{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "APT28 has demonstrated a decade of persistence in weaponizing zero-day and unpatched vulnerabilities for credential theft and privilege escalation. Identifying active exploitation through behaviour is required to catch intrusions that occur between patching cycles."
      },
      "name": "APT28: Outlook and Print Spooler Exploitation",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1190",
        "attack.t1566",
        "attack.t1555",
        "attack.t1041"
      ],
      "series": {
        "slug": "apt28-an-evolution-of-tradecraft-from-x-agent-to-llm-malware",
        "index": 1,
        "title": "APT28: An Evolution of Tradecraft from X-Agent to LLM Malware",
        "total": 2
      },
      "related": [
        {
          "hunt": "apt28-edge-device-hijacking",
          "reason": "Edge device hijacking (MooBot/FrostArmada) targets router infrastructure rather than endpoint software and is handled in a separate hunt.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "network": {
          "name": "Network telemetry",
          "category": "network",
          "telemetry": [
            "network"
          ]
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A standard rule fires on a known CVE or a static IP; this hunt correlates the presence of unpatched vulnerabilities with behavioural anomalies (rare process children, outbound SMB) across multiple telemetry surfaces, providing context a single rule cannot provide.",
      "coverage": [
        {
          "stage": "initial-access-phishing-and-vulnerability-exploitation",
          "steps": [
            "lead-vulnerability-check",
            "ukr-net-phishing-lookups"
          ],
          "status": "covered"
        },
        {
          "stage": "privilege-escalation-gooseegg",
          "steps": [
            "spooler-privesc-baseline"
          ],
          "status": "covered"
        },
        {
          "stage": "credential-harvesting-ntlm-relay",
          "steps": [
            "outbound-smb-relay"
          ],
          "status": "covered"
        },
        {
          "stage": "c2-edge-device-hijacking",
          "reason": "Belongs to another part of the 'APT28: An Evolution of Tradecraft from X-Agent to LLM Malware' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "exfiltration-llm-infostealer",
          "reason": "Belongs to another part of the 'APT28: An Evolution of Tradecraft from X-Agent to LLM Malware' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Initial Access via Phishing and Vulnerabilities",
            "slug": "initial-access-phishing-and-vulnerability-exploitation",
            "tactic": "initial-access",
            "techniques": [
              "T1566",
              "T1190"
            ],
            "observables": [
              "CVE-2023-23397 (Outlook)",
              "CVE-2022-38028 (Windows Print Spooler)",
              "SedKit exploit kit",
              "Spear phishing emails",
              "UKR.NET phishing landing pages"
            ]
          },
          {
            "name": "Privilege Escalation via GooseEgg",
            "slug": "privilege-escalation-gooseegg",
            "tactic": "execution",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "GooseEgg utility",
              "Windows Print Spooler service exploitation",
              "SYSTEM-level execution"
            ]
          },
          {
            "name": "Net-NTLMv2 Hash Harvesting",
            "slug": "credential-harvesting-ntlm-relay",
            "tactic": "credential-access",
            "techniques": [
              "T1555"
            ],
            "observables": [
              "Net-NTLMv2 hashes",
              "Authentication to attacker-controlled SMB shares",
              "Crafted Outlook reminders",
              "Spoofed UKR.NET webmail portal"
            ]
          },
          {
            "name": "Infrastructure Hijacking on Edge Devices",
            "slug": "c2-edge-device-hijacking",
            "tactic": "command-and-control",
            "techniques": [
              "T1572"
            ],
            "observables": [
              "MooBot botnet",
              "FrostArmada campaign",
              "Ubiquiti EdgeRouters",
              "MikroTik and TP-Link routers",
              "Rewritten DNS/DHCP settings pointing to actor-controlled resolvers",
              "X-Tunnel network pivot"
            ]
          },
          {
            "name": "LLM-Integrated Data Exfiltration",
            "slug": "exfiltration-llm-infostealer",
            "tactic": "exfiltration",
            "techniques": [
              "T1041"
            ],
            "observables": [
              "LLM-integrated infostealer",
              "Harvesting Office, PDF, and TXT documents",
              "Commands generated by legitimate AI services"
            ]
          }
        ],
        "summary": "APT28 (Fancy Bear) has transitioned from a decade-long reliance on a stable in-house implant suite like X-Agent to a highly fragmented, disposable toolkit and extensive infrastructure hijacking. The actor currently weaponizes edge devices such as Ubiquiti and MikroTik routers for proxying traffic and harvesting credentials, while integrating LLM-driven malware for automated document exfiltration."
      },
      "severity": "high",
      "rationale": "The hunt should prioritize endpoints that are identified as vulnerable to the target CVEs. If vulnerability scanning coverage is incomplete, widen the scope to all Windows workstations and servers during the deep-dive phase.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary is exploiting unpatched Outlook or Print Spooler vulnerabilities to harvest NTLM credentials or escalate privileges, evidenced by outbound SMB connections to external IPs and rare child processes launched by the spooler service.",
      "parameters": {
        "scope_hosts": {
          "from": {
            "ref": "scoping-input",
            "kind": "manual",
            "observed": "2026-06-22"
          },
          "type": "list[host]",
          "default": [],
          "description": "Hostnames identified in the scoping step to focus the behavioural search."
        },
        "target_cves": {
          "from": {
            "ref": "sekoia-apt28-evolution",
            "kind": "article",
            "observed": "2026-06-22"
          },
          "type": "list[string]",
          "default": [
            "CVE-2023-23397",
            "CVE-2022-38028"
          ],
          "description": "CVE identifiers targeted by APT28 for initial access and privilege escalation."
        },
        "lookback_days": {
          "from": {
            "ref": "standard-retention",
            "kind": "manual",
            "observed": "2026-06-22"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "ukr_net_domain": {
          "from": {
            "ref": "sekoia-apt28-evolution",
            "kind": "article",
            "observed": "2026-06-22"
          },
          "type": "list[domain]",
          "default": [
            "ukr.net"
          ],
          "description": "The phishing target domain spoofed in APT28 campaigns."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.sekoia.com/blog/apt28-an-evolution-of-tradecraft",
          "gates": [
            "dry-run",
            "lint",
            "critic"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.sekoia.com/blog/apt28-an-evolution-of-tradecraft",
          "name": "Sekoia \u2014 APT28: An Evolution of Tradecraft"
        }
      ],
      "blind_spots": [
        {
          "id": "vulnerability-inventory-gap",
          "risk": "An unmanaged host could be exploited without being caught in the lead query.",
          "owner": "Vulnerability Management Team",
          "stage": "initial-access-phishing-and-vulnerability-exploitation",
          "question": "Are there vulnerable hosts not currently reporting to the vulnerability scanner?",
          "requires": "Comprehensive hb_vulnerability_finding coverage",
          "remediation": "Audit the overlap between hb_devices and hb_vulnerability_finding to identify missing assets."
        },
        {
          "id": "network-outbound-visibility",
          "risk": "Exfiltration or hash relay attempts using SMB could be missed if host-based network logging is disabled.",
          "owner": "Network Security Team",
          "stage": "credential-harvesting-ntlm-relay",
          "question": "Can we see outbound SMB traffic from every network segment?",
          "requires": "hb_network_connection with port 445 logging",
          "remediation": "Ensure outbound SMB traffic is logged and alert on external port 445 connections."
        },
        {
          "id": "no-agent-coverage",
          "risk": "Privilege escalation via GooseEgg on a host without an agent would leave no behavioural trace.",
          "owner": "Endpoint Engineering",
          "stage": "privilege-escalation-gooseegg",
          "question": "Do we have process telemetry for the entire Windows estate?",
          "requires": "Endpoint agent on all Windows systems",
          "remediation": "Deploy agents to all Windows servers and workstations."
        }
      ]
    },
    "name": "APT28: Outlook and Print Spooler Exploitation",
    "description": "This hunt targets the endpoint-resident tradecraft of APT28, specifically focusing on the exploitation of CVE-2023-23397 (Outlook) and CVE-2022-38028 (Print Spooler). The hunt begins with a low-cost lead query to identify vulnerable hosts. If found, it triggers an expensive fan-out to search for active indicators: Net-NTLMv2 hash harvesting via forced SMB authentication, the GooseEgg privilege escalation utility, and lookups for known phishing domains. By correlating vulnerability state with behavioural indicators like rare spooler child processes and outbound SMB traffic, the hunt identifies active intrusions that standard signature-based rules may miss."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "apt28-an-evolution-of-tradecraft-from-x-agent-to-llm-malware",
          "index": 1,
          "title": "APT28: An Evolution of Tradecraft from X-Agent to LLM Malware",
          "total": 2
        },
        "coverage": [
          {
            "stage": "initial-access-phishing-and-vulnerability-exploitation",
            "steps": [
              "lead-vulnerability-check",
              "ukr-net-phishing-lookups"
            ],
            "status": "covered"
          },
          {
            "stage": "privilege-escalation-gooseegg",
            "steps": [
              "spooler-privesc-baseline"
            ],
            "status": "covered"
          },
          {
            "stage": "credential-harvesting-ntlm-relay",
            "steps": [
              "outbound-smb-relay"
            ],
            "status": "covered"
          },
          {
            "stage": "c2-edge-device-hijacking",
            "reason": "Belongs to another part of the 'APT28: An Evolution of Tradecraft from X-Agent to LLM Malware' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "exfiltration-llm-infostealer",
            "reason": "Belongs to another part of the 'APT28: An Evolution of Tradecraft from X-Agent to LLM Malware' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary is exploiting unpatched Outlook or Print Spooler vulnerabilities to harvest NTLM credentials or escalate privileges, evidenced by outbound SMB connections to external IPs and rare child processes launched by the spooler service.",
        "blind_spots": [
          {
            "id": "vulnerability-inventory-gap",
            "risk": "An unmanaged host could be exploited without being caught in the lead query.",
            "owner": "Vulnerability Management Team",
            "stage": "initial-access-phishing-and-vulnerability-exploitation",
            "question": "Are there vulnerable hosts not currently reporting to the vulnerability scanner?",
            "requires": "Comprehensive hb_vulnerability_finding coverage",
            "remediation": "Audit the overlap between hb_devices and hb_vulnerability_finding to identify missing assets."
          },
          {
            "id": "network-outbound-visibility",
            "risk": "Exfiltration or hash relay attempts using SMB could be missed if host-based network logging is disabled.",
            "owner": "Network Security Team",
            "stage": "credential-harvesting-ntlm-relay",
            "question": "Can we see outbound SMB traffic from every network segment?",
            "requires": "hb_network_connection with port 445 logging",
            "remediation": "Ensure outbound SMB traffic is logged and alert on external port 445 connections."
          },
          {
            "id": "no-agent-coverage",
            "risk": "Privilege escalation via GooseEgg on a host without an agent would leave no behavioural trace.",
            "owner": "Endpoint Engineering",
            "stage": "privilege-escalation-gooseegg",
            "question": "Do we have process telemetry for the entire Windows estate?",
            "requires": "Endpoint agent on all Windows systems",
            "remediation": "Deploy agents to all Windows servers and workstations."
          }
        ],
        "scoping_notes": "The hunt should prioritize endpoints that are identified as vulnerable to the target CVEs. If vulnerability scanning coverage is incomplete, widen the scope to all Windows workstations and servers during the deep-dive phase.",
        "beyond_detection": "A standard rule fires on a known CVE or a static IP; this hunt correlates the presence of unpatched vulnerabilities with behavioural anomalies (rare process children, outbound SMB) across multiple telemetry surfaces, providing context a single rule cannot provide."
      }
    },
    {
      "id": "lead-vulnerability-check",
      "type": "query",
      "label": "Identify vulnerable hosts",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_uid, cve_uid, severity, affected_package_name, affected_package_version FROM hb_vulnerability_finding WHERE instr(',' || '{{target_cves}}' || ',', ',' || cve_uid || ',') > 0",
        "surface": "hb_vulnerability_finding",
        "description": "Identify endpoints that are vulnerable to the specific CVEs APT28 is known to weaponize.",
        "expected_signal": "A list of device UIDs that remain unpatched. Zero rows prove the estate is patched against these specific flaws."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify vulnerable hosts",
        "reads": [
          "affected_package_name",
          "affected_package_version",
          "cve_uid",
          "device_uid",
          "severity"
        ],
        "source": "hb_vulnerability_finding",
        "target": "endpoint",
        "content": "SELECT device_uid, cve_uid, severity, affected_package_name, affected_package_version FROM hb_vulnerability_finding WHERE instr(',' || '{{target_cves}}' || ',', ',' || cve_uid || ',') > 0",
        "silence": "evidence_of_absence",
        "expected": "A list of device UIDs that remain unpatched. Zero rows prove the estate is patched against these specific flaws.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "agent-lead-assessment",
      "type": "analytic",
      "label": "Assess vulnerability lead",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "network"
        ],
        "context": [
          "lead-vulnerability-check"
        ],
        "objective": "Review the vulnerability findings and decide if the environment is exposed enough to continue the hunt for exploitation.",
        "description": "Determine if the vulnerability findings warrant a deep dive into behavioural logs.",
        "max_iterations": 3,
        "expected_signal": "A verdict on whether to proceed based on the presence and count of vulnerable hosts.",
        "success_criteria": "A recommendation to either start the deep dive or close the hunt."
      },
      "parents": [
        {
          "id": "lead-vulnerability-check"
        }
      ]
    },
    {
      "id": "gate-on-vulnerability",
      "type": "checkpoint",
      "label": "Gate on vulnerability presence",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the lead assessment confirms that at least one host is unpatched for the target CVEs",
        "condition": "the lead assessment confirms that at least one host is unpatched for the target CVEs",
        "blind_spot": "vulnerability-inventory-gap",
        "confidence": "high",
        "description": "Route the hunt to the expensive behavioural queries only if vulnerable hosts are confirmed.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "agent-lead-assessment"
        }
      ]
    },
    {
      "id": "outbound-smb-relay",
      "type": "query",
      "label": "Outbound SMB connections from endpoints",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "network",
        "content": "SELECT device_hostname, process_name, dst_endpoint_ip, dst_endpoint_port, time FROM hb_network_connection WHERE dst_endpoint_port = 445 AND direction = 'outbound' AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)",
        "surface": "hb_network_connection",
        "description": "Detect potential NTLM hash harvesting triggered by Outlook reminder exploitation.",
        "expected_signal": "Network connections to port 445 on external IP addresses; silence proves no unauthenticated SMB traffic left the scope."
      },
      "parents": [
        {
          "id": "gate-on-vulnerability",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Outbound SMB connections from endpoints",
        "reads": [
          "device_hostname",
          "direction",
          "dst_endpoint_ip",
          "dst_endpoint_port",
          "process_name",
          "time"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT device_hostname, process_name, dst_endpoint_ip, dst_endpoint_port, time FROM hb_network_connection WHERE dst_endpoint_port = 445 AND direction = 'outbound' AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)",
        "silence": "not_evidence_of_absence",
        "expected": "Network connections to port 445 on external IP addresses; silence proves no unauthenticated SMB traffic left the scope.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "spooler-privesc-baseline",
      "type": "query",
      "label": "Rare child processes of Print Spooler",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT LOWER(process_name) AS proc, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_process_activity WHERE LOWER(parent_process_name) LIKE '%spoolsv.exe' AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY proc HAVING host_count <= 3 ORDER BY host_count ASC",
        "surface": "hb_process_activity",
        "description": "Detect the use of GooseEgg by identifying anomalous children of the Spooler service.",
        "expected_signal": "Rare processes launched by spoolsv.exe; fleet-wide printing utilities will be filtered by the HAVING clause."
      },
      "parents": [
        {
          "id": "gate-on-vulnerability",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Rare child processes of Print Spooler",
        "reads": [
          "device_hostname",
          "parent_process_name",
          "process_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT LOWER(process_name) AS proc, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_process_activity WHERE LOWER(parent_process_name) LIKE '%spoolsv.exe' AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY proc HAVING host_count <= 3 ORDER BY host_count ASC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Rare processes launched by spoolsv.exe; fleet-wide printing utilities will be filtered by the HAVING clause.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_name"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "ukr-net-phishing-lookups",
      "type": "query",
      "label": "Lookups for ukr.net phishing indicators",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, query_hostname, time FROM hb_dns_activity WHERE instr(',' || '{{ukr_net_domain}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)",
        "surface": "hb_dns_activity",
        "description": "Identify activity related to the spoofed webmail portal used in recent campaigns.",
        "expected_signal": "Any resolution of the targeted phishing domain on an endpoint."
      },
      "parents": [
        {
          "id": "gate-on-vulnerability",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Lookups for ukr.net phishing indicators",
        "reads": [
          "device_hostname",
          "process_name",
          "query_hostname",
          "time"
        ],
        "source": "hb_dns_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, query_hostname, time FROM hb_dns_activity WHERE instr(',' || '{{ukr_net_domain}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)",
        "silence": "not_evidence_of_absence",
        "expected": "Any resolution of the targeted phishing domain on an endpoint.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "agent-triage-results",
      "type": "analytic",
      "label": "Synthesize exploitation evidence",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "network"
        ],
        "context": [
          "agent-lead-assessment",
          "outbound-smb-relay",
          "spooler-privesc-baseline",
          "ukr-net-phishing-lookups"
        ],
        "objective": "Determine if any host is exhibiting signs of active APT28 exploitation, such as GooseEgg execution or NTLM relay activity, and weight the risk for each host.",
        "description": "Correlate the vulnerability findings with the network and process indicators to confirm exploitation.",
        "max_iterations": 6,
        "expected_signal": "A detailed analysis linking the vulnerable hosts to suspicious behavioural hits.",
        "success_criteria": "A per-host verdict of compromised, suspicious, or benign with supporting citations."
      },
      "parents": [
        {
          "id": "outbound-smb-relay",
          "kind": "merge"
        },
        {
          "id": "spooler-privesc-baseline",
          "kind": "merge"
        },
        {
          "id": "ukr-net-phishing-lookups",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "decision-route-verdict",
      "type": "checkpoint",
      "label": "Route based on triage verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage verdict identifies at least one compromised host with active exploitation indicators",
        "condition": "the triage verdict identifies at least one compromised host with active exploitation indicators",
        "blind_spot": "no-agent-coverage",
        "confidence": "high",
        "description": "Initiate response for confirmed compromises or refer ambiguous cases to an analyst.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "agent-triage-results"
        }
      ]
    },
    {
      "id": "action-isolate-host",
      "type": "action",
      "label": "Isolate compromised host",
      "config": {
        "target": "endpoint",
        "description": "Contain the threat and prevent further lateral movement or credential abuse.",
        "instructions": "Isolate the host immediately. Revoke all active sessions for the user account identified in the triage.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "decision-route-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "task-manual-review",
      "type": "task",
      "label": "Manual analyst review",
      "config": {
        "assignee": "analyst",
        "description": "Verify the findings and perform deeper forensic analysis.",
        "instructions": "Review the cited rows. Inspect the host for the presence of the GooseEgg utility or unusual SMB client activity. Check for Net-NTLMv2 hash relay attempts in identity provider logs."
      },
      "parents": [
        {
          "id": "gate-on-vulnerability",
          "branch": "default"
        },
        {
          "id": "gate-on-vulnerability",
          "branch": "on_unavailable"
        },
        {
          "id": "decision-route-verdict",
          "branch": "default"
        },
        {
          "id": "decision-route-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "decision-route-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "action-isolate-host"
        }
      ]
    },
    {
      "id": "task-close-out",
      "type": "task",
      "label": "Close out hunt",
      "config": {
        "assignee": "analyst",
        "description": "Finalize the hunt and record the state of the estate.",
        "instructions": "Document the vulnerable vs patched state of the estate. Recommend a standing rule for rare spoolsv.exe children if successful."
      },
      "parents": [
        {
          "id": "gate-on-vulnerability",
          "branch": "on_refutes"
        },
        {
          "id": "task-manual-review"
        }
      ]
    }
  ]
}