{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Linking identity, execution, and persistence context is the only way to reliably distinguish administrative maintenance from multi-stage intrusions. This hunt prevents single-stage alerts from being closed without investigating the broader intrusion story."
      },
      "name": "Contextual Investigation of Phased PowerShell Intrusions",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1053.005",
        "attack.t1059.001",
        "attack.t1133",
        "command and control",
        "execution",
        "initial access",
        "persistence"
      ],
      "related": [
        {
          "hunt": "lateral-movement-from-privileged-logon",
          "reason": "This hunt focuses on persistence and C2; lateral movement after a remote admin logon is a distinct follow-on scenario.",
          "relation": "sibling"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "network": {
          "name": "Network telemetry",
          "category": "network",
          "telemetry": [
            "network"
          ]
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        },
        "identity": {
          "name": "Identity / sign-in telemetry",
          "category": "identity",
          "telemetry": [
            "identity"
          ]
        }
      },
      "analysis": "While individual rules fire on schtasks or encoded powershell, this hunt pivots between identity (auth_signin), script content (script_activity), and persistent job configuration (scheduled_job) while baselining outbound traffic to confirm a coherent sequence that a single-surface rule cannot see. The analyst must weigh the combination of these signals to reach a verdict.",
      "coverage": [
        {
          "stage": "initial-access-remote-signin",
          "steps": [
            "rare-remote-logons"
          ],
          "status": "covered"
        },
        {
          "stage": "execution-powershell-scripts",
          "steps": [
            "suspicious-script-activity"
          ],
          "status": "covered"
        },
        {
          "stage": "persistence-scheduled-task",
          "steps": [
            "scheduled-task-persistence"
          ],
          "status": "covered"
        },
        {
          "stage": "c2-malicious-network-connection",
          "steps": [
            "suspicious-network-connections"
          ],
          "status": "covered"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "External Remote Access",
            "slug": "initial-access-remote-signin",
            "tactic": "initial-access",
            "techniques": [
              "T1133"
            ],
            "observables": [
              "Sign-in from an unusual country",
              "Connection via corporate VPN",
              "Sign-in to privileged administrator account"
            ]
          },
          {
            "name": "PowerShell Execution",
            "slug": "execution-powershell-scripts",
            "tactic": "execution",
            "techniques": [
              "T1059.001"
            ],
            "observables": [
              "Suspicious PowerShell command-line arguments",
              "Encoded PowerShell commands",
              "PowerShell script blocks downloading external files"
            ]
          },
          {
            "name": "Scheduled Task Persistence",
            "slug": "persistence-scheduled-task",
            "tactic": "persistence",
            "techniques": [
              "T1053.005"
            ],
            "observables": [
              "Scheduled task creation using schtasks",
              "Recurring task execution (e.g., nightly)",
              "Service account assigned to scheduled job"
            ]
          },
          {
            "name": "Command and Control Connection",
            "slug": "c2-malicious-network-connection",
            "tactic": "command-and-control",
            "observables": [
              "Workstation contacting a malicious IP address",
              "Connection to a suspicious domain",
              "Outbound network traffic from endpoint processes"
            ]
          }
        ],
        "summary": "An adversary gains initial access through external remote services or compromised accounts, followed by the execution of malicious PowerShell scripts. They establish persistence using scheduled tasks and maintain communication with command-and-control infrastructure via network connections to suspicious IP addresses."
      },
      "severity": "medium",
      "rationale": "Focus on Windows domain controllers and administrator workstations first. Ensure that PowerShell Script Block Logging is enabled on target hosts. The hunt filters for hosts with rare remote interactive logins to reduce noise from common network traffic.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary has gained initial access via remote services, executed PowerShell for post-exploitation, and established persistence through scheduled tasks to maintain a C2 connection.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Initial Windows host list to narrow the search."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "admin_accounts": {
          "from": {
            "ref": "internal-privileged-account-list",
            "kind": "manual",
            "observed": "2024-01-01"
          },
          "type": "list[string]",
          "default": [
            "Administrator",
            "root",
            "svc_admin"
          ],
          "description": "Privileged accounts to monitor for rare remote interactive sign-ins."
        },
        "compromised_hostnames": {
          "type": "list[host]",
          "default": [],
          "description": "Hosts flagged in the early triage phase to be investigated for persistence."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.sekoia.com/blog/ai-soc-agents-are-only-as-good-as-the-context-they-can-see",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.sekoia.com/blog/ai-soc-agents-are-only-as-good-as-the-context-they-can-see",
          "name": "Why AI SOC Agents Need Context to Investigate Alerts"
        }
      ],
      "blind_spots": [
        {
          "id": "incomplete-telemetry-chain",
          "risk": "If a host reports auth sign-ins but fails to report script activity, the agent will lack the context to confirm execution, leading to a false negative.",
          "owner": "SIEM Engineering",
          "question": "Whether a stage of the attack chain is missed due to a host not reporting to one specific surface.",
          "requires": "Unified coverage across auth, script, and job surfaces",
          "remediation": "Audit log ingestion for all four required surfaces per Windows asset."
        },
        {
          "id": "no-vpn-telemetry",
          "risk": "Remote access via undocumented gateways would bypass the rare-remote-logons query.",
          "owner": "Network Engineering",
          "stage": "initial-access-remote-signin",
          "question": "Whether the remote access occurred via a VPN gateway not reporting to the auth surface.",
          "requires": "hb_auth_signin from VPN provider",
          "remediation": "Integrate VPN logs into hb_auth_signin."
        }
      ]
    },
    "name": "Contextual Investigation of Phased PowerShell Intrusions",
    "description": "This hunt follows a complete attack chain from initial remote access to command and control. By linking identity telemetry from sign-ins with endpoint script activity and persistent scheduled jobs, it distinguishes between routine administrative work and a multi-stage breach. The phased approach allows an agent to first evaluate access and execution evidence before investigating the resulting persistence and rare network connections. The hunt uses two baseline queries to isolate rare behavior from common fleet noise."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "coverage": [
          {
            "stage": "initial-access-remote-signin",
            "steps": [
              "rare-remote-logons"
            ],
            "status": "covered"
          },
          {
            "stage": "execution-powershell-scripts",
            "steps": [
              "suspicious-script-activity"
            ],
            "status": "covered"
          },
          {
            "stage": "persistence-scheduled-task",
            "steps": [
              "scheduled-task-persistence"
            ],
            "status": "covered"
          },
          {
            "stage": "c2-malicious-network-connection",
            "steps": [
              "suspicious-network-connections"
            ],
            "status": "covered"
          }
        ],
        "rationale": "An adversary has gained initial access via remote services, executed PowerShell for post-exploitation, and established persistence through scheduled tasks to maintain a C2 connection.",
        "blind_spots": [
          {
            "id": "incomplete-telemetry-chain",
            "risk": "If a host reports auth sign-ins but fails to report script activity, the agent will lack the context to confirm execution, leading to a false negative.",
            "owner": "SIEM Engineering",
            "question": "Whether a stage of the attack chain is missed due to a host not reporting to one specific surface.",
            "requires": "Unified coverage across auth, script, and job surfaces",
            "remediation": "Audit log ingestion for all four required surfaces per Windows asset."
          },
          {
            "id": "no-vpn-telemetry",
            "risk": "Remote access via undocumented gateways would bypass the rare-remote-logons query.",
            "owner": "Network Engineering",
            "stage": "initial-access-remote-signin",
            "question": "Whether the remote access occurred via a VPN gateway not reporting to the auth surface.",
            "requires": "hb_auth_signin from VPN provider",
            "remediation": "Integrate VPN logs into hb_auth_signin."
          }
        ],
        "scoping_notes": "Focus on Windows domain controllers and administrator workstations first. Ensure that PowerShell Script Block Logging is enabled on target hosts. The hunt filters for hosts with rare remote interactive logins to reduce noise from common network traffic.",
        "beyond_detection": "While individual rules fire on schtasks or encoded powershell, this hunt pivots between identity (auth_signin), script content (script_activity), and persistent job configuration (scheduled_job) while baselining outbound traffic to confirm a coherent sequence that a single-surface rule cannot see. The analyst must weigh the combination of these signals to reach a verdict."
      }
    },
    {
      "id": "scoping-hosts",
      "type": "query",
      "label": "Identify candidate Windows hosts",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT hostname AS device_hostname FROM hb_devices WHERE platform = 'Windows' AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_devices",
        "description": "Narrow the investigation to Windows devices currently reporting telemetry.",
        "expected_signal": "A list of hostnames. Silence suggests no Windows devices are enrolled."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify candidate Windows hosts",
        "reads": [
          "hostname",
          "platform",
          "time"
        ],
        "source": "hb_devices",
        "target": "endpoint",
        "content": "SELECT hostname AS device_hostname FROM hb_devices WHERE platform = 'Windows' AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hostnames. Silence suggests no Windows devices are enrolled.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "rare-remote-logons",
      "type": "query",
      "label": "Rare remote interactive sign-ins",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "identity",
        "content": "SELECT dst_endpoint_name, actor_user_name, src_endpoint_ip, src_location_country, COUNT(DISTINCT dst_endpoint_name) AS host_count, MIN(time) AS first_seen FROM hb_auth_signin WHERE logon_type = 'Remote Interactive' AND (instr(',' || '{{admin_accounts}}' || ',', ',' || actor_user_name || ',') > 0 OR '{{admin_accounts}}' = '') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || dst_endpoint_name || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY src_endpoint_ip, actor_user_name, src_location_country HAVING host_count < 3",
        "surface": "hb_auth_signin",
        "description": "Detect initial access via RDP targeting admin accounts, baselined by host count to find anomalies.",
        "expected_signal": "Sign-ins from rare source IPs to specific hosts. Silence suggests only common or internal access occurred."
      },
      "parents": [
        {
          "id": "scoping-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare remote interactive sign-ins",
        "reads": [
          "dst_endpoint_name",
          "actor_user_name",
          "src_endpoint_ip",
          "src_location_country",
          "logon_type",
          "time"
        ],
        "source": "hb_auth_signin",
        "target": "identity",
        "content": "SELECT dst_endpoint_name, actor_user_name, src_endpoint_ip, src_location_country, COUNT(DISTINCT dst_endpoint_name) AS host_count, MIN(time) AS first_seen FROM hb_auth_signin WHERE logon_type = 'Remote Interactive' AND (instr(',' || '{{admin_accounts}}' || ',', ',' || actor_user_name || ',') > 0 OR '{{admin_accounts}}' = '') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || dst_endpoint_name || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY src_endpoint_ip, actor_user_name, src_location_country HAVING host_count < 3",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Sign-ins from rare source IPs to specific hosts. Silence suggests only common or internal access occurred.",
        "verified": "dry-run",
        "prevalence": {
          "by": "dst_endpoint_name",
          "key": [
            "src_endpoint_ip"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "suspicious-script-activity",
      "type": "query",
      "label": "Suspicious PowerShell script blocks",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, actor_user_name, script_content, time FROM hb_script_activity WHERE (LOWER(script_content) LIKE '%webclient%' OR LOWER(script_content) LIKE '%download%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_script_activity",
        "description": "Search for script blocks containing download logic or web client calls indicative of staging.",
        "expected_signal": "Script contents performing external downloads. Silence means no such script blocks were logged."
      },
      "parents": [
        {
          "id": "scoping-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Suspicious PowerShell script blocks",
        "reads": [
          "device_hostname",
          "actor_user_name",
          "script_content",
          "time"
        ],
        "source": "hb_script_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, actor_user_name, script_content, time FROM hb_script_activity WHERE (LOWER(script_content) LIKE '%webclient%' OR LOWER(script_content) LIKE '%download%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Script contents performing external downloads. Silence means no such script blocks were logged.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "triage-early-stage",
      "type": "analytic",
      "label": "Triage early-stage indicators",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity",
          "network"
        ],
        "context": [
          "rare-remote-logons",
          "suspicious-script-activity"
        ],
        "objective": "Determine if remote logins correlate with suspicious script execution on the same hosts or by the same accounts. Output a list of compromised_hostnames that show this combined behavior to be used as a parameter in the next phase.",
        "description": "Assess whether the remote sign-ins and script activity on specific hosts suggest a likely breach.",
        "max_iterations": 4,
        "expected_signal": "A per-host verdict of suspicious | benign for the early stages.",
        "success_criteria": "A verdict citing specific logins and script blocks. The output must explicitly list the hostnames for the next phase."
      },
      "parents": [
        {
          "id": "rare-remote-logons",
          "kind": "merge"
        },
        {
          "id": "suspicious-script-activity",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "scheduled-task-persistence",
      "type": "query",
      "label": "Scheduled task persistence in temp paths",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "endpoint",
        "content": "SELECT device_hostname, job_name, job_cmd_line, job_user_name, time FROM hb_scheduled_job WHERE (LOWER(job_cmd_line) LIKE '%powershell%' OR LOWER(job_cmd_line) LIKE '%cmd.exe%') AND (LOWER(job_cmd_line) LIKE '%\\\\temp\\\\%' OR LOWER(job_cmd_line) LIKE '%\\\\public\\\\%' OR LOWER(job_cmd_line) LIKE '%\\\\appdata\\\\%') AND ('{{compromised_hostnames}}' = '' OR instr(',' || '{{compromised_hostnames}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_scheduled_job",
        "description": "Find scheduled tasks on compromised hosts that execute scripts from user-writable or temporary paths.",
        "expected_signal": "Tasks pointing at staging directories on identified hosts. Silence suggests no persistence via this mechanism."
      },
      "parents": [
        {
          "id": "triage-early-stage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Scheduled task persistence in temp paths",
        "reads": [
          "device_hostname",
          "job_name",
          "job_cmd_line",
          "job_user_name",
          "time"
        ],
        "source": "hb_scheduled_job",
        "target": "endpoint",
        "content": "SELECT device_hostname, job_name, job_cmd_line, job_user_name, time FROM hb_scheduled_job WHERE (LOWER(job_cmd_line) LIKE '%powershell%' OR LOWER(job_cmd_line) LIKE '%cmd.exe%') AND (LOWER(job_cmd_line) LIKE '%\\\\temp\\\\%' OR LOWER(job_cmd_line) LIKE '%\\\\public\\\\%' OR LOWER(job_cmd_line) LIKE '%\\\\appdata\\\\%') AND ('{{compromised_hostnames}}' = '' OR instr(',' || '{{compromised_hostnames}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Tasks pointing at staging directories on identified hosts. Silence suggests no persistence via this mechanism.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "suspicious-network-connections",
      "type": "query",
      "label": "Rare outbound connections from compromised hosts",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "network",
        "content": "SELECT device_hostname, dst_endpoint_ip, process_name, COUNT(*) AS connection_count, MIN(time) AS first_seen FROM hb_network_connection WHERE direction = 'outbound' AND ('{{compromised_hostnames}}' = '' OR instr(',' || '{{compromised_hostnames}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, dst_endpoint_ip, process_name HAVING (SELECT COUNT(DISTINCT device_hostname) FROM hb_network_connection AS internal WHERE internal.dst_endpoint_ip = hb_network_connection.dst_endpoint_ip) < 5",
        "surface": "hb_network_connection",
        "description": "Identify outbound connections to destinations that are rare across the fleet, suggesting C2 traffic.",
        "expected_signal": "Connections to rare IPs on identified hosts. Silence provides evidence of absence for new external beaconing from these hosts."
      },
      "parents": [
        {
          "id": "triage-early-stage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare outbound connections from compromised hosts",
        "reads": [
          "device_hostname",
          "dst_endpoint_ip",
          "process_name",
          "direction",
          "time"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT device_hostname, dst_endpoint_ip, process_name, COUNT(*) AS connection_count, MIN(time) AS first_seen FROM hb_network_connection WHERE direction = 'outbound' AND ('{{compromised_hostnames}}' = '' OR instr(',' || '{{compromised_hostnames}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, dst_endpoint_ip, process_name HAVING (SELECT COUNT(DISTINCT device_hostname) FROM hb_network_connection AS internal WHERE internal.dst_endpoint_ip = hb_network_connection.dst_endpoint_ip) < 5",
        "silence": "evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Connections to rare IPs on identified hosts. Silence provides evidence of absence for new external beaconing from these hosts.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "dst_endpoint_ip"
          ],
          "rare_below": 5
        },
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "full-chain-assessment",
      "type": "analytic",
      "label": "Full-chain intrusion assessment",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity",
          "network"
        ],
        "context": [
          "triage-early-stage",
          "scheduled-task-persistence",
          "suspicious-network-connections"
        ],
        "objective": "Evaluate the complete attack chain per host. Specifically assess the temporal proximity between the remote logins (Step 3) and the task creation (Step 7). Determine if the persistence and rare connections represent a coherent multi-stage intrusion.",
        "description": "Combine the early triage results with follow-on persistence and network evidence to determine the final verdict.",
        "max_iterations": 5,
        "expected_signal": "A detailed timeline and malicious | benign verdict per host.",
        "success_criteria": "A verdict citing rows from all phases. The agent must comment on whether tasks were created shortly after a suspicious login."
      },
      "parents": [
        {
          "id": "scheduled-task-persistence",
          "kind": "merge"
        },
        {
          "id": "suspicious-network-connections",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on full verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the full-chain-assessment verdict identifies a malicious sequence of access, execution, and either persistence or C2 traffic, especially where the task was created shortly after login",
        "condition": "the full-chain-assessment verdict identifies a malicious sequence of access, execution, and either persistence or C2 traffic, especially where the task was created shortly after login",
        "blind_spot": "incomplete-telemetry-chain",
        "confidence": "high",
        "description": "Direct response based on the correlation of all four stages of the intrusion.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "full-chain-assessment"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate compromised endpoint",
      "config": {
        "target": "endpoint",
        "description": "Contain the threat by isolating the affected host and revoking credentials.",
        "instructions": "Isolate the host identified in the full-chain verdict and revoke active sessions for the involved administrator account.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Analyst final review",
      "config": {
        "assignee": "analyst",
        "description": "Review the correlated evidence and confirm the agent's findings for tuning or further response.",
        "instructions": "Examine the timeline constructed by the agent. Verify if the PowerShell script execution and scheduled task align with legitimate administrator maintenance or represent an intrusion. Confirm if the outbound IP is an unknown destination."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "hunt-closeout",
      "type": "task",
      "label": "Hunt close-out and documentation",
      "config": {
        "assignee": "analyst",
        "description": "Record the results of the hunt and document any observed visibility gaps.",
        "instructions": "Document the investigation findings. Record which hosts were identified and why others were excluded. List any rare destination IPs found for potential blocklisting."
      },
      "parents": [
        {
          "id": "analyst-review"
        }
      ]
    }
  ]
}