{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "User-driven manual execution via social engineering is a top-prevalence threat according to Huntress SOC data. This hunt provides the chain of evidence required to distinguish rogue RMM use from normal administration."
      },
      "name": "Endpoint Social Engineering and Malicious Execution",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1566",
        "attack.t1204.001",
        "attack.t1219",
        "attack.t1555",
        "attack.t1071.001",
        "command and control",
        "credential access",
        "execution",
        "initial access",
        "persistence"
      ],
      "series": {
        "slug": "huntress-tragic-quadrant-top-cyber-threats-wrecking-businesses",
        "index": 1,
        "title": "Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses",
        "total": 2
      },
      "related": [
        {
          "hunt": "mailbox-manipulation-persistence",
          "reason": "Persistence via M365 mailbox rules is an identity-layer hunt and out of scope for this endpoint-focused lifecycle.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A standing rule for explorer.exe spawning a shell is too noisy; this hunt uses network lures and follow-on file-access patterns to provide the context an analyst needs to act.",
      "coverage": [
        {
          "stage": "initial-access-phishing-lures",
          "steps": [
            "lure-traffic"
          ],
          "status": "covered"
        },
        {
          "stage": "execution-clickfix-win-r",
          "steps": [
            "clickfix-execution"
          ],
          "status": "covered"
        },
        {
          "stage": "persistence-rmm-abuse",
          "steps": [
            "rogue-rmm-check"
          ],
          "status": "covered"
        },
        {
          "stage": "c2-infostealer-deployment",
          "steps": [
            "infostealer-file-access"
          ],
          "status": "covered"
        },
        {
          "stage": "credential-access-token-theft",
          "reason": "Belongs to another part of the 'Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "persistence-mailbox-manipulation",
          "reason": "Belongs to another part of the 'Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Social Engineering with AI-Tuned Lures",
            "slug": "initial-access-phishing-lures",
            "tactic": "initial-access",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "claude.ai",
              "Railway",
              "Cisco redirect URLs",
              "Trend Micro redirect URLs",
              "Mimecast redirect URLs",
              "AI-tuned lures",
              "fake document shares",
              "service agreement lures"
            ]
          },
          {
            "name": "User-Driven ClickFix Command Execution",
            "slug": "execution-clickfix-win-r",
            "tactic": "execution",
            "techniques": [
              "T1204.001"
            ],
            "observables": [
              "Win+R",
              "Windows Run box",
              "Human Verification prompt",
              "multi-stage infection command"
            ]
          },
          {
            "name": "Adversary-in-the-Middle and Device Code Token Harvesting",
            "slug": "credential-access-token-theft",
            "tactic": "credential-access",
            "techniques": [
              "T1557",
              "T1528"
            ],
            "observables": [
              "session token",
              "device code login flow",
              "access token",
              "Microsoft 365 login page impersonation"
            ]
          },
          {
            "name": "Persistence via Rogue RMM Installation",
            "slug": "persistence-rmm-abuse",
            "tactic": "persistence",
            "techniques": [
              "T1219"
            ],
            "observables": [
              "rogue RMM tool",
              "Remote Monitoring and Management tools"
            ]
          },
          {
            "name": "Stealthy Mailbox Rule Manipulation",
            "slug": "persistence-mailbox-manipulation",
            "tactic": "persistence",
            "techniques": [
              "T1137.005",
              "T1564.008"
            ],
            "observables": [
              "inbox rules",
              "RSS Feeds folder",
              "Archive folders"
            ]
          },
          {
            "name": "Infostealer and RAT Deployment",
            "slug": "c2-infostealer-deployment",
            "tactic": "command-and-control",
            "techniques": [
              "T1555",
              "T1071.001"
            ],
            "observables": [
              "LummaC2",
              "SectopRAT",
              "FakeAgent"
            ]
          }
        ],
        "summary": "The Huntress Tragic Quadrant outlines common 2026 threats targeting SMBs, where attackers use AI-enhanced social engineering (ClickFix, fake lures) and trusted platforms (Claude.ai) to deliver infostealers and rogue RMM tools. The campaign progresses from initial access via session token theft (AiTM) or user-driven command execution to persistence through mailbox manipulation and remote management software abuse."
      },
      "severity": "high",
      "rationale": "Focus on Windows endpoints where users have local administrative rights. Servers where RMM tools are expected can be filtered by hostname to reduce noise.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An attacker has used AI-tuned phishing lures or ClickFix social engineering to trick a user into executing shell commands from the Run box, eventually deploying rogue RMM tools or infostealers.",
      "parameters": {
        "rmm_names": {
          "type": "list[string]",
          "default": [
            "anydesk.exe",
            "screenconnect.exe",
            "atera.exe",
            "splashtop.exe",
            "tvnserver.exe"
          ],
          "description": "Common RMM process names used to establish a prevalence baseline."
        },
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Optional list of hostnames to narrow the search; leave empty for all hosts."
        },
        "shell_names": {
          "type": "list[string]",
          "default": [
            "powershell.exe",
            "cmd.exe"
          ],
          "description": "Shell processes monitored for Run-box execution."
        },
        "lure_domains": {
          "from": {
            "ref": "huntress-tragic-quadrant",
            "kind": "article",
            "observed": "2026-10-01"
          },
          "type": "list[domain]",
          "default": [
            "claude.ai",
            "railway.app",
            "railway.com"
          ],
          "description": "Domains known to host malicious artifacts or lures."
        },
        "browser_files": {
          "type": "list[string]",
          "default": [
            "login data",
            "cookies",
            "web data"
          ],
          "description": "Target files typically harvested by infostealers."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "redirect_domains": {
          "from": {
            "ref": "huntress-tragic-quadrant",
            "kind": "article",
            "observed": "2026-10-01"
          },
          "type": "list[domain]",
          "default": [
            "cisco.com",
            "trendmicro.com",
            "mimecast.com"
          ],
          "description": "Legitimate service domains used as phishing redirectors."
        },
        "legitimate_browsers": {
          "type": "list[string]",
          "default": [
            "chrome.exe",
            "msedge.exe",
            "firefox.exe"
          ],
          "description": "Legitimate browser process names to exclude from theft detection."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.huntress.com/blog/huntress-tragic-quadrant-cyber-threats",
          "gates": [
            "dry-run",
            "lint",
            "critic"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.huntress.com/blog/huntress-tragic-quadrant-cyber-threats",
          "name": "Huntress \u2014 Tragic Quadrant: Top Cyber Threats Wrecking Businesses"
        }
      ],
      "blind_spots": [
        {
          "id": "no-proxy-telemetry",
          "risk": "Endpoint agents may miss browser-internal redirects or specific AI-hosted artifacts that a network proxy would capture.",
          "stage": "initial-access-phishing-lures",
          "question": "Did the user click a redirect that bypasses endpoint-only HTTP logging?",
          "requires": "hb_http_activity from a proxy or firewall"
        },
        {
          "id": "cmd-line-truncation",
          "risk": "Attackers use long, encoded PowerShell strings; if truncated, key indicators like 'iex' may be lost.",
          "stage": "execution-clickfix-win-r",
          "question": "What was the complete payload pasted into the Run box?",
          "requires": "Full process_cmd_line length"
        }
      ]
    },
    "name": "Endpoint Social Engineering and Malicious Execution",
    "description": "This phased hunt investigates the full lifecycle of host-based infection as described in the Huntress Tragic Quadrant. It begins by identifying suspicious URI redirects and shell processes spawned directly by the Windows desktop shell (explorer.exe), which is the primary indicator of ClickFix social engineering. In the second phase, the hunt corroborates these findings by identifying unauthorized RMM tools and sensitive file access patterns characteristic of infostealers like LummaC2. An agent-driven analysis weighs the early-stage access signals against follow-on persistence and impact evidence to confirm the intrusion chain."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "huntress-tragic-quadrant-top-cyber-threats-wrecking-businesses",
          "index": 1,
          "title": "Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses",
          "total": 2
        },
        "coverage": [
          {
            "stage": "initial-access-phishing-lures",
            "steps": [
              "lure-traffic"
            ],
            "status": "covered"
          },
          {
            "stage": "execution-clickfix-win-r",
            "steps": [
              "clickfix-execution"
            ],
            "status": "covered"
          },
          {
            "stage": "persistence-rmm-abuse",
            "steps": [
              "rogue-rmm-check"
            ],
            "status": "covered"
          },
          {
            "stage": "c2-infostealer-deployment",
            "steps": [
              "infostealer-file-access"
            ],
            "status": "covered"
          },
          {
            "stage": "credential-access-token-theft",
            "reason": "Belongs to another part of the 'Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "persistence-mailbox-manipulation",
            "reason": "Belongs to another part of the 'Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An attacker has used AI-tuned phishing lures or ClickFix social engineering to trick a user into executing shell commands from the Run box, eventually deploying rogue RMM tools or infostealers.",
        "blind_spots": [
          {
            "id": "no-proxy-telemetry",
            "risk": "Endpoint agents may miss browser-internal redirects or specific AI-hosted artifacts that a network proxy would capture.",
            "stage": "initial-access-phishing-lures",
            "question": "Did the user click a redirect that bypasses endpoint-only HTTP logging?",
            "requires": "hb_http_activity from a proxy or firewall"
          },
          {
            "id": "cmd-line-truncation",
            "risk": "Attackers use long, encoded PowerShell strings; if truncated, key indicators like 'iex' may be lost.",
            "stage": "execution-clickfix-win-r",
            "question": "What was the complete payload pasted into the Run box?",
            "requires": "Full process_cmd_line length"
          }
        ],
        "scoping_notes": "Focus on Windows endpoints where users have local administrative rights. Servers where RMM tools are expected can be filtered by hostname to reduce noise.",
        "beyond_detection": "A standing rule for explorer.exe spawning a shell is too noisy; this hunt uses network lures and follow-on file-access patterns to provide the context an analyst needs to act."
      }
    },
    {
      "id": "scope-windows-hosts",
      "type": "query",
      "label": "Scope Windows Hosts",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT DISTINCT device_hostname FROM hb_software_inventory WHERE (package_type = 'msi' OR package_type = 'exe') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)",
        "surface": "hb_software_inventory",
        "description": "Identify Windows endpoints in the software inventory to target the hunt.",
        "expected_signal": "A list of hostnames representing the Windows estate. Silence means no Windows software inventory is present."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Scope Windows Hosts",
        "reads": [
          "device_hostname",
          "package_type"
        ],
        "source": "hb_software_inventory",
        "target": "endpoint",
        "content": "SELECT DISTINCT device_hostname FROM hb_software_inventory WHERE (package_type = 'msi' OR package_type = 'exe') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hostnames representing the Windows estate. Silence means no Windows software inventory is present.",
        "verified": "dry-run",
        "verified_at": "2026-10-02"
      }
    },
    {
      "id": "lure-traffic",
      "type": "query",
      "label": "Phishing Lure Traffic",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "web",
        "content": "SELECT device_hostname, url_hostname, url_full, time FROM hb_http_activity WHERE (instr(',' || '{{lure_domains}}' || ',', ',' || LOWER(url_hostname) || ',') > 0 OR instr(',' || '{{redirect_domains}}' || ',', ',' || LOWER(url_hostname) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_http_activity",
        "description": "Find HTTP requests to AI platforms or known redirectors identified in the article.",
        "expected_signal": "Outbound traffic to domains like claude.ai or Railway following a redirect link. Silence means no report-specific traffic was found."
      },
      "parents": [
        {
          "id": "scope-windows-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Phishing Lure Traffic",
        "reads": [
          "device_hostname",
          "url_hostname",
          "url_full",
          "time"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT device_hostname, url_hostname, url_full, time FROM hb_http_activity WHERE (instr(',' || '{{lure_domains}}' || ',', ',' || LOWER(url_hostname) || ',') > 0 OR instr(',' || '{{redirect_domains}}' || ',', ',' || LOWER(url_hostname) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Outbound traffic to domains like claude.ai or Railway following a redirect link. Silence means no report-specific traffic was found.",
        "verified": "dry-run",
        "verified_at": "2026-10-02"
      }
    },
    {
      "id": "clickfix-execution",
      "type": "query",
      "label": "ClickFix Shell Execution",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, parent_process_name, time FROM hb_process_activity WHERE LOWER(parent_process_name) LIKE '%explorer.exe' AND instr(',' || '{{shell_names}}' || ',', ',' || LOWER(process_name) || ',') > 0 AND (LOWER(process_cmd_line) LIKE '%iex%' OR LOWER(process_cmd_line) LIKE '%-enc%' OR LOWER(process_cmd_line) LIKE '%getstring%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Detect shell processes spawned by explorer.exe with encoded commands, typical of Run box pasting.",
        "expected_signal": "A shell process launched directly from explorer.exe with suspicious arguments. This indicates a user-driven paste event."
      },
      "parents": [
        {
          "id": "scope-windows-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "ClickFix Shell Execution",
        "reads": [
          "device_hostname",
          "process_name",
          "process_cmd_line",
          "parent_process_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, parent_process_name, time FROM hb_process_activity WHERE LOWER(parent_process_name) LIKE '%explorer.exe' AND instr(',' || '{{shell_names}}' || ',', ',' || LOWER(process_name) || ',') > 0 AND (LOWER(process_cmd_line) LIKE '%iex%' OR LOWER(process_cmd_line) LIKE '%-enc%' OR LOWER(process_cmd_line) LIKE '%getstring%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "A shell process launched directly from explorer.exe with suspicious arguments. This indicates a user-driven paste event.",
        "verified": "dry-run",
        "verified_at": "2026-10-02"
      }
    },
    {
      "id": "early-stage-triage",
      "type": "analytic",
      "label": "Early Stage Triage",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "web"
        ],
        "context": [
          "lure-traffic",
          "clickfix-execution"
        ],
        "objective": "Determine which hosts show high-confidence signs of social engineering leading to manual shell execution.",
        "description": "Determine which hosts show high-confidence signs of social engineering leading to manual shell execution.",
        "max_iterations": 3,
        "expected_signal": "A verdict per host identifying high-confidence early-stage compromises.",
        "success_criteria": "A list of hosts with confirmed early-stage social engineering activity."
      },
      "parents": [
        {
          "id": "lure-traffic",
          "kind": "merge"
        },
        {
          "id": "clickfix-execution",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "rogue-rmm-check",
      "type": "query",
      "label": "Rogue RMM Check",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT process_name, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_process_activity WHERE instr(',' || '{{rmm_names}}' || ',', ',' || LOWER(process_name) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_name HAVING host_count <= 3 ORDER BY host_count ASC",
        "surface": "hb_process_activity",
        "description": "Find rogue RMM tools by stack-counting common RMM names across the estate.",
        "expected_signal": "An RMM tool seen on three or fewer hosts. Tools found fleet-wide are likely authorized; rare ones suggest rogue installation."
      },
      "parents": [
        {
          "id": "early-stage-triage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rogue RMM Check",
        "reads": [
          "process_name",
          "device_hostname",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT process_name, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_process_activity WHERE instr(',' || '{{rmm_names}}' || ',', ',' || LOWER(process_name) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_name HAVING host_count <= 3 ORDER BY host_count ASC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "An RMM tool seen on three or fewer hosts. Tools found fleet-wide are likely authorized; rare ones suggest rogue installation.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_name"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-10-02"
      }
    },
    {
      "id": "infostealer-file-access",
      "type": "query",
      "label": "Infostealer File Access",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, file_name, file_path, time FROM hb_file_activity WHERE instr(',' || '{{browser_files}}' || ',', ',' || LOWER(file_name) || ',') > 0 AND instr(',' || '{{legitimate_browsers}}' || ',', ',' || LOWER(process_name) || ',') = 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_file_activity",
        "description": "Identify non-browser processes accessing browser credential and session data using a list-based exclusion.",
        "expected_signal": "Any row showing an unknown process reading sensitive browser files. Silence means no such access was observed."
      },
      "parents": [
        {
          "id": "early-stage-triage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Infostealer File Access",
        "reads": [
          "device_hostname",
          "process_name",
          "file_name",
          "file_path",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, file_name, file_path, time FROM hb_file_activity WHERE instr(',' || '{{browser_files}}' || ',', ',' || LOWER(file_name) || ',') > 0 AND instr(',' || '{{legitimate_browsers}}' || ',', ',' || LOWER(process_name) || ',') = 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Any row showing an unknown process reading sensitive browser files. Silence means no such access was observed.",
        "verified": "dry-run",
        "verified_at": "2026-10-02"
      }
    },
    {
      "id": "full-chain-analysis",
      "type": "analytic",
      "label": "Full Chain Analysis",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "web"
        ],
        "context": [
          "early-stage-triage",
          "rogue-rmm-check",
          "infostealer-file-access"
        ],
        "objective": "Determine whether the social engineering confirmed in early-stage-triage led to rogue persistence or infostealer activity.",
        "description": "Combine early-stage verdicts with follow-on evidence to identify complete intrusion chains.",
        "max_iterations": 6,
        "expected_signal": "A final malicious or suspicious verdict for each affected host citing the full chain.",
        "success_criteria": "A final per-host verdict citing evidence from both early and follow-on stages."
      },
      "parents": [
        {
          "id": "rogue-rmm-check",
          "kind": "merge"
        },
        {
          "id": "infostealer-file-access",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "response-decision",
      "type": "checkpoint",
      "label": "Response Decision",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the final verdict identifies malicious activity linking the initial lure to execution and subsequent RMM or infostealer activity",
        "condition": "the final verdict identifies malicious activity linking the initial lure to execution and subsequent RMM or infostealer activity",
        "blind_spot": "no-proxy-telemetry",
        "confidence": "high",
        "description": "Direct response actions based on the confidence of the intrusion chain.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "full-chain-analysis"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate Host",
      "config": {
        "target": "endpoint",
        "description": "Sever network access to prevent further data theft or command execution.",
        "instructions": "Isolate the affected host using the EDR. Revoke active SaaS session tokens and force a password reset for the logged-in user.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "response-decision",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Analyst Review",
      "config": {
        "assignee": "analyst",
        "description": "Verify the agent's findings and identify any false positives in shell execution patterns.",
        "instructions": "Review the full process command line from the shell execution step. Confirm if the rare RMM identified is a rogue instance or a one-off approved project tool. If the shell query is high-fidelity, promote it to a standing rule."
      },
      "parents": [
        {
          "id": "response-decision",
          "branch": "default"
        },
        {
          "id": "response-decision",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Hunt Closure",
      "config": {
        "assignee": "analyst",
        "description": "Document findings and close out the hunt.",
        "instructions": "Record the hosts examined, any confirmed threats, and false positives for baseline tuning. Document coverage gaps for the HTTP surface if lures were missed."
      },
      "parents": [
        {
          "id": "response-decision",
          "branch": "on_refutes"
        },
        {
          "id": "analyst-review"
        }
      ]
    }
  ]
}