{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Akira ransomware results in total business disruption; detecting the terminal exfiltration phase and backup destruction provides the final opportunity for intervention before catastrophic data loss."
      },
      "name": "Akira Ransomware Exfiltration and Impact",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1048.003",
        "attack.t1020",
        "attack.t1486",
        "attack.t1490",
        "attack.t1047",
        "command and control",
        "credential access",
        "discovery",
        "execution",
        "exfiltration",
        "impact",
        "initial access",
        "lateral movement"
      ],
      "series": {
        "slug": "from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira",
        "index": 3,
        "title": "From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira",
        "total": 3
      },
      "related": [
        {
          "hunt": "bumblebee-loader-behavior",
          "reason": "The initial delivery and C2 establishment phases are handled in the first hunt of this series.",
          "relation": "out-of-scope-alternative"
        },
        {
          "hunt": "bumblebee-persistence-and-ad-credential-harvesting",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "network": {
          "name": "Network telemetry",
          "category": "network",
          "telemetry": [
            "network"
          ]
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A single rule might alert on vssadmin usage, but this hunt pivots between original binary names, rare destination stacking, and network volume across three different telemetry surfaces to distinguish a ransomware incident from administrative maintenance.",
      "coverage": [
        {
          "stage": "data-exfiltration-sftp",
          "steps": [
            "identify-suspect-processes",
            "bulk-exfiltration-stacking"
          ],
          "status": "covered"
        },
        {
          "stage": "impact-ransomware-encryption",
          "steps": [
            "identify-suspect-processes",
            "shadow-copy-removal"
          ],
          "status": "covered"
        },
        {
          "stage": "initial-access-seo-redirection",
          "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "execution-dll-side-loading",
          "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "c2-establishment-adaptix",
          "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "internal-discovery-and-persistence",
          "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "lateral-movement-tunneling",
          "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "credential-access-harvesting",
          "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "SEO Poisoning Redirection",
            "slug": "initial-access-seo-redirection",
            "tactic": "initial-access",
            "techniques": [
              "T1189",
              "T1583.008"
            ],
            "observables": [
              "opmanager.pro",
              "download-center.online",
              "ip-scanner.org",
              "download-server.online",
              "soft-server.online",
              "soft-hub.pro",
              "netml.shop",
              "/Get?q="
            ]
          },
          {
            "name": "Bumblebee DLL Side-Loading",
            "slug": "execution-dll-side-loading",
            "tactic": "execution",
            "techniques": [
              "T1204.002",
              "T1574.002"
            ],
            "observables": [
              "ManageEngine-OpManager.msi",
              "consent.exe",
              "msimg32.dll",
              "%TEMP%\\ApplicationInstallationFolder_11",
              "ApplicationInstallationFolder_11"
            ]
          },
          {
            "name": "AdaptixC2 Infrastructure Setup",
            "slug": "c2-establishment-adaptix",
            "tactic": "command-and-control",
            "techniques": [
              "T1071.001",
              "T1568.002",
              "T1055"
            ],
            "observables": [
              "AdgNsy.exe",
              "4.239.95.1:8080",
              "84.32.84.32"
            ]
          },
          {
            "name": "Internal Reconnaissance and Persistence",
            "slug": "internal-discovery-and-persistence",
            "tactic": "discovery",
            "techniques": [
              "T1082",
              "T1016",
              "T1136.002",
              "T1543.003"
            ],
            "observables": [
              "systeminfo",
              "nltest",
              "RustDesk",
              "Enterprise Admin accounts"
            ]
          },
          {
            "name": "SSH Tunneling and RDP Pivot",
            "slug": "lateral-movement-tunneling",
            "tactic": "lateral-movement",
            "techniques": [
              "T1021.001",
              "T1572"
            ],
            "observables": [
              "reverse SSH tunnel",
              "RDP proxy traffic"
            ]
          },
          {
            "name": "Active Directory and Veeam Credential Harvesting",
            "slug": "credential-access-harvesting",
            "tactic": "credential-access",
            "techniques": [
              "T1003.003",
              "T1003.001",
              "T1552.004"
            ],
            "observables": [
              "wbadmin.exe",
              "ntds.dit",
              "lsassy",
              "Veeam credential dumping script"
            ]
          },
          {
            "name": "Data Exfiltration via SFTP",
            "slug": "data-exfiltration-sftp",
            "tactic": "exfiltration",
            "techniques": [
              "T1048.003",
              "T1020"
            ],
            "observables": [
              "FileZilla.exe",
              "75GB exfiltrated",
              "Ukrainian IP space"
            ]
          },
          {
            "name": "Akira Ransomware Impact",
            "slug": "impact-ransomware-encryption",
            "tactic": "impact",
            "techniques": [
              "T1486",
              "T1490",
              "T1047"
            ],
            "observables": [
              "locker.exe",
              "delete Volume Shadow Copies",
              "WMI"
            ]
          }
        ],
        "summary": "Threat actors utilized Bing SEO poisoning to deliver Bumblebee malware via trojanized software installers, leading to the deployment of AdaptixC2 for network discovery. The attackers leveraged RDP over SSH tunnels to move laterally and harvest credentials from NTDS.dit and LSASS before exfiltrating 75GB of data and deploying Akira ransomware."
      },
      "severity": "critical",
      "rationale": "Focus the hunt on file servers, domain controllers, and backup infrastructure (e.g., Veeam servers), as these were specifically targeted for bulk data theft and encryption in this scenario.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary is exfiltrating bulk data via SFTP using FileZilla and executing Akira ransomware, evidenced by massive outbound network transfers and the destruction of Volume Shadow Copies.",
      "parameters": {
        "exfil_tools": {
          "from": {
            "ref": "dfir-report-akira",
            "kind": "article",
            "observed": "2025-07-01"
          },
          "type": "list[string]",
          "default": [
            "filezilla.exe",
            "sftp.exe"
          ],
          "description": "Original file names of common exfiltration tools."
        },
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Limit the hunt to specific hosts; leave empty to scan the full estate."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "impact_admin_tools": {
          "from": {
            "ref": "dfir-report-akira",
            "kind": "article",
            "observed": "2025-07-01"
          },
          "type": "list[string]",
          "default": [
            "vssadmin.exe",
            "wmic.exe",
            "powershell.exe",
            "pwsh.exe",
            "powershell_ise.exe"
          ],
          "description": "Legitimate administrative tools often abused for shadow copy deletion."
        },
        "ransomware_binaries": {
          "from": {
            "ref": "dfir-report-akira",
            "kind": "article",
            "observed": "2025-07-01"
          },
          "type": "list[string]",
          "default": [
            "locker.exe",
            "akira.exe"
          ],
          "description": "Original file names associated with the Akira payload."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/",
          "name": "The DFIR Report \u2014 From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira"
        }
      ],
      "blind_spots": [
        {
          "id": "missing-byte-counters",
          "risk": "Without byte counters, we can see the connection to the Ukrainian destination but cannot confirm the magnitude of the data breach.",
          "stage": "data-exfiltration-sftp",
          "question": "Was 75GB of data actually exfiltrated?",
          "requires": "hb_network_connection with traffic_bytes from flow logs"
        },
        {
          "id": "api-shadow-deletion",
          "risk": "Advanced ransomware using direct API calls (e.g., IVssBackupComponents) to delete shadows will bypass process command-line monitoring.",
          "stage": "impact-ransomware-encryption",
          "question": "Was shadow deletion performed without using the command line?",
          "requires": "Endpoint monitoring for COM/WMI API calls"
        }
      ]
    },
    "name": "Akira Ransomware Exfiltration and Impact",
    "description": "This hunt identifies the final, high-impact phase of an Akira ransomware intrusion. It scopes for the execution of known exfiltration tools and the ransomware binary itself (locker.exe), then corroborates this with behavioral evidence: bulk network transfers to rare destinations\u2014matching the 75GB volume reported\u2014and the deletion of system recovery options via shadow copy removal. An agent triages these signals to confirm if a host has reached the final stage of encryption, enabling immediate containment before widespread business disruption occurs."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira",
          "index": 3,
          "title": "From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira",
          "total": 3
        },
        "coverage": [
          {
            "stage": "data-exfiltration-sftp",
            "steps": [
              "identify-suspect-processes",
              "bulk-exfiltration-stacking"
            ],
            "status": "covered"
          },
          {
            "stage": "impact-ransomware-encryption",
            "steps": [
              "identify-suspect-processes",
              "shadow-copy-removal"
            ],
            "status": "covered"
          },
          {
            "stage": "initial-access-seo-redirection",
            "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "execution-dll-side-loading",
            "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "c2-establishment-adaptix",
            "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "internal-discovery-and-persistence",
            "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "lateral-movement-tunneling",
            "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "credential-access-harvesting",
            "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary is exfiltrating bulk data via SFTP using FileZilla and executing Akira ransomware, evidenced by massive outbound network transfers and the destruction of Volume Shadow Copies.",
        "blind_spots": [
          {
            "id": "missing-byte-counters",
            "risk": "Without byte counters, we can see the connection to the Ukrainian destination but cannot confirm the magnitude of the data breach.",
            "stage": "data-exfiltration-sftp",
            "question": "Was 75GB of data actually exfiltrated?",
            "requires": "hb_network_connection with traffic_bytes from flow logs"
          },
          {
            "id": "api-shadow-deletion",
            "risk": "Advanced ransomware using direct API calls (e.g., IVssBackupComponents) to delete shadows will bypass process command-line monitoring.",
            "stage": "impact-ransomware-encryption",
            "question": "Was shadow deletion performed without using the command line?",
            "requires": "Endpoint monitoring for COM/WMI API calls"
          }
        ],
        "scoping_notes": "Focus the hunt on file servers, domain controllers, and backup infrastructure (e.g., Veeam servers), as these were specifically targeted for bulk data theft and encryption in this scenario.",
        "beyond_detection": "A single rule might alert on vssadmin usage, but this hunt pivots between original binary names, rare destination stacking, and network volume across three different telemetry surfaces to distinguish a ransomware incident from administrative maintenance."
      }
    },
    {
      "id": "identify-suspect-processes",
      "type": "query",
      "label": "Identify Suspect Processes",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_original_file_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{exfil_tools}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0 OR instr(',' || '{{ransomware_binaries}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Locate execution of the reported exfiltration tools or ransomware binaries by matching original file names to bypass renaming evasion.",
        "expected_signal": "A hit names the host and binary (e.g., locker.exe renamed or FileZilla). Silence suggests these specific binaries did not run in the lookback window."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify Suspect Processes",
        "reads": [
          "device_hostname",
          "process_name",
          "process_original_file_name",
          "process_cmd_line",
          "user_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_original_file_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{exfil_tools}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0 OR instr(',' || '{{ransomware_binaries}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "evidence_of_absence",
        "expected": "A hit names the host and binary (e.g., locker.exe renamed or FileZilla). Silence suggests these specific binaries did not run in the lookback window.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "bulk-exfiltration-stacking",
      "type": "query",
      "label": "Bulk Exfiltration Stacking",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "network",
        "content": "SELECT dst_endpoint_ip, dst_endpoint_port, COUNT(DISTINCT device_hostname) AS host_count, SUM(traffic_bytes) AS total_bytes, MIN(time) AS first_seen FROM hb_network_connection WHERE state_kind = 'log' AND traffic_bytes > 104857600 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_ip, dst_endpoint_port HAVING host_count < 3 ORDER BY total_bytes DESC",
        "surface": "hb_network_connection",
        "description": "Identify hosts pushing massive outbound volume (over 100MB) to destinations seen on very few hosts, characteristic of data theft.",
        "expected_signal": "One or two hosts pushing huge volume to a unique IP, especially on port 22 (SFTP). Benign noise includes backup servers; outliers represent potential exfiltration."
      },
      "parents": [
        {
          "id": "identify-suspect-processes"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Bulk Exfiltration Stacking",
        "reads": [
          "dst_endpoint_ip",
          "dst_endpoint_port",
          "device_hostname",
          "traffic_bytes",
          "time",
          "state_kind"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT dst_endpoint_ip, dst_endpoint_port, COUNT(DISTINCT device_hostname) AS host_count, SUM(traffic_bytes) AS total_bytes, MIN(time) AS first_seen FROM hb_network_connection WHERE state_kind = 'log' AND traffic_bytes > 104857600 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_ip, dst_endpoint_port HAVING host_count < 3 ORDER BY total_bytes DESC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "One or two hosts pushing huge volume to a unique IP, especially on port 22 (SFTP). Benign noise includes backup servers; outliers represent potential exfiltration.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "dst_endpoint_ip"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "shadow-copy-removal",
      "type": "query",
      "label": "Shadow Copy Removal",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, time FROM hb_process_activity WHERE (instr(',' || '{{impact_admin_tools}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || '{{impact_admin_tools}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND LOWER(process_cmd_line) LIKE '%shadow%' AND LOWER(process_cmd_line) LIKE '%delete%' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Detect the final precursor to ransomware impact: the deletion of Volume Shadow Copies using administrative tools.",
        "expected_signal": "Process rows showing tools like vssadmin or wmic used to delete shadows. This is a high-confidence indicator of ransomware preparation."
      },
      "parents": [
        {
          "id": "identify-suspect-processes"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Shadow Copy Removal",
        "reads": [
          "device_hostname",
          "process_name",
          "process_cmd_line",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, time FROM hb_process_activity WHERE (instr(',' || '{{impact_admin_tools}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || '{{impact_admin_tools}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND LOWER(process_cmd_line) LIKE '%shadow%' AND LOWER(process_cmd_line) LIKE '%delete%' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Process rows showing tools like vssadmin or wmic used to delete shadows. This is a high-confidence indicator of ransomware preparation.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "triage-final-stage",
      "type": "analytic",
      "label": "Triage Final Stage",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "network"
        ],
        "context": [
          "identify-suspect-processes",
          "bulk-exfiltration-stacking",
          "shadow-copy-removal"
        ],
        "objective": "Determine if the presence of suspect binaries (FileZilla/locker.exe), bulk outbound transfers, and shadow deletion together indicate an active ransomware intrusion.",
        "description": "Synthesize tool execution, bulk network flow, and backup destruction into a single maliciousness verdict per host.",
        "max_iterations": 4,
        "expected_signal": "A confirmed malicious verdict for hosts showing correlated exfiltration and ransomware activity.",
        "success_criteria": "A per-host verdict citing specific rows from process and network surfaces."
      },
      "parents": [
        {
          "id": "bulk-exfiltration-stacking",
          "kind": "merge"
        },
        {
          "id": "shadow-copy-removal",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-remediation",
      "type": "checkpoint",
      "label": "Route Remediation",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage verdict is malicious for at least one host based on correlated exfiltration and impact signals",
        "condition": "the triage verdict is malicious for at least one host based on correlated exfiltration and impact signals",
        "blind_spot": "missing-byte-counters",
        "confidence": "high",
        "description": "Direct the response based on the agent's triage results.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-final-stage"
        }
      ]
    },
    {
      "id": "isolate-affected-host",
      "type": "action",
      "label": "Isolate Affected Host",
      "config": {
        "target": "endpoint",
        "description": "Prevent the spread of encryption and stop ongoing data exfiltration.",
        "instructions": "Isolate the host immediately. Revoke all active sessions for users observed executing exfiltration tools or the ransomware binary.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-remediation",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-impact-review",
      "type": "task",
      "label": "Analyst Impact Review",
      "config": {
        "assignee": "analyst",
        "description": "Confirm the scope of data theft and the progress of encryption.",
        "instructions": "Verify the destination IP in the Ukraine IP space; check the host for the .akira extension on critical file shares and backup drives."
      },
      "parents": [
        {
          "id": "route-remediation",
          "branch": "default"
        },
        {
          "id": "route-remediation",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-affected-host"
        }
      ]
    },
    {
      "id": "close-out-hunt",
      "type": "task",
      "label": "Hunt Close-out",
      "config": {
        "assignee": "analyst",
        "description": "Document findings and transition to incident response if required.",
        "instructions": "Record the total bytes exfiltrated per host. If no activity was found, ensure the exfiltration tools are included in software restriction policies."
      },
      "parents": [
        {
          "id": "route-remediation",
          "branch": "on_refutes"
        },
        {
          "id": "analyst-impact-review"
        }
      ]
    }
  ]
}