Threat hunts for Check Point
3 hunts covering Check Point, each with a hypothesis, the queries that test it and what the hunt cannot see.
3 hunts
-
high Part 2 of 2Research by Rapid7
Metasploit Lateral Movement and Native Persistence
An intruder uses Metasploit to move laterally via WinRM and SMB and maintains persistence through direct process creation from user-writable paths to evade shell-based detection.
3 query2 analytic2 checkpoint1 action2 taskCVE-2026-0265 · CVE-2026-16232 -
high Part 1 of 2Research by Rapid7
Metasploit 2026: External Recon and Web Exploitation
An adversary is using recently released Metasploit scanner and exploit modules to fingerprint organization SCADA infrastructure or exploit unauthenticated vulnerabilities in public-facing web applications.
3 query1 analytic1 checkpoint1 action2 taskCVE-2026-0265 · CVE-2026-16232 -
highResearch by Sekoia
Gamaredon Modular Espionage Chain
An intruder has exploited a Windows WinRAR path traversal vulnerability to execute HTA-based loaders, subsequently deploying VBScript stagers, an ADS-resident worm, and a modular PowerShell stealer persisting in the registry.
5 query2 analytic1 checkpoint1 action2 taskCVE-2025-8088