{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "The privilege escalation to root via PAM hijacking is a critical stage in the Zimbra compromise that allows attackers to move from application-level access to full host control. Detecting this and the subsequent root persistence is vital for preventing long-term occupancy and data theft."
      },
      "name": "Zimbra Privilege Escalation and Root Persistence",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1548.003",
        "attack.t1556",
        "attack.t1543.002",
        "attack.t1070.006",
        "command and control",
        "credential access",
        "discovery",
        "exfiltration",
        "initial access",
        "lateral movement",
        "persistence",
        "privilege escalation",
        "reconnaissance"
      ],
      "series": {
        "slug": "unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570",
        "index": 2,
        "title": "Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570",
        "total": 3
      },
      "related": [
        {
          "hunt": "zimbra-webshell-and-c2",
          "reason": "This hunt focuses on host-level privilege escalation, while initial access via CVE-2026-73570 and JSP webshell deployment are covered in a separate hunt.",
          "relation": "out-of-scope-alternative"
        },
        {
          "hunt": "zimbra-rce-webshell-entry",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A simple rule might find 'zimlog.service', but this hunt uses a fleet-wide prevalence baseline to find rare services and correlates them with the specific, complex file-system pivots used during the PAM hijacking, which a single-surface rule cannot easily capture.",
      "coverage": [
        {
          "stage": "privilege-escalation-pam-hook",
          "steps": [
            "pam-symlink-abuse",
            "triage-escalation"
          ],
          "status": "covered"
        },
        {
          "stage": "host-persistence-systemd",
          "steps": [
            "rare-systemd-services",
            "triage-escalation"
          ],
          "status": "covered"
        },
        {
          "stage": "reconnaissance-and-probing",
          "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "initial-access-cve-2026-73570",
          "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "persistence-jsp-webshells",
          "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "discovery-cluster-mapping",
          "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "credential-access-zimbra-secrets",
          "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "lateral-movement-ssh-rsync",
          "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "command-and-control-agent",
          "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "exfiltration-mailbox-data",
          "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Pre-exploitation scanning",
            "slug": "reconnaissance-and-probing",
            "tactic": "reconnaissance",
            "techniques": [
              "T1595"
            ],
            "observables": [
              "User-Agent: ZB73570",
              "oast.fun",
              "oast.online",
              "dnslog.pp.ua",
              "requestrepo.com",
              "bypass.eu.org",
              "Commands: curl, wget, ping, nslookup, id"
            ]
          },
          {
            "name": "Zimbra SNMP command injection",
            "slug": "initial-access-cve-2026-73570",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "CVE-2026-73570",
              "swatchdog",
              "snmptrap"
            ]
          },
          {
            "name": "JSP web shell deployment",
            "slug": "persistence-jsp-webshells",
            "tactic": "persistence",
            "techniques": [
              "T1505.003"
            ],
            "observables": [
              "Jetty and mailboxd application paths",
              "JSP files",
              "Payload reconstruction from staged fragments",
              "chmod on webroot directories"
            ]
          },
          {
            "name": "Zimbra cluster mapping",
            "slug": "discovery-cluster-mapping",
            "tactic": "discovery",
            "techniques": [
              "T1087",
              "T1083"
            ],
            "observables": [
              "zmprov",
              "/opt/zimbra/.ssh/zimbra_identity"
            ]
          },
          {
            "name": "PAM hook privilege escalation",
            "slug": "privilege-escalation-pam-hook",
            "tactic": "privilege-escalation",
            "techniques": [
              "T1548.003",
              "T1556"
            ],
            "observables": [
              "Symlink: zmmailboxd.out -> /etc/pam.d/sudo",
              "zmmailboxdmgr",
              "zmstat-fd",
              "pam_exec session hook",
              "NOPASSWD: ALL in sudoers"
            ]
          },
          {
            "name": "Systemd service persistence",
            "slug": "host-persistence-systemd",
            "tactic": "persistence",
            "techniques": [
              "T1543.002"
            ],
            "observables": [
              "/etc/systemd/system/zimlog.service",
              "Timestomping to match rsync.service or sshd.service",
              "systemctl enable zimlog.service"
            ]
          },
          {
            "name": "Service credential collection",
            "slug": "credential-access-zimbra-secrets",
            "tactic": "credential-access",
            "techniques": [
              "T1552",
              "T1555"
            ],
            "observables": [
              "zmlocalconfig -s",
              "ldapsearch",
              "zimbraPreAuthKey",
              "zimbraAuthTokenKey",
              "zimbraTwoFactorAuthSecret"
            ]
          },
          {
            "name": "Lateral movement across nodes",
            "slug": "lateral-movement-ssh-rsync",
            "tactic": "lateral-movement",
            "techniques": [
              "T1021.004"
            ],
            "observables": [
              "ssh -o BatchMode=yes",
              "rsync of payload fragments",
              "SSH identity: /opt/zimbra/.ssh/zimbra_identity"
            ]
          },
          {
            "name": "Remote access agents",
            "slug": "command-and-control-agent",
            "tactic": "command-and-control",
            "techniques": [
              "T1071.001",
              "T1105"
            ],
            "observables": [
              "zimdown2",
              "zimclient2",
              "agent2.sh",
              "openssl s_client",
              "Named pipe: /tmp/s",
              "WebSocket connections"
            ]
          },
          {
            "name": "Mailbox exfiltration attempt",
            "slug": "exfiltration-mailbox-data",
            "tactic": "exfiltration",
            "techniques": [
              "T1567",
              "T1041"
            ],
            "observables": [
              "zimbra-exfil/client-dump",
              "Compressed archive creation",
              "Transfer of collected data"
            ]
          }
        ],
        "summary": "Attackers exploit a command injection vulnerability (CVE-2026-73570) in Zimbra's SNMP notification path to execute commands as the zimbra user. The campaign involves deploying JSP web shells, escalating privileges to root via PAM hooks, stealing service credentials, and moving laterally across the cluster using existing SSH identities."
      },
      "severity": "high",
      "rationale": "Start with public-facing MTA and Mailbox nodes identified in hb_software_inventory. Widen the scope to all hosts if the initial queries show any suspicious PAM activity.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An intruder has escalated from the Zimbra service account to root by symlinking application logs to PAM configurations and established persistence through a rare systemd service.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Target Zimbra hostnames; leave empty to scan the entire estate."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570/",
          "gates": [
            "dry-run",
            "lint",
            "critic"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570/",
          "name": "MSRC Blog - Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570"
        }
      ],
      "blind_spots": [
        {
          "id": "no-file-telemetry",
          "risk": "If the EDR only logs a 'write' or 'create' but not the symlink target, the specific PAM hijacking technique may appear as normal log rotation or noise.",
          "stage": "privilege-escalation-pam-hook",
          "question": "Was the file modification actually a symlink creation?",
          "requires": "hb_file_activity with symlink target tracking"
        },
        {
          "id": "timestomping-blindness",
          "risk": "A successful timestomp makes the persistence mechanism look like a pre-existing, legitimate component, potentially misleading an analyst who filters by 'new' files.",
          "stage": "host-persistence-systemd",
          "question": "What was the actual creation time of the zimlog.service file?",
          "requires": "MFT or inode birth time analysis"
        }
      ]
    },
    "name": "Zimbra Privilege Escalation and Root Persistence",
    "description": "This hunt targets the complex post-exploitation chain observed in CVE-2026-73570. An adversary takes ownership of the sudo PAM configuration by symlinking application logs to sensitive system files. It then identifies rare systemd services created in /etc/systemd/system/, specifically focusing on services named zimlog.service or those whose timestamps have been modified to match legitimate system services like rsync or sshd. The hunt uses an agent to correlate these file and service anomalies, allowing an analyst to confirm root-level persistence."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570",
          "index": 2,
          "title": "Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570",
          "total": 3
        },
        "coverage": [
          {
            "stage": "privilege-escalation-pam-hook",
            "steps": [
              "pam-symlink-abuse",
              "triage-escalation"
            ],
            "status": "covered"
          },
          {
            "stage": "host-persistence-systemd",
            "steps": [
              "rare-systemd-services",
              "triage-escalation"
            ],
            "status": "covered"
          },
          {
            "stage": "reconnaissance-and-probing",
            "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "initial-access-cve-2026-73570",
            "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "persistence-jsp-webshells",
            "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "discovery-cluster-mapping",
            "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "credential-access-zimbra-secrets",
            "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "lateral-movement-ssh-rsync",
            "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "command-and-control-agent",
            "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "exfiltration-mailbox-data",
            "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An intruder has escalated from the Zimbra service account to root by symlinking application logs to PAM configurations and established persistence through a rare systemd service.",
        "blind_spots": [
          {
            "id": "no-file-telemetry",
            "risk": "If the EDR only logs a 'write' or 'create' but not the symlink target, the specific PAM hijacking technique may appear as normal log rotation or noise.",
            "stage": "privilege-escalation-pam-hook",
            "question": "Was the file modification actually a symlink creation?",
            "requires": "hb_file_activity with symlink target tracking"
          },
          {
            "id": "timestomping-blindness",
            "risk": "A successful timestomp makes the persistence mechanism look like a pre-existing, legitimate component, potentially misleading an analyst who filters by 'new' files.",
            "stage": "host-persistence-systemd",
            "question": "What was the actual creation time of the zimlog.service file?",
            "requires": "MFT or inode birth time analysis"
          }
        ],
        "scoping_notes": "Start with public-facing MTA and Mailbox nodes identified in hb_software_inventory. Widen the scope to all hosts if the initial queries show any suspicious PAM activity.",
        "beyond_detection": "A simple rule might find 'zimlog.service', but this hunt uses a fleet-wide prevalence baseline to find rare services and correlates them with the specific, complex file-system pivots used during the PAM hijacking, which a single-surface rule cannot easily capture."
      }
    },
    {
      "id": "scope-zimbra-hosts",
      "type": "query",
      "label": "Identify Zimbra servers",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_hostname, package_name, package_version, vendor_name FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%zimbra%' OR LOWER(vendor_name) LIKE '%zimbra%')",
        "surface": "hb_software_inventory",
        "description": "Define the scope by identifying hosts that have Zimbra software installed.",
        "expected_signal": "A list of hosts running Zimbra. Silence indicates no Zimbra installation is visible in the current inventory."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify Zimbra servers",
        "reads": [
          "device_hostname",
          "package_name",
          "package_version",
          "vendor_name"
        ],
        "source": "hb_software_inventory",
        "target": "endpoint",
        "content": "SELECT device_hostname, package_name, package_version, vendor_name FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%zimbra%' OR LOWER(vendor_name) LIKE '%zimbra%')",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hosts running Zimbra. Silence indicates no Zimbra installation is visible in the current inventory.",
        "verified": "dry-run",
        "verified_at": "2026-10-01"
      }
    },
    {
      "id": "rare-systemd-services",
      "type": "query",
      "label": "Rare systemd services",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT job_name, job_definition_path, job_cmd_line, COUNT(DISTINCT device_hostname) AS host_count FROM hb_scheduled_job WHERE job_definition_path LIKE '/etc/systemd/system/%' AND (('{{scope_hosts}}' = '') OR (instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY job_name, job_definition_path, job_cmd_line HAVING host_count <= 2",
        "surface": "hb_scheduled_job",
        "description": "Stack-count systemd services to find the 'zimlog.service' or other anomalies across the fleet.",
        "expected_signal": "A service found on only one or two hosts, specifically looking for 'zimlog.service'."
      },
      "parents": [
        {
          "id": "scope-zimbra-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare systemd services",
        "reads": [
          "job_name",
          "job_definition_path",
          "job_cmd_line",
          "device_hostname",
          "time"
        ],
        "source": "hb_scheduled_job",
        "target": "endpoint",
        "content": "SELECT job_name, job_definition_path, job_cmd_line, COUNT(DISTINCT device_hostname) AS host_count FROM hb_scheduled_job WHERE job_definition_path LIKE '/etc/systemd/system/%' AND (('{{scope_hosts}}' = '') OR (instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY job_name, job_definition_path, job_cmd_line HAVING host_count <= 2",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A service found on only one or two hosts, specifically looking for 'zimlog.service'.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "job_name",
            "job_definition_path"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-10-01"
      }
    },
    {
      "id": "pam-symlink-abuse",
      "type": "query",
      "label": "PAM and Log Symlink Abuse",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, file_path, actor_user_name, process_name, time FROM hb_file_activity WHERE (LOWER(file_path) LIKE '%/etc/pam.d/sudo%' OR LOWER(file_path) LIKE '%zmmailboxd.out%') AND (('{{scope_hosts}}' = '') OR (instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_file_activity",
        "description": "Identify file activity where the zimbra account touches the PAM sudo configuration or its own log files abnormally.",
        "expected_signal": "Modifications to the PAM configuration by a non-root user (zimbra), or operations involving the zmmailboxd.out log file that precede sudo elevation."
      },
      "parents": [
        {
          "id": "scope-zimbra-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "PAM and Log Symlink Abuse",
        "reads": [
          "device_hostname",
          "file_path",
          "actor_user_name",
          "process_name",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, file_path, actor_user_name, process_name, time FROM hb_file_activity WHERE (LOWER(file_path) LIKE '%/etc/pam.d/sudo%' OR LOWER(file_path) LIKE '%zmmailboxd.out%') AND (('{{scope_hosts}}' = '') OR (instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Modifications to the PAM configuration by a non-root user (zimbra), or operations involving the zmmailboxd.out log file that precede sudo elevation.",
        "verified": "dry-run",
        "verified_at": "2026-10-01"
      }
    },
    {
      "id": "triage-escalation",
      "type": "analytic",
      "label": "Evaluate Escalation Evidence",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "scope-zimbra-hosts",
          "rare-systemd-services",
          "pam-symlink-abuse"
        ],
        "objective": "Determine if the zimbra user successfully hijacked the PAM configuration and established root-level persistence via a systemd service. Analyze whether the service appears to be timestomped to match legitimate services.",
        "description": "Correlate file-system manipulation with new, rare system services to confirm root privilege escalation.",
        "max_iterations": 5,
        "expected_signal": "A per-host verdict on the maliciousness of the observed activity.",
        "success_criteria": "A verdict of malicious | suspicious | benign per host, citing specific rows from the file activity and job tables."
      },
      "parents": [
        {
          "id": "rare-systemd-services",
          "kind": "merge"
        },
        {
          "id": "pam-symlink-abuse",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage-escalation verdict is malicious for at least one host involving PAM configuration modification and a rare systemd service",
        "condition": "the triage-escalation verdict is malicious for at least one host involving PAM configuration modification and a rare systemd service",
        "blind_spot": "no-file-telemetry",
        "confidence": "high",
        "description": "Direct the response based on the agent's confidence in the privilege escalation findings.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-escalation"
        }
      ]
    },
    {
      "id": "isolate-server",
      "type": "action",
      "label": "Isolate Compromised Server",
      "config": {
        "target": "endpoint",
        "description": "Contain the threat by isolating the server where root access was established.",
        "instructions": "Isolate the host immediately. Do not restart services as this may trigger persistence hooks. Capture a memory image and the /etc/pam.d/ and /etc/systemd/system/ directories for forensic analysis.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-manual-review",
      "type": "task",
      "label": "Forensic Review of Persistence",
      "config": {
        "assignee": "analyst",
        "description": "Manually verify the symlink state and timestomping evidence that the telemetry might obscure.",
        "instructions": "Inspect the file system on isolated hosts. Verify if /opt/zimbra/log/zmmailboxd.out is a symlink to /etc/pam.d/sudo. Check the modification times of /etc/systemd/system/zimlog.service against the systemd journal to confirm timestomping."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-server"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out",
      "config": {
        "assignee": "analyst",
        "description": "Document results and findings.",
        "instructions": "Summarize which hosts were examined. If no activity was found, record the negative results as evidence of absence for this specific technique."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "analyst-manual-review"
        }
      ]
    }
  ]
}