Huntbase Hub

Threat hunts from this week's research.

Each hunt turns a piece of public threat research into something you can run: a hypothesis, the queries that test it, what a hit looks like, and what the hunt cannot see.

Want to run them against your own data? Sign up to Huntbase, free →

149 of 149 hunts

  1. medium
    Research by Red Canary

    Correlating Proxy-Obscured Identity and Endpoint Activity

    An adversary is using multi-hop proxy infrastructure to authenticate via Okta and subsequently execute discovery commands on an endpoint, obscured by network egress to proxy relay ports.

    5 query2 analytic1 checkpoint1 action2 task
    T1059 · T1078 · T1090.003
  2. medium
    Research by Elastic Security Labs

    Rapid Identity Breakout and Exfiltration

    An adversary uses a compromised privileged identity to exfiltrate data via a multi-hop proxy or tunnel within 30 minutes of initial access, moving faster than traditional telemetry export batches.

    3 query2 analytic2 checkpoint1 action2 task
    T1041 · T1078 · T1090.003
  3. medium
    Research by Elastic Security Labs

    Endpoint-to-Cloud Phased Intrusion Hunt

    An adversary establishes a beachhead on an endpoint, moves laterally to obtain administrative access, and pivots to cloud services while maintaining C2 via a multi-hop proxy.

    5 query2 analytic1 checkpoint1 action2 task
    T1021 · T1078 · T1090.003 · T1204
  4. medium
    Research by Elastic Security Labs

    Multi-hop Proxy and Tor Infrastructure Activity

    An adversary is masking command-and-control traffic by routing it through multi-hop proxies, Tor entry nodes, or tunneling services to bypass perimeter monitoring.

    3 query1 analytic1 checkpoint1 action2 task
    T1090.003
  5. medium
    Research by Elastic Security Labs

    Multi-hop proxy and tunnel triage via identity context

    An intruder is using a multi-hop proxy or tunneling service to obfuscate C2 traffic, which can be distinguished from legitimate researcher activity by correlating network leads with user risk profiles and local port bindings.

    4 query1 analytic1 checkpoint1 action2 task
    T1090.003
  6. medium
    Research by Microsoft

    Managed Access and Tenant Integrity

    An adversary has established persistence via cross-tenant delegated administration or unattended remote support, subsequently deploying autonomous agents that communicate through multi-hop proxies.

    5 query2 analytic1 checkpoint1 action2 task
    T1059 · T1078.004 · T1090.003 · T1219
  7. medium
    Research by Microsoft

    Network Proxy and Relay Obfuscation Detection

    An adversary is using multi-hop proxies or Operational Relay Box (ORB) networks to disguise command-and-control traffic, which can be identified by shell processes making outbound connections to rare external IP addresses and resolving proxy-related DNS infrastructure.

    3 query1 analytic1 checkpoint1 action2 task
    T1090.003
  8. medium
    Research by Elastic Security Labs

    Vulnerable Driver Exploitation and Kernel Escalation

    An adversary has exploited a public-facing application to stage and load a vulnerable kernel driver, bypassing security controls to gain persistent high-integrity access to the host.

    4 query2 analytic2 checkpoint1 action2 task
    T1068 · T1105 · T1190
  9. medium Part 2 of 2
    Research by Microsoft

    Cloud Workload Identity and Network Triage

    An adversary uses over-permissioned cloud identities to compromise container workloads, establishing persistence through rare outbound network channels that bypass standard scanning.

    3 query1 analytic1 checkpoint1 action2 task
    T1071.001 · T1078.004 · T1190
  10. medium Part 1 of 2
    Research by Microsoft

    Cloud Workload Runtime and Exploitation Behavior

    An adversary has exploited a public-facing containerized application and is maintaining persistence through binary drift or suspicious shell execution within the workload runtime.

    3 query2 analytic2 checkpoint1 action3 task
    T1059 · T1190 · T1542
  11. medium
    Research by Microsoft

    Edge AI Artifact Integrity and Data Exfiltration

    An adversary has compromised the Edge AI supply chain to poison model artifacts, then manipulated those models via prompt injection to exfiltrate sensitive weights and credentials over high-volume network channels.

    5 query2 analytic1 checkpoint1 action2 task
    T1041 · T1090.003 · T1195 · T1204.002
  12. high Part 2 of 2
    Research by Unit 42

    Appliance Persistence and Identity Abuse

    An adversary has modified appliance scheduled tasks to disable MFA and is exfiltrating credentials via native Slack webhook integrations.

    3 query1 analytic1 checkpoint1 action2 task
    T1556 · T1566 · T1684.001
  13. high Part 1 of 2
    Research by Unit 42

    Collaboration Platform Phishing and Execution

    An intruder has compromised an enterprise identity using collaboration tools to bypass email-based controls and execute malicious code via sideloading or malicious dependencies.

    4 query2 analytic2 checkpoint1 action2 task
    T1566 · T1684.001
  14. high Part 1 of 2
    Research by Unit 42

    Build-Time Execution and Secret Harvesting

    An attacker has compromised a software dependency to execute malicious code during the build phase, subsequently harvesting cloud and developer credentials from the environment's configuration files.

    3 query1 analytic1 checkpoint2 task
    T1003 · T1059.003 · T1059.007 · T1105
  15. high
    Research by Elastic Security Labs

    AWS Cloud Identity Takeover Chain

    An adversary has gained initial access to a cloud account by brute-forcing the console and performing a password reset, then used that access to establish a presence across multiple projects in the organization.

    5 query2 analytic1 checkpoint1 action2 task
    T1078.004 · T1098 · T1110.001
  16. medium Part 2 of 2
    Research by Unit 42

    Endpoint Data Staging and Exfiltration

    An adversary has staged sensitive information in temporary directories and is exfiltrating that data via rare outbound network connections or DNS lookups.

    3 query1 analytic1 checkpoint1 action2 task
    T1041 · T1071.001 · T1074.001
  17. medium Part 1 of 2
    Research by Unit 42

    Identity and Cloud Pivot from Web Exploits

    An adversary has exploited an internet-facing web server to establish a beachhead and is now manipulating cloud or SaaS identities to persist and reconfigure the environment.

    3 query2 analytic2 checkpoint1 action2 task
    T1078 · T1098 · T1190
  18. high
    Research by Elastic Security Labs

    Linux Fileless and In-Memory Execution

    An adversary is executing malicious code on Linux hosts by staging payloads in memory-backed file descriptors, using interpreter one-liners, or running unlinked binaries to avoid on-disk detection.

    5 query2 analytic1 checkpoint1 action2 task
    T1014 · T1059.004 · T1059.006 · T1070.004
  19. high
    Research by Elastic Security Labs

    Kubernetes Service Account Abuse and Escape

    An intruder has harvested a service account token from a compromised pod and is using it to deploy a privileged pod for container escape, bypassing standard runtime process detection.

    4 query2 analytic1 checkpoint1 action2 task
    T1552.006 · T1609 · T1610 · T1611
  20. high
    Research by Microsoft

    AI-Themed Social Engineering and Multi-Stage Fraud

    An adversary is using lookalike AI domains and installers to trick users into downloading stealers or performing device-code authentication, leading to token theft and financial fraud.

    5 query2 analytic1 checkpoint1 action2 task
    T1190 · T1486 · T1555 · T1566
  21. medium
    Research by Datadog Security Labs

    Linux eBPF Rootkit Execution and Manipulation

    An intruder has deployed an eBPF rootkit that hides network connections and kernel objects by manipulating syscall returns and tampering with Netlink buffers.

    5 query2 analytic1 checkpoint1 action2 task
    T1014 · T1090.003 · T1204.002 · T1562.001
  22. high
    Research by Huntress

    AD RMS Discovery and Administrative Reconnaissance

    An adversary is identifying on-premises AD RMS clusters via DNS and rights-policy template enumeration before escalating privileges via local group membership to reach the administrative surface.

    5 query2 analytic1 checkpoint1 action2 task
    T1018 · T1078.002 · T1083 · T1090.003
  23. medium
    Research by Elastic Security Labs

    Multi-Stage Intrusion and Ransomware Triage

    An adversary has established a beachhead, moved laterally to host-314, exfiltrated data via Node.js to an AI service, and initiated ransomware encryption.

    3 query1 analytic1 checkpoint1 action2 task
    T1003 · T1021 · T1041 · T1486
  24. high
    Research by Unit 42

    Commodity Loader and Multi-Payload PPI Activity

    An intruder is using trojanised installers to deploy a multi-stage loader that beacons to rotational C2 domains and installs follow-on backdoors like Insomnia RAT and ARKTunnel.

    5 query2 analytic1 checkpoint1 action2 task
    T1059.003 · T1071.001 · T1090.003 · T1190