Huntbase Hub · All hunts

Threat hunts for SQL Server

8 hunts covering SQL Server, each with a hypothesis, the queries that test it and what the hunt cannot see.

8 hunts

  1. high
    Research by Cisco Talos

    Microsoft Patch Tuesday September 2026 Exposure

    An adversary is exploiting September 2026 zero-day or critical remote code execution vulnerabilities, such as those in DNS Server or the Windows Update Stack, to establish initial access or escalate privileges on unpatched systems.

    3 query1 analytic1 checkpoint2 task
    CVE-2026-58599 · CVE-2026-65669
  2. high Part 2 of 2
    Research by Microsoft

    Storm-3168 Web Application Probing

    An adversary is conducting automated web reconnaissance by probing for specific administrative and AI-related paths to identify vulnerable entry points for a subsequent cloud-focused intrusion.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  3. high Part 1 of 2
    Research by Microsoft

    Storm-3168: Automated Azure Resource Destruction and Recovery Inhibition

    A compromised service principal is executing an automated sequence of Azure resource discovery, mass deletion, and credential collection to facilitate a cloud-native ransomware operation.

    4 query2 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  4. high
    Research by Huntress

    AD RMS Discovery and Administrative Reconnaissance

    An adversary is identifying on-premises AD RMS clusters via DNS and rights-policy template enumeration before escalating privileges via local group membership to reach the administrative surface.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · discovery · privilege escalation
  5. high Part 2 of 2
    Research by Huntress

    PaperCut NG and MF Pre-Auth RCE Exploitation

    An unauthenticated intruder has exploited PaperCut NG/MF authorization bypass and unsafe class loading to execute arbitrary Java bytecode, profiled the system, and deleted server logs to hide their activities.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2026-81578 · CVE-2026-82078
  6. high
    Research by Huntress

    AD RMS Master Key Extraction and Offline Decryption

    An intruder has extracted the AD RMS Server Licensor Certificate (SLC) private key through a Trusted Publishing Domain export and is using it to decrypt protected documents offline.

    4 query2 analytic1 checkpoint1 action2 task
    collection · credential access · discovery
  7. high Part 2 of 2
    Research by Sekoia

    PureCrypter Loader and Mallox Ransomware Execution

    An adversary is using PureCrypter to deliver Mallox ransomware, identified by Windows Defender exclusion commands followed by the retrieval of encrypted payloads disguised as media files and persistent Run keys in user profiles.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · execution
  8. high Part 1 of 2
    Research by Sekoia

    Mallox Ransomware MSSQL Authentication and Service Abuse

    An adversary is brute-forcing the MSSQL sa account to enable administrative features and execute a PowerShell loader from the SQL process.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · execution