← All hunts medium TLP:CLEAR Part 1 of 2

AI Agent and Social Engineering Initial Access

An adversary has gained initial access by using AI-generated phishing lures, malicious AI skills, or ClickFix social engineering where users paste malicious terminal commands.

Based on research by ESET Research 2026-09-29 12 steps · 5 queries T1190 T1195 T1203 T1566

Brief

Why Now

Adversaries are evolving faster than many security teams can track. The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive (https://www.welivesecurity.com/en/business-security/smb-cybersecurity-squeeze-ai-agents-work-old-attacks-overdrive/) details how attackers use AI to refine social engineering and exploit the trust users place in AI agents. Traditional alerts often miss these techniques because the actions look like user activity or standard cloud application integrations. This hunt provides a structured way to find these gaps.

Scoping and Early Leads

The hunt begins by identifying the most vulnerable part of the fleet. A scoping query lists hosts with critical unpatched vulnerabilities that attackers might target once they gain a foothold. This provides a focused list of hostnames to prioritize in the following steps. The next phase runs two checks in parallel. First, it monitors for ClickFix activity. This occurs when a browser process spawns a terminal like PowerShell or CMD. This behavior is highly unusual and often indicates a user was tricked into pasting a command to fix a fake browser error. Second, it searches M365 audit logs for new application or skill consents. Attackers use these to grant malicious AI agents access to corporate data.

Evidence Analysis

An analyst or automated agent then weighs these leads. If the hunt finds suspicious browser-to-terminal activity or new AI consents, it fans out to look for confirmation of a compromise. One query examines PowerShell script block logs for indicators like IEX, Get-Clipboard, or remote downloads. This reveals exactly what the user executed. Simultaneously, the hunt stacks outbound HTTP traffic to find rare domains. Many AI-driven attacks use infrastructure that appears briefly or uses domains generated by LLM hallucinations. By filtering for domains seen on only one or two hosts, the hunt surfaces potential command-and-control channels.

Blind Spots

This hunt relies heavily on PowerShell Script Block Logging (Event ID 4104). Without this logging, we can see that a terminal was launched, but we cannot see the deobfuscated commands used for persistence. In the cloud, if a malicious AI skill was consented to more than 90 days ago, it may fall outside the standard Unified Audit Log retention window.

In this series

Steps

  1. Identify hosts with critical vulnerabilities

    Query · scoping

    Scope the hunt by identifying hosts with high-severity vulnerabilities that are candidates for rapid exploitation, joining with hb_devices to provide hostnames for filtering.

    reads hb_vulnerability_findingsql
    SELECT d.hostname AS device_hostname, v.cve_uid, v.affected_package_name, v.affected_package_version, v.severity_id FROM hb_vulnerability_finding v JOIN hb_devices d ON v.device_uid = d.device_uid WHERE v.severity_id >= 4 AND v.status != 'suppressed' AND d.provider = v.provider

    What a hit looks like. A list of hostnames and their high-severity vulnerabilities. Silence implies no critical unpatched vulnerabilities are known to the scanner.

  2. Detect terminals launched with browser parents

    Query · detection candidate

    Identify ClickFix social engineering where a user pastes a command following a browser prompt.

    reads hb_process_activitysql
    SELECT device_hostname, process_name, process_cmd_line, parent_process_name, time FROM hb_process_activity WHERE instr(',' || '{{terminal_processes}}' || ',', ',' || LOWER(process_name) || ',') > 0 AND instr(',' || '{{browser_parents}}' || ',', ',' || LOWER(parent_process_name) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || LOWER(device_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. A terminal process spawned directly by a web browser. Silence is expected in a healthy environment.

  3. Identify new M365 AI application and skill consents

    Query · enrichment

    Find M365 Unified Audit Log events for application consents that may represent malicious AI skills.

    reads hb_cloud_api_activitysql
    SELECT actor_user_name, api_operation, resource_name, src_endpoint_ip, time FROM hb_cloud_api_activity WHERE provider = 'm365' AND (api_operation = 'ConsentToApplication' OR api_operation = 'Add app role assignment') AND (LOWER(resource_name) LIKE '%ai%' OR LOWER(resource_name) LIKE '%bot%' OR LOWER(resource_name) LIKE '%copilot%' OR LOWER(resource_name) LIKE '%skill%') AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Users granting permissions to AI-related applications or skills. This can identify the rug pull supply chain compromise.

  4. Weigh early-stage evidence

    Agent triage

    Analyze the scope, process leads, and M365 events to determine if an entry vector is present.

  5. Examine script block content for malicious indicators

    Query · triage

    Review the actual commands executed in terminal sessions, looking for ClickFix commands or data retrieval script blocks.

    reads hb_script_activitysql
    SELECT device_hostname, script_content, script_type, time FROM hb_script_activity WHERE (script_content LIKE '%Get-Clipboard%' OR script_content LIKE '%IEX%' OR script_content LIKE '%Invoke-Expression%' OR script_content LIKE '%curl%' OR script_content LIKE '%wget%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || LOWER(device_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Scripts that interact with the clipboard or perform remote downloads, typical of ClickFix lures.

  6. Identify rare outbound HTTP domains

    Query · baseline

    Stack-count outbound domain resolutions to find rare C2 domains or squatting domains invented by LLM hallucinations, focusing on suspect hosts.

    reads hb_http_activitysql
    SELECT url_hostname, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_http_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || LOWER(device_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY url_hostname HAVING host_count <= 2 ORDER BY host_count ASC

    What a hit looks like. Rare domains contacted by a small number of hosts. These often represent attacker-controlled infrastructure.

  7. Final compromise assessment

    Agent triage

    Correlate the entry vector leads with the follow-on script and network evidence.

  8. Route on compromise verdict

    Decision

    Determine whether to contain the host or review findings based on the agent's verdict.

  9. Isolate compromised host

    Response action

    Prevent further lateral movement or exfiltration after confirmed terminal execution.

  10. Manual Analyst Review

    Analyst task

    Investigate the specific commands and network activity to understand the scope of the compromise.

  11. Close out hunt

    Analyst task

    Finalize the hunt when no evidence of compromise is found.

Coverage

Scenario coverage

StageCoveredHow, or why not
AI-Enhanced Phishing and ClickFix
T1566
Yes clickfix-terminal-activity
AI Agent Supply Chain Compromise
T1195
Yes m365-ai-app-consents
Rapid Vulnerability Exploitation
T1190
Yes scoping-vulnerable-hosts
Indirect Prompt Injection and Terminal Execution
T1203
Yes script-execution-content
Credential Theft via Infostealer
T1555
Out of scope Belongs to another part of the 'The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive' series.
EDR Impairment via Vulnerable Drivers
T1562.001
Out of scope Belongs to another part of the 'The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive' series.
Data Encryption and Exfiltration
T1486 · T1041
Out of scope Belongs to another part of the 'The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive' series.

Blind spots

  • Needs hb_script_activity (PowerShell Script Block Logging / Windows Event ID 4104). Without script logging, the hunt can identify that a terminal was launched, but cannot see the deobfuscated commands used for persistence or exfiltration. It would answer What specific code was executed when a user pasted a command into the terminal?.
  • Needs hb_cloud_api_activity (Unified Audit Log). If the consent happened outside the retention window (typically 90 days), the initial access event will be invisible. It would answer When was the malicious skill first consented to?.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
browser_parentslist[string]chrome.exe, msedge.exe, firefox.exe, brave.exeBrowser process names that should not typically be direct parents of terminals.
lookback_daysnumber14Days of history to examine.
scope_hostslist[host]—Optional list of hostnames to scope the hunt; leave empty for fleet-wide.
terminal_processeslist[string]powershell.exe, pwsh.exe, cmd.exe, bash, shProcess names for terminal environments commonly abused in ClickFix.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint
Web server / proxy logssiemnetwork

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: A simple rule might alert on PowerShell launching from Chrome, but this
  hunt pivots to script content and uses stack-counting on HTTP traffic to identify
  rare domains that likely represent C2 or squatting infrastructure invented by LLMs.
blind_spots:
- id: no-script-logging
  question: What specific code was executed when a user pasted a command into the
    terminal?
  requires: hb_script_activity (PowerShell Script Block Logging / Windows Event ID
    4104)
  risk: Without script logging, the hunt can identify that a terminal was launched,
    but cannot see the deobfuscated commands used for persistence or exfiltration.
  stage: execution-indirect-prompt-injection
- id: ual-retention
  question: When was the malicious skill first consented to?
  requires: hb_cloud_api_activity (Unified Audit Log)
  risk: If the consent happened outside the retention window (typically 90 days),
    the initial access event will be invisible.
  stage: initial-access-malicious-ai-skills
coverage:
- stage: phishing-ai-enhanced-social-engineering
  status: covered
  steps:
  - clickfix-terminal-activity
- stage: initial-access-malicious-ai-skills
  status: covered
  steps:
  - m365-ai-app-consents
- stage: exploit-public-facing-rapid-cve
  status: covered
  steps:
  - scoping-vulnerable-hosts
- stage: execution-indirect-prompt-injection
  status: covered
  steps:
  - script-execution-content
- reason: 'Belongs to another part of the ''The SMB cybersecurity squeeze: AI agents
    at work, old attacks in overdrive'' series.'
  stage: credential-access-password-stores
  status: out_of_scope
- reason: 'Belongs to another part of the ''The SMB cybersecurity squeeze: AI agents
    at work, old attacks in overdrive'' series.'
  stage: evasion-vulnerable-driver-edr-killer
  status: out_of_scope
- reason: 'Belongs to another part of the ''The SMB cybersecurity squeeze: AI agents
    at work, old attacks in overdrive'' series.'
  stage: impact-ransomware-data-exfiltration
  status: out_of_scope
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: keep-as-periodic-hunt
  justification: AI-enhanced phishing and social engineering (ClickFix) are reaching
    high click-through rates. Detecting these before they result in full ransomware
    deployment or data theft is a critical operational need for resource-strapped
    SMBs.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An adversary has gained initial access by using AI-generated phishing
  lures, malicious AI skills, or ClickFix social engineering where users paste malicious
  terminal commands.
labels:
- hunt
- attack.t1566
- attack.t1195
- attack.t1190
- attack.t1203
- credential access
- defense evasion
- execution
- impact
- initial access
- m365
name: AI Agent and Social Engineering Initial Access
parameters:
  browser_parents:
    default:
    - chrome.exe
    - msedge.exe
    - firefox.exe
    - brave.exe
    description: Browser process names that should not typically be direct parents
      of terminals.
    type: list[string]
  lookback_days:
    default: '14'
    description: Days of history to examine.
    type: number
  scope_hosts:
    default: []
    description: Optional list of hostnames to scope the hunt; leave empty for fleet-wide.
    type: list[host]
  terminal_processes:
    default:
    - powershell.exe
    - pwsh.exe
    - cmd.exe
    - bash
    - sh
    description: Process names for terminal environments commonly abused in ClickFix.
    type: list[string]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.welivesecurity.com/en/business-security/smb-cybersecurity-squeeze-ai-agents-work-old-attacks-overdrive/
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Start with internet-facing web servers and hosts identified with critical
  vulnerabilities. Monitor users with high-privilege access to M365 who may be targeted
  for AI skill rug pull attacks.
references:
- name: 'The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive'
  url: https://www.welivesecurity.com/en/business-security/smb-cybersecurity-squeeze-ai-agents-work-old-attacks-overdrive/
related:
- hunt: credential-access-password-stores
  reason: Password storage theft is a post-compromise activity that follows the initial
    access hunted here.
  relation: out-of-scope-alternative
scenario:
  stages:
  - name: AI-Enhanced Phishing and ClickFix
    observables:
    - QR codes in phishing emails
    - Fake AI troubleshooting error messages
    - AI-generated lures with high click-through rates
    - ClickFix prompts asking users to paste commands
    slug: phishing-ai-enhanced-social-engineering
    tactic: initial-access
    techniques:
    - T1566
  - name: AI Agent Supply Chain Compromise
    observables:
    - Installation of malicious 'skills' from public repositories
    - Malicious MCP (Model Context Protocol) server connections
    - AI agent 'rug pull' behavior where a tool morphs into an infostealer
    slug: initial-access-malicious-ai-skills
    tactic: initial-access
    techniques:
    - T1195
  - name: Rapid Vulnerability Exploitation
    observables:
    - Exploitation of known vulnerabilities on or before disclosure day
    - Scanning for vulnerable software libraries invented by LLM hallucinations
    slug: exploit-public-facing-rapid-cve
    tactic: initial-access
    techniques:
    - T1190
  - name: Indirect Prompt Injection and Terminal Execution
    observables:
    - EchoLeak-style data exposure in Microsoft 365 Copilot
    - Users pasting commands into terminals following ClickFix lures
    - Malicious instructions retrieved by agents from webpages or emails
    slug: execution-indirect-prompt-injection
    tactic: execution
    techniques:
    - T1203
  - name: Credential Theft via Infostealer
    observables:
    - Access to browser password databases
    - Phishing-as-a-service kits capturing login credentials
    - Infostealer malware execution
    slug: credential-access-password-stores
    tactic: credential-access
    techniques:
    - T1555
  - name: EDR Impairment via Vulnerable Drivers
    observables:
    - Loading of known vulnerable drivers (BYOVD)
    - Tools designed to kill EDR processes
    - Abuse of legitimate drivers to gain kernel-level access
    slug: evasion-vulnerable-driver-edr-killer
    tactic: defense-evasion
    techniques:
    - T1562.001
  - name: Data Encryption and Exfiltration
    observables:
    - PromptLock ransomware execution
    - Encryption of files on local or shared drives
    - Exfiltration of sensitive data via AI agent tools
    - C2 traffic to attacker-controlled domains
    slug: impact-ransomware-data-exfiltration
    tactic: impact
    techniques:
    - T1486
    - T1041
  summary: AI agents are being compromised via malicious supply chain skills and indirect
    prompt injection, while traditional threats like phishing and vulnerability exploitation
    are accelerated by AI-driven automation. Adversaries are increasingly using 'Bring
    Your Own Vulnerable Driver' (BYOVD) techniques to disable EDR tools before deploying
    ransomware or exfiltrating credentials.
series:
  index: 1
  slug: the-smb-cybersecurity-squeeze-ai-agents-at-work-old-attacks-in-overdrive
  title: 'The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive'
  total: 2
severity: medium
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  web:
    category: siem
    name: Web server / proxy logs
    telemetry:
    - network
tlp: clear
type: investigation
---


# AI Agent and Social Engineering Initial Access

This hunt follows a phased flow to detect AI-enhanced initial access. It first identifies vulnerable hosts and monitors for signs of user-driven command execution (ClickFix) or unauthorized AI agent registrations in M365. An early-stage agent weighs these indicators before fanning out to examine the specific script content and outbound network traffic for signs of successful exploitation and command-and-control. This approach targets the lethal trifecta of agentic security: data access, external exposure, and communication permissions.

## scoping-vulnerable-hosts
<!-- Identify hosts with critical vulnerabilities -->
Scope the hunt by identifying hosts with high-severity vulnerabilities that are candidates for rapid exploitation, joining with hb_devices to provide hostnames for filtering.

```sqlite target=endpoint role=scoping
~~~yaml
expected: A list of hostnames and their high-severity vulnerabilities. Silence implies
  no critical unpatched vulnerabilities are known to the scanner.
reads:
- device_uid
- cve_uid
- affected_package_name
- affected_package_version
- severity_id
- status
- provider
silence: not_evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT d.hostname AS device_hostname, v.cve_uid, v.affected_package_name, v.affected_package_version, v.severity_id FROM hb_vulnerability_finding v JOIN hb_devices d ON v.device_uid = d.device_uid WHERE v.severity_id >= 4 AND v.status != 'suppressed' AND d.provider = v.provider
```

## early-access-leads
<!-- Monitor for terminal execution and AI agent registration -->
parallel:
- → clickfix-terminal-activity
- → m365-ai-app-consents
join: → early-stage-read

## clickfix-terminal-activity
<!-- Detect terminals launched with browser parents -->
Identify ClickFix social engineering where a user pastes a command following a browser prompt.

```sqlite target=endpoint role=detection-candidate params=(terminal_processes=terminal_processes, browser_parents=browser_parents, scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: A terminal process spawned directly by a web browser. Silence is expected
  in a healthy environment.
reads:
- device_hostname
- process_name
- process_cmd_line
- parent_process_name
- time
silence: evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, process_name, process_cmd_line, parent_process_name, time FROM hb_process_activity WHERE instr(',' || '{{terminal_processes}}' || ',', ',' || LOWER(process_name) || ',') > 0 AND instr(',' || '{{browser_parents}}' || ',', ',' || LOWER(parent_process_name) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || LOWER(device_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## m365-ai-app-consents
<!-- Identify new M365 AI application and skill consents -->
Find M365 Unified Audit Log events for application consents that may represent malicious AI skills.

```sqlite target=endpoint role=enrichment params=(lookback_days=lookback_days)
~~~yaml
expected: Users granting permissions to AI-related applications or skills. This can
  identify the rug pull supply chain compromise.
reads:
- actor_user_name
- api_operation
- resource_name
- src_endpoint_ip
- time
- provider
silence: not_evidence_of_absence
source: hb_cloud_api_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT actor_user_name, api_operation, resource_name, src_endpoint_ip, time FROM hb_cloud_api_activity WHERE provider = 'm365' AND (api_operation = 'ConsentToApplication' OR api_operation = 'Add app role assignment') AND (LOWER(resource_name) LIKE '%ai%' OR LOWER(resource_name) LIKE '%bot%' OR LOWER(resource_name) LIKE '%copilot%' OR LOWER(resource_name) LIKE '%skill%') AND time >= datetime('now', '-{{lookback_days}} days')
```

## early-stage-read
<!-- Weigh early-stage evidence -->
```agent target=hunter
cite: required
context:
- scoping-vulnerable-hosts
- clickfix-terminal-activity
- m365-ai-app-consents
max_iterations: 3
objective: Determine if the process and cloud activities indicate a credible initial
  access attempt via social engineering or AI supply chain compromise.
success_criteria: Verdicts (malicious | suspicious | benign) for each host and user
  identified in the leads.
tools:
- endpoint
- web
```

## follow-on-activity
<!-- Hunt for script execution and outbound C2 -->
parallel:
- → script-execution-content
- → outbound-http-prevalence
join: → follow-on-read

## script-execution-content
<!-- Examine script block content for malicious indicators -->
Review the actual commands executed in terminal sessions, looking for ClickFix commands or data retrieval script blocks.

```sqlite target=endpoint role=triage params=(scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: Scripts that interact with the clipboard or perform remote downloads, typical
  of ClickFix lures.
reads:
- device_hostname
- script_content
- script_type
- time
silence: not_evidence_of_absence
source: hb_script_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, script_content, script_type, time FROM hb_script_activity WHERE (script_content LIKE '%Get-Clipboard%' OR script_content LIKE '%IEX%' OR script_content LIKE '%Invoke-Expression%' OR script_content LIKE '%curl%' OR script_content LIKE '%wget%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || LOWER(device_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## outbound-http-prevalence
<!-- Identify rare outbound HTTP domains -->
Stack-count outbound domain resolutions to find rare C2 domains or squatting domains invented by LLM hallucinations, focusing on suspect hosts.

```sqlite target=web role=baseline params=(scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: Rare domains contacted by a small number of hosts. These often represent
  attacker-controlled infrastructure.
prevalence:
  by: device_hostname
  key:
  - url_hostname
  rare_below: 3
reads:
- url_hostname
- device_hostname
- time
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT url_hostname, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_http_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || LOWER(device_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY url_hostname HAVING host_count <= 2 ORDER BY host_count ASC
```

## follow-on-read
<!-- Final compromise assessment -->
```agent target=hunter
cite: required
context:
- early-stage-read
- script-execution-content
- outbound-http-prevalence
max_iterations: 5
objective: Confirm whether the early-stage leads resulted in successful execution
  or data exfiltration based on the script and HTTP activity.
success_criteria: A final verdict citing specific script commands and rare domain
  connections.
tools:
- endpoint
- web
```

## compromise-decision
<!-- Route on compromise verdict -->
if~: "The final compromise assessment indicates a malicious verdict with evidence of terminal execution or data exfiltration." (confidence: high, judge=hunter)
then: → isolate-host
indeterminate: → analyst-manual-review
unavailable: → analyst-manual-review (blind_spot: no-script-logging)
else: → close-out

## isolate-host
<!-- Isolate compromised host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host immediately. Revoke any M365 session tokens associated with users identified in the cloud audit logs.
```
→ analyst-manual-review

## analyst-manual-review
<!-- Manual Analyst Review -->
```manual target=analyst
Examine the script_content from hb_script_activity for the confirmed hosts. Verify the legitimacy of the rare domains identified. Check for signs of lateral movement originating from the beachhead.
```
→ end

## close-out
<!-- Close out hunt -->
```manual target=analyst
Record the findings. If suspicious ClickFix patterns were found but not confirmed, consider a user awareness training session. Tune detection rules if any benign browser-to-terminal patterns were seen.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.