{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Session token theft via AiTM and Device Code flows is a prevalent threat that bypasses traditional MFA. Detecting the subsequent mailbox manipulation is critical to preventing financial fraud."
      },
      "name": "Cloud Identity Hijacking and Mailbox Persistence",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1566",
        "attack.t1557",
        "attack.t1528",
        "attack.t1137.005",
        "attack.t1564.008",
        "command and control",
        "credential access",
        "execution",
        "initial access",
        "persistence"
      ],
      "series": {
        "slug": "huntress-tragic-quadrant-top-cyber-threats-wrecking-businesses",
        "index": 2,
        "title": "Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses",
        "total": 2
      },
      "related": [
        {
          "hunt": "initial-access-phishing-lures",
          "reason": "Phishing delivery via email is out of scope for this post-authentication identity hunt.",
          "relation": "out-of-scope-alternative"
        },
        {
          "hunt": "endpoint-social-engineering-malicious-execution",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        },
        "identity": {
          "name": "Identity / sign-in telemetry",
          "category": "identity",
          "telemetry": [
            "identity"
          ]
        }
      },
      "analysis": "A single rule on mailbox rule creation generates excessive noise from IT automation. This hunt correlates sign-in anomalies with post-auth cloud behavior and endpoint DNS telemetry to distinguish BEC from routine admin work.",
      "coverage": [
        {
          "stage": "credential-access-token-theft",
          "steps": [
            "scoping-anomalous-auth",
            "phishing-dns-check"
          ],
          "status": "covered"
        },
        {
          "stage": "persistence-mailbox-manipulation",
          "steps": [
            "mailbox-persistence-ops"
          ],
          "status": "covered"
        },
        {
          "stage": "initial-access-phishing-lures",
          "reason": "Belongs to another part of the 'Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "execution-clickfix-win-r",
          "reason": "Belongs to another part of the 'Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "persistence-rmm-abuse",
          "reason": "Belongs to another part of the 'Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "c2-infostealer-deployment",
          "reason": "Belongs to another part of the 'Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Social Engineering with AI-Tuned Lures",
            "slug": "initial-access-phishing-lures",
            "tactic": "initial-access",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "claude.ai",
              "Railway",
              "Cisco redirect URLs",
              "Trend Micro redirect URLs",
              "Mimecast redirect URLs",
              "AI-tuned lures",
              "fake document shares",
              "service agreement lures"
            ]
          },
          {
            "name": "User-Driven ClickFix Command Execution",
            "slug": "execution-clickfix-win-r",
            "tactic": "execution",
            "techniques": [
              "T1204.001"
            ],
            "observables": [
              "Win+R",
              "Windows Run box",
              "Human Verification prompt",
              "multi-stage infection command"
            ]
          },
          {
            "name": "Adversary-in-the-Middle and Device Code Token Harvesting",
            "slug": "credential-access-token-theft",
            "tactic": "credential-access",
            "techniques": [
              "T1557",
              "T1528"
            ],
            "observables": [
              "session token",
              "device code login flow",
              "access token",
              "Microsoft 365 login page impersonation"
            ]
          },
          {
            "name": "Persistence via Rogue RMM Installation",
            "slug": "persistence-rmm-abuse",
            "tactic": "persistence",
            "techniques": [
              "T1219"
            ],
            "observables": [
              "rogue RMM tool",
              "Remote Monitoring and Management tools"
            ]
          },
          {
            "name": "Stealthy Mailbox Rule Manipulation",
            "slug": "persistence-mailbox-manipulation",
            "tactic": "persistence",
            "techniques": [
              "T1137.005",
              "T1564.008"
            ],
            "observables": [
              "inbox rules",
              "RSS Feeds folder",
              "Archive folders"
            ]
          },
          {
            "name": "Infostealer and RAT Deployment",
            "slug": "c2-infostealer-deployment",
            "tactic": "command-and-control",
            "techniques": [
              "T1555",
              "T1071.001"
            ],
            "observables": [
              "LummaC2",
              "SectopRAT",
              "FakeAgent"
            ]
          }
        ],
        "summary": "The Huntress Tragic Quadrant outlines common 2026 threats targeting SMBs, where attackers use AI-enhanced social engineering (ClickFix, fake lures) and trusted platforms (Claude.ai) to deliver infostealers and rogue RMM tools. The campaign progresses from initial access via session token theft (AiTM) or user-driven command execution to persistence through mailbox manipulation and remote management software abuse."
      },
      "severity": "high",
      "rationale": "Focus on high-value users such as executives and finance personnel. The analyst should populate scope_hosts from the workstations identified in the scoping query to improve DNS correlation precision.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary has bypassed multi-factor authentication via session token theft or device code phishing and established persistence by modifying mailbox rules to hide intercepted communications.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "A list of hostnames to narrow the DNS investigation; leave empty to hunt across the entire estate."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "rule_operations": {
          "from": {
            "ref": "M365 Unified Audit Log Operations",
            "kind": "manual",
            "observed": "2026-10-01"
          },
          "type": "list[string]",
          "default": [
            "new-inboxrule",
            "set-inboxrule",
            "update-inboxrule"
          ],
          "description": "Cloud API operations related to mailbox rule modification."
        },
        "phishing_domains": {
          "from": {
            "ref": "Huntress Tragic Quadrant",
            "kind": "article",
            "observed": "2026-10-01"
          },
          "type": "list[domain]",
          "default": [
            "claude.ai",
            "railway.app",
            "railway.com"
          ],
          "description": "Domains hosting token-harvesting infrastructure or malicious artifacts."
        },
        "suspicious_folders": {
          "from": {
            "ref": "Huntress Tragic Quadrant",
            "kind": "article",
            "observed": "2026-10-01"
          },
          "type": "list[string]",
          "default": [
            "rss feeds",
            "archive",
            "conversation history"
          ],
          "description": "Target folders used for stealthy mail redirection."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.huntress.com/blog/huntress-tragic-quadrant-cyber-threats",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.huntress.com/blog/huntress-tragic-quadrant-cyber-threats",
          "name": "Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses"
        }
      ],
      "blind_spots": [
        {
          "id": "missing-cloud-audit-logs",
          "risk": "An attacker retains persistence while the hunt only observes the initial sign-in.",
          "stage": "persistence-mailbox-manipulation",
          "question": "Whether the attacker created rules inside the mailbox.",
          "requires": "hb_cloud_api_activity for provider m365"
        },
        {
          "id": "ephemeral-infrastructure",
          "risk": "Infrastructure rotation makes domain matching an unreliable single signal.",
          "stage": "credential-access-token-theft",
          "question": "Whether the host contacted a domain not in the phishing_domains list.",
          "requires": "hb_dns_activity"
        }
      ]
    },
    "name": "Cloud Identity Hijacking and Mailbox Persistence",
    "description": "This hunt identifies session hijacking and subsequent mailbox persistence in Microsoft 365 environments. It begins by scoping anomalous sign-ins that use the device code flow or bypass MFA. The hunt then corroborates these leads by checking for the creation of stealthy inbox rules targeting low-visibility folders and DNS activity toward known token-harvesting infrastructure. An agent correlates these signals to confirm active account takeover and business email compromise preparation."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "huntress-tragic-quadrant-top-cyber-threats-wrecking-businesses",
          "index": 2,
          "title": "Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses",
          "total": 2
        },
        "coverage": [
          {
            "stage": "credential-access-token-theft",
            "steps": [
              "scoping-anomalous-auth",
              "phishing-dns-check"
            ],
            "status": "covered"
          },
          {
            "stage": "persistence-mailbox-manipulation",
            "steps": [
              "mailbox-persistence-ops"
            ],
            "status": "covered"
          },
          {
            "stage": "initial-access-phishing-lures",
            "reason": "Belongs to another part of the 'Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "execution-clickfix-win-r",
            "reason": "Belongs to another part of the 'Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "persistence-rmm-abuse",
            "reason": "Belongs to another part of the 'Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "c2-infostealer-deployment",
            "reason": "Belongs to another part of the 'Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary has bypassed multi-factor authentication via session token theft or device code phishing and established persistence by modifying mailbox rules to hide intercepted communications.",
        "blind_spots": [
          {
            "id": "missing-cloud-audit-logs",
            "risk": "An attacker retains persistence while the hunt only observes the initial sign-in.",
            "stage": "persistence-mailbox-manipulation",
            "question": "Whether the attacker created rules inside the mailbox.",
            "requires": "hb_cloud_api_activity for provider m365"
          },
          {
            "id": "ephemeral-infrastructure",
            "risk": "Infrastructure rotation makes domain matching an unreliable single signal.",
            "stage": "credential-access-token-theft",
            "question": "Whether the host contacted a domain not in the phishing_domains list.",
            "requires": "hb_dns_activity"
          }
        ],
        "scoping_notes": "Focus on high-value users such as executives and finance personnel. The analyst should populate scope_hosts from the workstations identified in the scoping query to improve DNS correlation precision.",
        "beyond_detection": "A single rule on mailbox rule creation generates excessive noise from IT automation. This hunt correlates sign-in anomalies with post-auth cloud behavior and endpoint DNS telemetry to distinguish BEC from routine admin work."
      }
    },
    {
      "id": "scoping-anomalous-auth",
      "type": "query",
      "label": "Scoping anomalous sign-ins",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "identity",
        "content": "SELECT actor_user_name, src_endpoint_ip, src_endpoint_hostname, event_type, mfa, time FROM hb_auth_signin WHERE provider = 'm365' AND status_id = 1 AND (LOWER(event_type) LIKE '%device%code%' OR (mfa IS NULL OR mfa = 'false')) AND time >= datetime('now', '-{{lookback_days}} days') ORDER BY time DESC",
        "surface": "hb_auth_signin",
        "description": "Identify successful M365 sign-ins that used the device code flow or lacked recorded MFA prompts.",
        "expected_signal": "A list of user accounts and source IPs associated with non-standard sign-ins. Silence suggests no easily detectable token-theft or device-code flow attempts occurred."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Scoping anomalous sign-ins",
        "reads": [
          "actor_user_name",
          "src_endpoint_ip",
          "src_endpoint_hostname",
          "event_type",
          "mfa",
          "time"
        ],
        "source": "hb_auth_signin",
        "target": "identity",
        "content": "SELECT actor_user_name, src_endpoint_ip, src_endpoint_hostname, event_type, mfa, time FROM hb_auth_signin WHERE provider = 'm365' AND status_id = 1 AND (LOWER(event_type) LIKE '%device%code%' OR (mfa IS NULL OR mfa = 'false')) AND time >= datetime('now', '-{{lookback_days}} days') ORDER BY time DESC",
        "silence": "not_evidence_of_absence",
        "expected": "A list of user accounts and source IPs associated with non-standard sign-ins. Silence suggests no easily detectable token-theft or device-code flow attempts occurred.",
        "verified": "dry-run",
        "verified_at": "2026-10-02"
      }
    },
    {
      "id": "mailbox-persistence-ops",
      "type": "query",
      "label": "Mailbox rule and folder manipulation",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT actor_user_name, api_operation, resource_name, resource_uid, src_endpoint_ip, time FROM hb_cloud_api_activity WHERE provider = 'm365' AND (instr(',' || '{{rule_operations}}' || ',', ',' || LOWER(api_operation) || ',') > 0 OR instr(',' || '{{suspicious_folders}}' || ',', ',' || LOWER(resource_uid) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') ORDER BY time DESC",
        "surface": "hb_cloud_api_activity",
        "description": "Identify the creation of inbox rules or folder interactions that redirect mail for persistence.",
        "expected_signal": "Audit events showing rule creation or movements to low-visibility folders. Frequent administrative updates are common; look for one-off rules on recently accessed accounts."
      },
      "parents": [
        {
          "id": "scoping-anomalous-auth"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Mailbox rule and folder manipulation",
        "reads": [
          "actor_user_name",
          "api_operation",
          "resource_name",
          "resource_uid",
          "src_endpoint_ip",
          "time"
        ],
        "source": "hb_cloud_api_activity",
        "target": "endpoint",
        "content": "SELECT actor_user_name, api_operation, resource_name, resource_uid, src_endpoint_ip, time FROM hb_cloud_api_activity WHERE provider = 'm365' AND (instr(',' || '{{rule_operations}}' || ',', ',' || LOWER(api_operation) || ',') > 0 OR instr(',' || '{{suspicious_folders}}' || ',', ',' || LOWER(resource_uid) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') ORDER BY time DESC",
        "silence": "evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Audit events showing rule creation or movements to low-visibility folders. Frequent administrative updates are common; look for one-off rules on recently accessed accounts.",
        "verified": "dry-run",
        "prevalence": {
          "by": "actor_user_name",
          "key": [
            "api_operation",
            "resource_uid"
          ],
          "rare_below": 2
        },
        "verified_at": "2026-10-02"
      }
    },
    {
      "id": "phishing-dns-check",
      "type": "query",
      "label": "Phishing and AI platform DNS check",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, query_hostname, COUNT(*) as lookups, MIN(time) as first_seen FROM hb_dns_activity WHERE (instr(',' || '{{phishing_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, query_hostname",
        "surface": "hb_dns_activity",
        "description": "Corroborate identity activity by looking for resolutions to known token-harvesting domains on the scoped hosts.",
        "expected_signal": "Any resolution to claude.ai or railway.app from a host associated with the anomalous sign-in. Silence means no DNS resolution for these specific domains occurred."
      },
      "parents": [
        {
          "id": "scoping-anomalous-auth"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Phishing and AI platform DNS check",
        "reads": [
          "device_hostname",
          "query_hostname",
          "time"
        ],
        "source": "hb_dns_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, query_hostname, COUNT(*) as lookups, MIN(time) as first_seen FROM hb_dns_activity WHERE (instr(',' || '{{phishing_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, query_hostname",
        "silence": "not_evidence_of_absence",
        "expected": "Any resolution to claude.ai or railway.app from a host associated with the anomalous sign-in. Silence means no DNS resolution for these specific domains occurred.",
        "verified": "dry-run",
        "verified_at": "2026-10-02"
      }
    },
    {
      "id": "triage-identity-threat",
      "type": "analytic",
      "label": "Triage identity threat",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity"
        ],
        "context": [
          "scoping-anomalous-auth",
          "mailbox-persistence-ops",
          "phishing-dns-check"
        ],
        "objective": "Determine if any user account shows a progression from a suspicious sign-in method to mailbox rule persistence. Cite the specific sign-in source IP and the name of any created inbox rules.",
        "description": "Correlate sign-ins, mailbox operations, and DNS indicators to settle on a verdict per user.",
        "max_iterations": 6,
        "expected_signal": "A per-user verdict of malicious, suspicious, or benign citing evidence from all context sources.",
        "success_criteria": "A verdict per user with clear row citations."
      },
      "parents": [
        {
          "id": "mailbox-persistence-ops",
          "kind": "merge"
        },
        {
          "id": "phishing-dns-check",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage verdict is malicious for at least one user account",
        "condition": "the triage verdict is malicious for at least one user account",
        "blind_spot": "missing-cloud-audit-logs",
        "confidence": "high",
        "description": "Route to containment if session hijacking is confirmed.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-identity-threat"
        }
      ]
    },
    {
      "id": "revoke-sessions",
      "type": "action",
      "label": "Revoke user sessions",
      "config": {
        "target": "identity",
        "description": "Terminate the adversary access by invalidating tokens.",
        "instructions": "Revoke all active refresh tokens and initiate a password reset for the affected users in M365.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-manual-review",
      "type": "task",
      "label": "Analyst manual review",
      "config": {
        "assignee": "analyst",
        "description": "Verify the contents of the modified rules to confirm business email compromise preparation.",
        "instructions": "Review the inbox rules for the flagged users; check for actions moving mail with keywords like payment or invoice to the RSS Feeds folder."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "revoke-sessions"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out",
      "config": {
        "assignee": "analyst",
        "description": "Finalize the hunt and record findings.",
        "instructions": "Record the results; if false positives were high, refine the rule_operations parameter to exclude service accounts."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "analyst-manual-review"
        }
      ]
    }
  ]
}