Detection of Phishing and Agent-Driven Exfiltration
An intruder has used a phishing attack to bypass multi-factor authentication and is now using compromised productivity applications to exfiltrate data over a C2 channel.
Based on research by Microsoft 2026-10-01 9 steps · 3 queries T1041 T1566
Brief
Why this hunt?
Microsoft recently shared Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026 (https://www.microsoft.com/en-us/security/blog/2026/09/30/secure-whats-next-your-guide-to-microsoft-security-at-microsoft-ignite-2026/), highlighting the evolution of identity threats. Attackers continue to find ways around multi-factor authentication, often using phishing to gain a foothold. This hunt addresses the need to see past the initial login and track what happens when an adversary uses local applications to steal data.
How the hunt flows
The hunt starts with a scoping phase focused on identity. It identifies successful logins where the authentication record shows that MFA was not used. By filtering for these specific sessions, the hunt creates a manageable list of users and source IPs to monitor for subsequent malicious behavior.
The second phase runs two queries in parallel to gather evidence of an active attack. The first query monitors process activity on the scoped hosts. It looks for rare child processes — specifically those that appear on three or fewer devices — that are launched by common productivity tools like Outlook, Word, or Teams. This isolates the execution of malicious payloads often delivered through phishing documents.
In parallel, the second query examines the network surface. It calculates the total volume of data sent to external, non-private IP addresses associated with the target users. By looking for high-volume egress, the hunt identifies potential exfiltration channels established by the attacker.
The final phase uses an agent to triage the collected data. The agent examines the suspicious sign-in, the rare process execution, and the high-volume network traffic. It determines if these events represent a coordinated attack chain, providing a clear verdict for the analyst.
What this hunt cannot see
This hunt is limited to hosts with active endpoint agents. If the phishing attack occurs on a host without telemetry, the process and local network activity will not be recorded. The results only cover the enrolled estate. Additionally, the hunt filters out internal IP traffic to maintain focus on external exfiltration. As a result, it will not detect an adversary who moves data laterally to an internal staging server before sending it out of the environment.
Steps
-
Identify successful sign-ins without MFA
Query · scopingFind successful authentications where multi-factor authentication was not recorded. These users serve as the primary focus for subsequent behavioral checks.
reads hb_auth_signinsqlSELECT actor_user_name, src_endpoint_ip, auth_protocol, device_hostname, time FROM hb_auth_signin WHERE status_id = 1 AND (mfa IS NULL OR LOWER(mfa) = 'false') AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. Login rows specifying a user and source IP. Silence suggests all successful logins within the period utilized MFA.
-
Rare child processes from productivity apps
Query · baselineIdentify unusual applications launched from productivity tools for the targeted users. This isolates execution typically associated with phishing payloads.
reads hb_process_activitysqlSELECT device_hostname, user_name, process_name, parent_process_name, process_cmd_line, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_process_activity WHERE instr(',' || '{{productivity_apps}}' || ',', ',' || LOWER(parent_process_name) || ',') > 0 AND NOT (instr(',' || '{{productivity_apps}}' || ',', ',' || LOWER(process_name) || ',') > 0) AND ('{{target_users}}' = '' OR instr(',' || '{{target_users}}' || ',', ',' || user_name || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_name HAVING host_count <= 3What a hit looks like. Rare child processes like cmd.exe or powershell.exe running under an office application for a user with suspicious sign-in activity.
-
High-volume external egress
Query · enrichmentDetect potential exfiltration by identifying large volumes of data sent to external IP addresses associated with the targeted users.
reads hb_network_connectionsqlSELECT device_hostname, user_name, dst_endpoint_ip, SUM(traffic_bytes) AS total_out_bytes, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_network_connection WHERE direction = 'outbound' AND ('{{target_users}}' = '' OR instr(',' || '{{target_users}}' || ',', ',' || user_name || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND NOT (dst_endpoint_ip LIKE '10.%' OR dst_endpoint_ip LIKE '192.168.%' OR dst_endpoint_ip LIKE '172.%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1, 2, 3 HAVING total_out_bytes > 5242880 ORDER BY total_out_bytes DESCWhat a hit looks like. Hosts with significant outbound traffic to external IPs that correlates with users identified in the scoping step.
-
Triage the attack chain
Agent triageThe agent correlates the anomalies across identity, process, and network telemetry to identify a confirmed intrusion.
-
Route on verdict
DecisionRoute the hunt based on the agent's findings.
-
Isolate host
Response actionContain the host to prevent further data loss.
-
Analyst review
Analyst taskConfirm the agent's verdict and investigate the nature of the exfiltrated data.
-
Close out
Analyst taskDocument findings and update defensive controls.
Coverage
Scenario coverage
| Stage | Covered | How, or why not |
|---|---|---|
| Phishing for Identity and Agent Access T1566 |
Yes | lead-signin-no-mfa, rare-child-process-spawn |
| Data Exfiltration over C2 Channel T1041 |
Yes | high-volume-external-egress |
Blind spots
- Needs an endpoint agent on every host in scope. A host without an agent provides no process or local network rows, so the result only covers the enrolled estate. It would answer whether the phishing execution occurred on a host without telemetry.
- Needs hb_smb_activity or internal flow logs. This hunt filters out internal IP traffic to reduce noise, missing lateral data staging. It would answer whether data was moved laterally to an internal relay before exfiltration.
Parameters & data
Parameters
| Parameter | Type | Default | What it is |
|---|---|---|---|
lookback_days | number | 14 | Days of history to examine. |
productivity_apps | list[string] | outlook.exe, msedge.exe, chrome.exe, teams.exe, winword.exe, excel.exe, powerpnt.exe | Filenames of applications often used as entry points for phishing. |
scope_hosts | list[host] | — | Optional list of hostnames to narrow the search; leave empty for the entire estate. |
target_users | list[string] | — | Users identified in the lead query; use these to focus subsequent parallel queries. |
Telemetry
| Source | Category | Telemetry |
|---|---|---|
| Endpoint telemetry (hb_ surfaces) | endpoint | endpoint |
| Identity / sign-in telemetry | identity | identity |
| Network telemetry | network | network |
Source
---
analysis: A single rule could fire on a large network transfer; this hunt correlates
that transfer with rare process execution and identity context to confirm a full
attack lifecycle.
blind_spots:
- id: no-endpoint-coverage
question: whether the phishing execution occurred on a host without telemetry
requires: an endpoint agent on every host in scope
risk: A host without an agent provides no process or local network rows, so the
result only covers the enrolled estate.
stage: initial-access-phishing
- id: internal-data-movement
question: whether data was moved laterally to an internal relay before exfiltration
requires: hb_smb_activity or internal flow logs
risk: This hunt filters out internal IP traffic to reduce noise, missing lateral
data staging.
stage: exfiltration-over-c2
coverage:
- stage: initial-access-phishing
status: covered
steps:
- lead-signin-no-mfa
- rare-child-process-spawn
- stage: exfiltration-over-c2
status: covered
steps:
- high-volume-external-egress
guardrails:
claims: no_unsupported
evidence: citation_required
missing_data: not_benign
telemetry: untrusted
hunt:
applicability: campaign-specific
handoff: keep-as-periodic-hunt
justification: Phishing and agent-driven exfiltration bypass traditional perimeter
defenses by abusing trusted identities; identifying these chains across surfaces
is a priority for data protection.
methodology: model-assisted
trigger: intel-report
hypothesis: An intruder has used a phishing attack to bypass multi-factor authentication
and is now using compromised productivity applications to exfiltrate data over a
C2 channel.
labels:
- hunt
- attack.t1566
- attack.t1041
- exfiltration
- initial access
name: Detection of Phishing and Agent-Driven Exfiltration
parameters:
lookback_days:
default: '14'
description: Days of history to examine.
from:
kind: manual
observed: '2026-09-30'
ref: standard-retention
type: number
productivity_apps:
default:
- outlook.exe
- msedge.exe
- chrome.exe
- teams.exe
- winword.exe
- excel.exe
- powerpnt.exe
description: Filenames of applications often used as entry points for phishing.
from:
kind: manual
observed: '2026-09-30'
ref: common-phishing-targets
type: list[string]
scope_hosts:
default: []
description: Optional list of hostnames to narrow the search; leave empty for
the entire estate.
from:
kind: manual
observed: '2026-09-30'
ref: analyst-scoping
type: list[host]
target_users:
default: []
description: Users identified in the lead query; use these to focus subsequent
parallel queries.
from:
kind: manual
observed: '2026-09-30'
ref: lead-step-pivot
type: list[string]
provenance:
authors:
- name: Huntbase hunt generation
org: huntbase.io
generated:
by: huntbase-hunt-generation
from: https://www.microsoft.com/en-us/security/blog/2026/09/30/secure-whats-next-your-guide-to-microsoft-security-at-microsoft-ignite-2026/
gates:
- dry-run
- lint
model: hb_google/gemini-3-flash-preview
rationale: Start with successful logins that bypassed MFA. Focusing on users with
high-volume egress reduces the initial scope to active sessions that may be exfiltrating
data.
references:
- name: "Microsoft Security - Secure what\u2019s next: Your guide to Microsoft Security\
\ at Microsoft Ignite 2026"
url: https://www.microsoft.com/en-us/security/blog/2026/09/30/secure-whats-next-your-guide-to-microsoft-security-at-microsoft-ignite-2026/
related:
- hunt: mfa-fatigue-and-lateral-movement
reason: MFA fatigue targets different user behaviors and uses lateral movement rather
than direct exfiltration from the entry point.
relation: out-of-scope-alternative
scenario:
stages:
- name: Phishing for Identity and Agent Access
observables:
- Attempts to bypass SMS MFA
- Delivery and execution of malicious attachments
- HTTP requests to phishing domains
- Compromise of local AI agents and identities
slug: initial-access-phishing
tactic: initial-access
techniques:
- T1566
- name: Data Exfiltration over C2 Channel
observables:
- Outbound network connections to external C2 servers
- Exfiltration of sensitive data using HTTP POST requests
- Persistent traffic to untrusted command-and-control infrastructure
- Access to sensitive files by compromised agents
slug: exfiltration-over-c2
tactic: exfiltration
techniques:
- T1041
summary: This attack scenario involves an initial breach via phishing to compromise
user identities or local AI agents, followed by the exfiltration of sensitive
data over established command-and-control (C2) channels. The campaign specifically
targets the unique permissions and access methods of non-human actors and agentic
systems, bypassing traditional alert-centric defenses.
severity: medium
targets:
analyst:
name: Tier-2 analyst
role: analyst
endpoint:
category: endpoint
name: Endpoint telemetry (hb_ surfaces)
telemetry:
- endpoint
hunter:
agent: true
name: Hunt agent
identity:
category: identity
name: Identity / sign-in telemetry
telemetry:
- identity
network:
category: network
name: Network telemetry
telemetry:
- network
tlp: clear
type: investigation
---
# Detection of Phishing and Agent-Driven Exfiltration
This hunt identifies the transition from initial access via phishing to data theft by correlating identity, process, and network telemetry. It first scopes the estate to successful logins where MFA was not utilized, then scans for rare child processes spawned from common productivity applications and high-volume outbound network traffic to external destinations. An agent weighs these independent signals to find a coordinated attack chain.
## lead-signin-no-mfa
<!-- Identify successful sign-ins without MFA -->
Find successful authentications where multi-factor authentication was not recorded. These users serve as the primary focus for subsequent behavioral checks.
```sqlite target=identity role=scoping params=(lookback_days=lookback_days)
~~~yaml
expected: Login rows specifying a user and source IP. Silence suggests all successful
logins within the period utilized MFA.
reads:
- actor_user_name
- src_endpoint_ip
- auth_protocol
- device_hostname
- time
- status_id
- mfa
silence: not_evidence_of_absence
source: hb_auth_signin
verified: dry-run
verified_at: '2026-10-01'
~~~
SELECT actor_user_name, src_endpoint_ip, auth_protocol, device_hostname, time FROM hb_auth_signin WHERE status_id = 1 AND (mfa IS NULL OR LOWER(mfa) = 'false') AND time >= datetime('now', '-{{lookback_days}} days')
```
## corroborate-attack
<!-- Corroborate attack with process and network anomalies -->
parallel:
- → rare-child-process-spawn
- → high-volume-external-egress
join: → triage-attack-chain
## rare-child-process-spawn
<!-- Rare child processes from productivity apps -->
Identify unusual applications launched from productivity tools for the targeted users. This isolates execution typically associated with phishing payloads.
```sqlite target=endpoint role=baseline params=(productivity_apps=productivity_apps, target_users=target_users, scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
baseline:
compare: first_seen
window: '{{lookback_days}}d'
expected: Rare child processes like cmd.exe or powershell.exe running under an office
application for a user with suspicious sign-in activity.
prevalence:
by: device_hostname
key:
- process_name
rare_below: 3
reads:
- device_hostname
- user_name
- process_name
- parent_process_name
- process_cmd_line
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-10-01'
~~~
SELECT device_hostname, user_name, process_name, parent_process_name, process_cmd_line, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_process_activity WHERE instr(',' || '{{productivity_apps}}' || ',', ',' || LOWER(parent_process_name) || ',') > 0 AND NOT (instr(',' || '{{productivity_apps}}' || ',', ',' || LOWER(process_name) || ',') > 0) AND ('{{target_users}}' = '' OR instr(',' || '{{target_users}}' || ',', ',' || user_name || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_name HAVING host_count <= 3
```
## high-volume-external-egress
<!-- High-volume external egress -->
Detect potential exfiltration by identifying large volumes of data sent to external IP addresses associated with the targeted users.
```sqlite target=network role=enrichment params=(target_users=target_users, scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: Hosts with significant outbound traffic to external IPs that correlates
with users identified in the scoping step.
reads:
- device_hostname
- user_name
- dst_endpoint_ip
- traffic_bytes
- direction
- time
silence: not_evidence_of_absence
source: hb_network_connection
verified: dry-run
verified_at: '2026-10-01'
~~~
SELECT device_hostname, user_name, dst_endpoint_ip, SUM(traffic_bytes) AS total_out_bytes, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_network_connection WHERE direction = 'outbound' AND ('{{target_users}}' = '' OR instr(',' || '{{target_users}}' || ',', ',' || user_name || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND NOT (dst_endpoint_ip LIKE '10.%' OR dst_endpoint_ip LIKE '192.168.%' OR dst_endpoint_ip LIKE '172.%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1, 2, 3 HAVING total_out_bytes > 5242880 ORDER BY total_out_bytes DESC
```
## triage-attack-chain
<!-- Triage the attack chain -->
```agent target=hunter
cite: required
context:
- lead-signin-no-mfa
- rare-child-process-spawn
- high-volume-external-egress
max_iterations: 6
objective: Determine if any host shows a coordinated sequence of suspicious sign-ins,
rare process execution from productivity apps, and high-volume exfiltration for
the same user.
success_criteria: A verdict of malicious, suspicious, or benign for each host, citing
specific rows from all three surfaces.
tools:
- endpoint
- identity
- network
```
## route-on-verdict
<!-- Route on verdict -->
if~: "the triage-attack-chain verdict is malicious for at least one host" (confidence: high, judge=hunter)
then: → isolate-host
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: no-endpoint-coverage)
else: → analyst-review
## isolate-host
<!-- Isolate host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host from the network immediately and collect the suspicious binary for analysis.
```
→ analyst-review
## analyst-review
<!-- Analyst review -->
```manual target=analyst
Review the cited rows from the triage step. Verify the source of the phishing email if possible and analyze the destination IP reputation. Determine the sensitivity of the data accessed by the process.
```
→ close-out
## close-out
<!-- Close out -->
```manual target=analyst
Record the indicators of compromise (IOCs) and report any MFA bypass techniques discovered. If the child process behavior is confirmed malicious, propose a standing detection rule for the SOC.
```
→ end
Run it
Take this hunt into your environment.
Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.
Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.