Huntbase Hub · All hunts

Threat hunts for Palo Alto Networks

24 hunts covering Palo Alto Networks, each with a hypothesis, the queries that test it and what the hunt cannot see.

24 hunts

  1. high
    Research by Unit 42

    Kubernetes Operator RBAC Abuse and Secret Theft

    A vulnerable or outdated Kubernetes operator is running with excessive ClusterRole permissions, allowing an attacker to exfiltrate cluster-wide secrets or establish unauthorized AI agent bridges to external endpoints.

    3 query1 analytic1 checkpoint2 task
    CVE-2026-6389
  2. high Part 2 of 2
    Research by Rapid7

    Metasploit Lateral Movement and Native Persistence

    An intruder uses Metasploit to move laterally via WinRM and SMB and maintains persistence through direct process creation from user-writable paths to evade shell-based detection.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2026-0265 · CVE-2026-16232
  3. high Part 1 of 2
    Research by Rapid7

    Metasploit 2026: External Recon and Web Exploitation

    An adversary is using recently released Metasploit scanner and exploit modules to fingerprint organization SCADA infrastructure or exploit unauthenticated vulnerabilities in public-facing web applications.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-0265 · CVE-2026-16232
  4. high
    Research by Sekoia

    Gamaredon Modular Espionage Chain

    An intruder has exploited a Windows WinRAR path traversal vulnerability to execute HTA-based loaders, subsequently deploying VBScript stagers, an ADS-resident worm, and a modular PowerShell stealer persisting in the registry.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2025-8088
  5. medium
    Research by Elastic Security Labs

    Rapid Identity Breakout and Exfiltration

    An adversary uses a compromised privileged identity to exfiltrate data via a multi-hop proxy or tunnel within 30 minutes of initial access, moving faster than traditional telemetry export batches.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · exfiltration · initial access
  6. medium
    Research by Microsoft

    Managed Access and Tenant Integrity

    An adversary has established persistence via cross-tenant delegated administration or unattended remote support, subsequently deploying autonomous agents that communicate through multi-hop proxies.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · execution · persistence
  7. high Part 2 of 2
    Research by Unit 42

    Appliance Persistence and Identity Abuse

    An adversary has modified appliance scheduled tasks to disable MFA and is exfiltrating credentials via native Slack webhook integrations.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion · execution · exfiltration
  8. high Part 1 of 2
    Research by Unit 42

    Collaboration Platform Phishing and Execution

    An intruder has compromised an enterprise identity using collaboration tools to bypass email-based controls and execute malicious code via sideloading or malicious dependencies.

    4 query2 analytic2 checkpoint1 action2 task
    defense evasion · execution · exfiltration
  9. high
    Research by Unit 42

    Commodity Loader and Multi-Payload PPI Activity

    An intruder is using trojanised installers to deploy a multi-stage loader that beacons to rotational C2 domains and installs follow-on backdoors like Insomnia RAT and ARKTunnel.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · execution · initial access
  10. high
    Research by Unit 42

    SPIFFE/SPIRE Workload Identity Spoofing

    An attacker with root access on a Kubernetes node is spoofing cgroup metadata to trick the SPIRE agent into issuing identities belonging to co-located workloads for unauthorized service impersonation.

    4 query2 analytic1 checkpoint1 action3 task
    command and control · credential access · defense evasion
  11. medium Part 2 of 2
    Research by Unit 42

    Anomalous Cloud Identity Behavior

    An adversary has compromised an administrative cloud identity and is accessing the environment through multi-hop proxies or Tor to perform discovery and initial access.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · discovery · execution
  12. medium Part 1 of 2
    Research by Unit 42

    Public app exploitation and cloud identity drift

    An adversary has exploited a public-facing application on a cloud instance to obtain its identity, which is now being used for activity that deviates from the host's established behavioral profile.

    5 query1 analytic1 checkpoint1 action2 task
    command and control · discovery · execution
  13. high Part 2 of 2
    Research by Unit 42

    ChainDrop Worm: Developer Tooling Persistence and Supply Chain Propagation

    An adversary has compromised developer environments by injecting malicious hooks into IDE configuration files, using automated GitHub workflows to propagate an npm worm and resolve C2 via Ethereum smart contracts.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  14. high Part 1 of 2
    Research by Unit 42

    ChainDrop: NPM Worm Endpoint and CI Runner Activity

    An intruder has infected an npm package and triggered a preinstall hook that uses the Bun runtime to harvest credentials from the filesystem and CI runner process memory.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  15. high Part 2 of 2
    Research by Unit 42

    Kimwolf Blockchain C2 and DDoS Impact

    IoT or Android devices in the environment are infected with Kimwolf v7, as indicated by a local proxy listener on port 23075 and Ethereum Name Service (ENS) resolution used to bypass traditional C2 infrastructure takedowns.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · execution
  16. high Part 1 of 2
    Research by Unit 42

    Kimwolf ADB Propagation and Evasion

    An intruder exploits unauthenticated ADB services on port 5555 to drop ELF binaries and masquerades as the netd_service system process to avoid detection on Android IoT devices.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · defense evasion · execution
  17. high Part 2 of 2
    Research by Unit 42

    Spring Ring: NTLM Relay and RAT C2

    An attacker has deployed a custom Python environment to facilitate NTLM relay attacks and a PowerShell-based RAT that beacons to external command-and-control infrastructure.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · discovery
  18. high Part 1 of 2
    Research by Unit 42

    Microsoft Teams Vishing and Malicious Payload Execution

    An adversary is using external Microsoft Teams accounts to masquerade as IT support and coerce employees into executing RMM tools or custom payloads that perform discovery and persistence.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · defense evasion · discovery
  19. high Part 2 of 2
    Research by Unit 42

    AMOS Stealer C2 and Exfiltration Patterns

    An adversary exfiltrates keychain, browser, and wallet data from macOS hosts by sending a sequence of HTTP POST requests containing specific stage parameters to malicious infrastructure.

    3 query1 analytic1 checkpoint1 action2 task
    collection · command and control · execution
  20. high Part 1 of 2
    Research by Unit 42

    Atomic macOS (AMOS) Stealer Activity

    An adversary has compromised a macOS host using deceptive Terminal setup commands to execute encoded shell scripts, establishing hidden persistence in Application Support and staging harvested data in temporary directories.

    5 query2 analytic1 checkpoint1 action2 task
    collection · command and control · execution
  21. high
    Research by Unit 42

    D2IP Malware and Obfuscated HTTP Exfiltration

    An adversary is using hard-coded IP addresses and malformed HTTP protocols to bypass DNS-based security controls, exfiltrate data, and proxy credential theft in real-time.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  22. high Part 2 of 2
    Research by Unit 42

    Aeternum Decentralized C2 and Telegram Exfiltration

    An intruder is using public blockchain RPC endpoints to retrieve C2 instructions and the Telegram Bot API to exfiltrate system reconnaissance data, evading traditional domain-based filtering.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · execution · exfiltration
  23. high Part 1 of 2
    Research by Unit 42

    Aeternum Loader Persistence and Execution

    The Aeternum loader has established persistence by creating a uniquely named LNK file in the user Startup directory and is executing auxiliary binaries from the local AppData profile.

    4 query2 analytic2 checkpoint1 action2 task
    command and control · execution · exfiltration
  24. high
    Research by Unit 42

    Endpoint AI-Assisted Scripting and Credential Dumping

    An intruder is using AI-generated scripts with iterative naming conventions to facilitate credential dumping and proxy tunneling across target organizations in Latin America.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · execution