{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "AI-enhanced phishing and social engineering (ClickFix) are reaching high click-through rates. Detecting these before they result in full ransomware deployment or data theft is a critical operational need for resource-strapped SMBs."
      },
      "name": "AI Agent and Social Engineering Initial Access",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1566",
        "attack.t1195",
        "attack.t1190",
        "attack.t1203",
        "credential access",
        "defense evasion",
        "execution",
        "impact",
        "initial access",
        "m365"
      ],
      "series": {
        "slug": "the-smb-cybersecurity-squeeze-ai-agents-at-work-old-attacks-in-overdrive",
        "index": 1,
        "title": "The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive",
        "total": 2
      },
      "related": [
        {
          "hunt": "credential-access-password-stores",
          "reason": "Password storage theft is a post-compromise activity that follows the initial access hunted here.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A simple rule might alert on PowerShell launching from Chrome, but this hunt pivots to script content and uses stack-counting on HTTP traffic to identify rare domains that likely represent C2 or squatting infrastructure invented by LLMs.",
      "coverage": [
        {
          "stage": "phishing-ai-enhanced-social-engineering",
          "steps": [
            "clickfix-terminal-activity"
          ],
          "status": "covered"
        },
        {
          "stage": "initial-access-malicious-ai-skills",
          "steps": [
            "m365-ai-app-consents"
          ],
          "status": "covered"
        },
        {
          "stage": "exploit-public-facing-rapid-cve",
          "steps": [
            "scoping-vulnerable-hosts"
          ],
          "status": "covered"
        },
        {
          "stage": "execution-indirect-prompt-injection",
          "steps": [
            "script-execution-content"
          ],
          "status": "covered"
        },
        {
          "stage": "credential-access-password-stores",
          "reason": "Belongs to another part of the 'The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "evasion-vulnerable-driver-edr-killer",
          "reason": "Belongs to another part of the 'The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "impact-ransomware-data-exfiltration",
          "reason": "Belongs to another part of the 'The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "AI-Enhanced Phishing and ClickFix",
            "slug": "phishing-ai-enhanced-social-engineering",
            "tactic": "initial-access",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "QR codes in phishing emails",
              "Fake AI troubleshooting error messages",
              "AI-generated lures with high click-through rates",
              "ClickFix prompts asking users to paste commands"
            ]
          },
          {
            "name": "AI Agent Supply Chain Compromise",
            "slug": "initial-access-malicious-ai-skills",
            "tactic": "initial-access",
            "techniques": [
              "T1195"
            ],
            "observables": [
              "Installation of malicious 'skills' from public repositories",
              "Malicious MCP (Model Context Protocol) server connections",
              "AI agent 'rug pull' behavior where a tool morphs into an infostealer"
            ]
          },
          {
            "name": "Rapid Vulnerability Exploitation",
            "slug": "exploit-public-facing-rapid-cve",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "Exploitation of known vulnerabilities on or before disclosure day",
              "Scanning for vulnerable software libraries invented by LLM hallucinations"
            ]
          },
          {
            "name": "Indirect Prompt Injection and Terminal Execution",
            "slug": "execution-indirect-prompt-injection",
            "tactic": "execution",
            "techniques": [
              "T1203"
            ],
            "observables": [
              "EchoLeak-style data exposure in Microsoft 365 Copilot",
              "Users pasting commands into terminals following ClickFix lures",
              "Malicious instructions retrieved by agents from webpages or emails"
            ]
          },
          {
            "name": "Credential Theft via Infostealer",
            "slug": "credential-access-password-stores",
            "tactic": "credential-access",
            "techniques": [
              "T1555"
            ],
            "observables": [
              "Access to browser password databases",
              "Phishing-as-a-service kits capturing login credentials",
              "Infostealer malware execution"
            ]
          },
          {
            "name": "EDR Impairment via Vulnerable Drivers",
            "slug": "evasion-vulnerable-driver-edr-killer",
            "tactic": "defense-evasion",
            "techniques": [
              "T1562.001"
            ],
            "observables": [
              "Loading of known vulnerable drivers (BYOVD)",
              "Tools designed to kill EDR processes",
              "Abuse of legitimate drivers to gain kernel-level access"
            ]
          },
          {
            "name": "Data Encryption and Exfiltration",
            "slug": "impact-ransomware-data-exfiltration",
            "tactic": "impact",
            "techniques": [
              "T1486",
              "T1041"
            ],
            "observables": [
              "PromptLock ransomware execution",
              "Encryption of files on local or shared drives",
              "Exfiltration of sensitive data via AI agent tools",
              "C2 traffic to attacker-controlled domains"
            ]
          }
        ],
        "summary": "AI agents are being compromised via malicious supply chain skills and indirect prompt injection, while traditional threats like phishing and vulnerability exploitation are accelerated by AI-driven automation. Adversaries are increasingly using 'Bring Your Own Vulnerable Driver' (BYOVD) techniques to disable EDR tools before deploying ransomware or exfiltrating credentials."
      },
      "severity": "medium",
      "rationale": "Start with internet-facing web servers and hosts identified with critical vulnerabilities. Monitor users with high-privilege access to M365 who may be targeted for AI skill rug pull attacks.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary has gained initial access by using AI-generated phishing lures, malicious AI skills, or ClickFix social engineering where users paste malicious terminal commands.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Optional list of hostnames to scope the hunt; leave empty for fleet-wide."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "browser_parents": {
          "type": "list[string]",
          "default": [
            "chrome.exe",
            "msedge.exe",
            "firefox.exe",
            "brave.exe"
          ],
          "description": "Browser process names that should not typically be direct parents of terminals."
        },
        "terminal_processes": {
          "type": "list[string]",
          "default": [
            "powershell.exe",
            "pwsh.exe",
            "cmd.exe",
            "bash",
            "sh"
          ],
          "description": "Process names for terminal environments commonly abused in ClickFix."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.welivesecurity.com/en/business-security/smb-cybersecurity-squeeze-ai-agents-work-old-attacks-overdrive/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.welivesecurity.com/en/business-security/smb-cybersecurity-squeeze-ai-agents-work-old-attacks-overdrive/",
          "name": "The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive"
        }
      ],
      "blind_spots": [
        {
          "id": "no-script-logging",
          "risk": "Without script logging, the hunt can identify that a terminal was launched, but cannot see the deobfuscated commands used for persistence or exfiltration.",
          "stage": "execution-indirect-prompt-injection",
          "question": "What specific code was executed when a user pasted a command into the terminal?",
          "requires": "hb_script_activity (PowerShell Script Block Logging / Windows Event ID 4104)"
        },
        {
          "id": "ual-retention",
          "risk": "If the consent happened outside the retention window (typically 90 days), the initial access event will be invisible.",
          "stage": "initial-access-malicious-ai-skills",
          "question": "When was the malicious skill first consented to?",
          "requires": "hb_cloud_api_activity (Unified Audit Log)"
        }
      ]
    },
    "name": "AI Agent and Social Engineering Initial Access",
    "description": "This hunt follows a phased flow to detect AI-enhanced initial access. It first identifies vulnerable hosts and monitors for signs of user-driven command execution (ClickFix) or unauthorized AI agent registrations in M365. An early-stage agent weighs these indicators before fanning out to examine the specific script content and outbound network traffic for signs of successful exploitation and command-and-control. This approach targets the lethal trifecta of agentic security: data access, external exposure, and communication permissions."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "the-smb-cybersecurity-squeeze-ai-agents-at-work-old-attacks-in-overdrive",
          "index": 1,
          "title": "The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive",
          "total": 2
        },
        "coverage": [
          {
            "stage": "phishing-ai-enhanced-social-engineering",
            "steps": [
              "clickfix-terminal-activity"
            ],
            "status": "covered"
          },
          {
            "stage": "initial-access-malicious-ai-skills",
            "steps": [
              "m365-ai-app-consents"
            ],
            "status": "covered"
          },
          {
            "stage": "exploit-public-facing-rapid-cve",
            "steps": [
              "scoping-vulnerable-hosts"
            ],
            "status": "covered"
          },
          {
            "stage": "execution-indirect-prompt-injection",
            "steps": [
              "script-execution-content"
            ],
            "status": "covered"
          },
          {
            "stage": "credential-access-password-stores",
            "reason": "Belongs to another part of the 'The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "evasion-vulnerable-driver-edr-killer",
            "reason": "Belongs to another part of the 'The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "impact-ransomware-data-exfiltration",
            "reason": "Belongs to another part of the 'The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary has gained initial access by using AI-generated phishing lures, malicious AI skills, or ClickFix social engineering where users paste malicious terminal commands.",
        "blind_spots": [
          {
            "id": "no-script-logging",
            "risk": "Without script logging, the hunt can identify that a terminal was launched, but cannot see the deobfuscated commands used for persistence or exfiltration.",
            "stage": "execution-indirect-prompt-injection",
            "question": "What specific code was executed when a user pasted a command into the terminal?",
            "requires": "hb_script_activity (PowerShell Script Block Logging / Windows Event ID 4104)"
          },
          {
            "id": "ual-retention",
            "risk": "If the consent happened outside the retention window (typically 90 days), the initial access event will be invisible.",
            "stage": "initial-access-malicious-ai-skills",
            "question": "When was the malicious skill first consented to?",
            "requires": "hb_cloud_api_activity (Unified Audit Log)"
          }
        ],
        "scoping_notes": "Start with internet-facing web servers and hosts identified with critical vulnerabilities. Monitor users with high-privilege access to M365 who may be targeted for AI skill rug pull attacks.",
        "beyond_detection": "A simple rule might alert on PowerShell launching from Chrome, but this hunt pivots to script content and uses stack-counting on HTTP traffic to identify rare domains that likely represent C2 or squatting infrastructure invented by LLMs."
      }
    },
    {
      "id": "scoping-vulnerable-hosts",
      "type": "query",
      "label": "Identify hosts with critical vulnerabilities",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT d.hostname AS device_hostname, v.cve_uid, v.affected_package_name, v.affected_package_version, v.severity_id FROM hb_vulnerability_finding v JOIN hb_devices d ON v.device_uid = d.device_uid WHERE v.severity_id >= 4 AND v.status != 'suppressed' AND d.provider = v.provider",
        "surface": "hb_vulnerability_finding",
        "description": "Scope the hunt by identifying hosts with high-severity vulnerabilities that are candidates for rapid exploitation, joining with hb_devices to provide hostnames for filtering.",
        "expected_signal": "A list of hostnames and their high-severity vulnerabilities. Silence implies no critical unpatched vulnerabilities are known to the scanner."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify hosts with critical vulnerabilities",
        "reads": [
          "device_uid",
          "cve_uid",
          "affected_package_name",
          "affected_package_version",
          "severity_id",
          "status",
          "provider"
        ],
        "source": "hb_vulnerability_finding",
        "target": "endpoint",
        "content": "SELECT d.hostname AS device_hostname, v.cve_uid, v.affected_package_name, v.affected_package_version, v.severity_id FROM hb_vulnerability_finding v JOIN hb_devices d ON v.device_uid = d.device_uid WHERE v.severity_id >= 4 AND v.status != 'suppressed' AND d.provider = v.provider",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hostnames and their high-severity vulnerabilities. Silence implies no critical unpatched vulnerabilities are known to the scanner.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "clickfix-terminal-activity",
      "type": "query",
      "label": "Detect terminals launched with browser parents",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, parent_process_name, time FROM hb_process_activity WHERE instr(',' || '{{terminal_processes}}' || ',', ',' || LOWER(process_name) || ',') > 0 AND instr(',' || '{{browser_parents}}' || ',', ',' || LOWER(parent_process_name) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || LOWER(device_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Identify ClickFix social engineering where a user pastes a command following a browser prompt.",
        "expected_signal": "A terminal process spawned directly by a web browser. Silence is expected in a healthy environment."
      },
      "parents": [
        {
          "id": "scoping-vulnerable-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Detect terminals launched with browser parents",
        "reads": [
          "device_hostname",
          "process_name",
          "process_cmd_line",
          "parent_process_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, parent_process_name, time FROM hb_process_activity WHERE instr(',' || '{{terminal_processes}}' || ',', ',' || LOWER(process_name) || ',') > 0 AND instr(',' || '{{browser_parents}}' || ',', ',' || LOWER(parent_process_name) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || LOWER(device_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "evidence_of_absence",
        "expected": "A terminal process spawned directly by a web browser. Silence is expected in a healthy environment.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "m365-ai-app-consents",
      "type": "query",
      "label": "Identify new M365 AI application and skill consents",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT actor_user_name, api_operation, resource_name, src_endpoint_ip, time FROM hb_cloud_api_activity WHERE provider = 'm365' AND (api_operation = 'ConsentToApplication' OR api_operation = 'Add app role assignment') AND (LOWER(resource_name) LIKE '%ai%' OR LOWER(resource_name) LIKE '%bot%' OR LOWER(resource_name) LIKE '%copilot%' OR LOWER(resource_name) LIKE '%skill%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "product": "m365",
        "surface": "hb_cloud_api_activity",
        "extension": "m365",
        "description": "Find M365 Unified Audit Log events for application consents that may represent malicious AI skills.",
        "expected_signal": "Users granting permissions to AI-related applications or skills. This can identify the rug pull supply chain compromise."
      },
      "parents": [
        {
          "id": "scoping-vulnerable-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Identify new M365 AI application and skill consents",
        "reads": [
          "actor_user_name",
          "api_operation",
          "resource_name",
          "src_endpoint_ip",
          "time",
          "provider"
        ],
        "source": "hb_cloud_api_activity",
        "target": "endpoint",
        "content": "SELECT actor_user_name, api_operation, resource_name, src_endpoint_ip, time FROM hb_cloud_api_activity WHERE provider = 'm365' AND (api_operation = 'ConsentToApplication' OR api_operation = 'Add app role assignment') AND (LOWER(resource_name) LIKE '%ai%' OR LOWER(resource_name) LIKE '%bot%' OR LOWER(resource_name) LIKE '%copilot%' OR LOWER(resource_name) LIKE '%skill%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Users granting permissions to AI-related applications or skills. This can identify the rug pull supply chain compromise.",
        "verified": "dry-run",
        "verified_at": "2026-09-29",
        "target_extension": "m365"
      }
    },
    {
      "id": "early-stage-read",
      "type": "analytic",
      "label": "Weigh early-stage evidence",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "web"
        ],
        "context": [
          "scoping-vulnerable-hosts",
          "clickfix-terminal-activity",
          "m365-ai-app-consents"
        ],
        "objective": "Determine if the process and cloud activities indicate a credible initial access attempt via social engineering or AI supply chain compromise.",
        "description": "Analyze the scope, process leads, and M365 events to determine if an entry vector is present.",
        "max_iterations": 3,
        "expected_signal": "A summary of suspicious activities per host or user.",
        "success_criteria": "Verdicts (malicious | suspicious | benign) for each host and user identified in the leads."
      },
      "parents": [
        {
          "id": "clickfix-terminal-activity",
          "kind": "merge"
        },
        {
          "id": "m365-ai-app-consents",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "script-execution-content",
      "type": "query",
      "label": "Examine script block content for malicious indicators",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "endpoint",
        "content": "SELECT device_hostname, script_content, script_type, time FROM hb_script_activity WHERE (script_content LIKE '%Get-Clipboard%' OR script_content LIKE '%IEX%' OR script_content LIKE '%Invoke-Expression%' OR script_content LIKE '%curl%' OR script_content LIKE '%wget%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || LOWER(device_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_script_activity",
        "description": "Review the actual commands executed in terminal sessions, looking for ClickFix commands or data retrieval script blocks.",
        "expected_signal": "Scripts that interact with the clipboard or perform remote downloads, typical of ClickFix lures."
      },
      "parents": [
        {
          "id": "early-stage-read"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Examine script block content for malicious indicators",
        "reads": [
          "device_hostname",
          "script_content",
          "script_type",
          "time"
        ],
        "source": "hb_script_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, script_content, script_type, time FROM hb_script_activity WHERE (script_content LIKE '%Get-Clipboard%' OR script_content LIKE '%IEX%' OR script_content LIKE '%Invoke-Expression%' OR script_content LIKE '%curl%' OR script_content LIKE '%wget%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || LOWER(device_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Scripts that interact with the clipboard or perform remote downloads, typical of ClickFix lures.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "outbound-http-prevalence",
      "type": "query",
      "label": "Identify rare outbound HTTP domains",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "web",
        "content": "SELECT url_hostname, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_http_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || LOWER(device_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY url_hostname HAVING host_count <= 2 ORDER BY host_count ASC",
        "surface": "hb_http_activity",
        "description": "Stack-count outbound domain resolutions to find rare C2 domains or squatting domains invented by LLM hallucinations, focusing on suspect hosts.",
        "expected_signal": "Rare domains contacted by a small number of hosts. These often represent attacker-controlled infrastructure."
      },
      "parents": [
        {
          "id": "early-stage-read"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Identify rare outbound HTTP domains",
        "reads": [
          "url_hostname",
          "device_hostname",
          "time"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT url_hostname, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_http_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || LOWER(device_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY url_hostname HAVING host_count <= 2 ORDER BY host_count ASC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Rare domains contacted by a small number of hosts. These often represent attacker-controlled infrastructure.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "url_hostname"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "follow-on-read",
      "type": "analytic",
      "label": "Final compromise assessment",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "web"
        ],
        "context": [
          "early-stage-read",
          "script-execution-content",
          "outbound-http-prevalence"
        ],
        "objective": "Confirm whether the early-stage leads resulted in successful execution or data exfiltration based on the script and HTTP activity.",
        "description": "Correlate the entry vector leads with the follow-on script and network evidence.",
        "max_iterations": 5,
        "expected_signal": "A final determination of whether a host has been successfully compromised.",
        "success_criteria": "A final verdict citing specific script commands and rare domain connections."
      },
      "parents": [
        {
          "id": "script-execution-content",
          "kind": "merge"
        },
        {
          "id": "outbound-http-prevalence",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "compromise-decision",
      "type": "checkpoint",
      "label": "Route on compromise verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "The final compromise assessment indicates a malicious verdict with evidence of terminal execution or data exfiltration.",
        "condition": "The final compromise assessment indicates a malicious verdict with evidence of terminal execution or data exfiltration.",
        "blind_spot": "no-script-logging",
        "confidence": "high",
        "description": "Determine whether to contain the host or review findings based on the agent's verdict.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "follow-on-read"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate compromised host",
      "config": {
        "target": "endpoint",
        "description": "Prevent further lateral movement or exfiltration after confirmed terminal execution.",
        "instructions": "Isolate the host immediately. Revoke any M365 session tokens associated with users identified in the cloud audit logs.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "compromise-decision",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-manual-review",
      "type": "task",
      "label": "Manual Analyst Review",
      "config": {
        "assignee": "analyst",
        "description": "Investigate the specific commands and network activity to understand the scope of the compromise.",
        "instructions": "Examine the script_content from hb_script_activity for the confirmed hosts. Verify the legitimacy of the rare domains identified. Check for signs of lateral movement originating from the beachhead."
      },
      "parents": [
        {
          "id": "compromise-decision",
          "branch": "default"
        },
        {
          "id": "compromise-decision",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out hunt",
      "config": {
        "assignee": "analyst",
        "description": "Finalize the hunt when no evidence of compromise is found.",
        "instructions": "Record the findings. If suspicious ClickFix patterns were found but not confirmed, consider a user awareness training session. Tune detection rules if any benign browser-to-terminal patterns were seen."
      },
      "parents": [
        {
          "id": "compromise-decision",
          "branch": "on_refutes"
        }
      ]
    }
  ]
}