← All hunts high TLP:CLEAR Part 2 of 2

Masqueraded Cryptominer Persistence and Stealthy Operation

An attacker has established persistence on an AhsayCBS server via a fake Edge service and is running a cryptominer that evades detection by monitoring for Task Manager and using a vulnerable kernel driver.

Based on research by Huntress 2026-10-10 12 steps · 5 queries T1036.004 T1036.005 T1057 T1059.001 T1124 T1496.001 T1543.003 T1564 T1571

Brief

Recent research from Huntress — AhsayCBS Flaws Exploit — details how unauthenticated RCE vulnerabilities in AhsayCBS backup servers allow attackers to drop webshells and deploy cryptominers. While a webshell is a clear indicator, the subsequent persistence and evasion techniques used by these actors are more subtle.

How the Hunt Flows

The hunt begins by identifying every host running AhsayCBS software. By scoping the search to these high-value backup servers, the analyst reduces noise from legitimate administrative tools and focuses on the systems most likely to be targeted by the unauthenticated RCE.

The second phase runs two queries in parallel to catch the adversary's dual-pronged persistence and evasion strategy. The first query looks for the creation of services like MicrosoftEdgeUpdateSvc that point to binaries in temp directories. Simultaneously, the hunt inspects PowerShell script logs for logic that stops and starts services whenever taskmgr appears in the process list.

Once the persistence mechanisms are identified, the hunt pivots to verify impact. It looks for the loading of the WinRing0 kernel driver, which miners use to access hardware MSRs for higher hash rates. This joins with network telemetry seeking outbound connections to known mining infrastructure and port 8029.

A final correlation step brings all indicators together. An analyst or automated agent reviews the full chain—from the fake service to the anti-analysis script and the kernel-level impact—to distinguish this malicious campaign from common administrative scripts or legitimate software updates.

What the Hunt Cannot See

This hunt relies on PowerShell script block logging (Event ID 4104) to see the anti-analysis loops. If an attacker obfuscates the script or splits it across multiple blocks, a keyword-based search for taskmgr may fail. Additionally, if the adversary manual-maps the WinRing0 driver rather than using the standard Windows loader, the kernel extension telemetry may not capture the event.

How to Run the Hunt

This playbook is provided in the hunt.md format. You can import it directly into Huntbase or any other runtime that supports the open hunt.md standard. It provides the structured queries and the logic required to correlate these disparate indicators into a single forensic verdict.

Steps

  1. Identify AhsayCBS Servers

    Query · scoping

    Find hosts running AhsayCBS software to prioritize behavioral checks.

    reads hb_software_inventorysql
    SELECT device_hostname, package_name, package_version FROM hb_software_inventory WHERE LOWER(package_name) LIKE '%ahsay%'

    What a hit looks like. A list of hostnames where Ahsay software is installed. Silence means no Ahsay packages were found in the current inventory.

  2. Detect Masqueraded Edge Service

    Query · detection candidate

    Find the MicrosoftEdgeUpdateSvc service created to daemonize the miner.

    reads hb_service_activitysql
    SELECT device_hostname, service_name, service_cmd_line, actor_user_name, time FROM hb_service_activity WHERE activity_id = 1 AND (LOWER(service_name) LIKE '%microsoftedgeupdatesvc%' OR LOWER(service_cmd_line) LIKE '%temp%msedge.exe%' OR LOWER(service_cmd_line) LIKE '%--daemonized%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Creation of a service with a name mimicking Edge, pointing to a binary in a temporary directory. This is a high-fidelity indicator of the campaign.

  3. Detect Anti-TaskMgr Script Blocks

    Query · triage

    Identify PowerShell scripts that monitor for Task Manager to hide mining activity.

    reads hb_script_activitysql
    SELECT device_hostname, script_content, actor_user_name, time FROM hb_script_activity WHERE activity_id = 1 AND (LOWER(script_content) LIKE '%taskmgr%' AND (LOWER(script_content) LIKE '%stop-service%' OR LOWER(script_content) LIKE '%start-service%')) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Script blocks containing logic to stop services when taskmgr is found. Silence proves the exact string was not seen, but evasion may be obfuscated.

  4. Analyze Persistence and Evasion Patterns

    Agent triage

    Analyze whether found services and scripts match the described miner-hiding behavior.

  5. Identify WinRing0 Driver Loads

    Query · baseline

    Find the vulnerable WinRing0 kernel driver used to optimize mining performance.

    reads hb_kernel_extension_activitysql
    SELECT device_hostname, driver_path, driver_signature_subject, MIN(time) AS first_seen FROM hb_kernel_extension_activity WHERE activity_id = 1 AND LOWER(driver_path) LIKE '%winring0x64.sys%' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, driver_path, driver_signature_subject

    What a hit looks like. Loads of the WinRing0x64.sys driver, especially in user-writable paths. Fleet-wide rarity increases confidence.

  6. Identify Miner Network Connections

    Query · enrichment

    Corroborate host activity with outbound connections to mining pool infrastructure.

    reads hb_network_connectionsql
    SELECT device_hostname, process_name, dst_endpoint_hostname, dst_endpoint_ip, dst_endpoint_port, time FROM hb_network_connection WHERE (instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(dst_endpoint_hostname) || ',') > 0 OR instr(',' || '{{c2_ips}}' || ',', ',' || dst_endpoint_ip || ',') > 0 OR dst_endpoint_port = 8029) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Connections to the known pool IP, domain, or the specific non-standard port 8029 used by the campaign.

  7. Evaluate Full Intrusion Chain

    Agent triage

    Final weigh-in combining early persistence with follow-on mining activity.

  8. Route on Verdict

    Decision

    Direct the hunt to containment or manual review based on agent findings.

  9. Isolate Endpoint and Collect Artifacts

    Response action

    Halt resource hijacking and preserve temporary payloads.

  10. Analyst Forensic Review

    Analyst task

    Manually verify the findings and tune future detections.

  11. Hunt Closure

    Analyst task

    Finalize results and document coverage gaps.

Coverage

Scenario coverage

StageCoveredHow, or why not
Masqueraded Service Creation
T1543.003 · T1036.004 · T1036.005
Yes fake-edge-service
Task Manager Aware Evasion
T1564 · T1057 · T1124 · T1059.001
Yes anti-analysis-logic
Vulnerable Kernel Driver Loading
T1543.003
Yes vulnerable-driver-load
XMRig Resource Hijacking
T1496.001 · T1571
Yes miner-network-traffic
AhsayCBS Unauthenticated RCE
T1190 · T1059.003
Out of scope Belongs to another part of the 'Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer' series.
JSP Webshell Deployment
T1505.003
Out of scope Belongs to another part of the 'Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer' series.
Miner Toolkit Ingress
T1105 · T1071.001
Out of scope Belongs to another part of the 'Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer' series.

Blind spots

  • Needs Complete PowerShell script block logging (Event ID 4104). Fragmented or obfuscated scripts may bypass simple keyword searches for taskmgr and service controls. It would answer Is the anti-analysis script obfuscated or split across multiple blocks?.
  • Needs hb_kernel_extension_activity reporting for all drivers. Manual mapping of drivers can bypass standard EDR load notification callbacks. It would answer Was the WinRing0 driver loaded via a method that avoids standard API calls?.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
c2_domainslist[domain]xmr.kryptex.networkCryptominer pool domains.
c2_ipslist[ip]51.195.127.124Cryptominer pool IP addresses from the report.
lookback_daysnumber14Days of history to examine.
scope_hostslist[host]—Hostnames of AhsayCBS servers to narrow the hunt.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint
Network telemetrynetworknetwork

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: This hunt correlates masqueraded service persistence with anti-analysis
  script behavior and kernel-level impact, providing context that a single detection
  rule on any one indicator would lack.
blind_spots:
- id: no-script-block-logging
  question: Is the anti-analysis script obfuscated or split across multiple blocks?
  requires: Complete PowerShell script block logging (Event ID 4104)
  risk: Fragmented or obfuscated scripts may bypass simple keyword searches for taskmgr
    and service controls.
  stage: anti-analysis-evasion
- id: no-kernel-load-events
  question: Was the WinRing0 driver loaded via a method that avoids standard API calls?
  requires: hb_kernel_extension_activity reporting for all drivers
  risk: Manual mapping of drivers can bypass standard EDR load notification callbacks.
  stage: kernel-driver-execution
coverage:
- stage: persistence-via-service
  status: covered
  steps:
  - fake-edge-service
- stage: anti-analysis-evasion
  status: covered
  steps:
  - anti-analysis-logic
- stage: kernel-driver-execution
  status: covered
  steps:
  - vulnerable-driver-load
- stage: cryptomining-impact
  status: covered
  steps:
  - miner-network-traffic
- reason: Belongs to another part of the 'Threat Actors Exploit Critical AhsayCBS
    Flaws to Drop Webshells and XMRig Cryptominer' series.
  stage: initial-exploitation-rce
  status: out_of_scope
- reason: Belongs to another part of the 'Threat Actors Exploit Critical AhsayCBS
    Flaws to Drop Webshells and XMRig Cryptominer' series.
  stage: webshell-persistence
  status: out_of_scope
- reason: Belongs to another part of the 'Threat Actors Exploit Critical AhsayCBS
    Flaws to Drop Webshells and XMRig Cryptominer' series.
  stage: payload-ingress-and-staging
  status: out_of_scope
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: promote-to-detection
  justification: The exploitation of AhsayCBS provides an unauthenticated RCE pathway
    into sensitive backup infrastructure. A negative result confirms that the server
    has not yet been used for resource hijacking, which can degrade performance and
    signal deeper attacker persistence.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An attacker has established persistence on an AhsayCBS server via a fake
  Edge service and is running a cryptominer that evades detection by monitoring for
  Task Manager and using a vulnerable kernel driver.
labels:
- hunt
- attack.t1543.003
- attack.t1036.004
- attack.t1036.005
- attack.t1564
- attack.t1057
- attack.t1124
- attack.t1059.001
- attack.t1496.001
- attack.t1571
- command and control
- defense evasion
- impact
- initial access
- persistence
name: Masqueraded Cryptominer Persistence and Stealthy Operation
parameters:
  c2_domains:
    default:
    - xmr.kryptex.network
    description: Cryptominer pool domains.
    from:
      kind: article
      observed: '2026-10-08'
      ref: huntress-ahsaycbs
    type: list[domain]
  c2_ips:
    default:
    - 51.195.127.124
    description: Cryptominer pool IP addresses from the report.
    from:
      kind: article
      observed: '2026-10-08'
      ref: huntress-ahsaycbs
    type: list[ip]
  lookback_days:
    default: '14'
    description: Days of history to examine.
    type: number
  scope_hosts:
    default: []
    description: Hostnames of AhsayCBS servers to narrow the hunt.
    type: list[host]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.huntress.com/blog/ahsaycbs-flaws-exploit
    gates:
    - dry-run
    - lint
    - critic
    model: hb_google/gemini-3-flash-preview
rationale: Focus on AhsayCBS application servers by checking software inventory first.
  If not explicitly tagged, widen scope to all servers with public-facing web services.
references:
- name: "Huntress \u2014 AhsayCBS Flaws Exploit"
  url: https://www.huntress.com/blog/ahsaycbs-flaws-exploit
related:
- hunt: ahsaycbs-initial-exploitation-rce
  reason: Initial RCE and webshell deployment are precursors to the cryptomining persistence
    covered here.
  relation: follows
scenario:
  stages:
  - name: AhsayCBS Unauthenticated RCE
    observables:
    - cbssvcX64.exe
    - cbssvcX86.exe
    - /rps/api/json/UpdateReceivers.do
    - random token bypass in checkSysPwd
    slug: initial-exploitation-rce
    tactic: initial-access
    techniques:
    - T1190
    - T1059.003
  - name: JSP Webshell Deployment
    observables:
    - .jsp files in application directory
    - com/ahsay/obs/api/ApiStructsAction.java
    slug: webshell-persistence
    tactic: persistence
    techniques:
    - T1505.003
  - name: Miner Toolkit Ingress
    observables:
    - curl -sk -o
    - certutil.exe
    - imagefiles-backup.oss-ap-southeast-7.aliyuncs.com
    - C:\Users\ADMINI~1\AppData\Local\Temp\Taskgmr.ps1
    - config.json
    - msedge.exe
    - edge.exe
    slug: payload-ingress-and-staging
    tactic: command-and-control
    techniques:
    - T1105
    - T1071.001
  - name: Masqueraded Service Creation
    observables:
    - MicrosoftEdgeUpdateSvc
    - msedge.exe
    - edge.exe
    - --daemonized
    - modified NSSM utility
    - renamed XMRig miner
    slug: persistence-via-service
    tactic: persistence
    techniques:
    - T1543.003
    - T1036.004
    - T1036.005
  - name: Task Manager Aware Evasion
    observables:
    - Taskgmr.ps1
    - Get-Process taskmgr
    - Get-Date
    - stop MicrosoftEdgeUpdateSvc when taskmgr opens
    slug: anti-analysis-evasion
    tactic: defense-evasion
    techniques:
    - T1564
    - T1057
    - T1124
    - T1059.001
  - name: Vulnerable Kernel Driver Loading
    observables:
    - WinRing0x64.sys
    - OpenLibSys driver
    slug: kernel-driver-execution
    tactic: defense-evasion
    techniques:
    - T1543.003
  - name: XMRig Resource Hijacking
    observables:
    - xmr.kryptex.network
    - 51.195.127.124:8029
    - edge.exe
    slug: cryptomining-impact
    tactic: impact
    techniques:
    - T1496.001
    - T1571
  summary: Threat actors are chaining CVE-2026-105133 and CVE-2026-105134 to achieve
    unauthenticated remote code execution on internet-exposed AhsayCBS backup management
    servers. Once compromised, actors deploy JSP webshells and download a cryptomining
    toolkit that includes XMRig, a modified NSSM utility for persistence, and an anti-analysis
    PowerShell script designed to hide mining activity from the Task Manager.
series:
  index: 2
  slug: threat-actors-exploit-critical-ahsaycbs-flaws-to-drop-webshells-and-xmrig-cryptominer
  title: Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig
    Cryptominer
  total: 2
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  network:
    category: network
    name: Network telemetry
    telemetry:
    - network
tlp: clear
type: investigation
---


# Masqueraded Cryptominer Persistence and Stealthy Operation

This hunt targets the post-exploitation lifecycle of AhsayCBS compromises. It identifying vulnerable hosts and then hunts for the creation of a fake Microsoft Edge service used to maintain a renamed XMRig miner. It looks for PowerShell script blocks that monitor for the Task Manager process to pause mining activity, evading user discovery. Finally, it correlates these behaviors with the loading of the WinRing0 vulnerable kernel driver and outbound connections to known mining infrastructure.

## scoping-ahsay-hosts
<!-- Identify AhsayCBS Servers -->
Find hosts running AhsayCBS software to prioritize behavioral checks.

```sqlite target=endpoint role=scoping
~~~yaml
expected: A list of hostnames where Ahsay software is installed. Silence means no
  Ahsay packages were found in the current inventory.
reads:
- device_hostname
- package_name
- package_version
silence: not_evidence_of_absence
source: hb_software_inventory
verified: dry-run
verified_at: '2026-10-10'
~~~
SELECT device_hostname, package_name, package_version FROM hb_software_inventory WHERE LOWER(package_name) LIKE '%ahsay%'
```

## early-stage-parallel
<!-- Hunt for Persistence and Evasion Scripts -->
parallel:
- → fake-edge-service
- → anti-analysis-logic
join: → triage-persistence-evasion

## fake-edge-service
<!-- Detect Masqueraded Edge Service -->
Find the MicrosoftEdgeUpdateSvc service created to daemonize the miner.

```sqlite target=endpoint role=detection-candidate params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: Creation of a service with a name mimicking Edge, pointing to a binary in
  a temporary directory. This is a high-fidelity indicator of the campaign.
reads:
- device_hostname
- service_name
- service_cmd_line
- actor_user_name
- time
silence: not_evidence_of_absence
source: hb_service_activity
verified: dry-run
verified_at: '2026-10-10'
~~~
SELECT device_hostname, service_name, service_cmd_line, actor_user_name, time FROM hb_service_activity WHERE activity_id = 1 AND (LOWER(service_name) LIKE '%microsoftedgeupdatesvc%' OR LOWER(service_cmd_line) LIKE '%temp%msedge.exe%' OR LOWER(service_cmd_line) LIKE '%--daemonized%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## anti-analysis-logic
<!-- Detect Anti-TaskMgr Script Blocks -->
Identify PowerShell scripts that monitor for Task Manager to hide mining activity.

```sqlite target=endpoint role=triage params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: Script blocks containing logic to stop services when taskmgr is found. Silence
  proves the exact string was not seen, but evasion may be obfuscated.
reads:
- device_hostname
- script_content
- actor_user_name
- time
silence: not_evidence_of_absence
source: hb_script_activity
verified: dry-run
verified_at: '2026-10-10'
~~~
SELECT device_hostname, script_content, actor_user_name, time FROM hb_script_activity WHERE activity_id = 1 AND (LOWER(script_content) LIKE '%taskmgr%' AND (LOWER(script_content) LIKE '%stop-service%' OR LOWER(script_content) LIKE '%start-service%')) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## triage-persistence-evasion
<!-- Analyze Persistence and Evasion Patterns -->
```agent target=hunter
cite: required
context:
- fake-edge-service
- anti-analysis-logic
max_iterations: 3
objective: Determine if the service activity and script content on these hosts represent
  the Taskgmr.ps1 and MicrosoftEdgeUpdateSvc pattern described in the research.
success_criteria: Verdicts citing specific rows from both queries that demonstrate
  correlated activity.
tools:
- endpoint
- network
```

## follow-on-parallel
<!-- Hunt for Mining Impact and Kernel Loads -->
parallel:
- → vulnerable-driver-load
- → miner-network-traffic
join: → evaluate-complete-intrusion

## vulnerable-driver-load
<!-- Identify WinRing0 Driver Loads -->
Find the vulnerable WinRing0 kernel driver used to optimize mining performance.

```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: Loads of the WinRing0x64.sys driver, especially in user-writable paths.
  Fleet-wide rarity increases confidence.
prevalence:
  by: device_hostname
  key:
  - driver_path
  rare_below: 3
reads:
- device_hostname
- driver_path
- driver_signature_subject
- time
silence: not_evidence_of_absence
source: hb_kernel_extension_activity
verified: dry-run
verified_at: '2026-10-10'
~~~
SELECT device_hostname, driver_path, driver_signature_subject, MIN(time) AS first_seen FROM hb_kernel_extension_activity WHERE activity_id = 1 AND LOWER(driver_path) LIKE '%winring0x64.sys%' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, driver_path, driver_signature_subject
```

## miner-network-traffic
<!-- Identify Miner Network Connections -->
Corroborate host activity with outbound connections to mining pool infrastructure.

```sqlite target=network role=enrichment params=(lookback_days=lookback_days, scope_hosts=scope_hosts, c2_domains=c2_domains, c2_ips=c2_ips)
~~~yaml
expected: Connections to the known pool IP, domain, or the specific non-standard port
  8029 used by the campaign.
reads:
- device_hostname
- process_name
- dst_endpoint_hostname
- dst_endpoint_ip
- dst_endpoint_port
- time
silence: not_evidence_of_absence
source: hb_network_connection
verified: dry-run
verified_at: '2026-10-10'
~~~
SELECT device_hostname, process_name, dst_endpoint_hostname, dst_endpoint_ip, dst_endpoint_port, time FROM hb_network_connection WHERE (instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(dst_endpoint_hostname) || ',') > 0 OR instr(',' || '{{c2_ips}}' || ',', ',' || dst_endpoint_ip || ',') > 0 OR dst_endpoint_port = 8029) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## evaluate-complete-intrusion
<!-- Evaluate Full Intrusion Chain -->
```agent target=hunter
cite: required
context:
- vulnerable-driver-load
- miner-network-traffic
- triage-persistence-evasion
max_iterations: 6
objective: Consolidate the findings from all previous steps. Assess if the host has
  persistence, is using the anti-analysis scripts, has loaded the WinRing0 driver,
  and is connecting to mining pools.
success_criteria: A final verdict of malicious | suspicious | benign per host, citing
  the chain of evidence.
tools:
- endpoint
- network
```

## route-on-verdict
<!-- Route on Verdict -->
if~: "the evaluate-complete-intrusion verdict is malicious for at least one host" (confidence: high, judge=hunter)
then: → isolate-and-collect
indeterminate: → analyst-forensic-review
unavailable: → analyst-forensic-review (blind_spot: no-script-block-logging)
else: → close-out

## isolate-and-collect
<!-- Isolate Endpoint and Collect Artifacts -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host and collect any binaries found in user temp folders, specifically msedge.exe, edge.exe, and Taskgmr.ps1.
```
→ analyst-forensic-review

## analyst-forensic-review
<!-- Analyst Forensic Review -->
```manual target=analyst
Review the collected artifacts and script content. Confirm if msedge.exe is a renamed NSSM utility and analyze Taskgmr.ps1 for anti-analysis loops. Check for secondary backdoors that may have been deployed alongside the miner.
```
→ close-out

## close-out
<!-- Hunt Closure -->
```manual target=analyst
Document the hosts found, the severity of the intrusion, and any blind spots encountered during the hunt.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, critic, then reviewed by a person.