Huntbase Hub · All hunts

Discovery threat hunts

77 hunts covering discovery, each with a hypothesis, the queries that test it and what the hunt cannot see.

77 hunts

  1. medium Part 2 of 2
    Research by Cisco Talos

    Unauthorized RMM and Ransomware Precursors

    An adversary is using unauthorized remote management tools to maintain persistence and is performing credential harvesting or staging ransomware encryption.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  2. medium Part 1 of 2
    Research by Cisco Talos

    Cloud Identity and AI Agent Anomalies

    An adversary has used social engineering or exploited public-facing remote services to compromise an administrative identity, then used that access to manipulate cloud repositories or orchestration layers via automated agents.

    3 query2 analytic2 checkpoint1 action2 task
    credential access · discovery · impact
  3. high Part 2 of 2
    Research by Huntress

    Web Worker Discovery and Payment Data Harvesting

    An intruder is using a compromised IIS web worker to execute discovery tools and search for payment card data or database credentials.

    3 query2 analytic2 checkpoint1 action2 task
    collection · discovery · execution
  4. high Part 1 of 2
    Research by Huntress

    Web Shell Ingress and Platform Probing

    An intruder has exploited a file upload vulnerability to drop web shells in member-facing directories after probing the application boundary and brute-forcing credentials.

    3 query1 analytic1 checkpoint1 action2 task
    collection · discovery · execution
  5. high
    Research by Cisco Talos

    UAT-11587 Antino Backdoor Phased Infection and M365 C2

    An adversary is using Cloudflare-hosted stagers to deliver the Rust-compiled Antino backdoor, which then establishes persistence via Run keys and communicates using Microsoft 365 as a dead-drop C2 channel.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · discovery · execution
  6. high Part 3 of 3
    Research by Microsoft

    Zimbra secrets theft and cluster propagation

    An intruder is using Zimbra administrative utilities to dump service credentials and move laterally to peer nodes using the zimbra service account's SSH identity.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2026-73570
  7. high Part 2 of 3
    Research by Microsoft

    Zimbra Privilege Escalation and Root Persistence

    An intruder has escalated from the Zimbra service account to root by symlinking application logs to PAM configurations and established persistence through a rare systemd service.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-73570
  8. high Part 1 of 3
    Research by Microsoft

    Zimbra CVE-2026-73570 RCE and JSP Web Shell Entry

    An attacker is exploiting CVE-2026-73570 on internet-facing Zimbra servers to execute commands via the SNMP path and drop JSP web shells in the webroot for persistence.

    4 query2 analytic2 checkpoint1 action2 task
    CVE-2026-73570
  9. medium Part 2 of 2
    Research by Elastic Security Labs

    Administrative AI Configuration File Tampering

    An adversary has modified system-wide AI configuration files or hooks on a Linux endpoint to bypass security constraints or establish persistence outside the managed reconciliation workflow.

    3 query1 analytic1 checkpoint1 action2 task
    discovery · execution · persistence
  10. medium Part 1 of 2
    Research by Elastic Security Labs

    Automated EDR Response Action Reconciliation

    An adversary has compromised a management principal or repurposed an Elastic workflow to perform mass remote execution across the Linux fleet, masquerading as a legitimate configuration reconciliation loop.

    5 query2 analytic1 checkpoint1 action2 task
    discovery · execution · persistence
  11. high Part 2 of 2
    Research by Microsoft

    Storm-3068 Build Pipeline Execution and Tunneling

    An adversary has modified build pipelines to execute malicious code on agents, deploying RMM tools and establishing tunnels to exfiltrate Kubernetes credentials.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  12. high Part 1 of 2
    Research by Microsoft

    Cloud Identity Takeover and DevOps Enumeration

    An adversary hijacked a cloud identity using self-service password reset to perform automated discovery across Azure DevOps repositories and harvest Kubernetes configuration files.

    4 query2 analytic2 checkpoint1 action3 task
    command and control · credential access · discovery
  13. medium
    Research by ESET Research

    Exploitation of AI-Generated Vibe-Coded Applications

    An attacker is exploiting vulnerabilities in AI-generated applications—such as missing input validation or hardcoded secrets—to gain initial access, brute-force credentials, or execute code from user-writable directories.

    5 query2 analytic1 checkpoint1 action2 task
    credential access · discovery · execution
  14. critical Part 3 of 3
    Research by The DFIR Report

    Akira Ransomware Exfiltration and Impact

    An adversary is exfiltrating bulk data via SFTP using FileZilla and executing Akira ransomware, evidenced by massive outbound network transfers and the destruction of Volume Shadow Copies.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  15. high Part 2 of 3
    Research by The DFIR Report

    Bumblebee Persistence and AD Credential Harvesting

    An adversary has established internal persistence through unauthorized remote access tools like RustDesk and is performing Active Directory credential harvesting by dumping the NTDS database and LSASS memory.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  16. high Part 1 of 3
    Research by The DFIR Report

    Bumblebee Delivery and C2 Establishment

    An intruder has lured an administrator to a look-alike download page via SEO poisoning, leading to a trojanized installer that side-loads Bumblebee via consent.exe and establishes AdaptixC2.

    4 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · discovery
  17. high
    Research by Rapid7

    SonicWall SMA1000 Edge Appliance Exploitation

    An adversary is exploiting a chain of SSRF and command injection vulnerabilities on a SonicWall SMA1000 appliance to achieve remote code execution, indicated by rare HTTP management traffic followed by shell spawns from web processes.

    3 query1 analytic1 checkpoint2 task
    CVE-2026-83548 · CVE-2026-83549
  18. medium
    Research by Cisco Talos

    Legacy System Access and Segmentation Bypass

    An adversary is exploiting unpatchable public-facing services or unauthorized VPN bridges to discover and laterally move toward isolated legacy OT assets.

    5 query2 analytic1 checkpoint1 action2 task
    discovery · initial access · lateral movement
  19. high Part 2 of 2
    Research by Huntress

    AI-Accelerated Post-Exploitation and Extortion

    An intruder is using AI-driven automation to conduct rapid internal reconnaissance, steal AI service tokens, and triage sensitive files for extortion at machine speed.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  20. high Part 1 of 2
    Research by Huntress

    Machine-Speed Perimeter and Identity Ingress

    An automated attacker is exploiting unpatched perimeter services or using AI-refined phishing to compromise identities, resulting in successful sign-ins from rare geolocations that correlate with known gateway vulnerabilities.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  21. high Part 2 of 2
    Research by Sekoia

    Gamaredon Gammasteel: Drive Discovery and S3 Exfiltration

    An adversary is using a recurring PowerShell timer to discover documents across user profiles and local/network drives, then exfiltrating them to an S3-compatible storage endpoint.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion · discovery · execution
  22. high Part 1 of 2
    Research by Sekoia

    Gammasteel Fileless PowerShell Registry Staging

    An intruder has staged encrypted PowerShell payloads in the user Printers registry hive and is executing them via hidden processes that avoid file-based detection.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion · discovery · execution
  23. high Part 2 of 2
    Research by Cisco Talos

    CLOSEDQUORUM AI Payload Actions

    An autonomous AI implant is performing credential theft, process injection, or WMI persistence based on plurality-vote decisions reached by a panel of LLM providers.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  24. high Part 1 of 2
    Research by Cisco Talos

    Autonomous LLM Decision Loop

    An autonomous implant performs host discovery and then queries multiple commercial AI providers to decide its next tactical moves, bypassing traditional C2 infrastructure.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  25. high Part 2 of 2
    Research by Microsoft

    Storm-3168 Web Application Probing

    An adversary is conducting automated web reconnaissance by probing for specific administrative and AI-related paths to identify vulnerable entry points for a subsequent cloud-focused intrusion.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  26. high Part 1 of 2
    Research by Microsoft

    Storm-3168: Automated Azure Resource Destruction and Recovery Inhibition

    A compromised service principal is executing an automated sequence of Azure resource discovery, mass deletion, and credential collection to facilitate a cloud-native ransomware operation.

    4 query2 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  27. critical Part 3 of 3
    Research by Microsoft

    Storm-2570 Data Exfiltration and Ransomware Impact

    An intruder is exfiltrating staged directories and Active Directory database fragments using synchronization tools before deploying a ransomware payload for mass encryption.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  28. high Part 1 of 3
    Research by Microsoft

    Storm-2570 Persistent Remote Access and Discovery

    An intruder has established redundant persistent access using commercial RMM tools and outbound tunneling utilities to bypass firewalls and conduct internal reconnaissance.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  29. high
    Research by CISA

    Integrator Supply Chain Compromise and SCADA Data Exfiltration

    A malicious actor has pivoted from a compromised third-party integrator network into the ICS environment, searched for SCADA schematics using sensitive keywords, and staged them in archives for exfiltration.

    6 query2 analytic1 checkpoint1 action2 task
    collection · discovery · exfiltration
  30. high Part 3 of 3
    Research by The DFIR Report

    Lateral Movement and Ransomware Deployment: The Gentlemen

    An adversary has moved laterally from an RMM-controlled beachhead using NetExec or GoTo Resolve to dump credentials and exfiltrate data to Wasabi before initiating domain-wide encryption via GPO.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2025-55182
  31. high Part 2 of 3
    Research by The DFIR Report

    Decentralized and SaaS C2 Infrastructure

    An intruder uses decentralized blockchain gateways or SaaS platforms to resolve C2 configuration and tunnel traffic, bypassing static network perimeter filters.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2025-55182
  32. high Part 1 of 3
    Research by The DFIR Report

    EtherRAT and TukTuk Initial Infection and Discovery

    An intruder has gained initial access via a trojanized MSI installer, established persistence using a Node.js-based EtherRAT, and is currently performing system discovery or sideloading TukTuk payloads.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2025-55182
  33. high Part 3 of 3
    Research by The DFIR Report

    Persistence and Exfiltration of Lunar Spider

    An adversary is maintaining long-term access via a masqueraded .NET backdoor and exfiltrating data via Rclone over FTP to a rare external destination.

    4 query1 analytic1 checkpoint1 action2 task
    CVE-2020-1472
  34. high Part 3 of 3
    Research by The DFIR Report

    Apache ActiveMQ Lateral Movement and Ransomware Impact

    An attacker has transitioned from an exploited ActiveMQ server to lateral movement via RDP using stolen credentials, ultimately deploying LockBit ransomware from user-writable directories or with specific execution flags.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2023-46604
  35. high Part 1 of 3
    Research by The DFIR Report

    ActiveMQ Exploitation and Metasploit Staging

    An intruder has exploited CVE-2023-46604 on an ActiveMQ server to run arbitrary code, staged a Metasploit payload, and escalated to SYSTEM privileges using named pipe impersonation.

    4 query2 analytic1 checkpoint1 action2 task
    CVE-2023-46604
  36. high
    Research by Sekoia

    Gamaredon GammaLoad Multi-stage Persistence and Execution

    An intruder has established persistent access using GammaLoad VBScripts that manage C2 configuration via registry keys in HKCU\Console and execute via a high-frequency task invoking an Alternate Data Stream.

    4 query1 analytic1 checkpoint1 action2 task
    discovery · execution · persistence
  37. high
    Research by Elastic Security Labs

    Kubernetes Service Account Abuse and Escape

    An intruder has harvested a service account token from a compromised pod and is using it to deploy a privileged pod for container escape, bypassing standard runtime process detection.

    4 query2 analytic1 checkpoint1 action2 task
    credential access · discovery · execution
  38. high
    Research by Huntress

    AD RMS Discovery and Administrative Reconnaissance

    An adversary is identifying on-premises AD RMS clusters via DNS and rights-policy template enumeration before escalating privileges via local group membership to reach the administrative surface.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · discovery · privilege escalation
  39. high
    Research by Elastic Security Labs

    Bulk Directory Discovery via AAD Graph API

    An adversary uses legacy Azure AD Graph API endpoints and known offensive Client IDs to perform bulk directory enumeration, specifically targeting internal API versions that expose sensitive authentication methods.

    3 query2 analytic2 checkpoint1 action2 task
    discovery · execution · initial access
  40. medium Part 2 of 2
    Research by Unit 42

    Anomalous Cloud Identity Behavior

    An adversary has compromised an administrative cloud identity and is accessing the environment through multi-hop proxies or Tor to perform discovery and initial access.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · discovery · execution
  41. medium Part 1 of 2
    Research by Unit 42

    Public app exploitation and cloud identity drift

    An adversary has exploited a public-facing application on a cloud instance to obtain its identity, which is now being used for activity that deviates from the host's established behavioral profile.

    5 query1 analytic1 checkpoint1 action2 task
    command and control · discovery · execution
  42. high Part 2 of 2
    Research by Unit 42

    Spring Ring: NTLM Relay and RAT C2

    An attacker has deployed a custom Python environment to facilitate NTLM relay attacks and a PowerShell-based RAT that beacons to external command-and-control infrastructure.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · discovery
  43. high Part 1 of 2
    Research by Unit 42

    Microsoft Teams Vishing and Malicious Payload Execution

    An adversary is using external Microsoft Teams accounts to masquerade as IT support and coerce employees into executing RMM tools or custom payloads that perform discovery and persistence.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · defense evasion · discovery
  44. high Part 3 of 3
    Research by The DFIR Report

    SystemBC C2 and WinSCP Exfiltration

    An adversary is using SystemBC for proxy tunneling and WinSCP for unencrypted FTP exfiltration from the Public Music directory to known ransomware affiliate infrastructure.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  45. high Part 2 of 3
    Research by The DFIR Report

    Identity-Based Lateral Movement and Credential Access

    An intruder has moved laterally to high-value infrastructure like domain controllers and backup servers using hijacked accounts or newly created local admins, then executed scripts to harvest credentials.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  46. high Part 1 of 3
    Research by The DFIR Report

    EarthTime Trojan to Ransomware Reconnaissance

    An adversary has gained initial access via a trojanized EarthTime installer, established a beachhead using SectopRAT with MSBuild injection, and is now performing environment discovery using specialized ransomware reconnaissance tools.

    6 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  47. high
    Research by Microsoft

    IT Support Impersonation and WinRM Lateral Expansion

    An adversary has hijacked a remote-support session to execute PowerShell, use a portable Node.js runtime for C2, and expand laterally via WinRM to domain controllers.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · discovery · execution
  48. high Part 3 of 3
    Research by Datadog Security Labs

    Shai-Hulud: Exfiltration and Deadman Switch

    An attacker is using the Shai-Hulud framework to exfiltrate stolen credentials through GitHub dead-drops and has installed a destructive deadman switch that triggers a home-directory wipe if tokens are revoked.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  49. high Part 2 of 3
    Research by Datadog Security Labs

    Shai-Hulud Secret Harvesting and Discovery

    An intruder has deployed the Shai-Hulud framework to extract credentials from filesystem paths and process memory, subsequently using them to automate the discovery of cloud and Kubernetes infrastructure secrets.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  50. high Part 1 of 3
    Research by Datadog Security Labs

    Shai-Hulud Framework Supply Chain Hook and Loader Bootstrap

    The adversary poisons a developer repository or AI coding assistant configuration to execute the Shai-Hulud loader and establish daemonized persistence.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · discovery
  51. medium
    Research by Elastic Security Labs

    AI Coding Agent Tool-Call Auditing

    An AI agent operating under developer credentials is executing rare shell commands, accessing sensitive configuration files, or communicating with third-party MCP servers without explicit developer intent.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · discovery · execution
  52. high
    Research by Elastic Security Labs

    Linux Local Privilege Escalation Behavior

    An intruder is exploiting a kernel vulnerability or a misconfigured SUID helper to transition from a low-privilege foothold in a writable directory to root privileges.

    4 query2 analytic1 checkpoint1 action2 task
    discovery · execution · privilege escalation
  53. high Part 2 of 2
    Research by Cisco Talos

    VoidLink Lateral Scanning and Mesh C2

    An intruder is using a VoidLink implant to perform automated internal reconnaissance and establish a peer-to-peer mesh command-and-control network between compromised Linux servers.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · discovery · execution
  54. high Part 1 of 2
    Research by Cisco Talos

    VoidLink: Exploitation and Kernel-Level Implant Deployment

    An adversary has exploited a Java-based Apache Dubbo service to deploy a ZigLang-based VoidLink implant and maintained stealth using an unsigned kernel-level rootkit.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · discovery · execution
  55. high Part 2 of 2
    Research by Microsoft

    AI Infrastructure Host Monetization and Persistence

    An attacker has compromised an AI gateway or retrieval engine and is now deploying masqueraded payloads to monetize the host via cryptomining and establish durable SSH or systemd persistence.

    6 query2 analytic1 checkpoint1 action2 task
    CVE-2025-68700 · CVE-2026-24770
  56. high Part 1 of 2
    Research by Microsoft

    AI Gateway Exploitation and Data Theft

    An intruder has exploited an exposed AI gateway or orchestration platform to harvest LLM API keys from process memory and exfiltrate tenant configurations from backend databases.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2025-68700 · CVE-2026-24770
  57. high Part 2 of 2
    Research by Huntress

    PaperCut NG and MF Pre-Auth RCE Exploitation

    An unauthenticated intruder has exploited PaperCut NG/MF authorization bypass and unsafe class loading to execute arbitrary Java bytecode, profiled the system, and deleted server logs to hide their activities.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2026-81578 · CVE-2026-82078
  58. high Part 2 of 2
    Research by The DFIR Report

    Interlock RAT C2 and RDP Lateral Movement

    An intruder has established a PHP-based RAT beachhead and is using Cloudflare Tunnels for C2 before moving laterally via RDP.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · discovery · execution
  59. high Part 1 of 2
    Research by The DFIR Report

    Interlock RAT Endpoint Execution and Reconnaissance

    An intruder has deployed a PHP-based RAT into user-writable directories via a PowerShell stager and is conducting automated system reconnaissance to map the environment.

    6 query2 analytic1 checkpoint1 action2 task
    command and control · discovery · execution
  60. critical Part 3 of 3
    Research by The DFIR Report

    Akira Ransomware Deployment and Credential Access

    An intruder has escalated privileges through NTDS dumping and database credential harvesting, and is now exfiltrating data before deploying Akira ransomware.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  61. high Part 2 of 3
    Research by The DFIR Report

    Bumblebee Reconnaissance and Privileged Persistence

    An intruder is performing domain discovery and establishing privileged persistence by creating rogue administrator accounts and external SSH tunnels from compromised systems.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  62. high Part 1 of 3
    Research by The DFIR Report

    Bumblebee SEO Poisoning and DLL Sideloading

    An intruder compromises privileged workstations by poisoning search results for IT tools, tricking users into running a trojanized MSI that side-loads Bumblebee malware via consent.exe.

    4 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · discovery
  63. high Part 2 of 2
    Research by Elastic Security Labs

    REVSTEALER: Credential Theft and Follow-on Impact

    An intruder has deployed an infostealer to harvest credentials from gaming and communication platforms, utilizing blockchain-based fallback infrastructure to maintain C2 and deploying impact modules like miners and proxies.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  64. medium
    Research by Huntress

    VSS Manipulation and Lateral Movement Correlation

    An attacker has moved laterally into the environment and is abusing Volume Shadow Copy Service utilities to either steal the Active Directory database or inhibit system recovery before a ransomware event.

    4 query2 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  65. high
    Research by Huntress

    AD RMS Master Key Extraction and Offline Decryption

    An intruder has extracted the AD RMS Server Licensor Certificate (SLC) private key through a Trusted Publishing Domain export and is using it to decrypt protected documents offline.

    4 query2 analytic1 checkpoint1 action2 task
    collection · credential access · discovery
  66. high Part 2 of 2
    Research by Microsoft

    Microsoft Graph and Cloud Application Exfiltration

    An adversary is using automated Graph API tools to enumerate organizational resources and exfiltrate SharePoint/OneDrive data after obtaining a cloud session via passkey-themed social engineering.

    4 query1 analytic1 checkpoint1 action2 task
    discovery · exfiltration · initial access
  67. high Part 1 of 2
    Research by Wiz

    TeamPCP Credential Validation and Discovery

    An adversary validates stolen cloud credentials and enumerates cloud infrastructure using offensive tools like TruffleHog or specialized Boto3 scripts following a supply chain compromise.

    4 query1 analytic1 checkpoint1 action2 task
    discovery · execution · exfiltration
  68. high Part 2 of 3
    Research by Cisco Talos

    UAT-10147: Host Elevation and Evasion

    An adversary is executing automated staging scripts to deploy privilege escalation tools and blind security software on compromised web servers.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · defense evasion · discovery
  69. high Part 1 of 3
    Research by Cisco Talos

    Web Exploit and Telemetry Theft (UAT-10147)

    The adversary exploits known web vulnerabilities in Zimbra, Telerik, or AjaxPro to achieve initial access and exfiltrates system identifiers to a Nacos configuration server via HTTP POST requests.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · discovery
  70. high Part 2 of 2
    Research by Huntress

    RMM Command and Control and Redundancy

    An attacker is using rogue ScreenConnect instances and secondary RMM tools to maintain persistence, identified by non-standard port connections and rare binaries running from user-writable directories.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · discovery · execution
  71. high Part 1 of 2
    Research by Huntress

    Rogue ScreenConnect Host Execution and Persistence

    An adversary is using social engineering to deploy rogue ScreenConnect clients that execute a multi-stage VBScript chain for host profiling and persistent access via registry run keys.

    6 query2 analytic1 checkpoint1 action2 task
    command and control · discovery · execution
  72. high Part 2 of 2
    Research by Huntress

    RMM-Driven Endpoint Lateral Movement and Masquerading

    An intruder who has compromised an N-central appliance is abusing the Take Control feature to drop masqueraded binaries in user folders and perform process enumeration on managed hosts.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-18556 · CVE-2026-18577
  73. high Part 1 of 2
    Research by Huntress

    N-central Web Exploitation and Persistence

    An attacker has exploited unauthenticated N-central web vulnerabilities to gain administrative control, subsequently establishing persistence through rogue user accounts and Cloudflare protocol tunnels.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2026-18556 · CVE-2026-18577
  74. high Part 3 of 3
    Research by Microsoft

    TerminalFix Asynchronous Shell and Reverse Tunnel

    An intruder has established long-term C2 presence using a PowerShell file-watch loop for asynchronous command execution and a Python-based reverse tunnel for persistent network-level proxying.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · discovery
  75. high Part 2 of 3
    Research by Microsoft

    TerminalFix ClickFix Delivery and Automated Reconnaissance

    An intruder has used a fake Cloudflare verification lure to trick a user into pasting a PowerShell command, facilitating local directory staging and automated domain discovery.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · discovery
  76. high Part 2 of 2
    Research by Elastic Security Labs

    Web Server Shell Execution and wp2shell Post-Exploitation

    An attacker has exploited a WordPress vulnerability to spawn a shell from a web server process and is currently performing system discovery or cleaning up traces of the wp2shell plugin.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2026-60137 · CVE-2026-63030
  77. high Part 1 of 2
    Research by Elastic Security Labs

    WordPress REST API Exploitation and Plugin Staging

    An attacker is exploiting the wp2shell WordPress Core RCE chain to upload and stage a malicious plugin by abusing the unauthenticated REST batch API.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-60137 · CVE-2026-63030