{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Browser-based script injection and persistence bypass traditional OS security controls and directly threaten financial assets; confirming the integrity of the user's web interaction surface is essential."
      },
      "name": "ClickFix Browser Injection and Extension Persistence",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1566",
        "attack.t1059.001",
        "attack.t1176",
        "attack.t1115"
      ],
      "series": {
        "slug": "clickfix-moves-into-the-browser-cryptocurrency-theft-with-google-hosted-c2",
        "index": 1,
        "title": "ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2",
        "total": 2
      },
      "related": [
        {
          "hunt": "google-visualization-api-c2",
          "reason": "The C2 hunt focuses on broader network patterns of Gviz abuse, while this hunt focuses on the user-assisted injection and extension persistence scenario.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A standard rule might fire on the gviz string, but a hunt is required to follow the chain from an HTTP lure to manual injection and finally to persistence in an extension. This hunt correlates software inventory, HTTP, script blocks, file activity, and process prevalence to confirm an intrusion.",
      "coverage": [
        {
          "stage": "social-engineering-lure-delivery",
          "steps": [
            "lure-delivery-http"
          ],
          "status": "covered"
        },
        {
          "stage": "user-assisted-script-injection",
          "steps": [
            "loader-execution-scripts"
          ],
          "status": "covered"
        },
        {
          "stage": "browser-extension-persistence",
          "steps": [
            "scoping-tampermonkey",
            "persistence-tampermonkey-files"
          ],
          "status": "covered"
        },
        {
          "stage": "cryptocurrency-theft-and-skimming",
          "steps": [
            "collection-clipboard-skimmer"
          ],
          "status": "covered"
        },
        {
          "stage": "google-visualization-api-c2",
          "reason": "Belongs to another part of the 'ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Social Engineering Lure Delivery",
            "slug": "social-engineering-lure-delivery",
            "tactic": "initial-access",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "Telegram channel posts",
              "DarkForums posts",
              "paste.sh links",
              "Google Docs filename: 'API Logic Flaw'",
              "Google Docs URL: docs.google.com/document/d/"
            ]
          },
          {
            "name": "User-Assisted Script Injection",
            "slug": "user-assisted-script-injection",
            "tactic": "execution",
            "techniques": [
              "T1059.001"
            ],
            "observables": [
              "javascript: protocol used in Chrome navigation bar",
              "Pasting obfuscated JS from paste.sh",
              "Base64 encoded strings in browser memory",
              "Injection into DOM <script> elements"
            ]
          },
          {
            "name": "Browser Extension Persistence",
            "slug": "browser-extension-persistence",
            "tactic": "persistence",
            "techniques": [
              "T1176"
            ],
            "observables": [
              "Tampermonkey extension installation",
              "Malicious loader script in Tampermonkey configuration",
              "Scripts targeting simpleswap.io or swapzone.io"
            ]
          },
          {
            "name": "Google Visualization API C2",
            "slug": "google-visualization-api-c2",
            "tactic": "command-and-control",
            "techniques": [
              "T1071"
            ],
            "observables": [
              "docs.google.com/spreadsheets/d/*/gviz/tq",
              "Visualization API queries: SELECT B, SELECT A",
              "JSON formatted data returned from Google Sheets",
              "Appended data via HTML POST to Google Forms"
            ]
          },
          {
            "name": "Cryptocurrency Theft and Skimming",
            "slug": "cryptocurrency-theft-and-skimming",
            "tactic": "collection",
            "techniques": [
              "T1115"
            ],
            "observables": [
              "Hooking browser fetch API",
              "Replacing cryptocurrency deposit addresses in server responses",
              "Replacing user clipboard content",
              "Displaying counterfeit 'bonus' UI elements"
            ]
          }
        ],
        "summary": "Actors lure cryptocurrency traders via Telegram and dark web forums to 'exploit' non-existent API flaws using a variation of ClickFix social engineering. Victims are tricked into manually injecting malicious JavaScript into their browsers or the Tampermonkey extension, which establishes persistence and uses the Google Visualization API to fetch second-stage skimmers from public Google Sheets to steal cryptocurrency by hijacking the clipboard."
      },
      "severity": "medium",
      "rationale": "Focus on endpoints with Tampermonkey installed first. Prioritize users with known access to financial or cryptocurrency domains.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An intruder has used a social engineering lure to trick a user into manually injecting a JavaScript loader or installing a malicious Tampermonkey script that facilitates persistent cryptocurrency theft via the Google Visualization API.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Narrow the hunt to specific hosts; leave empty to scan the entire estate."
        },
        "lure_domains": {
          "from": {
            "ref": "talos-clickfix-2026",
            "kind": "article",
            "observed": "2026-09-08"
          },
          "type": "list[domain]",
          "default": [
            "paste.sh",
            "docs.google.com"
          ],
          "description": "Domains used to host lures and first-stage loader scripts."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "lure_path_patterns": {
          "from": {
            "ref": "talos-clickfix-2026",
            "kind": "article",
            "observed": "2026-09-08"
          },
          "type": "list[string]",
          "default": [
            "/document/d/",
            "/spreadsheets/d/"
          ],
          "description": "Specific URL path patterns or fragments found in social engineering lures."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://blog.talosintelligence.com/clickfix-moves-into-the-browser/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://blog.talosintelligence.com/clickfix-moves-into-the-browser/",
          "name": "Cisco Talos \u2014 ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2"
        }
      ],
      "blind_spots": [
        {
          "id": "browser-memory-blind-spot",
          "risk": "A user-injected script that does not trigger persistence may execute entirely in-memory and be invisible to script surfaces.",
          "stage": "user-assisted-script-injection",
          "question": "Was the script injected only into memory via the navigation bar without triggering script-block logging?",
          "requires": "Browser-internal instrumentation"
        },
        {
          "id": "encrypted-extension-data",
          "risk": "The hunt can see file writes to extension folders, but cannot read the script text inside extension-managed IndexedDB or storage files without forensic tooling.",
          "stage": "browser-extension-persistence",
          "question": "What is the content of the scripts stored inside Tampermonkey's private database?",
          "requires": "Extension-specific database parsing"
        }
      ]
    },
    "name": "ClickFix Browser Injection and Extension Persistence",
    "description": "This hunt identifies ClickFix campaigns targeting browser sessions rather than the operating system. It identifies the delivery of social engineering lures via Google Docs and the subsequent persistence through the Tampermonkey extension. The hunt follows a phased flow: first scoping for the extension, then identifying initial delivery and execution signals, and finally corroborating with file-based persistence and behavioral indicators of cryptocurrency skimming like rare clipboard manipulation."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "clickfix-moves-into-the-browser-cryptocurrency-theft-with-google-hosted-c2",
          "index": 1,
          "title": "ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2",
          "total": 2
        },
        "coverage": [
          {
            "stage": "social-engineering-lure-delivery",
            "steps": [
              "lure-delivery-http"
            ],
            "status": "covered"
          },
          {
            "stage": "user-assisted-script-injection",
            "steps": [
              "loader-execution-scripts"
            ],
            "status": "covered"
          },
          {
            "stage": "browser-extension-persistence",
            "steps": [
              "scoping-tampermonkey",
              "persistence-tampermonkey-files"
            ],
            "status": "covered"
          },
          {
            "stage": "cryptocurrency-theft-and-skimming",
            "steps": [
              "collection-clipboard-skimmer"
            ],
            "status": "covered"
          },
          {
            "stage": "google-visualization-api-c2",
            "reason": "Belongs to another part of the 'ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An intruder has used a social engineering lure to trick a user into manually injecting a JavaScript loader or installing a malicious Tampermonkey script that facilitates persistent cryptocurrency theft via the Google Visualization API.",
        "blind_spots": [
          {
            "id": "browser-memory-blind-spot",
            "risk": "A user-injected script that does not trigger persistence may execute entirely in-memory and be invisible to script surfaces.",
            "stage": "user-assisted-script-injection",
            "question": "Was the script injected only into memory via the navigation bar without triggering script-block logging?",
            "requires": "Browser-internal instrumentation"
          },
          {
            "id": "encrypted-extension-data",
            "risk": "The hunt can see file writes to extension folders, but cannot read the script text inside extension-managed IndexedDB or storage files without forensic tooling.",
            "stage": "browser-extension-persistence",
            "question": "What is the content of the scripts stored inside Tampermonkey's private database?",
            "requires": "Extension-specific database parsing"
          }
        ],
        "scoping_notes": "Focus on endpoints with Tampermonkey installed first. Prioritize users with known access to financial or cryptocurrency domains.",
        "beyond_detection": "A standard rule might fire on the gviz string, but a hunt is required to follow the chain from an HTTP lure to manual injection and finally to persistence in an extension. This hunt correlates software inventory, HTTP, script blocks, file activity, and process prevalence to confirm an intrusion."
      }
    },
    {
      "id": "scoping-tampermonkey",
      "type": "query",
      "label": "Scope hosts with Tampermonkey installed",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_hostname, package_name, package_version, package_uid FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%tampermonkey%' OR package_uid = 'dhdgffkkebhmkfjojejmpbldmpobfkfo') AND asset_scope = 'endpoint'",
        "surface": "hb_software_inventory",
        "description": "Identify hosts where the Tampermonkey extension is present, as it is the campaign's primary method for script persistence.",
        "expected_signal": "A list of hosts with the extension. Silence indicates low baseline risk for the persistence stage of this specific campaign."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Scope hosts with Tampermonkey installed",
        "reads": [
          "asset_scope",
          "device_hostname",
          "package_name",
          "package_uid",
          "package_version"
        ],
        "source": "hb_software_inventory",
        "target": "endpoint",
        "content": "SELECT device_hostname, package_name, package_version, package_uid FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%tampermonkey%' OR package_uid = 'dhdgffkkebhmkfjojejmpbldmpobfkfo') AND asset_scope = 'endpoint'",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hosts with the extension. Silence indicates low baseline risk for the persistence stage of this specific campaign.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "lure-delivery-http",
      "type": "query",
      "label": "HTTP traffic to lure domains",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "web",
        "content": "SELECT device_hostname, url_hostname, url_path, time FROM hb_http_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND instr(',' || '{{lure_domains}}' || ',', ',' || LOWER(url_hostname) || ',') > 0 AND (LOWER(url_path) LIKE '%/document/d/%' OR LOWER(url_path) LIKE '%/spreadsheets/d/%' OR instr(',' || '{{lure_path_patterns}}' || ',', ',' || LOWER(url_path) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_http_activity",
        "description": "Identify users accessing the Google Docs or Paste sites mentioned in the social engineering lures.",
        "expected_signal": "Hosts visiting the specific Google Docs or Paste.sh links. This provides the context for subsequent script execution."
      },
      "parents": [
        {
          "id": "scoping-tampermonkey"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "HTTP traffic to lure domains",
        "reads": [
          "device_hostname",
          "time",
          "url_hostname",
          "url_path"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT device_hostname, url_hostname, url_path, time FROM hb_http_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND instr(',' || '{{lure_domains}}' || ',', ',' || LOWER(url_hostname) || ',') > 0 AND (LOWER(url_path) LIKE '%/document/d/%' OR LOWER(url_path) LIKE '%/spreadsheets/d/%' OR instr(',' || '{{lure_path_patterns}}' || ',', ',' || LOWER(url_path) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Hosts visiting the specific Google Docs or Paste.sh links. This provides the context for subsequent script execution.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "loader-execution-scripts",
      "type": "query",
      "label": "Google Visualization API script execution",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, actor_user_name, script_content, time FROM hb_script_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(LOWER(script_content), 'gviz/tq') > 0 OR instr(LOWER(script_content), 'google.visualization') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_script_activity",
        "description": "Detect the execution of the first-stage loader script which uses the Gviz API for C2.",
        "expected_signal": "Script contents showing query construction against Google spreadsheets. This is the primary indicator of the ClickFix loader."
      },
      "parents": [
        {
          "id": "scoping-tampermonkey"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Google Visualization API script execution",
        "reads": [
          "actor_user_name",
          "device_hostname",
          "script_content",
          "time"
        ],
        "source": "hb_script_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, actor_user_name, script_content, time FROM hb_script_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(LOWER(script_content), 'gviz/tq') > 0 OR instr(LOWER(script_content), 'google.visualization') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Script contents showing query construction against Google spreadsheets. This is the primary indicator of the ClickFix loader.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "agent-early-triage",
      "type": "analytic",
      "label": "Triage early loader activity",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "web"
        ],
        "context": [
          "lure-delivery-http",
          "loader-execution-scripts"
        ],
        "objective": "Determine if any host has both accessed a lure domain and executed a script containing Gviz API patterns.",
        "description": "Synthesize the HTTP and script evidence to identify hosts that likely moved from lure access to loader execution.",
        "max_iterations": 3,
        "expected_signal": "A list of hosts where lure activity and script execution occurred in close temporal proximity.",
        "success_criteria": "A per-host verdict of suspicious or malicious citing the specific URL and script content."
      },
      "parents": [
        {
          "id": "lure-delivery-http",
          "kind": "merge"
        },
        {
          "id": "loader-execution-scripts",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "persistence-tampermonkey-files",
      "type": "query",
      "label": "Tampermonkey persistence files",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, file_path, file_name, time FROM hb_file_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND LOWER(file_path) LIKE '%tampermonkey%' AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_file_activity",
        "description": "Find file modifications in the Tampermonkey storage directory.",
        "expected_signal": "Writes to extension storage. This confirms the 'persistence' stage of the campaign."
      },
      "parents": [
        {
          "id": "agent-early-triage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Tampermonkey persistence files",
        "reads": [
          "device_hostname",
          "file_name",
          "file_path",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, file_path, file_name, time FROM hb_file_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND LOWER(file_path) LIKE '%tampermonkey%' AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Writes to extension storage. This confirms the 'persistence' stage of the campaign.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "collection-clipboard-skimmer",
      "type": "query",
      "label": "Rare clipboard manipulation",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT LOWER(process_cmd_line) AS cmd, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_name) LIKE '%clip.exe' OR LOWER(process_cmd_line) LIKE '%get-clipboard%' OR LOWER(process_cmd_line) LIKE '%set-clipboard%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY cmd HAVING hosts <= 3",
        "surface": "hb_process_activity",
        "description": "Detect the address-swapping behavior of the skimmer by identifying rare usage of clipboard interaction tools.",
        "expected_signal": "Low-prevalence clipboard manipulation. Fleet-wide admin scripts will be filtered out, leaving manual or malicious activity."
      },
      "parents": [
        {
          "id": "agent-early-triage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare clipboard manipulation",
        "reads": [
          "device_hostname",
          "process_cmd_line",
          "process_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT LOWER(process_cmd_line) AS cmd, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_name) LIKE '%clip.exe' OR LOWER(process_cmd_line) LIKE '%get-clipboard%' OR LOWER(process_cmd_line) LIKE '%set-clipboard%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY cmd HAVING hosts <= 3",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Low-prevalence clipboard manipulation. Fleet-wide admin scripts will be filtered out, leaving manual or malicious activity.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "cmd"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "agent-final-synthesis",
      "type": "analytic",
      "label": "Synthesize full attack chain",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "web"
        ],
        "context": [
          "agent-early-triage",
          "persistence-tampermonkey-files",
          "collection-clipboard-skimmer"
        ],
        "objective": "Confirm the presence of a persistent browser-based skimmer by correlating the early triage results with follow-on persistence and collection signals.",
        "description": "Final assessment to confirm hosts demonstrating the full path from delivery to collection.",
        "max_iterations": 5,
        "expected_signal": "Confirmed malicious verdicts for hosts where early loader signals correlate with persistent files or rare clipboard activity.",
        "success_criteria": "A final malicious verdict citing the specific gviz loader and the associated persistence or skimming activity."
      },
      "parents": [
        {
          "id": "persistence-tampermonkey-files",
          "kind": "merge"
        },
        {
          "id": "collection-clipboard-skimmer",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "infection-decision",
      "type": "checkpoint",
      "label": "Infection routing",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the agent-final-synthesis verdict is malicious for at least one host, citing gviz loader execution and either file persistence or skimmer activity",
        "condition": "the agent-final-synthesis verdict is malicious for at least one host, citing gviz loader execution and either file persistence or skimmer activity",
        "blind_spot": "browser-memory-blind-spot",
        "confidence": "high",
        "description": "Route results based on the agent's synthesis of the full attack chain.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "agent-final-synthesis"
        }
      ]
    },
    {
      "id": "action-contain-host",
      "type": "action",
      "label": "Isolate host and revoke sessions",
      "config": {
        "target": "endpoint",
        "description": "Prevent further financial loss and C2 communication by isolating the affected endpoint.",
        "instructions": "Isolate the host from the network. Inform the user of browser compromise and revoke active web sessions, specifically targeting crypto trading sites SimpleSwap and SwapZone.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "infection-decision",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "task-forensic-audit",
      "type": "task",
      "label": "Forensic extension audit",
      "config": {
        "assignee": "analyst",
        "description": "Analyst manual review of extension storage and browser profiles to extract the malicious script content and identify the C2 spreadsheet.",
        "instructions": "Audit the user's Chrome Profile. Inspect Tampermonkey's private storage (Local Extension Settings) for scripts targeting SimpleSwap or SwapZone. Extract any spreadsheet IDs from gviz URLs."
      },
      "parents": [
        {
          "id": "infection-decision",
          "branch": "default"
        },
        {
          "id": "infection-decision",
          "branch": "on_unavailable"
        },
        {
          "id": "action-contain-host"
        }
      ]
    },
    {
      "id": "task-close-out",
      "type": "task",
      "label": "Close out and document",
      "config": {
        "assignee": "analyst",
        "description": "Final documentation of findings and closure of the hunt.",
        "instructions": "Document the hosts examined. If malicious Tampermonkey scripts were found, contribute their signatures to detection engineering for a standing rule."
      },
      "parents": [
        {
          "id": "infection-decision",
          "branch": "on_refutes"
        },
        {
          "id": "task-forensic-audit"
        }
      ]
    }
  ]
}