← All hunts medium TLP:CLEAR Part 1 of 2

Cloud Identity and AI Agent Anomalies

An adversary has used social engineering or exploited public-facing remote services to compromise an administrative identity, then used that access to manipulate cloud repositories or orchestration layers via automated agents.

Based on research by Cisco Talos 2026-10-02 11 steps · 3 queries T1003.001 T1133 T1190 T1204.002

Brief

Why Now

Adversaries increasingly target the cloud control plane to redirect orchestration or inject malicious code into deployment pipelines. Cisco Talos describes these shifting tactics in their analysis, The Fine Art of Frustrating the Adversary. As organizations adopt more automated agents and complex container orchestration, the surface area for identity-based attacks grows. This hunt addresses the need to monitor how administrative identities interact with these layers.

How the Hunt Flows

The first phase scopes the environment by auditing successful logins to sensitive management interfaces. An analyst or an automated agent examines sign-ins to the Azure Portal, AWS Console, Okta, and Kubernetes API servers. This step looks for logins from unusual countries or those occurring without multi-factor authentication. If these leads appear anomalous, the hunt proceeds to behavioral analysis.

The second phase fans out to examine cloud API activity and network telemetry. The hunt identifies rare API operations related to EKS manipulation or repository creation. Simultaneously, it stack-counts network connections to orchestration management ports (like 6443 or 10250) and the cloud metadata service IP. By filtering for connections that appear on only one or two hosts, the hunt isolates non-standard pivots that deviate from fleet-wide administrative noise.

Finally, the hunt synthesizes these findings. An analyst correlates the suspicious login with the subsequent API and network behavior to confirm if the activity represents a legitimate automated process or an active intrusion. If the activity is malicious, the playbook provides instructions to revoke credentials and isolate the compromised identities.

Blind Spots

This hunt focuses on successful access. It does not see the precursor activity, such as password spraying or MFA fatigue attempts, that leads to the initial compromise. Additionally, because the network telemetry relies on endpoint agents, any traffic originating from unmanaged cloud instances to the metadata service or orchestration ports remains invisible. Full visibility into those pivots requires VPC flow logs.

In this series

Steps

  1. Suspicious logins to sensitive interfaces

    Query · scoping

    Identify successful sign-ins to critical services that manage the cloud or network perimeter as a lead for further investigation.

    reads hb_auth_signinsql
    SELECT actor_user_name, dst_endpoint_name, src_endpoint_ip, src_location_country, mfa, device_hostname, time FROM hb_auth_signin WHERE status_id = 1 AND (instr(',' || '{{sensitive_resources}}' || ',', ',' || LOWER(dst_endpoint_name) || ',') > 0 OR LOWER(dst_endpoint_name) LIKE '%kube%') AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Login events from unusual IPs or countries targeting sensitive infrastructure; the presence of these rows triggers the next read.

  2. Evaluate sign-in lead

    Agent triage

    Decide whether any of the identified logins are anomalous enough to warrant expensive behavioral analysis across the fleet.

  3. Gate: Proceed to behavioral analysis?

    Decision

    Route the hunt based on the agent assessment of the initial access lead to avoid unnecessary processing.

  4. Agentic Cloud API and Repository activity

    Query · triage

    Identify repository creation, EKS manipulation, or unusual data staging operations consistent with automated agents.

    reads hb_cloud_api_activitysql
    SELECT actor_user_name, api_operation, api_service_name, resource_name, src_endpoint_ip, time FROM hb_cloud_api_activity WHERE (LOWER(api_operation) LIKE '%repository%' OR LOWER(api_operation) LIKE '%putbucket%' OR LOWER(api_service_name) LIKE '%eks%' OR LOWER(api_service_name) LIKE '%kubernetes%') AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Unexpected writes to package registries or repository creation performed by the identities flagged in the lead query.

  5. Rare orchestration and metadata connections

    Query · baseline

    Stack-count network connections to management ports and the metadata service to find rare access from scoped hosts.

    reads hb_network_connectionsql
    SELECT dst_endpoint_ip, dst_endpoint_port, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_network_connection WHERE (dst_endpoint_ip = '{{metadata_ip}}' OR dst_endpoint_port IN (6443, 8443, 10250)) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_ip, dst_endpoint_port HAVING host_count <= 2 ORDER BY host_count ASC

    What a hit looks like. A connection to a Kubernetes management port or metadata service appearing on only one or two hosts, indicating non-standard activity.

  6. Synthesize and Triage

    Agent triage

    Correlate the initial login lead with the subsequent cloud API and network orchestration behavior to determine if an intrusion is occurring.

  7. Route on final triage

    Decision

    Direct the response based on the synthesis of all evidence.

  8. Revoke credentials and isolate

    Response action

    Halt the adversary's progress by revoking compromised sessions and isolating any active AI agent credentials.

  9. Analyst Review

    Analyst task

    Human review of the evidence to ensure tuning and valid containment.

  10. Close out

    Analyst task

    Standard wrap-up for non-malicious findings.

Coverage

Scenario coverage

StageCoveredHow, or why not
Phishing and Social Engineering
T1204.002
Yes suspicious-sensitive-logins, evaluate-login-lead
Exploitation of Public-Facing Apps
T1190 · T1133
Yes suspicious-sensitive-logins, rare-orchestration-connections
Agentic Malactivity and Discovery
T1190
Yes agentic-api-patterns
Persistence via RMM Software
T1133
Out of scope Belongs to another part of the 'The Fine Art of Frustrating the Adversary' series.
LSASS Credential Access
T1003.001
Out of scope Belongs to another part of the 'The Fine Art of Frustrating the Adversary' series.
Ransomware Encryption
T1486
Out of scope Belongs to another part of the 'The Fine Art of Frustrating the Adversary' series.

Blind spots

  • Needs hb_auth_signin with detailed logon types and MFA failure reasons. The lead query focuses on successful entry; the precursor brute-force activity may be invisible. It would answer whether the successful login was preceded by multiple MFA fatigue or password spray attempts.
  • Needs VPC flow logs for all cloud subnets. A network pivot from a host without an agent will not appear in hb_network_connection, leaving a blind spot for unmanaged compute. It would answer whether an unmanaged cloud instance accessed the metadata service.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
lookback_daysnumber14Days of history to examine.
metadata_ipip169.254.169.254Cloud Instance Metadata Service IP address.
scope_hostslist[host]—Paste the device_hostname values from the lead query here to narrow the second stage.
sensitive_resourceslist[string]kubernetes, vpn-gateway, admin-console, azure-portal, aws-console, oktaCritical resource names to monitor in sign-in logs.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint
Identity / sign-in telemetryidentityidentity
Network telemetrynetworknetwork

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: A standard detection rule might alert on any Kubernetes login, but this
  hunt uses a gated flow to correlate those logins with fleet-wide prevalence and
  rare behavioral pivots in the cloud control plane.
blind_spots:
- id: limited-identity-context
  question: whether the successful login was preceded by multiple MFA fatigue or password
    spray attempts
  requires: hb_auth_signin with detailed logon types and MFA failure reasons
  risk: The lead query focuses on successful entry; the precursor brute-force activity
    may be invisible.
  stage: initial-access-social-engineering
- id: metadata-visibility
  question: whether an unmanaged cloud instance accessed the metadata service
  requires: VPC flow logs for all cloud subnets
  risk: A network pivot from a host without an agent will not appear in hb_network_connection,
    leaving a blind spot for unmanaged compute.
  stage: exploitation-public-facing-apps
coverage:
- stage: initial-access-social-engineering
  status: covered
  steps:
  - suspicious-sensitive-logins
  - evaluate-login-lead
- stage: exploitation-public-facing-apps
  status: covered
  steps:
  - suspicious-sensitive-logins
  - rare-orchestration-connections
- stage: ai-agent-discovery-c2
  status: covered
  steps:
  - agentic-api-patterns
- reason: Belongs to another part of the 'The Fine Art of Frustrating the Adversary'
    series.
  stage: unauthorized-rmm-persistence
  status: out_of_scope
- reason: Belongs to another part of the 'The Fine Art of Frustrating the Adversary'
    series.
  stage: credential-harvesting-lsass
  status: out_of_scope
- reason: Belongs to another part of the 'The Fine Art of Frustrating the Adversary'
    series.
  stage: data-encrypted-for-impact
  status: out_of_scope
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: keep-as-periodic-hunt
  justification: Adversaries are targeting cloud control planes and using automated
    agents to manipulate infrastructure. Identifying anomalous logins followed by
    rare management port access provides effective detection for these advanced techniques.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An adversary has used social engineering or exploited public-facing remote
  services to compromise an administrative identity, then used that access to manipulate
  cloud repositories or orchestration layers via automated agents.
labels:
- hunt
- attack.t1133
- attack.t1190
- attack.t1204.002
- attack.t1003.001
- credential access
- discovery
- impact
- initial access
- persistence
name: Cloud Identity and AI Agent Anomalies
parameters:
  lookback_days:
    default: '14'
    description: Days of history to examine.
    type: number
  metadata_ip:
    default: 169.254.169.254
    description: Cloud Instance Metadata Service IP address.
    type: ip
  scope_hosts:
    default: []
    description: Paste the device_hostname values from the lead query here to narrow
      the second stage.
    type: list[host]
  sensitive_resources:
    default:
    - kubernetes
    - vpn-gateway
    - admin-console
    - azure-portal
    - aws-console
    - okta
    description: Critical resource names to monitor in sign-in logs.
    from:
      kind: manual
      observed: '2024-10-01'
      ref: architectural-critical-assets
    type: list[string]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://blog.talosintelligence.com/the-fine-art-of-frustrating-the-adversary/
    gates:
    - dry-run
    - lint
    - critic
    model: hb_google/gemini-3-flash-preview
rationale: Focus on administrative identities and service accounts used for automation.
  This hunt is particularly valuable in hybrid environments with high Kubernetes adoption.
references:
- name: "Cisco Talos \u2014 The Fine Art of Frustrating the Adversary"
  url: https://blog.talosintelligence.com/the-fine-art-of-frustrating-the-adversary/
related:
- hunt: unauthorized-rmm-persistence
  reason: Persistence through RMM tools uses endpoint process and file telemetry,
    which is handled in a separate hunt.
  relation: out-of-scope-alternative
scenario:
  stages:
  - name: Phishing and Social Engineering
    observables:
    - Lures sent from expired domains
    - Communication with fictional employee profiles
    - Urgency-based messaging (unpaid taxes, injured relatives)
    slug: initial-access-social-engineering
    tactic: initial-access
    techniques:
    - T1204.002
  - name: Exploitation of Public-Facing Apps
    observables:
    - Unauthorized sign-ins to critical servers
    - Connections to Kubernetes API servers
    - Access to exposed VPN gateways
    slug: exploitation-public-facing-apps
    tactic: initial-access
    techniques:
    - T1190
    - T1133
  - name: Persistence via RMM Software
    observables:
    - Zoho Unattended Agent
    - AnyDesk
    - ScreenConnect
    - Atera
    - Unauthorized remote technician sessions
    slug: unauthorized-rmm-persistence
    tactic: persistence
    techniques:
    - T1133
  - name: LSASS Credential Access
    observables:
    - Mimikatz
    - comsvcs.dll
    - procdump -ma lsass.exe
    - Direct access to LSASS memory
    slug: credential-harvesting-lsass
    tactic: credential-access
    techniques:
    - T1003.001
  - name: Agentic Malactivity and Discovery
    observables:
    - Unexpected writes to package registries
    - Repository creation and dataset commits
    - API calls to Kubernetes interfaces
    - DNS-over-HTTPS relays usage
    - Access to cloud metadata services
    slug: ai-agent-discovery-c2
    tactic: discovery
    techniques:
    - T1190
  - name: Ransomware Encryption
    observables:
    - Execution of ransomware encryptor
    - High-volume file modification / renaming
    slug: data-encrypted-for-impact
    tactic: impact
    techniques:
    - T1486
  summary: This scenario outlines the diverse set of adversary behaviors described
    by Cisco Talos, moving from initial access via social engineering or service exploitation
    to persistence using legitimate remote-management tools. It concludes with credential
    harvesting from LSASS memory, data encryption for impact, and emerging malicious
    activity from misconfigured AI agents targeting cloud infrastructure.
series:
  index: 1
  slug: the-fine-art-of-frustrating-the-adversary
  title: The Fine Art of Frustrating the Adversary
  total: 2
severity: medium
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  identity:
    category: identity
    name: Identity / sign-in telemetry
    telemetry:
    - identity
  network:
    category: network
    name: Network telemetry
    telemetry:
    - network
tlp: clear
type: investigation
---


# Cloud Identity and AI Agent Anomalies

This hunt identifies unauthorized access to critical cloud management interfaces and orchestration systems. It uses a gated flow, starting with a lightweight audit of logins to sensitive resources like Kubernetes API servers or VPN gateways. If the lead is suspicious, the hunt expands to examine rare cloud API operations and rare network connections to orchestration management ports, stack-counting these behaviors to separate manual or agentic intrusions from fleet-wide administrative noise.

## suspicious-sensitive-logins
<!-- Suspicious logins to sensitive interfaces -->
Identify successful sign-ins to critical services that manage the cloud or network perimeter as a lead for further investigation.

```sqlite target=identity role=scoping params=(lookback_days=lookback_days, sensitive_resources=sensitive_resources)
~~~yaml
expected: Login events from unusual IPs or countries targeting sensitive infrastructure;
  the presence of these rows triggers the next read.
reads:
- actor_user_name
- device_hostname
- dst_endpoint_name
- mfa
- src_endpoint_ip
- src_location_country
- status_id
- time
silence: not_evidence_of_absence
source: hb_auth_signin
verified: dry-run
verified_at: '2026-10-02'
~~~
SELECT actor_user_name, dst_endpoint_name, src_endpoint_ip, src_location_country, mfa, device_hostname, time FROM hb_auth_signin WHERE status_id = 1 AND (instr(',' || '{{sensitive_resources}}' || ',', ',' || LOWER(dst_endpoint_name) || ',') > 0 OR LOWER(dst_endpoint_name) LIKE '%kube%') AND time >= datetime('now', '-{{lookback_days}} days')
```

## evaluate-login-lead
<!-- Evaluate sign-in lead -->
```agent target=hunter
cite: required
context:
- suspicious-sensitive-logins
max_iterations: 3
objective: Determine if any sign-in to sensitive infrastructure shown in the lead
  query is anomalous based on source IP, geography, or lack of MFA.
success_criteria: A verdict of suspicious or benign for each identified session.
tools:
- endpoint
- identity
- network
```

## auth-gate
<!-- Gate: Proceed to behavioral analysis? -->
if~: "the login-lead verdict is suspicious for at least one session" (confidence: high, judge=hunter)
then: → behavioral-fan-out
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: limited-identity-context)
else: → close-out

## behavioral-fan-out
<!-- Fan-out to behavioral surfaces -->
parallel:
- → agentic-api-patterns
- → rare-orchestration-connections
join: → triage-synthesis

## agentic-api-patterns
<!-- Agentic Cloud API and Repository activity -->
Identify repository creation, EKS manipulation, or unusual data staging operations consistent with automated agents.

```sqlite target=endpoint role=triage params=(lookback_days=lookback_days)
~~~yaml
expected: Unexpected writes to package registries or repository creation performed
  by the identities flagged in the lead query.
reads:
- actor_user_name
- api_operation
- api_service_name
- resource_name
- src_endpoint_ip
- time
silence: not_evidence_of_absence
source: hb_cloud_api_activity
verified: dry-run
verified_at: '2026-10-02'
~~~
SELECT actor_user_name, api_operation, api_service_name, resource_name, src_endpoint_ip, time FROM hb_cloud_api_activity WHERE (LOWER(api_operation) LIKE '%repository%' OR LOWER(api_operation) LIKE '%putbucket%' OR LOWER(api_service_name) LIKE '%eks%' OR LOWER(api_service_name) LIKE '%kubernetes%') AND time >= datetime('now', '-{{lookback_days}} days')
```

## rare-orchestration-connections
<!-- Rare orchestration and metadata connections -->
Stack-count network connections to management ports and the metadata service to find rare access from scoped hosts.

```sqlite target=network role=baseline params=(lookback_days=lookback_days, metadata_ip=metadata_ip, scope_hosts=scope_hosts)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: A connection to a Kubernetes management port or metadata service appearing
  on only one or two hosts, indicating non-standard activity.
prevalence:
  by: device_hostname
  key:
  - dst_endpoint_ip
  - dst_endpoint_port
  rare_below: 3
reads:
- device_hostname
- dst_endpoint_ip
- dst_endpoint_port
- time
silence: not_evidence_of_absence
source: hb_network_connection
verified: dry-run
verified_at: '2026-10-02'
~~~
SELECT dst_endpoint_ip, dst_endpoint_port, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_network_connection WHERE (dst_endpoint_ip = '{{metadata_ip}}' OR dst_endpoint_port IN (6443, 8443, 10250)) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_ip, dst_endpoint_port HAVING host_count <= 2 ORDER BY host_count ASC
```

## triage-synthesis
<!-- Synthesize and Triage -->
```agent target=hunter
cite: required
context:
- evaluate-login-lead
- agentic-api-patterns
- rare-orchestration-connections
max_iterations: 6
objective: Assess whether the suspicious login from Step 1 is corroborated by the
  rare cloud API activity or orchestration network pivots found in the fan-out queries.
success_criteria: A malicious | suspicious | benign verdict per host or identity.
tools:
- endpoint
- identity
- network
```

## final-route
<!-- Route on final triage -->
if~: "the triage-synthesis verdict is malicious for at least one identity" (confidence: high, judge=hunter)
then: → revoke-and-isolate
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: metadata-visibility)
else: → close-out

## revoke-and-isolate
<!-- Revoke credentials and isolate -->
```action target=identity
~~~yaml
approval: required
~~~
Revoke all active sessions for the identified user account, rotate any long-lived cloud keys (AKIA/ASIA), and disable the account in the primary identity provider.
```
→ analyst-review

## analyst-review
<!-- Analyst Review -->
```manual target=analyst
Verify the cloud API operations and rare network connections. If the activity was a legitimate, approved automated process, tune the sensitive resource list.
```
→ end

## close-out
<!-- Close out -->
```manual target=analyst
Record the hunt results. Document any service accounts found accessing orchestration layers for inclusion in future whitelists.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, critic, then reviewed by a person.