{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "The exploitation of AhsayCBS provides an unauthenticated RCE pathway into sensitive backup infrastructure. A negative result confirms that the server has not yet been used for resource hijacking, which can degrade performance and signal deeper attacker persistence."
      },
      "name": "Masqueraded Cryptominer Persistence and Stealthy Operation",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1543.003",
        "attack.t1036.004",
        "attack.t1036.005",
        "attack.t1564",
        "attack.t1057",
        "attack.t1124",
        "attack.t1059.001",
        "attack.t1496.001",
        "attack.t1571",
        "command and control",
        "defense evasion",
        "impact",
        "initial access",
        "persistence"
      ],
      "series": {
        "slug": "threat-actors-exploit-critical-ahsaycbs-flaws-to-drop-webshells-and-xmrig-cryptominer",
        "index": 2,
        "title": "Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer",
        "total": 2
      },
      "related": [
        {
          "hunt": "ahsaycbs-initial-exploitation-rce",
          "reason": "Initial RCE and webshell deployment are precursors to the cryptomining persistence covered here.",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "network": {
          "name": "Network telemetry",
          "category": "network",
          "telemetry": [
            "network"
          ]
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "This hunt correlates masqueraded service persistence with anti-analysis script behavior and kernel-level impact, providing context that a single detection rule on any one indicator would lack.",
      "coverage": [
        {
          "stage": "persistence-via-service",
          "steps": [
            "fake-edge-service"
          ],
          "status": "covered"
        },
        {
          "stage": "anti-analysis-evasion",
          "steps": [
            "anti-analysis-logic"
          ],
          "status": "covered"
        },
        {
          "stage": "kernel-driver-execution",
          "steps": [
            "vulnerable-driver-load"
          ],
          "status": "covered"
        },
        {
          "stage": "cryptomining-impact",
          "steps": [
            "miner-network-traffic"
          ],
          "status": "covered"
        },
        {
          "stage": "initial-exploitation-rce",
          "reason": "Belongs to another part of the 'Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "webshell-persistence",
          "reason": "Belongs to another part of the 'Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "payload-ingress-and-staging",
          "reason": "Belongs to another part of the 'Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "AhsayCBS Unauthenticated RCE",
            "slug": "initial-exploitation-rce",
            "tactic": "initial-access",
            "techniques": [
              "T1190",
              "T1059.003"
            ],
            "observables": [
              "cbssvcX64.exe",
              "cbssvcX86.exe",
              "/rps/api/json/UpdateReceivers.do",
              "random token bypass in checkSysPwd"
            ]
          },
          {
            "name": "JSP Webshell Deployment",
            "slug": "webshell-persistence",
            "tactic": "persistence",
            "techniques": [
              "T1505.003"
            ],
            "observables": [
              ".jsp files in application directory",
              "com/ahsay/obs/api/ApiStructsAction.java"
            ]
          },
          {
            "name": "Miner Toolkit Ingress",
            "slug": "payload-ingress-and-staging",
            "tactic": "command-and-control",
            "techniques": [
              "T1105",
              "T1071.001"
            ],
            "observables": [
              "curl -sk -o",
              "certutil.exe",
              "imagefiles-backup.oss-ap-southeast-7.aliyuncs.com",
              "C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\Taskgmr.ps1",
              "config.json",
              "msedge.exe",
              "edge.exe"
            ]
          },
          {
            "name": "Masqueraded Service Creation",
            "slug": "persistence-via-service",
            "tactic": "persistence",
            "techniques": [
              "T1543.003",
              "T1036.004",
              "T1036.005"
            ],
            "observables": [
              "MicrosoftEdgeUpdateSvc",
              "msedge.exe",
              "edge.exe",
              "--daemonized",
              "modified NSSM utility",
              "renamed XMRig miner"
            ]
          },
          {
            "name": "Task Manager Aware Evasion",
            "slug": "anti-analysis-evasion",
            "tactic": "defense-evasion",
            "techniques": [
              "T1564",
              "T1057",
              "T1124",
              "T1059.001"
            ],
            "observables": [
              "Taskgmr.ps1",
              "Get-Process taskmgr",
              "Get-Date",
              "stop MicrosoftEdgeUpdateSvc when taskmgr opens"
            ]
          },
          {
            "name": "Vulnerable Kernel Driver Loading",
            "slug": "kernel-driver-execution",
            "tactic": "defense-evasion",
            "techniques": [
              "T1543.003"
            ],
            "observables": [
              "WinRing0x64.sys",
              "OpenLibSys driver"
            ]
          },
          {
            "name": "XMRig Resource Hijacking",
            "slug": "cryptomining-impact",
            "tactic": "impact",
            "techniques": [
              "T1496.001",
              "T1571"
            ],
            "observables": [
              "xmr.kryptex.network",
              "51.195.127.124:8029",
              "edge.exe"
            ]
          }
        ],
        "summary": "Threat actors are chaining CVE-2026-105133 and CVE-2026-105134 to achieve unauthenticated remote code execution on internet-exposed AhsayCBS backup management servers. Once compromised, actors deploy JSP webshells and download a cryptomining toolkit that includes XMRig, a modified NSSM utility for persistence, and an anti-analysis PowerShell script designed to hide mining activity from the Task Manager."
      },
      "severity": "high",
      "rationale": "Focus on AhsayCBS application servers by checking software inventory first. If not explicitly tagged, widen scope to all servers with public-facing web services.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An attacker has established persistence on an AhsayCBS server via a fake Edge service and is running a cryptominer that evades detection by monitoring for Task Manager and using a vulnerable kernel driver.",
      "parameters": {
        "c2_ips": {
          "from": {
            "ref": "huntress-ahsaycbs",
            "kind": "article",
            "observed": "2026-10-08"
          },
          "type": "list[ip]",
          "default": [
            "51.195.127.124"
          ],
          "description": "Cryptominer pool IP addresses from the report."
        },
        "c2_domains": {
          "from": {
            "ref": "huntress-ahsaycbs",
            "kind": "article",
            "observed": "2026-10-08"
          },
          "type": "list[domain]",
          "default": [
            "xmr.kryptex.network"
          ],
          "description": "Cryptominer pool domains."
        },
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Hostnames of AhsayCBS servers to narrow the hunt."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.huntress.com/blog/ahsaycbs-flaws-exploit",
          "gates": [
            "dry-run",
            "lint",
            "critic"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.huntress.com/blog/ahsaycbs-flaws-exploit",
          "name": "Huntress \u2014 AhsayCBS Flaws Exploit"
        }
      ],
      "blind_spots": [
        {
          "id": "no-script-block-logging",
          "risk": "Fragmented or obfuscated scripts may bypass simple keyword searches for taskmgr and service controls.",
          "stage": "anti-analysis-evasion",
          "question": "Is the anti-analysis script obfuscated or split across multiple blocks?",
          "requires": "Complete PowerShell script block logging (Event ID 4104)"
        },
        {
          "id": "no-kernel-load-events",
          "risk": "Manual mapping of drivers can bypass standard EDR load notification callbacks.",
          "stage": "kernel-driver-execution",
          "question": "Was the WinRing0 driver loaded via a method that avoids standard API calls?",
          "requires": "hb_kernel_extension_activity reporting for all drivers"
        }
      ]
    },
    "name": "Masqueraded Cryptominer Persistence and Stealthy Operation",
    "description": "This hunt targets the post-exploitation lifecycle of AhsayCBS compromises. It identifying vulnerable hosts and then hunts for the creation of a fake Microsoft Edge service used to maintain a renamed XMRig miner. It looks for PowerShell script blocks that monitor for the Task Manager process to pause mining activity, evading user discovery. Finally, it correlates these behaviors with the loading of the WinRing0 vulnerable kernel driver and outbound connections to known mining infrastructure."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "threat-actors-exploit-critical-ahsaycbs-flaws-to-drop-webshells-and-xmrig-cryptominer",
          "index": 2,
          "title": "Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer",
          "total": 2
        },
        "coverage": [
          {
            "stage": "persistence-via-service",
            "steps": [
              "fake-edge-service"
            ],
            "status": "covered"
          },
          {
            "stage": "anti-analysis-evasion",
            "steps": [
              "anti-analysis-logic"
            ],
            "status": "covered"
          },
          {
            "stage": "kernel-driver-execution",
            "steps": [
              "vulnerable-driver-load"
            ],
            "status": "covered"
          },
          {
            "stage": "cryptomining-impact",
            "steps": [
              "miner-network-traffic"
            ],
            "status": "covered"
          },
          {
            "stage": "initial-exploitation-rce",
            "reason": "Belongs to another part of the 'Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "webshell-persistence",
            "reason": "Belongs to another part of the 'Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "payload-ingress-and-staging",
            "reason": "Belongs to another part of the 'Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An attacker has established persistence on an AhsayCBS server via a fake Edge service and is running a cryptominer that evades detection by monitoring for Task Manager and using a vulnerable kernel driver.",
        "blind_spots": [
          {
            "id": "no-script-block-logging",
            "risk": "Fragmented or obfuscated scripts may bypass simple keyword searches for taskmgr and service controls.",
            "stage": "anti-analysis-evasion",
            "question": "Is the anti-analysis script obfuscated or split across multiple blocks?",
            "requires": "Complete PowerShell script block logging (Event ID 4104)"
          },
          {
            "id": "no-kernel-load-events",
            "risk": "Manual mapping of drivers can bypass standard EDR load notification callbacks.",
            "stage": "kernel-driver-execution",
            "question": "Was the WinRing0 driver loaded via a method that avoids standard API calls?",
            "requires": "hb_kernel_extension_activity reporting for all drivers"
          }
        ],
        "scoping_notes": "Focus on AhsayCBS application servers by checking software inventory first. If not explicitly tagged, widen scope to all servers with public-facing web services.",
        "beyond_detection": "This hunt correlates masqueraded service persistence with anti-analysis script behavior and kernel-level impact, providing context that a single detection rule on any one indicator would lack."
      }
    },
    {
      "id": "scoping-ahsay-hosts",
      "type": "query",
      "label": "Identify AhsayCBS Servers",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_hostname, package_name, package_version FROM hb_software_inventory WHERE LOWER(package_name) LIKE '%ahsay%'",
        "surface": "hb_software_inventory",
        "description": "Find hosts running AhsayCBS software to prioritize behavioral checks.",
        "expected_signal": "A list of hostnames where Ahsay software is installed. Silence means no Ahsay packages were found in the current inventory."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify AhsayCBS Servers",
        "reads": [
          "device_hostname",
          "package_name",
          "package_version"
        ],
        "source": "hb_software_inventory",
        "target": "endpoint",
        "content": "SELECT device_hostname, package_name, package_version FROM hb_software_inventory WHERE LOWER(package_name) LIKE '%ahsay%'",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hostnames where Ahsay software is installed. Silence means no Ahsay packages were found in the current inventory.",
        "verified": "dry-run",
        "verified_at": "2026-10-10"
      }
    },
    {
      "id": "fake-edge-service",
      "type": "query",
      "label": "Detect Masqueraded Edge Service",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, service_name, service_cmd_line, actor_user_name, time FROM hb_service_activity WHERE activity_id = 1 AND (LOWER(service_name) LIKE '%microsoftedgeupdatesvc%' OR LOWER(service_cmd_line) LIKE '%temp%msedge.exe%' OR LOWER(service_cmd_line) LIKE '%--daemonized%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_service_activity",
        "description": "Find the MicrosoftEdgeUpdateSvc service created to daemonize the miner.",
        "expected_signal": "Creation of a service with a name mimicking Edge, pointing to a binary in a temporary directory. This is a high-fidelity indicator of the campaign."
      },
      "parents": [
        {
          "id": "scoping-ahsay-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Detect Masqueraded Edge Service",
        "reads": [
          "device_hostname",
          "service_name",
          "service_cmd_line",
          "actor_user_name",
          "time"
        ],
        "source": "hb_service_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, service_name, service_cmd_line, actor_user_name, time FROM hb_service_activity WHERE activity_id = 1 AND (LOWER(service_name) LIKE '%microsoftedgeupdatesvc%' OR LOWER(service_cmd_line) LIKE '%temp%msedge.exe%' OR LOWER(service_cmd_line) LIKE '%--daemonized%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Creation of a service with a name mimicking Edge, pointing to a binary in a temporary directory. This is a high-fidelity indicator of the campaign.",
        "verified": "dry-run",
        "verified_at": "2026-10-10"
      }
    },
    {
      "id": "anti-analysis-logic",
      "type": "query",
      "label": "Detect Anti-TaskMgr Script Blocks",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "endpoint",
        "content": "SELECT device_hostname, script_content, actor_user_name, time FROM hb_script_activity WHERE activity_id = 1 AND (LOWER(script_content) LIKE '%taskmgr%' AND (LOWER(script_content) LIKE '%stop-service%' OR LOWER(script_content) LIKE '%start-service%')) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_script_activity",
        "description": "Identify PowerShell scripts that monitor for Task Manager to hide mining activity.",
        "expected_signal": "Script blocks containing logic to stop services when taskmgr is found. Silence proves the exact string was not seen, but evasion may be obfuscated."
      },
      "parents": [
        {
          "id": "scoping-ahsay-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Detect Anti-TaskMgr Script Blocks",
        "reads": [
          "device_hostname",
          "script_content",
          "actor_user_name",
          "time"
        ],
        "source": "hb_script_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, script_content, actor_user_name, time FROM hb_script_activity WHERE activity_id = 1 AND (LOWER(script_content) LIKE '%taskmgr%' AND (LOWER(script_content) LIKE '%stop-service%' OR LOWER(script_content) LIKE '%start-service%')) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Script blocks containing logic to stop services when taskmgr is found. Silence proves the exact string was not seen, but evasion may be obfuscated.",
        "verified": "dry-run",
        "verified_at": "2026-10-10"
      }
    },
    {
      "id": "triage-persistence-evasion",
      "type": "analytic",
      "label": "Analyze Persistence and Evasion Patterns",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "network"
        ],
        "context": [
          "fake-edge-service",
          "anti-analysis-logic"
        ],
        "objective": "Determine if the service activity and script content on these hosts represent the Taskgmr.ps1 and MicrosoftEdgeUpdateSvc pattern described in the research.",
        "description": "Analyze whether found services and scripts match the described miner-hiding behavior.",
        "max_iterations": 3,
        "expected_signal": "A per-host verdict linking the masqueraded service to the anti-analysis logic.",
        "success_criteria": "Verdicts citing specific rows from both queries that demonstrate correlated activity."
      },
      "parents": [
        {
          "id": "fake-edge-service",
          "kind": "merge"
        },
        {
          "id": "anti-analysis-logic",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "vulnerable-driver-load",
      "type": "query",
      "label": "Identify WinRing0 Driver Loads",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT device_hostname, driver_path, driver_signature_subject, MIN(time) AS first_seen FROM hb_kernel_extension_activity WHERE activity_id = 1 AND LOWER(driver_path) LIKE '%winring0x64.sys%' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, driver_path, driver_signature_subject",
        "surface": "hb_kernel_extension_activity",
        "description": "Find the vulnerable WinRing0 kernel driver used to optimize mining performance.",
        "expected_signal": "Loads of the WinRing0x64.sys driver, especially in user-writable paths. Fleet-wide rarity increases confidence."
      },
      "parents": [
        {
          "id": "triage-persistence-evasion"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Identify WinRing0 Driver Loads",
        "reads": [
          "device_hostname",
          "driver_path",
          "driver_signature_subject",
          "time"
        ],
        "source": "hb_kernel_extension_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, driver_path, driver_signature_subject, MIN(time) AS first_seen FROM hb_kernel_extension_activity WHERE activity_id = 1 AND LOWER(driver_path) LIKE '%winring0x64.sys%' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, driver_path, driver_signature_subject",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Loads of the WinRing0x64.sys driver, especially in user-writable paths. Fleet-wide rarity increases confidence.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "driver_path"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-10-10"
      }
    },
    {
      "id": "miner-network-traffic",
      "type": "query",
      "label": "Identify Miner Network Connections",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "network",
        "content": "SELECT device_hostname, process_name, dst_endpoint_hostname, dst_endpoint_ip, dst_endpoint_port, time FROM hb_network_connection WHERE (instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(dst_endpoint_hostname) || ',') > 0 OR instr(',' || '{{c2_ips}}' || ',', ',' || dst_endpoint_ip || ',') > 0 OR dst_endpoint_port = 8029) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_network_connection",
        "description": "Corroborate host activity with outbound connections to mining pool infrastructure.",
        "expected_signal": "Connections to the known pool IP, domain, or the specific non-standard port 8029 used by the campaign."
      },
      "parents": [
        {
          "id": "triage-persistence-evasion"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Identify Miner Network Connections",
        "reads": [
          "device_hostname",
          "process_name",
          "dst_endpoint_hostname",
          "dst_endpoint_ip",
          "dst_endpoint_port",
          "time"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT device_hostname, process_name, dst_endpoint_hostname, dst_endpoint_ip, dst_endpoint_port, time FROM hb_network_connection WHERE (instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(dst_endpoint_hostname) || ',') > 0 OR instr(',' || '{{c2_ips}}' || ',', ',' || dst_endpoint_ip || ',') > 0 OR dst_endpoint_port = 8029) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Connections to the known pool IP, domain, or the specific non-standard port 8029 used by the campaign.",
        "verified": "dry-run",
        "verified_at": "2026-10-10"
      }
    },
    {
      "id": "evaluate-complete-intrusion",
      "type": "analytic",
      "label": "Evaluate Full Intrusion Chain",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "network"
        ],
        "context": [
          "vulnerable-driver-load",
          "miner-network-traffic",
          "triage-persistence-evasion"
        ],
        "objective": "Consolidate the findings from all previous steps. Assess if the host has persistence, is using the anti-analysis scripts, has loaded the WinRing0 driver, and is connecting to mining pools.",
        "description": "Final weigh-in combining early persistence with follow-on mining activity.",
        "max_iterations": 6,
        "expected_signal": "A conclusive verdict on whether the host is actively mining and using the described stealth mechanisms.",
        "success_criteria": "A final verdict of malicious | suspicious | benign per host, citing the chain of evidence."
      },
      "parents": [
        {
          "id": "vulnerable-driver-load",
          "kind": "merge"
        },
        {
          "id": "miner-network-traffic",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on Verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the evaluate-complete-intrusion verdict is malicious for at least one host",
        "condition": "the evaluate-complete-intrusion verdict is malicious for at least one host",
        "blind_spot": "no-script-block-logging",
        "confidence": "high",
        "description": "Direct the hunt to containment or manual review based on agent findings.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "evaluate-complete-intrusion"
        }
      ]
    },
    {
      "id": "isolate-and-collect",
      "type": "action",
      "label": "Isolate Endpoint and Collect Artifacts",
      "config": {
        "target": "endpoint",
        "description": "Halt resource hijacking and preserve temporary payloads.",
        "instructions": "Isolate the host and collect any binaries found in user temp folders, specifically msedge.exe, edge.exe, and Taskgmr.ps1.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-forensic-review",
      "type": "task",
      "label": "Analyst Forensic Review",
      "config": {
        "assignee": "analyst",
        "description": "Manually verify the findings and tune future detections.",
        "instructions": "Review the collected artifacts and script content. Confirm if msedge.exe is a renamed NSSM utility and analyze Taskgmr.ps1 for anti-analysis loops. Check for secondary backdoors that may have been deployed alongside the miner."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-and-collect"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Hunt Closure",
      "config": {
        "assignee": "analyst",
        "description": "Finalize results and document coverage gaps.",
        "instructions": "Document the hosts found, the severity of the intrusion, and any blind spots encountered during the hunt."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "analyst-forensic-review"
        }
      ]
    }
  ]
}