{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "AI allows adversaries to scale personalized fraud and vulnerability research; confirming these targeted efforts have not transitioned into active breaches is a critical hygiene task."
      },
      "name": "AI-Enhanced OSINT and Identity Abuse",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1190",
        "attack.t1566",
        "credential access",
        "impact",
        "initial access"
      ],
      "related": [
        {
          "hunt": "social-media-privacy-audit",
          "reason": "This hunt focuses on technical compromise, not the proactive auditing of employee social media privacy.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        },
        "identity": {
          "name": "Identity / sign-in telemetry",
          "category": "identity",
          "telemetry": [
            "identity"
          ]
        }
      },
      "analysis": "A single rule might catch a web shell, but this hunt correlates vulnerability inventory, external exposure, and anomalous sign-in patterns to identify the full lifecycle of an AI-enhanced campaign.",
      "coverage": [
        {
          "stage": "vulnerability-discovery-and-exploitation",
          "steps": [
            "scoping-vulnerable-assets",
            "probing-activity",
            "exposed-services"
          ],
          "status": "covered"
        },
        {
          "stage": "personalized-phishing-and-social-engineering",
          "steps": [
            "anomalous-signins"
          ],
          "reason": "Covered via the outcome of successful phishing (account takeover).",
          "status": "covered"
        },
        {
          "stage": "credential-harvesting-and-malware-execution",
          "steps": [
            "shell-execution",
            "anomalous-signins"
          ],
          "status": "covered"
        },
        {
          "stage": "bec-and-fraudulent-impact",
          "steps": [
            "anomalous-signins"
          ],
          "status": "covered"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "AI-Aided Vulnerability Exploitation",
            "slug": "vulnerability-discovery-and-exploitation",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "Automated identification of internet-facing vulnerabilities",
              "Exploitation of public-facing software bugs or misconfigurations"
            ]
          },
          {
            "name": "AI-Driven Personalized Phishing",
            "slug": "personalized-phishing-and-social-engineering",
            "tactic": "initial-access",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "Phishing emails containing personal details (workplace, schools, birthdays, recent travel)",
              "Malicious links in emails or social media",
              "Deepfake video or voice calls impersonating victims",
              "Social engineering scripts designed by LLMs"
            ]
          },
          {
            "name": "Credential Harvesting and Malware Execution",
            "slug": "credential-harvesting-and-malware-execution",
            "tactic": "credential-access",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "Logins to fraudulent credential harvesting pages",
              "Installation of malware via malicious email attachments or links",
              "Execution of suspicious binary or script payloads"
            ]
          },
          {
            "name": "Business Email Compromise and Fraud",
            "slug": "bec-and-fraudulent-impact",
            "tactic": "impact",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "Anomalous sign-ins using harvested work credentials",
              "Business Email Compromise (BEC) targeting colleagues",
              "Fraudulent financial requests or sextortion threats"
            ]
          }
        ],
        "summary": "Threat actors are leveraging AI to automate OSINT at scale, creating highly personalized phishing and social engineering campaigns by profiling victims' personal and professional lives. This AI-driven pipeline facilitates more convincing deepfakes, credential harvesting, and Business Email Compromise (BEC) attacks by lowering the technical barrier for fraudsters."
      },
      "severity": "medium",
      "rationale": "Focus on internet-facing web servers and employees in high-value roles (Finance, HR, C-suite) who are the primary targets of AI-automated OSINT.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary is using AI-automated OSINT to identify vulnerable web applications and craft high-fidelity phishing lures, leading to server exploitation and account takeover for fraud.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Specific hostnames to focus the hunt; leave empty for all hosts."
        },
        "shell_paths": {
          "type": "list[path]",
          "default": [
            "cmd.exe",
            "powershell.exe",
            "sh",
            "bash"
          ],
          "description": "Shell processes to monitor for spawns from web servers."
        },
        "target_cves": {
          "type": "list[string]",
          "default": [
            "CVE-2024-21887",
            "CVE-2023-46604",
            "CVE-2023-22515"
          ],
          "description": "Critical CVEs prioritized by automated scanners."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.welivesecurity.com/en/privacy/ai-powered-osint-why-everyone-viable-target-fraud/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.welivesecurity.com/en/privacy/ai-powered-osint-why-everyone-viable-target-fraud/",
          "name": "ESET Research \u2014 AI-driven OSINT in the wrong hands"
        }
      ],
      "blind_spots": [
        {
          "id": "deepfake-telemetry-gap",
          "risk": "Social engineering conducted over voice or video cannot be detected via current endpoint or cloud telemetry.",
          "stage": "personalized-phishing-and-social-engineering",
          "question": "whether the phishing attempt used AI-generated deepfake audio calls",
          "requires": "VoIP or voice log analysis"
        },
        {
          "id": "unmanaged-infra-gap",
          "risk": "Exploitation of servers missing an agent will show up in HTTP logs but will not show follow-on process activity.",
          "stage": "vulnerability-discovery-and-exploitation",
          "question": "whether exploitation occurred on shadow-IT or unmanaged servers",
          "requires": "Complete EDR coverage on all web servers"
        }
      ]
    },
    "name": "AI-Enhanced OSINT and Identity Abuse",
    "description": "This hunt identifies the transition from automated external reconnaissance to active internal breach. It first scopes vulnerable and exposed assets that AI scanners prioritize, then evaluates suspicious HTTP activity. A second phase hunts for the outcome: web shells spawned from server processes and anomalous user sign-ins from rare locations indicating credential theft. An agent correlates these phases to identify successful AI-enhanced social engineering campaigns."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "coverage": [
          {
            "stage": "vulnerability-discovery-and-exploitation",
            "steps": [
              "scoping-vulnerable-assets",
              "probing-activity",
              "exposed-services"
            ],
            "status": "covered"
          },
          {
            "stage": "personalized-phishing-and-social-engineering",
            "steps": [
              "anomalous-signins"
            ],
            "reason": "Covered via the outcome of successful phishing (account takeover).",
            "status": "covered"
          },
          {
            "stage": "credential-harvesting-and-malware-execution",
            "steps": [
              "shell-execution",
              "anomalous-signins"
            ],
            "status": "covered"
          },
          {
            "stage": "bec-and-fraudulent-impact",
            "steps": [
              "anomalous-signins"
            ],
            "status": "covered"
          }
        ],
        "rationale": "An adversary is using AI-automated OSINT to identify vulnerable web applications and craft high-fidelity phishing lures, leading to server exploitation and account takeover for fraud.",
        "blind_spots": [
          {
            "id": "deepfake-telemetry-gap",
            "risk": "Social engineering conducted over voice or video cannot be detected via current endpoint or cloud telemetry.",
            "stage": "personalized-phishing-and-social-engineering",
            "question": "whether the phishing attempt used AI-generated deepfake audio calls",
            "requires": "VoIP or voice log analysis"
          },
          {
            "id": "unmanaged-infra-gap",
            "risk": "Exploitation of servers missing an agent will show up in HTTP logs but will not show follow-on process activity.",
            "stage": "vulnerability-discovery-and-exploitation",
            "question": "whether exploitation occurred on shadow-IT or unmanaged servers",
            "requires": "Complete EDR coverage on all web servers"
          }
        ],
        "scoping_notes": "Focus on internet-facing web servers and employees in high-value roles (Finance, HR, C-suite) who are the primary targets of AI-automated OSINT.",
        "beyond_detection": "A single rule might catch a web shell, but this hunt correlates vulnerability inventory, external exposure, and anomalous sign-in patterns to identify the full lifecycle of an AI-enhanced campaign."
      }
    },
    {
      "id": "scoping-vulnerable-assets",
      "type": "query",
      "label": "Scope vulnerable internet-facing assets",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_uid, cve_uid, affected_package_name, severity, last_seen FROM hb_vulnerability_finding WHERE severity_id >= 4 AND (instr(',' || '{{target_cves}}' || ',', ',' || cve_uid || ',') > 0 OR is_kev = 'true')",
        "surface": "hb_vulnerability_finding",
        "description": "Identify hosts with critical vulnerabilities that AI-assisted reconnaissance would likely discover and exploit.",
        "expected_signal": "A list of vulnerable hosts. Silence indicates no known critical vulnerabilities are currently reported."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Scope vulnerable internet-facing assets",
        "reads": [
          "device_uid",
          "cve_uid",
          "affected_package_name",
          "severity",
          "last_seen"
        ],
        "source": "hb_vulnerability_finding",
        "target": "endpoint",
        "content": "SELECT device_uid, cve_uid, affected_package_name, severity, last_seen FROM hb_vulnerability_finding WHERE severity_id >= 4 AND (instr(',' || '{{target_cves}}' || ',', ',' || cve_uid || ',') > 0 OR is_kev = 'true')",
        "silence": "not_evidence_of_absence",
        "expected": "A list of vulnerable hosts. Silence indicates no known critical vulnerabilities are currently reported.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "probing-activity",
      "type": "query",
      "label": "Suspicious HTTP exploitation probing",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "web",
        "content": "SELECT device_hostname, src_endpoint_ip, LOWER(url_path) AS path, status_code, COUNT(*) AS req_count FROM hb_http_activity WHERE http_method = 'POST' AND status_code = 200 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, src_endpoint_ip, LOWER(url_path) HAVING req_count > 50",
        "surface": "hb_http_activity",
        "description": "Detect automated POST requests to web applications that suggest vulnerability exploitation attempts.",
        "expected_signal": "A high volume of successful POSTs from a single IP to a specific path, suggesting automated exploitation."
      },
      "parents": [
        {
          "id": "scoping-vulnerable-assets"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Suspicious HTTP exploitation probing",
        "reads": [
          "device_hostname",
          "src_endpoint_ip",
          "url_path",
          "status_code",
          "time"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT device_hostname, src_endpoint_ip, LOWER(url_path) AS path, status_code, COUNT(*) AS req_count FROM hb_http_activity WHERE http_method = 'POST' AND status_code = 200 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, src_endpoint_ip, LOWER(url_path) HAVING req_count > 50",
        "silence": "not_evidence_of_absence",
        "expected": "A high volume of successful POSTs from a single IP to a specific path, suggesting automated exploitation.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "exposed-services",
      "type": "query",
      "label": "Exposed administrative services",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT domain_or_ip, port, product, discovered_at FROM hb_exposed_assets WHERE port IN (22, 445, 3389) AND discovered_at >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_exposed_assets",
        "description": "Identify internet-exposed RDP, SSH, or SMB ports which AI-driven scanners prioritize for breach attempts.",
        "expected_signal": "Company IP addresses exposing administrative ports. Rare ports indicate potential misconfigurations."
      },
      "parents": [
        {
          "id": "scoping-vulnerable-assets"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Exposed administrative services",
        "reads": [
          "domain_or_ip",
          "port",
          "product",
          "discovered_at"
        ],
        "source": "hb_exposed_assets",
        "target": "endpoint",
        "content": "SELECT domain_or_ip, port, product, discovered_at FROM hb_exposed_assets WHERE port IN (22, 445, 3389) AND discovered_at >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "new_this_window"
        },
        "expected": "Company IP addresses exposing administrative ports. Rare ports indicate potential misconfigurations.",
        "verified": "dry-run",
        "prevalence": {
          "by": "domain_or_ip",
          "key": [
            "port"
          ],
          "rare_below": 2
        },
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "early-stage-triage",
      "type": "analytic",
      "label": "Triage early-stage access signals",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity",
          "web"
        ],
        "context": [
          "scoping-vulnerable-assets",
          "probing-activity",
          "exposed-services"
        ],
        "objective": "Determine which hosts are actively being probed or targeted based on vulnerability and exposure data.",
        "description": "Identify hosts that are the likely targets of AI-automated reconnaissance.",
        "max_iterations": 3,
        "expected_signal": "A per-host verdict citing vulnerability and exposure risks.",
        "success_criteria": "A statement identifying specific hosts at risk of initial access."
      },
      "parents": [
        {
          "id": "probing-activity",
          "kind": "merge"
        },
        {
          "id": "exposed-services",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "shell-execution",
      "type": "query",
      "label": "Web servers spawning shell processes",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, parent_process_name, process_name, process_cmd_line, time FROM hb_process_activity WHERE (LOWER(parent_process_name) LIKE '%httpd%' OR LOWER(parent_process_name) LIKE '%nginx%' OR LOWER(parent_process_name) LIKE '%w3wp.exe%') AND (instr(',' || '{{shell_paths}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR LOWER(process_name) LIKE '%/sh' OR LOWER(process_name) LIKE '%/bash' OR LOWER(process_name) LIKE '%\\cmd.exe' OR LOWER(process_name) LIKE '%\\powershell.exe') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Detect T1190 follow-on activity where an exploited web application executes a shell. The query handles full paths by matching the shell basename.",
        "expected_signal": "Rows showing a web server process as the parent of a shell like cmd.exe or bash."
      },
      "parents": [
        {
          "id": "early-stage-triage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Web servers spawning shell processes",
        "reads": [
          "device_hostname",
          "parent_process_name",
          "process_name",
          "process_cmd_line",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, parent_process_name, process_name, process_cmd_line, time FROM hb_process_activity WHERE (LOWER(parent_process_name) LIKE '%httpd%' OR LOWER(parent_process_name) LIKE '%nginx%' OR LOWER(parent_process_name) LIKE '%w3wp.exe%') AND (instr(',' || '{{shell_paths}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR LOWER(process_name) LIKE '%/sh' OR LOWER(process_name) LIKE '%/bash' OR LOWER(process_name) LIKE '%\\cmd.exe' OR LOWER(process_name) LIKE '%\\powershell.exe') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "evidence_of_absence",
        "expected": "Rows showing a web server process as the parent of a shell like cmd.exe or bash.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "anomalous-signins",
      "type": "query",
      "label": "Anomalous user sign-ins with geographic context",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "identity",
        "content": "SELECT actor_user_name, src_endpoint_ip, src_location_country, MIN(time) AS first_seen, COUNT(*) AS login_count FROM hb_auth_signin WHERE status_id = 1 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, src_endpoint_ip, src_location_country HAVING login_count < 5",
        "surface": "hb_auth_signin",
        "description": "Find users signing in from IPs that are rare for their account, including country data for immediate triage.",
        "expected_signal": "Sign-in events from IPs only seen once or twice for a given user, potentially in unexpected countries."
      },
      "parents": [
        {
          "id": "early-stage-triage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Anomalous user sign-ins with geographic context",
        "reads": [
          "actor_user_name",
          "src_endpoint_ip",
          "src_location_country",
          "time",
          "status_id"
        ],
        "source": "hb_auth_signin",
        "target": "identity",
        "content": "SELECT actor_user_name, src_endpoint_ip, src_location_country, MIN(time) AS first_seen, COUNT(*) AS login_count FROM hb_auth_signin WHERE status_id = 1 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, src_endpoint_ip, src_location_country HAVING login_count < 5",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Sign-in events from IPs only seen once or twice for a given user, potentially in unexpected countries.",
        "verified": "dry-run",
        "prevalence": {
          "by": "actor_user_name",
          "key": [
            "src_endpoint_ip"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "impact-assessment",
      "type": "analytic",
      "label": "Final assessment of campaign impact",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity",
          "web"
        ],
        "context": [
          "early-stage-triage",
          "shell-execution",
          "anomalous-signins"
        ],
        "objective": "Determine if current telemetry indicates a successful intrusion or account takeover following AI-based reconnaissance. Note: reconcile the device_uid from the scoping step with the device_hostname used in later steps to ensure accurate cross-surface correlation.",
        "description": "Correlate early triage with follow-on execution and sign-in patterns to confirm a successful campaign.",
        "max_iterations": 5,
        "expected_signal": "A definitive verdict identifying specific hosts and accounts that show evidence of compromise.",
        "success_criteria": "A per-host and per-user verdict citing specific process or sign-in events."
      },
      "parents": [
        {
          "id": "shell-execution",
          "kind": "merge"
        },
        {
          "id": "anomalous-signins",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-impact",
      "type": "checkpoint",
      "label": "Route on verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the impact-assessment verdict is malicious for at least one host or user account",
        "condition": "the impact-assessment verdict is malicious for at least one host or user account",
        "blind_spot": "unmanaged-infra-gap",
        "confidence": "high",
        "description": "Direct the hunt to containment if a breach is confirmed.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "impact-assessment"
        }
      ]
    },
    {
      "id": "contain-threat",
      "type": "action",
      "label": "Isolate host and revoke sessions",
      "config": {
        "target": "endpoint",
        "description": "Halt active attacker movement on identified assets.",
        "instructions": "Isolate the compromised host from the network and revoke all active sessions for the identified user in the identity provider.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-impact",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Review triage and confirm breach",
      "config": {
        "assignee": "analyst",
        "description": "Manually verify the findings cited by the agent before closing the incident.",
        "instructions": "Review the shell spawn command lines and the source IPs of anomalous logins. Confirm if the activity aligns with a personalized phishing or exploit campaign."
      },
      "parents": [
        {
          "id": "route-on-impact",
          "branch": "default"
        },
        {
          "id": "route-on-impact",
          "branch": "on_unavailable"
        },
        {
          "id": "contain-threat"
        }
      ]
    },
    {
      "id": "close-out-benign",
      "type": "task",
      "label": "Close-out benign findings",
      "config": {
        "assignee": "analyst",
        "description": "Document the hunt outcome when no malicious activity was found.",
        "instructions": "Record the evidence of absence and document the status of vulnerable/exposed assets for remediation."
      },
      "parents": [
        {
          "id": "route-on-impact",
          "branch": "on_refutes"
        }
      ]
    },
    {
      "id": "final-documentation",
      "type": "task",
      "label": "Final documentation",
      "config": {
        "assignee": "analyst",
        "description": "Document the incident scope and trigger remediation workflows.",
        "instructions": "Record patches needed for exploited servers and update the social engineering awareness training for targeted users."
      },
      "parents": [
        {
          "id": "analyst-review"
        }
      ]
    }
  ]
}