issue.

Blind Spots

This hunt has specific limitations. It relies on service crashes as a secondary indicator of exploitation because encrypted payloads often hide the actual exploit string from network-level inspection. If an attacker achieves exploitation without crashing the service, the technical signal remains silent.

Additionally, the behavioral analysis depends on cloud audit retention. If data harvesting occurred more than 14 days ago, standard retention policies may have purged the relevant API logs. Finally, while the hunt identifies that a search occurred, it does not see the specific content of the records retrieved without application-level logging.

Running the Hunt

This playbook is formatted as an open hunt.md file. It imports directly into Huntbase or any compatible runtime that supports the hunt.md standard. Practitioners should run this periodically or immediately following reports of new perimeter vulnerabilities to ensure that exploitation has not already transitioned into active data theft.

In this series

Steps

  1. Identify Citrix NetScaler inventory

    Query · scoping

    Scope the estate to find Citrix NetScaler instances that may be vulnerable to the reported memory overflow.

    reads hb_software_inventorysql
    SELECT device_hostname, package_name, package_version, vendor_name FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%netscaler%' OR LOWER(vendor_name) LIKE '%citrix%')

    What a hit looks like. A list of hostnames running Citrix software. Silence suggests no managed NetScaler instances are visible in inventory.

  2. NetScaler HTTP service crashes

    Query · baseline

    Detect server-side errors on NetScaler hosts that suggest a memory overflow or denial of service attack occurred.

    reads hb_http_activitysql
    SELECT device_hostname, url_path, status_code, COUNT(*) AS crash_count, MIN(time) AS first_error, MAX(time) AS last_error FROM hb_http_activity WHERE status_code >= 500 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, url_path, status_code

    What a hit looks like. A spike in HTTP 500 errors on specific paths. Silence suggests the NetScaler service is stable.

  3. Anomalous identity search volume

    Query · detection candidate

    Find users performing an excessive number of search or read operations, which may indicate the abuse of lawful access to extract sensitive records.

    reads hb_cloud_api_activitysql
    SELECT actor_user_name, api_operation, api_service_name, src_endpoint_ip, COUNT(*) AS call_count, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_cloud_api_activity WHERE (instr(',' || '{{sensitive_search_ops}}' || ',', ',' || LOWER(api_operation) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, api_operation, api_service_name, src_endpoint_ip HAVING call_count > 100

    What a hit looks like. Identities with hundreds of search API calls from single IPs. Silence means no high-volume read patterns were detected in the audit log.

  4. Triage perimeter and identity findings

    Agent triage

    Correlate perimeter service instability with unusual identity search patterns to confirm a multi-stage intrusion.

  5. Route based on agent verdict

    Decision

    Direct the hunt to containment if malicious behavior is confirmed.

  6. Isolate compromised assets

    Response action

    Halt further exploitation and data extraction.

  7. Analyst validation and verification

    Analyst task

    Review the evidence to ensure the agent's verdict is accurate and record false positive data.

  8. Remediate NetScaler vulnerability

    Analyst task

    Ensure the perimeter is secured against future exploitation of CVE-2026-88779.

  9. Close out hunt

    Analyst task

    Finalize the hunt results and document the coverage achieved.

Coverage

Scenario coverage

StageCoveredHow, or why not
Citrix NetScaler Vulnerability Exploitation
T1190
Yes citrix-inventory-scope, netscaler-service-crashes
Abuse of Lawful Identity Access
T1078
Yes identity-search-anomalies
Trojanised Software Execution
T1195
Out of scope Belongs to another part of the 'Making sure the checks get printed' series.
AI-Analysis Evasion (A3)
T1027
Out of scope Belongs to another part of the 'Making sure the checks get printed' series.
Kernel driver EDR Impairment
T1562.001 · T1068
Out of scope Belongs to another part of the 'Making sure the checks get printed' series.
Ransomware Encryption
T1486
Out of scope Belongs to another part of the 'Making sure the checks get printed' series.

Blind spots

  • Needs Extended retention of hb_cloud_api_activity. A breach that occurred earlier would be invisible to the API search query. It would answer whether high-volume searching occurred outside the current 14-day window.
  • Needs Application-specific logs for the CPR or record system. API activity shows that a search happened, but not which specific records were viewed, making impact assessment difficult. It would answer what specific data was retrieved during the searches.
  • Needs SSL/TLS decryption or appliance-local logs. Without payload inspection, the hunt relies on service crashes as a secondary indicator rather than seeing the exploit itself. It would answer the specific exploitation strings used in the memory overflow attack.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
lookback_daysnumber14Days of history to examine.
scope_hostslist[host]—Optional list of NetScaler hostnames to focus on after the scoping step.
sensitive_search_opslist[string]search, read, list, get, queryAPI operations associated with data retrieval and searching.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint
Web server / proxy logssiemnetwork

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: A simple rule on HTTP 500s or high API usage is too noisy. This hunt uses
  the funnel approach to scope the perimeter, look for new crash patterns on specific
  paths, and correlate them with identity search anomalies that match the Danish CPR
  breach profile.
blind_spots:
- id: limited-cloud-audit-retention
  question: whether high-volume searching occurred outside the current 14-day window
  requires: Extended retention of hb_cloud_api_activity
  risk: A breach that occurred earlier would be invisible to the API search query.
  stage: lawful-access-identity-abuse
- id: application-level-query-logging
  question: what specific data was retrieved during the searches
  requires: Application-specific logs for the CPR or record system
  risk: API activity shows that a search happened, but not which specific records
    were viewed, making impact assessment difficult.
  stage: lawful-access-identity-abuse
- id: encrypted-perimeter-payloads
  question: the specific exploitation strings used in the memory overflow attack
  requires: SSL/TLS decryption or appliance-local logs
  risk: Without payload inspection, the hunt relies on service crashes as a secondary
    indicator rather than seeing the exploit itself.
  stage: citrix-netscaler-exploitation
coverage:
- stage: citrix-netscaler-exploitation
  status: covered
  steps:
  - citrix-inventory-scope
  - netscaler-service-crashes
- stage: lawful-access-identity-abuse
  status: covered
  steps:
  - identity-search-anomalies
- reason: Belongs to another part of the 'Making sure the checks get printed' series.
  stage: trojanized-utility-execution
  status: out_of_scope
- reason: Belongs to another part of the 'Making sure the checks get printed' series.
  stage: ai-analysis-evasion-obfuscation
  status: out_of_scope
- reason: Belongs to another part of the 'Making sure the checks get printed' series.
  stage: kernel-driver-edr-impairment
  status: out_of_scope
- reason: Belongs to another part of the 'Making sure the checks get printed' series.
  stage: ransomware-data-encryption
  status: out_of_scope
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: keep-as-periodic-hunt
  justification: The exploitation of perimeter devices and the abuse of valid credentials
    for large-scale data theft are high-impact events that often bypass automated
    rules. A hunt is required to correlate these disparate signals into a single intrusion
    narrative.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An adversary is exploiting a memory overflow in Citrix NetScaler to gain
  initial access or disrupt services, while simultaneously abusing lawful identity
  access to perform high-volume, unauthorized searches against sensitive record systems.
labels:
- hunt
- attack.t1190
- attack.t1078
- attack.t1530
- defense evasion
- execution
- impact
- initial access
name: Perimeter Vulnerabilities and Identity Access Abuse
parameters:
  lookback_days:
    default: '14'
    description: Days of history to examine.
    type: number
  scope_hosts:
    default: []
    description: Optional list of NetScaler hostnames to focus on after the scoping
      step.
    type: list[host]
  sensitive_search_ops:
    default:
    - search
    - read
    - list
    - get
    - query
    description: API operations associated with data retrieval and searching.
    type: list[string]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://blog.talosintelligence.com/making-sure-the-checks-get-printed/
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Begin by identifying all Citrix NetScaler appliances in the environment
  using software inventory. If vulnerability scan data is available, prioritize those
  with active CVE-2026-88779 findings.
references:
- name: "Talos \u2014 Making sure the checks get printed"
  url: https://blog.talosintelligence.com/making-sure-the-checks-get-printed/
related:
- hunt: netscaler-webshell-persistence
  reason: Once initial access is gained via NetScaler, adversaries often drop webshells;
    this hunt focuses only on the exploit and identity abuse.
  relation: follows
scenario:
  stages:
  - name: Citrix NetScaler Vulnerability Exploitation
    observables:
    - CVE-2026-88779
    - Memory overflow in Citrix NetScaler
    slug: citrix-netscaler-exploitation
    tactic: initial-access
    techniques:
    - T1190
  - name: Abuse of Lawful Identity Access
    observables:
    - Abuse of Danish company lawful access to CPR system
    slug: lawful-access-identity-abuse
    tactic: initial-access
    techniques:
    - T1078
  - name: Trojanised Software Execution
    observables:
    - KMSAuto Net.exe
    - SECOH-QAD.exe
    - PulseBrowser.29kh.in12.Talos
    - 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507
    - fed979f93bcaf4e73ebd25748093a92095d5109cbd01d55f97bdc50ce509ad2f
    - 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f
    - 58d6fec4ba24c32d38c9a0c7c39df3cb0e91f500b323e841121d703c7b718681
    slug: trojanized-utility-execution
    tactic: execution
    techniques:
    - T1195
  - name: AI-Analysis Evasion (A3)
    observables:
    - Plaintext imperative language instructions in binaries
    - Template spraying designed to trick LLMs
    - Instructions telling AI to ignore files
    slug: ai-analysis-evasion-obfuscation
    tactic: defense-evasion
    techniques:
    - T1027
  - name: Kernel driver EDR Impairment
    observables:
    - Abusing vulnerable drivers to disable EDR from kernel space
    - MANTLEMAZE driver abuse
    slug: kernel-driver-edr-impairment
    tactic: defense-evasion
    techniques:
    - T1562.001
    - T1068
  - name: Ransomware Encryption
    observables:
    - Warlock ransomware activity
    - Encryption of water utility and telecom systems
    slug: ransomware-data-encryption
    tactic: impact
    techniques:
    - T1486
  summary: Mantlemaze and other threat actors are employing 'AI-Analysis Evasion'
    (A3) by embedding natural-language instructions in malware to trick automated
    scrutiny, often pairing it with kernel-level driver abuse to disable EDR. These
    techniques are observed alongside high-impact threats including vulnerabilities
    in Citrix NetScaler and ransomware attacks by groups like Warlock.
series:
  index: 1
  slug: making-sure-the-checks-get-printed
  title: Making sure the checks get printed
  total: 2
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  web:
    category: siem
    name: Web server / proxy logs
    telemetry:
    - network
tlp: clear
type: investigation
---


# Perimeter Vulnerabilities and Identity Access Abuse

This hunt examines two critical exposure points: the exploitation of the Citrix NetScaler perimeter (CVE-2026-88779) and the abuse of valid accounts for large-scale data harvesting. The hunt first scopes the environment for vulnerable Citrix instances, then fans out to monitor for service instability and anomalous spikes in identity search API calls. By correlating perimeter crashes with identity search behavior, the hunt identifies successful intrusions that leverage lawful access to bypass traditional MFA and alerting.

## citrix-inventory-scope
<!-- Identify Citrix NetScaler inventory -->
Scope the estate to find Citrix NetScaler instances that may be vulnerable to the reported memory overflow.

```sqlite target=endpoint role=scoping
~~~yaml
expected: A list of hostnames running Citrix software. Silence suggests no managed
  NetScaler instances are visible in inventory.
reads:
- device_hostname
- package_name
- package_version
- vendor_name
silence: not_evidence_of_absence
source: hb_software_inventory
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT device_hostname, package_name, package_version, vendor_name FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%netscaler%' OR LOWER(vendor_name) LIKE '%citrix%')
```

## parallel-assessment
<!-- Assess perimeter stability and identity usage -->
parallel:
- → netscaler-service-crashes
- → identity-search-anomalies
join: → triage-incidents

## netscaler-service-crashes
<!-- NetScaler HTTP service crashes -->
Detect server-side errors on NetScaler hosts that suggest a memory overflow or denial of service attack occurred.

```sqlite target=web role=baseline params=(scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
baseline:
  compare: new_this_window
  window: '{{lookback_days}}d'
expected: A spike in HTTP 500 errors on specific paths. Silence suggests the NetScaler
  service is stable.
prevalence:
  by: device_hostname
  key:
  - url_path
  rare_below: 3
reads:
- device_hostname
- status_code
- time
- url_path
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT device_hostname, url_path, status_code, COUNT(*) AS crash_count, MIN(time) AS first_error, MAX(time) AS last_error FROM hb_http_activity WHERE status_code >= 500 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, url_path, status_code
```

## identity-search-anomalies
<!-- Anomalous identity search volume -->
Find users performing an excessive number of search or read operations, which may indicate the abuse of lawful access to extract sensitive records.

```sqlite target=endpoint role=detection-candidate params=(sensitive_search_ops=sensitive_search_ops, lookback_days=lookback_days)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: Identities with hundreds of search API calls from single IPs. Silence means
  no high-volume read patterns were detected in the audit log.
prevalence:
  by: src_endpoint_ip
  key:
  - actor_user_name
  - api_operation
  rare_below: 5
reads:
- actor_user_name
- api_operation
- api_service_name
- src_endpoint_ip
- time
silence: not_evidence_of_absence
source: hb_cloud_api_activity
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT actor_user_name, api_operation, api_service_name, src_endpoint_ip, COUNT(*) AS call_count, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_cloud_api_activity WHERE (instr(',' || '{{sensitive_search_ops}}' || ',', ',' || LOWER(api_operation) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, api_operation, api_service_name, src_endpoint_ip HAVING call_count > 100
```

## triage-incidents
<!-- Triage perimeter and identity findings -->
```agent target=hunter
cite: required
context:
- citrix-inventory-scope
- netscaler-service-crashes
- identity-search-anomalies
max_iterations: 6
objective: Determine whether the HTTP crashes on NetScaler hosts and the high-volume
  API searches by specific users together indicate active exploitation and data theft
  via lawful access abuse.
success_criteria: A verdict of malicious | suspicious | benign citing specific row
  counts and temporal proximity between service errors and identity spikes.
tools:
- endpoint
- web
```

## route-on-verdict
<!-- Route based on agent verdict -->
if~: "the triage-incidents verdict is malicious for at least one host or user account" (confidence: medium, judge=hunter)
then: → isolate-compromised-assets
indeterminate: → analyst-validation
unavailable: → analyst-validation (blind_spot: limited-cloud-audit-retention)
else: → close-out

## isolate-compromised-assets
<!-- Isolate compromised assets -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the affected NetScaler host and revoke the credentials for any user account identified as participating in anomalous search activity.
```
→ analyst-validation

## analyst-validation
<!-- Analyst validation and verification -->
```manual target=analyst
Review the cited rows from HTTP and API logs. Verify if the identified searches are consistent with legitimate administrative tasks or if they match the Danish CPR breach pattern of abusing lawful access.
```
→ vulnerability-remediation

## vulnerability-remediation
<!-- Remediate NetScaler vulnerability -->
```manual target=analyst
Coordinate with the infrastructure team to apply patches to the identified vulnerable NetScaler instances and verify the service stability post-patch.
```
→ end

## close-out
<!-- Close out hunt -->
```manual target=analyst
Record the findings, update any detections for high-volume API calls, and document the hosts that were patched during this hunt cycle.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.