{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Ransomware remains the highest risk to SMBs, and 'BYOVD' (Bring Your Own Vulnerable Driver) is a primary method used to disable the protection these companies rely on. This hunt catches the transition from theft to impact."
      },
      "name": "EDR Impairment and Ransomware Impact",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1555",
        "attack.t1562.001",
        "attack.t1486",
        "attack.t1041",
        "credential access",
        "defense evasion",
        "execution",
        "impact",
        "initial access"
      ],
      "series": {
        "slug": "the-smb-cybersecurity-squeeze-ai-agents-at-work-old-attacks-in-overdrive",
        "index": 2,
        "title": "The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive",
        "total": 2
      },
      "related": [
        {
          "hunt": "phishing-ai-enhanced-social-engineering",
          "reason": "The initial access via AI-enhanced phishing is handled in a separate hunt in this series.",
          "relation": "out-of-scope-alternative"
        },
        {
          "hunt": "ai-agent-social-engineering-access",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A simple rule for unsigned drivers would fire too often on development tools. This hunt combines that signal with the lead (credential theft) and the aftermath (mass file activity) to provide the necessary context for high-confidence host isolation.",
      "coverage": [
        {
          "stage": "credential-access-password-stores",
          "steps": [
            "credential-store-access"
          ],
          "status": "covered"
        },
        {
          "stage": "evasion-vulnerable-driver-edr-killer",
          "steps": [
            "driver-load-check"
          ],
          "status": "covered"
        },
        {
          "stage": "impact-ransomware-data-exfiltration",
          "steps": [
            "high-volume-file-activity"
          ],
          "status": "covered"
        },
        {
          "stage": "phishing-ai-enhanced-social-engineering",
          "reason": "Belongs to another part of the 'The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "initial-access-malicious-ai-skills",
          "reason": "Belongs to another part of the 'The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "exploit-public-facing-rapid-cve",
          "reason": "Belongs to another part of the 'The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "execution-indirect-prompt-injection",
          "reason": "Belongs to another part of the 'The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "AI-Enhanced Phishing and ClickFix",
            "slug": "phishing-ai-enhanced-social-engineering",
            "tactic": "initial-access",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "QR codes in phishing emails",
              "Fake AI troubleshooting error messages",
              "AI-generated lures with high click-through rates",
              "ClickFix prompts asking users to paste commands"
            ]
          },
          {
            "name": "AI Agent Supply Chain Compromise",
            "slug": "initial-access-malicious-ai-skills",
            "tactic": "initial-access",
            "techniques": [
              "T1195"
            ],
            "observables": [
              "Installation of malicious 'skills' from public repositories",
              "Malicious MCP (Model Context Protocol) server connections",
              "AI agent 'rug pull' behavior where a tool morphs into an infostealer"
            ]
          },
          {
            "name": "Rapid Vulnerability Exploitation",
            "slug": "exploit-public-facing-rapid-cve",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "Exploitation of known vulnerabilities on or before disclosure day",
              "Scanning for vulnerable software libraries invented by LLM hallucinations"
            ]
          },
          {
            "name": "Indirect Prompt Injection and Terminal Execution",
            "slug": "execution-indirect-prompt-injection",
            "tactic": "execution",
            "techniques": [
              "T1203"
            ],
            "observables": [
              "EchoLeak-style data exposure in Microsoft 365 Copilot",
              "Users pasting commands into terminals following ClickFix lures",
              "Malicious instructions retrieved by agents from webpages or emails"
            ]
          },
          {
            "name": "Credential Theft via Infostealer",
            "slug": "credential-access-password-stores",
            "tactic": "credential-access",
            "techniques": [
              "T1555"
            ],
            "observables": [
              "Access to browser password databases",
              "Phishing-as-a-service kits capturing login credentials",
              "Infostealer malware execution"
            ]
          },
          {
            "name": "EDR Impairment via Vulnerable Drivers",
            "slug": "evasion-vulnerable-driver-edr-killer",
            "tactic": "defense-evasion",
            "techniques": [
              "T1562.001"
            ],
            "observables": [
              "Loading of known vulnerable drivers (BYOVD)",
              "Tools designed to kill EDR processes",
              "Abuse of legitimate drivers to gain kernel-level access"
            ]
          },
          {
            "name": "Data Encryption and Exfiltration",
            "slug": "impact-ransomware-data-exfiltration",
            "tactic": "impact",
            "techniques": [
              "T1486",
              "T1041"
            ],
            "observables": [
              "PromptLock ransomware execution",
              "Encryption of files on local or shared drives",
              "Exfiltration of sensitive data via AI agent tools",
              "C2 traffic to attacker-controlled domains"
            ]
          }
        ],
        "summary": "AI agents are being compromised via malicious supply chain skills and indirect prompt injection, while traditional threats like phishing and vulnerability exploitation are accelerated by AI-driven automation. Adversaries are increasingly using 'Bring Your Own Vulnerable Driver' (BYOVD) techniques to disable EDR tools before deploying ransomware or exfiltrating credentials."
      },
      "severity": "medium",
      "rationale": "The lead query identifies hosts where non-browser processes access browser credential stores. These hosts should be provided in the scope_hosts parameter for the parallel checks to focus on likely compromised endpoints.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary is stealing credentials from browser stores and attempting to disable security controls using vulnerable drivers before launching a high-volume ransomware or exfiltration attack.",
      "parameters": {
        "scope_hosts": {
          "from": {
            "ref": "analyst-pivot",
            "kind": "manual",
            "observed": "2024-01-01"
          },
          "type": "list[host]",
          "default": [],
          "description": "List of hostnames identified in the lead query to narrow subsequent searches."
        },
        "lookback_days": {
          "from": {
            "ref": "standard-hunt-period",
            "kind": "manual",
            "observed": "2024-01-01"
          },
          "type": "number",
          "default": "14",
          "description": "Days of historical telemetry to examine."
        },
        "credential_files": {
          "from": {
            "ref": "eset-smb-2026",
            "kind": "article",
            "observed": "2026-09-21"
          },
          "type": "list[string]",
          "default": [
            "login data",
            "cookies",
            "logins.json",
            "key4.db"
          ],
          "description": "Browser credential and session filenames targeted by infostealers."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.welivesecurity.com/en/business-security/smb-cybersecurity-squeeze-ai-agents-work-old-attacks-overdrive/",
          "gates": [
            "dry-run",
            "lint",
            "critic"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.welivesecurity.com/en/business-security/smb-cybersecurity-squeeze-ai-agents-work-old-attacks-overdrive/",
          "name": "The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive"
        }
      ],
      "blind_spots": [
        {
          "id": "kernel-visibility-gap",
          "risk": "Some EDR versions may fail to report kernel loads once they are actively being impaired, leading to a silent failure in the hunt.",
          "stage": "evasion-vulnerable-driver-edr-killer",
          "question": "Was every driver load event captured and signature verified?",
          "requires": "hb_kernel_extension_activity with consistent cross-platform signature status"
        },
        {
          "id": "process-on-disk-evasion",
          "risk": "If an infostealer is injected into a legitimate process, the file activity lead might only attribute the access to the legitimate process name.",
          "stage": "credential-access-password-stores",
          "question": "Was the infostealer running purely in memory?",
          "requires": "hb_process_activity with on_disk = 0 tracking"
        }
      ]
    },
    "name": "EDR Impairment and Ransomware Impact",
    "description": "This hunt targets the late-stage progression of an intrusion in an SMB environment. It starts by identifying suspicious access to browser credential stores, then fans out to detect the loading of unsigned or revoked kernel drivers used for EDR impairment. Simultaneously, it baselines file activity to find rare processes performing mass encryption or renaming. An agent weighs these signals to identify coordinated impact attempts."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "the-smb-cybersecurity-squeeze-ai-agents-at-work-old-attacks-in-overdrive",
          "index": 2,
          "title": "The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive",
          "total": 2
        },
        "coverage": [
          {
            "stage": "credential-access-password-stores",
            "steps": [
              "credential-store-access"
            ],
            "status": "covered"
          },
          {
            "stage": "evasion-vulnerable-driver-edr-killer",
            "steps": [
              "driver-load-check"
            ],
            "status": "covered"
          },
          {
            "stage": "impact-ransomware-data-exfiltration",
            "steps": [
              "high-volume-file-activity"
            ],
            "status": "covered"
          },
          {
            "stage": "phishing-ai-enhanced-social-engineering",
            "reason": "Belongs to another part of the 'The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "initial-access-malicious-ai-skills",
            "reason": "Belongs to another part of the 'The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "exploit-public-facing-rapid-cve",
            "reason": "Belongs to another part of the 'The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "execution-indirect-prompt-injection",
            "reason": "Belongs to another part of the 'The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary is stealing credentials from browser stores and attempting to disable security controls using vulnerable drivers before launching a high-volume ransomware or exfiltration attack.",
        "blind_spots": [
          {
            "id": "kernel-visibility-gap",
            "risk": "Some EDR versions may fail to report kernel loads once they are actively being impaired, leading to a silent failure in the hunt.",
            "stage": "evasion-vulnerable-driver-edr-killer",
            "question": "Was every driver load event captured and signature verified?",
            "requires": "hb_kernel_extension_activity with consistent cross-platform signature status"
          },
          {
            "id": "process-on-disk-evasion",
            "risk": "If an infostealer is injected into a legitimate process, the file activity lead might only attribute the access to the legitimate process name.",
            "stage": "credential-access-password-stores",
            "question": "Was the infostealer running purely in memory?",
            "requires": "hb_process_activity with on_disk = 0 tracking"
          }
        ],
        "scoping_notes": "The lead query identifies hosts where non-browser processes access browser credential stores. These hosts should be provided in the scope_hosts parameter for the parallel checks to focus on likely compromised endpoints.",
        "beyond_detection": "A simple rule for unsigned drivers would fire too often on development tools. This hunt combines that signal with the lead (credential theft) and the aftermath (mass file activity) to provide the necessary context for high-confidence host isolation."
      }
    },
    {
      "id": "credential-store-access",
      "type": "query",
      "label": "Suspicious access to browser credential stores",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_hostname, actor_user_name, process_name, file_name, file_path, time FROM hb_file_activity WHERE instr(',' || '{{credential_files}}' || ',', ',' || LOWER(file_name) || ',') > 0 AND activity_id = 2 AND (LOWER(process_name) NOT LIKE '%\\\\chrome.exe' AND LOWER(process_name) NOT LIKE '%\\\\msedge.exe' AND LOWER(process_name) NOT LIKE '%\\\\firefox.exe') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_file_activity",
        "description": "Identify potential infostealer activity by finding non-browser processes reading password files.",
        "expected_signal": "Rows show processes like cmd.exe or unknown binaries reading browser databases. Silence suggests no such direct access was recorded."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Suspicious access to browser credential stores",
        "reads": [
          "activity_id",
          "actor_user_name",
          "device_hostname",
          "file_name",
          "file_path",
          "process_name",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, actor_user_name, process_name, file_name, file_path, time FROM hb_file_activity WHERE instr(',' || '{{credential_files}}' || ',', ',' || LOWER(file_name) || ',') > 0 AND activity_id = 2 AND (LOWER(process_name) NOT LIKE '%\\\\chrome.exe' AND LOWER(process_name) NOT LIKE '%\\\\msedge.exe' AND LOWER(process_name) NOT LIKE '%\\\\firefox.exe') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Rows show processes like cmd.exe or unknown binaries reading browser databases. Silence suggests no such direct access was recorded.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "driver-load-check",
      "type": "query",
      "label": "Unsigned or suspicious driver loading",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, driver_path, driver_signature_subject, driver_signed, time FROM hb_kernel_extension_activity WHERE (driver_signed = 'false' OR LOWER(driver_signature_status) != 'valid') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_kernel_extension_activity",
        "description": "Detect the BYOVD technique used to kill security software by loading vulnerable drivers.",
        "expected_signal": "A list of unsigned or untrusted drivers. Silence is a strong indicator that no standard BYOVD tool was loaded."
      },
      "parents": [
        {
          "id": "credential-store-access"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Unsigned or suspicious driver loading",
        "reads": [
          "device_hostname",
          "driver_path",
          "driver_signature_status",
          "driver_signature_subject",
          "driver_signed",
          "time"
        ],
        "source": "hb_kernel_extension_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, driver_path, driver_signature_subject, driver_signed, time FROM hb_kernel_extension_activity WHERE (driver_signed = 'false' OR LOWER(driver_signature_status) != 'valid') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "A list of unsigned or untrusted drivers. Silence is a strong indicator that no standard BYOVD tool was loaded.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "high-volume-file-activity",
      "type": "query",
      "label": "Rare processes with high modification volume",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT process_name, COUNT(DISTINCT device_hostname) AS hosts, COUNT(*) AS total_events, MIN(time) AS first_seen FROM hb_file_activity WHERE activity_id IN (3, 5) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_name HAVING hosts <= 3 AND total_events > 50 ORDER BY hosts ASC",
        "surface": "hb_file_activity",
        "description": "Identify the final ransomware or exfiltration stage where a rare process touches many files.",
        "expected_signal": "A process rare across the fleet modifying a large number of files on a single host. Silence means no mass modification occurred during the window."
      },
      "parents": [
        {
          "id": "credential-store-access"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare processes with high modification volume",
        "reads": [
          "activity_id",
          "device_hostname",
          "process_name",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT process_name, COUNT(DISTINCT device_hostname) AS hosts, COUNT(*) AS total_events, MIN(time) AS first_seen FROM hb_file_activity WHERE activity_id IN (3, 5) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_name HAVING hosts <= 3 AND total_events > 50 ORDER BY hosts ASC",
        "silence": "evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A process rare across the fleet modifying a large number of files on a single host. Silence means no mass modification occurred during the window.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_name"
          ],
          "rare_below": 4
        },
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "triage-impact",
      "type": "analytic",
      "label": "Weigh evidence of impairment and impact",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "credential-store-access",
          "driver-load-check",
          "high-volume-file-activity"
        ],
        "objective": "Determine if any host shows a sequence of credential theft followed by suspicious driver loading and finally high-volume file modifications. Cite the specific process names and driver paths found in all three steps.",
        "description": "Correlate the credential access, driver loading, and file activity per host to determine the severity.",
        "max_iterations": 4,
        "expected_signal": "A verdict characterizing the activity as a coordinated ransomware attack, an infostealer, or benign activity.",
        "success_criteria": "A malicious | suspicious | benign verdict per host with supporting row citations."
      },
      "parents": [
        {
          "id": "driver-load-check",
          "kind": "merge"
        },
        {
          "id": "high-volume-file-activity",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-verdict",
      "type": "checkpoint",
      "label": "Route based on agent verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage verdict is malicious for at least one host involving driver loading and mass file activity",
        "condition": "the triage verdict is malicious for at least one host involving driver loading and mass file activity",
        "blind_spot": "kernel-visibility-gap",
        "confidence": "high",
        "description": "Initiate immediate isolation for malicious activity or refer suspicious cases to manual review.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-impact"
        }
      ]
    },
    {
      "id": "isolate-endpoint",
      "type": "action",
      "label": "Isolate impacted endpoint",
      "config": {
        "target": "endpoint",
        "description": "Immediately network-isolate the host to prevent further encryption or exfiltration.",
        "instructions": "Isolate the host immediately via the EDR console. Preserve the endpoint state for forensic memory collection, focusing on the malicious driver.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "forensic-review",
      "type": "task",
      "label": "Manual forensic review",
      "config": {
        "assignee": "analyst",
        "description": "Verify the agent's findings and identify the persistence mechanism or original entry point.",
        "instructions": "Review the cited driver paths and file activities. Check the process_cmd_line for the processes touching credential stores to find where they were launched from."
      },
      "parents": [
        {
          "id": "route-verdict",
          "branch": "default"
        },
        {
          "id": "route-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "route-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "isolate-endpoint"
        }
      ]
    },
    {
      "id": "hunt-closeout",
      "type": "task",
      "label": "Hunt closeout and documentation",
      "config": {
        "assignee": "analyst",
        "description": "Document findings and any visibility gaps discovered during the hunt.",
        "instructions": "Record the findings. If driver loading was not visible on some OS versions, document this as a telemetry gap for the platform team."
      },
      "parents": [
        {
          "id": "forensic-review"
        }
      ]
    }
  ]
}