{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Cloud workload compromise is a high-impact risk; validating that runtime security and network segments actually contain threats is a core operational requirement."
      },
      "name": "Cloud Runtime, Lateral Movement, and Impact",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1078",
        "attack.t1486",
        "attack.t1566",
        "execution",
        "impact",
        "initial access",
        "lateral movement",
        "persistence"
      ],
      "series": {
        "slug": "6-ai-soc-integrations-actually-worth-connecting",
        "index": 2,
        "title": "6 AI SOC Integrations Actually Worth Connecting",
        "total": 2
      },
      "related": [
        {
          "hunt": "initial-access-phishing-portals",
          "reason": "Phishing identification handles the credential theft stage that precedes this post-compromise hunt.",
          "relation": "out-of-scope-alternative"
        },
        {
          "hunt": "identity-access-exposure-investigation",
          "relation": "follows"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "network": {
          "name": "Network telemetry",
          "category": "network",
          "telemetry": [
            "network"
          ]
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "Simple rules fire on single blocked connections; this hunt correlates suspicious execution with file theft and network violations across four telemetry surfaces to distinguish a coordinated attack from background noise.",
      "coverage": [
        {
          "stage": "suspicious-cloud-runtime-execution",
          "steps": [
            "runtime-execution-temp",
            "sensitive-file-reads"
          ],
          "status": "covered"
        },
        {
          "stage": "lateral-movement-segmentation-violation",
          "steps": [
            "segmentation-violations"
          ],
          "status": "covered"
        },
        {
          "stage": "data-encryption-for-impact",
          "steps": [
            "impact-file-activity"
          ],
          "status": "covered"
        },
        {
          "stage": "incident-alerting-and-response",
          "steps": [
            "webhook-tampering"
          ],
          "status": "covered"
        },
        {
          "stage": "initial-access-phishing-portals",
          "reason": "Belongs to another part of the '6 AI SOC Integrations Actually Worth Connecting' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "vulnerability-and-exposure-discovery",
          "reason": "Belongs to another part of the '6 AI SOC Integrations Actually Worth Connecting' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "credential-abuse-and-mfa-evasion",
          "reason": "Belongs to another part of the '6 AI SOC Integrations Actually Worth Connecting' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Credential Harvesting via Phishing Portals",
            "slug": "initial-access-phishing-portals",
            "tactic": "initial-access",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "bottleneck.the",
              "Mokn authentication portals",
              "Credential testing activity"
            ]
          },
          {
            "name": "Vulnerability and Exposure Discovery",
            "slug": "vulnerability-and-exposure-discovery",
            "tactic": "initial-access",
            "techniques": [
              "T1078"
            ],
            "observables": [
              "Holm Security vulnerability scans",
              "Asset risk profiling",
              "Exposed human assets"
            ]
          },
          {
            "name": "Credential Abuse and MFA Evasion",
            "slug": "credential-abuse-and-mfa-evasion",
            "tactic": "persistence",
            "techniques": [
              "T1078"
            ],
            "observables": [
              "Silverfort MFA decisions",
              "Suspicious access patterns",
              "Policy actions",
              "Hybrid environment authentication logs"
            ]
          },
          {
            "name": "Suspicious Cloud Runtime Execution",
            "slug": "suspicious-cloud-runtime-execution",
            "tactic": "execution",
            "techniques": [
              "T1078"
            ],
            "observables": [
              "Upwind runtime workload monitoring",
              "Process accessing sensitive resource",
              "Anomalous cloud asset behavior"
            ]
          },
          {
            "name": "Lateral Movement across Segments",
            "slug": "lateral-movement-segmentation-violation",
            "tactic": "lateral-movement",
            "techniques": [
              "T1078"
            ],
            "observables": [
              "Akamai Guardicore network traffic logs",
              "Communication between isolated workloads",
              "Zero Trust policy violations"
            ]
          },
          {
            "name": "Data Encryption for Impact",
            "slug": "data-encryption-for-impact",
            "tactic": "impact",
            "techniques": [
              "T1486"
            ],
            "observables": [
              "Ransomware activity",
              "Spyware delivery",
              "Mass file modification"
            ]
          },
          {
            "name": "Incident Alerting and Response",
            "slug": "incident-alerting-and-response",
            "tactic": "impact",
            "techniques": [
              "T1486"
            ],
            "observables": [
              "ilert incident notifications",
              "Slack notification webhooks",
              "Teams alert messages",
              "Voice call escalation"
            ]
          }
        ],
        "summary": "An adversary leverages deceptive authentication portals to harvest credentials and identifies unpatched vulnerabilities across the attack surface. The campaign progresses to cloud runtime execution and lateral movement across microsegmented workloads, culminating in ransomware encryption and automated incident notification."
      },
      "severity": "medium",
      "rationale": "Focus on workloads in public subnets first; widen to internal management systems if lateral movement is suspected.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary has compromised a cloud workload using valid credentials and is moving across network segments before encrypting data and suppressing alerts via webhooks.",
      "parameters": {
        "scope_hosts": {
          "from": {
            "ref": "analyst-defined",
            "kind": "manual",
            "observed": "2024-03-20"
          },
          "type": "list[host]",
          "default": [],
          "description": "Optional: Hostnames of specific cloud workloads to focus on."
        },
        "lookback_days": {
          "from": {
            "ref": "hunt-standard-lookback",
            "kind": "manual",
            "observed": "2024-03-20"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "sensitive_paths": {
          "from": {
            "ref": "standard-system-targets",
            "kind": "manual",
            "observed": "2024-03-20"
          },
          "type": "list[path]",
          "default": [
            "/etc/shadow",
            "/etc/sudoers",
            "/etc/pam.d",
            "C:\\Windows\\System32\\config\\SAM"
          ],
          "description": "Sensitive system files indicating credential theft or escalation."
        },
        "alerting_domains": {
          "from": {
            "ref": "sekoia-ai-soc",
            "kind": "article",
            "observed": "2024-03-20"
          },
          "type": "list[domain]",
          "default": [
            "hooks.slack.com",
            "ilert.com",
            "bottleneck.the"
          ],
          "description": "Known alerting and webhook domains to monitor."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.sekoia.com/blog/ai-soc-integrations-6-capabilities-worth-connecting",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.sekoia.com/blog/ai-soc-integrations-6-capabilities-worth-connecting",
          "name": "Sekoia \u2014 AI SOC Integrations: 6 Capabilities Worth Connecting"
        }
      ],
      "blind_spots": [
        {
          "id": "no-network-fabric-logs",
          "risk": "A host without microsegmentation or VPC flow logging would not show blocked connections, making the lateral movement triage blind.",
          "stage": "lateral-movement-segmentation-violation",
          "question": "Did lateral movement succeed through an unmonitored or allowed path?",
          "requires": "hb_network_connection with activity_id=5 (Refuse)"
        },
        {
          "id": "encryption-threshold-noise",
          "risk": "An attacker encrypting only high-value configuration or secret files (e.g., .env or keys) would evade the mass modification check.",
          "stage": "data-encryption-for-impact",
          "question": "Is targeted encryption occurring below the 50-file threshold?",
          "requires": "hb_file_activity mass counts"
        }
      ]
    },
    "name": "Cloud Runtime, Lateral Movement, and Impact",
    "description": "This hunt identifies post-compromise stages of a cloud-based intrusion. The analyst identifies active workloads, then hunts for suspicious runtime execution and sensitive file access. The second phase seeks evidence of lateral movement via network segmentation violations, mass file modifications during encryption, and outbound HTTP traffic to alerting platforms."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "6-ai-soc-integrations-actually-worth-connecting",
          "index": 2,
          "title": "6 AI SOC Integrations Actually Worth Connecting",
          "total": 2
        },
        "coverage": [
          {
            "stage": "suspicious-cloud-runtime-execution",
            "steps": [
              "runtime-execution-temp",
              "sensitive-file-reads"
            ],
            "status": "covered"
          },
          {
            "stage": "lateral-movement-segmentation-violation",
            "steps": [
              "segmentation-violations"
            ],
            "status": "covered"
          },
          {
            "stage": "data-encryption-for-impact",
            "steps": [
              "impact-file-activity"
            ],
            "status": "covered"
          },
          {
            "stage": "incident-alerting-and-response",
            "steps": [
              "webhook-tampering"
            ],
            "status": "covered"
          },
          {
            "stage": "initial-access-phishing-portals",
            "reason": "Belongs to another part of the '6 AI SOC Integrations Actually Worth Connecting' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "vulnerability-and-exposure-discovery",
            "reason": "Belongs to another part of the '6 AI SOC Integrations Actually Worth Connecting' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "credential-abuse-and-mfa-evasion",
            "reason": "Belongs to another part of the '6 AI SOC Integrations Actually Worth Connecting' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary has compromised a cloud workload using valid credentials and is moving across network segments before encrypting data and suppressing alerts via webhooks.",
        "blind_spots": [
          {
            "id": "no-network-fabric-logs",
            "risk": "A host without microsegmentation or VPC flow logging would not show blocked connections, making the lateral movement triage blind.",
            "stage": "lateral-movement-segmentation-violation",
            "question": "Did lateral movement succeed through an unmonitored or allowed path?",
            "requires": "hb_network_connection with activity_id=5 (Refuse)"
          },
          {
            "id": "encryption-threshold-noise",
            "risk": "An attacker encrypting only high-value configuration or secret files (e.g., .env or keys) would evade the mass modification check.",
            "stage": "data-encryption-for-impact",
            "question": "Is targeted encryption occurring below the 50-file threshold?",
            "requires": "hb_file_activity mass counts"
          }
        ],
        "scoping_notes": "Focus on workloads in public subnets first; widen to internal management systems if lateral movement is suspected.",
        "beyond_detection": "Simple rules fire on single blocked connections; this hunt correlates suspicious execution with file theft and network violations across four telemetry surfaces to distinguish a coordinated attack from background noise."
      }
    },
    {
      "id": "scope-cloud-workloads",
      "type": "query",
      "label": "Identify active cloud workloads",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT DISTINCT device_hostname FROM hb_process_activity WHERE (LOWER(process_path) LIKE '/var/www/%' OR LOWER(process_path) LIKE '/opt/%' OR LOWER(process_path) LIKE '%python%' OR LOWER(process_path) LIKE '%java%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Identify hosts running web or application services to narrow the investigative focus.",
        "expected_signal": "A list of hostnames representing active workloads. Silence indicates no matching service activity."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify active cloud workloads",
        "reads": [
          "device_hostname",
          "process_path",
          "process_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT DISTINCT device_hostname FROM hb_process_activity WHERE (LOWER(process_path) LIKE '/var/www/%' OR LOWER(process_path) LIKE '/opt/%' OR LOWER(process_path) LIKE '%python%' OR LOWER(process_path) LIKE '%java%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hostnames representing active workloads. Silence indicates no matching service activity.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "runtime-execution-temp",
      "type": "query",
      "label": "Execution from writable paths",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE (LOWER(process_path) LIKE '/tmp/%' OR LOWER(process_path) LIKE '/dev/shm/%' OR LOWER(process_path) LIKE '%\\temp\\%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Detect processes launched from /tmp or /dev/shm, where adversaries often stage malware.",
        "expected_signal": "Process metadata from untrusted paths. Silence proves no such processes ran in the monitored window."
      },
      "parents": [
        {
          "id": "scope-cloud-workloads"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Execution from writable paths",
        "reads": [
          "device_hostname",
          "process_name",
          "process_path",
          "process_cmd_line",
          "user_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE (LOWER(process_path) LIKE '/tmp/%' OR LOWER(process_path) LIKE '/dev/shm/%' OR LOWER(process_path) LIKE '%\\temp\\%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "evidence_of_absence",
        "expected": "Process metadata from untrusted paths. Silence proves no such processes ran in the monitored window.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "sensitive-file-reads",
      "type": "query",
      "label": "Sensitive system file access",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "endpoint",
        "content": "SELECT device_hostname, actor_user_name, file_path, process_name, time FROM hb_file_activity WHERE instr(',' || '{{sensitive_paths}}' || ',', ',' || LOWER(file_path) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_file_activity",
        "description": "Identify processes reading system secrets, which follows initial execution.",
        "expected_signal": "Rows linking a process to a secret-carrying file. Silence suggests no such file touches were recorded."
      },
      "parents": [
        {
          "id": "scope-cloud-workloads"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Sensitive system file access",
        "reads": [
          "device_hostname",
          "actor_user_name",
          "file_path",
          "process_name",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, actor_user_name, file_path, process_name, time FROM hb_file_activity WHERE instr(',' || '{{sensitive_paths}}' || ',', ',' || LOWER(file_path) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Rows linking a process to a secret-carrying file. Silence suggests no such file touches were recorded.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "early-stage-triage",
      "type": "analytic",
      "label": "Evaluate workload compromise",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "network",
          "web"
        ],
        "context": [
          "scope-cloud-workloads",
          "runtime-execution-temp",
          "sensitive-file-reads"
        ],
        "objective": "Establish if the processes in /tmp or temporary paths are responsible for sensitive file access on the scoped hosts.",
        "description": "Determine if execution in writable paths correlates with sensitive file access.",
        "max_iterations": 3,
        "expected_signal": "A per-host verdict on whether a workload was likely compromised.",
        "success_criteria": "A verdict for each host naming the suspicious processes and the specific secrets accessed."
      },
      "parents": [
        {
          "id": "runtime-execution-temp",
          "kind": "merge"
        },
        {
          "id": "sensitive-file-reads",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "segmentation-violations",
      "type": "query",
      "label": "Network segmentation violations",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "network",
        "content": "SELECT device_hostname, src_endpoint_ip, dst_endpoint_ip, dst_endpoint_port, time FROM hb_network_connection WHERE activity_id = 5 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_network_connection",
        "description": "Identify blocked traffic from compromised workloads to restricted segments.",
        "expected_signal": "Blocked connection attempts from scoped workloads. Silence suggests microsegmentation is either clean or unmonitored."
      },
      "parents": [
        {
          "id": "early-stage-triage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Network segmentation violations",
        "reads": [
          "device_hostname",
          "src_endpoint_ip",
          "dst_endpoint_ip",
          "dst_endpoint_port",
          "time"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT device_hostname, src_endpoint_ip, dst_endpoint_ip, dst_endpoint_port, time FROM hb_network_connection WHERE activity_id = 5 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Blocked connection attempts from scoped workloads. Silence suggests microsegmentation is either clean or unmonitored.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "dst_endpoint_ip"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "impact-file-activity",
      "type": "query",
      "label": "Mass file modification",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, actor_user_name, activity_name, COUNT(DISTINCT file_path) AS file_count, MIN(time) AS first_seen FROM hb_file_activity WHERE activity_id IN (1, 3, 4, 5) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, actor_user_name, activity_name HAVING file_count > 50 ORDER BY file_count DESC",
        "surface": "hb_file_activity",
        "description": "Find signs of encryption by counting unusually high file activity per actor.",
        "expected_signal": "High file modification counts associated with a single user. Silence proves an absence of mass file changes."
      },
      "parents": [
        {
          "id": "early-stage-triage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Mass file modification",
        "reads": [
          "device_hostname",
          "actor_user_name",
          "activity_name",
          "file_path",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, actor_user_name, activity_name, COUNT(DISTINCT file_path) AS file_count, MIN(time) AS first_seen FROM hb_file_activity WHERE activity_id IN (1, 3, 4, 5) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, actor_user_name, activity_name HAVING file_count > 50 ORDER BY file_count DESC",
        "silence": "evidence_of_absence",
        "expected": "High file modification counts associated with a single user. Silence proves an absence of mass file changes.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "webhook-tampering",
      "type": "query",
      "label": "Outbound alerting webhooks",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "web",
        "content": "SELECT device_hostname, url_hostname, url_path, time FROM hb_http_activity WHERE instr(',' || '{{alerting_domains}}' || ',', ',' || LOWER(url_hostname) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_http_activity",
        "description": "Detect traffic to Slack or ilert that could indicate alert suppression or exfiltration.",
        "expected_signal": "HTTP requests to incident management platforms. Silence suggests no such webhooks were fired from workloads."
      },
      "parents": [
        {
          "id": "early-stage-triage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Outbound alerting webhooks",
        "reads": [
          "device_hostname",
          "url_hostname",
          "url_path",
          "time"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT device_hostname, url_hostname, url_path, time FROM hb_http_activity WHERE instr(',' || '{{alerting_domains}}' || ',', ',' || LOWER(url_hostname) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "HTTP requests to incident management platforms. Silence suggests no such webhooks were fired from workloads.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "follow-on-triage",
      "type": "analytic",
      "label": "Full attack chain synthesis",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "network",
          "web"
        ],
        "context": [
          "early-stage-triage",
          "segmentation-violations",
          "impact-file-activity",
          "webhook-tampering"
        ],
        "objective": "Determine if the compromised workloads from the early triage have proceeded to violate network policies, encrypt files, or manipulate alerting systems.",
        "description": "Correlate early stage workload compromise with the follow-on lateral and impact evidence.",
        "max_iterations": 4,
        "expected_signal": "A final verdict linking the runtime execution to subsequent impact behaviors.",
        "success_criteria": "A verdict citing the linkage between suspicious processes and the follow-on lateral or impact rows."
      },
      "parents": [
        {
          "id": "segmentation-violations",
          "kind": "merge"
        },
        {
          "id": "impact-file-activity",
          "kind": "merge"
        },
        {
          "id": "webhook-tampering",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "final-decision",
      "type": "checkpoint",
      "label": "Decision on host isolation",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "The agent identifies a host with suspicious execution followed by network policy violations or mass file encryption.",
        "condition": "The agent identifies a host with suspicious execution followed by network policy violations or mass file encryption.",
        "blind_spot": "no-network-fabric-logs",
        "confidence": "high",
        "description": "Route the findings to containment or manual analyst review.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "follow-on-triage"
        }
      ]
    },
    {
      "id": "contain-and-rotate",
      "type": "action",
      "label": "Isolate host and rotate keys",
      "config": {
        "target": "endpoint",
        "description": "Stop the intrusion and prevent re-entry via compromised credentials.",
        "instructions": "Isolate the host cited in the verdict. If the actor_user_name is a service account, rotate its API keys immediately; if a user account, reset the password and audit MFA logs.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "final-decision",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Analyst confirmation",
      "config": {
        "assignee": "analyst",
        "description": "Review agent citations and confirm the intrusion chain.",
        "instructions": "Review the processes in /tmp and the files touched. Verify if the segmentation violations correlate with the workload's known peers."
      },
      "parents": [
        {
          "id": "final-decision",
          "branch": "default"
        },
        {
          "id": "final-decision",
          "branch": "on_unavailable"
        },
        {
          "id": "final-decision",
          "branch": "on_refutes"
        },
        {
          "id": "contain-and-rotate"
        }
      ]
    },
    {
      "id": "hunt-closure",
      "type": "task",
      "label": "Hunt closure",
      "config": {
        "assignee": "analyst",
        "description": "Document findings and tune the hunt parameters.",
        "instructions": "Record whether the attack chain was found and if any alerting domains should be added to the parameter list."
      },
      "parents": [
        {
          "id": "analyst-review"
        }
      ]
    }
  ]
}