Threat hunts for SQL Server
8 hunts covering SQL Server, each with a hypothesis, the queries that test it and what the hunt cannot see.
8 hunts
-
highResearch by Cisco Talos
Microsoft Patch Tuesday September 2026 Exposure
An adversary is exploiting September 2026 zero-day or critical remote code execution vulnerabilities, such as those in DNS Server or the Windows Update Stack, to establish initial access or escalate privileges on unpatched systems.
3 query1 analytic1 checkpoint2 taskCVE-2026-58599 · CVE-2026-65669 -
high Part 2 of 2Research by Microsoft
Storm-3168 Web Application Probing
An adversary is conducting automated web reconnaissance by probing for specific administrative and AI-related paths to identify vulnerable entry points for a subsequent cloud-focused intrusion.
3 query1 analytic1 checkpoint1 action2 taskcredential access · discovery · impact -
high Part 1 of 2Research by Microsoft
Storm-3168: Automated Azure Resource Destruction and Recovery Inhibition
A compromised service principal is executing an automated sequence of Azure resource discovery, mass deletion, and credential collection to facilitate a cloud-native ransomware operation.
4 query2 analytic1 checkpoint1 action2 taskcredential access · discovery · impact -
highResearch by Huntress
AD RMS Discovery and Administrative Reconnaissance
An adversary is identifying on-premises AD RMS clusters via DNS and rights-policy template enumeration before escalating privileges via local group membership to reach the administrative surface.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · discovery · privilege escalation -
high Part 2 of 2Research by Huntress
PaperCut NG and MF Pre-Auth RCE Exploitation
An unauthenticated intruder has exploited PaperCut NG/MF authorization bypass and unsafe class loading to execute arbitrary Java bytecode, profiled the system, and deleted server logs to hide their activities.
5 query2 analytic1 checkpoint1 action2 taskCVE-2026-81578 · CVE-2026-82078 -
highResearch by Huntress
AD RMS Master Key Extraction and Offline Decryption
An intruder has extracted the AD RMS Server Licensor Certificate (SLC) private key through a Trusted Publishing Domain export and is using it to decrypt protected documents offline.
4 query2 analytic1 checkpoint1 action2 taskcollection · credential access · discovery -
high Part 2 of 2Research by Sekoia
PureCrypter Loader and Mallox Ransomware Execution
An adversary is using PureCrypter to deliver Mallox ransomware, identified by Windows Defender exclusion commands followed by the retrieval of encrypted payloads disguised as media files and persistent Run keys in user profiles.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution -
high Part 1 of 2Research by Sekoia
Mallox Ransomware MSSQL Authentication and Service Abuse
An adversary is brute-forcing the MSSQL sa account to enable administrative features and execute a PowerShell loader from the SQL process.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution