Perimeter Vulnerabilities and Identity Access Abuse
An adversary is exploiting a memory overflow in Citrix NetScaler to gain initial access or disrupt services, while simultaneously abusing lawful identity access to perform high-volume, unauthorized searches against sensitive record systems.
Based on research by Cisco Talos 2026-10-09 10 steps · 3 queries T1078 T1190 T1530
Brief
Perimeter Risks and Data Access
Security teams recently observed a pattern of perimeter exploitation followed by the abuse of lawful data access. The research from Talos — Making sure the checks get printed highlights how adversaries move from technical vulnerabilities to behavioral abuse. This hunt addresses this shift by looking for the technical residue of an exploit and the subsequent misuse of search interfaces.
Scoping the Perimeter
The hunt begins by identifying every Citrix NetScaler instance across the managed environment. It queries software inventory surfaces to locate these appliances by vendor name and package description. This scoping phase ensures the rest of the hunt focuses on the relevant attack surface and provides a baseline for where technical instability might manifest.
Identifying Technical and Behavioral Signals
The second phase runs two parallel assessments. First, it monitors NetScaler hosts for HTTP 500 errors and service crashes. A memory overflow exploit often causes the underlying web service to fail or restart, leaving a trail of server-side errors on specific URL paths.
Simultaneously, the hunt audits cloud API activity for anomalous search behavior. It looks for identities that perform over 100 search, read, or list operations within a short window. While many users perform these actions legitimately, a massive spike from a single IP address often indicates automated data extraction or account abuse.
Correlating the Findings
The triage phase brings these two disparate signals together. An analyst or an automated agent reviews the temporal proximity between a NetScaler service crash and a surge in identity search calls. When a perimeter device fails and an account immediately begins harvesting data, the likelihood of a successful intrusion is high. This correlation identifies the "why" behind a service failure that might otherwise be dismissed as a routine IT issue.
Blind Spots
This hunt has specific limitations. It relies on service crashes as a secondary indicator of exploitation because encrypted payloads often hide the actual exploit string from network-level inspection. If an attacker achieves exploitation without crashing the service, the technical signal remains silent.
Additionally, the behavioral analysis depends on cloud audit retention. If data harvesting occurred more than 14 days ago, standard retention policies may have purged the relevant API logs. Finally, while the hunt identifies that a search occurred, it does not see the specific content of the records retrieved without application-level logging.
Running the Hunt
This playbook is formatted as an open hunt.md file. It imports directly into Huntbase or any compatible runtime that supports the hunt.md standard. Practitioners should run this periodically or immediately following reports of new perimeter vulnerabilities to ensure that exploitation has not already transitioned into active data theft.
In this series
Steps
-
Identify Citrix NetScaler inventory
Query · scopingScope the estate to find Citrix NetScaler instances that may be vulnerable to the reported memory overflow.
reads hb_software_inventorysqlSELECT device_hostname, package_name, package_version, vendor_name FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%netscaler%' OR LOWER(vendor_name) LIKE '%citrix%')What a hit looks like. A list of hostnames running Citrix software. Silence suggests no managed NetScaler instances are visible in inventory.
-
NetScaler HTTP service crashes
Query · baselineDetect server-side errors on NetScaler hosts that suggest a memory overflow or denial of service attack occurred.
reads hb_http_activitysqlSELECT device_hostname, url_path, status_code, COUNT(*) AS crash_count, MIN(time) AS first_error, MAX(time) AS last_error FROM hb_http_activity WHERE status_code >= 500 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, url_path, status_codeWhat a hit looks like. A spike in HTTP 500 errors on specific paths. Silence suggests the NetScaler service is stable.
-
Anomalous identity search volume
Query · detection candidateFind users performing an excessive number of search or read operations, which may indicate the abuse of lawful access to extract sensitive records.
reads hb_cloud_api_activitysqlSELECT actor_user_name, api_operation, api_service_name, src_endpoint_ip, COUNT(*) AS call_count, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_cloud_api_activity WHERE (instr(',' || '{{sensitive_search_ops}}' || ',', ',' || LOWER(api_operation) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, api_operation, api_service_name, src_endpoint_ip HAVING call_count > 100What a hit looks like. Identities with hundreds of search API calls from single IPs. Silence means no high-volume read patterns were detected in the audit log.
-
Triage perimeter and identity findings
Agent triageCorrelate perimeter service instability with unusual identity search patterns to confirm a multi-stage intrusion.
-
Route based on agent verdict
DecisionDirect the hunt to containment if malicious behavior is confirmed.
-
Isolate compromised assets
Response actionHalt further exploitation and data extraction.
-
Analyst validation and verification
Analyst taskReview the evidence to ensure the agent's verdict is accurate and record false positive data.
-
Remediate NetScaler vulnerability
Analyst taskEnsure the perimeter is secured against future exploitation of CVE-2026-88779.
-
Close out hunt
Analyst taskFinalize the hunt results and document the coverage achieved.
Coverage
Scenario coverage
| Stage | Covered | How, or why not |
|---|---|---|
| Citrix NetScaler Vulnerability Exploitation T1190 |
Yes | citrix-inventory-scope, netscaler-service-crashes |
| Abuse of Lawful Identity Access T1078 |
Yes | identity-search-anomalies |
| Trojanised Software Execution T1195 |
Out of scope | Belongs to another part of the 'Making sure the checks get printed' series. |
| AI-Analysis Evasion (A3) T1027 |
Out of scope | Belongs to another part of the 'Making sure the checks get printed' series. |
| Kernel driver EDR Impairment T1562.001 · T1068 |
Out of scope | Belongs to another part of the 'Making sure the checks get printed' series. |
| Ransomware Encryption T1486 |
Out of scope | Belongs to another part of the 'Making sure the checks get printed' series. |
Blind spots
- Needs Extended retention of hb_cloud_api_activity. A breach that occurred earlier would be invisible to the API search query. It would answer whether high-volume searching occurred outside the current 14-day window.
- Needs Application-specific logs for the CPR or record system. API activity shows that a search happened, but not which specific records were viewed, making impact assessment difficult. It would answer what specific data was retrieved during the searches.
- Needs SSL/TLS decryption or appliance-local logs. Without payload inspection, the hunt relies on service crashes as a secondary indicator rather than seeing the exploit itself. It would answer the specific exploitation strings used in the memory overflow attack.
Parameters & data
Parameters
| Parameter | Type | Default | What it is |
|---|---|---|---|
lookback_days | number | 14 | Days of history to examine. |
scope_hosts | list[host] | — | Optional list of NetScaler hostnames to focus on after the scoping step. |
sensitive_search_ops | list[string] | search, read, list, get, query | API operations associated with data retrieval and searching. |
Telemetry
| Source | Category | Telemetry |
|---|---|---|
| Endpoint telemetry (hb_ surfaces) | endpoint | endpoint |
| Web server / proxy logs | siem | network |
Source
---
analysis: A simple rule on HTTP 500s or high API usage is too noisy. This hunt uses
the funnel approach to scope the perimeter, look for new crash patterns on specific
paths, and correlate them with identity search anomalies that match the Danish CPR
breach profile.
blind_spots:
- id: limited-cloud-audit-retention
question: whether high-volume searching occurred outside the current 14-day window
requires: Extended retention of hb_cloud_api_activity
risk: A breach that occurred earlier would be invisible to the API search query.
stage: lawful-access-identity-abuse
- id: application-level-query-logging
question: what specific data was retrieved during the searches
requires: Application-specific logs for the CPR or record system
risk: API activity shows that a search happened, but not which specific records
were viewed, making impact assessment difficult.
stage: lawful-access-identity-abuse
- id: encrypted-perimeter-payloads
question: the specific exploitation strings used in the memory overflow attack
requires: SSL/TLS decryption or appliance-local logs
risk: Without payload inspection, the hunt relies on service crashes as a secondary
indicator rather than seeing the exploit itself.
stage: citrix-netscaler-exploitation
coverage:
- stage: citrix-netscaler-exploitation
status: covered
steps:
- citrix-inventory-scope
- netscaler-service-crashes
- stage: lawful-access-identity-abuse
status: covered
steps:
- identity-search-anomalies
- reason: Belongs to another part of the 'Making sure the checks get printed' series.
stage: trojanized-utility-execution
status: out_of_scope
- reason: Belongs to another part of the 'Making sure the checks get printed' series.
stage: ai-analysis-evasion-obfuscation
status: out_of_scope
- reason: Belongs to another part of the 'Making sure the checks get printed' series.
stage: kernel-driver-edr-impairment
status: out_of_scope
- reason: Belongs to another part of the 'Making sure the checks get printed' series.
stage: ransomware-data-encryption
status: out_of_scope
guardrails:
claims: no_unsupported
evidence: citation_required
missing_data: not_benign
telemetry: untrusted
hunt:
applicability: campaign-specific
handoff: keep-as-periodic-hunt
justification: The exploitation of perimeter devices and the abuse of valid credentials
for large-scale data theft are high-impact events that often bypass automated
rules. A hunt is required to correlate these disparate signals into a single intrusion
narrative.
methodology: model-assisted
trigger: intel-report
hypothesis: An adversary is exploiting a memory overflow in Citrix NetScaler to gain
initial access or disrupt services, while simultaneously abusing lawful identity
access to perform high-volume, unauthorized searches against sensitive record systems.
labels:
- hunt
- attack.t1190
- attack.t1078
- attack.t1530
- defense evasion
- execution
- impact
- initial access
name: Perimeter Vulnerabilities and Identity Access Abuse
parameters:
lookback_days:
default: '14'
description: Days of history to examine.
type: number
scope_hosts:
default: []
description: Optional list of NetScaler hostnames to focus on after the scoping
step.
type: list[host]
sensitive_search_ops:
default:
- search
- read
- list
- get
- query
description: API operations associated with data retrieval and searching.
type: list[string]
provenance:
authors:
- name: Huntbase hunt generation
org: huntbase.io
generated:
by: huntbase-hunt-generation
from: https://blog.talosintelligence.com/making-sure-the-checks-get-printed/
gates:
- dry-run
- lint
model: hb_google/gemini-3-flash-preview
rationale: Begin by identifying all Citrix NetScaler appliances in the environment
using software inventory. If vulnerability scan data is available, prioritize those
with active CVE-2026-88779 findings.
references:
- name: "Talos \u2014 Making sure the checks get printed"
url: https://blog.talosintelligence.com/making-sure-the-checks-get-printed/
related:
- hunt: netscaler-webshell-persistence
reason: Once initial access is gained via NetScaler, adversaries often drop webshells;
this hunt focuses only on the exploit and identity abuse.
relation: follows
scenario:
stages:
- name: Citrix NetScaler Vulnerability Exploitation
observables:
- CVE-2026-88779
- Memory overflow in Citrix NetScaler
slug: citrix-netscaler-exploitation
tactic: initial-access
techniques:
- T1190
- name: Abuse of Lawful Identity Access
observables:
- Abuse of Danish company lawful access to CPR system
slug: lawful-access-identity-abuse
tactic: initial-access
techniques:
- T1078
- name: Trojanised Software Execution
observables:
- KMSAuto Net.exe
- SECOH-QAD.exe
- PulseBrowser.29kh.in12.Talos
- 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507
- fed979f93bcaf4e73ebd25748093a92095d5109cbd01d55f97bdc50ce509ad2f
- 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f
- 58d6fec4ba24c32d38c9a0c7c39df3cb0e91f500b323e841121d703c7b718681
slug: trojanized-utility-execution
tactic: execution
techniques:
- T1195
- name: AI-Analysis Evasion (A3)
observables:
- Plaintext imperative language instructions in binaries
- Template spraying designed to trick LLMs
- Instructions telling AI to ignore files
slug: ai-analysis-evasion-obfuscation
tactic: defense-evasion
techniques:
- T1027
- name: Kernel driver EDR Impairment
observables:
- Abusing vulnerable drivers to disable EDR from kernel space
- MANTLEMAZE driver abuse
slug: kernel-driver-edr-impairment
tactic: defense-evasion
techniques:
- T1562.001
- T1068
- name: Ransomware Encryption
observables:
- Warlock ransomware activity
- Encryption of water utility and telecom systems
slug: ransomware-data-encryption
tactic: impact
techniques:
- T1486
summary: Mantlemaze and other threat actors are employing 'AI-Analysis Evasion'
(A3) by embedding natural-language instructions in malware to trick automated
scrutiny, often pairing it with kernel-level driver abuse to disable EDR. These
techniques are observed alongside high-impact threats including vulnerabilities
in Citrix NetScaler and ransomware attacks by groups like Warlock.
series:
index: 1
slug: making-sure-the-checks-get-printed
title: Making sure the checks get printed
total: 2
severity: high
targets:
analyst:
name: Tier-2 analyst
role: analyst
endpoint:
category: endpoint
name: Endpoint telemetry (hb_ surfaces)
telemetry:
- endpoint
hunter:
agent: true
name: Hunt agent
web:
category: siem
name: Web server / proxy logs
telemetry:
- network
tlp: clear
type: investigation
---
# Perimeter Vulnerabilities and Identity Access Abuse
This hunt examines two critical exposure points: the exploitation of the Citrix NetScaler perimeter (CVE-2026-88779) and the abuse of valid accounts for large-scale data harvesting. The hunt first scopes the environment for vulnerable Citrix instances, then fans out to monitor for service instability and anomalous spikes in identity search API calls. By correlating perimeter crashes with identity search behavior, the hunt identifies successful intrusions that leverage lawful access to bypass traditional MFA and alerting.
## citrix-inventory-scope
<!-- Identify Citrix NetScaler inventory -->
Scope the estate to find Citrix NetScaler instances that may be vulnerable to the reported memory overflow.
```sqlite target=endpoint role=scoping
~~~yaml
expected: A list of hostnames running Citrix software. Silence suggests no managed
NetScaler instances are visible in inventory.
reads:
- device_hostname
- package_name
- package_version
- vendor_name
silence: not_evidence_of_absence
source: hb_software_inventory
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT device_hostname, package_name, package_version, vendor_name FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%netscaler%' OR LOWER(vendor_name) LIKE '%citrix%')
```
## parallel-assessment
<!-- Assess perimeter stability and identity usage -->
parallel:
- → netscaler-service-crashes
- → identity-search-anomalies
join: → triage-incidents
## netscaler-service-crashes
<!-- NetScaler HTTP service crashes -->
Detect server-side errors on NetScaler hosts that suggest a memory overflow or denial of service attack occurred.
```sqlite target=web role=baseline params=(scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
baseline:
compare: new_this_window
window: '{{lookback_days}}d'
expected: A spike in HTTP 500 errors on specific paths. Silence suggests the NetScaler
service is stable.
prevalence:
by: device_hostname
key:
- url_path
rare_below: 3
reads:
- device_hostname
- status_code
- time
- url_path
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT device_hostname, url_path, status_code, COUNT(*) AS crash_count, MIN(time) AS first_error, MAX(time) AS last_error FROM hb_http_activity WHERE status_code >= 500 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, url_path, status_code
```
## identity-search-anomalies
<!-- Anomalous identity search volume -->
Find users performing an excessive number of search or read operations, which may indicate the abuse of lawful access to extract sensitive records.
```sqlite target=endpoint role=detection-candidate params=(sensitive_search_ops=sensitive_search_ops, lookback_days=lookback_days)
~~~yaml
baseline:
compare: first_seen
window: '{{lookback_days}}d'
expected: Identities with hundreds of search API calls from single IPs. Silence means
no high-volume read patterns were detected in the audit log.
prevalence:
by: src_endpoint_ip
key:
- actor_user_name
- api_operation
rare_below: 5
reads:
- actor_user_name
- api_operation
- api_service_name
- src_endpoint_ip
- time
silence: not_evidence_of_absence
source: hb_cloud_api_activity
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT actor_user_name, api_operation, api_service_name, src_endpoint_ip, COUNT(*) AS call_count, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_cloud_api_activity WHERE (instr(',' || '{{sensitive_search_ops}}' || ',', ',' || LOWER(api_operation) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, api_operation, api_service_name, src_endpoint_ip HAVING call_count > 100
```
## triage-incidents
<!-- Triage perimeter and identity findings -->
```agent target=hunter
cite: required
context:
- citrix-inventory-scope
- netscaler-service-crashes
- identity-search-anomalies
max_iterations: 6
objective: Determine whether the HTTP crashes on NetScaler hosts and the high-volume
API searches by specific users together indicate active exploitation and data theft
via lawful access abuse.
success_criteria: A verdict of malicious | suspicious | benign citing specific row
counts and temporal proximity between service errors and identity spikes.
tools:
- endpoint
- web
```
## route-on-verdict
<!-- Route based on agent verdict -->
if~: "the triage-incidents verdict is malicious for at least one host or user account" (confidence: medium, judge=hunter)
then: → isolate-compromised-assets
indeterminate: → analyst-validation
unavailable: → analyst-validation (blind_spot: limited-cloud-audit-retention)
else: → close-out
## isolate-compromised-assets
<!-- Isolate compromised assets -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the affected NetScaler host and revoke the credentials for any user account identified as participating in anomalous search activity.
```
→ analyst-validation
## analyst-validation
<!-- Analyst validation and verification -->
```manual target=analyst
Review the cited rows from HTTP and API logs. Verify if the identified searches are consistent with legitimate administrative tasks or if they match the Danish CPR breach pattern of abusing lawful access.
```
→ vulnerability-remediation
## vulnerability-remediation
<!-- Remediate NetScaler vulnerability -->
```manual target=analyst
Coordinate with the infrastructure team to apply patches to the identified vulnerable NetScaler instances and verify the service stability post-patch.
```
→ end
## close-out
<!-- Close out hunt -->
```manual target=analyst
Record the findings, update any detections for high-volume API calls, and document the hosts that were patched during this hunt cycle.
```
→ end
Run it
Take this hunt into your environment.
Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.
Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.