{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Gamaredon is a high-tempo, FSB-linked actor targeting government infrastructure. Their modular approach using registry-resident payloads and ADS-hidden worms requires a multi-surface hunt to bypass standard detection layers."
      },
      "name": "Gamaredon Modular Espionage Chain",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1190",
        "attack.t1566",
        "attack.t1218.005",
        "attack.t1059.001",
        "attack.t1071",
        "attack.t1053.005",
        "attack.t1041",
        "attack.t1555"
      ],
      "related": [
        {
          "hunt": "gammawiper-behavioral-hunt",
          "reason": "GammaWipe is a destructive component often used against researchers; this hunt focuses on the espionage and exfiltration chain.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A standard detection rule for mshta.exe or Run keys lacks the context to connect them to the 70+ registry modules or the ADS-hidden worm. This phased hunt correlates initial vulnerability status with high-volume modular writes and propagation indicators across the entire infection lifecycle.",
      "coverage": [
        {
          "stage": "gammaphish-initial-access-exploit",
          "steps": [
            "vulnerable-winrar-hosts",
            "mshta-startup-or-remote"
          ],
          "status": "covered"
        },
        {
          "stage": "gammaload-vbscript-staging",
          "steps": [
            "gammaload-registry-run"
          ],
          "status": "covered"
        },
        {
          "stage": "gammaworm-propagation-persistence",
          "steps": [
            "gammaworm-ads-lnk"
          ],
          "status": "covered"
        },
        {
          "stage": "gammasteel-powershell-exfiltration",
          "steps": [
            "gammasteel-registry-blobs",
            "intrusion-chain-agent"
          ],
          "status": "covered"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "GammaPhish Initial Access via WinRAR Exploit",
            "slug": "gammaphish-initial-access-exploit",
            "tactic": "initial-access",
            "techniques": [
              "T1190",
              "T1566",
              "T1218.005"
            ],
            "observables": [
              "Weaponised xHTML files",
              "Malicious RAR archives",
              "CVE-2025-8088 exploitation",
              "HTA files extracted to \\Microsoft\\Windows\\Start Menu\\Programs\\Startup",
              "mshta.exe execution calling remote staging URLs"
            ]
          },
          {
            "name": "GammaLoad VBScript Staging",
            "slug": "gammaload-vbscript-staging",
            "tactic": "execution",
            "techniques": [
              "T1059.001",
              "T1071"
            ],
            "observables": [
              "Cascade of VBScript loaders",
              "Host fingerprinting via script",
              "Dead Drop Resolvers (DDR) stored in Windows registry",
              "HTTP requests for additional VBScript payloads"
            ]
          },
          {
            "name": "GammaWorm Propagation and Persistence",
            "slug": "gammaworm-propagation-persistence",
            "tactic": "persistence",
            "techniques": [
              "T1053.005",
              "T1059.001"
            ],
            "observables": [
              "Obfuscated VBScript worm (LitterDrifter)",
              "Malicious code hidden in NTFS Alternate Data Streams (ADS)",
              "Scheduled tasks for persistence",
              "Creation of LNK shortcut files on USB and network drives",
              "Hiding of legitimate directories on removable media"
            ]
          },
          {
            "name": "GammaSteel PowerShell Exfiltration",
            "slug": "gammasteel-powershell-exfiltration",
            "tactic": "exfiltration",
            "techniques": [
              "T1041",
              "T1555",
              "T1059.001"
            ],
            "observables": [
              "Modular PowerShell stealer",
              "71 distinct modules stored as encrypted registry values",
              "Encryption using Windows Data Protection API (DPAPI)",
              "Real-time monitoring of local/network file modifications",
              "Exfiltration to S3-compatible cloud storage",
              "Fallback C2 communication for remote code execution"
            ]
          }
        ],
        "summary": "Gamaredon (FSB) 2026 espionage campaign targeting Ukrainian entities through a modular infection chain including GammaPhish initial access, GammaLoad staging, GammaWorm propagation, and GammaSteel exfiltration. The campaign leverages a critical WinRAR vulnerability (CVE-2025-8088) to drop payloads that persist via registry keys, NTFS Alternate Data Streams, and scheduled tasks."
      },
      "severity": "high",
      "rationale": "Scope the hunt to all Windows endpoints, prioritizing those with vulnerable versions of WinRAR as identified in hb_software_inventory.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An intruder has exploited a Windows WinRAR path traversal vulnerability to execute HTA-based loaders, subsequently deploying VBScript stagers, an ADS-resident worm, and a modular PowerShell stealer persisting in the registry.",
      "parameters": {
        "cve_id": {
          "from": {
            "ref": "sekoia_gamaredon_2026",
            "kind": "article",
            "observed": "2026-06-11"
          },
          "type": "string",
          "default": "CVE-2025-8088",
          "description": "WinRAR vulnerability used in the initial GammaPhish stage."
        },
        "scope_hosts": {
          "from": {
            "ref": "analyst_input",
            "kind": "manual",
            "observed": "2026-06-11"
          },
          "type": "list[host]",
          "default": [],
          "description": "Limit the hunt to specific hostnames; leave empty for fleet-wide analysis."
        },
        "lookback_days": {
          "from": {
            "ref": "default_retention",
            "kind": "manual",
            "observed": "2026-06-11"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "startup_path_pattern": {
          "from": {
            "ref": "standard_windows_path",
            "kind": "manual",
            "observed": "2026-06-11"
          },
          "type": "path",
          "default": "%\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\%",
          "description": "Standard startup folder path for HTA extraction."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.sekoia.com/blog/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.sekoia.com/blog/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm",
          "name": "Sekoia \u2014 FSB\u2019s matryoshka #1/3: Inside Gamaredon Cyber Operations"
        }
      ],
      "blind_spots": [
        {
          "id": "no-endpoint-telemetry",
          "risk": "An unmanaged vulnerable host can act as a silent staging platform or propagation source.",
          "question": "Which unmanaged hosts are vulnerable to CVE-2025-8088?",
          "requires": "endpoint agent coverage"
        },
        {
          "id": "encryption-hides-payload",
          "risk": "While we can detect the existence of modules via registry write volume, their encrypted nature hides their specific functional logic from static analysis.",
          "stage": "gammasteel-powershell-exfiltration",
          "question": "What is the content and functionality of the individual PowerShell modules?",
          "requires": "forensic DPAPI key extraction"
        },
        {
          "id": "ads-visibility",
          "risk": "If the file sensor ignores or truncates stream identifiers, GammaWorm persistence will remain invisible to behavioral queries.",
          "stage": "gammaworm-propagation-persistence",
          "question": "Are NTFS Alternate Data Streams visible in the file sensor telemetry?",
          "requires": "hb_file_activity that resolves NTFS streams"
        }
      ]
    },
    "name": "Gamaredon Modular Espionage Chain",
    "description": "This hunt reconstructs the multi-stage Gamaredon (UAC-0010) Matryoshka infection chain. It begins by identifying vulnerable WinRAR instances (CVE-2025-8088) and subsequent mshta.exe execution. It then pivots to find GammaLoad VBScript persistence and GammaWorm propagation via Alternate Data Streams and LNK files. Finally, the hunt identifies GammaSteel exfiltration modules by detecting high-volume encrypted registry values, which the group uses to maintain stealth and persistence across Ukrainian targets."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "coverage": [
          {
            "stage": "gammaphish-initial-access-exploit",
            "steps": [
              "vulnerable-winrar-hosts",
              "mshta-startup-or-remote"
            ],
            "status": "covered"
          },
          {
            "stage": "gammaload-vbscript-staging",
            "steps": [
              "gammaload-registry-run"
            ],
            "status": "covered"
          },
          {
            "stage": "gammaworm-propagation-persistence",
            "steps": [
              "gammaworm-ads-lnk"
            ],
            "status": "covered"
          },
          {
            "stage": "gammasteel-powershell-exfiltration",
            "steps": [
              "gammasteel-registry-blobs",
              "intrusion-chain-agent"
            ],
            "status": "covered"
          }
        ],
        "rationale": "An intruder has exploited a Windows WinRAR path traversal vulnerability to execute HTA-based loaders, subsequently deploying VBScript stagers, an ADS-resident worm, and a modular PowerShell stealer persisting in the registry.",
        "blind_spots": [
          {
            "id": "no-endpoint-telemetry",
            "risk": "An unmanaged vulnerable host can act as a silent staging platform or propagation source.",
            "question": "Which unmanaged hosts are vulnerable to CVE-2025-8088?",
            "requires": "endpoint agent coverage"
          },
          {
            "id": "encryption-hides-payload",
            "risk": "While we can detect the existence of modules via registry write volume, their encrypted nature hides their specific functional logic from static analysis.",
            "stage": "gammasteel-powershell-exfiltration",
            "question": "What is the content and functionality of the individual PowerShell modules?",
            "requires": "forensic DPAPI key extraction"
          },
          {
            "id": "ads-visibility",
            "risk": "If the file sensor ignores or truncates stream identifiers, GammaWorm persistence will remain invisible to behavioral queries.",
            "stage": "gammaworm-propagation-persistence",
            "question": "Are NTFS Alternate Data Streams visible in the file sensor telemetry?",
            "requires": "hb_file_activity that resolves NTFS streams"
          }
        ],
        "scoping_notes": "Scope the hunt to all Windows endpoints, prioritizing those with vulnerable versions of WinRAR as identified in hb_software_inventory.",
        "beyond_detection": "A standard detection rule for mshta.exe or Run keys lacks the context to connect them to the 70+ registry modules or the ADS-hidden worm. This phased hunt correlates initial vulnerability status with high-volume modular writes and propagation indicators across the entire infection lifecycle."
      }
    },
    {
      "id": "vulnerable-winrar-hosts",
      "type": "query",
      "label": "Inventory vulnerable WinRAR instances",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_uid, resource_uid, affected_package_version, severity FROM hb_vulnerability_finding WHERE cve_uid = '{{cve_id}}' AND status != 'suppressed'",
        "surface": "hb_vulnerability_finding",
        "description": "Identify hosts in the estate that are vulnerable to the WinRAR path traversal vulnerability CVE-2025-8088, establishing the initial scope.",
        "expected_signal": "A list of host UIDs and resource identifiers reporting the WinRAR vulnerability. Silence proves the vulnerability is not currently present in the scanned inventory."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Inventory vulnerable WinRAR instances",
        "reads": [
          "affected_package_version",
          "cve_uid",
          "device_uid",
          "resource_uid",
          "severity",
          "status"
        ],
        "source": "hb_vulnerability_finding",
        "target": "endpoint",
        "content": "SELECT device_uid, resource_uid, affected_package_version, severity FROM hb_vulnerability_finding WHERE cve_uid = '{{cve_id}}' AND status != 'suppressed'",
        "silence": "not_evidence_of_absence",
        "expected": "A list of host UIDs and resource identifiers reporting the WinRAR vulnerability. Silence proves the vulnerability is not currently present in the scanned inventory.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "mshta-startup-or-remote",
      "type": "query",
      "label": "GammaPhish MSHTA staging",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_cmd_line, user_name, time FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%\\\\mshta.exe' OR LOWER(process_name) = 'mshta.exe') AND (LOWER(process_cmd_line) LIKE '%http%' OR LOWER(process_cmd_line) LIKE LOWER('{{startup_path_pattern}}')) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Identify mshta.exe executing payloads from remote URLs or the Startup directory, typical of GammaPhish staging.",
        "expected_signal": "Process events showing mshta.exe reaching out to staging URLs or running an HTA from a user startup path."
      },
      "parents": [
        {
          "id": "vulnerable-winrar-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "GammaPhish MSHTA staging",
        "reads": [
          "device_hostname",
          "process_cmd_line",
          "process_name",
          "time",
          "user_name"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_cmd_line, user_name, time FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%\\\\mshta.exe' OR LOWER(process_name) = 'mshta.exe') AND (LOWER(process_cmd_line) LIKE '%http%' OR LOWER(process_cmd_line) LIKE LOWER('{{startup_path_pattern}}')) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Process events showing mshta.exe reaching out to staging URLs or running an HTA from a user startup path.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "gammaload-registry-run",
      "type": "query",
      "label": "GammaLoad VBScript persistence",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "endpoint",
        "content": "SELECT device_hostname, reg_target, reg_value_data, time FROM hb_registry_activity WHERE (LOWER(reg_target) LIKE '%\\\\currentversion\\\\run%' OR LOWER(reg_target) LIKE '%\\\\currentversion\\\\runonce%') AND (LOWER(reg_value_data) LIKE '%.vbs%' OR LOWER(reg_value_data) LIKE '%wscript%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_registry_activity",
        "description": "Search for VBScript loaders established in standard registry Run/RunOnce keys, indicating GammaLoad persistence.",
        "expected_signal": "Registry values pointing to VBScript files in autorun locations. Silence means no such persistence is present in the telemetry."
      },
      "parents": [
        {
          "id": "vulnerable-winrar-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "GammaLoad VBScript persistence",
        "reads": [
          "device_hostname",
          "reg_target",
          "reg_value_data",
          "time"
        ],
        "source": "hb_registry_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, reg_target, reg_value_data, time FROM hb_registry_activity WHERE (LOWER(reg_target) LIKE '%\\\\currentversion\\\\run%' OR LOWER(reg_target) LIKE '%\\\\currentversion\\\\runonce%') AND (LOWER(reg_value_data) LIKE '%.vbs%' OR LOWER(reg_value_data) LIKE '%wscript%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Registry values pointing to VBScript files in autorun locations. Silence means no such persistence is present in the telemetry.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "early-stage-triage",
      "type": "analytic",
      "label": "Triage early infection stages",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "vulnerable-winrar-hosts",
          "mshta-startup-or-remote",
          "gammaload-registry-run"
        ],
        "objective": "Identify if vulnerable WinRAR hosts show signs of successful HTA staging or VBScript loader execution.",
        "description": "Correlate host vulnerability status with observed initial access and persistence events.",
        "max_iterations": 4,
        "expected_signal": "Per-host verdict for early-stage compromise.",
        "success_criteria": "A verdict for each host citing evidence of early-stage infection."
      },
      "parents": [
        {
          "id": "mshta-startup-or-remote",
          "kind": "merge"
        },
        {
          "id": "gammaload-registry-run",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "gammaworm-ads-lnk",
      "type": "query",
      "label": "GammaWorm ADS and LNK creation",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, file_path, process_name, time FROM hb_file_activity WHERE (instr(substr(file_path, 4), ':') > 0 OR LOWER(file_name) LIKE '%.lnk') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_file_activity",
        "description": "Detect GammaWorm (LitterDrifter) activity by identifying the creation of Alternate Data Streams and suspicious LNK shortcut files.",
        "expected_signal": "File paths containing colons past the drive letter (ADS) or a volume of new LNK files. Silence indicates no such visible propagation."
      },
      "parents": [
        {
          "id": "early-stage-triage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "GammaWorm ADS and LNK creation",
        "reads": [
          "device_hostname",
          "file_name",
          "file_path",
          "process_name",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, file_path, process_name, time FROM hb_file_activity WHERE (instr(substr(file_path, 4), ':') > 0 OR LOWER(file_name) LIKE '%.lnk') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "File paths containing colons past the drive letter (ADS) or a volume of new LNK files. Silence indicates no such visible propagation.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "gammasteel-registry-blobs",
      "type": "query",
      "label": "GammaSteel modular registry storage",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, reg_key_path, COUNT(*) AS module_count, MIN(time) AS first_write FROM hb_registry_activity WHERE state_kind = 'log' AND (LOWER(reg_key_path) LIKE '%software\\\\microsoft\\\\%' OR LOWER(reg_key_path) LIKE '%software\\\\classes\\\\%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, reg_key_path HAVING module_count > 50",
        "surface": "hb_registry_activity",
        "description": "Identify GammaSteel's modular footprint by counting high volumes of values written to a single registry key path, indicative of the 70+ encrypted modules.",
        "expected_signal": "A registry key on a host containing more than 50 values (Gamaredon uses ~71). This stack-count highlights modular deployment."
      },
      "parents": [
        {
          "id": "early-stage-triage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "GammaSteel modular registry storage",
        "reads": [
          "device_hostname",
          "reg_key_path",
          "state_kind",
          "time"
        ],
        "source": "hb_registry_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, reg_key_path, COUNT(*) AS module_count, MIN(time) AS first_write FROM hb_registry_activity WHERE state_kind = 'log' AND (LOWER(reg_key_path) LIKE '%software\\\\microsoft\\\\%' OR LOWER(reg_key_path) LIKE '%software\\\\classes\\\\%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, reg_key_path HAVING module_count > 50",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "new_this_window"
        },
        "expected": "A registry key on a host containing more than 50 values (Gamaredon uses ~71). This stack-count highlights modular deployment.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "reg_key_path"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "intrusion-chain-agent",
      "type": "analytic",
      "label": "Unified Matryoshka chain assessment",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "early-stage-triage",
          "gammaworm-ads-lnk",
          "gammasteel-registry-blobs"
        ],
        "objective": "Determine if the evidence supports a full-chain Gamaredon compromise, building on the early-stage triage.",
        "description": "Synthesize early-stage and follow-on evidence to confirm a complete Gamaredon intrusion.",
        "max_iterations": 5,
        "expected_signal": "A high-confidence assessment of the infection chain per host.",
        "success_criteria": "A detailed verdict citing the transition from initial access to modular stealer deployment."
      },
      "parents": [
        {
          "id": "gammaworm-ads-lnk",
          "kind": "merge"
        },
        {
          "id": "gammasteel-registry-blobs",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on chain verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the intrusion-chain-agent verdict is malicious for at least one host",
        "condition": "the intrusion-chain-agent verdict is malicious for at least one host",
        "blind_spot": "no-endpoint-telemetry",
        "confidence": "high",
        "description": "Direct response or forensic actions based on the confidence of the intrusion chain verdict.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "intrusion-chain-agent"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate compromised host",
      "config": {
        "target": "endpoint",
        "description": "Halt the exfiltration of sensitive documents by GammaSteel and prevent worm propagation.",
        "instructions": "Isolate the host from the network immediately to prevent data exfiltration and further worm propagation.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "manual-review",
      "type": "task",
      "label": "Forensic review and module recovery",
      "config": {
        "assignee": "analyst",
        "description": "Acquire the modular encrypted payloads from the registry for deeper analysis.",
        "instructions": "Collect the registry hives from identified hosts to extract GammaSteel modules. Verify the content of Alternate Data Streams on the filesystem to confirm worm persistence. Review USB insertion history for possible propagation events."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Hunt close out",
      "config": {
        "assignee": "analyst",
        "description": "Document findings and assess detection gaps for modular registry storage.",
        "instructions": "Summarize the findings per host. If the high-volume registry module query provided high-fidelity results, recommend promoting it to a permanent detection rule for modular malware storage."
      },
      "parents": [
        {
          "id": "manual-review"
        }
      ]
    }
  ]
}