{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "The exploitation of perimeter devices and the abuse of valid credentials for large-scale data theft are high-impact events that often bypass automated rules. A hunt is required to correlate these disparate signals into a single intrusion narrative."
      },
      "name": "Perimeter Vulnerabilities and Identity Access Abuse",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1190",
        "attack.t1078",
        "attack.t1530",
        "defense evasion",
        "execution",
        "impact",
        "initial access"
      ],
      "series": {
        "slug": "making-sure-the-checks-get-printed",
        "index": 1,
        "title": "Making sure the checks get printed",
        "total": 2
      },
      "related": [
        {
          "hunt": "netscaler-webshell-persistence",
          "reason": "Once initial access is gained via NetScaler, adversaries often drop webshells; this hunt focuses only on the exploit and identity abuse.",
          "relation": "follows"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A simple rule on HTTP 500s or high API usage is too noisy. This hunt uses the funnel approach to scope the perimeter, look for new crash patterns on specific paths, and correlate them with identity search anomalies that match the Danish CPR breach profile.",
      "coverage": [
        {
          "stage": "citrix-netscaler-exploitation",
          "steps": [
            "citrix-inventory-scope",
            "netscaler-service-crashes"
          ],
          "status": "covered"
        },
        {
          "stage": "lawful-access-identity-abuse",
          "steps": [
            "identity-search-anomalies"
          ],
          "status": "covered"
        },
        {
          "stage": "trojanized-utility-execution",
          "reason": "Belongs to another part of the 'Making sure the checks get printed' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "ai-analysis-evasion-obfuscation",
          "reason": "Belongs to another part of the 'Making sure the checks get printed' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "kernel-driver-edr-impairment",
          "reason": "Belongs to another part of the 'Making sure the checks get printed' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "ransomware-data-encryption",
          "reason": "Belongs to another part of the 'Making sure the checks get printed' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Citrix NetScaler Vulnerability Exploitation",
            "slug": "citrix-netscaler-exploitation",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "CVE-2026-88779",
              "Memory overflow in Citrix NetScaler"
            ]
          },
          {
            "name": "Abuse of Lawful Identity Access",
            "slug": "lawful-access-identity-abuse",
            "tactic": "initial-access",
            "techniques": [
              "T1078"
            ],
            "observables": [
              "Abuse of Danish company lawful access to CPR system"
            ]
          },
          {
            "name": "Trojanised Software Execution",
            "slug": "trojanized-utility-execution",
            "tactic": "execution",
            "techniques": [
              "T1195"
            ],
            "observables": [
              "KMSAuto Net.exe",
              "SECOH-QAD.exe",
              "PulseBrowser.29kh.in12.Talos",
              "9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507",
              "fed979f93bcaf4e73ebd25748093a92095d5109cbd01d55f97bdc50ce509ad2f",
              "9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f",
              "58d6fec4ba24c32d38c9a0c7c39df3cb0e91f500b323e841121d703c7b718681"
            ]
          },
          {
            "name": "AI-Analysis Evasion (A3)",
            "slug": "ai-analysis-evasion-obfuscation",
            "tactic": "defense-evasion",
            "techniques": [
              "T1027"
            ],
            "observables": [
              "Plaintext imperative language instructions in binaries",
              "Template spraying designed to trick LLMs",
              "Instructions telling AI to ignore files"
            ]
          },
          {
            "name": "Kernel driver EDR Impairment",
            "slug": "kernel-driver-edr-impairment",
            "tactic": "defense-evasion",
            "techniques": [
              "T1562.001",
              "T1068"
            ],
            "observables": [
              "Abusing vulnerable drivers to disable EDR from kernel space",
              "MANTLEMAZE driver abuse"
            ]
          },
          {
            "name": "Ransomware Encryption",
            "slug": "ransomware-data-encryption",
            "tactic": "impact",
            "techniques": [
              "T1486"
            ],
            "observables": [
              "Warlock ransomware activity",
              "Encryption of water utility and telecom systems"
            ]
          }
        ],
        "summary": "Mantlemaze and other threat actors are employing 'AI-Analysis Evasion' (A3) by embedding natural-language instructions in malware to trick automated scrutiny, often pairing it with kernel-level driver abuse to disable EDR. These techniques are observed alongside high-impact threats including vulnerabilities in Citrix NetScaler and ransomware attacks by groups like Warlock."
      },
      "severity": "high",
      "rationale": "Begin by identifying all Citrix NetScaler appliances in the environment using software inventory. If vulnerability scan data is available, prioritize those with active CVE-2026-88779 findings.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary is exploiting a memory overflow in Citrix NetScaler to gain initial access or disrupt services, while simultaneously abusing lawful identity access to perform high-volume, unauthorized searches against sensitive record systems.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Optional list of NetScaler hostnames to focus on after the scoping step."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "sensitive_search_ops": {
          "type": "list[string]",
          "default": [
            "search",
            "read",
            "list",
            "get",
            "query"
          ],
          "description": "API operations associated with data retrieval and searching."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://blog.talosintelligence.com/making-sure-the-checks-get-printed/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://blog.talosintelligence.com/making-sure-the-checks-get-printed/",
          "name": "Talos \u2014 Making sure the checks get printed"
        }
      ],
      "blind_spots": [
        {
          "id": "limited-cloud-audit-retention",
          "risk": "A breach that occurred earlier would be invisible to the API search query.",
          "stage": "lawful-access-identity-abuse",
          "question": "whether high-volume searching occurred outside the current 14-day window",
          "requires": "Extended retention of hb_cloud_api_activity"
        },
        {
          "id": "application-level-query-logging",
          "risk": "API activity shows that a search happened, but not which specific records were viewed, making impact assessment difficult.",
          "stage": "lawful-access-identity-abuse",
          "question": "what specific data was retrieved during the searches",
          "requires": "Application-specific logs for the CPR or record system"
        },
        {
          "id": "encrypted-perimeter-payloads",
          "risk": "Without payload inspection, the hunt relies on service crashes as a secondary indicator rather than seeing the exploit itself.",
          "stage": "citrix-netscaler-exploitation",
          "question": "the specific exploitation strings used in the memory overflow attack",
          "requires": "SSL/TLS decryption or appliance-local logs"
        }
      ]
    },
    "name": "Perimeter Vulnerabilities and Identity Access Abuse",
    "description": "This hunt examines two critical exposure points: the exploitation of the Citrix NetScaler perimeter (CVE-2026-88779) and the abuse of valid accounts for large-scale data harvesting. The hunt first scopes the environment for vulnerable Citrix instances, then fans out to monitor for service instability and anomalous spikes in identity search API calls. By correlating perimeter crashes with identity search behavior, the hunt identifies successful intrusions that leverage lawful access to bypass traditional MFA and alerting."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "making-sure-the-checks-get-printed",
          "index": 1,
          "title": "Making sure the checks get printed",
          "total": 2
        },
        "coverage": [
          {
            "stage": "citrix-netscaler-exploitation",
            "steps": [
              "citrix-inventory-scope",
              "netscaler-service-crashes"
            ],
            "status": "covered"
          },
          {
            "stage": "lawful-access-identity-abuse",
            "steps": [
              "identity-search-anomalies"
            ],
            "status": "covered"
          },
          {
            "stage": "trojanized-utility-execution",
            "reason": "Belongs to another part of the 'Making sure the checks get printed' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "ai-analysis-evasion-obfuscation",
            "reason": "Belongs to another part of the 'Making sure the checks get printed' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "kernel-driver-edr-impairment",
            "reason": "Belongs to another part of the 'Making sure the checks get printed' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "ransomware-data-encryption",
            "reason": "Belongs to another part of the 'Making sure the checks get printed' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary is exploiting a memory overflow in Citrix NetScaler to gain initial access or disrupt services, while simultaneously abusing lawful identity access to perform high-volume, unauthorized searches against sensitive record systems.",
        "blind_spots": [
          {
            "id": "limited-cloud-audit-retention",
            "risk": "A breach that occurred earlier would be invisible to the API search query.",
            "stage": "lawful-access-identity-abuse",
            "question": "whether high-volume searching occurred outside the current 14-day window",
            "requires": "Extended retention of hb_cloud_api_activity"
          },
          {
            "id": "application-level-query-logging",
            "risk": "API activity shows that a search happened, but not which specific records were viewed, making impact assessment difficult.",
            "stage": "lawful-access-identity-abuse",
            "question": "what specific data was retrieved during the searches",
            "requires": "Application-specific logs for the CPR or record system"
          },
          {
            "id": "encrypted-perimeter-payloads",
            "risk": "Without payload inspection, the hunt relies on service crashes as a secondary indicator rather than seeing the exploit itself.",
            "stage": "citrix-netscaler-exploitation",
            "question": "the specific exploitation strings used in the memory overflow attack",
            "requires": "SSL/TLS decryption or appliance-local logs"
          }
        ],
        "scoping_notes": "Begin by identifying all Citrix NetScaler appliances in the environment using software inventory. If vulnerability scan data is available, prioritize those with active CVE-2026-88779 findings.",
        "beyond_detection": "A simple rule on HTTP 500s or high API usage is too noisy. This hunt uses the funnel approach to scope the perimeter, look for new crash patterns on specific paths, and correlate them with identity search anomalies that match the Danish CPR breach profile."
      }
    },
    {
      "id": "citrix-inventory-scope",
      "type": "query",
      "label": "Identify Citrix NetScaler inventory",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_hostname, package_name, package_version, vendor_name FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%netscaler%' OR LOWER(vendor_name) LIKE '%citrix%')",
        "surface": "hb_software_inventory",
        "description": "Scope the estate to find Citrix NetScaler instances that may be vulnerable to the reported memory overflow.",
        "expected_signal": "A list of hostnames running Citrix software. Silence suggests no managed NetScaler instances are visible in inventory."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify Citrix NetScaler inventory",
        "reads": [
          "device_hostname",
          "package_name",
          "package_version",
          "vendor_name"
        ],
        "source": "hb_software_inventory",
        "target": "endpoint",
        "content": "SELECT device_hostname, package_name, package_version, vendor_name FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%netscaler%' OR LOWER(vendor_name) LIKE '%citrix%')",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hostnames running Citrix software. Silence suggests no managed NetScaler instances are visible in inventory.",
        "verified": "dry-run",
        "verified_at": "2026-10-09"
      }
    },
    {
      "id": "netscaler-service-crashes",
      "type": "query",
      "label": "NetScaler HTTP service crashes",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "web",
        "content": "SELECT device_hostname, url_path, status_code, COUNT(*) AS crash_count, MIN(time) AS first_error, MAX(time) AS last_error FROM hb_http_activity WHERE status_code >= 500 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, url_path, status_code",
        "surface": "hb_http_activity",
        "description": "Detect server-side errors on NetScaler hosts that suggest a memory overflow or denial of service attack occurred.",
        "expected_signal": "A spike in HTTP 500 errors on specific paths. Silence suggests the NetScaler service is stable."
      },
      "parents": [
        {
          "id": "citrix-inventory-scope"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "NetScaler HTTP service crashes",
        "reads": [
          "device_hostname",
          "status_code",
          "time",
          "url_path"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT device_hostname, url_path, status_code, COUNT(*) AS crash_count, MIN(time) AS first_error, MAX(time) AS last_error FROM hb_http_activity WHERE status_code >= 500 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, url_path, status_code",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "new_this_window"
        },
        "expected": "A spike in HTTP 500 errors on specific paths. Silence suggests the NetScaler service is stable.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "url_path"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-10-09"
      }
    },
    {
      "id": "identity-search-anomalies",
      "type": "query",
      "label": "Anomalous identity search volume",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT actor_user_name, api_operation, api_service_name, src_endpoint_ip, COUNT(*) AS call_count, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_cloud_api_activity WHERE (instr(',' || '{{sensitive_search_ops}}' || ',', ',' || LOWER(api_operation) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, api_operation, api_service_name, src_endpoint_ip HAVING call_count > 100",
        "surface": "hb_cloud_api_activity",
        "description": "Find users performing an excessive number of search or read operations, which may indicate the abuse of lawful access to extract sensitive records.",
        "expected_signal": "Identities with hundreds of search API calls from single IPs. Silence means no high-volume read patterns were detected in the audit log."
      },
      "parents": [
        {
          "id": "citrix-inventory-scope"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Anomalous identity search volume",
        "reads": [
          "actor_user_name",
          "api_operation",
          "api_service_name",
          "src_endpoint_ip",
          "time"
        ],
        "source": "hb_cloud_api_activity",
        "target": "endpoint",
        "content": "SELECT actor_user_name, api_operation, api_service_name, src_endpoint_ip, COUNT(*) AS call_count, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_cloud_api_activity WHERE (instr(',' || '{{sensitive_search_ops}}' || ',', ',' || LOWER(api_operation) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, api_operation, api_service_name, src_endpoint_ip HAVING call_count > 100",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Identities with hundreds of search API calls from single IPs. Silence means no high-volume read patterns were detected in the audit log.",
        "verified": "dry-run",
        "prevalence": {
          "by": "src_endpoint_ip",
          "key": [
            "actor_user_name",
            "api_operation"
          ],
          "rare_below": 5
        },
        "verified_at": "2026-10-09"
      }
    },
    {
      "id": "triage-incidents",
      "type": "analytic",
      "label": "Triage perimeter and identity findings",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "web"
        ],
        "context": [
          "citrix-inventory-scope",
          "netscaler-service-crashes",
          "identity-search-anomalies"
        ],
        "objective": "Determine whether the HTTP crashes on NetScaler hosts and the high-volume API searches by specific users together indicate active exploitation and data theft via lawful access abuse.",
        "description": "Correlate perimeter service instability with unusual identity search patterns to confirm a multi-stage intrusion.",
        "max_iterations": 6,
        "expected_signal": "A per-host and per-user verdict indicating risk level.",
        "success_criteria": "A verdict of malicious | suspicious | benign citing specific row counts and temporal proximity between service errors and identity spikes."
      },
      "parents": [
        {
          "id": "netscaler-service-crashes",
          "kind": "merge"
        },
        {
          "id": "identity-search-anomalies",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route based on agent verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage-incidents verdict is malicious for at least one host or user account",
        "condition": "the triage-incidents verdict is malicious for at least one host or user account",
        "blind_spot": "limited-cloud-audit-retention",
        "confidence": "medium",
        "description": "Direct the hunt to containment if malicious behavior is confirmed.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-incidents"
        }
      ]
    },
    {
      "id": "isolate-compromised-assets",
      "type": "action",
      "label": "Isolate compromised assets",
      "config": {
        "target": "endpoint",
        "description": "Halt further exploitation and data extraction.",
        "instructions": "Isolate the affected NetScaler host and revoke the credentials for any user account identified as participating in anomalous search activity.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-validation",
      "type": "task",
      "label": "Analyst validation and verification",
      "config": {
        "assignee": "analyst",
        "description": "Review the evidence to ensure the agent's verdict is accurate and record false positive data.",
        "instructions": "Review the cited rows from HTTP and API logs. Verify if the identified searches are consistent with legitimate administrative tasks or if they match the Danish CPR breach pattern of abusing lawful access."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-compromised-assets"
        }
      ]
    },
    {
      "id": "vulnerability-remediation",
      "type": "task",
      "label": "Remediate NetScaler vulnerability",
      "config": {
        "assignee": "analyst",
        "description": "Ensure the perimeter is secured against future exploitation of CVE-2026-88779.",
        "instructions": "Coordinate with the infrastructure team to apply patches to the identified vulnerable NetScaler instances and verify the service stability post-patch."
      },
      "parents": [
        {
          "id": "analyst-validation"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out hunt",
      "config": {
        "assignee": "analyst",
        "description": "Finalize the hunt results and document the coverage achieved.",
        "instructions": "Record the findings, update any detections for high-volume API calls, and document the hosts that were patched during this hunt cycle."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        }
      ]
    }
  ]
}