---
analysis: A single detection rule for whoami is noisy and frequently ignored; this
  hunt pivots between the burst volume of discovery within hour buckets, specific
  AI token file access, and high-velocity internal network connections to provide
  the aggregate context that distinguishes an automated agent from a human administrator.
blind_spots:
- id: limited-telemetry-retention
  question: Did the automated discovery sequence begin before the current 14-day window?
  requires: extended retention for process and network events
  risk: A slowly-initiated AI agent that then speeds up would have its origin outside
    the lookback window.
  stage: automated-internal-discovery
- id: environment-variable-tokens
  question: Are AI API tokens being stolen from environment variables rather than
    on-disk configuration files?
  requires: hb_process_activity with environment variable capture
  risk: Attackers can scrape tokens from process memory or environment blocks without
    touching the .config files targeted by the file activity query.
  stage: credential-and-token-theft
coverage:
- stage: automated-internal-discovery
  status: covered
  steps:
  - discovery-burst
  - internal-scan-burst
- stage: credential-and-token-theft
  status: covered
  steps:
  - ai-token-access
- reason: The precise AI-assisted scanning of files for PII (Read activity) requires
    high-fidelity file-read logs which often exceed the noise floor of generic hb_file_activity;
    we focus on the precursor token theft instead.
  stage: rapid-data-triage-and-encryption
  status: not_visible
- reason: "Belongs to another part of the 'AI Attacks Move Faster. Huntress\u2019\
    \ Agentic SOC Keeps Up' series."
  stage: ai-enhanced-phishing
  status: out_of_scope
- reason: "Belongs to another part of the 'AI Attacks Move Faster. Huntress\u2019\
    \ Agentic SOC Keeps Up' series."
  stage: external-service-compromise
  status: out_of_scope
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: promote-to-detection
  justification: As attackers use AI to compress the dwell-time between initial access
    and extortion, defenders must hunt for volume-based anomalies that precede bulk
    encryption; a negative result confirms the estate is not currently undergoing
    a machine-speed automated breach.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An intruder is using AI-driven automation to conduct rapid internal reconnaissance,
  steal AI service tokens, and triage sensitive files for extortion at machine speed.
labels:
- hunt
- attack.t1003
- attack.t1083
- attack.t1018
- attack.t1486
- attack.t1566
name: AI-Accelerated Post-Exploitation and Extortion
parameters:
  discovery_commands:
    default:
    - whoami.exe
    - net.exe
    - ipconfig.exe
    - quser.exe
    - nltest.exe
    - systeminfo.exe
    - netstat.exe
    - tasklist.exe
    - arp.exe
    description: Standard discovery executables that indicate automated reconnaissance
      when run in a burst.
    from:
      kind: manual
      observed: '2026-09-22'
      ref: common discovery tool list
    type: list[string]
  lookback_days:
    default: '14'
    description: Days of history to examine.
    from:
      kind: article
      observed: '2026-09-22'
      ref: https://www.huntress.com/blog/ai-attackers-machine-speed-huntress-athena
    type: number
  scope_hosts:
    default: []
    description: Narrow the hunt to specific high-value targets; leave empty for fleet-wide.
    from:
      kind: manual
      observed: '2026-09-22'
      ref: analyst-defined scope
    type: list[host]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.huntress.com/blog/ai-attackers-machine-speed-huntress-athena
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Focus on developer workstations, AI engineering environments, and cloud
  administration hosts where API tokens for Anthropic, OpenAI, or AWS are likely to
  reside.
references:
- name: "Huntress \u2014 AI Attackers Move Faster. Huntress\u2019 Agentic SOC Keeps\
    \ Up"
  url: https://www.huntress.com/blog/ai-attackers-machine-speed-huntress-athena
related:
- hunt: discovery-tool-execution
  reason: This hunt focuses on the speed and volume of discovery rather than the mere
    presence of common tools.
  relation: out-of-scope-alternative
- hunt: machine-speed-perimeter-identity-ingress
  relation: follows
scenario:
  stages:
  - name: AI-Enhanced Phishing and Social Engineering
    observables:
    - Phishing emails with AI-refined language
    - Video calls with AI-altered faces (deepfakes)
    - Compromised accounts used for high-volume phishing
    slug: ai-enhanced-phishing
    tactic: initial-access
    techniques:
    - T1566
  - name: Compromise of External Remote Services
    observables:
    - Anomalous VPN authentications without MFA
    - Connections from unusual geolocations via VPN
    - Exploitation of vulnerable network appliances or firewalls
    - Exposed services on ports 443 or 1194
    slug: external-service-compromise
    tactic: initial-access
    techniques:
    - T1133
    - T1190
  - name: Automated Internal Reconnaissance
    observables:
    - High-speed internal network scanning and enumeration
    - Rapid execution of system discovery commands
    - Unusual outbound internal traffic patterns from recently accessed hosts
    slug: automated-internal-discovery
    tactic: discovery
    techniques:
    - T1083
    - T1018
  - name: Credential Dumping and Session Token Theft
    observables:
    - Theft of API keys and session tokens for AI models (e.g., Anthropic, OpenAI)
    - Memory dumping of lsass.exe
    - Loading of dbghelp.dll or dbgcore.dll from non-standard paths
    - Access to local credential stores or browser profile directories
    slug: credential-and-token-theft
    tactic: credential-access
    techniques:
    - T1003
  - name: Automated Data Triage and Impact
    observables:
    - AI-assisted scanning of files for PII, PHI, or intellectual property
    - Rapid traversal of file shares and local directories
    - Bulk file encryption and renaming (ransomware activity)
    - Execution of scripts or binaries for automated data classification
    slug: rapid-data-triage-and-encryption
    tactic: impact
    techniques:
    - T1486
  summary: Attackers are utilizing AI to accelerate traditional tradecraft, moving
    from initial access via compromised VPNs or firewalls to rapid internal discovery
    and automated data triage. While AI enhances the speed of reconnaissance and phishing,
    the core post-exploitation behaviors such as credential dumping and lateral movement
    remain observable through endpoint and identity telemetry.
series:
  index: 2
  slug: ai-attacks-move-faster-huntress-agentic-soc-keeps-up
  title: "AI Attacks Move Faster. Huntress\u2019 Agentic SOC Keeps Up"
  total: 2
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  network:
    category: network
    name: Network telemetry
    telemetry:
    - network
tlp: clear
type: investigation
---


# AI-Accelerated Post-Exploitation and Extortion

Adversaries are increasingly using AI agents to accelerate traditional post-exploitation tradecraft. This hunt targets the machine speed signals of these attacks: bursts of system discovery commands in short time windows, the theft of AI-specific API tokens (Anthropic/OpenAI) used for further automation, and high-volume internal scanning. By focusing on volume and velocity rather than just the presence of a tool, we identify compromises that would otherwise move faster than manual triage cycles.

## discovery-burst
<!-- Rapid automated discovery bursts -->
Identify hosts where a high number of discovery commands executed in a short window, distinguishing AI-accelerated bursts from high aggregate activity.

```sqlite target=endpoint role=detection-candidate params=(lookback_days=lookback_days, discovery_commands=discovery_commands, scope_hosts=scope_hosts)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: A single user or host running 5+ discovery commands within a single hour;
  isolated instances are typically administrative, while hourly bursts suggest a script
  or agent.
reads:
- device_hostname
- user_name
- process_name
- process_original_file_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, user_name, STRFTIME('%Y-%m-%d %H:00:00', time) AS hour_bucket, COUNT(*) AS cmd_count, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_process_activity WHERE (instr(',' || '{{discovery_commands}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || '{{discovery_commands}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY device_hostname, user_name, hour_bucket HAVING cmd_count >= 5 ORDER BY cmd_count DESC
```

## parallel-signals
<!-- Corroborate with token theft and network scanning -->
parallel:
- → ai-token-access
- → internal-scan-burst
join: → triage-acceleration

## ai-token-access
<!-- Access to AI API tokens and configurations -->
Find file access events targeting the AI model configuration directories mentioned in recent misuse reports.

```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: Unauthorized or unusual processes reading AI API keys or cloud credentials.
  Silence means these specific local paths were not accessed.
prevalence:
  by: device_hostname
  key:
  - file_path
  rare_below: 3
reads:
- device_hostname
- actor_user_name
- file_path
- process_name
- time
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, actor_user_name, file_path, process_name, time FROM hb_file_activity WHERE (LOWER(file_path) LIKE '%.anthropic%' OR LOWER(file_path) LIKE '%.openai%' OR LOWER(file_path) LIKE '%.config/gcloud%' OR LOWER(file_path) LIKE '%.aws/credentials%') AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)
```

## internal-scan-burst
<!-- High-velocity internal network scanning -->
Locate hosts attempting to connect to a high volume of unique internal targets, filtering out common service discovery noise.

```sqlite target=network role=triage params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: A host contacting more than 20 unique internal IPs. This filters out NetBIOS
  and SSDP while highlighting scanning behavior.
reads:
- device_hostname
- src_endpoint_ip
- dst_endpoint_ip
- dst_endpoint_port
- protocol
- direction
- disposition
- time
silence: not_evidence_of_absence
source: hb_network_connection
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, src_endpoint_ip, COUNT(DISTINCT dst_endpoint_ip) AS unique_targets, COUNT(*) AS total_conns, MIN(time) AS first_seen FROM hb_network_connection WHERE direction = 'outbound' AND disposition = 'Allowed' AND (dst_endpoint_ip LIKE '10.%' OR dst_endpoint_ip LIKE '192.168.%' OR dst_endpoint_ip LIKE '172.16.%' OR dst_endpoint_ip LIKE '172.31.%') AND NOT (dst_endpoint_port IN (137, 138, 1900) AND protocol = 'udp') AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY device_hostname, src_endpoint_ip HAVING unique_targets > 20 ORDER BY unique_targets DESC
```

## triage-acceleration
<!-- Evaluate machine-speed evidence -->
```agent target=hunter
cite: required
context:
- discovery-burst
- ai-token-access
- internal-scan-burst
max_iterations: 4
objective: Determine if the observed high-volume discovery bursts and network scanning,
  combined with any AI token access, indicates an automated attacker presence. Cite
  the specific command bursts and targets.
success_criteria: A verdict of malicious or suspicious for any host demonstrating
  the machine-speed post-exploitation pattern.
tools:
- endpoint
- network
```

## route-on-speed
<!-- Route on automated attack verdict -->
if~: "the triage verdict identifies an automated or high-speed post-exploitation event as malicious on at least one host" (confidence: high, judge=hunter)
then: → isolate-compromised-host
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: limited-telemetry-retention)
else: → remediation-closeout

## isolate-compromised-host
<!-- Isolate high-speed beachhead -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host reporting the discovery burst and scanning. Revoke any AI API tokens or cloud credentials found to have been accessed on the host.
```
→ analyst-review

## analyst-review
<!-- Review automated activity -->
```manual target=analyst
Investigate the parent process of the discovery burst to find the initial execution vector (e.g., a web server exploit or phishing payload). Check for lateral movement attempts using any credentials accessed during the session.
```
→ end

## remediation-closeout
<!-- Remediation and close-out -->
```manual target=analyst
Record the baseline discovery volume for future tuning. If high-volume activity was legitimate IT administration, whitelist the specific service account or script path used.
```
→ end
