{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "AI-integrated malware represents an escalation in autonomous cyber attacks. Tracking cognitive artifacts allows defenders to identify these threats at the metadata level, scaling the defense beyond traditional reverse engineering."
      },
      "name": "AI-Integrated Malware Execution and Orchestration",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1190",
        "attack.t1059.006",
        "attack.t1106",
        "attack.t1497",
        "attack.t1027",
        "attack.t1071.001"
      ],
      "related": [
        {
          "hunt": "local-inference-engine-audit",
          "reason": "This hunt focuses on malware; auditing legitimate LLM runtime sprawl is a separate compliance task.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A simple rule for 'Ollama' is too noisy for production. This hunt uses a phased flow to baseline normal execution and then pivots into high-fidelity behavioral markers like natural-language evasion strings and LLM API traffic patterns to confirm malicious intent.",
      "coverage": [
        {
          "stage": "initial-access-exploit",
          "steps": [
            "scope-vulnerable-hosts"
          ],
          "status": "covered"
        },
        {
          "stage": "ai-integrated-execution",
          "steps": [
            "rare-ai-frameworks",
            "local-runtime-execution"
          ],
          "status": "covered"
        },
        {
          "stage": "ai-analysis-evasion",
          "steps": [
            "evasion-string-detection"
          ],
          "status": "covered"
        },
        {
          "stage": "ai-api-orchestration",
          "steps": [
            "llm-api-communication"
          ],
          "status": "covered"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Exploit Public-Facing Application",
            "slug": "initial-access-exploit",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "Exploitation of web-facing services",
              "Vulnerable internet-facing assets"
            ]
          },
          {
            "name": "AI Framework and Runtime Execution",
            "slug": "ai-integrated-execution",
            "tactic": "execution",
            "techniques": [
              "T1059.006",
              "T1106"
            ],
            "observables": [
              "Python imports: langchain, litellm, openai",
              "Local LLM runtimes: ollama, llama.cpp, vllm",
              "AI-related file extensions: .gguf, .safetensors",
              "Embedded prompt templates in code",
              "PE resource strings: CompanyName or FileDescription containing AI terms"
            ]
          },
          {
            "name": "AI-Analysis Evasion",
            "slug": "ai-analysis-evasion",
            "tactic": "defence-evasion",
            "techniques": [
              "T1497",
              "T1027"
            ],
            "observables": [
              "Natural-language suppression text addressed to LLM sandboxes (e.g., 'there's nothing to see here')",
              "Evasion strings embedded in script blocks or binary metadata"
            ]
          },
          {
            "name": "AI Provider API Orchestration",
            "slug": "ai-api-orchestration",
            "tactic": "command-and-control",
            "techniques": [
              "T1071.001"
            ],
            "observables": [
              "api.openai.com",
              "api.anthropic.com",
              "api.deepseek.com",
              "generativelanguage.googleapis.com",
              "Agentic syntax: tool_call, tool_calls, function_call",
              "API key prefixes in traffic or scripts"
            ]
          }
        ],
        "summary": "Threat actors are evolving to use AI-integrated malware that operationalizes LLMs for autonomous orchestration or targets AI systems. This new tradecraft leaves 'cognitive artifacts' such as embedded prompt templates, AI framework imports like LangChain, and communication with hosted LLM provider endpoints."
      },
      "severity": "high",
      "rationale": "Focus on high-vulnerability hosts first, particularly those with internet exposure. If legitimate Python development is common, baseline those users first to reduce noise.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "Adversaries use AI frameworks or local runtimes for autonomous malware orchestration, detectable through cognitive artifacts like framework-specific imports, natural-language evasion strings, and outbound provider API traffic.",
      "parameters": {
        "llm_domains": {
          "from": {
            "ref": "https://blog.talosintelligence.com/introducing-cairn-frontier-tracking-for-ai-integrated-malware/",
            "kind": "article",
            "observed": "2026-09-22"
          },
          "type": "list[domain]",
          "default": [
            "api.openai.com",
            "api.anthropic.com",
            "api.deepseek.com",
            "generativelanguage.googleapis.com"
          ],
          "description": "LLM provider API endpoints used for orchestration."
        },
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Limit the hunt to specific hosts; leave empty for the whole estate."
        },
        "ai_frameworks": {
          "from": {
            "ref": "https://blog.talosintelligence.com/introducing-cairn-frontier-tracking-for-ai-integrated-malware/",
            "kind": "article",
            "observed": "2026-09-22"
          },
          "type": "list[string]",
          "default": [
            "langchain",
            "litellm",
            "openai",
            "tool_call",
            "function_call"
          ],
          "description": "Keywords for AI frameworks and agentic orchestration logic."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "evasion_strings": {
          "from": {
            "ref": "https://blog.talosintelligence.com/introducing-cairn-frontier-tracking-for-ai-integrated-malware/",
            "kind": "article",
            "observed": "2026-09-22"
          },
          "type": "list[string]",
          "default": [
            "nothing to see here",
            "ignore this script",
            "safe to execute",
            "no malicious activity"
          ],
          "description": "Natural language strings used to suppress AI-driven analysis."
        },
        "runtime_binaries": {
          "from": {
            "ref": "https://blog.talosintelligence.com/introducing-cairn-frontier-tracking-for-ai-integrated-malware/",
            "kind": "article",
            "observed": "2026-09-22"
          },
          "type": "list[string]",
          "default": [
            "ollama",
            "llama.cpp",
            "vllm",
            "llama-server"
          ],
          "description": "Binaries associated with local LLM inference engines."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://blog.talosintelligence.com/introducing-cairn-frontier-tracking-for-ai-integrated-malware/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://blog.talosintelligence.com/introducing-cairn-frontier-tracking-for-ai-integrated-malware/",
          "name": "Introducing CAIRN: Frontier tracking for AI-integrated malware"
        }
      ],
      "blind_spots": [
        {
          "id": "encrypted-prompts",
          "risk": "While we see the connection to OpenAI or Anthropic, we cannot see the malicious prompts or data exfiltration without decryption.",
          "owner": "SOC Engineering",
          "stage": "ai-api-orchestration",
          "question": "What instructions were being sent to the AI providers?",
          "requires": "TLS inspection of LLM API endpoints",
          "remediation": "Deploy transparent TLS inspection for known AI provider endpoints."
        },
        {
          "id": "custom-llm-endpoints",
          "risk": "If the attacker hosts their own API on a generic cloud IP, our domain-based filters will not fire.",
          "owner": "Network Security",
          "stage": "ai-api-orchestration",
          "question": "Was the malware communicating with a private LLM endpoint?",
          "requires": "Heuristic network clustering",
          "remediation": "Monitor for anomalous outbound traffic on ports 443/8080 to cloud providers not associated with business tools."
        }
      ]
    },
    "name": "AI-Integrated Malware Execution and Orchestration",
    "description": "This hunt focuses on the emerging threat of AI-integrated malware by tracking the transition from initial host exploitation to the execution of AI-enabled payloads. We search for cognitive artifacts\u2014metadata-level indicators such as AI framework imports in process command lines and the presence of local inference engines. The hunt then correlates these execution signals with natural-language evasion strings addressed to LLM-based sandboxes and outbound communication to established LLM provider endpoints for autonomous orchestration."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "coverage": [
          {
            "stage": "initial-access-exploit",
            "steps": [
              "scope-vulnerable-hosts"
            ],
            "status": "covered"
          },
          {
            "stage": "ai-integrated-execution",
            "steps": [
              "rare-ai-frameworks",
              "local-runtime-execution"
            ],
            "status": "covered"
          },
          {
            "stage": "ai-analysis-evasion",
            "steps": [
              "evasion-string-detection"
            ],
            "status": "covered"
          },
          {
            "stage": "ai-api-orchestration",
            "steps": [
              "llm-api-communication"
            ],
            "status": "covered"
          }
        ],
        "rationale": "Adversaries use AI frameworks or local runtimes for autonomous malware orchestration, detectable through cognitive artifacts like framework-specific imports, natural-language evasion strings, and outbound provider API traffic.",
        "blind_spots": [
          {
            "id": "encrypted-prompts",
            "risk": "While we see the connection to OpenAI or Anthropic, we cannot see the malicious prompts or data exfiltration without decryption.",
            "owner": "SOC Engineering",
            "stage": "ai-api-orchestration",
            "question": "What instructions were being sent to the AI providers?",
            "requires": "TLS inspection of LLM API endpoints",
            "remediation": "Deploy transparent TLS inspection for known AI provider endpoints."
          },
          {
            "id": "custom-llm-endpoints",
            "risk": "If the attacker hosts their own API on a generic cloud IP, our domain-based filters will not fire.",
            "owner": "Network Security",
            "stage": "ai-api-orchestration",
            "question": "Was the malware communicating with a private LLM endpoint?",
            "requires": "Heuristic network clustering",
            "remediation": "Monitor for anomalous outbound traffic on ports 443/8080 to cloud providers not associated with business tools."
          }
        ],
        "scoping_notes": "Focus on high-vulnerability hosts first, particularly those with internet exposure. If legitimate Python development is common, baseline those users first to reduce noise.",
        "beyond_detection": "A simple rule for 'Ollama' is too noisy for production. This hunt uses a phased flow to baseline normal execution and then pivots into high-fidelity behavioral markers like natural-language evasion strings and LLM API traffic patterns to confirm malicious intent."
      }
    },
    {
      "id": "scope-vulnerable-hosts",
      "type": "query",
      "label": "Identify vulnerable internet-facing assets",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_uid, cve_uid, severity, title FROM hb_vulnerability_finding WHERE severity_id >= 4 AND resource_type = 'device' AND status != 'suppressed'",
        "surface": "hb_vulnerability_finding",
        "description": "Find devices with high-severity vulnerabilities that serve as potential beachheads for AI-integrated malware.",
        "expected_signal": "A list of hosts with critical vulnerabilities. These are the priority targets for the subsequent execution-focused queries."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify vulnerable internet-facing assets",
        "reads": [
          "cve_uid",
          "device_uid",
          "resource_type",
          "severity",
          "severity_id",
          "status",
          "title"
        ],
        "source": "hb_vulnerability_finding",
        "target": "endpoint",
        "content": "SELECT device_uid, cve_uid, severity, title FROM hb_vulnerability_finding WHERE severity_id >= 4 AND resource_type = 'device' AND status != 'suppressed'",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hosts with critical vulnerabilities. These are the priority targets for the subsequent execution-focused queries.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "rare-ai-frameworks",
      "type": "query",
      "label": "Rare AI framework usage in command lines",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT process_name, process_cmd_line, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_process_activity WHERE (instr(LOWER(process_cmd_line), 'langchain') > 0 OR instr(LOWER(process_cmd_line), 'litellm') > 0 OR instr(LOWER(process_cmd_line), 'openai') > 0 OR instr(LOWER(process_cmd_line), 'tool_call') > 0 OR instr(LOWER(process_cmd_line), 'function_call') > 0) AND ('{{ai_frameworks}}' != '') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_name, process_cmd_line HAVING hosts <= 3",
        "surface": "hb_process_activity",
        "description": "Identify anomalous usage of AI libraries that suggest an autonomous agent rather than legitimate development.",
        "expected_signal": "A small number of hosts running AI framework keywords. Fleet-wide presence suggests legitimate tools, while isolated usage is a lead."
      },
      "parents": [
        {
          "id": "scope-vulnerable-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare AI framework usage in command lines",
        "reads": [
          "device_hostname",
          "process_cmd_line",
          "process_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT process_name, process_cmd_line, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_process_activity WHERE (instr(LOWER(process_cmd_line), 'langchain') > 0 OR instr(LOWER(process_cmd_line), 'litellm') > 0 OR instr(LOWER(process_cmd_line), 'openai') > 0 OR instr(LOWER(process_cmd_line), 'tool_call') > 0 OR instr(LOWER(process_cmd_line), 'function_call') > 0) AND ('{{ai_frameworks}}' != '') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_name, process_cmd_line HAVING hosts <= 3",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A small number of hosts running AI framework keywords. Fleet-wide presence suggests legitimate tools, while isolated usage is a lead.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_name",
            "process_cmd_line"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "local-runtime-execution",
      "type": "query",
      "label": "Local LLM runtime execution",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE instr(',' || '{{runtime_binaries}}' || ',', ',' || LOWER(process_name) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Detect the execution of local inference engines like Ollama that enable on-device orchestration.",
        "expected_signal": "Rows showing local LLM servers running on endpoints. Rarity and association with the previously identified vulnerable hosts increase suspicion."
      },
      "parents": [
        {
          "id": "scope-vulnerable-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Local LLM runtime execution",
        "reads": [
          "device_hostname",
          "process_cmd_line",
          "process_name",
          "time",
          "user_name"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE instr(',' || '{{runtime_binaries}}' || ',', ',' || LOWER(process_name) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Rows showing local LLM servers running on endpoints. Rarity and association with the previously identified vulnerable hosts increase suspicion.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "triage-early-execution",
      "type": "analytic",
      "label": "Triage AI execution relevance",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "rare-ai-frameworks",
          "local-runtime-execution"
        ],
        "objective": "Determine if the execution of AI runtimes and frameworks concentrates on specific suspicious hosts and lacks legitimate developer context.",
        "description": "Assess whether identified AI framework usage and runtimes represent unauthorized activity.",
        "max_iterations": 4,
        "expected_signal": "A per-host assessment of the AI artifacts.",
        "success_criteria": "A list of hosts where AI execution is suspicious and requires further investigation for intent."
      },
      "parents": [
        {
          "id": "rare-ai-frameworks",
          "kind": "merge"
        },
        {
          "id": "local-runtime-execution",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "evasion-string-detection",
      "type": "query",
      "label": "AI-analysis evasion strings in scripts",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, script_content, time FROM hb_script_activity WHERE (instr(LOWER(script_content), 'nothing to see here') > 0 OR instr(LOWER(script_content), 'ignore this script') > 0 OR instr(LOWER(script_content), 'safe to execute') > 0 OR instr(LOWER(script_content), 'no malicious activity') > 0) AND ('{{evasion_strings}}' != '') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_script_activity",
        "description": "Detect cognitive artifacts that target AI security scanners, indicating malicious intent.",
        "expected_signal": "Script contents containing natural language addressed to a LLM sandbox. This is a very high-fidelity signal of AI-integrated malware tradecraft."
      },
      "parents": [
        {
          "id": "triage-early-execution"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "AI-analysis evasion strings in scripts",
        "reads": [
          "device_hostname",
          "process_name",
          "script_content",
          "time"
        ],
        "source": "hb_script_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, script_content, time FROM hb_script_activity WHERE (instr(LOWER(script_content), 'nothing to see here') > 0 OR instr(LOWER(script_content), 'ignore this script') > 0 OR instr(LOWER(script_content), 'safe to execute') > 0 OR instr(LOWER(script_content), 'no malicious activity') > 0) AND ('{{evasion_strings}}' != '') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Script contents containing natural language addressed to a LLM sandbox. This is a very high-fidelity signal of AI-integrated malware tradecraft.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "llm-api-communication",
      "type": "query",
      "label": "Outbound DNS to LLM provider APIs",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, query_hostname, time FROM hb_dns_activity WHERE instr(',' || '{{llm_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_dns_activity",
        "description": "Correlate identified hosts and processes with orchestration traffic to LLM providers.",
        "expected_signal": "DNS resolutions for major LLM providers. When associated with the rare AI processes identified earlier, these indicate C2 orchestration."
      },
      "parents": [
        {
          "id": "triage-early-execution"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Outbound DNS to LLM provider APIs",
        "reads": [
          "device_hostname",
          "process_name",
          "query_hostname",
          "time"
        ],
        "source": "hb_dns_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, query_hostname, time FROM hb_dns_activity WHERE instr(',' || '{{llm_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "DNS resolutions for major LLM providers. When associated with the rare AI processes identified earlier, these indicate C2 orchestration.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "triage-follow-on",
      "type": "analytic",
      "label": "Final AI malware chain triage",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "triage-early-execution",
          "evasion-string-detection",
          "llm-api-communication"
        ],
        "objective": "Establish if any host shows the co-occurrence of rare AI execution, cognitive evasion strings, and outbound LLM provider traffic.",
        "description": "Synthesize the complete attack chain: execution, evasion, and orchestration.",
        "max_iterations": 6,
        "expected_signal": "A comprehensive per-host verdict linking behavioral stages.",
        "success_criteria": "A final verdict citing specific execution rows and corresponding intent/C2 evidence."
      },
      "parents": [
        {
          "id": "evasion-string-detection",
          "kind": "merge"
        },
        {
          "id": "llm-api-communication",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "decision-route",
      "type": "checkpoint",
      "label": "Route on AI-integrated malware verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage-follow-on verdict is malicious for at least one host",
        "condition": "the triage-follow-on verdict is malicious for at least one host",
        "blind_spot": "encrypted-prompts",
        "confidence": "high",
        "description": "Route the findings based on the confirmed presence of the AI-integrated attack chain.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-follow-on"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate endpoint",
      "config": {
        "target": "endpoint",
        "description": "Stop autonomous orchestration by isolating the infected host.",
        "instructions": "Isolate the host from the network. Capture memory before shutdown to preserve prompt artifacts.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "decision-route",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Analyst forensic review",
      "config": {
        "assignee": "analyst",
        "description": "Verify the agentic logic and extract cognitive artifacts for reporting.",
        "instructions": "Review the identified scripts and processes. Extract embedded prompt templates and provider API keys. Attribute the malware to known AI families (e.g., CLOSEDQUORUM) if possible."
      },
      "parents": [
        {
          "id": "decision-route",
          "branch": "default"
        },
        {
          "id": "decision-route",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out and tune",
      "config": {
        "assignee": "analyst",
        "description": "Finalize the hunt and record tuning notes for future AI artifact detection.",
        "instructions": "Record the results. If legitimate AI activity caused noise, add the authorized paths to the exclusion parameters."
      },
      "parents": [
        {
          "id": "decision-route",
          "branch": "on_refutes"
        },
        {
          "id": "analyst-review"
        }
      ]
    }
  ]
}