Huntbase Hub · All hunts

Threat hunts for VPN

33 hunts covering VPN, each with a hypothesis, the queries that test it and what the hunt cannot see.

33 hunts

  1. high
    Research by Huntress

    VPN Entry and Identity Harvest

    An adversary has gained initial access via a VPN without multi-factor authentication and is harvesting credentials via LSASS dumping or Kerberoasting to facilitate exfiltration and eventual disk encryption.

    5 query2 analytic1 checkpoint1 action2 task
    credential access · exfiltration · impact
  2. medium Part 2 of 2
    Research by Cisco Talos

    Unauthorized RMM and Ransomware Precursors

    An adversary is using unauthorized remote management tools to maintain persistence and is performing credential harvesting or staging ransomware encryption.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  3. medium Part 1 of 2
    Research by Cisco Talos

    Cloud Identity and AI Agent Anomalies

    An adversary has used social engineering or exploited public-facing remote services to compromise an administrative identity, then used that access to manipulate cloud repositories or orchestration layers via automated agents.

    3 query2 analytic2 checkpoint1 action2 task
    credential access · discovery · impact
  4. critical Part 3 of 3
    Research by The DFIR Report

    Akira Ransomware Exfiltration and Impact

    An adversary is exfiltrating bulk data via SFTP using FileZilla and executing Akira ransomware, evidenced by massive outbound network transfers and the destruction of Volume Shadow Copies.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  5. high Part 2 of 3
    Research by The DFIR Report

    Bumblebee Persistence and AD Credential Harvesting

    An adversary has established internal persistence through unauthorized remote access tools like RustDesk and is performing Active Directory credential harvesting by dumping the NTDS database and LSASS memory.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  6. high Part 1 of 3
    Research by The DFIR Report

    Bumblebee Delivery and C2 Establishment

    An intruder has lured an administrator to a look-alike download page via SEO poisoning, leading to a trojanized installer that side-loads Bumblebee via consent.exe and establishes AdaptixC2.

    4 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · discovery
  7. medium
    Research by Sekoia

    Remote access and persistence via scheduled tasks

    An attacker has gained access via an external remote service and established persistence using a scheduled task that executes a remote administration tool or a malicious script.

    3 query2 analytic2 checkpoint1 action2 task
    execution · initial access · persistence
  8. medium
    Research by Cisco Talos

    Legacy System Access and Segmentation Bypass

    An adversary is exploiting unpatchable public-facing services or unauthorized VPN bridges to discover and laterally move toward isolated legacy OT assets.

    5 query2 analytic1 checkpoint1 action2 task
    discovery · initial access · lateral movement
  9. medium
    Research by Sekoia

    Contextual Investigation of Phased PowerShell Intrusions

    An adversary has gained initial access via remote services, executed PowerShell for post-exploitation, and established persistence through scheduled tasks to maintain a C2 connection.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · execution · initial access
  10. high
    Research by Rapid7

    Citrix NetScaler Authentication Bypass and Exposure

    An unauthenticated attacker has exploited CVE-2026-19490 on an internet-facing NetScaler appliance to bypass authentication and gain unauthorized remote access.

    3 query1 analytic1 checkpoint2 task
    CVE-2026-19490
  11. high Part 2 of 2
    Research by Huntress

    AI-Accelerated Post-Exploitation and Extortion

    An intruder is using AI-driven automation to conduct rapid internal reconnaissance, steal AI service tokens, and triage sensitive files for extortion at machine speed.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  12. high Part 1 of 2
    Research by Huntress

    Machine-Speed Perimeter and Identity Ingress

    An automated attacker is exploiting unpatched perimeter services or using AI-refined phishing to compromise identities, resulting in successful sign-ins from rare geolocations that correlate with known gateway vulnerabilities.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  13. high Part 1 of 2
    Research by The DFIR Report

    Bumblebee Delivery and Persistence

    An intruder has delivered Bumblebee malware through a trojanized MSI installer via SEO poisoning, using DLL side-loading of consent.exe and establishing persistence with remote management tools like RustDesk.

    4 query2 analytic2 checkpoint1 action2 task
    credential access · execution · exfiltration
  14. high Part 2 of 2
    Research by Huntress

    DarkMe RAT: COM Hijacking and Application Profiling

    An intruder has established persistence and stealthy execution by hijacking a COM object via script and launching it with Rundll32's /sta flag, followed by a broad profiling of local financial and security applications.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2023-38831 · CVE-2024-21412
  15. high
    Research by Elastic Security Labs

    Living off the coding agent: Tunnels and LaunchAgents

    An adversary is using a signed coding agent to proxy shell execution, establish reverse tunnels for service exposure, and install LaunchAgent persistence on a developer workstation.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  16. high Part 2 of 2
    Research by Unit 42

    Appliance Persistence and Identity Abuse

    An adversary has modified appliance scheduled tasks to disable MFA and is exfiltrating credentials via native Slack webhook integrations.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion · execution · exfiltration
  17. high Part 1 of 2
    Research by Unit 42

    Collaboration Platform Phishing and Execution

    An intruder has compromised an enterprise identity using collaboration tools to bypass email-based controls and execute malicious code via sideloading or malicious dependencies.

    4 query2 analytic2 checkpoint1 action2 task
    defense evasion · execution · exfiltration
  18. critical
    Research by Volexity

    SonicWall Appliance Zero-Day Exploitation and Webshells

    An adversary has exploited a pre-authentication proxy bypass and CVE-2026-15410 to execute commands on a SonicWall SMA appliance, established persistence via Nginx rewrites, and moved laterally using specific browser fingerprints.

    6 query2 analytic1 checkpoint1 action2 task
    CVE-2026-15410
  19. high Part 3 of 3
    Research by Datadog Security Labs

    Shai-Hulud: Exfiltration and Deadman Switch

    An attacker is using the Shai-Hulud framework to exfiltrate stolen credentials through GitHub dead-drops and has installed a destructive deadman switch that triggers a home-directory wipe if tokens are revoked.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  20. high Part 2 of 3
    Research by Datadog Security Labs

    Shai-Hulud Secret Harvesting and Discovery

    An intruder has deployed the Shai-Hulud framework to extract credentials from filesystem paths and process memory, subsequently using them to automate the discovery of cloud and Kubernetes infrastructure secrets.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  21. high Part 1 of 3
    Research by Datadog Security Labs

    Shai-Hulud Framework Supply Chain Hook and Loader Bootstrap

    The adversary poisons a developer repository or AI coding assistant configuration to execute the Shai-Hulud loader and establish daemonized persistence.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · discovery
  22. high Part 1 of 2
    Research by Mandiant

    Interactive Remote Access and Support Tool Abuse

    An intruder uses vishing to direct users to a self-destructing note service and installs unauthorized RMM tools to pivot into corporate VDI infrastructure.

    3 query2 analytic2 checkpoint1 action2 task
    collection · execution · exfiltration
  23. high Part 2 of 2
    Research by Huntress

    PaperCut NG and MF Pre-Auth RCE Exploitation

    An unauthenticated intruder has exploited PaperCut NG/MF authorization bypass and unsafe class loading to execute arbitrary Java bytecode, profiled the system, and deleted server logs to hide their activities.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2026-81578 · CVE-2026-82078
  24. high Part 2 of 2
    Research by Elastic Security Labs

    REVSTEALER: Credential Theft and Follow-on Impact

    An intruder has deployed an infostealer to harvest credentials from gaming and communication platforms, utilizing blockchain-based fallback infrastructure to maintain C2 and deploying impact modules like miners and proxies.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  25. high Part 1 of 2
    Research by Wiz

    TeamPCP Credential Validation and Discovery

    An adversary validates stolen cloud credentials and enumerates cloud infrastructure using offensive tools like TruffleHog or specialized Boto3 scripts following a supply chain compromise.

    4 query1 analytic1 checkpoint1 action2 task
    discovery · execution · exfiltration
  26. high Part 2 of 2
    Research by Volexity

    VerdantBamboo Stolen Credential and Pivot Hunt

    An adversary has used stolen administrative or service account credentials to access edge appliances via VPN or SSH, subsequently using web-based management interfaces to pivot further or deploy persistence.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · execution · initial access
  27. high Part 1 of 2
    Research by Volexity

    VERDANTBAMBOO Edge Appliance Post-Exploitation

    An adversary compromises an edge appliance, uses an inadvertent sudo configuration to escalate to root, and creates persistence via cron to tunnel traffic through DNS-over-HTTPS.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · execution · initial access
  28. high
    Research by CISA

    NextGen Mirth Connect Exploitation and Exfiltration

    An intruder is exploiting SQL injection or XXE vulnerabilities in NextGen Mirth Connect to exfiltrate credentials or write malicious files from the service process, typically identifiable by rare API traffic and unusual file system activity.

    3 query1 analytic1 checkpoint2 task
    CVE-2026-78224 · CVE-2026-82578
  29. high
    Research by CISA

    Orthanc DICOM Server Vulnerability Exploitation

    An intruder exploits CVE-2026-87020 by uploading a malformed image to an authenticated session on a vulnerable Orthanc server, causing a heap overflow and process crash.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2026-87020
  30. critical Part 2 of 2
    Research by Mandiant

    UNC6201 Network Evasion and C2

    An adversary is using iptables REDIRECT rules for Single Packet Authorization and DNS-over-HTTPS for command-and-control to hide ingress traffic and outbound beacons on compromised appliances.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-22769
  31. critical Part 1 of 2
    Research by Mandiant

    Dell RecoverPoint Appliance Intrusion and Persistence

    An adversary is exploiting hardcoded credentials (CVE-2026-22769) to deploy SLAYSTYLE web shells and persistent GRIMBOLT backdoors on Dell RecoverPoint for Virtual Machines appliances.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2026-22769
  32. high Part 2 of 2
    Research by Huntress

    RMM-Driven Endpoint Lateral Movement and Masquerading

    An intruder who has compromised an N-central appliance is abusing the Take Control feature to drop masqueraded binaries in user folders and perform process enumeration on managed hosts.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-18556 · CVE-2026-18577
  33. high Part 1 of 2
    Research by Huntress

    N-central Web Exploitation and Persistence

    An attacker has exploited unauthenticated N-central web vulnerabilities to gain administrative control, subsequently establishing persistence through rogue user accounts and Cloudflare protocol tunnels.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2026-18556 · CVE-2026-18577