{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "The compromise of service keys on a mail server is a high-impact event that provides long-term, cluster-wide access; proactive hunting for the reuse of these keys is required to mitigate the risk of mass mailbox exfiltration."
      },
      "name": "Zimbra secrets theft and cluster propagation",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1087",
        "attack.t1083",
        "attack.t1552",
        "attack.t1555",
        "attack.t1021.004",
        "attack.t1071.001",
        "attack.t1567",
        "attack.t1041",
        "command and control",
        "credential access",
        "discovery",
        "exfiltration",
        "initial access",
        "lateral movement",
        "persistence",
        "privilege escalation",
        "reconnaissance"
      ],
      "series": {
        "slug": "unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570",
        "index": 3,
        "title": "Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570",
        "total": 3
      },
      "related": [
        {
          "hunt": "zimbra-persistence-webshells",
          "reason": "Persistence via JSP webshells and systemd units is handled in a separate hunt focused on the post-exploitation survival phase.",
          "relation": "out-of-scope-alternative"
        },
        {
          "hunt": "zimbra-privesc-pam-systemd",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "While a rule can alert on the zimbra user running zmlocalconfig, this hunt pivots from that single indicator to look for the fleet-wide consequences: lateral movement and data staging. By using a baseline for administrative mapping tools, it filters out routine maintenance that simple rules would likely miss or over-alert on.",
      "coverage": [
        {
          "stage": "discovery-cluster-mapping",
          "steps": [
            "discovery-and-mapping"
          ],
          "status": "covered"
        },
        {
          "stage": "credential-access-zimbra-secrets",
          "steps": [
            "secret-collection-activity"
          ],
          "status": "covered"
        },
        {
          "stage": "lateral-movement-ssh-rsync",
          "steps": [
            "lateral-movement-activity"
          ],
          "status": "covered"
        },
        {
          "stage": "command-and-control-agent",
          "steps": [
            "exfiltration-and-c2-activity"
          ],
          "status": "covered"
        },
        {
          "stage": "exfiltration-mailbox-data",
          "steps": [
            "exfiltration-and-c2-activity"
          ],
          "status": "covered"
        },
        {
          "stage": "reconnaissance-and-probing",
          "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "initial-access-cve-2026-73570",
          "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "persistence-jsp-webshells",
          "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "privilege-escalation-pam-hook",
          "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "host-persistence-systemd",
          "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Pre-exploitation scanning",
            "slug": "reconnaissance-and-probing",
            "tactic": "reconnaissance",
            "techniques": [
              "T1595"
            ],
            "observables": [
              "User-Agent: ZB73570",
              "oast.fun",
              "oast.online",
              "dnslog.pp.ua",
              "requestrepo.com",
              "bypass.eu.org",
              "Commands: curl, wget, ping, nslookup, id"
            ]
          },
          {
            "name": "Zimbra SNMP command injection",
            "slug": "initial-access-cve-2026-73570",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "CVE-2026-73570",
              "swatchdog",
              "snmptrap"
            ]
          },
          {
            "name": "JSP web shell deployment",
            "slug": "persistence-jsp-webshells",
            "tactic": "persistence",
            "techniques": [
              "T1505.003"
            ],
            "observables": [
              "Jetty and mailboxd application paths",
              "JSP files",
              "Payload reconstruction from staged fragments",
              "chmod on webroot directories"
            ]
          },
          {
            "name": "Zimbra cluster mapping",
            "slug": "discovery-cluster-mapping",
            "tactic": "discovery",
            "techniques": [
              "T1087",
              "T1083"
            ],
            "observables": [
              "zmprov",
              "/opt/zimbra/.ssh/zimbra_identity"
            ]
          },
          {
            "name": "PAM hook privilege escalation",
            "slug": "privilege-escalation-pam-hook",
            "tactic": "privilege-escalation",
            "techniques": [
              "T1548.003",
              "T1556"
            ],
            "observables": [
              "Symlink: zmmailboxd.out -> /etc/pam.d/sudo",
              "zmmailboxdmgr",
              "zmstat-fd",
              "pam_exec session hook",
              "NOPASSWD: ALL in sudoers"
            ]
          },
          {
            "name": "Systemd service persistence",
            "slug": "host-persistence-systemd",
            "tactic": "persistence",
            "techniques": [
              "T1543.002"
            ],
            "observables": [
              "/etc/systemd/system/zimlog.service",
              "Timestomping to match rsync.service or sshd.service",
              "systemctl enable zimlog.service"
            ]
          },
          {
            "name": "Service credential collection",
            "slug": "credential-access-zimbra-secrets",
            "tactic": "credential-access",
            "techniques": [
              "T1552",
              "T1555"
            ],
            "observables": [
              "zmlocalconfig -s",
              "ldapsearch",
              "zimbraPreAuthKey",
              "zimbraAuthTokenKey",
              "zimbraTwoFactorAuthSecret"
            ]
          },
          {
            "name": "Lateral movement across nodes",
            "slug": "lateral-movement-ssh-rsync",
            "tactic": "lateral-movement",
            "techniques": [
              "T1021.004"
            ],
            "observables": [
              "ssh -o BatchMode=yes",
              "rsync of payload fragments",
              "SSH identity: /opt/zimbra/.ssh/zimbra_identity"
            ]
          },
          {
            "name": "Remote access agents",
            "slug": "command-and-control-agent",
            "tactic": "command-and-control",
            "techniques": [
              "T1071.001",
              "T1105"
            ],
            "observables": [
              "zimdown2",
              "zimclient2",
              "agent2.sh",
              "openssl s_client",
              "Named pipe: /tmp/s",
              "WebSocket connections"
            ]
          },
          {
            "name": "Mailbox exfiltration attempt",
            "slug": "exfiltration-mailbox-data",
            "tactic": "exfiltration",
            "techniques": [
              "T1567",
              "T1041"
            ],
            "observables": [
              "zimbra-exfil/client-dump",
              "Compressed archive creation",
              "Transfer of collected data"
            ]
          }
        ],
        "summary": "Attackers exploit a command injection vulnerability (CVE-2026-73570) in Zimbra's SNMP notification path to execute commands as the zimbra user. The campaign involves deploying JSP web shells, escalating privileges to root via PAM hooks, stealing service credentials, and moving laterally across the cluster using existing SSH identities."
      },
      "severity": "high",
      "rationale": "Start with internet-facing Zimbra nodes (MTA and Mailbox roles). Focus on systems where the optional zimbra-snmp package is installed, as this is the injection vector for the primary CVE.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An intruder is using Zimbra administrative utilities to dump service credentials and move laterally to peer nodes using the zimbra service account's SSH identity.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "List of Zimbra server hostnames to narrow the search; leave empty to scan all hosts."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570/",
          "name": "Microsoft Blog \u2014 Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570"
        }
      ],
      "blind_spots": [
        {
          "id": "limited-process-visibility",
          "risk": "Attackers can map the cluster from a single node without an agent, making the first stage of the attack invisible.",
          "stage": "discovery-cluster-mapping",
          "question": "whether administrative commands were run on unmanaged nodes",
          "requires": "endpoint agent presence on all nodes"
        },
        {
          "id": "ssh-identity-exfiltration",
          "risk": "If the attacker exfiltrates the SSH identity to an external machine to move laterally from outside, the local process logs will not capture the subsequent connections.",
          "stage": "lateral-movement-ssh-rsync",
          "question": "whether the SSH identity was copied rather than executed",
          "requires": "detailed file-read monitoring of the SSH identity path"
        }
      ]
    },
    "name": "Zimbra secrets theft and cluster propagation",
    "description": "After an initial breach, actors use Zimbra-specific tools like zmprov and zmlocalconfig to identify peer nodes and extract LDAP or replication passwords. This hunt targets the post-compromise stages of a Zimbra mail server intrusion. It focuses on how attackers map the cluster and harvest service credentials. The hunt follows a phased approach. First, it identifies high-risk administrative activity on Zimbra servers. Then, the agent pivots to find evidence of lateral movement via SSH identity reuse and the staging of mailbox data for exfiltration. By correlating these behaviors across the cluster, the analyst distinguishes legitimate administrative work from an active, spreading intrusion."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570",
          "index": 3,
          "title": "Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570",
          "total": 3
        },
        "coverage": [
          {
            "stage": "discovery-cluster-mapping",
            "steps": [
              "discovery-and-mapping"
            ],
            "status": "covered"
          },
          {
            "stage": "credential-access-zimbra-secrets",
            "steps": [
              "secret-collection-activity"
            ],
            "status": "covered"
          },
          {
            "stage": "lateral-movement-ssh-rsync",
            "steps": [
              "lateral-movement-activity"
            ],
            "status": "covered"
          },
          {
            "stage": "command-and-control-agent",
            "steps": [
              "exfiltration-and-c2-activity"
            ],
            "status": "covered"
          },
          {
            "stage": "exfiltration-mailbox-data",
            "steps": [
              "exfiltration-and-c2-activity"
            ],
            "status": "covered"
          },
          {
            "stage": "reconnaissance-and-probing",
            "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "initial-access-cve-2026-73570",
            "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "persistence-jsp-webshells",
            "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "privilege-escalation-pam-hook",
            "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "host-persistence-systemd",
            "reason": "Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An intruder is using Zimbra administrative utilities to dump service credentials and move laterally to peer nodes using the zimbra service account's SSH identity.",
        "blind_spots": [
          {
            "id": "limited-process-visibility",
            "risk": "Attackers can map the cluster from a single node without an agent, making the first stage of the attack invisible.",
            "stage": "discovery-cluster-mapping",
            "question": "whether administrative commands were run on unmanaged nodes",
            "requires": "endpoint agent presence on all nodes"
          },
          {
            "id": "ssh-identity-exfiltration",
            "risk": "If the attacker exfiltrates the SSH identity to an external machine to move laterally from outside, the local process logs will not capture the subsequent connections.",
            "stage": "lateral-movement-ssh-rsync",
            "question": "whether the SSH identity was copied rather than executed",
            "requires": "detailed file-read monitoring of the SSH identity path"
          }
        ],
        "scoping_notes": "Start with internet-facing Zimbra nodes (MTA and Mailbox roles). Focus on systems where the optional zimbra-snmp package is installed, as this is the injection vector for the primary CVE.",
        "beyond_detection": "While a rule can alert on the zimbra user running zmlocalconfig, this hunt pivots from that single indicator to look for the fleet-wide consequences: lateral movement and data staging. By using a baseline for administrative mapping tools, it filters out routine maintenance that simple rules would likely miss or over-alert on."
      }
    },
    {
      "id": "identify-zimbra-hosts",
      "type": "query",
      "label": "Identify Zimbra servers",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_hostname, package_name, package_version, install_path FROM hb_software_inventory WHERE LOWER(package_name) LIKE '%zimbra%'",
        "surface": "hb_software_inventory",
        "description": "Filter the estate to hosts running Zimbra Collaboration Suite to focus behavioral hunting.",
        "expected_signal": "A list of hosts where Zimbra is installed. Silence indicates no Zimbra nodes were found in the current inventory."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify Zimbra servers",
        "reads": [
          "device_hostname",
          "package_name",
          "package_version",
          "install_path"
        ],
        "source": "hb_software_inventory",
        "target": "endpoint",
        "content": "SELECT device_hostname, package_name, package_version, install_path FROM hb_software_inventory WHERE LOWER(package_name) LIKE '%zimbra%'",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hosts where Zimbra is installed. Silence indicates no Zimbra nodes were found in the current inventory.",
        "verified": "dry-run",
        "verified_at": "2026-10-01"
      }
    },
    {
      "id": "discovery-and-mapping",
      "type": "query",
      "label": "Zimbra cluster mapping and reconnaissance",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT LOWER(process_cmd_line) AS cmd, COUNT(DISTINCT device_hostname) AS hosts, COUNT(*) AS executions, MIN(time) AS first_seen FROM hb_process_activity WHERE (LOWER(process_cmd_line) LIKE '%zmprov%' OR LOWER(process_cmd_line) LIKE '%ldapsearch%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1 HAVING hosts <= 3 ORDER BY hosts ASC",
        "surface": "hb_process_activity",
        "description": "Detect the use of cluster-mapping tools like zmprov or broad LDAP searches that reveal node roles.",
        "expected_signal": "Command lines that are rare across the fleet; legitimate admin scripts usually appear on all Zimbra nodes, whereas attacker reconnaissance is localized."
      },
      "parents": [
        {
          "id": "identify-zimbra-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Zimbra cluster mapping and reconnaissance",
        "reads": [
          "device_hostname",
          "process_cmd_line",
          "user_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT LOWER(process_cmd_line) AS cmd, COUNT(DISTINCT device_hostname) AS hosts, COUNT(*) AS executions, MIN(time) AS first_seen FROM hb_process_activity WHERE (LOWER(process_cmd_line) LIKE '%zmprov%' OR LOWER(process_cmd_line) LIKE '%ldapsearch%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1 HAVING hosts <= 3 ORDER BY hosts ASC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Command lines that are rare across the fleet; legitimate admin scripts usually appear on all Zimbra nodes, whereas attacker reconnaissance is localized.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_cmd_line"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-10-01"
      }
    },
    {
      "id": "secret-collection-activity",
      "type": "query",
      "label": "Zimbra service credential dumping",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_cmd_line, user_name, time FROM hb_process_activity WHERE LOWER(process_cmd_line) LIKE '%zmlocalconfig% -s%' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Identify the extraction of service-account credentials using zmlocalconfig, a prerequisite for lateral movement.",
        "expected_signal": "The zimbra user dumping sensitive configuration secrets. This is the primary indicator of credential theft intent."
      },
      "parents": [
        {
          "id": "identify-zimbra-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Zimbra service credential dumping",
        "reads": [
          "device_hostname",
          "process_cmd_line",
          "user_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_cmd_line, user_name, time FROM hb_process_activity WHERE LOWER(process_cmd_line) LIKE '%zmlocalconfig% -s%' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "The zimbra user dumping sensitive configuration secrets. This is the primary indicator of credential theft intent.",
        "verified": "dry-run",
        "verified_at": "2026-10-01"
      }
    },
    {
      "id": "early-triage-agent",
      "type": "analytic",
      "label": "Triage early-stage indicators",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "discovery-and-mapping",
          "secret-collection-activity"
        ],
        "objective": "Identify hosts where rare cluster-mapping commands or credential dumping occurred, distinguishing them from baseline admin activity.",
        "description": "Determine if the observed administrative tool usage suggests a post-compromise discovery phase.",
        "max_iterations": 4,
        "expected_signal": "A per-host verdict on whether the discovery and secret collection is suspicious.",
        "success_criteria": "A verdict citing specific rows that warrant follow-on hunting for lateral movement."
      },
      "parents": [
        {
          "id": "discovery-and-mapping",
          "kind": "merge"
        },
        {
          "id": "secret-collection-activity",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "lateral-movement-activity",
      "type": "query",
      "label": "Lateral movement via SSH and rsync",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_cmd_line, user_name, time FROM hb_process_activity WHERE (LOWER(process_cmd_line) LIKE '%/opt/zimbra/.ssh/zimbra_identity%' OR (LOWER(process_cmd_line) LIKE '%ssh %' AND LOWER(process_cmd_line) LIKE '%batchmode%') OR LOWER(process_cmd_line) LIKE '%rsync %') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Detect the reuse of the zimbra_identity SSH key for automated movement between nodes.",
        "expected_signal": "SSH or rsync processes using the Zimbra batch-mode identity. This indicates propagation from a compromised node to the rest of the cluster."
      },
      "parents": [
        {
          "id": "early-triage-agent"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Lateral movement via SSH and rsync",
        "reads": [
          "device_hostname",
          "process_cmd_line",
          "user_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_cmd_line, user_name, time FROM hb_process_activity WHERE (LOWER(process_cmd_line) LIKE '%/opt/zimbra/.ssh/zimbra_identity%' OR (LOWER(process_cmd_line) LIKE '%ssh %' AND LOWER(process_cmd_line) LIKE '%batchmode%') OR LOWER(process_cmd_line) LIKE '%rsync %') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "SSH or rsync processes using the Zimbra batch-mode identity. This indicates propagation from a compromised node to the rest of the cluster.",
        "verified": "dry-run",
        "verified_at": "2026-10-01"
      }
    },
    {
      "id": "exfiltration-and-c2-activity",
      "type": "query",
      "label": "Exfiltration staging and C2 implants",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "endpoint",
        "content": "SELECT device_hostname, file_path, process_name, time FROM hb_file_activity WHERE (LOWER(file_path) LIKE '%/tmp/s' OR LOWER(file_name) LIKE '%.tar.gz' OR LOWER(file_name) LIKE '%.zip' OR LOWER(file_name) LIKE '%zimdown2%' OR LOWER(file_name) LIKE '%zimclient2%' OR LOWER(file_name) LIKE '%zimbra-exfil%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_file_activity",
        "description": "Identify named pipes, archive files, and known Zimbra-specific exfiltration implants.",
        "expected_signal": "Creation of archives in non-standard paths or the presence of named pipes and implant binaries. Silence confirms the absence of these specific staging artifacts."
      },
      "parents": [
        {
          "id": "early-triage-agent"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Exfiltration staging and C2 implants",
        "reads": [
          "device_hostname",
          "file_path",
          "process_name",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, file_path, process_name, time FROM hb_file_activity WHERE (LOWER(file_path) LIKE '%/tmp/s' OR LOWER(file_name) LIKE '%.tar.gz' OR LOWER(file_name) LIKE '%.zip' OR LOWER(file_name) LIKE '%zimdown2%' OR LOWER(file_name) LIKE '%zimclient2%' OR LOWER(file_name) LIKE '%zimbra-exfil%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Creation of archives in non-standard paths or the presence of named pipes and implant binaries. Silence confirms the absence of these specific staging artifacts.",
        "verified": "dry-run",
        "verified_at": "2026-10-01"
      }
    },
    {
      "id": "follow-on-triage-agent",
      "type": "analytic",
      "label": "Correlate cluster-wide intrusion",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "early-triage-agent",
          "lateral-movement-activity",
          "exfiltration-and-c2-activity"
        ],
        "objective": "Determine if the discovery and secret theft from the first phase is logically connected to the lateral movement or exfiltration staging found in the second phase.",
        "description": "Connect the initial secret theft to the follow-on movement and exfiltration staging.",
        "max_iterations": 6,
        "expected_signal": "A comprehensive verdict showing the full attack chain from a single beachhead across the cluster.",
        "success_criteria": "A final verdict of malicious | suspicious per host, citing the evidence chain."
      },
      "parents": [
        {
          "id": "lateral-movement-activity",
          "kind": "merge"
        },
        {
          "id": "exfiltration-and-c2-activity",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the follow-on-triage-agent verdict is malicious for at least one host",
        "condition": "the follow-on-triage-agent verdict is malicious for at least one host",
        "blind_spot": "limited-process-visibility",
        "confidence": "high",
        "description": "Initiate containment for hosts with confirmed post-compromise activity.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "follow-on-triage-agent"
        }
      ]
    },
    {
      "id": "isolate-compromised-node",
      "type": "action",
      "label": "Isolate Zimbra node",
      "config": {
        "target": "endpoint",
        "description": "Halt the cluster-wide intrusion by isolating affected hosts.",
        "instructions": "Isolate the compromised Zimbra host immediately. Rotate the SSH identity at /opt/zimbra/.ssh/zimbra_identity and change all service passwords found via zmlocalconfig across the entire cluster.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-remediation-review",
      "type": "task",
      "label": "Analyst remediation review",
      "config": {
        "assignee": "analyst",
        "description": "Verify the extent of any mailbox data exfiltration.",
        "instructions": "Review Zimbra mailbox access logs for the service accounts involved. Check for large-scale archive transfers or uncharacteristic outbound network traffic to the remote C2 endpoints identified in the triage."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-compromised-node"
        }
      ]
    },
    {
      "id": "close-out-investigation",
      "type": "task",
      "label": "Close out investigation",
      "config": {
        "assignee": "analyst",
        "description": "Document findings and adjust baselines.",
        "instructions": "Record the hunt outcome. If the activity was legitimate administration, update the prevalence thresholds to exclude the specific script or command pattern observed."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        }
      ]
    }
  ]
}