{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Unauthenticated command injection on internet-facing mail servers provides an immediate beachhead for cluster-wide credential theft and mailbox exfiltration. A negative result confirms that the vulnerable SNMP notification path has not been exploited on the current estate."
      },
      "name": "Zimbra CVE-2026-73570 RCE and JSP Web Shell Entry",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1190",
        "attack.t1059.004",
        "attack.t1505.003",
        "attack.t1071.001",
        "attack.t1041",
        "command and control",
        "credential access",
        "discovery",
        "exfiltration",
        "initial access",
        "lateral movement",
        "persistence",
        "privilege escalation",
        "reconnaissance"
      ],
      "series": {
        "slug": "unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570",
        "index": 1,
        "title": "Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570",
        "total": 3
      },
      "related": [
        {
          "hunt": "zimbra-privilege-escalation-pam",
          "reason": "This hunt identifies entry; a separate hunt examines the PAM-exec privilege escalation observed in the same campaign.",
          "relation": "follows"
        },
        {
          "hunt": "zimbra-credential-harvesting",
          "reason": "Attackers target LDAP and MySQL secrets after establishing a web shell; that activity requires specialized credential-access queries.",
          "relation": "follows"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A simple rule for the ZB73570 User-Agent is easily bypassed by rotating headers. This hunt uses a prevalence baseline for JSP files in application webroots and pivots into the specific process lineage of a monitoring component (swatchdog) that should never spawn network tools or interactive shells.",
      "coverage": [
        {
          "stage": "reconnaissance-and-probing",
          "steps": [
            "lead-probing-activity"
          ],
          "status": "covered"
        },
        {
          "stage": "initial-access-cve-2026-73570",
          "steps": [
            "command-injection-processes"
          ],
          "status": "covered"
        },
        {
          "stage": "persistence-jsp-webshells",
          "steps": [
            "rare-jsp-webshells"
          ],
          "status": "covered"
        },
        {
          "stage": "discovery-cluster-mapping",
          "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "privilege-escalation-pam-hook",
          "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "host-persistence-systemd",
          "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "credential-access-zimbra-secrets",
          "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "lateral-movement-ssh-rsync",
          "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "command-and-control-agent",
          "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "exfiltration-mailbox-data",
          "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Pre-exploitation scanning",
            "slug": "reconnaissance-and-probing",
            "tactic": "reconnaissance",
            "techniques": [
              "T1595"
            ],
            "observables": [
              "User-Agent: ZB73570",
              "oast.fun",
              "oast.online",
              "dnslog.pp.ua",
              "requestrepo.com",
              "bypass.eu.org",
              "Commands: curl, wget, ping, nslookup, id"
            ]
          },
          {
            "name": "Zimbra SNMP command injection",
            "slug": "initial-access-cve-2026-73570",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "CVE-2026-73570",
              "swatchdog",
              "snmptrap"
            ]
          },
          {
            "name": "JSP web shell deployment",
            "slug": "persistence-jsp-webshells",
            "tactic": "persistence",
            "techniques": [
              "T1505.003"
            ],
            "observables": [
              "Jetty and mailboxd application paths",
              "JSP files",
              "Payload reconstruction from staged fragments",
              "chmod on webroot directories"
            ]
          },
          {
            "name": "Zimbra cluster mapping",
            "slug": "discovery-cluster-mapping",
            "tactic": "discovery",
            "techniques": [
              "T1087",
              "T1083"
            ],
            "observables": [
              "zmprov",
              "/opt/zimbra/.ssh/zimbra_identity"
            ]
          },
          {
            "name": "PAM hook privilege escalation",
            "slug": "privilege-escalation-pam-hook",
            "tactic": "privilege-escalation",
            "techniques": [
              "T1548.003",
              "T1556"
            ],
            "observables": [
              "Symlink: zmmailboxd.out -> /etc/pam.d/sudo",
              "zmmailboxdmgr",
              "zmstat-fd",
              "pam_exec session hook",
              "NOPASSWD: ALL in sudoers"
            ]
          },
          {
            "name": "Systemd service persistence",
            "slug": "host-persistence-systemd",
            "tactic": "persistence",
            "techniques": [
              "T1543.002"
            ],
            "observables": [
              "/etc/systemd/system/zimlog.service",
              "Timestomping to match rsync.service or sshd.service",
              "systemctl enable zimlog.service"
            ]
          },
          {
            "name": "Service credential collection",
            "slug": "credential-access-zimbra-secrets",
            "tactic": "credential-access",
            "techniques": [
              "T1552",
              "T1555"
            ],
            "observables": [
              "zmlocalconfig -s",
              "ldapsearch",
              "zimbraPreAuthKey",
              "zimbraAuthTokenKey",
              "zimbraTwoFactorAuthSecret"
            ]
          },
          {
            "name": "Lateral movement across nodes",
            "slug": "lateral-movement-ssh-rsync",
            "tactic": "lateral-movement",
            "techniques": [
              "T1021.004"
            ],
            "observables": [
              "ssh -o BatchMode=yes",
              "rsync of payload fragments",
              "SSH identity: /opt/zimbra/.ssh/zimbra_identity"
            ]
          },
          {
            "name": "Remote access agents",
            "slug": "command-and-control-agent",
            "tactic": "command-and-control",
            "techniques": [
              "T1071.001",
              "T1105"
            ],
            "observables": [
              "zimdown2",
              "zimclient2",
              "agent2.sh",
              "openssl s_client",
              "Named pipe: /tmp/s",
              "WebSocket connections"
            ]
          },
          {
            "name": "Mailbox exfiltration attempt",
            "slug": "exfiltration-mailbox-data",
            "tactic": "exfiltration",
            "techniques": [
              "T1567",
              "T1041"
            ],
            "observables": [
              "zimbra-exfil/client-dump",
              "Compressed archive creation",
              "Transfer of collected data"
            ]
          }
        ],
        "summary": "Attackers exploit a command injection vulnerability (CVE-2026-73570) in Zimbra's SNMP notification path to execute commands as the zimbra user. The campaign involves deploying JSP web shells, escalating privileges to root via PAM hooks, stealing service credentials, and moving laterally across the cluster using existing SSH identities."
      },
      "severity": "high",
      "rationale": "The hunt begins by identifying hosts with CVE-2026-73570 findings. If the vulnerability scanner is not up to date, the analyst can alternative-scope by searching hb_software_inventory for 'Zimbra' packages version < 10.1.20.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An attacker is exploiting CVE-2026-73570 on internet-facing Zimbra servers to execute commands via the SNMP path and drop JSP web shells in the webroot for persistence.",
      "parameters": {
        "scope_hosts": {
          "from": {
            "ref": "analyst-input",
            "kind": "manual",
            "observed": "2026-09-30"
          },
          "type": "list[host]",
          "default": [],
          "description": "Hostnames to filter investigations; analyst should paste results from the scoping step here."
        },
        "oast_domains": {
          "from": {
            "ref": "msrc-blog-cve-2026-73570",
            "kind": "article",
            "observed": "2026-09-30"
          },
          "type": "list[domain]",
          "default": [
            "oast.fun",
            "oast.online",
            "dnslog.pp.ua",
            "requestrepo.com",
            "bypass.eu.org"
          ],
          "description": "Callback domains observed in probing activity."
        },
        "lookback_days": {
          "from": {
            "ref": "standard-lookback",
            "kind": "manual",
            "observed": "2026-09-30"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "exploit_user_agent": {
          "from": {
            "ref": "msrc-blog-cve-2026-73570",
            "kind": "article",
            "observed": "2026-09-30"
          },
          "type": "string",
          "default": "ZB73570",
          "description": "CVE-specific User-Agent from Microsoft telemetry."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570/",
          "gates": [
            "dry-run",
            "lint",
            "critic"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570/",
          "name": "Microsoft Security Blog \u2014 Unauthenticated command injection on internet-facing mail servers"
        }
      ],
      "blind_spots": [
        {
          "id": "no-http-telemetry",
          "risk": "Without HTTP visibility, the lead activity is missed and the gate to deeper investigation remains closed.",
          "stage": "reconnaissance-and-probing",
          "question": "Are the reconnaissance probes reaching the mail server?",
          "requires": "hb_http_activity or web server logs"
        },
        {
          "id": "no-endpoint-telemetry",
          "risk": "If the mail server lacks an endpoint agent, unauthenticated command execution occurs invisibly.",
          "stage": "initial-access-cve-2026-73570",
          "question": "Can we observe the child processes of snmptrap?",
          "requires": "hb_process_activity on Linux mail servers"
        },
        {
          "id": "short-file-retention",
          "risk": "Attackers often deploy shells early and then use them sparingly; short retention hides the persistence installation.",
          "stage": "persistence-jsp-webshells",
          "question": "Was the JSP web shell drop captured if it occurred weeks ago?",
          "requires": "hb_file_activity retention > 14 days"
        }
      ]
    },
    "name": "Zimbra CVE-2026-73570 RCE and JSP Web Shell Entry",
    "description": "This hunt targets the unauthenticated remote command injection vulnerability in the Zimbra SNMP notification path. Attackers use crafted SMTP requests to trigger the swatchdog and snmptrap execution chain. The hunt follows a gated flow: it first identifies vulnerable Zimbra hosts and checks for reconnaissance probes matching known CVE-specific User-Agents and OAST callback domains. Only if probes are detected does the hunt execute expensive process-ancestry and file-prevalence queries. An agent weighs the network probes against the host-side command execution and the presence of rare JSP files to identify a confirmed compromise."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570",
          "index": 1,
          "title": "Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570",
          "total": 3
        },
        "coverage": [
          {
            "stage": "reconnaissance-and-probing",
            "steps": [
              "lead-probing-activity"
            ],
            "status": "covered"
          },
          {
            "stage": "initial-access-cve-2026-73570",
            "steps": [
              "command-injection-processes"
            ],
            "status": "covered"
          },
          {
            "stage": "persistence-jsp-webshells",
            "steps": [
              "rare-jsp-webshells"
            ],
            "status": "covered"
          },
          {
            "stage": "discovery-cluster-mapping",
            "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "privilege-escalation-pam-hook",
            "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "host-persistence-systemd",
            "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "credential-access-zimbra-secrets",
            "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "lateral-movement-ssh-rsync",
            "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "command-and-control-agent",
            "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "exfiltration-mailbox-data",
            "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An attacker is exploiting CVE-2026-73570 on internet-facing Zimbra servers to execute commands via the SNMP path and drop JSP web shells in the webroot for persistence.",
        "blind_spots": [
          {
            "id": "no-http-telemetry",
            "risk": "Without HTTP visibility, the lead activity is missed and the gate to deeper investigation remains closed.",
            "stage": "reconnaissance-and-probing",
            "question": "Are the reconnaissance probes reaching the mail server?",
            "requires": "hb_http_activity or web server logs"
          },
          {
            "id": "no-endpoint-telemetry",
            "risk": "If the mail server lacks an endpoint agent, unauthenticated command execution occurs invisibly.",
            "stage": "initial-access-cve-2026-73570",
            "question": "Can we observe the child processes of snmptrap?",
            "requires": "hb_process_activity on Linux mail servers"
          },
          {
            "id": "short-file-retention",
            "risk": "Attackers often deploy shells early and then use them sparingly; short retention hides the persistence installation.",
            "stage": "persistence-jsp-webshells",
            "question": "Was the JSP web shell drop captured if it occurred weeks ago?",
            "requires": "hb_file_activity retention > 14 days"
          }
        ],
        "scoping_notes": "The hunt begins by identifying hosts with CVE-2026-73570 findings. If the vulnerability scanner is not up to date, the analyst can alternative-scope by searching hb_software_inventory for 'Zimbra' packages version < 10.1.20.",
        "beyond_detection": "A simple rule for the ZB73570 User-Agent is easily bypassed by rotating headers. This hunt uses a prevalence baseline for JSP files in application webroots and pivots into the specific process lineage of a monitoring component (swatchdog) that should never spawn network tools or interactive shells."
      }
    },
    {
      "id": "scoping-vulnerable-hosts",
      "type": "query",
      "label": "Scope Vulnerable Zimbra Hosts",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_uid, resource_uid, title FROM hb_vulnerability_finding WHERE cve_uid = 'CVE-2026-73570' AND status != 'suppressed'",
        "surface": "hb_vulnerability_finding",
        "description": "Identify hosts currently known to have the CVE-2026-73570 finding.",
        "expected_signal": "A list of hosts that have the CVE finding. Silence indicates either a patched estate or a missing scanner integration."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Scope Vulnerable Zimbra Hosts",
        "reads": [
          "device_uid",
          "resource_uid",
          "title",
          "cve_uid",
          "status"
        ],
        "source": "hb_vulnerability_finding",
        "target": "endpoint",
        "content": "SELECT device_uid, resource_uid, title FROM hb_vulnerability_finding WHERE cve_uid = 'CVE-2026-73570' AND status != 'suppressed'",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hosts that have the CVE finding. Silence indicates either a patched estate or a missing scanner integration.",
        "verified": "dry-run",
        "verified_at": "2026-10-01"
      }
    },
    {
      "id": "lead-probing-activity",
      "type": "query",
      "label": "Identify Reconnaissance Probes",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "web",
        "content": "SELECT device_hostname, src_endpoint_ip, user_agent, url_hostname, url_full, time FROM hb_http_activity WHERE (LOWER(user_agent) = LOWER('{{exploit_user_agent}}') OR instr(',' || '{{oast_domains}}' || ',', ',' || LOWER(url_hostname) || ',') > 0) AND (('{{scope_hosts}}' = '') OR (instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_http_activity",
        "description": "Find HTTP probes that use the CVE-specific User-Agent or hit OAST domains.",
        "expected_signal": "Requests from external IPs using the ZB73570 User-Agent. Silence proves that specific known scanners were not seen in the window."
      },
      "parents": [
        {
          "id": "scoping-vulnerable-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Identify Reconnaissance Probes",
        "reads": [
          "device_hostname",
          "src_endpoint_ip",
          "user_agent",
          "url_hostname",
          "url_full",
          "time"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT device_hostname, src_endpoint_ip, user_agent, url_hostname, url_full, time FROM hb_http_activity WHERE (LOWER(user_agent) = LOWER('{{exploit_user_agent}}') OR instr(',' || '{{oast_domains}}' || ',', ',' || LOWER(url_hostname) || ',') > 0) AND (('{{scope_hosts}}' = '') OR (instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "evidence_of_absence",
        "expected": "Requests from external IPs using the ZB73570 User-Agent. Silence proves that specific known scanners were not seen in the window.",
        "verified": "dry-run",
        "verified_at": "2026-10-01"
      }
    },
    {
      "id": "evaluate-lead",
      "type": "analytic",
      "label": "Evaluate Probing Lead",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "web"
        ],
        "context": [
          "lead-probing-activity"
        ],
        "objective": "Determine if the HTTP activity in lead-probing-activity constitutes a plausible exploit attempt against a mail server.",
        "description": "Determine if the lead activity warrants a deeper host-level investigation.",
        "max_iterations": 3,
        "expected_signal": "A verdict on whether the probes are suspicious for the identified hosts.",
        "success_criteria": "A per-host verdict of suspicious | benign."
      },
      "parents": [
        {
          "id": "lead-probing-activity"
        }
      ]
    },
    {
      "id": "gate-to-deep-investigation",
      "type": "checkpoint",
      "label": "Gate: Proceed to Deep Investigation",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the verdict in evaluate-lead is suspicious for at least one host",
        "condition": "the verdict in evaluate-lead is suspicious for at least one host",
        "blind_spot": "no-http-telemetry",
        "confidence": "high",
        "description": "Open expensive queries only when probes are confirmed.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "evaluate-lead"
        }
      ]
    },
    {
      "id": "command-injection-processes",
      "type": "query",
      "label": "Swatchdog Command Injection Chain",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, parent_process_name, user_name, time FROM hb_process_activity WHERE (LOWER(parent_process_name) LIKE '%swatchdog%' OR LOWER(process_name) LIKE '%snmptrap%') AND (LOWER(process_cmd_line) LIKE '%curl%' OR LOWER(process_cmd_line) LIKE '%wget%' OR LOWER(process_cmd_line) LIKE '%/bin/sh%' OR LOWER(process_cmd_line) LIKE '%/bin/bash%') AND (('{{scope_hosts}}' = '') OR (instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Find the specific process tree of swatchdog invoking snmptrap to launch shell commands.",
        "expected_signal": "Process command lines showing the zimbra user executing network tools or shells via snmptrap. This is a high-confidence indicator of exploitation."
      },
      "parents": [
        {
          "id": "gate-to-deep-investigation",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Swatchdog Command Injection Chain",
        "reads": [
          "device_hostname",
          "process_name",
          "process_cmd_line",
          "parent_process_name",
          "user_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, parent_process_name, user_name, time FROM hb_process_activity WHERE (LOWER(parent_process_name) LIKE '%swatchdog%' OR LOWER(process_name) LIKE '%snmptrap%') AND (LOWER(process_cmd_line) LIKE '%curl%' OR LOWER(process_cmd_line) LIKE '%wget%' OR LOWER(process_cmd_line) LIKE '%/bin/sh%' OR LOWER(process_cmd_line) LIKE '%/bin/bash%') AND (('{{scope_hosts}}' = '') OR (instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "evidence_of_absence",
        "expected": "Process command lines showing the zimbra user executing network tools or shells via snmptrap. This is a high-confidence indicator of exploitation.",
        "verified": "dry-run",
        "verified_at": "2026-10-01"
      }
    },
    {
      "id": "rare-jsp-webshells",
      "type": "query",
      "label": "Rare JSP Web Shell Creation",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT LOWER(file_path) AS jsp_path, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_file_activity WHERE activity_id = 1 AND LOWER(file_path) LIKE '%.jsp' AND (LOWER(file_path) LIKE '%/opt/zimbra/jetty/webapps/%' OR LOWER(file_path) LIKE '%/opt/zimbra/mailboxd/webapps/%') AND (('{{scope_hosts}}' = '') OR (instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY jsp_path HAVING host_count <= 5 ORDER BY host_count ASC",
        "surface": "hb_file_activity",
        "description": "Identify rare JSP files dropped in Zimbra application paths across the fleet.",
        "expected_signal": "JSP files that appear on few hosts; these are likely web shells. Benign JSP updates should appear on many hosts simultaneously."
      },
      "parents": [
        {
          "id": "gate-to-deep-investigation",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare JSP Web Shell Creation",
        "reads": [
          "device_hostname",
          "file_path",
          "activity_id",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT LOWER(file_path) AS jsp_path, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_file_activity WHERE activity_id = 1 AND LOWER(file_path) LIKE '%.jsp' AND (LOWER(file_path) LIKE '%/opt/zimbra/jetty/webapps/%' OR LOWER(file_path) LIKE '%/opt/zimbra/mailboxd/webapps/%') AND (('{{scope_hosts}}' = '') OR (instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY jsp_path HAVING host_count <= 5 ORDER BY host_count ASC",
        "silence": "evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "JSP files that appear on few hosts; these are likely web shells. Benign JSP updates should appear on many hosts simultaneously.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "jsp_path"
          ],
          "rare_below": 5
        },
        "verified_at": "2026-10-01"
      }
    },
    {
      "id": "triage-investigation",
      "type": "analytic",
      "label": "Triage Investigation Evidence",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "web"
        ],
        "context": [
          "evaluate-lead",
          "command-injection-processes",
          "rare-jsp-webshells"
        ],
        "objective": "Confirm if the identified hosts exhibit a complete exploit chain: from the ZB73570 User-Agent probe to the swatchdog/snmptrap command execution and finally the creation of a rare JSP web shell.",
        "description": "Correlate lead probes, process command injection, and file creation to confirm compromise.",
        "max_iterations": 6,
        "expected_signal": "A comprehensive per-host verdict citing the causal chain.",
        "success_criteria": "A final verdict of malicious | suspicious | benign per host."
      },
      "parents": [
        {
          "id": "command-injection-processes",
          "kind": "merge"
        },
        {
          "id": "rare-jsp-webshells",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on Triage Verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage-investigation verdict is malicious for at least one host",
        "condition": "the triage-investigation verdict is malicious for at least one host",
        "blind_spot": "no-endpoint-telemetry",
        "confidence": "high",
        "description": "Direct malicious activity to containment.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-investigation"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate Compromised Mail Server",
      "config": {
        "target": "endpoint",
        "description": "Contain the threat and prevent lateral movement to the cluster.",
        "instructions": "Isolate the host from the network. Capture the JSP file identified in rare-jsp-webshells and check /opt/zimbra/log/ for staging fragments before remediation.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Analyst Review",
      "config": {
        "assignee": "analyst",
        "description": "Verify the agent's findings and handle indeterminate cases.",
        "instructions": "Review the process tree for swatchdog. Confirm if the JSP file content contains web shell commands. If malicious, verify if cluster-wide secrets (LDAP/MySQL) were accessed."
      },
      "parents": [
        {
          "id": "gate-to-deep-investigation",
          "branch": "default"
        },
        {
          "id": "gate-to-deep-investigation",
          "branch": "on_unavailable"
        },
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close Out",
      "config": {
        "assignee": "analyst",
        "description": "Finalize the hunt and record negative findings.",
        "instructions": "Document the absence of exploitation on the examined Zimbra hosts. If probes were seen but no execution occurred, consider promoting the HTTP User-Agent query to a detection rule."
      },
      "parents": [
        {
          "id": "gate-to-deep-investigation",
          "branch": "on_refutes"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        }
      ]
    }
  ]
}