{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Chinese state-linked actors are documented to use the EBurst tool to target critical infrastructure for credential theft and mailbox exfiltration. Identifying these campaigns before they reach full data exfiltration prevents significant intelligence loss."
      },
      "name": "EBurst Password Spraying and Mailbox Exfiltration",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1110.003",
        "attack.t1110.001",
        "attack.t1041",
        "attack.t1190",
        "collection",
        "command and control",
        "credential access",
        "defense evasion",
        "execution",
        "initial access",
        "persistence"
      ],
      "series": {
        "slug": "chinese-government-linked-cyber-threat-actors-combine-automated-and-hands-on-hacking-tools-to-st",
        "index": 2,
        "title": "Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data",
        "total": 2
      },
      "related": [
        {
          "hunt": "softether-vpn-persistence-detection",
          "reason": "The same advisory identifies SoftEther VPN as a persistence mechanism used after credential theft.",
          "relation": "sibling"
        },
        {
          "hunt": "perimeter-exploitation-vpn-persistence",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        },
        "identity": {
          "name": "Identity / sign-in telemetry",
          "category": "identity",
          "telemetry": [
            "identity"
          ]
        }
      },
      "analysis": "While a detection rule might alert on a single high-volume spray from an IP, this hunt correlates that spraying behavior across multiple distinct Exchange interfaces with follow-on cloud API operations against mailboxes, reducing noise and identifying the complete attack chain.",
      "coverage": [
        {
          "stage": "credential-access-eburst-spraying",
          "steps": [
            "scoping-exchange-auth",
            "ip-spray-detection"
          ],
          "status": "covered"
        },
        {
          "stage": "collection-mailbox-exfiltration",
          "steps": [
            "mailbox-api-activity"
          ],
          "status": "covered"
        },
        {
          "stage": "initial-access-vulnerability-exploitation",
          "reason": "Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "execution-malware-payload",
          "reason": "Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "persistence-vpn-installation",
          "reason": "Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "defence-evasion-masquerading",
          "reason": "Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "command-and-control-obfuscated-channels",
          "reason": "Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Web and Service Exploitation",
            "slug": "initial-access-vulnerability-exploitation",
            "tactic": "initial-access",
            "techniques": [
              "T1190",
              "T1189"
            ],
            "observables": [
              "BBScan",
              "dirsearch",
              "Fscan",
              "ksubdomain",
              "masscan",
              "NMAP",
              "OneForAll",
              "ShuiZe",
              "wpscan",
              "MicroScan",
              "XSS payloads targeting JavaScript",
              "Exploits for CVE-2016-3081",
              "Exploits for CVE-2019-11510",
              "Exploits for CVE-2021-22205",
              "Targeting ports 21, 22, 53, 80, 443, 1080",
              "PHP/ASP enumeration"
            ]
          },
          {
            "name": "Malware Execution",
            "slug": "execution-malware-payload",
            "tactic": "execution",
            "techniques": [
              "T1059.006",
              "T1059.007",
              "T1059.001"
            ],
            "observables": [
              "live700_v1.exe",
              "DiagTrack.exe",
              "Python-based exploit scripts",
              "Go-based exploit utilities",
              "Password-protected .zip files containing executables"
            ]
          },
          {
            "name": "VPN-based Persistence",
            "slug": "persistence-vpn-installation",
            "tactic": "persistence",
            "techniques": [
              "T1133"
            ],
            "observables": [
              "SoftEther VPN installers",
              "conhost.exe (renamed installer)",
              "dllhost.exe (renamed installer)",
              "curl or wget used to download SoftEther on Linux",
              "PowerShell used to download SoftEther on Windows",
              "Automatic reconnection configuration on startup"
            ]
          },
          {
            "name": "Service and Process Masquerading",
            "slug": "defence-evasion-masquerading",
            "tactic": "defence-evasion",
            "techniques": [
              "T1036.003"
            ],
            "observables": [
              "DiagTrack.exe",
              "conhost.exe",
              "dllhost.exe"
            ]
          },
          {
            "name": "EBurst Password Spraying",
            "slug": "credential-access-eburst-spraying",
            "tactic": "credential-access",
            "techniques": [
              "T1110.003",
              "T1110.001"
            ],
            "observables": [
              "EBurst tool",
              "Password spraying against ECP",
              "Password spraying against EWS",
              "Password spraying against OWA",
              "Password spraying against ActiveSync",
              "Password spraying against MAPI/RPC"
            ]
          },
          {
            "name": "Multi-protocol Command and Control",
            "slug": "command-and-control-obfuscated-channels",
            "tactic": "command-and-control",
            "techniques": [
              "T1071"
            ],
            "observables": [
              "dns.studiocloud.xyz",
              "98aiblog.com",
              "hmbcloud.com",
              "hmbcloud.net",
              "hmbiplc-01.com",
              "iepl.node.cm",
              "javacheck.ooguy.com",
              "javaupdate.giize.com",
              "sexytube0.com",
              "twimg.co.uk",
              "HTTP-based C2 communications"
            ]
          },
          {
            "name": "Email Data Collection",
            "slug": "collection-mailbox-exfiltration",
            "tactic": "collection",
            "techniques": [
              "T1041"
            ],
            "observables": [
              "Querying user mailbox data via DiagTrack.exe"
            ]
          }
        ],
        "summary": "Chinese government-linked threat actors, enabled by Integrity Technology Group, use a combination of automated scanning tools like MicroScan and manual exploitation to target global organizations. They establish persistence using legitimate VPN software like SoftEther and perform large-scale password spraying with EBurst to exfiltrate sensitive email data and credentials."
      },
      "severity": "high",
      "rationale": "Focus on high-value identity targets and servers hosting publicly accessible Exchange interfaces (OWA, ActiveSync). Monitoring the Autodiscover service is critical as it is a common target for the EBurst tool.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary is conducting automated password spraying via the EBurst tool against Exchange interfaces and then using successful logins to exfiltrate mailbox data via cloud APIs.",
      "parameters": {
        "scope_hosts": {
          "from": {
            "ref": "analyst-defined",
            "kind": "manual",
            "observed": "2024-01-01"
          },
          "type": "list[host]",
          "default": [],
          "description": "Exchange servers or endpoints identified in the scoping step to focus the hunt."
        },
        "lookback_days": {
          "from": {
            "ref": "standard-retention",
            "kind": "manual",
            "observed": "2024-01-01"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "exchange_interfaces": {
          "from": {
            "ref": "AA26-281A",
            "kind": "article",
            "observed": "2026-10-08"
          },
          "type": "list[string]",
          "default": [
            "ECP",
            "EWS",
            "OAB",
            "OWA",
            "RPC",
            "API",
            "MAPI",
            "Autodiscover",
            "ActiveSync"
          ],
          "description": "Names of Exchange interfaces to monitor for password spraying."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a",
          "name": "CISA AA26-281A - Chinese Government-linked Cyber Threat Actors"
        }
      ],
      "blind_spots": [
        {
          "id": "cloud-logging-limitations",
          "risk": "Without Advanced Auditing, the API logs only show that a mailbox was accessed, not which specific items were viewed or exported, making it difficult to assess the exact impact of exfiltration.",
          "owner": "Cloud Infrastructure Team",
          "stage": "collection-mailbox-exfiltration",
          "question": "Which specific email messages were read by the adversary?",
          "requires": "Microsoft 365 Advanced Auditing (MailItemsAccessed)",
          "remediation": "Enable 'MailItemsAccessed' auditing for all critical mailboxes."
        },
        {
          "id": "ip-masking-via-botnets",
          "risk": "If the adversary rotates IPs for every single login attempt, the per-IP unique user stack-count will fall below the detection threshold.",
          "owner": "Security Engineering",
          "stage": "credential-access-eburst-spraying",
          "question": "Is the spray originating from a known botnet or common VPN providers?",
          "requires": "Source IP Geolocation and ASN context",
          "remediation": "Pivot to user-agent and ASN stacking if per-IP spraying metrics are low."
        }
      ]
    },
    "name": "EBurst Password Spraying and Mailbox Exfiltration",
    "description": "This hunt targets the identity-focused tradecraft of Chinese government-linked actors. It begins by identifying Exchange endpoints experiencing high authentication failure rates, then fans out to identify specific source IPs conducting distributed password sprays across multiple accounts. Finally, it correlates these IPs with unusual mailbox-related API activity in the cloud control plane to detect post-compromise data collection and exfiltration."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "chinese-government-linked-cyber-threat-actors-combine-automated-and-hands-on-hacking-tools-to-st",
          "index": 2,
          "title": "Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data",
          "total": 2
        },
        "coverage": [
          {
            "stage": "credential-access-eburst-spraying",
            "steps": [
              "scoping-exchange-auth",
              "ip-spray-detection"
            ],
            "status": "covered"
          },
          {
            "stage": "collection-mailbox-exfiltration",
            "steps": [
              "mailbox-api-activity"
            ],
            "status": "covered"
          },
          {
            "stage": "initial-access-vulnerability-exploitation",
            "reason": "Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "execution-malware-payload",
            "reason": "Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "persistence-vpn-installation",
            "reason": "Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "defence-evasion-masquerading",
            "reason": "Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "command-and-control-obfuscated-channels",
            "reason": "Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary is conducting automated password spraying via the EBurst tool against Exchange interfaces and then using successful logins to exfiltrate mailbox data via cloud APIs.",
        "blind_spots": [
          {
            "id": "cloud-logging-limitations",
            "risk": "Without Advanced Auditing, the API logs only show that a mailbox was accessed, not which specific items were viewed or exported, making it difficult to assess the exact impact of exfiltration.",
            "owner": "Cloud Infrastructure Team",
            "stage": "collection-mailbox-exfiltration",
            "question": "Which specific email messages were read by the adversary?",
            "requires": "Microsoft 365 Advanced Auditing (MailItemsAccessed)",
            "remediation": "Enable 'MailItemsAccessed' auditing for all critical mailboxes."
          },
          {
            "id": "ip-masking-via-botnets",
            "risk": "If the adversary rotates IPs for every single login attempt, the per-IP unique user stack-count will fall below the detection threshold.",
            "owner": "Security Engineering",
            "stage": "credential-access-eburst-spraying",
            "question": "Is the spray originating from a known botnet or common VPN providers?",
            "requires": "Source IP Geolocation and ASN context",
            "remediation": "Pivot to user-agent and ASN stacking if per-IP spraying metrics are low."
          }
        ],
        "scoping_notes": "Focus on high-value identity targets and servers hosting publicly accessible Exchange interfaces (OWA, ActiveSync). Monitoring the Autodiscover service is critical as it is a common target for the EBurst tool.",
        "beyond_detection": "While a detection rule might alert on a single high-volume spray from an IP, this hunt correlates that spraying behavior across multiple distinct Exchange interfaces with follow-on cloud API operations against mailboxes, reducing noise and identifying the complete attack chain."
      }
    },
    {
      "id": "scoping-exchange-auth",
      "type": "query",
      "label": "Scoping Exchange Auth Failures",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "identity",
        "content": "SELECT device_hostname, COUNT(*) AS failure_count, MIN(time) AS first_fail, MAX(time) AS last_fail FROM hb_auth_signin WHERE status_id = 2 AND (instr(',' || '{{exchange_interfaces}}' || ',', ',' || UPPER(dst_endpoint_name) || ',') > 0 OR LOWER(service_name) LIKE '%exchange%' OR LOWER(logon_process_name) LIKE '%exchange%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname HAVING failure_count > 20 ORDER BY failure_count DESC",
        "surface": "hb_auth_signin",
        "description": "Identify Exchange servers or endpoints experiencing an unusual volume of authentication failures to narrow the hunt scope. Note: Populate the scope_hosts parameter with the hostnames discovered here for use in the subsequent ip-spray-detection step.",
        "expected_signal": "A list of hosts acting as targets for auth failures. Silence suggests no broad spraying against Exchange targets is currently observable."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Scoping Exchange Auth Failures",
        "reads": [
          "device_hostname",
          "dst_endpoint_name",
          "logon_process_name",
          "service_name",
          "status_id",
          "time"
        ],
        "source": "hb_auth_signin",
        "target": "identity",
        "content": "SELECT device_hostname, COUNT(*) AS failure_count, MIN(time) AS first_fail, MAX(time) AS last_fail FROM hb_auth_signin WHERE status_id = 2 AND (instr(',' || '{{exchange_interfaces}}' || ',', ',' || UPPER(dst_endpoint_name) || ',') > 0 OR LOWER(service_name) LIKE '%exchange%' OR LOWER(logon_process_name) LIKE '%exchange%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname HAVING failure_count > 20 ORDER BY failure_count DESC",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hosts acting as targets for auth failures. Silence suggests no broad spraying against Exchange targets is currently observable.",
        "verified": "dry-run",
        "verified_at": "2026-10-09"
      }
    },
    {
      "id": "ip-spray-detection",
      "type": "query",
      "label": "IP-based Password Spraying Detection",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "identity",
        "content": "SELECT src_endpoint_ip, COUNT(DISTINCT actor_user_name) AS unique_targets, COUNT(*) AS total_attempts, MIN(time) AS start_time FROM hb_auth_signin WHERE status_id = 2 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY src_endpoint_ip HAVING unique_targets >= 5 ORDER BY unique_targets DESC",
        "surface": "hb_auth_signin",
        "description": "Find source IPs attempting to authenticate against multiple unique user accounts.",
        "expected_signal": "A few IPs targeting multiple unique users. Benign noise typically targets one user many times."
      },
      "parents": [
        {
          "id": "scoping-exchange-auth"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "IP-based Password Spraying Detection",
        "reads": [
          "actor_user_name",
          "device_hostname",
          "src_endpoint_ip",
          "status_id",
          "time"
        ],
        "source": "hb_auth_signin",
        "target": "identity",
        "content": "SELECT src_endpoint_ip, COUNT(DISTINCT actor_user_name) AS unique_targets, COUNT(*) AS total_attempts, MIN(time) AS start_time FROM hb_auth_signin WHERE status_id = 2 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY src_endpoint_ip HAVING unique_targets >= 5 ORDER BY unique_targets DESC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A few IPs targeting multiple unique users. Benign noise typically targets one user many times.",
        "verified": "dry-run",
        "prevalence": {
          "by": "actor_user_name",
          "key": [
            "src_endpoint_ip"
          ],
          "rare_below": 5
        },
        "verified_at": "2026-10-09"
      }
    },
    {
      "id": "mailbox-api-activity",
      "type": "query",
      "label": "Unusual Mailbox API Operations",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT src_endpoint_ip, actor_user_name, api_operation, api_service_name, resource_name, COUNT(*) AS call_count FROM hb_cloud_api_activity WHERE (provider = 'm365' OR api_service_name = 'Exchange') AND (LOWER(api_operation) LIKE '%mailbox%' OR LOWER(api_operation) LIKE '%message%' OR LOWER(api_operation) LIKE '%folder%') AND activity_id IN (2, 3) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY src_endpoint_ip, actor_user_name, api_operation, api_service_name, resource_name HAVING call_count > 10 ORDER BY call_count DESC",
        "surface": "hb_cloud_api_activity",
        "description": "Identify API activity targeting mailbox resources, specifically high-volume read or update operations.",
        "expected_signal": "High frequency of API calls targeting mailbox data per IP and account. This identifies post-auth data access."
      },
      "parents": [
        {
          "id": "scoping-exchange-auth"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Unusual Mailbox API Operations",
        "reads": [
          "activity_id",
          "actor_user_name",
          "api_operation",
          "api_service_name",
          "provider",
          "resource_name",
          "src_endpoint_ip",
          "time"
        ],
        "source": "hb_cloud_api_activity",
        "target": "endpoint",
        "content": "SELECT src_endpoint_ip, actor_user_name, api_operation, api_service_name, resource_name, COUNT(*) AS call_count FROM hb_cloud_api_activity WHERE (provider = 'm365' OR api_service_name = 'Exchange') AND (LOWER(api_operation) LIKE '%mailbox%' OR LOWER(api_operation) LIKE '%message%' OR LOWER(api_operation) LIKE '%folder%') AND activity_id IN (2, 3) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY src_endpoint_ip, actor_user_name, api_operation, api_service_name, resource_name HAVING call_count > 10 ORDER BY call_count DESC",
        "silence": "not_evidence_of_absence",
        "expected": "High frequency of API calls targeting mailbox data per IP and account. This identifies post-auth data access.",
        "verified": "dry-run",
        "verified_at": "2026-10-09"
      }
    },
    {
      "id": "triage-investigation",
      "type": "analytic",
      "label": "Triage Auth and API Correlation",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity"
        ],
        "context": [
          "scoping-exchange-auth",
          "ip-spray-detection",
          "mailbox-api-activity"
        ],
        "objective": "Identify if any IP conducting a spray in the auth logs matches an IP performing mailbox API operations. Determine if the accounts targeted in the spray were successfully used for API access.",
        "description": "Evaluate whether the observed auth failures, password sprays, and mailbox API activities constitute a confirmed compromise.",
        "max_iterations": 6,
        "expected_signal": "A per-IP and per-account verdict confirming malicious activity based on technical evidence.",
        "success_criteria": "A verdict of malicious | suspicious | benign citing specific rows for each host and account."
      },
      "parents": [
        {
          "id": "ip-spray-detection",
          "kind": "merge"
        },
        {
          "id": "mailbox-api-activity",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on Triage Verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage verdict is malicious for at least one source IP and account pair",
        "condition": "the triage verdict is malicious for at least one source IP and account pair",
        "blind_spot": "cloud-logging-limitations",
        "confidence": "high",
        "description": "Route the hunt based on the agent's maliciousness verdict.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-investigation"
        }
      ]
    },
    {
      "id": "suspend-identity",
      "type": "action",
      "label": "Suspend Compromised Identity",
      "config": {
        "target": "identity",
        "description": "Immediately halt further data exfiltration by suspending the affected account.",
        "instructions": "Suspend the user account identified as compromised and revoke all active OAuth/MFA tokens.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Analyst Review of Exfiltration",
      "config": {
        "assignee": "analyst",
        "description": "Conduct a manual review of the data accessed to determine the scope of exfiltration.",
        "instructions": "Review the specific 'resource_name' entries in the mailbox API query. Identify if any mailbox redirection rules or auto-forwarding was configured by the attacker for persistence."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "suspend-identity"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Hunt Close-out",
      "config": {
        "assignee": "analyst",
        "description": "Finalize the hunt and document any tuning notes for future detection rules.",
        "instructions": "Document the findings. If benign scanning IPs were found, recommend them for a global exclusion list to reduce future false positives."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "analyst-review"
        }
      ]
    }
  ]
}