Huntbase Hub
Threat hunts from this week's research.
Each hunt turns a piece of public threat research into something you can run: a hypothesis, the queries that test it, what a hit looks like, and what the hunt cannot see.
Want to run them against your own data? Sign up to Huntbase, free →
149 of 149 hunts
-
mediumResearch by Red Canary
Correlating Proxy-Obscured Identity and Endpoint Activity
An adversary is using multi-hop proxy infrastructure to authenticate via Okta and subsequently execute discovery commands on an endpoint, obscured by network egress to proxy relay ports.
5 query2 analytic1 checkpoint1 action2 taskT1059 · T1078 · T1090.003 -
mediumResearch by Elastic Security Labs
Rapid Identity Breakout and Exfiltration
An adversary uses a compromised privileged identity to exfiltrate data via a multi-hop proxy or tunnel within 30 minutes of initial access, moving faster than traditional telemetry export batches.
3 query2 analytic2 checkpoint1 action2 taskT1041 · T1078 · T1090.003 -
mediumResearch by Elastic Security Labs
Endpoint-to-Cloud Phased Intrusion Hunt
An adversary establishes a beachhead on an endpoint, moves laterally to obtain administrative access, and pivots to cloud services while maintaining C2 via a multi-hop proxy.
5 query2 analytic1 checkpoint1 action2 taskT1021 · T1078 · T1090.003 · T1204 -
mediumResearch by Elastic Security Labs
Multi-hop Proxy and Tor Infrastructure Activity
An adversary is masking command-and-control traffic by routing it through multi-hop proxies, Tor entry nodes, or tunneling services to bypass perimeter monitoring.
3 query1 analytic1 checkpoint1 action2 taskT1090.003 -
mediumResearch by Elastic Security Labs
Multi-hop proxy and tunnel triage via identity context
An intruder is using a multi-hop proxy or tunneling service to obfuscate C2 traffic, which can be distinguished from legitimate researcher activity by correlating network leads with user risk profiles and local port bindings.
4 query1 analytic1 checkpoint1 action2 taskT1090.003 -
mediumResearch by Microsoft
Managed Access and Tenant Integrity
An adversary has established persistence via cross-tenant delegated administration or unattended remote support, subsequently deploying autonomous agents that communicate through multi-hop proxies.
5 query2 analytic1 checkpoint1 action2 taskT1059 · T1078.004 · T1090.003 · T1219 -
mediumResearch by Microsoft
Network Proxy and Relay Obfuscation Detection
An adversary is using multi-hop proxies or Operational Relay Box (ORB) networks to disguise command-and-control traffic, which can be identified by shell processes making outbound connections to rare external IP addresses and resolving proxy-related DNS infrastructure.
3 query1 analytic1 checkpoint1 action2 taskT1090.003 -
mediumResearch by Elastic Security Labs
Vulnerable Driver Exploitation and Kernel Escalation
An adversary has exploited a public-facing application to stage and load a vulnerable kernel driver, bypassing security controls to gain persistent high-integrity access to the host.
4 query2 analytic2 checkpoint1 action2 taskT1068 · T1105 · T1190 -
medium Part 2 of 2Research by Microsoft
Cloud Workload Identity and Network Triage
An adversary uses over-permissioned cloud identities to compromise container workloads, establishing persistence through rare outbound network channels that bypass standard scanning.
3 query1 analytic1 checkpoint1 action2 taskT1071.001 · T1078.004 · T1190 -
medium Part 1 of 2Research by Microsoft
Cloud Workload Runtime and Exploitation Behavior
An adversary has exploited a public-facing containerized application and is maintaining persistence through binary drift or suspicious shell execution within the workload runtime.
3 query2 analytic2 checkpoint1 action3 taskT1059 · T1190 · T1542 -
mediumResearch by Microsoft
Edge AI Artifact Integrity and Data Exfiltration
An adversary has compromised the Edge AI supply chain to poison model artifacts, then manipulated those models via prompt injection to exfiltrate sensitive weights and credentials over high-volume network channels.
5 query2 analytic1 checkpoint1 action2 taskT1041 · T1090.003 · T1195 · T1204.002 -
high Part 2 of 2Research by Unit 42
Appliance Persistence and Identity Abuse
An adversary has modified appliance scheduled tasks to disable MFA and is exfiltrating credentials via native Slack webhook integrations.
3 query1 analytic1 checkpoint1 action2 taskT1556 · T1566 · T1684.001 -
high Part 1 of 2Research by Unit 42
Collaboration Platform Phishing and Execution
An intruder has compromised an enterprise identity using collaboration tools to bypass email-based controls and execute malicious code via sideloading or malicious dependencies.
4 query2 analytic2 checkpoint1 action2 taskT1566 · T1684.001 -
high Part 1 of 2Research by Unit 42
Build-Time Execution and Secret Harvesting
An attacker has compromised a software dependency to execute malicious code during the build phase, subsequently harvesting cloud and developer credentials from the environment's configuration files.
3 query1 analytic1 checkpoint2 taskT1003 · T1059.003 · T1059.007 · T1105 -
highResearch by Elastic Security Labs
AWS Cloud Identity Takeover Chain
An adversary has gained initial access to a cloud account by brute-forcing the console and performing a password reset, then used that access to establish a presence across multiple projects in the organization.
5 query2 analytic1 checkpoint1 action2 taskT1078.004 · T1098 · T1110.001 -
medium Part 2 of 2Research by Unit 42
Endpoint Data Staging and Exfiltration
An adversary has staged sensitive information in temporary directories and is exfiltrating that data via rare outbound network connections or DNS lookups.
3 query1 analytic1 checkpoint1 action2 taskT1041 · T1071.001 · T1074.001 -
medium Part 1 of 2Research by Unit 42
Identity and Cloud Pivot from Web Exploits
An adversary has exploited an internet-facing web server to establish a beachhead and is now manipulating cloud or SaaS identities to persist and reconfigure the environment.
3 query2 analytic2 checkpoint1 action2 taskT1078 · T1098 · T1190 -
highResearch by Elastic Security Labs
Linux Fileless and In-Memory Execution
An adversary is executing malicious code on Linux hosts by staging payloads in memory-backed file descriptors, using interpreter one-liners, or running unlinked binaries to avoid on-disk detection.
5 query2 analytic1 checkpoint1 action2 taskT1014 · T1059.004 · T1059.006 · T1070.004 -
highResearch by Elastic Security Labs
Kubernetes Service Account Abuse and Escape
An intruder has harvested a service account token from a compromised pod and is using it to deploy a privileged pod for container escape, bypassing standard runtime process detection.
4 query2 analytic1 checkpoint1 action2 taskT1552.006 · T1609 · T1610 · T1611 -
highResearch by Microsoft
AI-Themed Social Engineering and Multi-Stage Fraud
An adversary is using lookalike AI domains and installers to trick users into downloading stealers or performing device-code authentication, leading to token theft and financial fraud.
5 query2 analytic1 checkpoint1 action2 taskT1190 · T1486 · T1555 · T1566 -
mediumResearch by Datadog Security Labs
Linux eBPF Rootkit Execution and Manipulation
An intruder has deployed an eBPF rootkit that hides network connections and kernel objects by manipulating syscall returns and tampering with Netlink buffers.
5 query2 analytic1 checkpoint1 action2 taskT1014 · T1090.003 · T1204.002 · T1562.001 -
highResearch by Huntress
AD RMS Discovery and Administrative Reconnaissance
An adversary is identifying on-premises AD RMS clusters via DNS and rights-policy template enumeration before escalating privileges via local group membership to reach the administrative surface.
5 query2 analytic1 checkpoint1 action2 taskT1018 · T1078.002 · T1083 · T1090.003 -
mediumResearch by Elastic Security Labs
Multi-Stage Intrusion and Ransomware Triage
An adversary has established a beachhead, moved laterally to host-314, exfiltrated data via Node.js to an AI service, and initiated ransomware encryption.
3 query1 analytic1 checkpoint1 action2 taskT1003 · T1021 · T1041 · T1486 -
highResearch by Unit 42
Commodity Loader and Multi-Payload PPI Activity
An intruder is using trojanised installers to deploy a multi-stage loader that beacons to rotational C2 domains and installs follow-on backdoors like Insomnia RAT and ARKTunnel.
5 query2 analytic1 checkpoint1 action2 taskT1059.003 · T1071.001 · T1090.003 · T1190
No hunts match those filters.