Huntbase Hub · All hunts

Threat hunts for SonicWall

3 hunts covering SonicWall, each with a hypothesis, the queries that test it and what the hunt cannot see.

3 hunts

  1. high
    Research by Rapid7

    SonicWall SMA1000 Edge Appliance Exploitation

    An adversary is exploiting a chain of SSRF and command injection vulnerabilities on a SonicWall SMA1000 appliance to achieve remote code execution, indicated by rare HTTP management traffic followed by shell spawns from web processes.

    3 query1 analytic1 checkpoint2 task
    CVE-2026-83548 · CVE-2026-83549
  2. high
    Research by Rapid7

    Metasploit Framework Exploitation and Post-Exploitation

    An intruder has leveraged one of sixteen new Metasploit modules to exploit a public-facing web application and establish persistence or conduct Kerberos authentication relaying.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2025-54988 · CVE-2025-66516
  3. high Part 2 of 2
    Research by Huntress

    DarkMe RAT: COM Hijacking and Application Profiling

    An intruder has established persistence and stealthy execution by hijacking a COM object via script and launching it with Rundll32's /sta flag, followed by a broad profiling of local financial and security applications.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2023-38831 · CVE-2024-21412