← All hunts medium TLP:CLEAR

AI-Enhanced OSINT and Identity Abuse

An adversary is using AI-automated OSINT to identify vulnerable web applications and craft high-fidelity phishing lures, leading to server exploitation and account takeover for fraud.

Based on research by ESET Research 2026-09-29 13 steps · 5 queries T1190 T1566

Brief

The Shift in Targeted Fraud

Adversaries are no longer limited by the manual effort required to research targets. ESET Research describes how AI-driven tools now scrape social data and scan for infrastructure vulnerabilities at scale in their article, AI-driven OSINT in the wrong hands. This automation allows even low-skill actors to execute high-fidelity phishing and exploitation campaigns against a broad range of targets.

How the Hunt Flows

The first phase scopes the environment using vulnerability findings. The query identifies hosts with critical CVEs that AI-assisted reconnaissance prioritizes. By filtering for high-severity issues and known exploited vulnerabilities, we isolate the systems most likely to be targeted by automated scanners.

Simultaneously, the hunt scans for inbound probing and exposed management ports. It looks for high volumes of successful POST requests to web applications and open administrative services like RDP, SSH, or SMB. This step identifies where automated tools have already found a path into the network.

A triage agent determines which hosts face active targeting based on this exposure. This bridges the gap between passive vulnerability data and active scanning evidence, creating a high-confidence list of targets for follow-on investigation.

The next phase hunts for the technical outcomes of a successful breach. One check monitors for web servers spawning shell processes like bash or cmd.exe. This indicates successful exploitation of the vulnerabilities identified earlier, where the attacker has gained command execution on a web-facing host.

Another check identifies anomalous user sign-ins. It flags logins from rare geographic locations or IPs for specific accounts. This suggests successful credential harvesting through personalized phishing, even if no direct malware was involved.

A final assessment agent correlates these signals to confirm a breach. It reconciles host identities and user accounts to map the campaign's full lifecycle from discovery to impact.

Blind Spots

This hunt relies on EDR and identity telemetry. It cannot see exploitation on shadow-IT or unmanaged servers where the agent is absent. It also lacks visibility into deepfake audio or video used in social engineering, as those interactions occur outside the scope of endpoint logs.

Running the Hunt

This hunt is provided as an open hunt.md playbook. It imports directly into Huntbase or any hunt.md-aware runtime. Because it correlates vulnerability inventory with active process and identity signals, it provides better context than a single detection rule. Run this to confirm if targeted reconnaissance against your environment has transitioned into a successful compromise.

Source: ESET Research — AI-driven OSINT in the wrong hands

Steps

  1. Scope vulnerable internet-facing assets

    Query · scoping

    Identify hosts with critical vulnerabilities that AI-assisted reconnaissance would likely discover and exploit.

    reads hb_vulnerability_findingsql
    SELECT device_uid, cve_uid, affected_package_name, severity, last_seen FROM hb_vulnerability_finding WHERE severity_id >= 4 AND (instr(',' || '{{target_cves}}' || ',', ',' || cve_uid || ',') > 0 OR is_kev = 'true')

    What a hit looks like. A list of vulnerable hosts. Silence indicates no known critical vulnerabilities are currently reported.

  2. Suspicious HTTP exploitation probing

    Query · enrichment

    Detect automated POST requests to web applications that suggest vulnerability exploitation attempts.

    reads hb_http_activitysql
    SELECT device_hostname, src_endpoint_ip, LOWER(url_path) AS path, status_code, COUNT(*) AS req_count FROM hb_http_activity WHERE http_method = 'POST' AND status_code = 200 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, src_endpoint_ip, LOWER(url_path) HAVING req_count > 50

    What a hit looks like. A high volume of successful POSTs from a single IP to a specific path, suggesting automated exploitation.

  3. Exposed administrative services

    Query · baseline

    Identify internet-exposed RDP, SSH, or SMB ports which AI-driven scanners prioritize for breach attempts.

    reads hb_exposed_assetssql
    SELECT domain_or_ip, port, product, discovered_at FROM hb_exposed_assets WHERE port IN (22, 445, 3389) AND discovered_at >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Company IP addresses exposing administrative ports. Rare ports indicate potential misconfigurations.

  4. Triage early-stage access signals

    Agent triage

    Identify hosts that are the likely targets of AI-automated reconnaissance.

  5. Web servers spawning shell processes

    Query · detection candidate

    Detect T1190 follow-on activity where an exploited web application executes a shell. The query handles full paths by matching the shell basename.

    reads hb_process_activitysql
    SELECT device_hostname, parent_process_name, process_name, process_cmd_line, time FROM hb_process_activity WHERE (LOWER(parent_process_name) LIKE '%httpd%' OR LOWER(parent_process_name) LIKE '%nginx%' OR LOWER(parent_process_name) LIKE '%w3wp.exe%') AND (instr(',' || '{{shell_paths}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR LOWER(process_name) LIKE '%/sh' OR LOWER(process_name) LIKE '%/bash' OR LOWER(process_name) LIKE '%\cmd.exe' OR LOWER(process_name) LIKE '%\powershell.exe') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Rows showing a web server process as the parent of a shell like cmd.exe or bash.

  6. Anomalous user sign-ins with geographic context

    Query · baseline

    Find users signing in from IPs that are rare for their account, including country data for immediate triage.

    reads hb_auth_signinsql
    SELECT actor_user_name, src_endpoint_ip, src_location_country, MIN(time) AS first_seen, COUNT(*) AS login_count FROM hb_auth_signin WHERE status_id = 1 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, src_endpoint_ip, src_location_country HAVING login_count < 5

    What a hit looks like. Sign-in events from IPs only seen once or twice for a given user, potentially in unexpected countries.

  7. Final assessment of campaign impact

    Agent triage

    Correlate early triage with follow-on execution and sign-in patterns to confirm a successful campaign.

  8. Route on verdict

    Decision

    Direct the hunt to containment if a breach is confirmed.

  9. Isolate host and revoke sessions

    Response action

    Halt active attacker movement on identified assets.

  10. Review triage and confirm breach

    Analyst task

    Manually verify the findings cited by the agent before closing the incident.

  11. Close-out benign findings

    Analyst task

    Document the hunt outcome when no malicious activity was found.

  12. Final documentation

    Analyst task

    Document the incident scope and trigger remediation workflows.

Coverage

Scenario coverage

StageCoveredHow, or why not
AI-Aided Vulnerability Exploitation
T1190
Yes scoping-vulnerable-assets, probing-activity, exposed-services
AI-Driven Personalized Phishing
T1566
Yes anomalous-signins
Credential Harvesting and Malware Execution
T1566
Yes shell-execution, anomalous-signins
Business Email Compromise and Fraud
T1566
Yes anomalous-signins

Blind spots

  • Needs VoIP or voice log analysis. Social engineering conducted over voice or video cannot be detected via current endpoint or cloud telemetry. It would answer whether the phishing attempt used AI-generated deepfake audio calls.
  • Needs Complete EDR coverage on all web servers. Exploitation of servers missing an agent will show up in HTTP logs but will not show follow-on process activity. It would answer whether exploitation occurred on shadow-IT or unmanaged servers.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
lookback_daysnumber14Days of history to examine.
scope_hostslist[host]—Specific hostnames to focus the hunt; leave empty for all hosts.
shell_pathslist[path]cmd.exe, powershell.exe, sh, bashShell processes to monitor for spawns from web servers.
target_cveslist[string]CVE-2024-21887, CVE-2023-46604, CVE-2023-22515Critical CVEs prioritized by automated scanners.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint
Identity / sign-in telemetryidentityidentity
Web server / proxy logssiemnetwork

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: A single rule might catch a web shell, but this hunt correlates vulnerability
  inventory, external exposure, and anomalous sign-in patterns to identify the full
  lifecycle of an AI-enhanced campaign.
blind_spots:
- id: deepfake-telemetry-gap
  question: whether the phishing attempt used AI-generated deepfake audio calls
  requires: VoIP or voice log analysis
  risk: Social engineering conducted over voice or video cannot be detected via current
    endpoint or cloud telemetry.
  stage: personalized-phishing-and-social-engineering
- id: unmanaged-infra-gap
  question: whether exploitation occurred on shadow-IT or unmanaged servers
  requires: Complete EDR coverage on all web servers
  risk: Exploitation of servers missing an agent will show up in HTTP logs but will
    not show follow-on process activity.
  stage: vulnerability-discovery-and-exploitation
coverage:
- stage: vulnerability-discovery-and-exploitation
  status: covered
  steps:
  - scoping-vulnerable-assets
  - probing-activity
  - exposed-services
- reason: Covered via the outcome of successful phishing (account takeover).
  stage: personalized-phishing-and-social-engineering
  status: covered
  steps:
  - anomalous-signins
- stage: credential-harvesting-and-malware-execution
  status: covered
  steps:
  - shell-execution
  - anomalous-signins
- stage: bec-and-fraudulent-impact
  status: covered
  steps:
  - anomalous-signins
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: promote-to-detection
  justification: AI allows adversaries to scale personalized fraud and vulnerability
    research; confirming these targeted efforts have not transitioned into active
    breaches is a critical hygiene task.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An adversary is using AI-automated OSINT to identify vulnerable web applications
  and craft high-fidelity phishing lures, leading to server exploitation and account
  takeover for fraud.
labels:
- hunt
- attack.t1190
- attack.t1566
- credential access
- impact
- initial access
name: AI-Enhanced OSINT and Identity Abuse
parameters:
  lookback_days:
    default: '14'
    description: Days of history to examine.
    type: number
  scope_hosts:
    default: []
    description: Specific hostnames to focus the hunt; leave empty for all hosts.
    type: list[host]
  shell_paths:
    default:
    - cmd.exe
    - powershell.exe
    - sh
    - bash
    description: Shell processes to monitor for spawns from web servers.
    type: list[path]
  target_cves:
    default:
    - CVE-2024-21887
    - CVE-2023-46604
    - CVE-2023-22515
    description: Critical CVEs prioritized by automated scanners.
    type: list[string]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.welivesecurity.com/en/privacy/ai-powered-osint-why-everyone-viable-target-fraud/
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Focus on internet-facing web servers and employees in high-value roles
  (Finance, HR, C-suite) who are the primary targets of AI-automated OSINT.
references:
- name: "ESET Research \u2014 AI-driven OSINT in the wrong hands"
  url: https://www.welivesecurity.com/en/privacy/ai-powered-osint-why-everyone-viable-target-fraud/
related:
- hunt: social-media-privacy-audit
  reason: This hunt focuses on technical compromise, not the proactive auditing of
    employee social media privacy.
  relation: out-of-scope-alternative
scenario:
  stages:
  - name: AI-Aided Vulnerability Exploitation
    observables:
    - Automated identification of internet-facing vulnerabilities
    - Exploitation of public-facing software bugs or misconfigurations
    slug: vulnerability-discovery-and-exploitation
    tactic: initial-access
    techniques:
    - T1190
  - name: AI-Driven Personalized Phishing
    observables:
    - Phishing emails containing personal details (workplace, schools, birthdays,
      recent travel)
    - Malicious links in emails or social media
    - Deepfake video or voice calls impersonating victims
    - Social engineering scripts designed by LLMs
    slug: personalized-phishing-and-social-engineering
    tactic: initial-access
    techniques:
    - T1566
  - name: Credential Harvesting and Malware Execution
    observables:
    - Logins to fraudulent credential harvesting pages
    - Installation of malware via malicious email attachments or links
    - Execution of suspicious binary or script payloads
    slug: credential-harvesting-and-malware-execution
    tactic: credential-access
    techniques:
    - T1566
  - name: Business Email Compromise and Fraud
    observables:
    - Anomalous sign-ins using harvested work credentials
    - Business Email Compromise (BEC) targeting colleagues
    - Fraudulent financial requests or sextortion threats
    slug: bec-and-fraudulent-impact
    tactic: impact
    techniques:
    - T1566
  summary: Threat actors are leveraging AI to automate OSINT at scale, creating highly
    personalized phishing and social engineering campaigns by profiling victims' personal
    and professional lives. This AI-driven pipeline facilitates more convincing deepfakes,
    credential harvesting, and Business Email Compromise (BEC) attacks by lowering
    the technical barrier for fraudsters.
severity: medium
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  identity:
    category: identity
    name: Identity / sign-in telemetry
    telemetry:
    - identity
  web:
    category: siem
    name: Web server / proxy logs
    telemetry:
    - network
tlp: clear
type: investigation
---


# AI-Enhanced OSINT and Identity Abuse

This hunt identifies the transition from automated external reconnaissance to active internal breach. It first scopes vulnerable and exposed assets that AI scanners prioritize, then evaluates suspicious HTTP activity. A second phase hunts for the outcome: web shells spawned from server processes and anomalous user sign-ins from rare locations indicating credential theft. An agent correlates these phases to identify successful AI-enhanced social engineering campaigns.

## scoping-vulnerable-assets
<!-- Scope vulnerable internet-facing assets -->
Identify hosts with critical vulnerabilities that AI-assisted reconnaissance would likely discover and exploit.

```sqlite target=endpoint role=scoping params=(target_cves=target_cves)
~~~yaml
expected: A list of vulnerable hosts. Silence indicates no known critical vulnerabilities
  are currently reported.
reads:
- device_uid
- cve_uid
- affected_package_name
- severity
- last_seen
silence: not_evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_uid, cve_uid, affected_package_name, severity, last_seen FROM hb_vulnerability_finding WHERE severity_id >= 4 AND (instr(',' || '{{target_cves}}' || ',', ',' || cve_uid || ',') > 0 OR is_kev = 'true')
```

## early-access-parallel
<!-- Parallel scan for initial access signals -->
parallel:
- → probing-activity
- → exposed-services
join: → early-stage-triage

## probing-activity
<!-- Suspicious HTTP exploitation probing -->
Detect automated POST requests to web applications that suggest vulnerability exploitation attempts.

```sqlite target=web role=enrichment params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: A high volume of successful POSTs from a single IP to a specific path, suggesting
  automated exploitation.
reads:
- device_hostname
- src_endpoint_ip
- url_path
- status_code
- time
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, src_endpoint_ip, LOWER(url_path) AS path, status_code, COUNT(*) AS req_count FROM hb_http_activity WHERE http_method = 'POST' AND status_code = 200 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, src_endpoint_ip, LOWER(url_path) HAVING req_count > 50
```

## exposed-services
<!-- Exposed administrative services -->
Identify internet-exposed RDP, SSH, or SMB ports which AI-driven scanners prioritize for breach attempts.

```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days)
~~~yaml
baseline:
  compare: new_this_window
  window: '{{lookback_days}}d'
expected: Company IP addresses exposing administrative ports. Rare ports indicate
  potential misconfigurations.
prevalence:
  by: domain_or_ip
  key:
  - port
  rare_below: 2
reads:
- domain_or_ip
- port
- product
- discovered_at
silence: not_evidence_of_absence
source: hb_exposed_assets
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT domain_or_ip, port, product, discovered_at FROM hb_exposed_assets WHERE port IN (22, 445, 3389) AND discovered_at >= datetime('now', '-{{lookback_days}} days')
```

## early-stage-triage
<!-- Triage early-stage access signals -->
```agent target=hunter
cite: required
context:
- scoping-vulnerable-assets
- probing-activity
- exposed-services
max_iterations: 3
objective: Determine which hosts are actively being probed or targeted based on vulnerability
  and exposure data.
success_criteria: A statement identifying specific hosts at risk of initial access.
tools:
- endpoint
- identity
- web
```

## follow-on-parallel
<!-- Hunt for execution and credential abuse -->
parallel:
- → shell-execution
- → anomalous-signins
join: → impact-assessment

## shell-execution
<!-- Web servers spawning shell processes -->
Detect T1190 follow-on activity where an exploited web application executes a shell. The query handles full paths by matching the shell basename.

```sqlite target=endpoint role=detection-candidate params=(shell_paths=shell_paths, lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: Rows showing a web server process as the parent of a shell like cmd.exe
  or bash.
reads:
- device_hostname
- parent_process_name
- process_name
- process_cmd_line
- time
silence: evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, parent_process_name, process_name, process_cmd_line, time FROM hb_process_activity WHERE (LOWER(parent_process_name) LIKE '%httpd%' OR LOWER(parent_process_name) LIKE '%nginx%' OR LOWER(parent_process_name) LIKE '%w3wp.exe%') AND (instr(',' || '{{shell_paths}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR LOWER(process_name) LIKE '%/sh' OR LOWER(process_name) LIKE '%/bash' OR LOWER(process_name) LIKE '%\cmd.exe' OR LOWER(process_name) LIKE '%\powershell.exe') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## anomalous-signins
<!-- Anomalous user sign-ins with geographic context -->
Find users signing in from IPs that are rare for their account, including country data for immediate triage.

```sqlite target=identity role=baseline params=(lookback_days=lookback_days)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: Sign-in events from IPs only seen once or twice for a given user, potentially
  in unexpected countries.
prevalence:
  by: actor_user_name
  key:
  - src_endpoint_ip
  rare_below: 3
reads:
- actor_user_name
- src_endpoint_ip
- src_location_country
- time
- status_id
silence: not_evidence_of_absence
source: hb_auth_signin
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT actor_user_name, src_endpoint_ip, src_location_country, MIN(time) AS first_seen, COUNT(*) AS login_count FROM hb_auth_signin WHERE status_id = 1 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, src_endpoint_ip, src_location_country HAVING login_count < 5
```

## impact-assessment
<!-- Final assessment of campaign impact -->
```agent target=hunter
cite: required
context:
- early-stage-triage
- shell-execution
- anomalous-signins
max_iterations: 5
objective: 'Determine if current telemetry indicates a successful intrusion or account
  takeover following AI-based reconnaissance. Note: reconcile the device_uid from
  the scoping step with the device_hostname used in later steps to ensure accurate
  cross-surface correlation.'
success_criteria: A per-host and per-user verdict citing specific process or sign-in
  events.
tools:
- endpoint
- identity
- web
```

## route-on-impact
<!-- Route on verdict -->
if~: "the impact-assessment verdict is malicious for at least one host or user account" (confidence: high, judge=hunter)
then: → contain-threat
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: unmanaged-infra-gap)
else: → close-out-benign

## contain-threat
<!-- Isolate host and revoke sessions -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the compromised host from the network and revoke all active sessions for the identified user in the identity provider.
```
→ analyst-review

## analyst-review
<!-- Review triage and confirm breach -->
```manual target=analyst
Review the shell spawn command lines and the source IPs of anomalous logins. Confirm if the activity aligns with a personalized phishing or exploit campaign.
```
→ final-documentation

## close-out-benign
<!-- Close-out benign findings -->
```manual target=analyst
Record the evidence of absence and document the status of vulnerable/exposed assets for remediation.
```
→ end

## final-documentation
<!-- Final documentation -->
```manual target=analyst
Record patches needed for exploited servers and update the social engineering awareness training for targeted users.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.