{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Modern collaboration attacks use AI to bypass standard email gateways; organizations must confirm that post-click persistence mechanisms like malicious extensions are not present on critical assets."
      },
      "name": "AI-Enhanced Collaboration and Browser Attacks",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1566",
        "attack.t1176",
        "attack.t1190",
        "attack.t1557",
        "credential access",
        "initial access",
        "persistence"
      ],
      "related": [
        {
          "hunt": "cloud-app-registration-monitoring",
          "reason": "This hunt focuses on browser-borne threats and extensions; a broader cloud-native hunt for any application registration is a sibling.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        },
        "identity": {
          "name": "Identity / sign-in telemetry",
          "category": "identity",
          "telemetry": [
            "identity"
          ]
        }
      },
      "analysis": "A simple rule for new browser extensions is too noisy for most fleets. This hunt uses a phased sequence to pivot from HTTP traffic and cloud API grants into rare software inventory, providing the necessary context to identify a true malicious chain.",
      "coverage": [
        {
          "stage": "initial-access-phishing-collaboration",
          "steps": [
            "phishing-clicks"
          ],
          "status": "covered"
        },
        {
          "stage": "oauth-phishing-and-consent",
          "steps": [
            "oauth-grants"
          ],
          "status": "covered"
        },
        {
          "stage": "malicious-browser-extensions",
          "steps": [
            "rare-extensions"
          ],
          "status": "covered"
        },
        {
          "stage": "session-hijacking-credential-access",
          "steps": [
            "anomalous-signins"
          ],
          "status": "covered"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Social Engineering via Trusted Relationships",
            "slug": "initial-access-phishing-collaboration",
            "tactic": "initial-access",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "Compromised supplier email threads",
              "Fraudulent payment requests",
              "Post-click phishing URLs",
              "Phishing attachments"
            ]
          },
          {
            "name": "OAuth Phishing and Credential Theft",
            "slug": "oauth-phishing-and-consent",
            "tactic": "initial-access",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "Malicious OAuth consent requests",
              "Credential theft via phishing landing pages",
              "Abuse of trusted application permissions"
            ]
          },
          {
            "name": "Persistence via Malicious Browser Extensions",
            "slug": "malicious-browser-extensions",
            "tactic": "persistence",
            "techniques": [
              "T1176"
            ],
            "observables": [
              "Installation of unauthorized browser extensions",
              "Malicious extension files in user profiles",
              "Suspicious extension-originating network traffic"
            ]
          },
          {
            "name": "Session Hijacking and Post-Click Theft",
            "slug": "session-hijacking-credential-access",
            "tactic": "credential-access",
            "techniques": [
              "T1557"
            ],
            "observables": [
              "Session cookie theft",
              "Unauthorized session hijacking in the browser",
              "Suspicious authentication attempts using stolen sessions"
            ]
          }
        ],
        "summary": "Attackers leverage compromised supplier email threads, fraudulent payment requests, and OAuth phishing to bypass traditional defenses. These sophisticated campaigns lead to the installation of malicious browser extensions and session hijacking to maintain persistent access to corporate collaboration environments."
      },
      "severity": "medium",
      "rationale": "Scope the hunt to critical business workstations first, particularly finance and executive users, as they are primary targets for AI-enhanced transaction fraud and social engineering.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary has bypassed traditional email defenses using AI-enhanced social engineering to trick a user into granting OAuth permissions or installing a malicious browser extension, leading to session hijacking and persistent access.",
      "parameters": {
        "scope_hosts": {
          "from": {
            "ref": "hunt-standard",
            "kind": "manual",
            "observed": "2026-09-22"
          },
          "type": "list[host]",
          "default": [],
          "description": "Optional list of hosts to narrow the hunt; typically populated from the scoping results."
        },
        "browser_names": {
          "from": {
            "ref": "hunt-standard",
            "kind": "manual",
            "observed": "2026-09-22"
          },
          "type": "list[string]",
          "default": [
            "chrome",
            "firefox",
            "msedge",
            "safari"
          ],
          "description": "Common browser package names to identify candidate hosts."
        },
        "lookback_days": {
          "from": {
            "ref": "hunt-standard",
            "kind": "manual",
            "observed": "2026-09-22"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "phishing_domains": {
          "from": {
            "ref": "proofpoint-ai-era-press-release",
            "kind": "article",
            "observed": "2026-09-22"
          },
          "type": "list[domain]",
          "default": [
            "proofpoint.com",
            "secure-login-verify.com",
            "microsoft-consent.net"
          ],
          "description": "Known or suspicious domains linked to phishing; includes the article domain as a baseline."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.proofpoint.com/us/newsroom/press-releases/proofpoint-stops-attacks-traditional-defenses-miss-ai-era",
          "gates": [
            "dry-run",
            "lint",
            "critic"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.proofpoint.com/us/newsroom/press-releases/proofpoint-stops-attacks-traditional-defenses-miss-ai-era",
          "name": "Proofpoint Stops the Attacks Traditional Defenses Miss in the AI Era"
        }
      ],
      "blind_spots": [
        {
          "id": "no-decryption",
          "risk": "We can see the domain visited but not whether credentials or tokens were exfiltrated in the request payload.",
          "stage": "initial-access-phishing-collaboration",
          "question": "What content was submitted to the phishing URL after the initial interaction.",
          "requires": "TLS decryption on a forward proxy"
        },
        {
          "id": "extension-data-gap",
          "risk": "The hunt sees the extension name and vendor but may not see if it has permissions to read page content or intercept form submissions.",
          "stage": "malicious-browser-extensions",
          "question": "The specific internal capabilities or permissions of a loaded browser extension.",
          "requires": "Browser internal database monitoring"
        },
        {
          "id": "cloud-api-latency",
          "risk": "There is a known delay in cloud API logging that might prevent identifying a very recent compromise.",
          "stage": "oauth-phishing-and-consent",
          "question": "Whether an OAuth grant occurred in the last few minutes.",
          "requires": "Unified Audit Log (UAL) near-real-time streaming"
        }
      ]
    },
    "name": "AI-Enhanced Collaboration and Browser Attacks",
    "description": "This hunt targets sophisticated collaboration attacks that use trusted relationships to move from a phishing click to a persistent browser implant. AI-generated lures often bypass standard signature-based gateways, requiring a search for behavioral anomalies across the entire attack chain. The hunt follows a phased approach: first identifying suspicious initial interactions and cloud permission grants, then searching for follow-on persistence in the form of rare browser extensions and anomalous sign-in patterns. By correlating these stages, the hunt identifies compromised accounts and hosts that traditional per-tool defenses miss."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "coverage": [
          {
            "stage": "initial-access-phishing-collaboration",
            "steps": [
              "phishing-clicks"
            ],
            "status": "covered"
          },
          {
            "stage": "oauth-phishing-and-consent",
            "steps": [
              "oauth-grants"
            ],
            "status": "covered"
          },
          {
            "stage": "malicious-browser-extensions",
            "steps": [
              "rare-extensions"
            ],
            "status": "covered"
          },
          {
            "stage": "session-hijacking-credential-access",
            "steps": [
              "anomalous-signins"
            ],
            "status": "covered"
          }
        ],
        "rationale": "An adversary has bypassed traditional email defenses using AI-enhanced social engineering to trick a user into granting OAuth permissions or installing a malicious browser extension, leading to session hijacking and persistent access.",
        "blind_spots": [
          {
            "id": "no-decryption",
            "risk": "We can see the domain visited but not whether credentials or tokens were exfiltrated in the request payload.",
            "stage": "initial-access-phishing-collaboration",
            "question": "What content was submitted to the phishing URL after the initial interaction.",
            "requires": "TLS decryption on a forward proxy"
          },
          {
            "id": "extension-data-gap",
            "risk": "The hunt sees the extension name and vendor but may not see if it has permissions to read page content or intercept form submissions.",
            "stage": "malicious-browser-extensions",
            "question": "The specific internal capabilities or permissions of a loaded browser extension.",
            "requires": "Browser internal database monitoring"
          },
          {
            "id": "cloud-api-latency",
            "risk": "There is a known delay in cloud API logging that might prevent identifying a very recent compromise.",
            "stage": "oauth-phishing-and-consent",
            "question": "Whether an OAuth grant occurred in the last few minutes.",
            "requires": "Unified Audit Log (UAL) near-real-time streaming"
          }
        ],
        "scoping_notes": "Scope the hunt to critical business workstations first, particularly finance and executive users, as they are primary targets for AI-enhanced transaction fraud and social engineering.",
        "beyond_detection": "A simple rule for new browser extensions is too noisy for most fleets. This hunt uses a phased sequence to pivot from HTTP traffic and cloud API grants into rare software inventory, providing the necessary context to identify a true malicious chain."
      }
    },
    {
      "id": "scoping-browsers",
      "type": "query",
      "label": "Identify hosts with active browsers",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_hostname, package_name, package_version FROM hb_software_inventory WHERE (instr(',' || '{{browser_names}}' || ',', ',' || LOWER(package_name) || ',') > 0 OR LOWER(package_name) LIKE '%chrome%' OR LOWER(package_name) LIKE '%firefox%' OR LOWER(package_name) LIKE '%edge%')",
        "surface": "hb_software_inventory",
        "description": "Identify the workstations that run common browsers where extensions could be installed as a baseline for the hunt.",
        "expected_signal": "A list of hosts currently running browsers. Zero hosts means no browsers are inventoried, suggesting a collection gap."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify hosts with active browsers",
        "reads": [
          "device_hostname",
          "package_name",
          "package_version"
        ],
        "source": "hb_software_inventory",
        "target": "endpoint",
        "content": "SELECT device_hostname, package_name, package_version FROM hb_software_inventory WHERE (instr(',' || '{{browser_names}}' || ',', ',' || LOWER(package_name) || ',') > 0 OR LOWER(package_name) LIKE '%chrome%' OR LOWER(package_name) LIKE '%firefox%' OR LOWER(package_name) LIKE '%edge%')",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hosts currently running browsers. Zero hosts means no browsers are inventoried, suggesting a collection gap.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "phishing-clicks",
      "type": "query",
      "label": "Analyze phishing URL interactions",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "web",
        "content": "SELECT device_hostname, url_full, src_endpoint_ip, user_agent, time FROM hb_http_activity WHERE (instr(',' || '{{phishing_domains}}' || ',', ',' || LOWER(url_hostname) || ',') > 0 OR LOWER(url_full) LIKE '%login%' OR LOWER(url_full) LIKE '%consent%' OR LOWER(url_full) LIKE '%authorize%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_http_activity",
        "description": "Find connections to known phishing domains or URLs with suspicious keywords indicating a social engineering lure.",
        "expected_signal": "Rows indicate a host interacted with a suspicious URL. Silence suggests no observed phishing traffic in the window."
      },
      "parents": [
        {
          "id": "scoping-browsers"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Analyze phishing URL interactions",
        "reads": [
          "device_hostname",
          "url_full",
          "src_endpoint_ip",
          "user_agent",
          "time",
          "url_hostname"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT device_hostname, url_full, src_endpoint_ip, user_agent, time FROM hb_http_activity WHERE (instr(',' || '{{phishing_domains}}' || ',', ',' || LOWER(url_hostname) || ',') > 0 OR LOWER(url_full) LIKE '%login%' OR LOWER(url_full) LIKE '%consent%' OR LOWER(url_full) LIKE '%authorize%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Rows indicate a host interacted with a suspicious URL. Silence suggests no observed phishing traffic in the window.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "oauth-grants",
      "type": "query",
      "label": "Suspicious cloud OAuth grants",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "endpoint",
        "content": "SELECT actor_user_name, api_operation, resource_name, src_endpoint_ip, time FROM hb_cloud_api_activity WHERE provider = 'm365' AND (LOWER(api_operation) LIKE '%consent%' OR LOWER(api_operation) LIKE '%permission%' OR LOWER(api_operation) LIKE '%app role%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_cloud_api_activity",
        "description": "Detect when a user grants permissions to an application, which often follows a successful phishing lure.",
        "expected_signal": "Users granting broad permissions to applications. Silence means no such cloud events were recorded."
      },
      "parents": [
        {
          "id": "scoping-browsers"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Suspicious cloud OAuth grants",
        "reads": [
          "actor_user_name",
          "api_operation",
          "resource_name",
          "src_endpoint_ip",
          "time",
          "provider"
        ],
        "source": "hb_cloud_api_activity",
        "target": "endpoint",
        "content": "SELECT actor_user_name, api_operation, resource_name, src_endpoint_ip, time FROM hb_cloud_api_activity WHERE provider = 'm365' AND (LOWER(api_operation) LIKE '%consent%' OR LOWER(api_operation) LIKE '%permission%' OR LOWER(api_operation) LIKE '%app role%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Users granting broad permissions to applications. Silence means no such cloud events were recorded.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "triage-initial-access",
      "type": "analytic",
      "label": "Triage initial access events",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity",
          "web"
        ],
        "context": [
          "phishing-clicks",
          "oauth-grants"
        ],
        "objective": "Identify users or hosts who visited phishing URLs and subsequently granted suspicious OAuth permissions.",
        "description": "Determine if any host or user shows strong evidence of successful initial access.",
        "max_iterations": 4,
        "expected_signal": "A summary of high-risk hosts and users to focus the follow-on queries.",
        "success_criteria": "A list of high-risk principals and endpoints."
      },
      "parents": [
        {
          "id": "phishing-clicks",
          "kind": "merge"
        },
        {
          "id": "oauth-grants",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "rare-extensions",
      "type": "query",
      "label": "Rare browser extension persistence",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT package_name, vendor_name, COUNT(DISTINCT device_hostname) AS host_count, MIN(collected_at) AS first_seen FROM hb_software_inventory WHERE package_type = 'extension' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY package_name, vendor_name HAVING host_count <= 3 ORDER BY host_count ASC",
        "surface": "hb_software_inventory",
        "description": "Find browser extensions seen on very few hosts, indicating a potential targeted malicious implant.",
        "expected_signal": "Extensions found on only one or two hosts. This is a durable signal of persistence if it follows a phishing interaction."
      },
      "parents": [
        {
          "id": "triage-initial-access"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Rare browser extension persistence",
        "reads": [
          "package_name",
          "vendor_name",
          "device_hostname",
          "collected_at",
          "package_type"
        ],
        "source": "hb_software_inventory",
        "target": "endpoint",
        "content": "SELECT package_name, vendor_name, COUNT(DISTINCT device_hostname) AS host_count, MIN(collected_at) AS first_seen FROM hb_software_inventory WHERE package_type = 'extension' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY package_name, vendor_name HAVING host_count <= 3 ORDER BY host_count ASC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Extensions found on only one or two hosts. This is a durable signal of persistence if it follows a phishing interaction.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "package_name",
            "vendor_name"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "anomalous-signins",
      "type": "query",
      "label": "Anomalous sign-ins without MFA",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "identity",
        "content": "SELECT actor_user_name, device_hostname, src_endpoint_ip, mfa, status, time FROM hb_auth_signin WHERE status_id = 1 AND (mfa = 'false' OR mfa IS NULL) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_auth_signin",
        "description": "Identify successful logins where MFA was not recorded, suggesting session hijacking from the browser.",
        "expected_signal": "Successful sign-ins without MFA, especially from IPs that match the phishing workstation."
      },
      "parents": [
        {
          "id": "triage-initial-access"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Anomalous sign-ins without MFA",
        "reads": [
          "actor_user_name",
          "device_hostname",
          "src_endpoint_ip",
          "mfa",
          "status",
          "time",
          "status_id"
        ],
        "source": "hb_auth_signin",
        "target": "identity",
        "content": "SELECT actor_user_name, device_hostname, src_endpoint_ip, mfa, status, time FROM hb_auth_signin WHERE status_id = 1 AND (mfa = 'false' OR mfa IS NULL) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Successful sign-ins without MFA, especially from IPs that match the phishing workstation.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "triage-final",
      "type": "analytic",
      "label": "Correlate attack chain evidence",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity",
          "web"
        ],
        "context": [
          "rare-extensions",
          "anomalous-signins",
          "triage-initial-access"
        ],
        "objective": "Determine if a phishing click or OAuth grant was followed by a rare extension installation or anomalous session reuse on the same host or user identity.",
        "description": "Connect the initial access evidence with the follow-on persistence and anomalous sign-ins.",
        "max_iterations": 6,
        "expected_signal": "A final verdict on the attack chain per host and user.",
        "success_criteria": "A per-host verdict of malicious | suspicious | benign, citing the connected rows across surfaces."
      },
      "parents": [
        {
          "id": "rare-extensions",
          "kind": "merge"
        },
        {
          "id": "anomalous-signins",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-remediation",
      "type": "checkpoint",
      "label": "Route on attack chain verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage verdict is malicious for at least one user or host",
        "condition": "the triage verdict is malicious for at least one user or host",
        "blind_spot": "cloud-api-latency",
        "confidence": "high",
        "description": "Decide whether to proceed with containment based on the agent's correlation.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-final"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate host and revoke sessions",
      "config": {
        "target": "endpoint",
        "description": "Immediately stop the attacker from using the persistence mechanism or hijacked sessions.",
        "instructions": "Isolate the identified endpoints, revoke the malicious OAuth grants in the Microsoft 365 portal, and terminate all active sessions for the affected users.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-remediation",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Analyst validation and tuning",
      "config": {
        "assignee": "analyst",
        "description": "Verify the connected evidence and document tuning recommendations for automated detection.",
        "instructions": "Review the cited rows for the phishing interaction, the OAuth grant, and the rare extension. Confirm if the extension behavior is truly malicious and if the sign-in without MFA represents a hijacked session."
      },
      "parents": [
        {
          "id": "route-remediation",
          "branch": "default"
        },
        {
          "id": "route-remediation",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out hunt",
      "config": {
        "assignee": "analyst",
        "description": "Document final findings and visibility gaps discovered during the hunt.",
        "instructions": "Record the total number of hosts and users examined. Note any visibility gaps, such as hosts missing browser extension inventory or cloud API logs that were missing critical user agent details."
      },
      "parents": [
        {
          "id": "route-remediation",
          "branch": "on_refutes"
        },
        {
          "id": "analyst-review"
        }
      ]
    }
  ]
}