{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Adversaries are targeting cloud control planes and using automated agents to manipulate infrastructure. Identifying anomalous logins followed by rare management port access provides effective detection for these advanced techniques."
      },
      "name": "Cloud Identity and AI Agent Anomalies",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1133",
        "attack.t1190",
        "attack.t1204.002",
        "attack.t1003.001",
        "credential access",
        "discovery",
        "impact",
        "initial access",
        "persistence"
      ],
      "series": {
        "slug": "the-fine-art-of-frustrating-the-adversary",
        "index": 1,
        "title": "The Fine Art of Frustrating the Adversary",
        "total": 2
      },
      "related": [
        {
          "hunt": "unauthorized-rmm-persistence",
          "reason": "Persistence through RMM tools uses endpoint process and file telemetry, which is handled in a separate hunt.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "network": {
          "name": "Network telemetry",
          "category": "network",
          "telemetry": [
            "network"
          ]
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        },
        "identity": {
          "name": "Identity / sign-in telemetry",
          "category": "identity",
          "telemetry": [
            "identity"
          ]
        }
      },
      "analysis": "A standard detection rule might alert on any Kubernetes login, but this hunt uses a gated flow to correlate those logins with fleet-wide prevalence and rare behavioral pivots in the cloud control plane.",
      "coverage": [
        {
          "stage": "initial-access-social-engineering",
          "steps": [
            "suspicious-sensitive-logins",
            "evaluate-login-lead"
          ],
          "status": "covered"
        },
        {
          "stage": "exploitation-public-facing-apps",
          "steps": [
            "suspicious-sensitive-logins",
            "rare-orchestration-connections"
          ],
          "status": "covered"
        },
        {
          "stage": "ai-agent-discovery-c2",
          "steps": [
            "agentic-api-patterns"
          ],
          "status": "covered"
        },
        {
          "stage": "unauthorized-rmm-persistence",
          "reason": "Belongs to another part of the 'The Fine Art of Frustrating the Adversary' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "credential-harvesting-lsass",
          "reason": "Belongs to another part of the 'The Fine Art of Frustrating the Adversary' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "data-encrypted-for-impact",
          "reason": "Belongs to another part of the 'The Fine Art of Frustrating the Adversary' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Phishing and Social Engineering",
            "slug": "initial-access-social-engineering",
            "tactic": "initial-access",
            "techniques": [
              "T1204.002"
            ],
            "observables": [
              "Lures sent from expired domains",
              "Communication with fictional employee profiles",
              "Urgency-based messaging (unpaid taxes, injured relatives)"
            ]
          },
          {
            "name": "Exploitation of Public-Facing Apps",
            "slug": "exploitation-public-facing-apps",
            "tactic": "initial-access",
            "techniques": [
              "T1190",
              "T1133"
            ],
            "observables": [
              "Unauthorized sign-ins to critical servers",
              "Connections to Kubernetes API servers",
              "Access to exposed VPN gateways"
            ]
          },
          {
            "name": "Persistence via RMM Software",
            "slug": "unauthorized-rmm-persistence",
            "tactic": "persistence",
            "techniques": [
              "T1133"
            ],
            "observables": [
              "Zoho Unattended Agent",
              "AnyDesk",
              "ScreenConnect",
              "Atera",
              "Unauthorized remote technician sessions"
            ]
          },
          {
            "name": "LSASS Credential Access",
            "slug": "credential-harvesting-lsass",
            "tactic": "credential-access",
            "techniques": [
              "T1003.001"
            ],
            "observables": [
              "Mimikatz",
              "comsvcs.dll",
              "procdump -ma lsass.exe",
              "Direct access to LSASS memory"
            ]
          },
          {
            "name": "Agentic Malactivity and Discovery",
            "slug": "ai-agent-discovery-c2",
            "tactic": "discovery",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "Unexpected writes to package registries",
              "Repository creation and dataset commits",
              "API calls to Kubernetes interfaces",
              "DNS-over-HTTPS relays usage",
              "Access to cloud metadata services"
            ]
          },
          {
            "name": "Ransomware Encryption",
            "slug": "data-encrypted-for-impact",
            "tactic": "impact",
            "techniques": [
              "T1486"
            ],
            "observables": [
              "Execution of ransomware encryptor",
              "High-volume file modification / renaming"
            ]
          }
        ],
        "summary": "This scenario outlines the diverse set of adversary behaviors described by Cisco Talos, moving from initial access via social engineering or service exploitation to persistence using legitimate remote-management tools. It concludes with credential harvesting from LSASS memory, data encryption for impact, and emerging malicious activity from misconfigured AI agents targeting cloud infrastructure."
      },
      "severity": "medium",
      "rationale": "Focus on administrative identities and service accounts used for automation. This hunt is particularly valuable in hybrid environments with high Kubernetes adoption.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary has used social engineering or exploited public-facing remote services to compromise an administrative identity, then used that access to manipulate cloud repositories or orchestration layers via automated agents.",
      "parameters": {
        "metadata_ip": {
          "type": "ip",
          "default": "169.254.169.254",
          "description": "Cloud Instance Metadata Service IP address."
        },
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Paste the device_hostname values from the lead query here to narrow the second stage."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "sensitive_resources": {
          "from": {
            "ref": "architectural-critical-assets",
            "kind": "manual",
            "observed": "2024-10-01"
          },
          "type": "list[string]",
          "default": [
            "kubernetes",
            "vpn-gateway",
            "admin-console",
            "azure-portal",
            "aws-console",
            "okta"
          ],
          "description": "Critical resource names to monitor in sign-in logs."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://blog.talosintelligence.com/the-fine-art-of-frustrating-the-adversary/",
          "gates": [
            "dry-run",
            "lint",
            "critic"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://blog.talosintelligence.com/the-fine-art-of-frustrating-the-adversary/",
          "name": "Cisco Talos \u2014 The Fine Art of Frustrating the Adversary"
        }
      ],
      "blind_spots": [
        {
          "id": "limited-identity-context",
          "risk": "The lead query focuses on successful entry; the precursor brute-force activity may be invisible.",
          "stage": "initial-access-social-engineering",
          "question": "whether the successful login was preceded by multiple MFA fatigue or password spray attempts",
          "requires": "hb_auth_signin with detailed logon types and MFA failure reasons"
        },
        {
          "id": "metadata-visibility",
          "risk": "A network pivot from a host without an agent will not appear in hb_network_connection, leaving a blind spot for unmanaged compute.",
          "stage": "exploitation-public-facing-apps",
          "question": "whether an unmanaged cloud instance accessed the metadata service",
          "requires": "VPC flow logs for all cloud subnets"
        }
      ]
    },
    "name": "Cloud Identity and AI Agent Anomalies",
    "description": "This hunt identifies unauthorized access to critical cloud management interfaces and orchestration systems. It uses a gated flow, starting with a lightweight audit of logins to sensitive resources like Kubernetes API servers or VPN gateways. If the lead is suspicious, the hunt expands to examine rare cloud API operations and rare network connections to orchestration management ports, stack-counting these behaviors to separate manual or agentic intrusions from fleet-wide administrative noise."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "the-fine-art-of-frustrating-the-adversary",
          "index": 1,
          "title": "The Fine Art of Frustrating the Adversary",
          "total": 2
        },
        "coverage": [
          {
            "stage": "initial-access-social-engineering",
            "steps": [
              "suspicious-sensitive-logins",
              "evaluate-login-lead"
            ],
            "status": "covered"
          },
          {
            "stage": "exploitation-public-facing-apps",
            "steps": [
              "suspicious-sensitive-logins",
              "rare-orchestration-connections"
            ],
            "status": "covered"
          },
          {
            "stage": "ai-agent-discovery-c2",
            "steps": [
              "agentic-api-patterns"
            ],
            "status": "covered"
          },
          {
            "stage": "unauthorized-rmm-persistence",
            "reason": "Belongs to another part of the 'The Fine Art of Frustrating the Adversary' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "credential-harvesting-lsass",
            "reason": "Belongs to another part of the 'The Fine Art of Frustrating the Adversary' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "data-encrypted-for-impact",
            "reason": "Belongs to another part of the 'The Fine Art of Frustrating the Adversary' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary has used social engineering or exploited public-facing remote services to compromise an administrative identity, then used that access to manipulate cloud repositories or orchestration layers via automated agents.",
        "blind_spots": [
          {
            "id": "limited-identity-context",
            "risk": "The lead query focuses on successful entry; the precursor brute-force activity may be invisible.",
            "stage": "initial-access-social-engineering",
            "question": "whether the successful login was preceded by multiple MFA fatigue or password spray attempts",
            "requires": "hb_auth_signin with detailed logon types and MFA failure reasons"
          },
          {
            "id": "metadata-visibility",
            "risk": "A network pivot from a host without an agent will not appear in hb_network_connection, leaving a blind spot for unmanaged compute.",
            "stage": "exploitation-public-facing-apps",
            "question": "whether an unmanaged cloud instance accessed the metadata service",
            "requires": "VPC flow logs for all cloud subnets"
          }
        ],
        "scoping_notes": "Focus on administrative identities and service accounts used for automation. This hunt is particularly valuable in hybrid environments with high Kubernetes adoption.",
        "beyond_detection": "A standard detection rule might alert on any Kubernetes login, but this hunt uses a gated flow to correlate those logins with fleet-wide prevalence and rare behavioral pivots in the cloud control plane."
      }
    },
    {
      "id": "suspicious-sensitive-logins",
      "type": "query",
      "label": "Suspicious logins to sensitive interfaces",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "identity",
        "content": "SELECT actor_user_name, dst_endpoint_name, src_endpoint_ip, src_location_country, mfa, device_hostname, time FROM hb_auth_signin WHERE status_id = 1 AND (instr(',' || '{{sensitive_resources}}' || ',', ',' || LOWER(dst_endpoint_name) || ',') > 0 OR LOWER(dst_endpoint_name) LIKE '%kube%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_auth_signin",
        "description": "Identify successful sign-ins to critical services that manage the cloud or network perimeter as a lead for further investigation.",
        "expected_signal": "Login events from unusual IPs or countries targeting sensitive infrastructure; the presence of these rows triggers the next read."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Suspicious logins to sensitive interfaces",
        "reads": [
          "actor_user_name",
          "device_hostname",
          "dst_endpoint_name",
          "mfa",
          "src_endpoint_ip",
          "src_location_country",
          "status_id",
          "time"
        ],
        "source": "hb_auth_signin",
        "target": "identity",
        "content": "SELECT actor_user_name, dst_endpoint_name, src_endpoint_ip, src_location_country, mfa, device_hostname, time FROM hb_auth_signin WHERE status_id = 1 AND (instr(',' || '{{sensitive_resources}}' || ',', ',' || LOWER(dst_endpoint_name) || ',') > 0 OR LOWER(dst_endpoint_name) LIKE '%kube%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Login events from unusual IPs or countries targeting sensitive infrastructure; the presence of these rows triggers the next read.",
        "verified": "dry-run",
        "verified_at": "2026-10-02"
      }
    },
    {
      "id": "evaluate-login-lead",
      "type": "analytic",
      "label": "Evaluate sign-in lead",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity",
          "network"
        ],
        "context": [
          "suspicious-sensitive-logins"
        ],
        "objective": "Determine if any sign-in to sensitive infrastructure shown in the lead query is anomalous based on source IP, geography, or lack of MFA.",
        "description": "Decide whether any of the identified logins are anomalous enough to warrant expensive behavioral analysis across the fleet.",
        "max_iterations": 3,
        "expected_signal": "A per-user or per-host determination citing the source IP and MFA state.",
        "success_criteria": "A verdict of suspicious or benign for each identified session."
      },
      "parents": [
        {
          "id": "suspicious-sensitive-logins"
        }
      ]
    },
    {
      "id": "auth-gate",
      "type": "checkpoint",
      "label": "Gate: Proceed to behavioral analysis?",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the login-lead verdict is suspicious for at least one session",
        "condition": "the login-lead verdict is suspicious for at least one session",
        "blind_spot": "limited-identity-context",
        "confidence": "high",
        "description": "Route the hunt based on the agent assessment of the initial access lead to avoid unnecessary processing.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "evaluate-login-lead"
        }
      ]
    },
    {
      "id": "agentic-api-patterns",
      "type": "query",
      "label": "Agentic Cloud API and Repository activity",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "endpoint",
        "content": "SELECT actor_user_name, api_operation, api_service_name, resource_name, src_endpoint_ip, time FROM hb_cloud_api_activity WHERE (LOWER(api_operation) LIKE '%repository%' OR LOWER(api_operation) LIKE '%putbucket%' OR LOWER(api_service_name) LIKE '%eks%' OR LOWER(api_service_name) LIKE '%kubernetes%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_cloud_api_activity",
        "description": "Identify repository creation, EKS manipulation, or unusual data staging operations consistent with automated agents.",
        "expected_signal": "Unexpected writes to package registries or repository creation performed by the identities flagged in the lead query."
      },
      "parents": [
        {
          "id": "auth-gate",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Agentic Cloud API and Repository activity",
        "reads": [
          "actor_user_name",
          "api_operation",
          "api_service_name",
          "resource_name",
          "src_endpoint_ip",
          "time"
        ],
        "source": "hb_cloud_api_activity",
        "target": "endpoint",
        "content": "SELECT actor_user_name, api_operation, api_service_name, resource_name, src_endpoint_ip, time FROM hb_cloud_api_activity WHERE (LOWER(api_operation) LIKE '%repository%' OR LOWER(api_operation) LIKE '%putbucket%' OR LOWER(api_service_name) LIKE '%eks%' OR LOWER(api_service_name) LIKE '%kubernetes%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Unexpected writes to package registries or repository creation performed by the identities flagged in the lead query.",
        "verified": "dry-run",
        "verified_at": "2026-10-02"
      }
    },
    {
      "id": "rare-orchestration-connections",
      "type": "query",
      "label": "Rare orchestration and metadata connections",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "network",
        "content": "SELECT dst_endpoint_ip, dst_endpoint_port, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_network_connection WHERE (dst_endpoint_ip = '{{metadata_ip}}' OR dst_endpoint_port IN (6443, 8443, 10250)) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_ip, dst_endpoint_port HAVING host_count <= 2 ORDER BY host_count ASC",
        "surface": "hb_network_connection",
        "description": "Stack-count network connections to management ports and the metadata service to find rare access from scoped hosts.",
        "expected_signal": "A connection to a Kubernetes management port or metadata service appearing on only one or two hosts, indicating non-standard activity."
      },
      "parents": [
        {
          "id": "auth-gate",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare orchestration and metadata connections",
        "reads": [
          "device_hostname",
          "dst_endpoint_ip",
          "dst_endpoint_port",
          "time"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT dst_endpoint_ip, dst_endpoint_port, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_network_connection WHERE (dst_endpoint_ip = '{{metadata_ip}}' OR dst_endpoint_port IN (6443, 8443, 10250)) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_ip, dst_endpoint_port HAVING host_count <= 2 ORDER BY host_count ASC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A connection to a Kubernetes management port or metadata service appearing on only one or two hosts, indicating non-standard activity.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "dst_endpoint_ip",
            "dst_endpoint_port"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-10-02"
      }
    },
    {
      "id": "triage-synthesis",
      "type": "analytic",
      "label": "Synthesize and Triage",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity",
          "network"
        ],
        "context": [
          "evaluate-login-lead",
          "agentic-api-patterns",
          "rare-orchestration-connections"
        ],
        "objective": "Assess whether the suspicious login from Step 1 is corroborated by the rare cloud API activity or orchestration network pivots found in the fan-out queries.",
        "description": "Correlate the initial login lead with the subsequent cloud API and network orchestration behavior to determine if an intrusion is occurring.",
        "max_iterations": 6,
        "expected_signal": "A detailed incident assessment linking the identity access to post-exploitation behavior.",
        "success_criteria": "A malicious | suspicious | benign verdict per host or identity."
      },
      "parents": [
        {
          "id": "agentic-api-patterns",
          "kind": "merge"
        },
        {
          "id": "rare-orchestration-connections",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "final-route",
      "type": "checkpoint",
      "label": "Route on final triage",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage-synthesis verdict is malicious for at least one identity",
        "condition": "the triage-synthesis verdict is malicious for at least one identity",
        "blind_spot": "metadata-visibility",
        "confidence": "high",
        "description": "Direct the response based on the synthesis of all evidence.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-synthesis"
        }
      ]
    },
    {
      "id": "revoke-and-isolate",
      "type": "action",
      "label": "Revoke credentials and isolate",
      "config": {
        "target": "identity",
        "description": "Halt the adversary's progress by revoking compromised sessions and isolating any active AI agent credentials.",
        "instructions": "Revoke all active sessions for the identified user account, rotate any long-lived cloud keys (AKIA/ASIA), and disable the account in the primary identity provider.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "final-route",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Analyst Review",
      "config": {
        "assignee": "analyst",
        "description": "Human review of the evidence to ensure tuning and valid containment.",
        "instructions": "Verify the cloud API operations and rare network connections. If the activity was a legitimate, approved automated process, tune the sensitive resource list."
      },
      "parents": [
        {
          "id": "auth-gate",
          "branch": "default"
        },
        {
          "id": "auth-gate",
          "branch": "on_unavailable"
        },
        {
          "id": "final-route",
          "branch": "default"
        },
        {
          "id": "final-route",
          "branch": "on_unavailable"
        },
        {
          "id": "revoke-and-isolate"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out",
      "config": {
        "assignee": "analyst",
        "description": "Standard wrap-up for non-malicious findings.",
        "instructions": "Record the hunt results. Document any service accounts found accessing orchestration layers for inclusion in future whitelists."
      },
      "parents": [
        {
          "id": "auth-gate",
          "branch": "on_refutes"
        },
        {
          "id": "final-route",
          "branch": "on_refutes"
        }
      ]
    }
  ]
}