{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "SonicWall SMA1000 appliances are critical edge gateways; unauthenticated RCE on these systems provides a direct path to internal networks. Active exploitation in the wild creates a high-risk exposure that justifies an estate-wide search."
      },
      "name": "SonicWall SMA1000 Edge Appliance Exploitation",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1190",
        "attack.t1059",
        "credential access",
        "discovery",
        "execution",
        "initial access"
      ],
      "related": [
        {
          "hunt": "sma1000-post-exploitation-credential-access",
          "reason": "Post-exploitation credential theft or token access requires different telemetry surfaces such as hb_auth_signin or hb_account_change which are out of scope for this initial RCE hunt.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "This hunt pivots between software inventory, traffic prevalence, and behavioural parent-child process relationships. A single detection rule might miss the chain if an adversary rotates URI paths, but this hunt correlates host vulnerability status with anomalous shell execution from management context.",
      "coverage": [
        {
          "stage": "discovery-of-exposed-vulnerable-gateways",
          "steps": [
            "scoping-vulnerable-appliances"
          ],
          "status": "covered"
        },
        {
          "stage": "initial-access-chained-vulnerability-exploitation",
          "steps": [
            "prevalence-management-traffic"
          ],
          "status": "covered"
        },
        {
          "stage": "execution-of-arbitrary-os-commands",
          "steps": [
            "behaviour-shell-execution"
          ],
          "status": "covered"
        },
        {
          "stage": "potential-credential-and-token-access",
          "reason": "Not examined by this hunt; belongs to a separate hunt.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Discovery of exposed vulnerable gateways",
            "slug": "discovery-of-exposed-vulnerable-gateways",
            "tactic": "discovery",
            "techniques": [
              "T1580"
            ],
            "observables": [
              "SonicWall SMA1000 Models 6210, 7210, 8200v",
              "Versions 12.4.3-03453 and earlier",
              "Versions 12.5.0-02835 and earlier",
              "SMA1000 Appliance Work Place interface",
              "Appliance Management Console (AMC)"
            ]
          },
          {
            "name": "Initial access via chained RCE",
            "slug": "initial-access-chained-vulnerability-exploitation",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "CVE-2026-83548 (SSRF)",
              "CVE-2026-83549 (Command Injection)",
              "Inbound requests to SMA1000 Appliance Work Place interface",
              "Unauthenticated access to sensitive management functionality"
            ]
          },
          {
            "name": "Execution of arbitrary OS commands",
            "slug": "execution-of-arbitrary-os-commands",
            "tactic": "execution",
            "techniques": [
              "T1059"
            ],
            "observables": [
              "Execution of arbitrary OS commands from the Appliance Management Console context",
              "Commands spawning from the web server or appliance management processes"
            ]
          },
          {
            "name": "Potential credential and token access",
            "slug": "potential-credential-and-token-access",
            "tactic": "credential-access",
            "techniques": [
              "T1555"
            ],
            "observables": [
              "Unauthorized access to user and administrator passwords",
              "Access to Time-based One-Time Password (TOTP) tokens"
            ]
          }
        ],
        "summary": "Attackers chain a critical SSRF vulnerability (CVE-2026-83548) and an OS command injection flaw (CVE-2026-83549) in SonicWall SMA1000 appliances to achieve unauthenticated remote code execution. This allows an external actor to execute arbitrary commands on the network edge and potentially access stored credentials or session tokens."
      },
      "severity": "high",
      "rationale": "Focus on internet-exposed SMA1000 appliances identified in the first step. Use the resulting hostnames to populate the scope_hosts parameter for traffic and process analysis.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary is exploiting a chain of SSRF and command injection vulnerabilities on a SonicWall SMA1000 appliance to achieve remote code execution, indicated by rare HTTP management traffic followed by shell spawns from web processes.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Specific hostnames to focus on; leave empty to hunt across all discovered vulnerable appliances."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "History to examine for exploitation signs."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.rapid7.com/blog/post/etr-critical-sonicwall-sma1000-vulnerabilities-cve-2026-83548-cve-2026-83549-exploited-in-the-wild",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.rapid7.com/blog/post/etr-critical-sonicwall-sma1000-vulnerabilities-cve-2026-83548-cve-2026-83549-exploited-in-the-wild",
          "name": "Rapid7 \u2014 Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild"
        }
      ],
      "blind_spots": [
        {
          "id": "appliance-log-visibility",
          "risk": "Standard HTTP logs show the request path but may miss the actual payload if it is contained in the request body, leading to an incomplete view of the injection attempt.",
          "stage": "initial-access-chained-vulnerability-exploitation",
          "question": "whether the command injection payload is directly visible in the web logs",
          "requires": "hb_http_activity with full POST body logs from the appliance"
        },
        {
          "id": "restricted-shell-logging",
          "risk": "Proprietary appliances often restrict OS-level auditing; command execution might only be visible if the appliance forwards audit logs to a central collector.",
          "stage": "execution-of-arbitrary-os-commands",
          "question": "whether commands executed via the injection are visible if the appliance does not support standard process auditing",
          "requires": "hb_process_activity from the appliance underlying OS"
        }
      ]
    },
    "name": "SonicWall SMA1000 Edge Appliance Exploitation",
    "description": "This hunt identifies SonicWall SMA1000 appliances vulnerable to CVE-2026-83548 and CVE-2026-83549 and searches for evidence of post-exploitation activity. Because these appliances are network-edge systems, any unauthenticated access to the Work Place or Management Console followed by process execution is irregular. The hunt starts by scoping the estate via software inventory, stack-counts HTTP paths to management interfaces to identify anomalous access, and identifies shell execution originating from web-related parent processes. An agent correlates these signals to identify compromised appliances."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "coverage": [
          {
            "stage": "discovery-of-exposed-vulnerable-gateways",
            "steps": [
              "scoping-vulnerable-appliances"
            ],
            "status": "covered"
          },
          {
            "stage": "initial-access-chained-vulnerability-exploitation",
            "steps": [
              "prevalence-management-traffic"
            ],
            "status": "covered"
          },
          {
            "stage": "execution-of-arbitrary-os-commands",
            "steps": [
              "behaviour-shell-execution"
            ],
            "status": "covered"
          },
          {
            "stage": "potential-credential-and-token-access",
            "reason": "Not examined by this hunt; belongs to a separate hunt.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary is exploiting a chain of SSRF and command injection vulnerabilities on a SonicWall SMA1000 appliance to achieve remote code execution, indicated by rare HTTP management traffic followed by shell spawns from web processes.",
        "blind_spots": [
          {
            "id": "appliance-log-visibility",
            "risk": "Standard HTTP logs show the request path but may miss the actual payload if it is contained in the request body, leading to an incomplete view of the injection attempt.",
            "stage": "initial-access-chained-vulnerability-exploitation",
            "question": "whether the command injection payload is directly visible in the web logs",
            "requires": "hb_http_activity with full POST body logs from the appliance"
          },
          {
            "id": "restricted-shell-logging",
            "risk": "Proprietary appliances often restrict OS-level auditing; command execution might only be visible if the appliance forwards audit logs to a central collector.",
            "stage": "execution-of-arbitrary-os-commands",
            "question": "whether commands executed via the injection are visible if the appliance does not support standard process auditing",
            "requires": "hb_process_activity from the appliance underlying OS"
          }
        ],
        "scoping_notes": "Focus on internet-exposed SMA1000 appliances identified in the first step. Use the resulting hostnames to populate the scope_hosts parameter for traffic and process analysis.",
        "beyond_detection": "This hunt pivots between software inventory, traffic prevalence, and behavioural parent-child process relationships. A single detection rule might miss the chain if an adversary rotates URI paths, but this hunt correlates host vulnerability status with anomalous shell execution from management context."
      }
    },
    {
      "id": "scoping-vulnerable-appliances",
      "type": "query",
      "label": "Identify vulnerable SonicWall appliances",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_hostname, package_name, package_version, vendor_name FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%sma1000%' OR LOWER(vendor_name) LIKE '%sonicwall%') AND (package_version <= '12.4.3-03453' OR package_version <= '12.5.0-02835')",
        "surface": "hb_software_inventory",
        "description": "Find resources running vulnerable versions of SonicWall SMA1000 software to define the target scope.",
        "expected_signal": "A list of hostnames representing the potential attack surface. Silence indicates no SonicWall SMA1000 software was discovered."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify vulnerable SonicWall appliances",
        "reads": [
          "device_hostname",
          "package_name",
          "package_version",
          "vendor_name"
        ],
        "source": "hb_software_inventory",
        "target": "endpoint",
        "content": "SELECT device_hostname, package_name, package_version, vendor_name FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%sma1000%' OR LOWER(vendor_name) LIKE '%sonicwall%') AND (package_version <= '12.4.3-03453' OR package_version <= '12.5.0-02835')",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hostnames representing the potential attack surface. Silence indicates no SonicWall SMA1000 software was discovered.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "prevalence-management-traffic",
      "type": "query",
      "label": "Rare HTTP requests to appliance management paths",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "web",
        "content": "SELECT device_hostname, url_path, COUNT(*) AS request_count, COUNT(DISTINCT src_endpoint_ip) AS unique_sources, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_http_activity WHERE (LOWER(url_path) LIKE '%workplace%' OR LOWER(url_path) LIKE '%/amc/%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, url_path HAVING request_count <= 10 ORDER BY request_count ASC",
        "surface": "hb_http_activity",
        "description": "Stack-count HTTP request paths on the scoped hosts to find rare access to the Work Place or AMC interfaces, which may indicate SSRF or command injection attempts.",
        "expected_signal": "Unusual paths or parameters that differ from baseline administrative use. Fewer than 10 hits per host to management paths is a strong lead for unauthenticated exploitation."
      },
      "parents": [
        {
          "id": "scoping-vulnerable-appliances"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare HTTP requests to appliance management paths",
        "reads": [
          "device_hostname",
          "url_path",
          "src_endpoint_ip",
          "time"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT device_hostname, url_path, COUNT(*) AS request_count, COUNT(DISTINCT src_endpoint_ip) AS unique_sources, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_http_activity WHERE (LOWER(url_path) LIKE '%workplace%' OR LOWER(url_path) LIKE '%/amc/%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, url_path HAVING request_count <= 10 ORDER BY request_count ASC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Unusual paths or parameters that differ from baseline administrative use. Fewer than 10 hits per host to management paths is a strong lead for unauthenticated exploitation.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "url_path"
          ],
          "rare_below": 10
        },
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "behaviour-shell-execution",
      "type": "query",
      "label": "Shell execution from appliance management processes",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, parent_process_name, parent_process_cmd_line, user_name, time FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%/sh' OR LOWER(process_name) LIKE '%/bash' OR LOWER(process_name) LIKE '%/nc' OR LOWER(process_name) LIKE '%/python%' OR LOWER(process_name) LIKE '%/perl%') AND (LOWER(parent_process_name) LIKE '%httpd%' OR LOWER(parent_process_name) LIKE '%nginx%' OR LOWER(parent_process_name) LIKE '%apache%' OR LOWER(parent_process_name) LIKE '%sonicwall%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') ORDER BY time DESC",
        "surface": "hb_process_activity",
        "description": "Identify shells or interpreters spawning from web-facing or management processes, suggesting successful command injection.",
        "expected_signal": "Shell execution on a network appliance is highly irregular. If the parent process is a web server or management daemon, it directly suggests exploitation of CVE-2026-83549."
      },
      "parents": [
        {
          "id": "prevalence-management-traffic"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Shell execution from appliance management processes",
        "reads": [
          "device_hostname",
          "process_name",
          "process_cmd_line",
          "parent_process_name",
          "parent_process_cmd_line",
          "user_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, parent_process_name, parent_process_cmd_line, user_name, time FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%/sh' OR LOWER(process_name) LIKE '%/bash' OR LOWER(process_name) LIKE '%/nc' OR LOWER(process_name) LIKE '%/python%' OR LOWER(process_name) LIKE '%/perl%') AND (LOWER(parent_process_name) LIKE '%httpd%' OR LOWER(parent_process_name) LIKE '%nginx%' OR LOWER(parent_process_name) LIKE '%apache%' OR LOWER(parent_process_name) LIKE '%sonicwall%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') ORDER BY time DESC",
        "silence": "evidence_of_absence",
        "expected": "Shell execution on a network appliance is highly irregular. If the parent process is a web server or management daemon, it directly suggests exploitation of CVE-2026-83549.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "exploitation-triage",
      "type": "analytic",
      "label": "Assess exploitation evidence",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "web"
        ],
        "context": [
          "scoping-vulnerable-appliances",
          "prevalence-management-traffic",
          "behaviour-shell-execution"
        ],
        "objective": "Determine if any SonicWall SMA1000 appliance shows a chain of rare management traffic followed by shell execution from a web process context.",
        "description": "Correlate vulnerable hosts with rare management traffic and subsequent shell execution to confirm exploitation of the chained RCE.",
        "max_iterations": 4,
        "expected_signal": "A per-host verdict linking vulnerable software status, anomalous web requests, and suspicious process execution.",
        "success_criteria": "A verdict of malicious | suspicious | benign per host, citing specific process and HTTP rows."
      },
      "parents": [
        {
          "id": "behaviour-shell-execution"
        }
      ]
    },
    {
      "id": "verdict-route",
      "type": "checkpoint",
      "label": "Route on triage result",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the exploitation-triage verdict is malicious or suspicious for at least one host",
        "condition": "the exploitation-triage verdict is malicious or suspicious for at least one host",
        "blind_spot": "appliance-log-visibility",
        "confidence": "high",
        "description": "Direct the analyst to remediation or close-out based on the agent's findings.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "exploitation-triage"
        }
      ]
    },
    {
      "id": "task-remediation-review",
      "type": "task",
      "label": "Analyze findings and coordinate patching",
      "config": {
        "assignee": "analyst",
        "description": "Verify suspicious activity on vulnerable hosts and coordinate with infrastructure teams to apply hotfixes.",
        "instructions": "Review the cited rows for evidence of RCE. Coordinate the application of SonicWall hotfixes (12.4.3-03526 or 12.5.0-02952). For appliances with confirmed suspicious activity, engage SonicWall Technical Support and plan to re-image hardware or re-deploy virtual instances as per vendor guidance."
      },
      "parents": [
        {
          "id": "verdict-route",
          "branch": "on_supports"
        },
        {
          "id": "verdict-route",
          "branch": "default"
        },
        {
          "id": "verdict-route",
          "branch": "on_unavailable"
        }
      ]
    },
    {
      "id": "task-close-out",
      "type": "task",
      "label": "Close out hunt",
      "config": {
        "assignee": "analyst",
        "description": "Document the search results and state of the estate for the vulnerability.",
        "instructions": "Record which appliances were checked and confirm if they are running fixed versions. If the estate remains vulnerable but clean, schedule a periodic re-run of this hunt until patching is verified."
      },
      "parents": [
        {
          "id": "verdict-route",
          "branch": "on_refutes"
        }
      ]
    }
  ]
}