Huntbase Hub · All hunts

Privilege Escalation threat hunts

22 hunts covering privilege escalation, each with a hypothesis, the queries that test it and what the hunt cannot see.

22 hunts

  1. high Part 3 of 3
    Research by Microsoft

    Zimbra secrets theft and cluster propagation

    An intruder is using Zimbra administrative utilities to dump service credentials and move laterally to peer nodes using the zimbra service account's SSH identity.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2026-73570
  2. high Part 2 of 3
    Research by Microsoft

    Zimbra Privilege Escalation and Root Persistence

    An intruder has escalated from the Zimbra service account to root by symlinking application logs to PAM configurations and established persistence through a rare systemd service.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-73570
  3. high Part 1 of 3
    Research by Microsoft

    Zimbra CVE-2026-73570 RCE and JSP Web Shell Entry

    An attacker is exploiting CVE-2026-73570 on internet-facing Zimbra servers to execute commands via the SNMP path and drop JSP web shells in the webroot for persistence.

    4 query2 analytic2 checkpoint1 action2 task
    CVE-2026-73570
  4. high
    Research by Unit 42

    Kubernetes Operator RBAC Abuse and Secret Theft

    A vulnerable or outdated Kubernetes operator is running with excessive ClusterRole permissions, allowing an attacker to exfiltrate cluster-wide secrets or establish unauthorized AI agent bridges to external endpoints.

    3 query1 analytic1 checkpoint2 task
    CVE-2026-6389
  5. high
    Research by Rapid7

    Windows Zero-Day Privilege Escalation and Ransomware

    Adversaries are exploiting unpatched Windows ALPC or Update Stack vulnerabilities to escalate to SYSTEM integrity and deploy ransomware, leaving traces of rare process elevations and specific link-resolution artifacts.

    4 query1 analytic1 checkpoint2 task
    CVE-2026-81963 · CVE-2026-85880
  6. high
    Research by Cisco Talos

    Microsoft Patch Tuesday September 2026 Exposure

    An adversary is exploiting September 2026 zero-day or critical remote code execution vulnerabilities, such as those in DNS Server or the Windows Update Stack, to establish initial access or escalate privileges on unpatched systems.

    3 query1 analytic1 checkpoint2 task
    CVE-2026-58599 · CVE-2026-65669
  7. high Part 3 of 3
    Research by The DFIR Report

    Apache ActiveMQ Lateral Movement and Ransomware Impact

    An attacker has transitioned from an exploited ActiveMQ server to lateral movement via RDP using stolen credentials, ultimately deploying LockBit ransomware from user-writable directories or with specific execution flags.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2023-46604
  8. high Part 1 of 3
    Research by The DFIR Report

    ActiveMQ Exploitation and Metasploit Staging

    An intruder has exploited CVE-2023-46604 on an ActiveMQ server to run arbitrary code, staged a Metasploit payload, and escalated to SYSTEM privileges using named pipe impersonation.

    4 query2 analytic1 checkpoint1 action2 task
    CVE-2023-46604
  9. medium
    Research by Elastic Security Labs

    Vulnerable Driver Exploitation and Kernel Escalation

    An adversary has exploited a public-facing application to stage and load a vulnerable kernel driver, bypassing security controls to gain persistent high-integrity access to the host.

    4 query2 analytic2 checkpoint1 action2 task
    execution · initial access · privilege escalation
  10. high
    Research by Elastic Security Labs

    AWS Cloud Identity Takeover Chain

    An adversary has gained initial access to a cloud account by brute-forcing the console and performing a password reset, then used that access to establish a presence across multiple projects in the organization.

    5 query2 analytic1 checkpoint1 action2 task
    initial access · persistence · privilege escalation
  11. medium Part 2 of 2
    Research by Unit 42

    Endpoint Data Staging and Exfiltration

    An adversary has staged sensitive information in temporary directories and is exfiltrating that data via rare outbound network connections or DNS lookups.

    3 query1 analytic1 checkpoint1 action2 task
    collection · exfiltration · initial access
  12. medium Part 1 of 2
    Research by Unit 42

    Identity and Cloud Pivot from Web Exploits

    An adversary has exploited an internet-facing web server to establish a beachhead and is now manipulating cloud or SaaS identities to persist and reconfigure the environment.

    3 query2 analytic2 checkpoint1 action2 task
    collection · exfiltration · initial access
  13. high
    Research by Elastic Security Labs

    Kubernetes Service Account Abuse and Escape

    An intruder has harvested a service account token from a compromised pod and is using it to deploy a privileged pod for container escape, bypassing standard runtime process detection.

    4 query2 analytic1 checkpoint1 action2 task
    credential access · discovery · execution
  14. high
    Research by Huntress

    AD RMS Discovery and Administrative Reconnaissance

    An adversary is identifying on-premises AD RMS clusters via DNS and rights-policy template enumeration before escalating privileges via local group membership to reach the administrative surface.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · discovery · privilege escalation
  15. high
    Research by Elastic Security Labs

    Linux Local Privilege Escalation Behavior

    An intruder is exploiting a kernel vulnerability or a misconfigured SUID helper to transition from a low-privilege foothold in a writable directory to root privileges.

    4 query2 analytic1 checkpoint1 action2 task
    discovery · execution · privilege escalation
  16. high Part 2 of 2
    Research by Unit 42

    AI-Agentic Escalation and Infrastructure Hijacking

    An automated AI agent loop is conducting high-speed privilege escalation via secrets managers, tampering with CI/CD configurations, and hijacking cloud AI endpoints for external orchestration.

    4 query1 analytic1 checkpoint1 action2 task
    credential access · impact · initial access
  17. high Part 1 of 2
    Research by Unit 42

    Automated Service Infiltration and Data Harvesting

    An intruder is using autonomous AI agents to breach public web services and map internal microservices while harvesting credentials, leaving behind unique filesystem artifacts and high-frequency network recon patterns.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · impact · initial access
  18. high
    Research by Datadog Security Labs

    Local Privilege Escalation via Copy-Fail Page Cache Corruption

    An unprivileged local attacker exploits CVE-2026-31431 by splicing AF_ALG crypto sockets into the page cache of sensitive system files to achieve root execution without modifying files on disk.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2026-31431
  19. high Part 2 of 2
    Research by Volexity

    VerdantBamboo Stolen Credential and Pivot Hunt

    An adversary has used stolen administrative or service account credentials to access edge appliances via VPN or SSH, subsequently using web-based management interfaces to pivot further or deploy persistence.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · execution · initial access
  20. high Part 1 of 2
    Research by Volexity

    VERDANTBAMBOO Edge Appliance Post-Exploitation

    An adversary compromises an edge appliance, uses an inadvertent sudo configuration to escalate to root, and creates persistence via cron to tunnel traffic through DNS-over-HTTPS.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · execution · initial access
  21. high Part 2 of 3
    Research by Cisco Talos

    UAT-10147: Host Elevation and Evasion

    An adversary is executing automated staging scripts to deploy privilege escalation tools and blind security software on compromised web servers.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · defense evasion · discovery
  22. high Part 1 of 3
    Research by Cisco Talos

    Web Exploit and Telemetry Theft (UAT-10147)

    The adversary exploits known web vulnerabilities in Zimbra, Telerik, or AjaxPro to achieve initial access and exfiltrates system identifiers to a Nacos configuration server via HTTP POST requests.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · discovery