{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Compromised executive identities are permanent assets in the cybercrime ecosystem used for multi-stage fraud and espionage; identifying the exposure before it is weaponized protects the organization's financial and reputational assets."
      },
      "name": "Executive Identity Harvesting and Dark Web Abuse",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1566",
        "attack.t1195",
        "attack.t1555",
        "attack.t1090.003",
        "command and control",
        "credential access",
        "initial access"
      ],
      "related": [
        {
          "hunt": "infostealer-malware-analysis",
          "reason": "Focuses on the generic malware delivery rather than the specific executive identity impact.",
          "relation": "alternative"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        },
        "identity": {
          "name": "Identity / sign-in telemetry",
          "category": "identity",
          "telemetry": [
            "identity"
          ]
        }
      },
      "analysis": "A single rule might find a Tor connection, but this hunt pivots between high-value account scoping, specific PII file-access anomalies, and identity-theft marketplace indicators across three separate telemetry surfaces.",
      "coverage": [
        {
          "stage": "identity-harvesting-and-phishing",
          "steps": [
            "harvest-sensitive-files",
            "harvest-credential-processes"
          ],
          "status": "covered"
        },
        {
          "stage": "infostealer-credential-scraping",
          "steps": [
            "harvest-credential-processes"
          ],
          "status": "covered"
        },
        {
          "stage": "marketplace-infrastructure-access",
          "steps": [
            "infra-marketplace-dns"
          ],
          "status": "covered"
        },
        {
          "stage": "executive-impersonation-weaponization",
          "steps": [
            "auth-executive-anomalies"
          ],
          "status": "covered"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Identity Harvesting via Phishing and Malware",
            "slug": "identity-harvesting-and-phishing",
            "tactic": "initial-access",
            "techniques": [
              "T1566",
              "T1195"
            ],
            "observables": [
              "Phishing emails targeting PII",
              "Infostealer malware logs",
              "SQL database breaches of data aggregators",
              "Compromised corporate onboarding paperwork"
            ]
          },
          {
            "name": "Infostealer Local Data Scraping",
            "slug": "infostealer-credential-scraping",
            "tactic": "credential-access",
            "techniques": [
              "T1555"
            ],
            "observables": [
              "Access to saved browser forms",
              "Extraction of PDF tax returns",
              "Scraping of corporate onboarding documents",
              "Unmanaged personal device compromise"
            ]
          },
          {
            "name": "Marketplace and Tor Infrastructure Interaction",
            "slug": "marketplace-infrastructure-access",
            "tactic": "command-and-control",
            "techniques": [
              "T1090.003"
            ],
            "observables": [
              "Xilo Tor hidden service access",
              "Bankomat mirror site traffic",
              "PeopleFinder marketplace domains",
              ".onion domain resolution",
              "Cryptocurrency payments in USDT, BTC, or XMR",
              "Telegram channel technical updates"
            ]
          },
          {
            "name": "Executive Impersonation and Downstream Fraud",
            "slug": "executive-impersonation-weaponization",
            "tactic": "initial-access",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "Business Email Compromise (BEC) attacks",
              "Executive impersonation login attempts",
              "Spearphishing using enriched PII",
              "Unauthorized lines of credit requests",
              "Anomalous sign-ins from C-suite executive identities"
            ]
          }
        ],
        "summary": "Cybercriminals harvest executive SSNs and PII through large-scale institutional breaches and infostealer malware, which are then traded on mature dark web marketplaces like Xilo and Bankomat. Threat actors purchase this enriched identity data to conduct highly credible executive impersonation, business email compromise (BEC), and sophisticated financial fraud."
      },
      "severity": "medium",
      "rationale": "Focus on C-suite, Presidents, and Board members. High-value sectors include Financials and Industrials. If the DNS surface shows no activity, prioritize the file-access baseline over the DNS-based triggers.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An intruder has deployed infostealer malware on a high-profile device to harvest PII and SSNs, which are subsequently traded on dark web marketplaces and used for account impersonation.",
      "parameters": {
        "scope_hosts": {
          "from": {
            "ref": "analyst-defined",
            "kind": "manual",
            "observed": "2024-05-20"
          },
          "type": "list[host]",
          "default": [],
          "description": "List of hostnames to narrow the search; leave empty to scan the entire estate."
        },
        "lookback_days": {
          "from": {
            "ref": "standard-retention",
            "kind": "manual",
            "observed": "2024-05-20"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "executive_usernames": {
          "from": {
            "ref": "rapid7-ssn-research",
            "kind": "article",
            "observed": "2026-08-27"
          },
          "type": "list[string]",
          "default": [
            "ceo",
            "cfo",
            "president",
            "exec",
            "vp"
          ],
          "description": "Usernames or patterns matching high-profile leadership accounts."
        },
        "marketplace_domains": {
          "from": {
            "ref": "rapid7-ssn-research",
            "kind": "article",
            "observed": "2026-08-27"
          },
          "type": "list[domain]",
          "default": [
            "xilo.cc",
            "bankomat.cc",
            "peoplefinder.su",
            "xilo.to",
            "bankomat.biz"
          ],
          "description": "Clear-web mirrors and domains associated with SSN marketplaces."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.rapid7.com/blog/post/tr-identity-as-a-service-dark-web-marketplaces-executive-ssn",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.rapid7.com/blog/post/tr-identity-as-a-service-dark-web-marketplaces-executive-ssn",
          "name": "Rapid7 \u2014 Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNs"
        }
      ],
      "blind_spots": [
        {
          "id": "no-endpoint-telemetry",
          "risk": "The article explicitly mentions infostealers scraping unmanaged personal devices; without telemetry from these, the harvesting phase is invisible.",
          "owner": "IT Security",
          "stage": "identity-harvesting-and-phishing",
          "question": "whether harvesting is occurring on an executive's home computer",
          "requires": "an endpoint agent on personal/unmanaged devices",
          "remediation": "Deploy managed browser profiles or endpoint agents to home-use devices for executives."
        },
        {
          "id": "dns-encryption",
          "risk": "Tor mirrors and marketplaces can be accessed via DoH, rendering network-level DNS logging ineffective.",
          "owner": "Network Engineering",
          "stage": "marketplace-infrastructure-access",
          "question": "whether the host is using DNS-over-HTTPS (DoH) to bypass DNS monitoring",
          "requires": "decrypted DNS or endpoint-level query logging",
          "remediation": "Enforce endpoint-level DNS logging via EDR rather than relying on network-fabric logs."
        }
      ]
    },
    "name": "Executive Identity Harvesting and Dark Web Abuse",
    "description": "This hunt targets the complete lifecycle of executive identity theft, from the initial harvesting of sensitive documents (tax returns, onboarding paperwork) via infostealers to the subsequent use of those identities in anomalous sign-in events. It uses a phased approach: first identifying hosts associated with executive identities, then searching for file and process activity indicative of PII scraping, and finally correlating those findings with DNS traffic to known SSN marketplaces and suspicious authentication patterns."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "coverage": [
          {
            "stage": "identity-harvesting-and-phishing",
            "steps": [
              "harvest-sensitive-files",
              "harvest-credential-processes"
            ],
            "status": "covered"
          },
          {
            "stage": "infostealer-credential-scraping",
            "steps": [
              "harvest-credential-processes"
            ],
            "status": "covered"
          },
          {
            "stage": "marketplace-infrastructure-access",
            "steps": [
              "infra-marketplace-dns"
            ],
            "status": "covered"
          },
          {
            "stage": "executive-impersonation-weaponization",
            "steps": [
              "auth-executive-anomalies"
            ],
            "status": "covered"
          }
        ],
        "rationale": "An intruder has deployed infostealer malware on a high-profile device to harvest PII and SSNs, which are subsequently traded on dark web marketplaces and used for account impersonation.",
        "blind_spots": [
          {
            "id": "no-endpoint-telemetry",
            "risk": "The article explicitly mentions infostealers scraping unmanaged personal devices; without telemetry from these, the harvesting phase is invisible.",
            "owner": "IT Security",
            "stage": "identity-harvesting-and-phishing",
            "question": "whether harvesting is occurring on an executive's home computer",
            "requires": "an endpoint agent on personal/unmanaged devices",
            "remediation": "Deploy managed browser profiles or endpoint agents to home-use devices for executives."
          },
          {
            "id": "dns-encryption",
            "risk": "Tor mirrors and marketplaces can be accessed via DoH, rendering network-level DNS logging ineffective.",
            "owner": "Network Engineering",
            "stage": "marketplace-infrastructure-access",
            "question": "whether the host is using DNS-over-HTTPS (DoH) to bypass DNS monitoring",
            "requires": "decrypted DNS or endpoint-level query logging",
            "remediation": "Enforce endpoint-level DNS logging via EDR rather than relying on network-fabric logs."
          }
        ],
        "scoping_notes": "Focus on C-suite, Presidents, and Board members. High-value sectors include Financials and Industrials. If the DNS surface shows no activity, prioritize the file-access baseline over the DNS-based triggers.",
        "beyond_detection": "A single rule might find a Tor connection, but this hunt pivots between high-value account scoping, specific PII file-access anomalies, and identity-theft marketplace indicators across three separate telemetry surfaces."
      }
    },
    {
      "id": "scoping-executive-assets",
      "type": "query",
      "label": "Identify executive-associated hosts",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "identity",
        "content": "SELECT DISTINCT device_hostname, actor_user_name, MAX(time) AS last_signin FROM hb_auth_signin WHERE instr(',' || '{{executive_usernames}}' || ',', ',' || LOWER(actor_user_name) || ',') > 0 AND status_id = 1 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, actor_user_name",
        "surface": "hb_auth_signin",
        "description": "Find hosts where high-profile leadership accounts have signed in recently to focus the hunt.",
        "expected_signal": "A list of hostnames mapped to executive users. Silence indicates no leadership sign-ins were recorded in the window."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify executive-associated hosts",
        "reads": [
          "actor_user_name",
          "device_hostname",
          "status_id",
          "time"
        ],
        "source": "hb_auth_signin",
        "target": "identity",
        "content": "SELECT DISTINCT device_hostname, actor_user_name, MAX(time) AS last_signin FROM hb_auth_signin WHERE instr(',' || '{{executive_usernames}}' || ',', ',' || LOWER(actor_user_name) || ',') > 0 AND status_id = 1 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, actor_user_name",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hostnames mapped to executive users. Silence indicates no leadership sign-ins were recorded in the window.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "harvest-sensitive-files",
      "type": "query",
      "label": "Access to PII and onboarding documents",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, actor_user_name, file_path, process_name, time FROM hb_file_activity WHERE instr(',' || '{{executive_usernames}}' || ',', ',' || LOWER(actor_user_name) || ',') > 0 AND (LOWER(file_name) LIKE '%.pdf' OR LOWER(file_name) LIKE '%.tax%') AND (LOWER(file_path) LIKE '%onboarding%' OR LOWER(file_path) LIKE '%passport%' OR LOWER(file_path) LIKE '%ssn%') AND NOT (LOWER(process_name) LIKE '%acrobat%' OR LOWER(process_name) LIKE '%chrome%' OR LOWER(process_name) LIKE '%edge%' OR LOWER(process_name) LIKE '%explorer%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_file_activity",
        "description": "Detect non-standard processes accessing files that typically contain SSNs and identity data.",
        "expected_signal": "An unusual process (like a temp-path binary) reading a PDF tax return. Silence means no suspicious access to these specific paths was seen."
      },
      "parents": [
        {
          "id": "scoping-executive-assets"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Access to PII and onboarding documents",
        "reads": [
          "actor_user_name",
          "device_hostname",
          "file_name",
          "file_path",
          "process_name",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, actor_user_name, file_path, process_name, time FROM hb_file_activity WHERE instr(',' || '{{executive_usernames}}' || ',', ',' || LOWER(actor_user_name) || ',') > 0 AND (LOWER(file_name) LIKE '%.pdf' OR LOWER(file_name) LIKE '%.tax%') AND (LOWER(file_path) LIKE '%onboarding%' OR LOWER(file_path) LIKE '%passport%' OR LOWER(file_path) LIKE '%ssn%') AND NOT (LOWER(process_name) LIKE '%acrobat%' OR LOWER(process_name) LIKE '%chrome%' OR LOWER(process_name) LIKE '%edge%' OR LOWER(process_name) LIKE '%explorer%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "An unusual process (like a temp-path binary) reading a PDF tax return. Silence means no suspicious access to these specific paths was seen.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "harvest-credential-processes",
      "type": "query",
      "label": "Browser credential store access",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "endpoint",
        "content": "SELECT device_hostname, user_name, process_name, process_cmd_line, parent_process_name, time FROM hb_process_activity WHERE (LOWER(process_cmd_line) LIKE '%\\google\\chrome\\user data%' OR LOWER(process_cmd_line) LIKE '%\\microsoft\\edge\\user data%') AND (LOWER(process_cmd_line) LIKE '%login data%' OR LOWER(process_cmd_line) LIKE '%cookies%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Identify processes interacting with browser 'Login Data' or cookie databases, a core infostealer behavior.",
        "expected_signal": "Command lines targeting Chrome or Edge profile data from non-browser processes. Silence is evidence of absence for this specific technique on enrolled hosts."
      },
      "parents": [
        {
          "id": "scoping-executive-assets"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Browser credential store access",
        "reads": [
          "device_hostname",
          "parent_process_name",
          "process_cmd_line",
          "process_name",
          "time",
          "user_name"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, user_name, process_name, process_cmd_line, parent_process_name, time FROM hb_process_activity WHERE (LOWER(process_cmd_line) LIKE '%\\google\\chrome\\user data%' OR LOWER(process_cmd_line) LIKE '%\\microsoft\\edge\\user data%') AND (LOWER(process_cmd_line) LIKE '%login data%' OR LOWER(process_cmd_line) LIKE '%cookies%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "evidence_of_absence",
        "expected": "Command lines targeting Chrome or Edge profile data from non-browser processes. Silence is evidence of absence for this specific technique on enrolled hosts.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "agent-harvesting-triage",
      "type": "analytic",
      "label": "Triage harvesting risk",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity"
        ],
        "context": [
          "scoping-executive-assets",
          "harvest-sensitive-files",
          "harvest-credential-processes"
        ],
        "objective": "Determine if any host shows evidence of infostealer activity targeting PII or credentials, specifically on high-profile assets.",
        "description": "Evaluate whether the file access and process activity suggests a successful identity harvesting operation.",
        "max_iterations": 3,
        "expected_signal": "A verdict on whether harvesting occurred.",
        "success_criteria": "A host-by-host verdict citing specific file paths or process command lines."
      },
      "parents": [
        {
          "id": "harvest-sensitive-files",
          "kind": "merge"
        },
        {
          "id": "harvest-credential-processes",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "infra-marketplace-dns",
      "type": "query",
      "label": "DNS to identity marketplaces",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, query_hostname, process_name, time FROM hb_dns_activity WHERE (instr(',' || '{{marketplace_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 OR query_hostname LIKE '%.onion%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_dns_activity",
        "description": "Identify traffic to Xilo, Bankom, or other mirror sites and Tor gateways.",
        "expected_signal": "DNS queries for named marketplaces or .onion domains. Silence proves these specific domains were not resolved by the monitored estate."
      },
      "parents": [
        {
          "id": "agent-harvesting-triage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "DNS to identity marketplaces",
        "reads": [
          "device_hostname",
          "process_name",
          "query_hostname",
          "time"
        ],
        "source": "hb_dns_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, query_hostname, process_name, time FROM hb_dns_activity WHERE (instr(',' || '{{marketplace_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 OR query_hostname LIKE '%.onion%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "evidence_of_absence",
        "expected": "DNS queries for named marketplaces or .onion domains. Silence proves these specific domains were not resolved by the monitored estate.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "auth-executive-anomalies",
      "type": "query",
      "label": "Rare executive sign-in patterns",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "identity",
        "content": "SELECT actor_user_name, src_endpoint_ip, src_location_country, COUNT(DISTINCT device_hostname) AS distinct_hosts, MIN(time) AS first_seen FROM hb_auth_signin WHERE instr(',' || '{{executive_usernames}}' || ',', ',' || LOWER(actor_user_name) || ',') > 0 AND status_id = 1 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, src_endpoint_ip, src_location_country HAVING distinct_hosts <= 2",
        "surface": "hb_auth_signin",
        "description": "Stack-count sign-in locations for executives to find rare IPs that may indicate impersonation.",
        "expected_signal": "A sign-in from a country or IP address never previously associated with an executive account."
      },
      "parents": [
        {
          "id": "agent-harvesting-triage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare executive sign-in patterns",
        "reads": [
          "actor_user_name",
          "device_hostname",
          "src_endpoint_ip",
          "src_location_country",
          "status_id",
          "time"
        ],
        "source": "hb_auth_signin",
        "target": "identity",
        "content": "SELECT actor_user_name, src_endpoint_ip, src_location_country, COUNT(DISTINCT device_hostname) AS distinct_hosts, MIN(time) AS first_seen FROM hb_auth_signin WHERE instr(',' || '{{executive_usernames}}' || ',', ',' || LOWER(actor_user_name) || ',') > 0 AND status_id = 1 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, src_endpoint_ip, src_location_country HAVING distinct_hosts <= 2",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A sign-in from a country or IP address never previously associated with an executive account.",
        "verified": "dry-run",
        "prevalence": {
          "by": "actor_user_name",
          "key": [
            "src_endpoint_ip"
          ],
          "rare_below": 2
        },
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "agent-weaponization-triage",
      "type": "analytic",
      "label": "Correlate harvesting with abuse",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity"
        ],
        "context": [
          "scoping-executive-assets",
          "infra-marketplace-dns",
          "auth-executive-anomalies",
          "agent-harvesting-triage"
        ],
        "objective": "Determine if the earlier harvesting evidence correlates with marketplace access or anomalous sign-ins for the same executive identity.",
        "description": "Final assessment of whether a confirmed harvesting event on a host led to successful marketplace trade or impersonation.",
        "max_iterations": 10,
        "expected_signal": "A high-confidence verdict on executive identity compromise.",
        "success_criteria": "A final verdict citing the link between the host harvesting and the subsequent auth/network activity."
      },
      "parents": [
        {
          "id": "infra-marketplace-dns",
          "kind": "merge"
        },
        {
          "id": "auth-executive-anomalies",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the agent-weaponization-triage verdict is malicious or suspicious for at least one host",
        "condition": "the agent-weaponization-triage verdict is malicious or suspicious for at least one host",
        "blind_spot": "no-endpoint-telemetry",
        "confidence": "high",
        "description": "Direct the hunt based on the agent's confidence in identity theft.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "agent-weaponization-triage"
        }
      ]
    },
    {
      "id": "isolate-endpoint",
      "type": "action",
      "label": "Isolate affected host",
      "config": {
        "target": "endpoint",
        "description": "Contain the threat by isolating the host that showed harvesting behavior.",
        "instructions": "Isolate the endpoint and revoke all active cloud/SaaS sessions for the affected executive user.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Analyst forensic review",
      "config": {
        "assignee": "analyst",
        "description": "Manually verify the findings and investigate for further lateral movement.",
        "instructions": "Review the cited DNS traffic and sign-in anomalies. Check if the 'harvesting' processes attempted to move laterally to other sensitive systems or databases."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-endpoint"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out hunt",
      "config": {
        "assignee": "analyst",
        "description": "Finalize documentation for negative results.",
        "instructions": "Record the window and users examined; note any visibility gaps discovered."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        }
      ]
    }
  ]
}