---
title: "Threat Hunt Plan: VIVOTEK Network Camera Firmware — Unauthenticated Command Injection and Post-Exploitation Pivot"
description: "Objective: determine whether any VIVOTEK network camera in the environment has been targeted or compromised through CVE-2026-22755"
---

[Skip to content](https://1898advisories.burnsmcd.com/threat-hunt-plan-vivotek-network-camera-firmware-unauthenticated-command-injection-and-post-exploitation-pivot-1#main-content)

![1898-logo-grey-R-1](https://1898advisories.burnsmcd.com/hs-fs/hubfs/1898-logo-grey-R-1.webp?width=188&height=100&name=1898-logo-grey-R-1.webp)

- [Cyberthreat](https://1898advisories.burnsmcd.com/tag/cyberthreat)
- [Threat Hunt](https://1898advisories.burnsmcd.com/tag/threat-hunt)
- [View All](https://1898advisories.burnsmcd.com/)

Open main navigation

Close main navigation

- [Cyberthreat](https://1898advisories.burnsmcd.com/tag/cyberthreat)
- [Threat Hunt](https://1898advisories.burnsmcd.com/tag/threat-hunt)
- [View All](https://1898advisories.burnsmcd.com/)
- [Contact us](https://1898andco.burnsmcd.com/contact-us)

[Contact us](https://1898andco.burnsmcd.com/contact-us)

 October 5, 2026

# Threat Hunt Plan: VIVOTEK Network Camera Firmware — Unauthenticated Command Injection and Post-Exploitation Pivot

![Picture of The 1898 & Co. Team](https://1898advisories.burnsmcd.com/hs-fs/hubfs/1898%20Cyberthreat%20Advisory%20Blog%20Assets/1898-Co-Ampersand.png?width=50&name=1898-Co-Ampersand.png) [The 1898 & Co. Team](https://1898advisories.burnsmcd.com/author/1898-co-team)

Date: 2026-10-02 | Revision 1.0 | Source: CISA ICS Advisory ICSA-26-272-03

#### Hunt Objective and Scope

Objective: determine whether any VIVOTEK network camera in the environment has been targeted or compromised through CVE-2026-22755 (CVSS v3.1 10.0, CVSS v4.0 10.0), an unauthenticated OS command injection in firmware modules shared across 37 camera models, and whether a compromised camera has been used as a pivot into adjacent IT or OT networks. A public proof-of-concept exploit exists (CISA SSVC exploitation status: PoC); no in-the-wild exploitation has been reported to CISA and the CVE is not in the KEV catalog at the time of writing.

Environment in scope: every VIVOTEK camera matching the affected model list (FD8365, FD8365v2, FD9165, FD9171, FD9187, FD9189, FD9365, FD9371, FD9381, FD9387, FD9389, FD9391, FE9180, FE9181, FE9191, FE9381, FE9382, FE9391, FE9582, IB9365, IB9371, IB9381, IB9387, IB9389, IB939, IB93587LPR, IP9165, IP9171, IP9172, IP9181, IP9191, IT9389, MA9321, MA9322, MS9321, MS9390, TB9330); the camera VLANs and the switch ports they attach to; video management system (VMS) and network video recorder (NVR) servers; administrative workstations and jump hosts that manage cameras; firewalls and proxies on the camera VLAN boundary; and any OT segment reachable from the camera network (substation, plant floor, pipeline station, building automation).

Time window: 90 days back from hunt start (2026-07-04 to current), extended to the earliest available firewall and NetFlow retention where cameras are internet-exposed, because the vulnerable code predates disclosure and the public proof of concept was available before CISA's 2026-09-29 publication.

Illustrative values used in queries: camera VLAN 10.20.30.0/24, VMS/NVR subnet 10.20.40.0/24. Replace both with the environment's actual camera and VMS ranges before running.

External attack-surface (EASM) hypothesis: INCLUDED. Network cameras are a canonical internet-exposed device class and the vulnerability is network-reachable without authentication, so Hypothesis 1 runs first and its output prioritizes the internal hypotheses.

#### Hypotheses and Hunt Procedures

**Hypothesis 1:** An external actor can reach an internet-facing VIVOTEK camera web, RTSP or management interface, observable as an exposed service in passive internet-scan indices. Execute FIRST; its output scopes Hypotheses 2 and 3.

**MITRE ATT&CK:** Reconnaissance | T1595 — Active Scanning | defender-side passive discovery of what an actor running the public proof of concept would enumerate · Initial Access | T1133 — External Remote Services | exposed camera management interfaces are a direct entry point · ICS | T0883 — Internet Accessible Device | a camera reachable from the internet at a critical facility is a finding in its own right.

**Collection Queries:**

**External Attack Surface** (EASM) — STRICTLY passive. Query third-party scan indices only; never port scan, banner grab, fetch a favicon or brute-force DNS against any target. API keys are referenced by environment variable name only (SHODAN\_API\_KEY, CENSYS\_API\_SECRET, CENSYS\_ORG\_ID, NETLAS\_API\_KEY); a missing key skips that engine and is recorded as a coverage gap. Run each query unscoped first to prove the filter matches the VIVOTEK population, then scoped to the organization's anchors (one anchor per query; never AND two anchors together).

`// Shodan — unscoped product validation (confirm the index's VIVOTEK product/title string before scoping) "VIVOTEK" http.title:"VIVOTEK"`

 

`// Shodan — RTSP banner form "VIVOTEK" port:554`

 

`// Shodan — scoped, one anchor per query (run each separately) http.title:"VIVOTEK" net:<your_public_CIDR> http.title:"VIVOTEK" org:"<Your Org Name>" http.title:"VIVOTEK" asn:AS<your_ASN>`

 

`// Shodan — paid tier only; otherwise rely on title/banner matching above vuln:CVE-2026-22755 net:<your_public_CIDR>`

 

`// Censys CenQL — CURRENT form (host.services.*); never the legacy services.* form host.services.software.vendor: "VIVOTEK"`

 

`// Censys CenQL — nested multi-criteria form, scoped host.services: (software.vendor: "VIVOTEK" and port = "443") and (host.autonomous_system.asn = <your_ASN> or host.ip: "<your_public_CIDR>")`

 

`// Censys CenQL — HTML title fallback where software attribution is absent host.services.endpoints.http.html_title: "VIVOTEK" and host.ip: "<your_public_CIDR>"`

 

`// Netlas — tie-breaker http.title:"VIVOTEK" host:<your_public_CIDR> AND port:(80 OR 443 OR 554 OR 8080)`

 

→ Cross-reference every exposed instance against the CISA Known Exploited Vulnerabilities catalog (https://www.cisa.gov/known-exploited-vulnerabilities-catalog) and against CVE-2026-22755; re-check KEV weekly during the hunt because a public PoC exists and KEV addition would raise priority.

**Analysis Queries:**

- Attribute each hit with at least two independent ownership signals (PTR record, ASN, TLS certificate CN/SAN, WHOIS/RDAP, the organization's own public IP and cloud inventory). Camera hits often sit on carrier or cellular ranges at remote sites, which breaks attribution in both directions; an unattributable hit is inconclusive, not negative.
- Record the model string, firmware banner (where present) and index scan timestamp for each hit; any listed model is presumed affected until confirmed on the latest VIVOTEK firmware, and a scan older than the hunt window is not evidence of current state.
- Corroborate each hit in at least two of Shodan, Censys and Netlas before escalating; absence from an index means only that the index did not observe the host.
- Historical pivot: establish whether each exposure spans the period since the public PoC appeared; continuous exposure means the device should be treated as presumptively enumerated.
- Feed every confirmed-owned exposed camera into Hypotheses 2 and 3 as a priority target and hunt it exhaustively; where the camera sits at an OT facility or shares a network with control systems, document the blast radius.

**Hypothesis 2:** An unauthenticated attacker has sent crafted HTTP requests containing OS command-injection payloads to a VIVOTEK camera web interface, observable as cgi-bin requests carrying shell metacharacters in firewall, proxy, WAF and packet data, and as exploit tooling executed on internal hosts in endpoint telemetry.

**MITRE ATT&CK:** Initial Access | T1190 — Exploit Public-Facing Application | CVE-2026-22755 is exploited over the camera's network service · Execution | T1059.004 — Command and Scripting Interpreter: Unix Shell | injected commands run in the camera's embedded Linux shell, potentially as root · ICS | T0866 — Exploitation of Remote Services | the camera is a networked device at the facility edge.

**Collection Queries:**

**CrowdStrike Falcon LogScale** (CQL) — internal hosts launching HTTP tooling against camera CGI paths with shell metacharacters (an attacker or pentest tool running the public PoC from an internal foothold):

`#event_simpleName=ProcessRollup2 | FileName = /^(curl|curl\.exe|wget|wget\.exe|python|python3|python\.exe|powershell\.exe|pwsh\.exe|pwsh)$/i | CommandLine = /cgi-bin/i | CommandLine = /(%3b|%7c|%60|%24%28|;|\||`|\$\()/i | table([@timestamp, ComputerName, UserName, FileName, ParentBaseFileName, CommandLine], limit=1000)`

 

**CrowdStrike Falcon LogScale** (CQL) — which processes on Falcon-managed hosts connect to the camera VLAN on web/RTSP ports (composite-key correlation of NetworkConnectIP4 to ProcessRollup2; NetworkConnectIP4 carries no ImageFileName):

`in(#event_simpleName, values=["ProcessRollup2", "NetworkConnectIP4"]) | case { #event_simpleName="NetworkConnectIP4" | cidr(RemoteAddressIP4, subnet=["10.20.30.0/24"]) | ProcKey := format("%s:%s", field=[aid, ContextProcessId]); #event_simpleName="ProcessRollup2" | ProcKey := format("%s:%s", field=[aid, TargetProcessId]); } | groupBy([ProcKey], function=[collect([ComputerName, ImageFileName, CommandLine, RemoteAddressIP4, RemotePort]), count(#event_simpleName, distinct=true, as=types)], limit=max) | types = 2`

 

**BPF / tcpdump** — rolling capture of all web and RTSP traffic to and from the camera VLAN at the camera VLAN uplink or a SPAN on the camera aggregation switch:

`tcpdump -i eth1 -nn -s 0 -G 3600 -C 500 -w /captures/vivotek_web_%Y%m%d_%H%M.pcap 'net 10.20.30.0/24 and (tcp port 80 or tcp port 443 or tcp port 8080 or tcp port 554)'`

 

`// Inbound HTTP requests to cameras from anything other than the VMS subnet (unexpected client population) tcpdump -i eth1 -nn -s 0 -w /captures/vivotek_unexpected_clients_%Y%m%d.pcap -G 86400 'dst net 10.20.30.0/24 and (tcp port 80 or tcp port 8080) and not src net 10.20.40.0/24'`

 

**Datadog Log Search** — firewall/WAF/proxy logs for camera-bound cgi-bin requests with encoded or literal shell metacharacters (requires firewall or reverse-proxy logs forwarded with URL fields):

`// time range: 2026-07-04T00:00Z to current source:(paloalto OR fortigate OR nginx) @network.destination.ip:10.20.30.* @http.url:*cgi-bin* (@http.url:*%3B* OR @http.url:*%7C* OR @http.url:*%60* OR @http.url:*%24%28*)`

 

**Datadog Log Search** — Windows process telemetry fallback for the CQL process query (Sysmon EID 1 forwarded via the Windows integration):

`// time range: 2026-07-04T00:00Z to current source:windows @evt.id:1 "cgi-bin" ("curl" OR "wget" OR "python" OR "Invoke-WebRequest")`

 

**Datadog Live Process Monitoring** (Infrastructure \> Processes — NOT a log source):

`command:curl user:root command:python3 cgi-bin`

 

// Data source gap: cameras cannot run the Datadog Agent; camera-side visibility depends entirely on network logs. If firewall URL logging is not forwarded, fall back to the source:windows query above and to PCAP.

**Datadog CloudTrail** — cloud-hosted VMS or camera cloud relays (security group changes exposing camera ports):

`// time range: 2026-07-04T00:00Z to current source:cloudtrail @evt.name:(AuthorizeSecurityGroupIngress OR ModifySecurityGroupRules) @requestParameters.ipPermissions.items.fromPort:(80 OR 443 OR 554 OR 8080)`

 

**Windows Event IDs to collect** (administrative workstations, jump hosts, VMS/NVR servers):

- 4688 — process creation with command line (curl/wget/python/PowerShell invoking camera URLs)
- 4104 — PowerShell script block logging (Invoke-WebRequest / Invoke-RestMethod to camera cgi-bin paths)
- 5156 — Windows Filtering Platform permitted connection (host to camera VLAN)
- Sysmon 1 — process creation; Sysmon 3 — network connection

`Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4688; StartTime=(Get-Date).AddDays(-90)} | Where-Object { $_.Message -match 'cgi-bin' } | Select-Object TimeCreated, Id, MachineName, Message | Export-Csv -NoTypeInformation C:\Hunt\vivotek_4688.csv`

 

`Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-PowerShell/Operational'; Id=4104; StartTime=(Get-Date).AddDays(-90)} | Where-Object { $_.Message -match 'cgi-bin' -and $_.Message -match '(Invoke-WebRequest|Invoke-RestMethod|iwr|irm)' } | Select-Object TimeCreated, MachineName, Message | Export-Csv -NoTypeInformation C:\Hunt\vivotek_4104.csv`

 

**OT Data Collection: Armis Centrix** — enumerate VIVOTEK devices and the clients that talk to their web/RTSP services; export CSV to seed the target population:

`in:devices brand:"VIVOTEK"`

 

`in:ipConnections endpointB:(device:(brand:"VIVOTEK")) serverPort:80,443,554,8080`

 

`in:ipConnections endpointA:(networkLocation:External) endpointB:(device:(brand:"VIVOTEK"))`

 

**OT Data Collection: Claroty xDome** — Devices → All Devices → Advanced Filters: Manufacturer = VIVOTEK → Export CSV to seed the Hypothesis 2 population; then Risk & Exposures → Vulnerabilities → All Vulnerabilities: filter CVEs = CVE-2026-22755 and record the affected devices; for each camera, open the device profile → Communications to confirm its peer set. API: POST /api/v1/devices/ and POST /api/v1/vulnerabilities/.

**OT Data Collection: Claroty CTD** — Assets view filtered to Vendor = VIVOTEK, export asset list; review the Network/Communications view for each camera's peers and pull PCAP for any non-VMS client from the on-premises CTD sensor (CTD retains PCAP locally, unlike xDome; confirm retention depth before relying on it).

**OT Data Collection: Dragos Platform** — Assets: scope to vendor VIVOTEK and export; Vulnerabilities view: filter to CVE-2026-22755 and note Now/Next/Never bucket; Communications Hub: destination = camera assets AND protocol IN \[HTTP, HTTPS, RTSP\] over 90d; export event PCAP for any session from a non-VMS source.

**OT Data Collection: Nozomi Guardian** — Asset view filtered to vendor VIVOTEK; Link view for each camera to enumerate client IPs and protocol mix; via API run N2QL to export the population for scripting:

`nodes | where vendor include? VIVOTEK | select ip mac_address vendor product_name firmware_version`

 

**OT Data Collection: Tenable OT** — Inventory → All Assets filtered to vendor = VIVOTEK, export; Risks → Findings filtered to CVE-2026-22755, carry every affected asset forward as a priority target.

**OT Data Collection: Forescout eyeInspect** — Command Center → Asset Inventory filtered to main\_vendor\_model matching VIVOTEK, export host list; pull Alerts for the camera IPs over the window (GET /api/v1/alerts with dst\_ip and start\_timestamp/end\_timestamp) and retrieve PCAP for each alert\_id where sensor capture is enabled.

**SNMP polling** — camera-facing switch ports and the cameras themselves (VIVOTEK cameras commonly expose an SNMP agent):

`snmpwalk -v2c -c <community> 10.20.30.1 IF-MIB::ifTable`

 

`snmpget -v2c -c <community> 10.20.30.1 IF-MIB::ifHCInOctets.<ifIndex> IF-MIB::ifHCOutOctets.<ifIndex> IF-MIB::ifInErrors.<ifIndex> IF-MIB::ifOutErrors.<ifIndex>`

 

`snmpwalk -v3 -l authPriv -u <user> -a SHA-256 -A <authpass> -x AES-256 -X <privpass> 10.20.30.50 system`

 

// Poll every 60 seconds during the hunt window and diff successive values; flag any camera sysUpTime reset with no change record, and treat any v1/v2c community-string access to cameras as a finding in its own right. Collect trap-receiver logs for the camera range and flag coldStart (1.3.6.1.6.3.1.1.5.1), warmStart (1.3.6.1.6.3.1.1.5.2), linkDown/linkUp (1.3.6.1.6.3.1.1.5.3 / .4) and authenticationFailure (1.3.6.1.6.3.1.1.5.5).

**YARA file-system scan** — exported firewall/proxy/WAF logs, VMS server web logs and HTTP objects carved from PCAP (tshark --export-objects http) for command-injection request artifacts:

`yara -r rules/vivotek_cmdinj.yar /hunt/exports/ >> /hunt/results/vivotek_cmdinj_hits.txt`

 

**Analysis Queries:**

**CrowdStrike Falcon LogScale** (CQL) — rarity of processes talking to cameras (anything other than the VMS client is suspicious):

`#event_simpleName=ProcessRollup2 | CommandLine = /10\.20\.30\./i | groupBy([FileName, ComputerName], function=count(as=execs), limit=max) | sort(execs, order=asc, limit=100)`

 

**CrowdStrike Falcon LogScale** (CQL) — timeline of the exploit-tooling hits for correlation with network evidence:

`#event_simpleName=ProcessRollup2 | CommandLine = /cgi-bin/i | CommandLine = /(wget|curl|tftp|busybox|nc |telnetd|chmod)/i | groupBy([ComputerName, UserName], function=[min(@timestamp, as=first_seen), max(@timestamp, as=last_seen), count(as=hits)], limit=max)`

 

**Wireshark display filters / tshark** — command-injection metacharacters in camera-bound HTTP requests (URI and POST body):

`http.request && ip.dst == 10.20.30.0/24 && http.request.uri contains "cgi-bin" && (http.request.uri matches "(?i)(%3b|%7c|%60|%24%28|;|\\||`|\\$\\()" || http contains "$(" || http contains "`")`

 

`tshark -r vivotek_web.pcap -Y 'http.request && ip.dst == 10.20.30.0/24 && http.request.uri contains "cgi-bin"' -T fields -e frame.time -e ip.src -e ip.dst -e http.request.method -e http.request.uri -e http.user_agent`

 

`tshark -r vivotek_web.pcap --export-objects http,/hunt/exports/http_objects`

 

**Datadog Log Analytics** — same base query as the Log Search above; use Table view; group by @network.client.ip, @network.destination.ip; time range 2026-07-04T00:00Z to current. Use Timeseries view grouped by @network.client.ip to identify bursts consistent with automated PoC scanning.

**Datadog Audit Trail** — confirm no one muted or deleted camera-network monitors during the window:

`// time range: 2026-07-04T00:00Z to current source:datadog @evt.name:Monitor @action:(deleted OR modified)`

 

**Datadog Monitor definition:**

`Type: Log Alert Query: source:(paloalto OR fortigate OR nginx) @network.destination.ip:10.20.30.* @http.url:*cgi-bin* (@http.url:*%3B* OR @http.url:*%7C* OR @http.url:*%60* OR @http.url:*%24%28*) Evaluation window: last 5 minutes Alert condition: count > 0 Message: "ALERT: possible CVE-2026-22755 command injection against a VIVOTEK camera — immediate investigation required @slack-ot-soc" Prerequisites: firewall or reverse-proxy logs for the camera VLAN forwarded to Datadog with URL attributes parsed into @http.url Create via: Monitors > New Monitor > Log Alert OR POST /api/v1/monitors`

 

**Windows Event Log PowerShell analysis** — summarize hosts and users issuing camera cgi-bin requests:

`Import-Csv C:\Hunt\vivotek_4688.csv | Group-Object MachineName | Sort-Object Count -Descending | Select-Object Name, Count | Export-Csv -NoTypeInformation C:\Hunt\vivotek_4688_by_host.csv`

 

**OT network and protocol analysis** — compare each camera's client set against its VMS/NVR baseline in the deployed OT platform (xDome Communication Analysis: Side A any, Side B Manufacturer = VIVOTEK, Protocol = HTTP, Time Frame Past 3 Months; Dragos Communications Hub; Nozomi Link view); any client outside the VMS subnet or the approved admin hosts is a candidate exploitation source. Correlate the timestamp of each candidate request with camera sysUpTime resets, video-loss events in the VMS and physical-security alarms (door forced, perimeter intrusion) logged to the SCADA alarm system or historian for the same site.

**YARA memory scan** — exploit tooling resident on admin/jump hosts (classic YARA 4.5; the PID is the positional target):

`Get-Process | Where-Object { $_.ProcessName -match '^(python|python3|pwsh|powershell|curl|wget)$' } | ForEach-Object { yara rules/vivotek_cmdinj.yar $_.Id } | Out-File -Append C:\Hunt\vivotek_mem_hits.txt`

 

// CrowdStrike Falcon Real Time Response (RTR) can push the rule file and run yara against remote hosts; Custom IOAs can alert on the CQL process pattern going forward.

**Hypothesis 3:** An attacker who has achieved root command execution on a VIVOTEK camera has used it to download second-stage payloads, establish command and control, or move laterally into IT or OT systems, observable as camera-initiated outbound connections, TFTP/HTTP payload retrieval and inbound connections from the camera VLAN to servers, workstations or control devices in firewall, NetFlow, OT-platform and endpoint telemetry.

**MITRE ATT&CK:** Command and Control | T1105 — Ingress Tool Transfer | IoT post-exploitation typically pulls a loader via wget, curl or tftp · Lateral Movement | T1021 — Remote Services | a compromised camera is a foothold from which SMB, RDP, SSH or WinRM sessions can be attempted · Credential Access | T1003 — OS Credential Dumping | credentials harvested from the camera or VMS are reused against Windows hosts · ICS | T0886 — Remote Services | pivot from the camera network into control-system segments.

**Collection Queries:**

**CrowdStrike Falcon LogScale** (CQL) — Falcon-managed hosts accepting inbound connections from the camera VLAN (cameras should not initiate sessions to servers or workstations):

`#event_simpleName=NetworkReceiveAcceptIP4 | cidr(RemoteAddressIP4, subnet=["10.20.30.0/24"]) | groupBy([ComputerName, LocalPort, RemoteAddressIP4], function=count(as=accepts), limit=max) | sort(accepts, order=desc, limit=200)`

 

**CrowdStrike Falcon LogScale** (CQL) — logons sourced from camera IPs:

`#event_simpleName=UserLogon | cidr(RemoteAddressIP4, subnet=["10.20.30.0/24"]) | table([@timestamp, ComputerName, UserName, LogonType, RemoteAddressIP4], limit=1000)`

 

**CrowdStrike Falcon LogScale** (CQL) — failed logons sourced from camera IPs (credential spraying from a camera foothold):

`#event_simpleName=UserLogonFailed2 | cidr(RemoteAddressIP4, subnet=["10.20.30.0/24"]) | groupBy([ComputerName, UserName, RemoteAddressIP4], function=count(as=failures), limit=max)`

 

**BPF / tcpdump** — camera-initiated traffic to anything other than the VMS subnet, NTP and DNS:

`tcpdump -i eth1 -nn -s 0 -G 3600 -C 500 -w /captures/vivotek_egress_%Y%m%d_%H%M.pcap 'src net 10.20.30.0/24 and not dst net 10.20.40.0/24 and not (udp port 123 or udp port 53)'`

 

`// Camera-initiated TFTP, Telnet and SYNs to lateral-movement ports tcpdump -i eth1 -nn -w /captures/vivotek_lateral_%Y%m%d.pcap -G 86400 'src net 10.20.30.0/24 and (udp port 69 or tcp port 23 or ((tcp[tcpflags] & tcp-syn != 0) and (tcp port 22 or tcp port 445 or tcp port 3389 or tcp port 5985 or tcp port 5986 or tcp port 502 or tcp port 44818 or tcp port 102)))'`

 

**Datadog Log Search** — firewall/NetFlow records of camera-initiated connections leaving the camera VLAN:

`// time range: 2026-07-04T00:00Z to current source:(paloalto OR fortigate OR netflow) @network.client.ip:10.20.30.* -@network.destination.ip:10.20.40.* -@network.destination.port:(53 OR 123)`

 

**Datadog Log Search** — Windows logons from camera IPs (fallback for the CQL logon queries):

`// time range: 2026-07-04T00:00Z to current source:windows @evt.id:(4624 OR 4625) @network.client.ip:10.20.30.*`

 

**Datadog Live Process Monitoring** (Infrastructure \> Processes — NOT a log source) on Linux VMS/NVR hosts:

`command:nc command:busybox`

 

// Data source gap: if NetFlow is not forwarded, use firewall session logs; if neither is available, PCAP at the camera VLAN uplink is the only camera-side evidence.

**Datadog CloudTrail** — cloud-hosted VMS instances reached from camera-originated traffic or with new access keys created after a camera-sourced logon:

`// time range: 2026-07-04T00:00Z to current source:cloudtrail @evt.name:(CreateAccessKey OR ConsoleLogin OR StartSession) -@network.client.ip:10.* -@network.client.ip:172.16.* -@network.client.ip:192.168.*`

 

**Windows Event IDs to collect** (all servers and workstations, VMS/NVR servers first):

- 4624 — successful logon (filter IpAddress in the camera VLAN; LogonType 3 and 10)
- 4625 — failed logon from camera IPs
- 4648 — explicit-credential logon
- 5140 / 5145 — network share access from camera IPs
- 4697 / 7045 — service installation following a camera-sourced logon

`Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4624,4625,4648; StartTime=(Get-Date).AddDays(-90)} | Where-Object { $_.Message -match 'Source Network Address:\s+10\.20\.30\.' } | Select-Object TimeCreated, Id, MachineName, Message | Export-Csv -NoTypeInformation C:\Hunt\vivotek_camera_logons.csv`

 

`Get-WinEvent -FilterHashtable @{LogName='System'; Id=7045; StartTime=(Get-Date).AddDays(-90)} | Select-Object TimeCreated, MachineName, Message | Export-Csv -NoTypeInformation C:\Hunt\vivotek_new_services.csv`

 

**OT Data Collection: Armis Centrix** — camera-initiated connections, external destinations and lateral-movement ports:

`in:ipConnections endpointA:(device:(brand:"VIVOTEK")) endpointB:(networkLocation:External)`

 

`in:ipConnections endpointA:(device:(brand:"VIVOTEK")) serverPort:22,23,69,445,3389,5985,5986`

 

`in:ipConnections endpointA:(device:(brand:"VIVOTEK")) serverPort:502,102,44818,20000,47808`

 

**OT Data Collection: Claroty xDome** — Network → Communication → Communication Analysis: Side A Manufacturer = VIVOTEK · Side B any Purdue level or External · Time Frame Past 3 Months; export every flow whose destination is not the VMS/NVR, NTP or DNS server. Alerts & Threats → Alerts → All Alerts filtered to the camera devices; row-click → export per-alert PCAP. Alerts & Threats → Threats → Malicious IPs cross-referenced against camera destinations.

**OT Data Collection: Claroty CTD** — Network view filtered to source = camera assets; export communications and baseline-deviation alerts for the window; retrieve sensor PCAP for any camera conversation with a non-VMS peer.

**OT Data Collection: Dragos Platform** — Communications Hub: source = camera assets AND destination zone IN \[Level 1, Level 2, Level 3, External\] AND protocol IN \[SMB, RDP, SSH, Telnet, TFTP, Modbus, EtherNet/IP, S7\] over 90d; Notifications filtered to the camera assets; open a Case on any hit and Export PCAP for window.

**OT Data Collection: Nozomi Guardian** — Link view filtered to camera source IPs; N2QL export of every link from the camera range to a non-VMS peer:

`links | where from in_subnet? 10.20.30.0/24 | where to in_subnet? 10.20.40.0/24 == false | select from to protocol first_activity_time last_activity_time`

 

**OT Data Collection: Tenable OT** — Network → Network Map: drill Asset Type → Vendor VIVOTEK → Asset to see which Purdue levels each camera reached; Events filtered to the camera assets for intrusion-detection and new-conversation events; download per-event PCAP.

**OT Data Collection: Forescout eyeInspect** — Alerts with src\_ip in the camera range (GET /api/v1/alerts with src\_ip, start\_timestamp, end\_timestamp); host changelog for the cameras to catch firmware\_version or os\_version transitions with no maintenance record.

**YARA file-system scan** — files carved from camera egress PCAP and any staging directories on VMS/NVR servers for IoT botnet loader artifacts:

`yara -r rules/iot_loader.yar /hunt/exports/http_objects/ >> /hunt/results/iot_loader_hits.txt`

 

`yara -r rules/iot_loader.yar /var/tmp/ /tmp/ /dev/shm/ >> /hunt/results/iot_loader_vms_hits.txt`

 

**Analysis Queries:**

**CrowdStrike Falcon LogScale** (CQL) — first-seen timeline of camera-sourced sessions per target host (a camera that suddenly starts talking to a server is the key signal):

`#event_simpleName=NetworkReceiveAcceptIP4 | cidr(RemoteAddressIP4, subnet=["10.20.30.0/24"]) | groupBy([ComputerName, RemoteAddressIP4, LocalPort], function=[min(@timestamp, as=first_seen), max(@timestamp, as=last_seen), count(as=sessions)], limit=max) | sort(first_seen, order=desc, limit=200)`

 

**CrowdStrike Falcon LogScale** (CQL) — credential-access follow-on on hosts that accepted camera-sourced sessions:

`#event_simpleName=ProcessRollup2 | CommandLine = /(sekurlsa|lsadump|comsvcs\.dll.*minidump|procdump.*lsass)/i | table([@timestamp, ComputerName, UserName, FileName, ParentBaseFileName, CommandLine], limit=1000)`

 

**Wireshark display filters / tshark** — camera egress, payload retrieval and OT protocol use (cameras should never speak industrial protocols):

`ip.src == 10.20.30.0/24 && !(ip.dst == 10.20.40.0/24) && !dns && !ntp`

 

`ip.src == 10.20.30.0/24 && (tftp || telnet || (http.request.method == "GET" && http.request.uri matches "(?i)\\.(sh|arm[5-7]?|mips|mpsl|x86|bin)$"))`

 

`ip.src == 10.20.30.0/24 && (modbus || enip || cip || s7comm || dnp3 || bacnet || opcua)`

 

`tshark -r vivotek_egress.pcap -Y 'ip.src == 10.20.30.0/24 && !(ip.dst == 10.20.40.0/24) && !dns && !ntp' -T fields -e frame.time -e ip.src -e ip.dst -e tcp.dstport -e udp.dstport -e http.host -e tls.handshake.extensions_server_name`

 

`tshark -r vivotek_egress.pcap -q -z conv,ip -Y 'ip.src == 10.20.30.0/24'`

 

**Datadog Log Analytics** — same base query as the egress Log Search; use Table view; group by @network.client.ip, @network.destination.ip, @network.destination.port; time range 2026-07-04T00:00Z to current. Use Top List view grouped by @network.destination.ip, sorted ascending, to surface rare destinations.

**Datadog Audit Trail** — API keys or users created around a camera-sourced session (credential abuse pivot):

`// time range: 2026-07-04T00:00Z to current source:datadog @evt.name:"Access Management" @action:created`

 

**Datadog Monitor definition:**

`Type: Log Alert Query: source:(paloalto OR fortigate OR netflow) @network.client.ip:10.20.30.* @network.destination.port:(22 OR 23 OR 69 OR 445 OR 3389 OR 5985 OR 5986 OR 502 OR 102 OR 44818) Evaluation window: last 5 minutes Alert condition: count > 0 Message: "ALERT: VIVOTEK camera initiating lateral-movement or OT-protocol connection — immediate investigation required @slack-ot-soc" Prerequisites: firewall session logs or NetFlow for the camera VLAN forwarded to Datadog with network attributes parsed Create via: Monitors > New Monitor > Log Alert OR POST /api/v1/monitors`

 

**Windows Event Log PowerShell analysis** — correlate camera-sourced logons with subsequent service installs on the same host:

`$logons = Import-Csv C:\Hunt\vivotek_camera_logons.csv; $svcs = Import-Csv C:\Hunt\vivotek_new_services.csv; $logons | ForEach-Object { $l = $_; $svcs | Where-Object { $_.MachineName -eq $l.MachineName -and [datetime]$_.TimeCreated -gt [datetime]$l.TimeCreated -and [datetime]$_.TimeCreated -lt ([datetime]$l.TimeCreated).AddHours(2) } } | Export-Csv -NoTypeInformation C:\Hunt\vivotek_logon_then_service.csv`

 

**OT network and protocol analysis** — baseline deviation: a camera's legitimate peer set is the VMS/NVR, NTP, DNS and the firmware update source. Flag any camera conversation to a Level 1–3 asset, any Modbus (function codes 5/6/15/16 writes), CIP (service codes 0x4C/0x4D read/write tag, 0x52 unconnected send) or S7 traffic sourced from a camera, and any new external destination. Correlate camera-sourced flows with SCADA alarms, historian process-variable excursions and VMS video-loss events at the same site and time.

**YARA memory scan** — credential-dumping tooling on Windows hosts that accepted camera-sourced sessions (requires SeDebugPrivilege; run via CrowdStrike RTR for remote hosts):

`Get-Process | ForEach-Object { yara rules/credential_dump.yar $_.Id } | Out-File -Append C:\Hunt\cred_dump_mem_hits.txt`

 

`// Linux VMS/NVR hosts: scan running processes for the loader rule for p in $(pgrep -f 'busybox|wget|tftp|nc '); do yara rules/iot_loader.yar $p; done >> /hunt/results/iot_loader_mem_hits.txt`

 

#### Threat Actor Profile

Opportunistic botnet operators (high likelihood): IoT botnet families have repeatedly weaponized camera command-injection flaws within days of public PoC release. Sophistication is low to moderate; access is via mass internet scanning for exposed camera interfaces; TTPs are automated exploitation, wget/tftp retrieval of architecture-specific loaders, persistence in writable flash or RAM, and use of the camera for DDoS, proxying or further scanning.

Ransomware and initial-access brokers (moderate likelihood): unmanaged IoT devices are attractive footholds because they carry no EDR. Sophistication is moderate; access is via exposed cameras or cameras reachable from a compromised IT host; TTPs are reverse shells from the camera, internal scanning, credential reuse against Windows hosts and VMS servers, and handoff to an operator for lateral movement.

Nation-state actors targeting critical infrastructure (lower likelihood, high impact): state-sponsored groups have used compromised edge and IoT devices, including cameras, as operational relay infrastructure and for reconnaissance of physical sites. Sophistication is high; access is via internet-exposed cameras at energy, transportation and government facilities; TTPs are quiet, low-volume command execution, use of the camera as a relay node, and observation of physical operations.

Hacktivists (moderate likelihood): groups targeting OT and physical-security systems have publicized compromised camera feeds for visibility. Sophistication is low; access is via internet exposure and public PoCs; TTPs are defacement, feed disruption and public disclosure of access.

Insider or contractor misuse (lower likelihood): integrators and security contractors with camera network access could run the public PoC against devices they service. TTPs are exploitation from approved admin hosts, which makes the Hypothesis 2 endpoint queries the primary detection.

#### Data Sources Required

**Network:** full packet capture or SPAN at the camera VLAN uplink; firewall session and URL/threat logs for the camera VLAN boundary; NetFlow/IPFIX from camera aggregation switches; reverse proxy or WAF logs where camera interfaces are published; DNS resolver logs for camera queries.

**Endpoint:** CrowdStrike Falcon telemetry (ProcessRollup2, NetworkConnectIP4, NetworkReceiveAcceptIP4, UserLogon, UserLogonFailed2) on VMS/NVR servers, admin workstations and jump hosts; Windows Security, System and PowerShell Operational logs; Sysmon EIDs 1 and 3 where deployed.

**OT/ICS:** OT monitoring platform inventories, communication maps, vulnerability matches and alert PCAP (Claroty CTD/xDome, Dragos, Nozomi, Armis, Tenable OT, Forescout eyeInspect); SCADA alarm logs and historian data for sites where cameras are installed; physical-security alarm logs (access control, perimeter intrusion).

**Vendor/device:** VMS/NVR event logs (camera offline, video loss, configuration changes); camera system logs exported through the VMS or camera web UI where retained; SNMP poll data and trap-receiver logs for cameras and their switch ports; firmware version records for each affected model.

Monitoring platform: Datadog log pipelines for firewall, NetFlow, Windows and CloudTrail sources; Datadog Audit Trail.

External attack surface: Shodan, Censys and Netlas, queried read-only; the CISA KEV catalog; the organization's authoritative public IP and cloud asset inventories, including carrier and cellular ranges used at remote sites. Without the public IP inventory, exposure cannot be attributed and the external determination cannot be made.

#### Detection Signatures

SIGMA rules:

`title: HTTP Tooling Sending Command Injection Payload to Camera CGI Path id: 8b7fbbff-f0b2-4282-91f8-e3f636f57c4b status: experimental description: Detects curl, wget, python or PowerShell command lines targeting a camera cgi-bin path with shell metacharacters, consistent with use of the public CVE-2026-22755 proof of concept from an internal host. references: - https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-03 author: 1898 & Co. date: 2026-10-02 tags: - attack.initial-access - attack.t1190 - cve.2026-22755 logsource: category: process_creation product: windows detection: selection_tool: Image|endswith: - '\curl.exe' - '\wget.exe' - '\python.exe' - '\powershell.exe' - '\pwsh.exe' selection_path: CommandLine|contains: '/cgi-bin/' selection_meta: CommandLine|contains: - '%3B' - '%7C' - '%60' - '%24%28' - ';wget' - ';curl' - '$(' condition: all of selection_* falsepositives: - Authorized penetration testing or vulnerability validation against cameras level: high`

 

`title: Inbound Remote Service Connection from Camera VLAN id: c059dd8d-954b-4224-a641-6e656027a39f status: experimental description: Detects a Windows host accepting an SMB, RDP, SSH or WinRM connection from the camera VLAN, indicating possible lateral movement from a compromised VIVOTEK camera. references: - https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-03 author: 1898 & Co. date: 2026-10-02 tags: - attack.lateral-movement - attack.t1021 logsource: category: network_connection product: windows detection: selection: Initiated: 'false' SourceIp|cidr: '10.20.30.0/24' DestinationPort: - 22 - 445 - 3389 - 5985 - 5986 condition: selection falsepositives: - None expected; cameras should not initiate sessions to Windows hosts. Validate any VMS-integrated camera feature that pushes files to an SMB share. level: high`

 

`title: Camera Cgi-bin Request With Shell Metacharacters id: 56a80dd3-a664-4ea6-870a-d41ca8608583 status: experimental description: Detects HTTP requests to a camera cgi-bin path containing URL-encoded shell metacharacters in proxy or WAF logs, consistent with CVE-2026-22755 exploitation attempts. references: - https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-03 author: 1898 & Co. date: 2026-10-02 tags: - attack.initial-access - attack.t1190 - cve.2026-22755 logsource: category: proxy detection: selection_path: c-uri|contains: '/cgi-bin/' selection_meta: c-uri|contains: - '%3B' - '%7C' - '%60' - '%24%28' condition: selection_path and selection_meta falsepositives: - Vulnerability scanners run by the security team level: high`

 

`title: Camera VLAN Outbound Connection to Non-Approved Destination id: a15cead3-3f0d-4b15-b015-a345fae63013 status: experimental description: Detects firewall-logged connections initiated by the camera VLAN on ports used for payload retrieval, remote shells and lateral movement. references: - https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-03 author: 1898 & Co. date: 2026-10-02 tags: - attack.command-and-control - attack.t1105 logsource: category: firewall detection: selection: src_ip|cidr: '10.20.30.0/24' dst_port: - 21 - 23 - 69 - 4444 - 6667 filter_vms: dst_ip|cidr: '10.20.40.0/24' condition: selection and not filter_vms falsepositives: - Camera FTP upload of snapshots to an approved server; add that server to the filter level: medium`

 

**Snort/Suricata rules** (Suricata 8 syntax; define CAMERA\_NET as the camera VLAN):

`alert http any any -> $CAMERA_NET any (msg:"LOCAL VIVOTEK CVE-2026-22755 possible command injection in cgi-bin URI"; flow:established,to_server; http.uri; content:"/cgi-bin/"; nocase; pcre:"/(\x3b|\x7c|\x60|\x24\x28|%3b|%7c|%60|%24%28)/i"; classtype:web-application-attack; reference:cve,2026-22755; sid:1000001; rev:1; metadata:affected_product VIVOTEK_Camera, created_at 2026_10_02;)`

 

`alert http any any -> $CAMERA_NET any (msg:"LOCAL VIVOTEK CVE-2026-22755 possible command injection in cgi-bin POST body"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/cgi-bin/"; nocase; http.request_body; pcre:"/(\x3b|\x7c|\x60|\x24\x28|%3b|%7c|%60|%24%28)\s*(wget|curl|tftp|busybox|sh|nc|telnetd)/i"; classtype:web-application-attack; reference:cve,2026-22755; sid:1000002; rev:1;)`

 

`alert http $CAMERA_NET any -> any any (msg:"LOCAL VIVOTEK camera-initiated HTTP download of script or IoT ELF payload"; flow:established,to_server; http.method; content:"GET"; http.uri; pcre:"/\.(sh|arm[5-7]?|mips|mpsl|x86|bin)$/i"; classtype:trojan-activity; sid:1000003; rev:1;)`

 

`alert udp $CAMERA_NET any -> any 69 (msg:"LOCAL VIVOTEK camera-initiated TFTP transfer"; threshold:type limit, track by_src, count 1, seconds 3600; classtype:policy-violation; sid:1000004; rev:1;)`

 

YARA rules:

VIVOTEK\_CmdInjection\_Request\_Artifacts targets the exploitation phase as it appears in exported web, proxy and WAF logs and in HTTP objects carved from PCAP. The condition requires a cgi-bin path together with an encoded or literal shell metacharacter and a downloader or shell command, so a cgi-bin request alone does not fire. Requiring at least one metacharacter and one command string suppresses ordinary camera configuration traffic, which routinely uses cgi-bin paths without injected commands.

`rule VIVOTEK_CmdInjection_Request_Artifacts { meta: description = "CVE-2026-22755 command injection request artifacts against VIVOTEK camera cgi-bin endpoints" author = "1898 & Co." date = "2026-10-02" reference = "https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-03" strings: $path = "/cgi-bin/" ascii nocase // camera CGI endpoint path $m1 = "%3B" ascii nocase // URL-encoded semicolon $m2 = "%7C" ascii nocase // URL-encoded pipe $m3 = "%60" ascii // URL-encoded backtick $m4 = "%24%28" ascii nocase // URL-encoded $( $m5 = ";wget" ascii nocase // literal chained wget $m6 = "$(" ascii // literal command substitution $c1 = "wget" ascii nocase // downloader $c2 = "tftp" ascii nocase // downloader $c3 = "busybox" ascii nocase // embedded Linux multi-call binary $c4 = "telnetd" ascii nocase // backdoor listener $c5 = "/bin/sh" ascii // shell invocation condition: $path and 1 of ($m*) and 1 of ($c*) }`

 

IoT\_Botnet\_Loader\_ELF\_Artifacts targets the second-stage payload a compromised camera retrieves, found in HTTP objects carved from camera egress traffic or in staging directories on VMS/NVR servers. The condition anchors on the ELF magic at offset 0 and requires two loader behaviours, which keeps it from matching legitimate ELF binaries that merely contain the word busybox. The filesize cap limits the rule to small embedded loaders.

`rule IoT_Botnet_Loader_ELF_Artifacts { meta: description = "Small ELF loader with IoT botnet download and persistence strings, as retrieved after camera command injection" author = "1898 & Co." date = "2026-10-02" reference = "https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-03" strings: $elf = { 7F 45 4C 46 } // ELF magic $s1 = "/bin/busybox" ascii // busybox applet invocation $s2 = "chmod 777" ascii // make dropped payload executable $s3 = "wget http" ascii nocase // HTTP retrieval $s4 = "tftp -g" ascii // TFTP retrieval $s5 = "/dev/watchdog" ascii // watchdog disable typical of IoT bots $s6 = "/proc/net/tcp" ascii // competitor-kill / port enumeration condition: $elf at 0 and filesize < 2MB and 2 of ($s*) }`

 

VIVOTEK\_Exploit\_Tooling\_Memory targets the public proof of concept, or a re-implementation of it, while it is resident in memory on an admin workstation, jump host or attacker-controlled internal system. The condition requires a VIVOTEK or cgi-bin marker together with an injection payload marker, which separates exploit tooling from a browser or VMS client that simply talks to cameras. Scan only scripting and HTTP-tool processes to keep noise and runtime down.

`rule VIVOTEK_Exploit_Tooling_Memory { meta: description = "In-memory artifacts of CVE-2026-22755 exploit tooling targeting VIVOTEK cameras" author = "1898 & Co." date = "2026-10-02" reference = "https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-03" strings: $v1 = "vivotek" ascii wide nocase // vendor marker in PoC banners or targets $v2 = "/cgi-bin/" ascii wide nocase // CGI path $p1 = "%3B" ascii wide nocase // encoded semicolon payload $p2 = "%24%28" ascii wide nocase // encoded $( payload $p3 = ";wget" ascii wide nocase // chained downloader $p4 = "telnetd -l /bin/sh" ascii wide // bind-shell payload $p5 = "nc -e /bin/sh" ascii wide // reverse-shell payload condition: 1 of ($v*) and 1 of ($p*) }`

 

Credential\_Dump\_Tool\_Memory\_Artifacts is the standing lateral-movement rule, applied here to Windows hosts that accepted camera-sourced sessions. Each branch requires a tool name together with its characteristic command or target string, and the catch-all branch requires a memory-read API, lsass.exe and a tool indicator together, which avoids matching legitimate software that only references lsass. Scanning process memory requires SeDebugPrivilege; CrowdStrike RTR can run it remotely.

`rule Credential_Dump_Tool_Memory_Artifacts { meta: description = "Memory artifacts of common credential dumping tools (mimikatz, WCE, gsecdump, comsvcs MiniDump)" author = "1898 & Co." date = "2026-10-02" reference = "https://attack.mitre.org/techniques/T1003/" strings: $mk1 = "sekurlsa::logonpasswords" ascii wide nocase // mimikatz LSASS dump command $mk2 = "lsadump::sam" ascii wide nocase // mimikatz SAM dump $mk3 = "privilege::debug" ascii wide nocase // mimikatz debug privilege $mk4 = "mimikatz" ascii wide nocase // tool name $mkh = { 6D 69 6D 69 6B 61 74 7A } // "mimikatz" hex $wce = "wce.exe" ascii wide nocase // Windows Credential Editor $gs = "gsecdump" ascii wide nocase // gsecdump name $md = "MiniDump" ascii wide // comsvcs MiniDump export $cs = "comsvcs" ascii wide nocase // comsvcs.dll $ls = "lsass.exe" ascii wide nocase // LSASS target $api1 = "NtReadVirtualMemory" ascii wide // memory-read API $api2 = "ReadProcessMemory" ascii wide // memory-read API condition: (2 of ($mk*) or $mkh) or ($wce and $ls) or $gs or ($md and $cs and $ls) or (1 of ($api*) and $ls and ($mk4 or $wce or $gs or $cs)) }`

 

#### Indicators of Compromise

Network IoCs (behavioral): HTTP GET or POST requests to camera /cgi-bin/ paths containing %3B, %7C, %60, %24%28 or literal ; | \` $( characters; requests to cameras from clients outside the VMS/NVR subnet and approved admin hosts; bursts of cgi-bin requests from a single source across many camera IPs (automated PoC scanning); camera-initiated HTTP GETs for .sh, .arm, .mips, .mpsl or .x86 files; camera-initiated TFTP (UDP/69), Telnet (TCP/23) or IRC/high-port outbound sessions; camera-initiated SYNs to TCP 22, 445, 3389, 5985/5986 or to Modbus (502), S7 (102) or EtherNet/IP (44818).

Host IoCs: Windows logons (4624/4625) with a source address in the camera VLAN; new services or scheduled tasks created shortly after a camera-sourced logon; curl, wget, python or PowerShell command lines combining a camera IP or cgi-bin path with shell metacharacters; small ELF loaders in /tmp, /var/tmp or /dev/shm on Linux VMS/NVR servers.

OT/operational IoCs: camera sysUpTime resets or SNMP coldStart/warmStart traps with no change record; camera firmware or configuration changes with no work order; video-loss or camera-offline events in the VMS coinciding with physical-security alarms; any camera appearing as a source of industrial-protocol traffic or as a new peer of a Level 1–3 asset in the OT monitoring platform.

External exposure indicators: any affected VIVOTEK model observed in Shodan, Censys or Netlas on an address attributable to the organization by at least two ownership signals; exposure continuous since the public PoC was released; camera interfaces on carrier or cellular ranges not present in the public IP inventory (shadow infrastructure).

#### False Positive Baseline

1\. VMS/NVR servers polling camera cgi-bin endpoints for status, snapshots and configuration on a fixed schedule; these requests do not carry shell metacharacters and originate from the VMS subnet.

2\. Authorized vulnerability scanning and penetration testing against cameras; confirm source IP and window against the approved test schedule.

3\. Camera firmware upgrades pushed from VMS or vendor tools, which produce sysUpTime resets and firmware-version changes; match against the patch change record for CVE-2026-22755 remediation.

4\. Cameras uploading snapshots or clips to an approved FTP, SMB or HTTP storage target, and resolving NTP and DNS servers; add these destinations to the egress baseline.

5\. Integrator or admin workstations using vendor configuration utilities or browsers against camera web interfaces during approved maintenance.

6\. External-exposure misattribution: index hits on shared hosting, CDN or carrier ranges that are not owned by the organization, and honeypots presenting VIVOTEK banners; do not report a hit without two independent ownership signals.

#### Escalation Criteria

1\. Any confirmed HTTP request to an affected camera containing an injected command (for example ;wget, $(, |sh) whether or not a response indicates success.

2\. Any camera-initiated retrieval of a script or ELF payload, TFTP transfer, Telnet session or connection to an external destination not in the egress baseline.

3\. Any Windows or Linux host accepting an SMB, RDP, SSH or WinRM session from the camera VLAN, or any logon with a camera IP as the source address.

4\. Any camera observed as a source of Modbus, EtherNet/IP/CIP, S7, DNP3 or BACnet traffic, or as a new peer of a Level 1–3 asset in the OT monitoring platform.

5\. Any YARA hit on VIVOTEK\_CmdInjection\_Request\_Artifacts in exported web, proxy or WAF logs or in HTTP objects carved from camera PCAP.

6\. Any YARA hit on IoT\_Botnet\_Loader\_ELF\_Artifacts in carved camera egress objects or in /tmp, /var/tmp or /dev/shm on a VMS/NVR server.

7\. Any YARA hit on VIVOTEK\_Exploit\_Tooling\_Memory in a scripting or HTTP-tool process on an internal host not running an approved, scheduled security test.

8\. Any YARA hit on Credential\_Dump\_Tool\_Memory\_Artifacts against a process on a host that accepted a camera-sourced session.

9\. An affected camera confirmed internet-exposed by two engines and two ownership signals, particularly where exposure spans the period since the public PoC appeared, where the camera is at a critical facility, or where the address is not in the public IP inventory (shadow infrastructure).

10\. CISA adds CVE-2026-22755 to the KEV catalog during the hunt, or a named threat actor or botnet is publicly attributed to its exploitation; re-prioritize every unpatched exposed camera immediately.

#### Hunt Completion Criteria and Reporting

The hunt is complete when every affected VIVOTEK camera has been inventoried with model, firmware version, network location and exposure status; the EASM sweep has covered every public IP, ASN and carrier range in the inventory with at least two engines; Hypotheses 2 and 3 have been executed across the full 90-day window for every camera, with exhaustive review of every externally exposed camera; and every escalation in Section 8 has been either dispositioned or handed to incident response.

The report must contain: the affected-camera inventory and firmware status before and after remediation; the EASM sweep coverage per engine and anchor, with per-hit provenance (engine, query, scan timestamp, ownership signals) and any coverage gaps from missing API keys or free-tier limits; per-hypothesis results stating Positive, Negative or Non-Conclusive, with the named missing input for any Non-Conclusive result (for example, no firewall URL logging on the camera VLAN or no PCAP retention); every YARA, SIGMA and Snort/Suricata hit with disposition; any coverage gaps in OT monitoring platform sensor health; and recommendations covering firmware updates, removal of internet exposure, camera VLAN egress filtering, and making the EASM sweep for camera and OT device exposure a recurring control.

#### Advisory IoC Reference

| IOC Type | IOC |
| --- | --- |
| CVE | CVE-2026-22755 \| CVSS v3.1 10.0 / v4.0 10.0 \| VIVOTEK network cameras (37 models across V, S, C, Dome, Bullet and Panoramic series); fixed in latest VIVOTEK firmware \| Unauthenticated OS command injection (CWE-77) in shared firmware modules enabling remote code execution, potentially as root; public PoC exists, no reported in-the-wild exploitation |
| Threat Actor | None attributed in source material — monitor https://www.cisa.gov/known-exploited-vulnerabilities-catalog |
| Malware | None published in source material — monitor https://www.cisa.gov/news-events/ics-advisories |
| Network IOC | None published in source material — monitor https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-03 |
| File IOC | None published in source material — monitor https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-03 |
| Behavioral | HTTP request to camera /cgi-bin/ path containing %3B, %7C, %60, %24%28 or literal ; \| \` $( metacharacters |
| Behavioral | Camera-initiated HTTP GET for .sh / .arm / .mips / .mpsl / .x86 payload, or TFTP (UDP/69) / Telnet (TCP/23) session |
| Behavioral | Windows logon (4624/4625) or SMB/RDP/SSH/WinRM session sourced from the camera VLAN |
| Behavioral | Camera appearing as source of Modbus, EtherNet/IP, S7, DNP3 or BACnet traffic, or as a new peer of a Level 1-3 asset |
| Behavioral | Camera sysUpTime reset or firmware/configuration change with no corresponding change record |
| Behavioral | Affected VIVOTEK model visible in passive internet-scan indices on an organization-attributed address |

[Threat Hunt](https://1898advisories.burnsmcd.com/tag/threat-hunt)

*The information in this cybersecurity advisory is provided "as is" for informational purposes only. 1898 & Co. does not provide any warranties or guarantees of any kind regarding this information. You assume all risks if you choose to rely on this information. In no event shall 1898 & Co. or its contractors or subcontractors be liable for any damages including, but not limited to, direct, indirect, special or consequential damages, arising out of, resulting from, or in any way connected with, this information, whether or not based upon warranty, contract, tort, or otherwise, whether or not arising out of negligence, and whether or not injury was sustained from, or arose out of the results of, or reliance upon the information*

*1898 & Co. does not endorse any product or service, except as expressly stated otherwise. Any reference to products or processes does not constitute or imply 1898 & Co.’s endorsement or recommendation.*

Subscribe

✕ Close

 

[Accessibility](https://1898andco.burnsmcd.com/accessibility)  |  [Privacy Statement](https://1898andco.burnsmcd.com/privacy)

© 2026 1898 & Co., a part of Burns & McDonnell. All Rights Reserved.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "The 1898 & Co. Team",
    "url" : "https://1898advisories.burnsmcd.com/author/1898-co-team"
  },
  "dateModified" : "2026-10-05T21:41:14.923Z",
  "datePublished" : "2026-10-05T21:41:14.000Z",
  "headline" : "Threat Hunt Plan: VIVOTEK Network Camera Firmware — Unauthenticated Command Injection and Post-Exploitation Pivot",
  "mainEntityOfPage" : {
    "@id" : "https://1898advisories.burnsmcd.com/threat-hunt-plan-vivotek-network-camera-firmware-unauthenticated-command-injection-and-post-exploitation-pivot-1",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "//cdn2.hubspot.net/hub/477837/file-2585615236-jpg/Logo_1_Primary_2Color1.jpg"
    },
    "name" : "Burns & McDonnell Engineering Co"
  }
}
```