← All hunts high TLP:CLEAR Part 2 of 2

AI-Accelerated Post-Exploitation and Extortion

An intruder is using AI-driven automation to conduct rapid internal reconnaissance, steal AI service tokens, and triage sensitive files for extortion at machine speed.

Based on research by Huntress 2026-09-28 9 steps · 3 queries T1003 T1018 T1083 T1486 T1566

Brief

Why This Hunt Matters

Attackers now use AI to accelerate traditional tradecraft, moving from entry to exfiltration faster than manual defenders can react. In the article AI Attacks Move Faster. Huntress’ Agentic SOC Keeps Up (https://www.huntress.com/blog/ai-attackers-machine-speed-huntress-athena), Huntress describes how machine-speed agents require machine-speed defense. This hunt provides a framework to find these automated intruders by looking for the noise they create when they operate at scale. We focus on velocity as a primary indicator of compromise.

How the Hunt Flows

The first phase targets the initial reconnaissance burst. The hunt queries hb_process_activity to find hosts where five or more discovery commands—such as whoami.exe, net.exe, systeminfo.exe, or ipconfig.exe—occur within a single hour. While administrators run these tools individually, they rarely execute them in such tight, automated clusters. The query groups activity by hour buckets to isolate these machine-driven patterns from standard background noise.

The hunt then pivots to look for the adversary's specific goals. It runs two queries in parallel to catch evidence of preparation for lateral movement or data theft. The first monitors hb_file_activity for unauthorized access to AI-specific API tokens and cloud credentials. It targets configuration paths like .openai, .anthropic, .config/gcloud, or .aws/credentials. Access to these files by non-developer processes or unusual user accounts suggests an attacker is harvesting keys to fuel further automation.

Simultaneously, the second query identifies high-velocity internal network scanning. It analyzes hb_network_connection to find hosts contacting more than 20 unique internal IP addresses in the lookback period. We filter out common, noisy UDP protocols like SSDP and NetBIOS to ensure the results reflect intentional scanning. This identifies the rapid smash and grab reconnaissance typical of an automated agent trying to map the internal network.

In the final phase, an agent or analyst evaluates the combined evidence from all three signals. If a host exhibits the discovery burst along with either token theft or internal scanning, the hunt marks the activity as a machine-speed attack. The playbook provides a decision point to route these confirmed cases to host isolation. This containment step is critical to stop the attack before the adversary can initiate bulk data exfiltration or ransomware deployment.

Blind Spots

This hunt relies on process and network telemetry within a defined 14-day window. If an automated attack moves slowly during its initial stages or began before this window, the hunt might miss the early indicators. Additionally, we target API tokens stored in configuration files on disk. If an attacker retrieves tokens from environment variables or direct process memory, our file-based queries will not see the theft. Environments with high levels of legitimate automation may also require additional tuning of the burst threshold to reduce false positives.

Running the Hunt

This hunt is an open hunt.md playbook. You can import it into Huntbase or any hunt.md-aware runtime to begin searching your environment. It is particularly effective when scoped to developer workstations, DevOps pipelines, and AI engineering environments where sensitive API keys and cloud credentials reside. Unlike a static detection for a single tool, this hunt uses aggregate behavior to find the needle in the automated haystack.

In this series

Steps

  1. Rapid automated discovery bursts

    Query · detection candidate

    Identify hosts where a high number of discovery commands executed in a short window, distinguishing AI-accelerated bursts from high aggregate activity.

    reads hb_process_activitysql
    SELECT device_hostname, user_name, STRFTIME('%Y-%m-%d %H:00:00', time) AS hour_bucket, COUNT(*) AS cmd_count, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_process_activity WHERE (instr(',' || '{{discovery_commands}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || '{{discovery_commands}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY device_hostname, user_name, hour_bucket HAVING cmd_count >= 5 ORDER BY cmd_count DESC

    What a hit looks like. A single user or host running 5+ discovery commands within a single hour; isolated instances are typically administrative, while hourly bursts suggest a script or agent.

  2. Access to AI API tokens and configurations

    Query · baseline

    Find file access events targeting the AI model configuration directories mentioned in recent misuse reports.

    reads hb_file_activitysql
    SELECT device_hostname, actor_user_name, file_path, process_name, time FROM hb_file_activity WHERE (LOWER(file_path) LIKE '%.anthropic%' OR LOWER(file_path) LIKE '%.openai%' OR LOWER(file_path) LIKE '%.config/gcloud%' OR LOWER(file_path) LIKE '%.aws/credentials%') AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)

    What a hit looks like. Unauthorized or unusual processes reading AI API keys or cloud credentials. Silence means these specific local paths were not accessed.

  3. High-velocity internal network scanning

    Query · triage

    Locate hosts attempting to connect to a high volume of unique internal targets, filtering out common service discovery noise.

    reads hb_network_connectionsql
    SELECT device_hostname, src_endpoint_ip, COUNT(DISTINCT dst_endpoint_ip) AS unique_targets, COUNT(*) AS total_conns, MIN(time) AS first_seen FROM hb_network_connection WHERE direction = 'outbound' AND disposition = 'Allowed' AND (dst_endpoint_ip LIKE '10.%' OR dst_endpoint_ip LIKE '192.168.%' OR dst_endpoint_ip LIKE '172.16.%' OR dst_endpoint_ip LIKE '172.31.%') AND NOT (dst_endpoint_port IN (137, 138, 1900) AND protocol = 'udp') AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY device_hostname, src_endpoint_ip HAVING unique_targets > 20 ORDER BY unique_targets DESC

    What a hit looks like. A host contacting more than 20 unique internal IPs. This filters out NetBIOS and SSDP while highlighting scanning behavior.

  4. Evaluate machine-speed evidence

    Agent triage

    Correlate the discovery bursts, token access, and network scanning to determine if a host is under automated control.

  5. Route on automated attack verdict

    Decision

    Directly respond to confirmed machine-speed attacks to minimize dwell time.

  6. Isolate high-speed beachhead

    Response action

    Contain the automated attack before it moves to bulk encryption or data exfiltration.

  7. Review automated activity

    Analyst task

    Verify the agent's findings and identify the entry point used by the attacker to initiate the automated sequence.

  8. Remediation and close-out

    Analyst task

    Document the findings and close the hunt if no malicious activity was confirmed.

Coverage

Scenario coverage

StageCoveredHow, or why not
Automated Internal Reconnaissance
T1083 · T1018
Yes discovery-burst, internal-scan-burst
Credential Dumping and Session Token Theft
T1003
Yes ai-token-access
Automated Data Triage and Impact
T1486
Not visible The precise AI-assisted scanning of files for PII (Read activity) requires high-fidelity file-read logs which often exceed the noise floor of generic hb_file_activity; we focus on the precursor token theft instead.
AI-Enhanced Phishing and Social Engineering
T1566
Out of scope Belongs to another part of the 'AI Attacks Move Faster. Huntress’ Agentic SOC Keeps Up' series.
Compromise of External Remote Services
T1133 · T1190
Out of scope Belongs to another part of the 'AI Attacks Move Faster. Huntress’ Agentic SOC Keeps Up' series.

Blind spots

  • Needs extended retention for process and network events. A slowly-initiated AI agent that then speeds up would have its origin outside the lookback window. It would answer Did the automated discovery sequence begin before the current 14-day window?.
  • Needs hb_process_activity with environment variable capture. Attackers can scrape tokens from process memory or environment blocks without touching the .config files targeted by the file activity query. It would answer Are AI API tokens being stolen from environment variables rather than on-disk configuration files?.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
discovery_commandslist[string]whoami.exe, net.exe, ipconfig.exe, quser.exe, nltest.exe, systeminfo.exe, netstat.exe, tasklist.exe, arp.exeStandard discovery executables that indicate automated reconnaissance when run in a burst.
lookback_daysnumber14Days of history to examine.
scope_hostslist[host]—Narrow the hunt to specific high-value targets; leave empty for fleet-wide.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint
Network telemetrynetworknetwork

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: A single detection rule for whoami is noisy and frequently ignored; this
  hunt pivots between the burst volume of discovery within hour buckets, specific
  AI token file access, and high-velocity internal network connections to provide
  the aggregate context that distinguishes an automated agent from a human administrator.
blind_spots:
- id: limited-telemetry-retention
  question: Did the automated discovery sequence begin before the current 14-day window?
  requires: extended retention for process and network events
  risk: A slowly-initiated AI agent that then speeds up would have its origin outside
    the lookback window.
  stage: automated-internal-discovery
- id: environment-variable-tokens
  question: Are AI API tokens being stolen from environment variables rather than
    on-disk configuration files?
  requires: hb_process_activity with environment variable capture
  risk: Attackers can scrape tokens from process memory or environment blocks without
    touching the .config files targeted by the file activity query.
  stage: credential-and-token-theft
coverage:
- stage: automated-internal-discovery
  status: covered
  steps:
  - discovery-burst
  - internal-scan-burst
- stage: credential-and-token-theft
  status: covered
  steps:
  - ai-token-access
- reason: The precise AI-assisted scanning of files for PII (Read activity) requires
    high-fidelity file-read logs which often exceed the noise floor of generic hb_file_activity;
    we focus on the precursor token theft instead.
  stage: rapid-data-triage-and-encryption
  status: not_visible
- reason: "Belongs to another part of the 'AI Attacks Move Faster. Huntress\u2019\
    \ Agentic SOC Keeps Up' series."
  stage: ai-enhanced-phishing
  status: out_of_scope
- reason: "Belongs to another part of the 'AI Attacks Move Faster. Huntress\u2019\
    \ Agentic SOC Keeps Up' series."
  stage: external-service-compromise
  status: out_of_scope
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: promote-to-detection
  justification: As attackers use AI to compress the dwell-time between initial access
    and extortion, defenders must hunt for volume-based anomalies that precede bulk
    encryption; a negative result confirms the estate is not currently undergoing
    a machine-speed automated breach.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An intruder is using AI-driven automation to conduct rapid internal reconnaissance,
  steal AI service tokens, and triage sensitive files for extortion at machine speed.
labels:
- hunt
- attack.t1003
- attack.t1083
- attack.t1018
- attack.t1486
- attack.t1566
name: AI-Accelerated Post-Exploitation and Extortion
parameters:
  discovery_commands:
    default:
    - whoami.exe
    - net.exe
    - ipconfig.exe
    - quser.exe
    - nltest.exe
    - systeminfo.exe
    - netstat.exe
    - tasklist.exe
    - arp.exe
    description: Standard discovery executables that indicate automated reconnaissance
      when run in a burst.
    from:
      kind: manual
      observed: '2026-09-22'
      ref: common discovery tool list
    type: list[string]
  lookback_days:
    default: '14'
    description: Days of history to examine.
    from:
      kind: article
      observed: '2026-09-22'
      ref: https://www.huntress.com/blog/ai-attackers-machine-speed-huntress-athena
    type: number
  scope_hosts:
    default: []
    description: Narrow the hunt to specific high-value targets; leave empty for fleet-wide.
    from:
      kind: manual
      observed: '2026-09-22'
      ref: analyst-defined scope
    type: list[host]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.huntress.com/blog/ai-attackers-machine-speed-huntress-athena
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Focus on developer workstations, AI engineering environments, and cloud
  administration hosts where API tokens for Anthropic, OpenAI, or AWS are likely to
  reside.
references:
- name: "Huntress \u2014 AI Attackers Move Faster. Huntress\u2019 Agentic SOC Keeps\
    \ Up"
  url: https://www.huntress.com/blog/ai-attackers-machine-speed-huntress-athena
related:
- hunt: discovery-tool-execution
  reason: This hunt focuses on the speed and volume of discovery rather than the mere
    presence of common tools.
  relation: out-of-scope-alternative
- hunt: machine-speed-perimeter-identity-ingress
  relation: follows
scenario:
  stages:
  - name: AI-Enhanced Phishing and Social Engineering
    observables:
    - Phishing emails with AI-refined language
    - Video calls with AI-altered faces (deepfakes)
    - Compromised accounts used for high-volume phishing
    slug: ai-enhanced-phishing
    tactic: initial-access
    techniques:
    - T1566
  - name: Compromise of External Remote Services
    observables:
    - Anomalous VPN authentications without MFA
    - Connections from unusual geolocations via VPN
    - Exploitation of vulnerable network appliances or firewalls
    - Exposed services on ports 443 or 1194
    slug: external-service-compromise
    tactic: initial-access
    techniques:
    - T1133
    - T1190
  - name: Automated Internal Reconnaissance
    observables:
    - High-speed internal network scanning and enumeration
    - Rapid execution of system discovery commands
    - Unusual outbound internal traffic patterns from recently accessed hosts
    slug: automated-internal-discovery
    tactic: discovery
    techniques:
    - T1083
    - T1018
  - name: Credential Dumping and Session Token Theft
    observables:
    - Theft of API keys and session tokens for AI models (e.g., Anthropic, OpenAI)
    - Memory dumping of lsass.exe
    - Loading of dbghelp.dll or dbgcore.dll from non-standard paths
    - Access to local credential stores or browser profile directories
    slug: credential-and-token-theft
    tactic: credential-access
    techniques:
    - T1003
  - name: Automated Data Triage and Impact
    observables:
    - AI-assisted scanning of files for PII, PHI, or intellectual property
    - Rapid traversal of file shares and local directories
    - Bulk file encryption and renaming (ransomware activity)
    - Execution of scripts or binaries for automated data classification
    slug: rapid-data-triage-and-encryption
    tactic: impact
    techniques:
    - T1486
  summary: Attackers are utilizing AI to accelerate traditional tradecraft, moving
    from initial access via compromised VPNs or firewalls to rapid internal discovery
    and automated data triage. While AI enhances the speed of reconnaissance and phishing,
    the core post-exploitation behaviors such as credential dumping and lateral movement
    remain observable through endpoint and identity telemetry.
series:
  index: 2
  slug: ai-attacks-move-faster-huntress-agentic-soc-keeps-up
  title: "AI Attacks Move Faster. Huntress\u2019 Agentic SOC Keeps Up"
  total: 2
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  network:
    category: network
    name: Network telemetry
    telemetry:
    - network
tlp: clear
type: investigation
---


# AI-Accelerated Post-Exploitation and Extortion

Adversaries are increasingly using AI agents to accelerate traditional post-exploitation tradecraft. This hunt targets the machine speed signals of these attacks: bursts of system discovery commands in short time windows, the theft of AI-specific API tokens (Anthropic/OpenAI) used for further automation, and high-volume internal scanning. By focusing on volume and velocity rather than just the presence of a tool, we identify compromises that would otherwise move faster than manual triage cycles.

## discovery-burst
<!-- Rapid automated discovery bursts -->
Identify hosts where a high number of discovery commands executed in a short window, distinguishing AI-accelerated bursts from high aggregate activity.

```sqlite target=endpoint role=detection-candidate params=(lookback_days=lookback_days, discovery_commands=discovery_commands, scope_hosts=scope_hosts)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: A single user or host running 5+ discovery commands within a single hour;
  isolated instances are typically administrative, while hourly bursts suggest a script
  or agent.
reads:
- device_hostname
- user_name
- process_name
- process_original_file_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, user_name, STRFTIME('%Y-%m-%d %H:00:00', time) AS hour_bucket, COUNT(*) AS cmd_count, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_process_activity WHERE (instr(',' || '{{discovery_commands}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || '{{discovery_commands}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY device_hostname, user_name, hour_bucket HAVING cmd_count >= 5 ORDER BY cmd_count DESC
```

## parallel-signals
<!-- Corroborate with token theft and network scanning -->
parallel:
- → ai-token-access
- → internal-scan-burst
join: → triage-acceleration

## ai-token-access
<!-- Access to AI API tokens and configurations -->
Find file access events targeting the AI model configuration directories mentioned in recent misuse reports.

```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: Unauthorized or unusual processes reading AI API keys or cloud credentials.
  Silence means these specific local paths were not accessed.
prevalence:
  by: device_hostname
  key:
  - file_path
  rare_below: 3
reads:
- device_hostname
- actor_user_name
- file_path
- process_name
- time
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, actor_user_name, file_path, process_name, time FROM hb_file_activity WHERE (LOWER(file_path) LIKE '%.anthropic%' OR LOWER(file_path) LIKE '%.openai%' OR LOWER(file_path) LIKE '%.config/gcloud%' OR LOWER(file_path) LIKE '%.aws/credentials%') AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)
```

## internal-scan-burst
<!-- High-velocity internal network scanning -->
Locate hosts attempting to connect to a high volume of unique internal targets, filtering out common service discovery noise.

```sqlite target=network role=triage params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: A host contacting more than 20 unique internal IPs. This filters out NetBIOS
  and SSDP while highlighting scanning behavior.
reads:
- device_hostname
- src_endpoint_ip
- dst_endpoint_ip
- dst_endpoint_port
- protocol
- direction
- disposition
- time
silence: not_evidence_of_absence
source: hb_network_connection
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, src_endpoint_ip, COUNT(DISTINCT dst_endpoint_ip) AS unique_targets, COUNT(*) AS total_conns, MIN(time) AS first_seen FROM hb_network_connection WHERE direction = 'outbound' AND disposition = 'Allowed' AND (dst_endpoint_ip LIKE '10.%' OR dst_endpoint_ip LIKE '192.168.%' OR dst_endpoint_ip LIKE '172.16.%' OR dst_endpoint_ip LIKE '172.31.%') AND NOT (dst_endpoint_port IN (137, 138, 1900) AND protocol = 'udp') AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY device_hostname, src_endpoint_ip HAVING unique_targets > 20 ORDER BY unique_targets DESC
```

## triage-acceleration
<!-- Evaluate machine-speed evidence -->
```agent target=hunter
cite: required
context:
- discovery-burst
- ai-token-access
- internal-scan-burst
max_iterations: 4
objective: Determine if the observed high-volume discovery bursts and network scanning,
  combined with any AI token access, indicates an automated attacker presence. Cite
  the specific command bursts and targets.
success_criteria: A verdict of malicious or suspicious for any host demonstrating
  the machine-speed post-exploitation pattern.
tools:
- endpoint
- network
```

## route-on-speed
<!-- Route on automated attack verdict -->
if~: "the triage verdict identifies an automated or high-speed post-exploitation event as malicious on at least one host" (confidence: high, judge=hunter)
then: → isolate-compromised-host
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: limited-telemetry-retention)
else: → remediation-closeout

## isolate-compromised-host
<!-- Isolate high-speed beachhead -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host reporting the discovery burst and scanning. Revoke any AI API tokens or cloud credentials found to have been accessed on the host.
```
→ analyst-review

## analyst-review
<!-- Review automated activity -->
```manual target=analyst
Investigate the parent process of the discovery burst to find the initial execution vector (e.g., a web server exploit or phishing payload). Check for lateral movement attempts using any credentials accessed during the session.
```
→ end

## remediation-closeout
<!-- Remediation and close-out -->
```manual target=analyst
Record the baseline discovery volume for future tuning. If high-volume activity was legitimate IT administration, whitelist the specific service account or script path used.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.