{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Microsoft SharePoint servers often host sensitive corporate data; an unauthenticated RCE represents a direct threat to the confidentiality and integrity of that data within the internal network."
      },
      "name": "SharePoint Business Data Connectivity Service Exploitation",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1190"
      ],
      "related": [
        {
          "hunt": "iis-w3wp-shell-execution",
          "reason": "Monitoring for shells spawned by w3wp.exe is a general behavioral hunt that covers many web exploits but lacks the specific context of BDC model delivery.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A standard detection rule might flag w3wp.exe spawning cmd.exe, but this hunt provides necessary context by identifying the delivery of Business Data Connectivity (.bdcm) models and scoping the search to hosts with known unpatched RCE vulnerabilities, reducing false positives from legitimate admin scripts.",
      "coverage": [
        {
          "stage": "initial-access-bdc-exploitation",
          "steps": [
            "find-vulnerable-sharepoint",
            "detect-bdcm-traffic",
            "find-rare-iis-children"
          ],
          "status": "covered"
        },
        {
          "stage": "execution-gadget-chain-command",
          "reason": "Not examined by this hunt; belongs to a separate hunt.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "SharePoint BDC Model Exploitation",
            "slug": "initial-access-bdc-exploitation",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "CVE-2026-63520",
              "CVE-2026-55040",
              ".bdcm model file upload",
              "LobSystem Type=\"Database\"",
              "LobSystem Type=\"DotNetAssembly\"",
              "TypeName=\"System.Windows.Data.ObjectDataProvider\"",
              "TypeName=\"System.Diagnostics.Process\"",
              "TypeName=\"System.Diagnostics.ProcessStartInfo\""
            ]
          },
          {
            "name": "Arbitrary Command Execution via Gadget Chain",
            "slug": "execution-gadget-chain-command",
            "tactic": "execution",
            "techniques": [
              "T1106"
            ],
            "observables": [
              "Process.Start()",
              "System.Windows.Data.ObjectDataProvider",
              "System.Diagnostics.Process",
              "System.Diagnostics.ProcessStartInfo",
              "w3wp.exe spawning child processes",
              "SharePoint Site service account privileges"
            ]
          }
        ],
        "summary": "Attackers exploit a remote code execution vulnerability in the Microsoft SharePoint Business Data Connectivity (BDC) subsystem by uploading malicious .bdcm model files. The exploit leverages an unrestricted .NET type instantiation flaw in the DbTypeReflector class to execute arbitrary commands via an ObjectDataProvider gadget chain under the context of the SharePoint service account."
      },
      "severity": "high",
      "rationale": "Scope the hunt to SharePoint Server Subscription Edition, SharePoint Server 2019, or 2016. Target systems where the Business Data Connectivity (BDC) service is active.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An attacker has exploited the SharePoint Business Data Connectivity service by uploading a malicious BDC model file to instantiate a .NET gadget chain, resulting in remote code execution within the IIS worker process context.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Target hostnames for the hunt; leave empty to scan the entire estate."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "vulnerability_ids": {
          "from": {
            "ref": "https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520",
            "kind": "article",
            "observed": "2026-08-24"
          },
          "type": "list[string]",
          "default": [
            "CVE-2026-63520",
            "CVE-2026-55040"
          ],
          "description": "CVE identifiers associated with the SharePoint BDC vulnerability."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520",
          "name": "Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)"
        }
      ],
      "blind_spots": [
        {
          "id": "encrypted-http-traffic",
          "risk": "Without inspecting the payload, the hunt cannot distinguish between a legitimate BDC model update and a malicious exploit file until execution occurs.",
          "stage": "initial-access-bdc-exploitation",
          "question": "What .NET types and gadget chains were actually contained within the BDC model XML?",
          "requires": "Decrypted HTTP traffic or POST request body inspection"
        },
        {
          "id": "no-uls-logs",
          "risk": "The hunt relies on the side effects of successful exploitation (process execution) and may miss failed attempts or more stealthy gadget chains that do not spawn processes.",
          "stage": "initial-access-bdc-exploitation",
          "question": "Whether the DbTypeReflector class logged an instantiation failure or the specific .NET type being resolved.",
          "requires": "Microsoft SharePoint Unified Logging Service (ULS) logs"
        }
      ]
    },
    "name": "SharePoint Business Data Connectivity Service Exploitation",
    "description": "This hunt identifies exploitation of CVE-2026-63520, an RCE vulnerability in the SharePoint DbTypeReflector class. The attack involves the delivery of a Business Data Connectivity (BDC) model file (.bdcm) containing a .NET gadget chain like ObjectDataProvider. The hunt first scopes to hosts with known unpatched vulnerabilities, then concurrently searches for BDC model uploads and rare child processes spawned by the SharePoint worker process (w3wp.exe). An agent correlates the presence of the vulnerability, the file delivery, and anomalous process behavior to settle on a verdict."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "coverage": [
          {
            "stage": "initial-access-bdc-exploitation",
            "steps": [
              "find-vulnerable-sharepoint",
              "detect-bdcm-traffic",
              "find-rare-iis-children"
            ],
            "status": "covered"
          },
          {
            "stage": "execution-gadget-chain-command",
            "reason": "Not examined by this hunt; belongs to a separate hunt.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An attacker has exploited the SharePoint Business Data Connectivity service by uploading a malicious BDC model file to instantiate a .NET gadget chain, resulting in remote code execution within the IIS worker process context.",
        "blind_spots": [
          {
            "id": "encrypted-http-traffic",
            "risk": "Without inspecting the payload, the hunt cannot distinguish between a legitimate BDC model update and a malicious exploit file until execution occurs.",
            "stage": "initial-access-bdc-exploitation",
            "question": "What .NET types and gadget chains were actually contained within the BDC model XML?",
            "requires": "Decrypted HTTP traffic or POST request body inspection"
          },
          {
            "id": "no-uls-logs",
            "risk": "The hunt relies on the side effects of successful exploitation (process execution) and may miss failed attempts or more stealthy gadget chains that do not spawn processes.",
            "stage": "initial-access-bdc-exploitation",
            "question": "Whether the DbTypeReflector class logged an instantiation failure or the specific .NET type being resolved.",
            "requires": "Microsoft SharePoint Unified Logging Service (ULS) logs"
          }
        ],
        "scoping_notes": "Scope the hunt to SharePoint Server Subscription Edition, SharePoint Server 2019, or 2016. Target systems where the Business Data Connectivity (BDC) service is active.",
        "beyond_detection": "A standard detection rule might flag w3wp.exe spawning cmd.exe, but this hunt provides necessary context by identifying the delivery of Business Data Connectivity (.bdcm) models and scoping the search to hosts with known unpatched RCE vulnerabilities, reducing false positives from legitimate admin scripts."
      }
    },
    {
      "id": "find-vulnerable-sharepoint",
      "type": "query",
      "label": "Identify vulnerable SharePoint hosts",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT resource_uid, cve_uid, severity, status FROM hb_vulnerability_finding WHERE instr(',' || '{{vulnerability_ids}}' || ',', ',' || cve_uid || ',') > 0 AND status != 'suppressed'",
        "surface": "hb_vulnerability_finding",
        "description": "Focus the hunt on hosts already flagged as vulnerable to the relevant SharePoint CVEs by scanning providers.",
        "expected_signal": "A list of resource IDs (hostnames) that have not yet been patched. Silence indicates no known vulnerable hosts in the scanner's inventory."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify vulnerable SharePoint hosts",
        "reads": [
          "resource_uid",
          "cve_uid",
          "severity",
          "status"
        ],
        "source": "hb_vulnerability_finding",
        "target": "endpoint",
        "content": "SELECT resource_uid, cve_uid, severity, status FROM hb_vulnerability_finding WHERE instr(',' || '{{vulnerability_ids}}' || ',', ',' || cve_uid || ',') > 0 AND status != 'suppressed'",
        "silence": "not_evidence_of_absence",
        "expected": "A list of resource IDs (hostnames) that have not yet been patched. Silence indicates no known vulnerable hosts in the scanner's inventory.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "detect-bdcm-traffic",
      "type": "query",
      "label": "Detect BDC model traffic",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "web",
        "content": "SELECT device_hostname, url_path, url_query, src_endpoint_ip, time FROM hb_http_activity WHERE (LOWER(url_path) LIKE '%.bdcm%' OR LOWER(url_query) LIKE '%.bdcm%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_http_activity",
        "description": "Find HTTP requests involving .bdcm files which transport the exploit payload.",
        "expected_signal": "HTTP requests targeting BDC model paths. Silence means no .bdcm files were requested within the lookback period."
      },
      "parents": [
        {
          "id": "find-vulnerable-sharepoint"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Detect BDC model traffic",
        "reads": [
          "device_hostname",
          "url_path",
          "url_query",
          "src_endpoint_ip",
          "time"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT device_hostname, url_path, url_query, src_endpoint_ip, time FROM hb_http_activity WHERE (LOWER(url_path) LIKE '%.bdcm%' OR LOWER(url_query) LIKE '%.bdcm%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "HTTP requests targeting BDC model paths. Silence means no .bdcm files were requested within the lookback period.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "find-rare-iis-children",
      "type": "query",
      "label": "Find rare w3wp.exe children",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT LOWER(process_name) AS proc, COUNT(DISTINCT device_hostname) AS host_count, COUNT(*) AS total_runs, MIN(time) AS first_seen FROM hb_process_activity WHERE LOWER(parent_process_name) LIKE '%w3wp.exe%' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1 HAVING host_count <= 3",
        "surface": "hb_process_activity",
        "description": "Detect successful RCE by finding rare child processes spawned by the SharePoint IIS worker process.",
        "expected_signal": "Anomalous child processes such as shells, discovery tools, or unexpected binaries on a small number of hosts. Benign activity includes standard SharePoint health scripts."
      },
      "parents": [
        {
          "id": "find-vulnerable-sharepoint"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Find rare w3wp.exe children",
        "reads": [
          "process_name",
          "device_hostname",
          "parent_process_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT LOWER(process_name) AS proc, COUNT(DISTINCT device_hostname) AS host_count, COUNT(*) AS total_runs, MIN(time) AS first_seen FROM hb_process_activity WHERE LOWER(parent_process_name) LIKE '%w3wp.exe%' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1 HAVING host_count <= 3",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Anomalous child processes such as shells, discovery tools, or unexpected binaries on a small number of hosts. Benign activity includes standard SharePoint health scripts.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "proc"
          ],
          "rare_below": 4
        },
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "triage-exploitation",
      "type": "analytic",
      "label": "Triage exploitation evidence",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "web"
        ],
        "context": [
          "find-vulnerable-sharepoint",
          "detect-bdcm-traffic",
          "find-rare-iis-children"
        ],
        "objective": "Determine if any host has been exploited using CVE-2026-63520 or CVE-2026-55040 by correlating vulnerable status, BDC model uploads, and anomalous process execution.",
        "description": "The agent weighs the vulnerability status, file delivery evidence, and process behavior to identify hosts showing a complete exploit chain.",
        "max_iterations": 4,
        "expected_signal": "A malicious verdict for any host where a .bdcm upload is temporally linked to a rare w3wp.exe child process on a vulnerable server.",
        "success_criteria": "A per-host verdict citing specific rows that demonstrate the exploit chain."
      },
      "parents": [
        {
          "id": "detect-bdcm-traffic",
          "kind": "merge"
        },
        {
          "id": "find-rare-iis-children",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "decision-on-compromise",
      "type": "checkpoint",
      "label": "Route based on verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage verdict is malicious for at least one host based on correlated file and process evidence",
        "condition": "the triage verdict is malicious for at least one host based on correlated file and process evidence",
        "blind_spot": "encrypted-http-traffic",
        "confidence": "high",
        "description": "Direct the response to host isolation if exploitation is confirmed.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-exploitation"
        }
      ]
    },
    {
      "id": "isolate-impacted-host",
      "type": "action",
      "label": "Isolate the impacted host",
      "config": {
        "target": "endpoint",
        "description": "Prevent lateral movement and further command execution by isolating the compromised SharePoint server.",
        "instructions": "Isolate the identified host and preserve memory for forensic investigation of the w3wp.exe process.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "decision-on-compromise",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "forensic-artifact-review",
      "type": "task",
      "label": "Forensic artifact review",
      "config": {
        "assignee": "analyst",
        "description": "An analyst verifies the BDC model content to confirm the presence of malicious .NET gadget chains.",
        "instructions": "Retrieve the .bdcm file mentioned in the HTTP traffic from the SharePoint server or database; check the XML content for TypeName attributes referencing ObjectDataProvider, DotNetAssembly, or other unusual .NET types."
      },
      "parents": [
        {
          "id": "decision-on-compromise",
          "branch": "default"
        },
        {
          "id": "decision-on-compromise",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-impacted-host"
        }
      ]
    },
    {
      "id": "verify-remediation",
      "type": "task",
      "label": "Verify remediation",
      "config": {
        "assignee": "analyst",
        "description": "Ensure the estate is protected against this RCE vulnerability after the hunt.",
        "instructions": "Verify that Microsoft SharePoint security updates from August 2026 or later are applied to all servers in the estate."
      },
      "parents": [
        {
          "id": "decision-on-compromise",
          "branch": "on_refutes"
        },
        {
          "id": "forensic-artifact-review"
        }
      ]
    }
  ]
}