{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Compromised RMM tools provide a direct path to total estate control; detecting the persistent endpoint-side fallout is the primary means of identifying ongoing breaches when appliance logs rotate."
      },
      "name": "RMM-Driven Endpoint Lateral Movement and Masquerading",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1036.005",
        "attack.t1057",
        "attack.t1021.001",
        "attack.t1090.003",
        "attack.t1572"
      ],
      "series": {
        "slug": "critical-n-able-n-central-vulnerability-and-active-exploitation",
        "index": 2,
        "title": "Critical N-able N-central Vulnerability and Active Exploitation",
        "total": 2
      },
      "related": [
        {
          "hunt": "n-central-appliance-exploitation",
          "reason": "That hunt focuses on the RMM appliance logs for the initial exploit attempt.",
          "relation": "out-of-scope-alternative"
        },
        {
          "hunt": "n-central-web-exploitation-persistence",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "network": {
          "name": "Network telemetry",
          "category": "network",
          "telemetry": [
            "network"
          ]
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A standard rule might flag svchost.exe in user folders, but this hunt correlates it with rare discovery activity and known attacker IPs across the fleet. It stack-counts discovery tools to separate administrative noise from strategic reconnaissance.",
      "coverage": [
        {
          "stage": "defense-evasion-masquerading",
          "steps": [
            "masqueraded-svchost"
          ],
          "status": "covered"
        },
        {
          "stage": "discovery-process-enumeration",
          "steps": [
            "rare-process-discovery"
          ],
          "status": "covered"
        },
        {
          "stage": "reconnaissance-api-probing",
          "reason": "Belongs to another part of the 'Critical N-able N-central Vulnerability and Active Exploitation' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "initial-access-rce",
          "reason": "Belongs to another part of the 'Critical N-able N-central Vulnerability and Active Exploitation' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "persistence-account-manipulation",
          "reason": "Belongs to another part of the 'Critical N-able N-central Vulnerability and Active Exploitation' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "persistence-c2-tunneling",
          "reason": "Belongs to another part of the 'Critical N-able N-central Vulnerability and Active Exploitation' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "lateral-movement-rmm-abuse",
          "reason": "Belongs to another part of the 'Critical N-able N-central Vulnerability and Active Exploitation' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "N-central API Reconnaissance",
            "slug": "reconnaissance-api-probing",
            "tactic": "reconnaissance",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "GET /remoteControlAction.do?method=getPierDetails",
              "23.234.100.105",
              "173.249.252.200",
              "185.156.46.150"
            ]
          },
          {
            "name": "Pre-Auth RCE and Auth Bypass",
            "slug": "initial-access-rce",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "CVE-2026-86218",
              "CVE-2026-18556",
              "CVE-2026-18577",
              "URL-encoded API requests using %2F"
            ]
          },
          {
            "name": "Malicious Account Creation",
            "slug": "persistence-account-manipulation",
            "tactic": "persistence",
            "techniques": [
              "T1136"
            ],
            "observables": [
              "Email addresses appended with '.invalid'",
              "Usernames with subtle character swaps",
              "Spoofed domains in email addresses"
            ]
          },
          {
            "name": "Cloudflare Protocol Tunneling",
            "slug": "persistence-c2-tunneling",
            "tactic": "command-and-control",
            "techniques": [
              "T1572",
              "T1090.003"
            ],
            "observables": [
              "Service name 'Cloudflared'",
              "Cloudflare tunnel account tag: 5568cd69c754b392121f1dbb8f900fda"
            ]
          },
          {
            "name": "Masqueraded Binary in User Folder",
            "slug": "defense-evasion-masquerading",
            "tactic": "defense-evasion",
            "techniques": [
              "T1036.005"
            ],
            "observables": [
              "svchost.exe located in Documents folder"
            ]
          },
          {
            "name": "Abuse of RMM Take Control",
            "slug": "lateral-movement-rmm-abuse",
            "tactic": "lateral-movement",
            "techniques": [
              "T1133"
            ],
            "observables": [
              "MSP Support account session logins",
              "Take Control session activity (Event IDs 4102, 8192, 8193)"
            ]
          },
          {
            "name": "Post-Exploitation Process Discovery",
            "slug": "discovery-process-enumeration",
            "tactic": "discovery",
            "techniques": [
              "T1057"
            ],
            "observables": [
              "Process list requests following exploitation"
            ]
          }
        ],
        "summary": "Attackers are exploiting multiple vulnerabilities in N-able N-central, including a zero-day RCE, to gain unauthenticated access to RMM consoles. Post-exploitation, they maintain persistence via Cloudflare tunnels and malicious user creation before using the built-in 'Take Control' feature to move laterally across managed endpoints."
      },
      "severity": "high",
      "rationale": "Prioritize Domain Controllers and file servers; threat actors have been observed strategically targeting these high-value assets for enumeration.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An intruder who has compromised an N-central appliance is abusing the Take Control feature to drop masqueraded binaries in user folders and perform process enumeration on managed hosts.",
      "parameters": {
        "scope_hosts": {
          "from": {
            "ref": "scoping-pivot",
            "kind": "manual",
            "observed": "2026-09-06"
          },
          "type": "list[host]",
          "default": [],
          "description": "Specific hosts to investigate; paste hostnames from the lead query result here to narrow the search."
        },
        "attacker_ips": {
          "from": {
            "ref": "huntress-n-able-blog",
            "kind": "article",
            "observed": "2026-09-06"
          },
          "type": "list[ip]",
          "default": [
            "23.234.100.105",
            "23.234.97.68",
            "173.249.252.176",
            "185.156.46.150",
            "23.234.94.43",
            "68.235.46.235",
            "173.249.252.200"
          ],
          "description": "IP addresses associated with reported N-able exploitation."
        },
        "lookback_days": {
          "from": {
            "ref": "standard-lookback",
            "kind": "manual",
            "observed": "2026-09-06"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine for endpoint activity."
        },
        "discovery_binaries": {
          "from": {
            "ref": "standard-discovery-tools",
            "kind": "manual",
            "observed": "2026-09-06"
          },
          "type": "list[string]",
          "default": [
            "tasklist.exe",
            "wmic.exe",
            "ps.exe",
            "whoami.exe",
            "systeminfo.exe"
          ],
          "description": "Standard binaries used for process discovery and enumeration."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.huntress.com/blog/n-able-vulnerability-exploitation",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.huntress.com/blog/n-able-vulnerability-exploitation",
          "name": "Huntress \u2014 Critical N-able N-central Vulnerability and Active Exploitation"
        }
      ],
      "blind_spots": [
        {
          "id": "endpoint-visibility-gap",
          "risk": "The RMM can land on unmonitored systems where this behavior is invisible.",
          "stage": "defense-evasion-masquerading",
          "question": "Are masqueraded binaries running on hosts without monitoring agents?",
          "requires": "endpoint agent installation on all managed hosts"
        },
        {
          "id": "network-log-retention",
          "risk": "Short retention windows may miss the initial beaconing phase.",
          "question": "Did the initial C2 callback happen before the lookback window?",
          "requires": "long-term retention of netflow or socket activity"
        }
      ]
    },
    "name": "RMM-Driven Endpoint Lateral Movement and Masquerading",
    "description": "This hunt identifies the endpoint-side evidence of N-central RMM exploitation. It focuses on identifying masqueraded binaries, specifically svchost.exe running from user-writable paths like Documents, which is an observed post-exploitation technique. The hunt then corroborates this by finding rare process discovery commands and connections to known attacker infrastructure on the affected hosts, allowing an analyst to distinguish intruder activity from legitimate RMM maintenance."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "critical-n-able-n-central-vulnerability-and-active-exploitation",
          "index": 2,
          "title": "Critical N-able N-central Vulnerability and Active Exploitation",
          "total": 2
        },
        "coverage": [
          {
            "stage": "defense-evasion-masquerading",
            "steps": [
              "masqueraded-svchost"
            ],
            "status": "covered"
          },
          {
            "stage": "discovery-process-enumeration",
            "steps": [
              "rare-process-discovery"
            ],
            "status": "covered"
          },
          {
            "stage": "reconnaissance-api-probing",
            "reason": "Belongs to another part of the 'Critical N-able N-central Vulnerability and Active Exploitation' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "initial-access-rce",
            "reason": "Belongs to another part of the 'Critical N-able N-central Vulnerability and Active Exploitation' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "persistence-account-manipulation",
            "reason": "Belongs to another part of the 'Critical N-able N-central Vulnerability and Active Exploitation' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "persistence-c2-tunneling",
            "reason": "Belongs to another part of the 'Critical N-able N-central Vulnerability and Active Exploitation' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "lateral-movement-rmm-abuse",
            "reason": "Belongs to another part of the 'Critical N-able N-central Vulnerability and Active Exploitation' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An intruder who has compromised an N-central appliance is abusing the Take Control feature to drop masqueraded binaries in user folders and perform process enumeration on managed hosts.",
        "blind_spots": [
          {
            "id": "endpoint-visibility-gap",
            "risk": "The RMM can land on unmonitored systems where this behavior is invisible.",
            "stage": "defense-evasion-masquerading",
            "question": "Are masqueraded binaries running on hosts without monitoring agents?",
            "requires": "endpoint agent installation on all managed hosts"
          },
          {
            "id": "network-log-retention",
            "risk": "Short retention windows may miss the initial beaconing phase.",
            "question": "Did the initial C2 callback happen before the lookback window?",
            "requires": "long-term retention of netflow or socket activity"
          }
        ],
        "scoping_notes": "Prioritize Domain Controllers and file servers; threat actors have been observed strategically targeting these high-value assets for enumeration.",
        "beyond_detection": "A standard rule might flag svchost.exe in user folders, but this hunt correlates it with rare discovery activity and known attacker IPs across the fleet. It stack-counts discovery tools to separate administrative noise from strategic reconnaissance."
      }
    },
    {
      "id": "masqueraded-svchost",
      "type": "query",
      "label": "Masqueraded svchost in user paths",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_path, process_cmd_line, user_name, time FROM hb_process_activity WHERE LOWER(process_name) = 'svchost.exe' AND (LOWER(process_path) LIKE '%\\\\documents\\\\%' OR LOWER(process_path) LIKE '%\\\\users\\\\public\\\\%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Identify svchost.exe running from non-standard user-writable paths, a high-fidelity indicator of this campaign.",
        "expected_signal": "A row naming a host and user path where svchost.exe is running. Silence provides evidence that no such processes are active on enrolled hosts."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Masqueraded svchost in user paths",
        "reads": [
          "device_hostname",
          "process_name",
          "process_path",
          "process_cmd_line",
          "user_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_path, process_cmd_line, user_name, time FROM hb_process_activity WHERE LOWER(process_name) = 'svchost.exe' AND (LOWER(process_path) LIKE '%\\\\documents\\\\%' OR LOWER(process_path) LIKE '%\\\\users\\\\public\\\\%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "evidence_of_absence",
        "expected": "A row naming a host and user path where svchost.exe is running. Silence provides evidence that no such processes are active on enrolled hosts.",
        "verified": "dry-run",
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "rare-process-discovery",
      "type": "query",
      "label": "Rare process discovery activity",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_cmd_line, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_process_activity WHERE instr(',' || '{{discovery_binaries}}' || ',', ',' || LOWER(process_name) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_cmd_line HAVING hosts <= 5 ORDER BY hosts ASC",
        "surface": "hb_process_activity",
        "description": "Stack-count discovery commands to identify strategic reconnaissance on suspicious hosts.",
        "expected_signal": "A small number of hosts running process enumeration tools; widespread administrative activity is filtered out."
      },
      "parents": [
        {
          "id": "masqueraded-svchost"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare process discovery activity",
        "reads": [
          "device_hostname",
          "process_name",
          "process_cmd_line",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_cmd_line, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_process_activity WHERE instr(',' || '{{discovery_binaries}}' || ',', ',' || LOWER(process_name) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_cmd_line HAVING hosts <= 5 ORDER BY hosts ASC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A small number of hosts running process enumeration tools; widespread administrative activity is filtered out.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_cmd_line"
          ],
          "rare_below": 5
        },
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "attacker-ip-connections",
      "type": "query",
      "label": "Connections to known attacker IPs",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "network",
        "content": "SELECT device_hostname, process_name, dst_endpoint_ip, dst_endpoint_port, time FROM hb_network_connection WHERE instr(',' || '{{attacker_ips}}' || ',', ',' || dst_endpoint_ip || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_network_connection",
        "description": "Confirm command and control traffic by matching scoped host activity against reported infrastructure.",
        "expected_signal": "A row showing a suspicious host communicating with a known-malicious IP. Absence proves no such connections exist in the telemetry window."
      },
      "parents": [
        {
          "id": "masqueraded-svchost"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Connections to known attacker IPs",
        "reads": [
          "device_hostname",
          "process_name",
          "dst_endpoint_ip",
          "dst_endpoint_port",
          "time"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT device_hostname, process_name, dst_endpoint_ip, dst_endpoint_port, time FROM hb_network_connection WHERE instr(',' || '{{attacker_ips}}' || ',', ',' || dst_endpoint_ip || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "A row showing a suspicious host communicating with a known-malicious IP. Absence proves no such connections exist in the telemetry window.",
        "verified": "dry-run",
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "triage-evidence",
      "type": "analytic",
      "label": "Triage endpoint evidence",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "network"
        ],
        "context": [
          "masqueraded-svchost",
          "rare-process-discovery",
          "attacker-ip-connections"
        ],
        "objective": "Determine if any host shows evidence of a masqueraded binary accompanied by discovery activity or connections to malicious IPs.",
        "description": "Evaluate the combined evidence of masquerading, discovery, and network patterns to confirm compromise.",
        "max_iterations": 6,
        "expected_signal": "A per-host verdict with citations.",
        "success_criteria": "A verdict of malicious | suspicious | benign per host, citing relevant rows."
      },
      "parents": [
        {
          "id": "rare-process-discovery",
          "kind": "merge"
        },
        {
          "id": "attacker-ip-connections",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage verdict is malicious for at least one host involving a masqueraded svchost process.",
        "condition": "the triage verdict is malicious for at least one host involving a masqueraded svchost process.",
        "blind_spot": "endpoint-visibility-gap",
        "confidence": "high",
        "description": "Direct the hunt towards containment or manual review based on the triage result.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-evidence"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate host",
      "config": {
        "target": "endpoint",
        "description": "Contain the threat by isolating the affected endpoint.",
        "instructions": "Isolate the host using the endpoint agent and collect the svchost.exe binary from the user path for further analysis.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "forensic-validation",
      "type": "task",
      "label": "Forensic validation",
      "config": {
        "assignee": "analyst",
        "description": "Perform manual review to confirm the findings and check for related RMM abuse signs.",
        "instructions": "Review the cited rows and check the hb_auth_signin surface for logins by the MSP Support account during the same timeframe. Verify if the svchost.exe binary is signed or presents an unusual metadata signature."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "hunt-close-out",
      "type": "task",
      "label": "Hunt close out",
      "config": {
        "assignee": "analyst",
        "description": "Finalize remediation steps and document results.",
        "instructions": "Ensure the N-central appliance is updated to 2026.3 HF4. Document the observed masquerading paths to refine standing detection rules."
      },
      "parents": [
        {
          "id": "forensic-validation"
        }
      ]
    }
  ]
}