{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Phishing and agent-driven exfiltration bypass traditional perimeter defenses by abusing trusted identities; identifying these chains across surfaces is a priority for data protection."
      },
      "name": "Detection of Phishing and Agent-Driven Exfiltration",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1566",
        "attack.t1041",
        "exfiltration",
        "initial access"
      ],
      "related": [
        {
          "hunt": "mfa-fatigue-and-lateral-movement",
          "reason": "MFA fatigue targets different user behaviors and uses lateral movement rather than direct exfiltration from the entry point.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "network": {
          "name": "Network telemetry",
          "category": "network",
          "telemetry": [
            "network"
          ]
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        },
        "identity": {
          "name": "Identity / sign-in telemetry",
          "category": "identity",
          "telemetry": [
            "identity"
          ]
        }
      },
      "analysis": "A single rule could fire on a large network transfer; this hunt correlates that transfer with rare process execution and identity context to confirm a full attack lifecycle.",
      "coverage": [
        {
          "stage": "initial-access-phishing",
          "steps": [
            "lead-signin-no-mfa",
            "rare-child-process-spawn"
          ],
          "status": "covered"
        },
        {
          "stage": "exfiltration-over-c2",
          "steps": [
            "high-volume-external-egress"
          ],
          "status": "covered"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Phishing for Identity and Agent Access",
            "slug": "initial-access-phishing",
            "tactic": "initial-access",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "Attempts to bypass SMS MFA",
              "Delivery and execution of malicious attachments",
              "HTTP requests to phishing domains",
              "Compromise of local AI agents and identities"
            ]
          },
          {
            "name": "Data Exfiltration over C2 Channel",
            "slug": "exfiltration-over-c2",
            "tactic": "exfiltration",
            "techniques": [
              "T1041"
            ],
            "observables": [
              "Outbound network connections to external C2 servers",
              "Exfiltration of sensitive data using HTTP POST requests",
              "Persistent traffic to untrusted command-and-control infrastructure",
              "Access to sensitive files by compromised agents"
            ]
          }
        ],
        "summary": "This attack scenario involves an initial breach via phishing to compromise user identities or local AI agents, followed by the exfiltration of sensitive data over established command-and-control (C2) channels. The campaign specifically targets the unique permissions and access methods of non-human actors and agentic systems, bypassing traditional alert-centric defenses."
      },
      "severity": "medium",
      "rationale": "Start with successful logins that bypassed MFA. Focusing on users with high-volume egress reduces the initial scope to active sessions that may be exfiltrating data.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An intruder has used a phishing attack to bypass multi-factor authentication and is now using compromised productivity applications to exfiltrate data over a C2 channel.",
      "parameters": {
        "scope_hosts": {
          "from": {
            "ref": "analyst-scoping",
            "kind": "manual",
            "observed": "2026-09-30"
          },
          "type": "list[host]",
          "default": [],
          "description": "Optional list of hostnames to narrow the search; leave empty for the entire estate."
        },
        "target_users": {
          "from": {
            "ref": "lead-step-pivot",
            "kind": "manual",
            "observed": "2026-09-30"
          },
          "type": "list[string]",
          "default": [],
          "description": "Users identified in the lead query; use these to focus subsequent parallel queries."
        },
        "lookback_days": {
          "from": {
            "ref": "standard-retention",
            "kind": "manual",
            "observed": "2026-09-30"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "productivity_apps": {
          "from": {
            "ref": "common-phishing-targets",
            "kind": "manual",
            "observed": "2026-09-30"
          },
          "type": "list[string]",
          "default": [
            "outlook.exe",
            "msedge.exe",
            "chrome.exe",
            "teams.exe",
            "winword.exe",
            "excel.exe",
            "powerpnt.exe"
          ],
          "description": "Filenames of applications often used as entry points for phishing."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.microsoft.com/en-us/security/blog/2026/09/30/secure-whats-next-your-guide-to-microsoft-security-at-microsoft-ignite-2026/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.microsoft.com/en-us/security/blog/2026/09/30/secure-whats-next-your-guide-to-microsoft-security-at-microsoft-ignite-2026/",
          "name": "Microsoft Security - Secure what\u2019s next: Your guide to Microsoft Security at Microsoft Ignite 2026"
        }
      ],
      "blind_spots": [
        {
          "id": "no-endpoint-coverage",
          "risk": "A host without an agent provides no process or local network rows, so the result only covers the enrolled estate.",
          "stage": "initial-access-phishing",
          "question": "whether the phishing execution occurred on a host without telemetry",
          "requires": "an endpoint agent on every host in scope"
        },
        {
          "id": "internal-data-movement",
          "risk": "This hunt filters out internal IP traffic to reduce noise, missing lateral data staging.",
          "stage": "exfiltration-over-c2",
          "question": "whether data was moved laterally to an internal relay before exfiltration",
          "requires": "hb_smb_activity or internal flow logs"
        }
      ]
    },
    "name": "Detection of Phishing and Agent-Driven Exfiltration",
    "description": "This hunt identifies the transition from initial access via phishing to data theft by correlating identity, process, and network telemetry. It first scopes the estate to successful logins where MFA was not utilized, then scans for rare child processes spawned from common productivity applications and high-volume outbound network traffic to external destinations. An agent weighs these independent signals to find a coordinated attack chain."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "coverage": [
          {
            "stage": "initial-access-phishing",
            "steps": [
              "lead-signin-no-mfa",
              "rare-child-process-spawn"
            ],
            "status": "covered"
          },
          {
            "stage": "exfiltration-over-c2",
            "steps": [
              "high-volume-external-egress"
            ],
            "status": "covered"
          }
        ],
        "rationale": "An intruder has used a phishing attack to bypass multi-factor authentication and is now using compromised productivity applications to exfiltrate data over a C2 channel.",
        "blind_spots": [
          {
            "id": "no-endpoint-coverage",
            "risk": "A host without an agent provides no process or local network rows, so the result only covers the enrolled estate.",
            "stage": "initial-access-phishing",
            "question": "whether the phishing execution occurred on a host without telemetry",
            "requires": "an endpoint agent on every host in scope"
          },
          {
            "id": "internal-data-movement",
            "risk": "This hunt filters out internal IP traffic to reduce noise, missing lateral data staging.",
            "stage": "exfiltration-over-c2",
            "question": "whether data was moved laterally to an internal relay before exfiltration",
            "requires": "hb_smb_activity or internal flow logs"
          }
        ],
        "scoping_notes": "Start with successful logins that bypassed MFA. Focusing on users with high-volume egress reduces the initial scope to active sessions that may be exfiltrating data.",
        "beyond_detection": "A single rule could fire on a large network transfer; this hunt correlates that transfer with rare process execution and identity context to confirm a full attack lifecycle."
      }
    },
    {
      "id": "lead-signin-no-mfa",
      "type": "query",
      "label": "Identify successful sign-ins without MFA",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "identity",
        "content": "SELECT actor_user_name, src_endpoint_ip, auth_protocol, device_hostname, time FROM hb_auth_signin WHERE status_id = 1 AND (mfa IS NULL OR LOWER(mfa) = 'false') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_auth_signin",
        "description": "Find successful authentications where multi-factor authentication was not recorded. These users serve as the primary focus for subsequent behavioral checks.",
        "expected_signal": "Login rows specifying a user and source IP. Silence suggests all successful logins within the period utilized MFA."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify successful sign-ins without MFA",
        "reads": [
          "actor_user_name",
          "src_endpoint_ip",
          "auth_protocol",
          "device_hostname",
          "time",
          "status_id",
          "mfa"
        ],
        "source": "hb_auth_signin",
        "target": "identity",
        "content": "SELECT actor_user_name, src_endpoint_ip, auth_protocol, device_hostname, time FROM hb_auth_signin WHERE status_id = 1 AND (mfa IS NULL OR LOWER(mfa) = 'false') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Login rows specifying a user and source IP. Silence suggests all successful logins within the period utilized MFA.",
        "verified": "dry-run",
        "verified_at": "2026-10-01"
      }
    },
    {
      "id": "rare-child-process-spawn",
      "type": "query",
      "label": "Rare child processes from productivity apps",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT device_hostname, user_name, process_name, parent_process_name, process_cmd_line, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_process_activity WHERE instr(',' || '{{productivity_apps}}' || ',', ',' || LOWER(parent_process_name) || ',') > 0 AND NOT (instr(',' || '{{productivity_apps}}' || ',', ',' || LOWER(process_name) || ',') > 0) AND ('{{target_users}}' = '' OR instr(',' || '{{target_users}}' || ',', ',' || user_name || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_name HAVING host_count <= 3",
        "surface": "hb_process_activity",
        "description": "Identify unusual applications launched from productivity tools for the targeted users. This isolates execution typically associated with phishing payloads.",
        "expected_signal": "Rare child processes like cmd.exe or powershell.exe running under an office application for a user with suspicious sign-in activity."
      },
      "parents": [
        {
          "id": "lead-signin-no-mfa"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare child processes from productivity apps",
        "reads": [
          "device_hostname",
          "user_name",
          "process_name",
          "parent_process_name",
          "process_cmd_line",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, user_name, process_name, parent_process_name, process_cmd_line, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_process_activity WHERE instr(',' || '{{productivity_apps}}' || ',', ',' || LOWER(parent_process_name) || ',') > 0 AND NOT (instr(',' || '{{productivity_apps}}' || ',', ',' || LOWER(process_name) || ',') > 0) AND ('{{target_users}}' = '' OR instr(',' || '{{target_users}}' || ',', ',' || user_name || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_name HAVING host_count <= 3",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Rare child processes like cmd.exe or powershell.exe running under an office application for a user with suspicious sign-in activity.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_name"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-10-01"
      }
    },
    {
      "id": "high-volume-external-egress",
      "type": "query",
      "label": "High-volume external egress",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "network",
        "content": "SELECT device_hostname, user_name, dst_endpoint_ip, SUM(traffic_bytes) AS total_out_bytes, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_network_connection WHERE direction = 'outbound' AND ('{{target_users}}' = '' OR instr(',' || '{{target_users}}' || ',', ',' || user_name || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND NOT (dst_endpoint_ip LIKE '10.%' OR dst_endpoint_ip LIKE '192.168.%' OR dst_endpoint_ip LIKE '172.%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1, 2, 3 HAVING total_out_bytes > 5242880 ORDER BY total_out_bytes DESC",
        "surface": "hb_network_connection",
        "description": "Detect potential exfiltration by identifying large volumes of data sent to external IP addresses associated with the targeted users.",
        "expected_signal": "Hosts with significant outbound traffic to external IPs that correlates with users identified in the scoping step."
      },
      "parents": [
        {
          "id": "lead-signin-no-mfa"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "High-volume external egress",
        "reads": [
          "device_hostname",
          "user_name",
          "dst_endpoint_ip",
          "traffic_bytes",
          "direction",
          "time"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT device_hostname, user_name, dst_endpoint_ip, SUM(traffic_bytes) AS total_out_bytes, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_network_connection WHERE direction = 'outbound' AND ('{{target_users}}' = '' OR instr(',' || '{{target_users}}' || ',', ',' || user_name || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND NOT (dst_endpoint_ip LIKE '10.%' OR dst_endpoint_ip LIKE '192.168.%' OR dst_endpoint_ip LIKE '172.%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1, 2, 3 HAVING total_out_bytes > 5242880 ORDER BY total_out_bytes DESC",
        "silence": "not_evidence_of_absence",
        "expected": "Hosts with significant outbound traffic to external IPs that correlates with users identified in the scoping step.",
        "verified": "dry-run",
        "verified_at": "2026-10-01"
      }
    },
    {
      "id": "triage-attack-chain",
      "type": "analytic",
      "label": "Triage the attack chain",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity",
          "network"
        ],
        "context": [
          "lead-signin-no-mfa",
          "rare-child-process-spawn",
          "high-volume-external-egress"
        ],
        "objective": "Determine if any host shows a coordinated sequence of suspicious sign-ins, rare process execution from productivity apps, and high-volume exfiltration for the same user.",
        "description": "The agent correlates the anomalies across identity, process, and network telemetry to identify a confirmed intrusion.",
        "max_iterations": 6,
        "expected_signal": "Per-host verdicts indicating whether the observed telemetry constitutes a coordinated attack.",
        "success_criteria": "A verdict of malicious, suspicious, or benign for each host, citing specific rows from all three surfaces."
      },
      "parents": [
        {
          "id": "rare-child-process-spawn",
          "kind": "merge"
        },
        {
          "id": "high-volume-external-egress",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage-attack-chain verdict is malicious for at least one host",
        "condition": "the triage-attack-chain verdict is malicious for at least one host",
        "blind_spot": "no-endpoint-coverage",
        "confidence": "high",
        "description": "Route the hunt based on the agent's findings.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-attack-chain"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate host",
      "config": {
        "target": "endpoint",
        "description": "Contain the host to prevent further data loss.",
        "instructions": "Isolate the host from the network immediately and collect the suspicious binary for analysis.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Analyst review",
      "config": {
        "assignee": "analyst",
        "description": "Confirm the agent's verdict and investigate the nature of the exfiltrated data.",
        "instructions": "Review the cited rows from the triage step. Verify the source of the phishing email if possible and analyze the destination IP reputation. Determine the sensitivity of the data accessed by the process."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out",
      "config": {
        "assignee": "analyst",
        "description": "Document findings and update defensive controls.",
        "instructions": "Record the indicators of compromise (IOCs) and report any MFA bypass techniques discovered. If the child process behavior is confirmed malicious, propose a standing detection rule for the SOC."
      },
      "parents": [
        {
          "id": "analyst-review"
        }
      ]
    }
  ]
}