Zimbra secrets theft and cluster propagation
An intruder is using Zimbra administrative utilities to dump service credentials and move laterally to peer nodes using the zimbra service account's SSH identity.
Based on research by Microsoft 2026-10-01 12 steps · 5 queries T1021.004 T1041 T1071.001 T1083 T1087 T1552 T1555 T1567
Brief
Why now
Microsoft recently published details on CVE-2026-73570 (https://www.microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570/), an unauthenticated command injection vulnerability in internet-facing Zimbra mail servers. This vulnerability allows an attacker to execute commands via the SNMP component. Once they gain access, attackers focus on harvesting credentials and expanding their reach to other parts of the infrastructure. This hunt addresses the post-compromise phase where an adversary maps the cluster and moves laterally.
How the hunt flows
The hunt begins by identifying every host in the environment running the Zimbra Collaboration Suite. The first query searches the software inventory surface for packages containing the name Zimbra. This scoping step is necessary to focus behavioral analysis on the relevant mail servers and avoid processing logs from unrelated systems.
The next phase identifies early evidence of discovery and secret theft. The hunt looks for rare executions of administrative tools like zmprov or ldapsearch. While administrators use these tools for maintenance, they typically do so in a predictable, cluster-wide manner. Attackers use them to map node roles and identify targets for lateral movement. Simultaneously, the hunt monitors for the zmlocalconfig utility being used with the -s flag. This specific command allows an actor to dump sensitive LDAP and replication passwords from the local configuration.
After identifying potential secret theft, the analyst pivots to look for follow-on movement and exfiltration staging. The hunt searches for the reuse of the zimbra_identity SSH key. If an attacker has compromised the main node, they will use this key to access peer nodes. The hunt also tracks rsync operations and SSH processes running in batch mode, which indicate automated movement or data synchronization across the cluster.
The final stage of the flow focuses on exfiltration and persistence staging. The hunt examines file activity for the creation of compressed archives in /tmp or other non-standard directories. It specifically looks for files associated with known Zimbra exfiltration tools, such as zimdown2, zimclient2, or zimbra-exfil. The presence of these files suggests that mailbox data is being staged for removal from the network.
What the hunt cannot see
This hunt cannot identify activity on nodes without an endpoint agent. If an attacker exfiltrates the SSH identity to an external machine and connects back into the environment, the local process logs will not capture those external connection attempts as they originate from outside the managed fleet. Additionally, the hunt does not monitor network-level SSH traffic, only the process execution on the Zimbra nodes.
In this series
Steps
-
Identify Zimbra servers
Query · scopingFilter the estate to hosts running Zimbra Collaboration Suite to focus behavioral hunting.
reads hb_software_inventorysqlSELECT device_hostname, package_name, package_version, install_path FROM hb_software_inventory WHERE LOWER(package_name) LIKE '%zimbra%'What a hit looks like. A list of hosts where Zimbra is installed. Silence indicates no Zimbra nodes were found in the current inventory.
-
Zimbra cluster mapping and reconnaissance
Query · baselineDetect the use of cluster-mapping tools like zmprov or broad LDAP searches that reveal node roles.
reads hb_process_activitysqlSELECT LOWER(process_cmd_line) AS cmd, COUNT(DISTINCT device_hostname) AS hosts, COUNT(*) AS executions, MIN(time) AS first_seen FROM hb_process_activity WHERE (LOWER(process_cmd_line) LIKE '%zmprov%' OR LOWER(process_cmd_line) LIKE '%ldapsearch%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1 HAVING hosts <= 3 ORDER BY hosts ASCWhat a hit looks like. Command lines that are rare across the fleet; legitimate admin scripts usually appear on all Zimbra nodes, whereas attacker reconnaissance is localized.
-
Zimbra service credential dumping
Query · detection candidateIdentify the extraction of service-account credentials using zmlocalconfig, a prerequisite for lateral movement.
reads hb_process_activitysqlSELECT device_hostname, process_cmd_line, user_name, time FROM hb_process_activity WHERE LOWER(process_cmd_line) LIKE '%zmlocalconfig% -s%' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. The zimbra user dumping sensitive configuration secrets. This is the primary indicator of credential theft intent.
-
Triage early-stage indicators
Agent triageDetermine if the observed administrative tool usage suggests a post-compromise discovery phase.
-
Lateral movement via SSH and rsync
Query · enrichmentDetect the reuse of the zimbra_identity SSH key for automated movement between nodes.
reads hb_process_activitysqlSELECT device_hostname, process_cmd_line, user_name, time FROM hb_process_activity WHERE (LOWER(process_cmd_line) LIKE '%/opt/zimbra/.ssh/zimbra_identity%' OR (LOWER(process_cmd_line) LIKE '%ssh %' AND LOWER(process_cmd_line) LIKE '%batchmode%') OR LOWER(process_cmd_line) LIKE '%rsync %') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. SSH or rsync processes using the Zimbra batch-mode identity. This indicates propagation from a compromised node to the rest of the cluster.
-
Exfiltration staging and C2 implants
Query · triageIdentify named pipes, archive files, and known Zimbra-specific exfiltration implants.
reads hb_file_activitysqlSELECT device_hostname, file_path, process_name, time FROM hb_file_activity WHERE (LOWER(file_path) LIKE '%/tmp/s' OR LOWER(file_name) LIKE '%.tar.gz' OR LOWER(file_name) LIKE '%.zip' OR LOWER(file_name) LIKE '%zimdown2%' OR LOWER(file_name) LIKE '%zimclient2%' OR LOWER(file_name) LIKE '%zimbra-exfil%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. Creation of archives in non-standard paths or the presence of named pipes and implant binaries. Silence confirms the absence of these specific staging artifacts.
-
Correlate cluster-wide intrusion
Agent triageConnect the initial secret theft to the follow-on movement and exfiltration staging.
-
Route on verdict
DecisionInitiate containment for hosts with confirmed post-compromise activity.
-
Isolate Zimbra node
Response actionHalt the cluster-wide intrusion by isolating affected hosts.
-
Analyst remediation review
Analyst taskVerify the extent of any mailbox data exfiltration.
-
Close out investigation
Analyst taskDocument findings and adjust baselines.
Coverage
Scenario coverage
| Stage | Covered | How, or why not |
|---|---|---|
| Zimbra cluster mapping T1087 · T1083 |
Yes | discovery-and-mapping |
| Service credential collection T1552 · T1555 |
Yes | secret-collection-activity |
| Lateral movement across nodes T1021.004 |
Yes | lateral-movement-activity |
| Remote access agents T1071.001 · T1105 |
Yes | exfiltration-and-c2-activity |
| Mailbox exfiltration attempt T1567 · T1041 |
Yes | exfiltration-and-c2-activity |
| Pre-exploitation scanning T1595 |
Out of scope | Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series. |
| Zimbra SNMP command injection T1190 |
Out of scope | Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series. |
| JSP web shell deployment T1505.003 |
Out of scope | Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series. |
| PAM hook privilege escalation T1548.003 · T1556 |
Out of scope | Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series. |
| Systemd service persistence T1543.002 |
Out of scope | Belongs to another part of the 'Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570' series. |
Blind spots
- Needs endpoint agent presence on all nodes. Attackers can map the cluster from a single node without an agent, making the first stage of the attack invisible. It would answer whether administrative commands were run on unmanaged nodes.
- Needs detailed file-read monitoring of the SSH identity path. If the attacker exfiltrates the SSH identity to an external machine to move laterally from outside, the local process logs will not capture the subsequent connections. It would answer whether the SSH identity was copied rather than executed.
Parameters & data
Parameters
| Parameter | Type | Default | What it is |
|---|---|---|---|
lookback_days | number | 14 | Days of history to examine. |
scope_hosts | list[host] | — | List of Zimbra server hostnames to narrow the search; leave empty to scan all hosts. |
Telemetry
| Source | Category | Telemetry |
|---|---|---|
| Endpoint telemetry (hb_ surfaces) | endpoint | endpoint |
Source
---
analysis: 'While a rule can alert on the zimbra user running zmlocalconfig, this hunt
pivots from that single indicator to look for the fleet-wide consequences: lateral
movement and data staging. By using a baseline for administrative mapping tools,
it filters out routine maintenance that simple rules would likely miss or over-alert
on.'
blind_spots:
- id: limited-process-visibility
question: whether administrative commands were run on unmanaged nodes
requires: endpoint agent presence on all nodes
risk: Attackers can map the cluster from a single node without an agent, making
the first stage of the attack invisible.
stage: discovery-cluster-mapping
- id: ssh-identity-exfiltration
question: whether the SSH identity was copied rather than executed
requires: detailed file-read monitoring of the SSH identity path
risk: If the attacker exfiltrates the SSH identity to an external machine to move
laterally from outside, the local process logs will not capture the subsequent
connections.
stage: lateral-movement-ssh-rsync
coverage:
- stage: discovery-cluster-mapping
status: covered
steps:
- discovery-and-mapping
- stage: credential-access-zimbra-secrets
status: covered
steps:
- secret-collection-activity
- stage: lateral-movement-ssh-rsync
status: covered
steps:
- lateral-movement-activity
- stage: command-and-control-agent
status: covered
steps:
- exfiltration-and-c2-activity
- stage: exfiltration-mailbox-data
status: covered
steps:
- exfiltration-and-c2-activity
- reason: 'Belongs to another part of the ''Unauthenticated command injection on internet-facing
mail servers: tracking CVE-2026-73570'' series.'
stage: reconnaissance-and-probing
status: out_of_scope
- reason: 'Belongs to another part of the ''Unauthenticated command injection on internet-facing
mail servers: tracking CVE-2026-73570'' series.'
stage: initial-access-cve-2026-73570
status: out_of_scope
- reason: 'Belongs to another part of the ''Unauthenticated command injection on internet-facing
mail servers: tracking CVE-2026-73570'' series.'
stage: persistence-jsp-webshells
status: out_of_scope
- reason: 'Belongs to another part of the ''Unauthenticated command injection on internet-facing
mail servers: tracking CVE-2026-73570'' series.'
stage: privilege-escalation-pam-hook
status: out_of_scope
- reason: 'Belongs to another part of the ''Unauthenticated command injection on internet-facing
mail servers: tracking CVE-2026-73570'' series.'
stage: host-persistence-systemd
status: out_of_scope
guardrails:
claims: no_unsupported
evidence: citation_required
missing_data: not_benign
telemetry: untrusted
hunt:
applicability: campaign-specific
handoff: promote-to-detection
justification: The compromise of service keys on a mail server is a high-impact
event that provides long-term, cluster-wide access; proactive hunting for the
reuse of these keys is required to mitigate the risk of mass mailbox exfiltration.
methodology: model-assisted
trigger: intel-report
hypothesis: An intruder is using Zimbra administrative utilities to dump service credentials
and move laterally to peer nodes using the zimbra service account's SSH identity.
labels:
- hunt
- attack.t1087
- attack.t1083
- attack.t1552
- attack.t1555
- attack.t1021.004
- attack.t1071.001
- attack.t1567
- attack.t1041
- command and control
- credential access
- discovery
- exfiltration
- initial access
- lateral movement
- persistence
- privilege escalation
- reconnaissance
name: Zimbra secrets theft and cluster propagation
parameters:
lookback_days:
default: '14'
description: Days of history to examine.
type: number
scope_hosts:
default: []
description: List of Zimbra server hostnames to narrow the search; leave empty
to scan all hosts.
type: list[host]
provenance:
authors:
- name: Huntbase hunt generation
org: huntbase.io
generated:
by: huntbase-hunt-generation
from: https://www.microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570/
gates:
- dry-run
- lint
model: hb_google/gemini-3-flash-preview
rationale: Start with internet-facing Zimbra nodes (MTA and Mailbox roles). Focus
on systems where the optional zimbra-snmp package is installed, as this is the injection
vector for the primary CVE.
references:
- name: "Microsoft Blog \u2014 Unauthenticated command injection on internet-facing\
\ mail servers: tracking CVE-2026-73570"
url: https://www.microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570/
related:
- hunt: zimbra-persistence-webshells
reason: Persistence via JSP webshells and systemd units is handled in a separate
hunt focused on the post-exploitation survival phase.
relation: out-of-scope-alternative
- hunt: zimbra-privesc-pam-systemd
relation: follows
scenario:
stages:
- name: Pre-exploitation scanning
observables:
- 'User-Agent: ZB73570'
- oast.fun
- oast.online
- dnslog.pp.ua
- requestrepo.com
- bypass.eu.org
- 'Commands: curl, wget, ping, nslookup, id'
slug: reconnaissance-and-probing
tactic: reconnaissance
techniques:
- T1595
- name: Zimbra SNMP command injection
observables:
- CVE-2026-73570
- swatchdog
- snmptrap
slug: initial-access-cve-2026-73570
tactic: initial-access
techniques:
- T1190
- name: JSP web shell deployment
observables:
- Jetty and mailboxd application paths
- JSP files
- Payload reconstruction from staged fragments
- chmod on webroot directories
slug: persistence-jsp-webshells
tactic: persistence
techniques:
- T1505.003
- name: Zimbra cluster mapping
observables:
- zmprov
- /opt/zimbra/.ssh/zimbra_identity
slug: discovery-cluster-mapping
tactic: discovery
techniques:
- T1087
- T1083
- name: PAM hook privilege escalation
observables:
- 'Symlink: zmmailboxd.out -> /etc/pam.d/sudo'
- zmmailboxdmgr
- zmstat-fd
- pam_exec session hook
- 'NOPASSWD: ALL in sudoers'
slug: privilege-escalation-pam-hook
tactic: privilege-escalation
techniques:
- T1548.003
- T1556
- name: Systemd service persistence
observables:
- /etc/systemd/system/zimlog.service
- Timestomping to match rsync.service or sshd.service
- systemctl enable zimlog.service
slug: host-persistence-systemd
tactic: persistence
techniques:
- T1543.002
- name: Service credential collection
observables:
- zmlocalconfig -s
- ldapsearch
- zimbraPreAuthKey
- zimbraAuthTokenKey
- zimbraTwoFactorAuthSecret
slug: credential-access-zimbra-secrets
tactic: credential-access
techniques:
- T1552
- T1555
- name: Lateral movement across nodes
observables:
- ssh -o BatchMode=yes
- rsync of payload fragments
- 'SSH identity: /opt/zimbra/.ssh/zimbra_identity'
slug: lateral-movement-ssh-rsync
tactic: lateral-movement
techniques:
- T1021.004
- name: Remote access agents
observables:
- zimdown2
- zimclient2
- agent2.sh
- openssl s_client
- 'Named pipe: /tmp/s'
- WebSocket connections
slug: command-and-control-agent
tactic: command-and-control
techniques:
- T1071.001
- T1105
- name: Mailbox exfiltration attempt
observables:
- zimbra-exfil/client-dump
- Compressed archive creation
- Transfer of collected data
slug: exfiltration-mailbox-data
tactic: exfiltration
techniques:
- T1567
- T1041
summary: Attackers exploit a command injection vulnerability (CVE-2026-73570) in
Zimbra's SNMP notification path to execute commands as the zimbra user. The campaign
involves deploying JSP web shells, escalating privileges to root via PAM hooks,
stealing service credentials, and moving laterally across the cluster using existing
SSH identities.
series:
index: 3
slug: unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570
title: 'Unauthenticated command injection on internet-facing mail servers: tracking
CVE-2026-73570'
total: 3
severity: high
targets:
analyst:
name: Tier-2 analyst
role: analyst
endpoint:
category: endpoint
name: Endpoint telemetry (hb_ surfaces)
telemetry:
- endpoint
hunter:
agent: true
name: Hunt agent
tlp: clear
type: investigation
---
# Zimbra secrets theft and cluster propagation
After an initial breach, actors use Zimbra-specific tools like zmprov and zmlocalconfig to identify peer nodes and extract LDAP or replication passwords. This hunt targets the post-compromise stages of a Zimbra mail server intrusion. It focuses on how attackers map the cluster and harvest service credentials. The hunt follows a phased approach. First, it identifies high-risk administrative activity on Zimbra servers. Then, the agent pivots to find evidence of lateral movement via SSH identity reuse and the staging of mailbox data for exfiltration. By correlating these behaviors across the cluster, the analyst distinguishes legitimate administrative work from an active, spreading intrusion.
## identify-zimbra-hosts
<!-- Identify Zimbra servers -->
Filter the estate to hosts running Zimbra Collaboration Suite to focus behavioral hunting.
```sqlite target=endpoint role=scoping
~~~yaml
expected: A list of hosts where Zimbra is installed. Silence indicates no Zimbra nodes
were found in the current inventory.
reads:
- device_hostname
- package_name
- package_version
- install_path
silence: not_evidence_of_absence
source: hb_software_inventory
verified: dry-run
verified_at: '2026-10-01'
~~~
SELECT device_hostname, package_name, package_version, install_path FROM hb_software_inventory WHERE LOWER(package_name) LIKE '%zimbra%'
```
## parallel-early-evidence
<!-- Search for early discovery and secret theft -->
parallel:
- → discovery-and-mapping
- → secret-collection-activity
join: → early-triage-agent
## discovery-and-mapping
<!-- Zimbra cluster mapping and reconnaissance -->
Detect the use of cluster-mapping tools like zmprov or broad LDAP searches that reveal node roles.
```sqlite target=endpoint role=baseline params=(scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
baseline:
compare: first_seen
window: '{{lookback_days}}d'
expected: Command lines that are rare across the fleet; legitimate admin scripts usually
appear on all Zimbra nodes, whereas attacker reconnaissance is localized.
prevalence:
by: device_hostname
key:
- process_cmd_line
rare_below: 3
reads:
- device_hostname
- process_cmd_line
- user_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-10-01'
~~~
SELECT LOWER(process_cmd_line) AS cmd, COUNT(DISTINCT device_hostname) AS hosts, COUNT(*) AS executions, MIN(time) AS first_seen FROM hb_process_activity WHERE (LOWER(process_cmd_line) LIKE '%zmprov%' OR LOWER(process_cmd_line) LIKE '%ldapsearch%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1 HAVING hosts <= 3 ORDER BY hosts ASC
```
## secret-collection-activity
<!-- Zimbra service credential dumping -->
Identify the extraction of service-account credentials using zmlocalconfig, a prerequisite for lateral movement.
```sqlite target=endpoint role=detection-candidate params=(scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: The zimbra user dumping sensitive configuration secrets. This is the primary
indicator of credential theft intent.
reads:
- device_hostname
- process_cmd_line
- user_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-10-01'
~~~
SELECT device_hostname, process_cmd_line, user_name, time FROM hb_process_activity WHERE LOWER(process_cmd_line) LIKE '%zmlocalconfig% -s%' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```
## early-triage-agent
<!-- Triage early-stage indicators -->
```agent target=hunter
cite: required
context:
- discovery-and-mapping
- secret-collection-activity
max_iterations: 4
objective: Identify hosts where rare cluster-mapping commands or credential dumping
occurred, distinguishing them from baseline admin activity.
success_criteria: A verdict citing specific rows that warrant follow-on hunting for
lateral movement.
tools:
- endpoint
```
## parallel-follow-on-evidence
<!-- Hunt for follow-on movement and exfiltration -->
parallel:
- → lateral-movement-activity
- → exfiltration-and-c2-activity
join: → follow-on-triage-agent
## lateral-movement-activity
<!-- Lateral movement via SSH and rsync -->
Detect the reuse of the zimbra_identity SSH key for automated movement between nodes.
```sqlite target=endpoint role=enrichment params=(scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: SSH or rsync processes using the Zimbra batch-mode identity. This indicates
propagation from a compromised node to the rest of the cluster.
reads:
- device_hostname
- process_cmd_line
- user_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-10-01'
~~~
SELECT device_hostname, process_cmd_line, user_name, time FROM hb_process_activity WHERE (LOWER(process_cmd_line) LIKE '%/opt/zimbra/.ssh/zimbra_identity%' OR (LOWER(process_cmd_line) LIKE '%ssh %' AND LOWER(process_cmd_line) LIKE '%batchmode%') OR LOWER(process_cmd_line) LIKE '%rsync %') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```
## exfiltration-and-c2-activity
<!-- Exfiltration staging and C2 implants -->
Identify named pipes, archive files, and known Zimbra-specific exfiltration implants.
```sqlite target=endpoint role=triage params=(scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: Creation of archives in non-standard paths or the presence of named pipes
and implant binaries. Silence confirms the absence of these specific staging artifacts.
reads:
- device_hostname
- file_path
- process_name
- time
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-10-01'
~~~
SELECT device_hostname, file_path, process_name, time FROM hb_file_activity WHERE (LOWER(file_path) LIKE '%/tmp/s' OR LOWER(file_name) LIKE '%.tar.gz' OR LOWER(file_name) LIKE '%.zip' OR LOWER(file_name) LIKE '%zimdown2%' OR LOWER(file_name) LIKE '%zimclient2%' OR LOWER(file_name) LIKE '%zimbra-exfil%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```
## follow-on-triage-agent
<!-- Correlate cluster-wide intrusion -->
```agent target=hunter
cite: required
context:
- early-triage-agent
- lateral-movement-activity
- exfiltration-and-c2-activity
max_iterations: 6
objective: Determine if the discovery and secret theft from the first phase is logically
connected to the lateral movement or exfiltration staging found in the second phase.
success_criteria: A final verdict of malicious | suspicious per host, citing the evidence
chain.
tools:
- endpoint
```
## route-on-verdict
<!-- Route on verdict -->
if~: "the follow-on-triage-agent verdict is malicious for at least one host" (confidence: high, judge=hunter)
then: → isolate-compromised-node
indeterminate: → analyst-remediation-review
unavailable: → analyst-remediation-review (blind_spot: limited-process-visibility)
else: → close-out-investigation
## isolate-compromised-node
<!-- Isolate Zimbra node -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the compromised Zimbra host immediately. Rotate the SSH identity at /opt/zimbra/.ssh/zimbra_identity and change all service passwords found via zmlocalconfig across the entire cluster.
```
→ analyst-remediation-review
## analyst-remediation-review
<!-- Analyst remediation review -->
```manual target=analyst
Review Zimbra mailbox access logs for the service accounts involved. Check for large-scale archive transfers or uncharacteristic outbound network traffic to the remote C2 endpoints identified in the triage.
```
→ end
## close-out-investigation
<!-- Close out investigation -->
```manual target=analyst
Record the hunt outcome. If the activity was legitimate administration, update the prevalence thresholds to exclude the specific script or command pattern observed.
```
→ end
Run it
Take this hunt into your environment.
Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.
Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.