← All hunts medium TLP:CLEAR

AI-Enhanced Collaboration and Browser Attacks

An adversary has bypassed traditional email defenses using AI-enhanced social engineering to trick a user into granting OAuth permissions or installing a malicious browser extension, leading to session hijacking and persistent access.

Based on research by Proofpoint 2026-09-29 12 steps · 5 queries T1176 T1190 T1557 T1566

Brief

Why this hunt

Adversaries now use AI-generated lures to create highly convincing social engineering campaigns that bypass traditional email security filters. The report by Proofpoint, Proofpoint Stops the Attacks Traditional Defenses Miss in the AI Era, highlights how these sophisticated interactions often lead to session hijacking or persistent access via collaboration tools. While a simple alert for every new browser extension is too noisy for most environments, this hunt provides a structured way to find malicious implants by looking for them specifically in the context of suspicious initial access.

How the hunt flows

The first phase scopes the environment. A query against software inventory surfaces every host running common web browsers. This baseline ensures the hunt focuses on endpoints where browser-based persistence is technically possible and narrows the subsequent search for high-risk workstations, such as those in finance or executive leadership.

The second phase searches for initial access evidence across two surfaces. The hunt monitors HTTP activity for connections to known phishing domains or URLs containing keywords like "consent" or "authorize." Simultaneously, it checks cloud API logs for users granting broad application permissions or roles in Microsoft 365. An analyst or automated agent then correlates these events to identify users who likely fell for a lure.

The third phase investigates persistence on the high-risk hosts identified previously. The hunt looks for browser extensions with very low prevalence — those installed on three or fewer devices across the entire fleet. It also checks for successful sign-ins where multi-factor authentication was not recorded, which often indicates that an attacker is reusing a hijacked session token stolen via a malicious extension.

The final phase connects the chain. The analyst verifies if the phishing visit or OAuth grant was followed by a rare extension installation or an anomalous sign-in on the same host. This correlation confirms the full attack path from the initial click to persistent access.

Limitations and Blind Spots

This hunt has three primary blind spots. First, without TLS decryption on a forward proxy, the hunt sees the domains visited but cannot inspect the payloads. We cannot confirm if a user submitted credentials or tokens, only that they interacted with the site. Second, software inventory typically provides the name and vendor of an extension but not its internal permissions. We cannot see if an extension has the right to read page content or intercept form data. Finally, cloud API logs often suffer from ingestion latency, meaning the very latest OAuth grants may not appear in the results for several minutes.

Steps

  1. Identify hosts with active browsers

    Query · scoping

    Identify the workstations that run common browsers where extensions could be installed as a baseline for the hunt.

    reads hb_software_inventorysql
    SELECT device_hostname, package_name, package_version FROM hb_software_inventory WHERE (instr(',' || '{{browser_names}}' || ',', ',' || LOWER(package_name) || ',') > 0 OR LOWER(package_name) LIKE '%chrome%' OR LOWER(package_name) LIKE '%firefox%' OR LOWER(package_name) LIKE '%edge%')

    What a hit looks like. A list of hosts currently running browsers. Zero hosts means no browsers are inventoried, suggesting a collection gap.

  2. Analyze phishing URL interactions

    Query · enrichment

    Find connections to known phishing domains or URLs with suspicious keywords indicating a social engineering lure.

    reads hb_http_activitysql
    SELECT device_hostname, url_full, src_endpoint_ip, user_agent, time FROM hb_http_activity WHERE (instr(',' || '{{phishing_domains}}' || ',', ',' || LOWER(url_hostname) || ',') > 0 OR LOWER(url_full) LIKE '%login%' OR LOWER(url_full) LIKE '%consent%' OR LOWER(url_full) LIKE '%authorize%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Rows indicate a host interacted with a suspicious URL. Silence suggests no observed phishing traffic in the window.

  3. Suspicious cloud OAuth grants

    Query · triage

    Detect when a user grants permissions to an application, which often follows a successful phishing lure.

    reads hb_cloud_api_activitysql
    SELECT actor_user_name, api_operation, resource_name, src_endpoint_ip, time FROM hb_cloud_api_activity WHERE provider = 'm365' AND (LOWER(api_operation) LIKE '%consent%' OR LOWER(api_operation) LIKE '%permission%' OR LOWER(api_operation) LIKE '%app role%') AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Users granting broad permissions to applications. Silence means no such cloud events were recorded.

  4. Triage initial access events

    Agent triage

    Determine if any host or user shows strong evidence of successful initial access.

  5. Rare browser extension persistence

    Query · detection candidate

    Find browser extensions seen on very few hosts, indicating a potential targeted malicious implant.

    reads hb_software_inventorysql
    SELECT package_name, vendor_name, COUNT(DISTINCT device_hostname) AS host_count, MIN(collected_at) AS first_seen FROM hb_software_inventory WHERE package_type = 'extension' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY package_name, vendor_name HAVING host_count <= 3 ORDER BY host_count ASC

    What a hit looks like. Extensions found on only one or two hosts. This is a durable signal of persistence if it follows a phishing interaction.

  6. Anomalous sign-ins without MFA

    Query · baseline

    Identify successful logins where MFA was not recorded, suggesting session hijacking from the browser.

    reads hb_auth_signinsql
    SELECT actor_user_name, device_hostname, src_endpoint_ip, mfa, status, time FROM hb_auth_signin WHERE status_id = 1 AND (mfa = 'false' OR mfa IS NULL) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Successful sign-ins without MFA, especially from IPs that match the phishing workstation.

  7. Correlate attack chain evidence

    Agent triage

    Connect the initial access evidence with the follow-on persistence and anomalous sign-ins.

  8. Route on attack chain verdict

    Decision

    Decide whether to proceed with containment based on the agent's correlation.

  9. Isolate host and revoke sessions

    Response action

    Immediately stop the attacker from using the persistence mechanism or hijacked sessions.

  10. Analyst validation and tuning

    Analyst task

    Verify the connected evidence and document tuning recommendations for automated detection.

  11. Close out hunt

    Analyst task

    Document final findings and visibility gaps discovered during the hunt.

Coverage

Scenario coverage

StageCoveredHow, or why not
Social Engineering via Trusted Relationships
T1566
Yes phishing-clicks
OAuth Phishing and Credential Theft
T1566
Yes oauth-grants
Persistence via Malicious Browser Extensions
T1176
Yes rare-extensions
Session Hijacking and Post-Click Theft
T1557
Yes anomalous-signins

Blind spots

  • Needs TLS decryption on a forward proxy. We can see the domain visited but not whether credentials or tokens were exfiltrated in the request payload. It would answer What content was submitted to the phishing URL after the initial interaction..
  • Needs Browser internal database monitoring. The hunt sees the extension name and vendor but may not see if it has permissions to read page content or intercept form submissions. It would answer The specific internal capabilities or permissions of a loaded browser extension..
  • Needs Unified Audit Log (UAL) near-real-time streaming. There is a known delay in cloud API logging that might prevent identifying a very recent compromise. It would answer Whether an OAuth grant occurred in the last few minutes..

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
browser_nameslist[string]chrome, firefox, msedge, safariCommon browser package names to identify candidate hosts.
lookback_daysnumber14Days of history to examine.
phishing_domainslist[domain]proofpoint.com, secure-login-verify.com, microsoft-consent.netKnown or suspicious domains linked to phishing; includes the article domain as a baseline.
scope_hostslist[host]—Optional list of hosts to narrow the hunt; typically populated from the scoping results.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint
Identity / sign-in telemetryidentityidentity
Web server / proxy logssiemnetwork

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: A simple rule for new browser extensions is too noisy for most fleets. This
  hunt uses a phased sequence to pivot from HTTP traffic and cloud API grants into
  rare software inventory, providing the necessary context to identify a true malicious
  chain.
blind_spots:
- id: no-decryption
  question: What content was submitted to the phishing URL after the initial interaction.
  requires: TLS decryption on a forward proxy
  risk: We can see the domain visited but not whether credentials or tokens were exfiltrated
    in the request payload.
  stage: initial-access-phishing-collaboration
- id: extension-data-gap
  question: The specific internal capabilities or permissions of a loaded browser
    extension.
  requires: Browser internal database monitoring
  risk: The hunt sees the extension name and vendor but may not see if it has permissions
    to read page content or intercept form submissions.
  stage: malicious-browser-extensions
- id: cloud-api-latency
  question: Whether an OAuth grant occurred in the last few minutes.
  requires: Unified Audit Log (UAL) near-real-time streaming
  risk: There is a known delay in cloud API logging that might prevent identifying
    a very recent compromise.
  stage: oauth-phishing-and-consent
coverage:
- stage: initial-access-phishing-collaboration
  status: covered
  steps:
  - phishing-clicks
- stage: oauth-phishing-and-consent
  status: covered
  steps:
  - oauth-grants
- stage: malicious-browser-extensions
  status: covered
  steps:
  - rare-extensions
- stage: session-hijacking-credential-access
  status: covered
  steps:
  - anomalous-signins
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: promote-to-detection
  justification: Modern collaboration attacks use AI to bypass standard email gateways;
    organizations must confirm that post-click persistence mechanisms like malicious
    extensions are not present on critical assets.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An adversary has bypassed traditional email defenses using AI-enhanced
  social engineering to trick a user into granting OAuth permissions or installing
  a malicious browser extension, leading to session hijacking and persistent access.
labels:
- hunt
- attack.t1566
- attack.t1176
- attack.t1190
- attack.t1557
- credential access
- initial access
- persistence
name: AI-Enhanced Collaboration and Browser Attacks
parameters:
  browser_names:
    default:
    - chrome
    - firefox
    - msedge
    - safari
    description: Common browser package names to identify candidate hosts.
    from:
      kind: manual
      observed: '2026-09-22'
      ref: hunt-standard
    type: list[string]
  lookback_days:
    default: '14'
    description: Days of history to examine.
    from:
      kind: manual
      observed: '2026-09-22'
      ref: hunt-standard
    type: number
  phishing_domains:
    default:
    - proofpoint.com
    - secure-login-verify.com
    - microsoft-consent.net
    description: Known or suspicious domains linked to phishing; includes the article
      domain as a baseline.
    from:
      kind: article
      observed: '2026-09-22'
      ref: proofpoint-ai-era-press-release
    type: list[domain]
  scope_hosts:
    default: []
    description: Optional list of hosts to narrow the hunt; typically populated from
      the scoping results.
    from:
      kind: manual
      observed: '2026-09-22'
      ref: hunt-standard
    type: list[host]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.proofpoint.com/us/newsroom/press-releases/proofpoint-stops-attacks-traditional-defenses-miss-ai-era
    gates:
    - dry-run
    - lint
    - critic
    model: hb_google/gemini-3-flash-preview
rationale: Scope the hunt to critical business workstations first, particularly finance
  and executive users, as they are primary targets for AI-enhanced transaction fraud
  and social engineering.
references:
- name: Proofpoint Stops the Attacks Traditional Defenses Miss in the AI Era
  url: https://www.proofpoint.com/us/newsroom/press-releases/proofpoint-stops-attacks-traditional-defenses-miss-ai-era
related:
- hunt: cloud-app-registration-monitoring
  reason: This hunt focuses on browser-borne threats and extensions; a broader cloud-native
    hunt for any application registration is a sibling.
  relation: out-of-scope-alternative
scenario:
  stages:
  - name: Social Engineering via Trusted Relationships
    observables:
    - Compromised supplier email threads
    - Fraudulent payment requests
    - Post-click phishing URLs
    - Phishing attachments
    slug: initial-access-phishing-collaboration
    tactic: initial-access
    techniques:
    - T1566
  - name: OAuth Phishing and Credential Theft
    observables:
    - Malicious OAuth consent requests
    - Credential theft via phishing landing pages
    - Abuse of trusted application permissions
    slug: oauth-phishing-and-consent
    tactic: initial-access
    techniques:
    - T1566
  - name: Persistence via Malicious Browser Extensions
    observables:
    - Installation of unauthorized browser extensions
    - Malicious extension files in user profiles
    - Suspicious extension-originating network traffic
    slug: malicious-browser-extensions
    tactic: persistence
    techniques:
    - T1176
  - name: Session Hijacking and Post-Click Theft
    observables:
    - Session cookie theft
    - Unauthorized session hijacking in the browser
    - Suspicious authentication attempts using stolen sessions
    slug: session-hijacking-credential-access
    tactic: credential-access
    techniques:
    - T1557
  summary: Attackers leverage compromised supplier email threads, fraudulent payment
    requests, and OAuth phishing to bypass traditional defenses. These sophisticated
    campaigns lead to the installation of malicious browser extensions and session
    hijacking to maintain persistent access to corporate collaboration environments.
severity: medium
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  identity:
    category: identity
    name: Identity / sign-in telemetry
    telemetry:
    - identity
  web:
    category: siem
    name: Web server / proxy logs
    telemetry:
    - network
tlp: clear
type: investigation
---


# AI-Enhanced Collaboration and Browser Attacks

This hunt targets sophisticated collaboration attacks that use trusted relationships to move from a phishing click to a persistent browser implant. AI-generated lures often bypass standard signature-based gateways, requiring a search for behavioral anomalies across the entire attack chain. The hunt follows a phased approach: first identifying suspicious initial interactions and cloud permission grants, then searching for follow-on persistence in the form of rare browser extensions and anomalous sign-in patterns. By correlating these stages, the hunt identifies compromised accounts and hosts that traditional per-tool defenses miss.

## scoping-browsers
<!-- Identify hosts with active browsers -->
Identify the workstations that run common browsers where extensions could be installed as a baseline for the hunt.

```sqlite target=endpoint role=scoping params=(browser_names=browser_names)
~~~yaml
expected: A list of hosts currently running browsers. Zero hosts means no browsers
  are inventoried, suggesting a collection gap.
reads:
- device_hostname
- package_name
- package_version
silence: not_evidence_of_absence
source: hb_software_inventory
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, package_name, package_version FROM hb_software_inventory WHERE (instr(',' || '{{browser_names}}' || ',', ',' || LOWER(package_name) || ',') > 0 OR LOWER(package_name) LIKE '%chrome%' OR LOWER(package_name) LIKE '%firefox%' OR LOWER(package_name) LIKE '%edge%')
```

## parallel-initial-access
<!-- Monitor for initial access indicators -->
parallel:
- → phishing-clicks
- → oauth-grants
join: → triage-initial-access

## phishing-clicks
<!-- Analyze phishing URL interactions -->
Find connections to known phishing domains or URLs with suspicious keywords indicating a social engineering lure.

```sqlite target=web role=enrichment params=(phishing_domains=phishing_domains, scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: Rows indicate a host interacted with a suspicious URL. Silence suggests
  no observed phishing traffic in the window.
reads:
- device_hostname
- url_full
- src_endpoint_ip
- user_agent
- time
- url_hostname
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, url_full, src_endpoint_ip, user_agent, time FROM hb_http_activity WHERE (instr(',' || '{{phishing_domains}}' || ',', ',' || LOWER(url_hostname) || ',') > 0 OR LOWER(url_full) LIKE '%login%' OR LOWER(url_full) LIKE '%consent%' OR LOWER(url_full) LIKE '%authorize%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## oauth-grants
<!-- Suspicious cloud OAuth grants -->
Detect when a user grants permissions to an application, which often follows a successful phishing lure.

```sqlite target=endpoint role=triage params=(lookback_days=lookback_days)
~~~yaml
expected: Users granting broad permissions to applications. Silence means no such
  cloud events were recorded.
reads:
- actor_user_name
- api_operation
- resource_name
- src_endpoint_ip
- time
- provider
silence: not_evidence_of_absence
source: hb_cloud_api_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT actor_user_name, api_operation, resource_name, src_endpoint_ip, time FROM hb_cloud_api_activity WHERE provider = 'm365' AND (LOWER(api_operation) LIKE '%consent%' OR LOWER(api_operation) LIKE '%permission%' OR LOWER(api_operation) LIKE '%app role%') AND time >= datetime('now', '-{{lookback_days}} days')
```

## triage-initial-access
<!-- Triage initial access events -->
```agent target=hunter
cite: required
context:
- phishing-clicks
- oauth-grants
max_iterations: 4
objective: Identify users or hosts who visited phishing URLs and subsequently granted
  suspicious OAuth permissions.
success_criteria: A list of high-risk principals and endpoints.
tools:
- endpoint
- identity
- web
```

## parallel-follow-on
<!-- Search for persistence and session hijacking -->
parallel:
- → rare-extensions
- → anomalous-signins
join: → triage-final

## rare-extensions
<!-- Rare browser extension persistence -->
Find browser extensions seen on very few hosts, indicating a potential targeted malicious implant.

```sqlite target=endpoint role=detection-candidate params=(scope_hosts=scope_hosts)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: Extensions found on only one or two hosts. This is a durable signal of persistence
  if it follows a phishing interaction.
prevalence:
  by: device_hostname
  key:
  - package_name
  - vendor_name
  rare_below: 3
reads:
- package_name
- vendor_name
- device_hostname
- collected_at
- package_type
silence: not_evidence_of_absence
source: hb_software_inventory
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT package_name, vendor_name, COUNT(DISTINCT device_hostname) AS host_count, MIN(collected_at) AS first_seen FROM hb_software_inventory WHERE package_type = 'extension' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY package_name, vendor_name HAVING host_count <= 3 ORDER BY host_count ASC
```

## anomalous-signins
<!-- Anomalous sign-ins without MFA -->
Identify successful logins where MFA was not recorded, suggesting session hijacking from the browser.

```sqlite target=identity role=baseline params=(scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: Successful sign-ins without MFA, especially from IPs that match the phishing
  workstation.
reads:
- actor_user_name
- device_hostname
- src_endpoint_ip
- mfa
- status
- time
- status_id
silence: not_evidence_of_absence
source: hb_auth_signin
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT actor_user_name, device_hostname, src_endpoint_ip, mfa, status, time FROM hb_auth_signin WHERE status_id = 1 AND (mfa = 'false' OR mfa IS NULL) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## triage-final
<!-- Correlate attack chain evidence -->
```agent target=hunter
cite: required
context:
- rare-extensions
- anomalous-signins
- triage-initial-access
max_iterations: 6
objective: Determine if a phishing click or OAuth grant was followed by a rare extension
  installation or anomalous session reuse on the same host or user identity.
success_criteria: A per-host verdict of malicious | suspicious | benign, citing the
  connected rows across surfaces.
tools:
- endpoint
- identity
- web
```

## route-remediation
<!-- Route on attack chain verdict -->
if~: "the triage verdict is malicious for at least one user or host" (confidence: high, judge=hunter)
then: → isolate-host
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: cloud-api-latency)
else: → close-out

## isolate-host
<!-- Isolate host and revoke sessions -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the identified endpoints, revoke the malicious OAuth grants in the Microsoft 365 portal, and terminate all active sessions for the affected users.
```
→ analyst-review

## analyst-review
<!-- Analyst validation and tuning -->
```manual target=analyst
Review the cited rows for the phishing interaction, the OAuth grant, and the rare extension. Confirm if the extension behavior is truly malicious and if the sign-in without MFA represents a hijacked session.
```
→ close-out

## close-out
<!-- Close out hunt -->
```manual target=analyst
Record the total number of hosts and users examined. Note any visibility gaps, such as hosts missing browser extension inventory or cloud API logs that were missing critical user agent details.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, critic, then reviewed by a person.