{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "As attackers use AI to compress the dwell-time between initial access and extortion, defenders must hunt for volume-based anomalies that precede bulk encryption; a negative result confirms the estate is not currently undergoing a machine-speed automated breach."
      },
      "name": "AI-Accelerated Post-Exploitation and Extortion",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1003",
        "attack.t1083",
        "attack.t1018",
        "attack.t1486",
        "attack.t1566"
      ],
      "series": {
        "slug": "ai-attacks-move-faster-huntress-agentic-soc-keeps-up",
        "index": 2,
        "title": "AI Attacks Move Faster. Huntress\u2019 Agentic SOC Keeps Up",
        "total": 2
      },
      "related": [
        {
          "hunt": "discovery-tool-execution",
          "reason": "This hunt focuses on the speed and volume of discovery rather than the mere presence of common tools.",
          "relation": "out-of-scope-alternative"
        },
        {
          "hunt": "machine-speed-perimeter-identity-ingress",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "network": {
          "name": "Network telemetry",
          "category": "network",
          "telemetry": [
            "network"
          ]
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A single detection rule for whoami is noisy and frequently ignored; this hunt pivots between the burst volume of discovery within hour buckets, specific AI token file access, and high-velocity internal network connections to provide the aggregate context that distinguishes an automated agent from a human administrator.",
      "coverage": [
        {
          "stage": "automated-internal-discovery",
          "steps": [
            "discovery-burst",
            "internal-scan-burst"
          ],
          "status": "covered"
        },
        {
          "stage": "credential-and-token-theft",
          "steps": [
            "ai-token-access"
          ],
          "status": "covered"
        },
        {
          "stage": "rapid-data-triage-and-encryption",
          "reason": "The precise AI-assisted scanning of files for PII (Read activity) requires high-fidelity file-read logs which often exceed the noise floor of generic hb_file_activity; we focus on the precursor token theft instead.",
          "status": "not_visible"
        },
        {
          "stage": "ai-enhanced-phishing",
          "reason": "Belongs to another part of the 'AI Attacks Move Faster. Huntress\u2019 Agentic SOC Keeps Up' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "external-service-compromise",
          "reason": "Belongs to another part of the 'AI Attacks Move Faster. Huntress\u2019 Agentic SOC Keeps Up' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "AI-Enhanced Phishing and Social Engineering",
            "slug": "ai-enhanced-phishing",
            "tactic": "initial-access",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "Phishing emails with AI-refined language",
              "Video calls with AI-altered faces (deepfakes)",
              "Compromised accounts used for high-volume phishing"
            ]
          },
          {
            "name": "Compromise of External Remote Services",
            "slug": "external-service-compromise",
            "tactic": "initial-access",
            "techniques": [
              "T1133",
              "T1190"
            ],
            "observables": [
              "Anomalous VPN authentications without MFA",
              "Connections from unusual geolocations via VPN",
              "Exploitation of vulnerable network appliances or firewalls",
              "Exposed services on ports 443 or 1194"
            ]
          },
          {
            "name": "Automated Internal Reconnaissance",
            "slug": "automated-internal-discovery",
            "tactic": "discovery",
            "techniques": [
              "T1083",
              "T1018"
            ],
            "observables": [
              "High-speed internal network scanning and enumeration",
              "Rapid execution of system discovery commands",
              "Unusual outbound internal traffic patterns from recently accessed hosts"
            ]
          },
          {
            "name": "Credential Dumping and Session Token Theft",
            "slug": "credential-and-token-theft",
            "tactic": "credential-access",
            "techniques": [
              "T1003"
            ],
            "observables": [
              "Theft of API keys and session tokens for AI models (e.g., Anthropic, OpenAI)",
              "Memory dumping of lsass.exe",
              "Loading of dbghelp.dll or dbgcore.dll from non-standard paths",
              "Access to local credential stores or browser profile directories"
            ]
          },
          {
            "name": "Automated Data Triage and Impact",
            "slug": "rapid-data-triage-and-encryption",
            "tactic": "impact",
            "techniques": [
              "T1486"
            ],
            "observables": [
              "AI-assisted scanning of files for PII, PHI, or intellectual property",
              "Rapid traversal of file shares and local directories",
              "Bulk file encryption and renaming (ransomware activity)",
              "Execution of scripts or binaries for automated data classification"
            ]
          }
        ],
        "summary": "Attackers are utilizing AI to accelerate traditional tradecraft, moving from initial access via compromised VPNs or firewalls to rapid internal discovery and automated data triage. While AI enhances the speed of reconnaissance and phishing, the core post-exploitation behaviors such as credential dumping and lateral movement remain observable through endpoint and identity telemetry."
      },
      "severity": "high",
      "rationale": "Focus on developer workstations, AI engineering environments, and cloud administration hosts where API tokens for Anthropic, OpenAI, or AWS are likely to reside.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An intruder is using AI-driven automation to conduct rapid internal reconnaissance, steal AI service tokens, and triage sensitive files for extortion at machine speed.",
      "parameters": {
        "scope_hosts": {
          "from": {
            "ref": "analyst-defined scope",
            "kind": "manual",
            "observed": "2026-09-22"
          },
          "type": "list[host]",
          "default": [],
          "description": "Narrow the hunt to specific high-value targets; leave empty for fleet-wide."
        },
        "lookback_days": {
          "from": {
            "ref": "https://www.huntress.com/blog/ai-attackers-machine-speed-huntress-athena",
            "kind": "article",
            "observed": "2026-09-22"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "discovery_commands": {
          "from": {
            "ref": "common discovery tool list",
            "kind": "manual",
            "observed": "2026-09-22"
          },
          "type": "list[string]",
          "default": [
            "whoami.exe",
            "net.exe",
            "ipconfig.exe",
            "quser.exe",
            "nltest.exe",
            "systeminfo.exe",
            "netstat.exe",
            "tasklist.exe",
            "arp.exe"
          ],
          "description": "Standard discovery executables that indicate automated reconnaissance when run in a burst."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.huntress.com/blog/ai-attackers-machine-speed-huntress-athena",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.huntress.com/blog/ai-attackers-machine-speed-huntress-athena",
          "name": "Huntress \u2014 AI Attackers Move Faster. Huntress\u2019 Agentic SOC Keeps Up"
        }
      ],
      "blind_spots": [
        {
          "id": "limited-telemetry-retention",
          "risk": "A slowly-initiated AI agent that then speeds up would have its origin outside the lookback window.",
          "stage": "automated-internal-discovery",
          "question": "Did the automated discovery sequence begin before the current 14-day window?",
          "requires": "extended retention for process and network events"
        },
        {
          "id": "environment-variable-tokens",
          "risk": "Attackers can scrape tokens from process memory or environment blocks without touching the .config files targeted by the file activity query.",
          "stage": "credential-and-token-theft",
          "question": "Are AI API tokens being stolen from environment variables rather than on-disk configuration files?",
          "requires": "hb_process_activity with environment variable capture"
        }
      ]
    },
    "name": "AI-Accelerated Post-Exploitation and Extortion",
    "description": "Adversaries are increasingly using AI agents to accelerate traditional post-exploitation tradecraft. This hunt targets the machine speed signals of these attacks: bursts of system discovery commands in short time windows, the theft of AI-specific API tokens (Anthropic/OpenAI) used for further automation, and high-volume internal scanning. By focusing on volume and velocity rather than just the presence of a tool, we identify compromises that would otherwise move faster than manual triage cycles."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "ai-attacks-move-faster-huntress-agentic-soc-keeps-up",
          "index": 2,
          "title": "AI Attacks Move Faster. Huntress\u2019 Agentic SOC Keeps Up",
          "total": 2
        },
        "coverage": [
          {
            "stage": "automated-internal-discovery",
            "steps": [
              "discovery-burst",
              "internal-scan-burst"
            ],
            "status": "covered"
          },
          {
            "stage": "credential-and-token-theft",
            "steps": [
              "ai-token-access"
            ],
            "status": "covered"
          },
          {
            "stage": "rapid-data-triage-and-encryption",
            "reason": "The precise AI-assisted scanning of files for PII (Read activity) requires high-fidelity file-read logs which often exceed the noise floor of generic hb_file_activity; we focus on the precursor token theft instead.",
            "status": "not_visible"
          },
          {
            "stage": "ai-enhanced-phishing",
            "reason": "Belongs to another part of the 'AI Attacks Move Faster. Huntress\u2019 Agentic SOC Keeps Up' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "external-service-compromise",
            "reason": "Belongs to another part of the 'AI Attacks Move Faster. Huntress\u2019 Agentic SOC Keeps Up' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An intruder is using AI-driven automation to conduct rapid internal reconnaissance, steal AI service tokens, and triage sensitive files for extortion at machine speed.",
        "blind_spots": [
          {
            "id": "limited-telemetry-retention",
            "risk": "A slowly-initiated AI agent that then speeds up would have its origin outside the lookback window.",
            "stage": "automated-internal-discovery",
            "question": "Did the automated discovery sequence begin before the current 14-day window?",
            "requires": "extended retention for process and network events"
          },
          {
            "id": "environment-variable-tokens",
            "risk": "Attackers can scrape tokens from process memory or environment blocks without touching the .config files targeted by the file activity query.",
            "stage": "credential-and-token-theft",
            "question": "Are AI API tokens being stolen from environment variables rather than on-disk configuration files?",
            "requires": "hb_process_activity with environment variable capture"
          }
        ],
        "scoping_notes": "Focus on developer workstations, AI engineering environments, and cloud administration hosts where API tokens for Anthropic, OpenAI, or AWS are likely to reside.",
        "beyond_detection": "A single detection rule for whoami is noisy and frequently ignored; this hunt pivots between the burst volume of discovery within hour buckets, specific AI token file access, and high-velocity internal network connections to provide the aggregate context that distinguishes an automated agent from a human administrator."
      }
    },
    {
      "id": "discovery-burst",
      "type": "query",
      "label": "Rapid automated discovery bursts",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, user_name, STRFTIME('%Y-%m-%d %H:00:00', time) AS hour_bucket, COUNT(*) AS cmd_count, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_process_activity WHERE (instr(',' || '{{discovery_commands}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || '{{discovery_commands}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY device_hostname, user_name, hour_bucket HAVING cmd_count >= 5 ORDER BY cmd_count DESC",
        "surface": "hb_process_activity",
        "description": "Identify hosts where a high number of discovery commands executed in a short window, distinguishing AI-accelerated bursts from high aggregate activity.",
        "expected_signal": "A single user or host running 5+ discovery commands within a single hour; isolated instances are typically administrative, while hourly bursts suggest a script or agent."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Rapid automated discovery bursts",
        "reads": [
          "device_hostname",
          "user_name",
          "process_name",
          "process_original_file_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, user_name, STRFTIME('%Y-%m-%d %H:00:00', time) AS hour_bucket, COUNT(*) AS cmd_count, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_process_activity WHERE (instr(',' || '{{discovery_commands}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || '{{discovery_commands}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY device_hostname, user_name, hour_bucket HAVING cmd_count >= 5 ORDER BY cmd_count DESC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A single user or host running 5+ discovery commands within a single hour; isolated instances are typically administrative, while hourly bursts suggest a script or agent.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "ai-token-access",
      "type": "query",
      "label": "Access to AI API tokens and configurations",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT device_hostname, actor_user_name, file_path, process_name, time FROM hb_file_activity WHERE (LOWER(file_path) LIKE '%.anthropic%' OR LOWER(file_path) LIKE '%.openai%' OR LOWER(file_path) LIKE '%.config/gcloud%' OR LOWER(file_path) LIKE '%.aws/credentials%') AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)",
        "surface": "hb_file_activity",
        "description": "Find file access events targeting the AI model configuration directories mentioned in recent misuse reports.",
        "expected_signal": "Unauthorized or unusual processes reading AI API keys or cloud credentials. Silence means these specific local paths were not accessed."
      },
      "parents": [
        {
          "id": "discovery-burst"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Access to AI API tokens and configurations",
        "reads": [
          "device_hostname",
          "actor_user_name",
          "file_path",
          "process_name",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, actor_user_name, file_path, process_name, time FROM hb_file_activity WHERE (LOWER(file_path) LIKE '%.anthropic%' OR LOWER(file_path) LIKE '%.openai%' OR LOWER(file_path) LIKE '%.config/gcloud%' OR LOWER(file_path) LIKE '%.aws/credentials%') AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)",
        "silence": "not_evidence_of_absence",
        "expected": "Unauthorized or unusual processes reading AI API keys or cloud credentials. Silence means these specific local paths were not accessed.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "file_path"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "internal-scan-burst",
      "type": "query",
      "label": "High-velocity internal network scanning",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "network",
        "content": "SELECT device_hostname, src_endpoint_ip, COUNT(DISTINCT dst_endpoint_ip) AS unique_targets, COUNT(*) AS total_conns, MIN(time) AS first_seen FROM hb_network_connection WHERE direction = 'outbound' AND disposition = 'Allowed' AND (dst_endpoint_ip LIKE '10.%' OR dst_endpoint_ip LIKE '192.168.%' OR dst_endpoint_ip LIKE '172.16.%' OR dst_endpoint_ip LIKE '172.31.%') AND NOT (dst_endpoint_port IN (137, 138, 1900) AND protocol = 'udp') AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY device_hostname, src_endpoint_ip HAVING unique_targets > 20 ORDER BY unique_targets DESC",
        "surface": "hb_network_connection",
        "description": "Locate hosts attempting to connect to a high volume of unique internal targets, filtering out common service discovery noise.",
        "expected_signal": "A host contacting more than 20 unique internal IPs. This filters out NetBIOS and SSDP while highlighting scanning behavior."
      },
      "parents": [
        {
          "id": "discovery-burst"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "High-velocity internal network scanning",
        "reads": [
          "device_hostname",
          "src_endpoint_ip",
          "dst_endpoint_ip",
          "dst_endpoint_port",
          "protocol",
          "direction",
          "disposition",
          "time"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT device_hostname, src_endpoint_ip, COUNT(DISTINCT dst_endpoint_ip) AS unique_targets, COUNT(*) AS total_conns, MIN(time) AS first_seen FROM hb_network_connection WHERE direction = 'outbound' AND disposition = 'Allowed' AND (dst_endpoint_ip LIKE '10.%' OR dst_endpoint_ip LIKE '192.168.%' OR dst_endpoint_ip LIKE '172.16.%' OR dst_endpoint_ip LIKE '172.31.%') AND NOT (dst_endpoint_port IN (137, 138, 1900) AND protocol = 'udp') AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY device_hostname, src_endpoint_ip HAVING unique_targets > 20 ORDER BY unique_targets DESC",
        "silence": "not_evidence_of_absence",
        "expected": "A host contacting more than 20 unique internal IPs. This filters out NetBIOS and SSDP while highlighting scanning behavior.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "triage-acceleration",
      "type": "analytic",
      "label": "Evaluate machine-speed evidence",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "network"
        ],
        "context": [
          "discovery-burst",
          "ai-token-access",
          "internal-scan-burst"
        ],
        "objective": "Determine if the observed high-volume discovery bursts and network scanning, combined with any AI token access, indicates an automated attacker presence. Cite the specific command bursts and targets.",
        "description": "Correlate the discovery bursts, token access, and network scanning to determine if a host is under automated control.",
        "max_iterations": 4,
        "expected_signal": "A unified verdict for each host involved in the high-volume activity.",
        "success_criteria": "A verdict of malicious or suspicious for any host demonstrating the machine-speed post-exploitation pattern."
      },
      "parents": [
        {
          "id": "ai-token-access",
          "kind": "merge"
        },
        {
          "id": "internal-scan-burst",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-speed",
      "type": "checkpoint",
      "label": "Route on automated attack verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage verdict identifies an automated or high-speed post-exploitation event as malicious on at least one host",
        "condition": "the triage verdict identifies an automated or high-speed post-exploitation event as malicious on at least one host",
        "blind_spot": "limited-telemetry-retention",
        "confidence": "high",
        "description": "Directly respond to confirmed machine-speed attacks to minimize dwell time.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-acceleration"
        }
      ]
    },
    {
      "id": "isolate-compromised-host",
      "type": "action",
      "label": "Isolate high-speed beachhead",
      "config": {
        "target": "endpoint",
        "description": "Contain the automated attack before it moves to bulk encryption or data exfiltration.",
        "instructions": "Isolate the host reporting the discovery burst and scanning. Revoke any AI API tokens or cloud credentials found to have been accessed on the host.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-speed",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Review automated activity",
      "config": {
        "assignee": "analyst",
        "description": "Verify the agent's findings and identify the entry point used by the attacker to initiate the automated sequence.",
        "instructions": "Investigate the parent process of the discovery burst to find the initial execution vector (e.g., a web server exploit or phishing payload). Check for lateral movement attempts using any credentials accessed during the session."
      },
      "parents": [
        {
          "id": "route-on-speed",
          "branch": "default"
        },
        {
          "id": "route-on-speed",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-compromised-host"
        }
      ]
    },
    {
      "id": "remediation-closeout",
      "type": "task",
      "label": "Remediation and close-out",
      "config": {
        "assignee": "analyst",
        "description": "Document the findings and close the hunt if no malicious activity was confirmed.",
        "instructions": "Record the baseline discovery volume for future tuning. If high-volume activity was legitimate IT administration, whitelist the specific service account or script path used."
      },
      "parents": [
        {
          "id": "route-on-speed",
          "branch": "on_refutes"
        }
      ]
    }
  ]
}