---
title: "Threat Hunt Plan: Armatura One Physical Access Control — Embedded ActiveMQ OpenWire Exploitation and Hard-Coded Credential Abuse"
description: "Objective: Determine whether any Armatura One physical access control server in the environment has been exposed to, or compromised through, exploitation of the embedded Apache ActiveMQ OpenWire deserialization flaw CVE-2023-46604"
---

[Skip to content](https://1898advisories.burnsmcd.com/threat-hunt-plan-armatura-one-physical-access-control-embedded-activemq-openwire-exploitation-and-hard-coded-credential-abuse#main-content)

![1898-logo-grey-R-1](https://1898advisories.burnsmcd.com/hs-fs/hubfs/1898-logo-grey-R-1.webp?width=188&height=100&name=1898-logo-grey-R-1.webp)

- [Cyberthreat](https://1898advisories.burnsmcd.com/tag/cyberthreat)
- [Threat Hunt](https://1898advisories.burnsmcd.com/tag/threat-hunt)
- [View All](https://1898advisories.burnsmcd.com/)

Open main navigation

Close main navigation

- [Cyberthreat](https://1898advisories.burnsmcd.com/tag/cyberthreat)
- [Threat Hunt](https://1898advisories.burnsmcd.com/tag/threat-hunt)
- [View All](https://1898advisories.burnsmcd.com/)
- [Contact us](https://1898andco.burnsmcd.com/contact-us)

[Contact us](https://1898andco.burnsmcd.com/contact-us)

 October 9, 2026

# Threat Hunt Plan: Armatura One Physical Access Control — Embedded ActiveMQ OpenWire Exploitation and Hard-Coded Credential Abuse

![Picture of The 1898 & Co. Team](https://1898advisories.burnsmcd.com/hs-fs/hubfs/1898%20Cyberthreat%20Advisory%20Blog%20Assets/1898-Co-Ampersand.png?width=50&name=1898-Co-Ampersand.png) [The 1898 & Co. Team](https://1898advisories.burnsmcd.com/author/1898-co-team)

Date: 2026-10-02 | Revision 1.2 | Source: CISA ICS Advisory ICSA-26-274-01 (published 2026-10-01)

#### Hunt Objective and Scope

Objective: Determine whether any Armatura One physical access control server in the environment has been exposed to, or compromised through, exploitation of the embedded Apache ActiveMQ OpenWire deserialization flaw CVE-2023-46604 (CVSS v3.1 9.8, CISA KEV), or abuse of the hard-coded cryptographic key, hard-coded database superuser password, and plain-text log credential weaknesses CVE-2026-94591, CVE-2026-94592, CVE-2026-94593 and CVE-2026-94594.

Environment in scope: every Armatura One server running a version prior to V4.7.2 (or prior to V4.6.1\_USA on the USA release line); the hosts and controllers that communicate with it (door controllers, readers, workstations running the management client); the network segments carrying its OpenWire broker and database traffic; any backup repository or support-bundle store holding Armatura One configuration or log files; and the organization's public IP space and cloud asset inventory for the external-exposure sweep.

Time window: the window starts at the earliest known exploitation, not at disclosure. CVE-2023-46604 has been exploited in the wild since at least October 10, 2023, and embedded copies are often left unpatched for years. For any Armatura One server that is internet-reachable (Hypothesis 1) or ran an affected version, the window therefore starts October 10, 2023 and is bounded by the data floor below. For the rest of the population, 90 days back from hunt start is the primary window.

Execution order: run Hypothesis 1 (external exposure) first; every confirmed internet-reachable Armatura One server becomes a priority target for an exhaustive pass in Hypotheses 2 through 4.

Data floor (pre-flight, before any leg runs): a time picker is not retention. For each telemetry family, measure the oldest retained event and record the floor date. Report the part of the window before the floor as Non-Conclusive, never clean.

`#event_simpleName=/^(ProcessRollup2|SyntheticProcessRollup2|NetworkConnectIP4|NetworkListenIP4|NetworkReceiveAcceptIP4|UserLogon|ServiceStarted)$/ | groupBy([#event_simpleName], function=min(@timestamp, as=oldest), limit=max)`

 

Do the same for the Windows Security and Sysmon channels on each server (the oldest event per channel) and for any PCAP store. Hypotheses 2 and 4 are event-based, so they are bounded by the floor. Hypothesis 3 is largely state-based: credential-bearing files, default passwords and encryption settings exist now and can be checked directly, regardless of log retention.

Note on ports: 61616/tcp is the Apache ActiveMQ OpenWire default and 8161/tcp the ActiveMQ web console default. Confirm the ports actually configured on each Armatura One installation (the broker and database ports are recorded in the installation configuration file) and substitute them throughout.

Note on names and paths: several queries match the string "armatura" in install paths, file names or cloud role names, which assumes the default vendor install directory. Confirm the actual install, log and backup paths on each server and substitute them; a server installed under a different path returns zero on those queries, which is a scoping gap, not a negative. Host-level scoping never relies on a hostname containing "armatura" — it uses the population of hosts listening on the OpenWire port.

#### Hypotheses and Hunt Procedures

**Hypothesis 1:** An external actor can reach an internet-facing Armatura One server or its embedded ActiveMQ OpenWire listener, observable as an exposed ActiveMQ or Armatura One service in passive internet-scan indices. Execute FIRST; its output scopes the internal hypotheses.

**MITRE ATT&CK:** Reconnaissance | T1595 — Active Scanning | defender-side passive discovery of what an actor enumerating vulnerable ActiveMQ brokers would find; Initial Access | T1190 — Exploit Public-Facing Application | an exposed OpenWire listener is directly exploitable without authentication; ICS | T0883 — Internet Accessible Device | an access control server reachable from the internet is an internet-accessible control asset.

**Verdict criteria:** Positive — an owned, two-engine-corroborated OpenWire, ActiveMQ console or Armatura One interface on a public IP; Negative — no owned hit across the full public IP and cloud inventory AND the unscoped control returns a non-zero population; Non-Conclusive — the unscoped control returns 0, or part of the inventory was not searched (first page only, rate-limited, no API key); missing coverage prevents determining exposure for those ranges.

**Control** — unscoped population: run \`product:"ActiveMQ OpenWire transport"\` unscoped first and record the count. A filter that matches nothing unscoped is unvalidated, so its scoped zero means nothing. Record whether results were paged to completion. A port number is a guess, not a protocol: require the OpenWire banner, not only port 61616. Treat honeypot-tagged hits as unattributed.

**Collection Queries** — passive external indices (STRICTLY passive; never probe, port scan, banner grab or fetch from target infrastructure; API keys referenced by env-var name only: SHODAN\_API\_KEY, CENSYS\_API\_SECRET, CENSYS\_ORG\_ID, NETLAS\_API\_KEY):

**Shodan** (primary) — author unscoped first to prove the filter matches ActiveMQ, then scope with one anchor per query:

`product:"ActiveMQ OpenWire transport"`

 

`product:"ActiveMQ OpenWire transport" net:<your_public_CIDR>`

 

`product:"ActiveMQ OpenWire transport" asn:AS<your_ASN>`

 

`port:8161 http.title:"Apache ActiveMQ" net:<your_public_CIDR>`

 

`// paid tier only; otherwise version-triage the banner manually vuln:CVE-2023-46604 net:<your_public_CIDR>`

 

`// CLI form (key read from SHODAN_API_KEY by the shodan client; never pass it inline) shodan search --fields ip_str,port,org,hostnames,product,version 'product:"ActiveMQ OpenWire transport" net:<your_public_CIDR>'`

 

**Censys** (CenQL — current form; never the legacy services.\* form):

`host.services: (port = "61616" and banner: "ActiveMQ")`

 

`host.services: (port = "61616" and banner: "ActiveMQ") and (host.autonomous_system.asn = <your_ASN> or host.ip: "<your_public_CIDR>")`

 

`host.services.endpoints.http.html_title: "Apache ActiveMQ" and host.ip: "<your_public_CIDR>"`

 

Netlas (tie-breaker):

`host:<your_public_CIDR> AND port:(61616 OR 8161)`

 

Armatura One web client: derive the management UI title string and favicon hash from an instance you own (re-using an index-computed hash, never fetching /favicon.ico from a target), then add an http.title / favicon clause to each engine scoped to your anchors.

Cross-reference every exposed service and version against the CISA Known Exploited Vulnerabilities catalog (https://www.cisa.gov/known-exploited-vulnerabilities-catalog); CVE-2023-46604 is KEV-listed with known ransomware use, so any in-range match is a presumptive ransomware initial-access risk.

**Analysis Queries:**

- Attribute each hit with at least two independent ownership signals (PTR record, ASN, TLS certificate CN/SAN, RDAP registrant, the organization's own cloud and IP inventory) before reporting; an unattributable hit is inconclusive, not negative.
- Version-triage each OpenWire banner against the affected ActiveMQ range and record the index scan timestamp; a banner older than the hunt window is a prompt to verify current state, not evidence of safety.
- Corroborate each owned hit in at least two of Shodan, Censys and Netlas before escalating; absence from an index means only that the index did not observe the host.
- Historical pivot: use each engine's host history to establish whether the exposure spans any part of the period since October 2023; continuous exposure across that period means the host should be presumed enumerated by mass-exploitation campaigns.
- Pivot every confirmed-owned exposed instance into Hypotheses 2 through 4 as a priority target and hunt it exhaustively; internet reachability of a physical access control server is a finding in its own right under NERC CIP-006 and IEC 62443, independent of confirmed exploitation.

**Hypothesis 2:** An unauthenticated attacker has exploited CVE-2023-46604 against the embedded ActiveMQ OpenWire listener of an Armatura One server, observable as the Java broker process loading a remote Spring XML configuration and spawning command shells, msiexec, PowerShell or download utilities in EDR process telemetry, Windows Security and Sysmon logs, and OpenWire network traffic.

**MITRE ATT&CK:** Initial Access | T1190 — Exploit Public-Facing Application | the OpenWire deserialization flaw is reached over the network before authentication; Execution | T1059.001 / T1059.003 — PowerShell / Windows Command Shell | observed exploitation launches shell commands from the broker process; Defense Evasion | T1218.007 — Msiexec | HelloKitty operators loaded remote MSI payloads disguised as PNG files via msiexec (Rapid7 reporting).

**Verdict criteria:** Positive — the Java broker process spawning a shell, msiexec or download utility outside a maintenance window, Spring application-context class names in OpenWire traffic, or a YARA hit on the exploit rules; Negative — none across the window AND the broker-visibility control returns the broker AND the data floor precedes the window start; Non-Conclusive — the broker is not visible in telemetry (no sensor on the server, or a floor later than the window); missing process telemetry prevents determining whether the broker was exploited.

**Control** — broker visibility on the same scope (the family is matched as a regex so that a long-running broker started before the window still appears):

`#event_simpleName=/ProcessRollup2/ event_platform=Win | FileName = /^javaw?\.exe$/i | join({#event_simpleName=NetworkListenIP4 | LocalPort = "61616"}, field=aid, key=aid, mode=inner) | head(1)`

 

**Collection Queries:**

**CrowdStrike Falcon LogScale** (CQL) — child processes spawned by a Java runtime on Windows hosts (the ActiveMQ broker runs inside java.exe/javaw.exe):

`#event_simpleName=ProcessRollup2 event_platform=Win | ParentBaseFileName = /^javaw?\.exe$/i | FileName = /^(cmd|powershell|pwsh|msiexec|certutil|bitsadmin|curl|wget|rundll32|regsvr32|mshta|wscript|cscript|whoami|net|net1)\.exe$/i | table([@timestamp, ComputerName, UserName, ParentBaseFileName, FileName, CommandLine, SHA256HashData], limit=1000)`

 

→ Expected Positive shape: java.exe or javaw.exe on a host listening on 61616, with a child such as cmd.exe, powershell.exe or msiexec.exe whose command line fetches a remote resource or runs reconnaissance (whoami, net).

**CrowdStrike Falcon LogScale** (CQL) — msiexec pulling a remote package (HelloKitty pattern, M2.png / M4.png):

`#event_simpleName=ProcessRollup2 event_platform=Win | FileName = /^msiexec\.exe$/i | CommandLine = /https?:\/\//i | table([@timestamp, ComputerName, UserName, ParentBaseFileName, CommandLine], limit=1000)`

 

**CrowdStrike Falcon LogScale** (CQL) — hosts listening on the ActiveMQ OpenWire and console ports (population of brokers, including Armatura One servers):

`#event_simpleName=NetworkListenIP4 | in(LocalPort, values=["61616", "8161"]) | groupBy([ComputerName, aid, LocalPort], function=count(as=cnt), limit=100000)`

 

**CrowdStrike Falcon LogScale** (CQL) — inbound connections accepted on the OpenWire port, by remote source:

`#event_simpleName=NetworkReceiveAcceptIP4 | LocalPort = "61616" | groupBy([ComputerName, RemoteAddressIP4], function=count(as=cnt), limit=100000) | sort(cnt, order=asc, limit=1000)`

 

BPF packet capture (tcpdump) on the span/tap facing the Armatura One server — rolling capture of OpenWire and console traffic:

`tcpdump -i eth1 -nn -s 0 -w '/var/pcap/armatura_openwire_%Y%m%d_%H%M%S.pcap' -G 3600 -C 500 '(host <armatura_server_ip> and (tcp port 61616 or tcp port 8161)) or (vlan and host <armatura_server_ip> and (tcp port 61616 or tcp port 8161))'`

 

`# outbound HTTP/HTTPS initiated by the server (remote Spring XML and payload retrieval) tcpdump -i eth1 -nn -s 0 -w '/var/pcap/armatura_egress_%Y%m%d_%H%M%S.pcap' -G 3600 '(src host <armatura_server_ip> and (tcp port 80 or tcp port 443 or tcp port 8080) and tcp[tcpflags] & tcp-syn != 0) or (vlan and src host <armatura_server_ip> and (tcp port 80 or tcp port 443 or tcp port 8080) and tcp[tcpflags] & tcp-syn != 0)' # VLAN two-branch form throughout: on a tagged trunk an untagged filter captures 0 frames; pair a host-scoped capture with a short unscoped control recording`

 

**Datadog Log Search** — Windows process creation forwarded from Sysmon (EID 1) on the Armatura One server:

`// time range: 2026-07-04T00:00Z to current source:windows @evt.id:1 @Event.EventData.Data.ParentImage:*java* (@Event.EventData.Data.Image:*cmd.exe OR @Event.EventData.Data.Image:*powershell.exe OR @Event.EventData.Data.Image:*msiexec.exe OR @Event.EventData.Data.Image:*certutil.exe)`

 

`// time range: 2026-07-04T00:00Z to current source:windows @evt.id:1 @Event.EventData.Data.Image:*msiexec.exe "http"`

 

**Datadog CloudTrail** — Armatura One servers hosted on AWS EC2: security-group changes opening the broker port:

`// time range: 2026-07-04T00:00Z to current source:cloudtrail @evt.name:(AuthorizeSecurityGroupIngress OR ModifySecurityGroupRules) "61616"`

 

**Datadog Live Process Monitoring** (Infrastructure \> Processes — not a log source):

`// time range: live (current process snapshot) command:java user:SYSTEM // fallback where Live Process Monitoring is not enabled: the source:windows Sysmon EID 1 search above`

 

**Windows Event IDs to collect:** 4688 (process creation with command line), Sysmon 1 (process creation), Sysmon 3 (network connection), Sysmon 11 (file create), 7045 (service installed), 4697 (service installed — Security log), 1033/1040/11707 (MsiInstaller — Application log).

`Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4688; StartTime=(Get-Date).AddDays(-90)} | Where-Object { $_.Message -match 'java(w)?\.exe' } | Select-Object TimeCreated, Id, Message | Export-Csv -NoTypeInformation C:\Hunt\armatura_4688_java_children.csv`

 

`Get-WinEvent -FilterHashtable @{LogName='Application'; ProviderName='MsiInstaller'; StartTime=(Get-Date).AddDays(-90)} | Select-Object TimeCreated, Id, Message | Export-Csv -NoTypeInformation C:\Hunt\armatura_msiinstaller.csv`

 

**OT Data Collection: Claroty xDome** — Network → Communication → Communication Analysis: Side A any device, Communication: Port = 61616, Side B the Armatura One server; Time Frame Past Month; export CSV. Communication Analysis is capped at about one month, so this leg covers one month of the 90-day window — state that next to any zero. Repeat with the server on Side A and Communication Type = Internet (External) to list its external peers.

**OT Data Collection: Claroty CTD** — on the on-prem CTD appliance, open the Armatura One server asset, review its Network/Communications view for 61616 peers, and export the per-alert PCAP for any threat alert on the asset (CTD retains PCAP locally; xDome does not).

**OT Data Collection: Dragos Platform** — Communications Hub: destination = Armatura One server AND destination port 61616 over 30 days; pivot each session to its asset record and Export PCAP for window from SiteStore.

**OT Data Collection: Nozomi Guardian** — N2QL via the Open API:

`links | where to == "<armatura_server_ip>" | join nodes from ip | select from to protocol transferred_bytes | sort transferred_bytes desc // our Nozomi KB documents no port field on links; select every peer of the server and filter the OpenWire sessions by port in the export`

 

**OT Data Collection: Armis Centrix (ASQ)** — connections to the OpenWire port and the Armatura device population:

`in:ipConnections serverPort:61616,8161`

 

`in:devices brand:"Armatura" // brand is the hardware maker, so this returns Armatura-branded door controllers and readers, NOT the Armatura One server (a generic Windows server whose brand is its hardware vendor)`

 

**OT Data Collection: Tenable OT** — Inventory → All Assets filtered to the Armatura One server, then Events filtered to the asset across the window; download per-event PCAPs from the Events page.

**OT Data Collection: Forescout eyeInspect** — GET /api/v1/alerts with dst\_ip=\<armatura\_server\_ip\> and dst\_port=61616 for the hunt window; retrieve each alert PCAP by alert\_id where sensor capture is enabled.

**YARA file-system scan** — staged Spring XML exploit configurations and MSI payloads on the Armatura One server:

`yara -r rules/armatura_activemq_exploit.yar C:\ProgramData\ C:\Users\ C:\Windows\Temp\ >> C:\Hunt\yara_file_hits.txt`

 

**Analysis Queries:**

**CrowdStrike Falcon LogScale** (CQL) — outbound connections made by a Java process (reverse join: process-rollup main, filtered NetworkConnectIP4 subquery). The family is matched as a regex so SyntheticProcessRollup2 is included: the broker is a long-running service, and a pinned ProcessRollup2 returns zero for a broker that started before the window. Run over the longest retained window (preferably 1 year):

`#event_simpleName=/ProcessRollup2/ event_platform=Win | FileName = /^javaw?\.exe$/i | join({#event_simpleName=NetworkConnectIP4 | in(RemotePort, values=["80", "443", "8080"]) | !cidr(RemoteAddressIP4, subnet=["10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16"])}, field=[aid, TargetProcessId], key=[aid, ContextProcessId], mode=inner, include=[RemoteAddressIP4, RemotePort]) | groupBy([ComputerName, RemoteAddressIP4, RemotePort], function=count(as=cnt), limit=100000) | sort(cnt, order=asc, limit=1000)`

 

**CrowdStrike Falcon LogScale** (CQL) — rarity of Java child processes across the fleet (rare = suspicious):

`#event_simpleName=ProcessRollup2 event_platform=Win | ParentBaseFileName = /^javaw?\.exe$/i | groupBy([FileName], function=[count(as=cnt), count(ComputerName, distinct=true, as=hosts)], limit=100000) | sort(cnt, order=asc, limit=100)`

 

**Wireshark display filters and tshark equivalents** — OpenWire exploitation (the exploit sends an ExceptionResponse, OpenWire type 31, whose class name points at a Spring application-context loader):

`tcp.port == 61616 && frame contains "ClassPathXmlApplicationContext"`

 

`tcp.port == 61616 && frame contains "FileSystemXmlApplicationContext"`

 

`openwire.type == 31`

 

`http.request.method == "GET" && http.request.uri matches "\\.(xml|png)$" && ip.src == <armatura_server_ip>`

 

`tshark -r armatura_openwire.pcap -Y 'tcp.port == 61616 && frame contains "XmlApplicationContext"' -T fields -e frame.time -e ip.src -e ip.dst -e tcp.srcport`

 

`tshark -r armatura_egress.pcap -Y 'http.request && ip.src == <armatura_server_ip>' -T fields -e frame.time -e ip.dst -e http.host -e http.request.uri`

 

**Datadog Log Analytics** — Java child-process rarity (mirrors the CQL groupBy):

`// time range: 2026-07-04T00:00Z to current source:windows @evt.id:1 @Event.EventData.Data.ParentImage:*java* // Use Top List view; group by @Event.EventData.Data.Image; sort ascending for rarest-first. Second query in Table view; group by host, @Event.EventData.Data.Image`

 

**Datadog Audit Trail** — changes to monitors or log pipelines covering the Armatura One server during the hunt window (defense-evasion check):

`// time range: 2026-07-04T00:00Z to current source:datadog @evt.name:Monitor @action:(modified OR deleted)`

 

**Datadog Monitor definition:**

`Type: Log Alert Query: source:windows @evt.id:1 @Event.EventData.Data.ParentImage:*java* (@Event.EventData.Data.Image:*cmd.exe OR @Event.EventData.Data.Image:*powershell.exe OR @Event.EventData.Data.Image:*msiexec.exe) Evaluation window: last 5 minutes Alert condition: count > 0 Message: "ALERT: Java broker process on an Armatura One server spawned a shell or msiexec — possible CVE-2023-46604 exploitation @pagerduty-soc" Prerequisites: Sysmon EID 1 collected on Armatura One servers and forwarded to Datadog as source:windows Create via: Monitors > New Monitor > Log Alert OR POST /api/v1/monitors`

 

**Windows Event Log PowerShell analysis** — Sysmon network connections by java.exe to non-RFC1918 destinations:

`Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=3; StartTime=(Get-Date).AddDays(-90)} | Where-Object { $_.Message -match 'Image: .*\\javaw?\.exe' -and $_.Message -notmatch 'DestinationIp: (10\.|192\.168\.|172\.(1[6-9]|2[0-9]|3[01])\.)' } | Select-Object TimeCreated, Message | Export-Csv -NoTypeInformation C:\Hunt\armatura_java_egress.csv`

 

OT network analysis: compare the 61616 peer set from the OT platform exports against the documented Armatura One architecture (management clients and door controllers only); any peer outside that set, any external peer, and any session immediately followed by an outbound HTTP request from the server is a candidate exploitation sequence.

**YARA memory scan** — Java broker process memory for Spring XML exploit remnants (classic YARA 4.5; PID is the positional target):

`Get-Process java,javaw -ErrorAction SilentlyContinue | ForEach-Object { yara rules/armatura_activemq_exploit.yar $_.Id >> C:\Hunt\yara_mem_hits.txt } // CrowdStrike Falcon RTR can push the rule file and run the same command remotely on in-scope hosts`

 

**Hypothesis 3:** An attacker or malicious insider has recovered Armatura One database or message-broker credentials through the hard-coded AES key and IV (CVE-2026-94591), the vendor-defined superuser password (CVE-2026-94592) or plain-text backup and broker logs (CVE-2026-94593, CVE-2026-94594), observable as reads of the installation configuration and log files by unexpected processes, database client utilities run on or against the server, and database logons from unexpected sources.

**MITRE ATT&CK:** Credential Access | T1552.001 — Unsecured Credentials: Credentials In Files | the configuration file and logs hold recoverable or plain-text credentials; Persistence / Privilege Escalation | T1078.001 — Valid Accounts: Default Accounts | the vendor-defined superuser password functions as a default account; Collection | T1005 — Data from Local System | cardholder and access-level data harvested from the database.

**Verdict criteria:** Positive — a credential-bearing file readable by non-administrators or shared outside the organization, the vendor-defined superuser password still in use, a database session from a host outside the documented administration set, or a record change with no operator session; Negative — none of these AND the field-presence and auditing controls return rows; Non-Conclusive — SACL auditing is not enabled on the install, log and backup directories, or command lines are not collected; missing file-access telemetry prevents determining whether credentials were read.

**Control** — field presence (a family control does not cover a field filter): the command-line legs filter on CommandLine, so prove that the field is populated on the servers; the object-access legs need EID 4663 to exist at all.

`#event_simpleName=/ProcessRollup2/ event_platform=Win | join({#event_simpleName=NetworkListenIP4 | LocalPort = "61616"}, field=aid, key=aid, mode=inner) | CommandLine = /./ | count()`

 

`source:windows @evt.id:4663 // time range: 2026-07-04T00:00Z to current — zero here means SACL auditing is off, which makes every 4663 leg Non-Conclusive`

 

**Collection Queries:**

**CrowdStrike Falcon LogScale** (CQL) — database client and dump utilities executed on any host:

`#event_simpleName=ProcessRollup2 event_platform=Win | FileName = /^(psql|pg_dump|pg_dumpall|pg_restore|sqlcmd|osql|mysql|mysqldump)\.exe$/i | table([@timestamp, ComputerName, UserName, ParentBaseFileName, FileName, CommandLine], limit=1000)`

 

→ Expected Positive shape: a database dump or client utility run by an account, or at a time, that no scheduled backup explains, especially with the superuser named on the command line.

**CrowdStrike Falcon LogScale** (CQL) — command lines touching Armatura configuration or log files:

`#event_simpleName=ProcessRollup2 event_platform=Win | CommandLine = /armatura/i | CommandLine = /(\.log|\.properties|\.conf|\.cfg|\.ini|\.xml|backup|restore|password)/i | table([@timestamp, ComputerName, UserName, FileName, CommandLine], limit=1000)`

 

**CrowdStrike Falcon LogScale** (CQL) — archives written on the Armatura One server (possible support-bundle or log staging):

`#event_simpleName=/^(ZipFileWritten|SevenZipFileWritten|RarFileWritten)$/ | TargetFileName = /armatura/i | table([@timestamp, ComputerName, TargetFileName], limit=1000)`

 

**BPF packet capture** — database traffic to the Armatura One server from any source (substitute the database port from the installation configuration):

`tcpdump -i eth1 -nn -s 0 -w '/var/pcap/armatura_db_%Y%m%d_%H%M%S.pcap' -G 3600 '(dst host <armatura_server_ip> and tcp port <armatura_db_port> and tcp[tcpflags] & tcp-syn != 0) or (vlan and dst host <armatura_server_ip> and tcp port <armatura_db_port> and tcp[tcpflags] & tcp-syn != 0)'`

 

**Datadog Log Search** — Windows Security object access (EID 4663) on Armatura configuration and log paths (requires SACL auditing on the install directory):

`// time range: 2026-07-04T00:00Z to current source:windows @evt.id:4663 @Event.EventData.Data.ObjectName:*Armatura*`

 

`// time range: 2026-07-04T00:00Z to current source:windows @evt.id:1 (@Event.EventData.Data.Image:*psql.exe OR @Event.EventData.Data.Image:*pg_dump.exe OR @Event.EventData.Data.Image:*sqlcmd.exe)`

 

**Datadog CloudTrail** — Armatura One backups or support bundles stored in S3 being read from unexpected principals:

`// time range: 2026-07-04T00:00Z to current source:cloudtrail @evt.name:(GetObject OR CopyObject) "armatura" -@network.client.ip:10.* -@network.client.ip:172.16.* -@network.client.ip:192.168.*`

 

**Windows Event IDs to collect:** 4663 (object access — SACL on install, log and backup directories), 4656 (handle requested), 4624/4625 (logons to the server, LogonType 3 and 10), 4648 (explicit credential use), 5140/5145 (network share access to the server).

`Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4663; StartTime=(Get-Date).AddDays(-90)} | Where-Object { $_.Message -match 'Armatura' } | Select-Object TimeCreated, Message | Export-Csv -NoTypeInformation C:\Hunt\armatura_4663_file_access.csv`

 

`Get-WinEvent -FilterHashtable @{LogName='Security'; Id=@(5140,5145); StartTime=(Get-Date).AddDays(-90)} | Where-Object { $_.Message -match 'Armatura|backup' } | Select-Object TimeCreated, Id, Message | Export-Csv -NoTypeInformation C:\Hunt\armatura_share_access.csv`

 

**OT Data Collection: Claroty xDome** — Communication Analysis with Side B = the Armatura One server and Communication: Port = the database port; Time Frame Past Month; any Side A other than the server itself and documented administration hosts is a candidate.

**OT Data Collection: Dragos Platform** — Communications Hub: destination = Armatura One server AND destination port = database port over 30 days; flag sources outside the documented administration hosts.

**YARA file-system scan** — plain-text credential exposure in Armatura One logs, backups and support bundles (exposure check for CVE-2026-94593 and CVE-2026-94594):

`yara -r rules/armatura_log_credentials.yar "C:\Program Files\Armatura" D:\Backups\Armatura\ \\fileserver\support-bundles\ >> C:\Hunt\yara_logcred_hits.txt`

 

**Analysis Queries:**

**CrowdStrike Falcon LogScale** (CQL) — database utilities run on hosts other than the Armatura One server (credential reuse from another system):

`#event_simpleName=ProcessRollup2 event_platform=Win | FileName = /^(psql|pg_dump|pg_dumpall|sqlcmd|mysql|mysqldump)\.exe$/i | groupBy([ComputerName, UserName, FileName], function=[count(as=cnt), min(@timestamp, as=first_seen), max(@timestamp, as=last_seen)], limit=100000) | sort(cnt, order=asc, limit=500)`

 

**CrowdStrike Falcon LogScale** (CQL) — interactive and network logons to Armatura One servers by account and source (scoped to hosts listening on the OpenWire port, not to a hostname convention):

`#event_simpleName=UserLogon event_platform=Win | join({#event_simpleName=NetworkListenIP4 | LocalPort = "61616"}, field=aid, key=aid, mode=inner) | in(LogonType, values=["3", "10"]) | groupBy([ComputerName, UserName, LogonType, RemoteAddressIP4], function=count(as=cnt), limit=100000) | sort(cnt, order=asc, limit=500)`

 

**Wireshark display filters** — database sessions to the server (pgsql dissector shown; substitute the protocol in use):

`ip.dst == <armatura_server_ip> && tcp.port == <armatura_db_port> && tcp.flags.syn == 1 && tcp.flags.ack == 0`

 

`pgsql.type == "Startup message" && ip.dst == <armatura_server_ip>`

 

`tshark -r armatura_db.pcap -Y 'pgsql.type == "Startup message"' -T fields -e frame.time -e ip.src -e pgsql.parameter_value`

 

**Datadog Log Analytics** — object access to Armatura paths by account:

`// time range: 2026-07-04T00:00Z to current source:windows @evt.id:4663 @Event.EventData.Data.ObjectName:*Armatura* // Use Table view; group by @Event.EventData.Data.SubjectUserName, @Event.EventData.Data.ProcessName; time range last 90 days`

 

**Datadog Audit Trail** — log-archive or sensitive-data-scanner changes that could expose ingested Armatura logs (plain-text credentials in forwarded logs):

`// time range: 2026-07-04T00:00Z to current source:datadog @evt.name:("Organization Management" OR "Access Management") @action:(created OR modified)`

 

**Datadog Monitor definition:**

`Type: Log Alert Query: source:windows @evt.id:1 (@Event.EventData.Data.Image:*pg_dump.exe OR @Event.EventData.Data.Image:*pg_dumpall.exe OR @Event.EventData.Data.Image:*psql.exe) Evaluation window: last 15 minutes Alert condition: count > 0 Message: "ALERT: Database client or dump utility executed — check against Armatura One maintenance window @slack-soc-alerts" Prerequisites: Sysmon EID 1 forwarded from Armatura One servers and administration hosts as source:windows Create via: Monitors > New Monitor > Log Alert OR POST /api/v1/monitors`

 

**Windows Event Log PowerShell analysis** — non-system accounts reading Armatura log and configuration files:

`Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4663; StartTime=(Get-Date).AddDays(-90)} | Where-Object { $_.Message -match 'Armatura' -and $_.Message -notmatch 'Account Name:\s+(SYSTEM|LOCAL SERVICE|NETWORK SERVICE)' } | Select-Object TimeCreated, Message | Export-Csv -NoTypeInformation C:\Hunt\armatura_nonsystem_reads.csv`

 

OT network analysis: compare database-port peers in the OT platform exports with the documented administration hosts; a database session from a door-controller subnet, a user workstation or an external address indicates credential reuse.

Access control audit correlation: export the Armatura One operator audit log and cardholder change history for the window and correlate with database sessions; record changes with no matching operator session (direct database modification) indicate superuser abuse.

Exposure state check (per server, with the system owner): record whether configuration-file credential encryption is enabled — under CVE-2026-94591 a server without it holds the database and broker credentials unencrypted — and whether the database superuser still uses the vendor-defined password (CVE-2026-94592). Both answers set the severity of every credential finding in this hypothesis.

**YARA memory scan** — not applicable to this hypothesis (credential recovery is file-based); rely on the file-system scan above and on Hypothesis 2 memory scans for the broker process.

**Hypothesis 4:** An attacker who has gained code execution or database access on an Armatura One server has used it to manipulate physical access control or to move laterally into corporate, OT or building systems, observable as credential dumping, new services or scheduled tasks, ransomware staging, and unexpected access-control record changes in EDR telemetry, Windows logs, OT monitoring platforms and the access control audit trail.

**MITRE ATT&CK:** Credential Access | T1003.001 — OS Credential Dumping: LSASS Memory | post-exploitation of ActiveMQ has been followed by credential theft before ransomware deployment; Lateral Movement | T1021.002 — Remote Services: SMB/Windows Admin Shares | ransomware operators spread from the broker host; Impact | T1486 — Data Encrypted for Impact | HelloKitty and TellYouThePass ransomware were deployed after CVE-2023-46604 exploitation; ICS | T0831 — Manipulation of Control | altering door schedules, access levels or credentials changes physical outcomes.

**Verdict criteria:** Positive — credential-dump tooling or LSASS access on a server or peer, a new service, account or scheduled task with no change record, shadow-copy deletion, SMB/RDP/WinRM originating from the server, or a physical-access change with no operator session; Negative — none across the window AND both family controls return rows; Non-Conclusive — a control returns 0, or the access-control audit trail is not exported; missing telemetry prevents determining whether the server was used to pivot or to change physical access.

**Control** — family presence on the servers and their peers (both must exist before their zero means anything):

`#event_simpleName=NetworkConnectIP4 | join({#event_simpleName=NetworkListenIP4 | LocalPort = "61616"}, field=aid, key=aid, mode=inner) | head(1)`

 

`#event_simpleName=ServiceStarted | head(1)`

 

**Collection Queries:**

**CrowdStrike Falcon LogScale** (CQL) — LSASS access and dump tooling on Armatura One servers and their peers:

`#event_simpleName=ProcessRollup2 event_platform=Win | CommandLine = /(sekurlsa|lsadump|comsvcs\.dll.*MiniDump|procdump.*lsass|ntdsutil.*ifm)/i | table([@timestamp, ComputerName, UserName, ParentBaseFileName, FileName, CommandLine], limit=1000)`

 

→ Expected Positive shape: any row. These command-line fragments have no routine administrative use on an access-control server.

**CrowdStrike Falcon LogScale** (CQL) — services created on hosts that listen on the OpenWire port:

`#event_simpleName=ServiceStarted | join({#event_simpleName=NetworkListenIP4 | LocalPort = "61616"}, field=aid, key=aid, mode=inner) | table([@timestamp, ComputerName, ServiceDisplayName, ImageFileName], limit=1000)`

 

**CrowdStrike Falcon LogScale** (CQL) — shadow-copy deletion and recovery inhibition (ransomware precursor):

`#event_simpleName=ProcessRollup2 event_platform=Win | CommandLine = /(vssadmin.*delete\s+shadows|wmic.*shadowcopy.*delete|bcdedit.*recoveryenabled\s+no|wbadmin.*delete\s+catalog)/i | table([@timestamp, ComputerName, UserName, FileName, CommandLine], limit=1000)`

 

**BPF packet capture** — SMB, RDP and WinRM originating from the Armatura One server:

`tcpdump -i eth1 -nn -s 0 -w '/var/pcap/armatura_lateral_%Y%m%d_%H%M%S.pcap' -G 3600 -C 500 '(src host <armatura_server_ip> and (tcp port 445 or tcp port 3389 or tcp port 5985 or tcp port 5986)) or (vlan and src host <armatura_server_ip> and (tcp port 445 or tcp port 3389 or tcp port 5985 or tcp port 5986))'`

 

**Datadog Log Search** — new services and scheduled tasks on the Armatura One server:

`// time range: 2026-07-04T00:00Z to current source:windows (@evt.id:7045 OR @evt.id:4698) host:<armatura_server_hostname>`

 

`// time range: 2026-07-04T00:00Z to current source:windows @evt.id:1 (@Event.EventData.Data.CommandLine:*vssadmin* OR @Event.EventData.Data.CommandLine:*shadowcopy*)`

 

**Datadog CloudTrail** — instance credential use from an EC2-hosted Armatura One server against other AWS resources:

`// time range: 2026-07-04T00:00Z to current source:cloudtrail @userIdentity.sessionContext.sessionIssuer.userName:*armatura* @evt.name:(ListBuckets OR GetSecretValue OR DescribeInstances OR CreateUser)`

 

**Windows Event IDs to collect:** 4624 (LogonType 3/10 originating from the server), 4648 (explicit credentials), 4672 (special privileges), 4698 (scheduled task created), 7045 (service installed), 4720 (user account created), 4732 (member added to local group), 1102 (audit log cleared), Sysmon 10 (process access — LSASS).

`Get-WinEvent -FilterHashtable @{LogName='Security'; Id=@(4720,4732,4698,1102); StartTime=(Get-Date).AddDays(-90)} | Select-Object TimeCreated, Id, Message | Export-Csv -NoTypeInformation C:\Hunt\armatura_persistence.csv`

 

`Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=10; StartTime=(Get-Date).AddDays(-90)} | Where-Object { $_.Message -match 'TargetImage: .*\\lsass\.exe' } | Select-Object TimeCreated, Message | Export-Csv -NoTypeInformation C:\Hunt\armatura_lsass_access.csv`

 

**OT Data Collection: Claroty xDome** — Alerts & Threats → Alerts → All Alerts, filter to Threat Alert and the Armatura One server; and Communication Analysis with Side A = the server and Side B Purdue Level 1–3, to list any flows from the access control server into the control network.

**OT Data Collection: Dragos Platform** — Notifications filtered to Lateral Movement (T0859/T0867) with the Armatura One server as source; Communications Hub: source = server AND protocol IN \[RDP, SMB, SSH\] over 30 days.

**OT Data Collection: Nozomi Guardian** — segmentation-violation query from the canonical template, filtered to the server as source:

`links | where from == "<armatura_server_ip>" | where from_zone != to_zone | join nodes to ip | select from to protocol to_zone transferred_bytes | sort transferred_bytes desc`

 

**OT Data Collection: Tenable OT** — Network → Network Map, drill from the Armatura One server to the Purdue levels it reached; Events filtered to the server for the window.

**OT Data Collection: Forescout eyeInspect** — GET /api/v1/alerts with src\_ip=\<armatura\_server\_ip\> for the hunt window; review host changelog for door controllers communicating with the server.

**OT Data Collection: Armis Centrix (ASQ)** — outbound remote-access protocols from the server:

`in:ipConnections protocol:RDP,SMB,SSH endpointA:(device:(ipAddress:10.50.10.20))`

 

`in:ipConnections protocol:RDP,SMB,SSH endpointB:(device:(ipAddress:10.50.10.20)) // 10.50.10.20 = illustrative Armatura One server IP; substitute yours. Run both sides — our ASQ KB does not document which endpoint is the initiator`

 

**SNMP polling** — switch port facing the Armatura One server and door-controller uplinks (SNMPv3 preferred; v1/v2c community access to these assets is itself a finding):

`snmpwalk -v3 -l authPriv -u <user> -a SHA-256 -A <authpass> -x AES-256 -X <privpass> <switch_ip> IF-MIB::ifTable`

 

`snmpget -v3 -l authPriv -u <user> -a SHA-256 -A <authpass> -x AES-256 -X <privpass> <switch_ip> IF-MIB::ifHCInOctets.<ifIndex> IF-MIB::ifHCOutOctets.<ifIndex> IF-MIB::ifInErrors.<ifIndex> IF-MIB::ifOutErrors.<ifIndex>`

 

`snmpwalk -v2c -c <community> <door_controller_ip> system # poll every 60 seconds during the hunt window and diff successive values; flag any sysUpTime reset on controllers and spikes on the server-facing port`

 

SNMP traps: from the trap receiver, filter the hunt window for coldStart (1.3.6.1.6.3.1.1.5.1) and warmStart (1.3.6.1.6.3.1.1.5.2) from door controllers, linkDown/linkUp (1.3.6.1.6.3.1.1.5.3 / .4) on the server-facing port, and authenticationFailure (1.3.6.1.6.3.1.1.5.5) from any access-control asset.

**YARA file-system scan** — ransomware staging and dropped tooling on the server and its peers:

`yara -r rules/armatura_activemq_exploit.yar C:\ProgramData\ C:\Users\Public\ >> C:\Hunt\yara_staging_hits.txt`

 

**Analysis Queries:**

**CrowdStrike Falcon LogScale** (CQL) — SMB and RDP connections initiated by hosts that also listen on the OpenWire port:

`#event_simpleName=NetworkConnectIP4 | in(RemotePort, values=["445", "3389", "5985", "5986"]) | join({#event_simpleName=NetworkListenIP4 | LocalPort = "61616"}, field=aid, key=aid, mode=inner) | groupBy([ComputerName, RemoteAddressIP4, RemotePort], function=count(as=cnt), limit=100000) | sort(cnt, order=desc, limit=500)`

 

**Wireshark display filters** — lateral movement from the server:

`ip.src == <armatura_server_ip> && smb2.cmd == 3 && smb2.tree contains "ADMIN$"`

 

`ip.src == <armatura_server_ip> && (rdp || tcp.port == 3389)`

 

`ip.src == <armatura_server_ip> && (bacnet || bvlc)`

 

`tshark -r armatura_lateral.pcap -Y 'smb2.cmd == 5' -T fields -e frame.time -e ip.dst -e smb2.filename`

 

**Datadog Log Analytics** — accounts created or added to groups on the server:

`// time range: 2026-07-04T00:00Z to current source:windows (@evt.id:4720 OR @evt.id:4732) host:<armatura_server_hostname> // Use Table view; group by @Event.EventData.Data.TargetUserName, @Event.EventData.Data.SubjectUserName; time range last 90 days`

 

**Datadog Audit Trail** — API keys or users created around the time of a suspected compromise:

`// time range: 2026-07-04T00:00Z to current source:datadog @evt.name:"Access Management" @action:created`

 

**Datadog Monitor definition:**

`Type: Log Alert Query: source:windows @evt.id:7045 host:<armatura_server_hostname> Evaluation window: last 5 minutes Alert condition: count > 0 Message: "ALERT: New service installed on Armatura One server — review for post-exploitation persistence @pagerduty-soc" Prerequisites: Windows System log (EID 7045) forwarded from Armatura One servers as source:windows Create via: Monitors > New Monitor > Log Alert OR POST /api/v1/monitors`

 

**Windows Event Log PowerShell analysis** — outbound logons from the server to other hosts:

`Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4648; StartTime=(Get-Date).AddDays(-90)} | Select-Object TimeCreated, @{n='Target';e={$_.Properties[8].Value}}, @{n='Account';e={$_.Properties[5].Value}} | Export-Csv -NoTypeInformation C:\Hunt\armatura_explicit_creds.csv`

 

Access control and alarm correlation: export the Armatura One event history (door forced, door held, access granted outside schedule, credential added, access-level changed, alarm acknowledged) for the window and correlate with the suspicious process or network timeline; any physical-access change within a short interval of a Java child process or database session is a high-priority finding. Where the access control system integrates with a BACnet building management system or a SCADA alarm server, correlate alarm suppression or acknowledgement events from those systems against the same timeline.

**YARA memory scan** — credential dumping tooling in process memory on the server and its peers (Windows hosts; requires SeDebugPrivilege; CrowdStrike Falcon RTR can execute remotely):

`Get-Process | ForEach-Object { yara rules/credential_dump_tools.yar $_.Id 2>$null } >> C:\Hunt\yara_creddump_hits.txt`

 

#### Threat Actor Profile

Ransomware operators: HelloKitty and TellYouThePass operators exploited CVE-2023-46604 from October 2023 to gain initial access, then delivered ransomware via remote MSI payloads (HelloKitty disguised them as M2.png and M4.png and loaded them with msiexec) or Java and .NET loaders. Sophistication is moderate; the access path is any network-reachable OpenWire listener, and TTPs include msiexec remote loading, credential dumping, shadow-copy deletion and SMB-based spread.

Opportunistic financially motivated actors: Kinsing cryptomining operators and other botnet operators mass-scan for exposed ActiveMQ brokers and exploit them automatically to deploy miners and remove competing malware. Sophistication is low to moderate; the access path is internet exposure, and TTPs include curl or wget payload retrieval, scheduled persistence and process-killing scripts.

Remote access trojan operators and state-aligned groups: exploitation of the same flaw was observed delivering SparkRAT from at least October 10, 2023, before public disclosure (Arctic Wolf reporting), and AhnLab ASEC reported activity it assessed as consistent with the Andariel group. Per the threat-actor KB's attribution caveats, this is a vendor assessment of overlapping activity, not a government attribution, and should be carried that way into any report. These actors seek durable access rather than immediate impact, making a physical access control server an attractive, rarely monitored foothold.

Insiders and contractors: the hard-coded credential weaknesses CVE-2026-94591 through CVE-2026-94594 require local file or operating system access, which places integrators, support staff and administrators with access to installation packages, backups or support bundles in scope. Sophistication is low; the outcome is undetected manipulation of cardholder records or access levels.

#### Data Sources Required

**Network:** full packet capture or span/tap on the Armatura One server segment (OpenWire, database, HTTP egress, SMB/RDP), NetFlow/IPFIX for the access control VLAN, and firewall logs for the boundary between the access control zone, corporate network and internet.

**Endpoint:** CrowdStrike Falcon telemetry (ProcessRollup2, NetworkConnectIP4, NetworkListenIP4, NetworkReceiveAcceptIP4, ServiceStarted, UserLogon, archive file-written events) on Armatura One servers and administration hosts; Windows Security log with command-line process auditing (4688) and SACL object auditing (4663) on install, log and backup directories; Sysmon (EIDs 1, 3, 10, 11); Windows System and Application logs (7045, MsiInstaller).

OT/ICS and physical security: Armatura One operator audit log, cardholder change history and door event history; any integrated building management or SCADA alarm server; OT monitoring platform data (Claroty xDome or CTD, Dragos, Nozomi Guardian, Armis Centrix, Tenable OT, Forescout eyeInspect) covering the access control network; switch SNMP counters and trap receiver logs for server and door-controller ports.

Cloud and SIEM: Datadog log ingestion of the Windows sources above, Datadog Audit Trail, and AWS CloudTrail where Armatura One servers or their backups are cloud-hosted.

External attack surface: Shodan, Censys and Netlas passive indices queried read-only; the CISA Known Exploited Vulnerabilities catalog; and the organization's authoritative public IP and cloud asset inventories, which are required to attribute any exposed host — without them the exposure determination cannot be made.

Vendor and asset records: Armatura One version inventory per server (to separate V4.7.2 / V4.6.1\_USA and later from affected builds), installation configuration file locations, and the list of backup and support-bundle destinations.

#### Detection Signatures

SIGMA rules:

`title: Java Broker Process Spawning Shell or Msiexec on Windows id: 3f6b2a1c-8d4e-4b7a-9c2e-1a5f0d7e6b31 status: experimental description: Detects a Java runtime (such as the Apache ActiveMQ broker embedded in Armatura One) spawning a command shell, PowerShell, msiexec or download utility, consistent with CVE-2023-46604 exploitation. references: - https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-01 - https://nvd.nist.gov/vuln/detail/CVE-2023-46604 author: 1898 & Co. date: 2026-10-02 tags: - attack.initial-access - attack.t1190 - attack.execution - attack.t1059 - cve.2023-46604 logsource: category: process_creation product: windows detection: selection_parent: ParentImage|endswith: - '\java.exe' - '\javaw.exe' selection_child: Image|endswith: - '\cmd.exe' - '\powershell.exe' - '\pwsh.exe' - '\msiexec.exe' - '\certutil.exe' - '\bitsadmin.exe' - '\curl.exe' - '\mshta.exe' - '\rundll32.exe' condition: selection_parent and selection_child falsepositives: - Vendor maintenance scripts launched by the Java service during documented upgrades level: high`

 

`title: Java Process Outbound HTTP to Public Address on Access Control Server id: 7c2e9b4d-1a3f-4e6b-8d5c-2f0a9e7b4c12 status: experimental description: Detects a Java process making an outbound connection to a public IP on common web ports, consistent with the broker retrieving a remote Spring XML configuration after CVE-2023-46604 exploitation. references: - https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-01 author: 1898 & Co. date: 2026-10-02 tags: - attack.command-and-control - attack.t1105 - cve.2023-46604 logsource: category: network_connection product: windows detection: selection: Image|endswith: - '\java.exe' - '\javaw.exe' Initiated: 'true' DestinationPort: - 80 - 443 - 8080 filter_private: DestinationIp|cidr: - '10.0.0.0/8' - '172.16.0.0/12' - '192.168.0.0/16' - '127.0.0.0/8' condition: selection and not filter_private falsepositives: - Vendor update or licensing checks from the Armatura One service; baseline and allowlist the documented vendor endpoints level: medium`

 

`title: Msiexec Installing Remote Package Disguised as Image id: 9a4d1e7b-3c6f-4a2e-b8d1-5e0c7f9a2b44 status: experimental description: Detects msiexec loading a remote package whose URL ends in an image extension, the delivery pattern used by HelloKitty ransomware operators after CVE-2023-46604 exploitation. references: - https://nvd.nist.gov/vuln/detail/CVE-2023-46604 author: 1898 & Co. date: 2026-10-02 tags: - attack.defense-evasion - attack.t1218.007 logsource: category: process_creation product: windows detection: selection: Image|endswith: '\msiexec.exe' CommandLine|contains: 'http' selection_ext: CommandLine|re: '(?i)\.(png|jpg|gif|bmp)(\s|"|$)' condition: selection and selection_ext falsepositives: - None expected; legitimate MSI packages are not served with image extensions level: high`

 

`title: Archive Created in Armatura One Installation Tree by Non-Service Process id: 5b8e2c6a-4f1d-4d9e-a7c3-0e6b2d8f1a57 status: experimental description: Detects a non-service process creating an archive or backup file in the Armatura One installation tree (possible credential or log staging), where configuration and logs hold recoverable or plain-text credentials (CVE-2026-94591, CVE-2026-94593, CVE-2026-94594). references: - https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-01 author: 1898 & Co. date: 2026-10-02 tags: - attack.credential-access - attack.t1552.001 logsource: category: file_event product: windows detection: selection: TargetFilename|contains: '\Armatura' TargetFilename|endswith: - '.zip' - '.7z' - '.rar' - '.bak' filter_service: Image|endswith: - '\java.exe' - '\javaw.exe' condition: selection and not filter_service falsepositives: - Administrator-initiated backups and vendor support-bundle generation during documented maintenance level: medium`

 

**Snort/Suricata rules:**

`alert tcp any any -> $HOME_NET 61616 (msg:"LOCAL ActiveMQ OpenWire ExceptionResponse with Spring ClassPathXmlApplicationContext - CVE-2023-46604 exploitation attempt"; flow:to_server,established; content:"ClassPathXmlApplicationContext"; nocase; reference:cve,2023-46604; classtype:attempted-admin; sid:1000101; rev:1; metadata:affected_product Armatura_One, created_at 2026_10_02;)`

 

`alert tcp any any -> $HOME_NET 61616 (msg:"LOCAL ActiveMQ OpenWire ExceptionResponse with Spring FileSystemXmlApplicationContext - CVE-2023-46604 exploitation attempt"; flow:to_server,established; content:"FileSystemXmlApplicationContext"; nocase; reference:cve,2023-46604; classtype:attempted-admin; sid:1000102; rev:1; metadata:affected_product Armatura_One, created_at 2026_10_02;)`

 

`alert http $ARMATURA_SERVERS any -> $EXTERNAL_NET any (msg:"LOCAL Armatura One server Java client fetching remote XML - CVE-2023-46604 Spring config retrieval"; flow:to_server,established; http.method; content:"GET"; http.user_agent; content:"Java/"; startswith; http.uri; content:".xml"; endswith; nocase; reference:cve,2023-46604; classtype:trojan-activity; sid:1000103; rev:2; metadata:affected_product Armatura_One, created_at 2026_10_02;)`

 

`alert http $ARMATURA_SERVERS any -> $EXTERNAL_NET any (msg:"LOCAL Armatura One server Windows Installer fetching image-named package - HelloKitty MSI delivery"; flow:to_server,established; http.user_agent; content:"Windows Installer"; http.uri; pcre:"/\.(png|jpg|gif|bmp)$/i"; reference:cve,2023-46604; classtype:trojan-activity; sid:1000105; rev:1; metadata:affected_product Armatura_One, created_at 2026_10_02;)`

 

`// define $ARMATURA_SERVERS in suricata.yaml address-groups as the Armatura One server addresses; the user-agent anchors (Java's HTTP client for the Spring config, Windows Installer for msiexec) keep ordinary browser image fetches from matching`

 

`alert tcp $EXTERNAL_NET any -> $HOME_NET 61616 (msg:"LOCAL Inbound connection to ActiveMQ OpenWire port from external network"; flow:to_server; flags:S; threshold:type limit, track by_src, count 1, seconds 3600; classtype:attempted-recon; sid:1000104; rev:1; metadata:affected_product Armatura_One, created_at 2026_10_02;)`

 

YARA rules:

The first rule targets the file-system artifacts of the exploitation stage: the Spring XML application-context file that the broker is coerced into fetching and the MSI payloads disguised as images. The condition requires a Spring beans declaration together with a process-launching construct, so ordinary Spring configuration files without command execution do not match; the MSI branch requires the OLE compound-file header at offset 0 together with a loader string so that legitimate installers are excluded.

`rule Armatura_ActiveMQ_Exploit_Spring_XML_Payload { meta: description = "Spring XML application-context payload or image-disguised MSI used in CVE-2023-46604 exploitation of embedded ActiveMQ" author = "1898 & Co." date = "2026-10-02" reference = "https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-01" strings: $s_beans = "http://www.springframework.org/schema/beans" ascii nocase // Spring beans namespace $s_pb = "java.lang.ProcessBuilder" ascii nocase // command execution bean $s_start = "start" ascii // init-method that launches the process $s_cmd1 = "cmd.exe" ascii nocase // Windows shell in constructor-arg $s_cmd2 = "powershell" ascii nocase // PowerShell in constructor-arg $s_cmd3 = "/bin/bash" ascii // Linux shell in constructor-arg $h_ole = { D0 CF 11 E0 A1 B1 1A E1 } // OLE compound file header (MSI) $s_loader = "dllloader" ascii wide nocase // .NET loader name reported in HelloKitty MSI payloads condition: ($s_beans and $s_pb and $s_start and any of ($s_cmd*)) or ($h_ole at 0 and $s_loader) }`

 

The second rule targets process memory of the Java broker after exploitation, where deserialized class names, the remote configuration URL and the launched command persist in heap strings. Apache ActiveMQ is itself configured through Spring, so Spring class names alone are expected in a healthy broker; the condition therefore requires a Spring application-context class name, ProcessBuilder AND a remote XML URL together. Validate the rule against a known-clean broker process on the same Armatura One build before relying on it — a hit on the clean baseline means the rule does not discriminate on that build and its hits must be triaged manually.

`rule Armatura_ActiveMQ_Exploit_Memory_Artifacts { meta: description = "In-memory remnants of CVE-2023-46604 exploitation within a Java ActiveMQ broker process" author = "1898 & Co." date = "2026-10-02" reference = "https://nvd.nist.gov/vuln/detail/CVE-2023-46604" strings: $c1 = "org.springframework.context.support.ClassPathXmlApplicationContext" ascii wide // gadget class from exploit $c2 = "org.springframework.context.support.FileSystemXmlApplicationContext" ascii wide // alternate gadget class $p1 = "java.lang.ProcessBuilder" ascii wide // execution bean $r1 = /https?:\/\/[a-z0-9\.\-:]{4,80}\/[^\s"']{0,120}\.xml/ ascii wide nocase // remote XML config URL condition: any of ($c*) and $p1 and $r1 }`

 

The third rule checks Armatura One logs, backups and support bundles for plain-text credential strings, which supports exposure assessment for CVE-2026-94593 and CVE-2026-94594. It requires a database or broker connection context alongside a password assignment, so generic log lines mentioning the word password do not match; hits should be handled as sensitive and not copied into tickets.

`rule Armatura_Log_Plaintext_Credentials { meta: description = "Plain-text database or broker credentials in Armatura One backup, restore or broker logs" author = "1898 & Co." date = "2026-10-02" reference = "https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-01" strings: $ctx1 = /(psql|pg_dump|pg_restore|jdbc:[a-z]+:\/\/)/ ascii nocase // database connection command or JDBC URL $ctx2 = /(brokerurl|tcp:\/\/[0-9\.]+:61616|openwire)/ ascii nocase // broker connection context $pw1 = /(password|passwd|pwd)\s*[=:]\s*[^\s,;]{4,}/ ascii nocase // password assignment with value $pw2 = /PGPASSWORD=[^\s]{4,}|postgres(ql)?:\/\/[^:\s\/]+:[^@\s]{4,}@/ ascii nocase // password in env var or connection URI (psql -W is a prompt flag and takes no value) condition: any of ($ctx*) and any of ($pw*) }`

 

The fourth rule is the standing credential-dumping memory rule required for any hypothesis involving lateral movement or credential access; it is scoped to Windows hosts (Armatura One servers and their administration peers) and requires SeDebugPrivilege to scan LSASS-adjacent processes. Each branch pairs a tool indicator with a second artifact so that a single generic string does not trigger a hit, and the catch-all branch requires a memory-read API, the LSASS name and at least one tool indicator together.

`rule Credential_Dump_Tool_Memory_Artifacts { meta: description = "Credential dumping tool artifacts in process memory: mimikatz, WCE, gsecdump, comsvcs MiniDump, generic LSASS readers" author = "1898 & Co." date = "2026-10-02" reference = "https://attack.mitre.org/techniques/T1003/001/" strings: $mk1 = "sekurlsa::logonpasswords" ascii wide nocase // mimikatz credential module $mk2 = "lsadump::sam" ascii wide nocase // mimikatz SAM dump $mk3 = "privilege::debug" ascii wide nocase // mimikatz debug privilege $mk4 = "mimikatz" ascii wide nocase // tool name $mkh = { 6D 69 6D 69 6B 61 74 7A } // "mimikatz" hex $wce = "wce.exe" ascii wide nocase // Windows Credential Editor $lsass = "lsass.exe" ascii wide nocase // LSASS target name $gsec = "gsecdump" ascii wide nocase // gsecdump tool name $md1 = "MiniDump" ascii wide // comsvcs export $md2 = "comsvcs" ascii wide nocase // comsvcs.dll $api1 = "NtReadVirtualMemory" ascii wide // memory-read API $api2 = "ReadProcessMemory" ascii wide // memory-read API condition: (2 of ($mk*)) or ($wce and $lsass) or $gsec or ($md1 and $md2 and $lsass) or (any of ($api*) and $lsass and (any of ($mk*) or $wce or $gsec or $md2)) }`

 

**YARA rule files:** rules/armatura\_activemq\_exploit.yar holds Armatura\_ActiveMQ\_Exploit\_Spring\_XML\_Payload and Armatura\_ActiveMQ\_Exploit\_Memory\_Artifacts; rules/armatura\_log\_credentials.yar holds Armatura\_Log\_Plaintext\_Credentials; rules/credential\_dump\_tools.yar holds Credential\_Dump\_Tool\_Memory\_Artifacts.

#### Indicators of Compromise

Network IOCs: inbound connections to the Armatura One OpenWire port (61616 by default) from any host outside the documented management clients and door controllers; OpenWire payloads containing ClassPathXmlApplicationContext or FileSystemXmlApplicationContext; outbound HTTP or HTTPS GET requests from the Armatura One server for .xml or image-named resources shortly after OpenWire sessions; outbound connections from the server to 45.32.120\[.\]181, an address reported deploying SparkRAT after CVE-2023-46604 exploitation; SMB, RDP or WinRM sessions initiated by the server.

Host IOCs: java.exe or javaw.exe spawning cmd.exe, powershell.exe, msiexec.exe, certutil.exe, curl.exe or similar; msiexec command lines referencing remote URLs ending in image extensions, including M2.png and M4.png; a .NET executable named dllloader; Spring XML files containing java.lang.ProcessBuilder in temporary or broker working directories; new services, scheduled tasks or local accounts on the server; shadow-copy deletion; LSASS access by non-system processes; database client or dump utilities executed outside maintenance windows; non-Armatura processes reading or archiving the installation configuration, backup or broker log files.

OT and physical-access IOCs: cardholder, access-level or door-schedule changes with no corresponding operator session; doors unlocked or schedules altered outside approved windows; alarm suppression or bulk acknowledgement; gaps or deletions in the access event history; door controllers rebooting (sysUpTime reset or coldStart traps) during the window; flows from the access control server into Purdue Level 1–3 networks.

External exposure IOCs: any owned public IP presenting an ActiveMQ OpenWire transport banner, an Apache ActiveMQ web console, or the Armatura One management interface in two or more passive indices; exposure history overlapping the period since October 2023; an exposed host absent from the organization's asset inventory (shadow infrastructure).

#### False Positive Baseline

- Armatura One upgrades and vendor maintenance: during documented upgrade windows the Java service and installer may legitimately spawn msiexec, cmd.exe or PowerShell; suppress by change ticket and time window, not by blanket process allowlist.
- Scheduled database backups: the Armatura One backup routine and administrator backup jobs legitimately invoke database dump utilities and write archives; baseline the scheduled task, account and time of day.
- Vendor licensing and update checks: the Armatura One service may contact documented vendor endpoints over HTTPS; allowlist those specific destinations after verification.
- Other ActiveMQ deployments: middleware, integration and monitoring platforms also embed ActiveMQ and listen on 61616; confirm each listener's host role before attributing activity to Armatura One, while still treating any unpatched broker as in scope.
- Support bundle generation: administrators may package logs for vendor support, producing archive writes in the install tree; correlate with a support case number and treat the bundle itself as credential-bearing.
- Internal vulnerability scanners: authorized scanners connect to 61616 and 8161 and may send OpenWire probes; suppress by scanner source IP and scan schedule.
- External-exposure misattribution: shared hosting, CDN or carrier addresses can appear in index results for the organization's ranges; do not report a hit as owned without two independent ownership signals.
- Cloud backup sync: legitimate backup agents reading Armatura backups in S3 generate GetObject events; baseline the role and source address.

#### Escalation Criteria

1\. Any Armatura One server running a version earlier than V4.7.2 (or V4.6.1\_USA) confirmed internet-reachable on its OpenWire, console or management port in two passive indices and attributed with two ownership signals.

2\. Exposure history for an owned Armatura One or ActiveMQ host that spans any period since October 2023, or an exposed host absent from the asset inventory.

3\. Any exposed service whose version matches a CISA KEV entry, including CVE-2023-46604.

4\. Any java.exe or javaw.exe process on an Armatura One server spawning a shell, msiexec, PowerShell or download utility outside a documented maintenance window.

5\. Any Snort/Suricata alert for sid 1000101 or 1000102 (Spring application-context class names in OpenWire traffic).

6\. Any connection from an Armatura One server to 45.32.120\[.\]181 or any msiexec command line loading a remote image-named package.

7\. Any YARA hit on Armatura\_ActiveMQ\_Exploit\_Spring\_XML\_Payload against files on an Armatura One server or its peers.

8\. Any YARA hit on Armatura\_ActiveMQ\_Exploit\_Memory\_Artifacts against a running java.exe or javaw.exe process on a build where the rule returned no hit on the known-clean baseline.

9\. Any YARA hit on Armatura\_Log\_Plaintext\_Credentials in a location accessible to non-administrative users, a shared file server or a support bundle sent to a third party (escalate for credential rotation and exposure review).

10\. Any YARA hit on Credential\_Dump\_Tool\_Memory\_Artifacts against any process on an Armatura One server or its administration peers.

11\. Any database session to the Armatura One database from a host outside the documented administration set, or use of the default superuser account after the vendor-defined password should have been changed.

12\. Any cardholder, access-level or door-schedule change without a matching operator session, or any deletion or gap in access event history.

13\. Any SMB, RDP or WinRM session, new service, new local account or shadow-copy deletion originating from or on an Armatura One server.

14\. Any flow from an Armatura One server into Purdue Level 1–3 networks not documented in the system architecture.

#### Hunt Completion Criteria and Reporting

The hunt is complete when: every Armatura One server has been inventoried with its version and patch status; the external-exposure sweep has run against the full public IP and cloud inventory in at least two engines with coverage gaps recorded; each of Hypotheses 2 through 4 has been executed across the full window for every in-scope server, exhaustively for any server found exposed in Hypothesis 1; all four YARA rules have been run against their target paths and processes; and every escalation condition has been dispositioned as Positive, Negative or Non-Conclusive. Report one verdict per hypothesis, using its Verdict criteria. A finding in a secondary leg does not downgrade the primary verdict, and a gap in our own collection (no SACL auditing, no Sysmon) is a coverage gap, never a Positive. A Non-Conclusive verdict reads "\<observation\>; missing \<input\> prevents determining \<question\>". A leg whose control returned 0 or was not run, and the part of the window before the data floor, are reported that way, never as clean. Make absence claims only from a single-predicate filter (filter for the indicator and count it), never by reading a distribution table. Quote only query results whose status reads Done. Record every limitation with its direction (for example, "no PCAP on the access-control VLAN — wire-level OpenWire confirmation unavailable, inbound and outbound").

The report must contain: the Armatura One asset inventory with version, exposure status and remediation owner; the external sweep coverage (engines, anchors, query timestamps) and per-hit provenance with ownership signals; per-hypothesis query results with row counts, time windows and any truncation or data-source gaps (for example missing Sysmon, no SACL auditing, no PCAP on the access control VLAN); YARA hits and dispositions; a timeline correlating process, network, database and physical access events for any suspicious server; credential-rotation status for the database superuser and broker accounts; and recommendations, including making the external exposure sweep and the Java child-process monitor recurring controls.

Escalation coverage: section 8 conditions 7 through 10 map one-to-one to the four YARA rules defined in section 5; any positive under these conditions moves the affected host to incident response.

#### Advisory IoC Reference

| IOC Type | IOC |
| --- | --- |
| CVE | CVE-2023-46604 \| CVSS v3.1 9.8 \| Armatura One \< V4.7.2; Armatura One (USA) \< V4.6.1\_USA (embedded Apache ActiveMQ) \| Unauthenticated OpenWire deserialization leading to code execution at highest privilege; CISA KEV-listed, exploited in the wild |
| CVE | CVE-2026-94591 \| CVSS v3.1 8.4 \| Armatura One \< V4.7.2; Armatura One (USA) \< V4.6.1\_USA \| Hard-coded AES-128-CBC key and IV shared across installations allow decryption of stored database and broker credentials |
| CVE | CVE-2026-94592 \| CVSS v3.1 8.4 \| Armatura One \< V4.7.2; Armatura One (USA) \< V4.6.1\_USA \| Vendor-defined database superuser password assigned at initialization |
| CVE | CVE-2026-94593 \| CVSS v3.1 7.8 \| Armatura One \< V4.7.2; Armatura One (USA) \< V4.6.1\_USA \| Backup and restore routine logs the superuser password in plain text |
| CVE | CVE-2026-94594 \| CVSS v3.1 4.0 \| Armatura One \< V4.7.2; Armatura One (USA) \< V4.6.1\_USA \| Message broker logs client credentials in plain text |
| Threat Actor | HelloKitty ransomware operators \| Ransomware \| CVEs: CVE-2023-46604 \| Primary TTPs: OpenWire exploitation, msiexec remote MSI loading, ransomware deployment |
| Threat Actor | TellYouThePass ransomware operators \| Ransomware \| CVEs: CVE-2023-46604 \| Primary TTPs: OpenWire exploitation, ransomware deployment |
| Threat Actor | Andariel (Lazarus subgroup) \| North Korea state-aligned \| CVEs: CVE-2023-46604 \| Primary TTPs: exploitation for remote access tooling delivery (public reporting) |
| Malware | HelloKitty \| Ransomware \| Deployed after CVE-2023-46604 exploitation via remote MSI payloads |
| Malware | TellYouThePass \| Ransomware \| Deployed after CVE-2023-46604 exploitation |
| Malware | Kinsing \| Cryptominer / botnet \| Mass exploitation of exposed ActiveMQ brokers for cryptomining |
| Malware | SparkRAT \| Remote access trojan \| Delivered after CVE-2023-46604 exploitation |
| Malware | dllloader \| .NET loader \| 32-bit .NET executable inside HelloKitty MSI payloads |
| Network IOC | IP: 45.32.120.181 (reported SparkRAT deployment after CVE-2023-46604 exploitation) |
| File IOC | Filename: M2.png (MSI payload disguised as image, loaded by msiexec) |
| File IOC | Filename: M4.png (MSI payload disguised as image, loaded by msiexec) |
| File IOC | No file hashes published in source material — monitor https://www.cisa.gov/known-exploited-vulnerabilities-catalog |
| Behavioral | java.exe or javaw.exe on an Armatura One server spawning cmd, powershell, msiexec, certutil or curl |
| Behavioral | OpenWire traffic to port 61616 containing ClassPathXmlApplicationContext or FileSystemXmlApplicationContext |
| Behavioral | Armatura One server issuing outbound HTTP GET for .xml or image-named resources after an OpenWire session |
| Behavioral | msiexec command line loading a remote URL ending in .png or other image extension |
| Behavioral | Database dump or client utility run against the Armatura One database outside a maintenance window |
| Behavioral | Non-Armatura process reading or archiving Armatura configuration, backup or broker log files |
| Behavioral | Cardholder, access-level or door-schedule change with no matching operator session |

[Threat Hunt](https://1898advisories.burnsmcd.com/tag/threat-hunt)

*The information in this cybersecurity advisory is provided "as is" for informational purposes only. 1898 & Co. does not provide any warranties or guarantees of any kind regarding this information. You assume all risks if you choose to rely on this information. In no event shall 1898 & Co. or its contractors or subcontractors be liable for any damages including, but not limited to, direct, indirect, special or consequential damages, arising out of, resulting from, or in any way connected with, this information, whether or not based upon warranty, contract, tort, or otherwise, whether or not arising out of negligence, and whether or not injury was sustained from, or arose out of the results of, or reliance upon the information*

*1898 & Co. does not endorse any product or service, except as expressly stated otherwise. Any reference to products or processes does not constitute or imply 1898 & Co.’s endorsement or recommendation.*

Subscribe

✕ Close

 

[Accessibility](https://1898andco.burnsmcd.com/accessibility)  |  [Privacy Statement](https://1898andco.burnsmcd.com/privacy)

© 2026 1898 & Co., a part of Burns & McDonnell. All Rights Reserved.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "The 1898 & Co. Team",
    "url" : "https://1898advisories.burnsmcd.com/author/1898-co-team"
  },
  "dateModified" : "2026-10-09T16:23:15.482Z",
  "datePublished" : "2026-10-09T16:23:15.000Z",
  "headline" : "Threat Hunt Plan: Armatura One Physical Access Control — Embedded ActiveMQ OpenWire Exploitation and Hard-Coded Credential Abuse",
  "mainEntityOfPage" : {
    "@id" : "https://1898advisories.burnsmcd.com/threat-hunt-plan-armatura-one-physical-access-control-embedded-activemq-openwire-exploitation-and-hard-coded-credential-abuse",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "//cdn2.hubspot.net/hub/477837/file-2585615236-jpg/Logo_1_Primary_2Color1.jpg"
    },
    "name" : "Burns & McDonnell Engineering Co"
  }
}
```