{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Initial access through identity-led phishing is a top priority; verifying targeted hosts are not vulnerable to follow-on exploitation reduces breach risk."
      },
      "name": "Identity Access and Exposure Investigation",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1566",
        "attack.t1078",
        "attack.t1078.004",
        "execution",
        "impact",
        "initial access",
        "lateral movement",
        "persistence"
      ],
      "series": {
        "slug": "6-ai-soc-integrations-actually-worth-connecting",
        "index": 1,
        "title": "6 AI SOC Integrations Actually Worth Connecting",
        "total": 2
      },
      "related": [
        {
          "hunt": "suspicious-cloud-runtime-execution",
          "reason": "This hunt confirms initial ingress; the follow-on hunt monitors what happens once the cloud identity is used for suspicious execution.",
          "relation": "follows"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        },
        "identity": {
          "name": "Identity / sign-in telemetry",
          "category": "identity",
          "telemetry": [
            "identity"
          ]
        }
      },
      "analysis": "A detection rule alerts on the domain visit; this hunt is required because it joins intent with host vulnerability and the statistical rarity of authentication behavior. A single rule cannot weigh whether a phishing hit on a high-risk host with rare MFA-less logins constitutes a confirmed breach.",
      "coverage": [
        {
          "stage": "initial-access-phishing-portals",
          "steps": [
            "phishing-lead",
            "agent-triage-lead"
          ],
          "status": "covered"
        },
        {
          "stage": "vulnerability-and-exposure-discovery",
          "steps": [
            "vulnerability-lookup"
          ],
          "status": "covered"
        },
        {
          "stage": "credential-abuse-and-mfa-evasion",
          "steps": [
            "rare-auth-anomalies"
          ],
          "status": "covered"
        },
        {
          "stage": "suspicious-cloud-runtime-execution",
          "reason": "Belongs to another part of the '6 AI SOC Integrations Actually Worth Connecting' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "lateral-movement-segmentation-violation",
          "reason": "Belongs to another part of the '6 AI SOC Integrations Actually Worth Connecting' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "data-encryption-for-impact",
          "reason": "Belongs to another part of the '6 AI SOC Integrations Actually Worth Connecting' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "incident-alerting-and-response",
          "reason": "Belongs to another part of the '6 AI SOC Integrations Actually Worth Connecting' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Credential Harvesting via Phishing Portals",
            "slug": "initial-access-phishing-portals",
            "tactic": "initial-access",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "bottleneck.the",
              "Mokn authentication portals",
              "Credential testing activity"
            ]
          },
          {
            "name": "Vulnerability and Exposure Discovery",
            "slug": "vulnerability-and-exposure-discovery",
            "tactic": "initial-access",
            "techniques": [
              "T1078"
            ],
            "observables": [
              "Holm Security vulnerability scans",
              "Asset risk profiling",
              "Exposed human assets"
            ]
          },
          {
            "name": "Credential Abuse and MFA Evasion",
            "slug": "credential-abuse-and-mfa-evasion",
            "tactic": "persistence",
            "techniques": [
              "T1078"
            ],
            "observables": [
              "Silverfort MFA decisions",
              "Suspicious access patterns",
              "Policy actions",
              "Hybrid environment authentication logs"
            ]
          },
          {
            "name": "Suspicious Cloud Runtime Execution",
            "slug": "suspicious-cloud-runtime-execution",
            "tactic": "execution",
            "techniques": [
              "T1078"
            ],
            "observables": [
              "Upwind runtime workload monitoring",
              "Process accessing sensitive resource",
              "Anomalous cloud asset behavior"
            ]
          },
          {
            "name": "Lateral Movement across Segments",
            "slug": "lateral-movement-segmentation-violation",
            "tactic": "lateral-movement",
            "techniques": [
              "T1078"
            ],
            "observables": [
              "Akamai Guardicore network traffic logs",
              "Communication between isolated workloads",
              "Zero Trust policy violations"
            ]
          },
          {
            "name": "Data Encryption for Impact",
            "slug": "data-encryption-for-impact",
            "tactic": "impact",
            "techniques": [
              "T1486"
            ],
            "observables": [
              "Ransomware activity",
              "Spyware delivery",
              "Mass file modification"
            ]
          },
          {
            "name": "Incident Alerting and Response",
            "slug": "incident-alerting-and-response",
            "tactic": "impact",
            "techniques": [
              "T1486"
            ],
            "observables": [
              "ilert incident notifications",
              "Slack notification webhooks",
              "Teams alert messages",
              "Voice call escalation"
            ]
          }
        ],
        "summary": "An adversary leverages deceptive authentication portals to harvest credentials and identifies unpatched vulnerabilities across the attack surface. The campaign progresses to cloud runtime execution and lateral movement across microsegmented workloads, culminating in ransomware encryption and automated incident notification."
      },
      "severity": "medium",
      "rationale": "Start with public-facing users and servers. Focus on assets with recent high-severity vulnerability findings reported by Holm Security.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary has harvested credentials through a phishing portal and is now using them to access vulnerable assets while attempting to evade multi-factor authentication.",
      "parameters": {
        "target_hosts": {
          "from": {
            "ref": "analyst-pivot",
            "kind": "manual",
            "observed": "2024-01-01"
          },
          "type": "list[host]",
          "default": [],
          "description": "Target hostnames extracted from the phishing lead step to focus the expensive queries."
        },
        "target_users": {
          "from": {
            "ref": "analyst-pivot",
            "kind": "manual",
            "observed": "2024-01-01"
          },
          "type": "list[string]",
          "default": [],
          "description": "Usernames extracted from the phishing lead step to focus authentication analysis."
        },
        "lookback_days": {
          "from": {
            "ref": "hunt-standard-config",
            "kind": "manual",
            "observed": "2024-01-01"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine for phishing hits and authentication anomalies."
        },
        "phishing_domains": {
          "from": {
            "ref": "sekoia-ai-soc-2026",
            "kind": "article",
            "observed": "2026-08-19"
          },
          "type": "list[domain]",
          "default": [
            "bottleneck.the"
          ],
          "description": "Domains identified as Mokn-realistic phishing portals or known harvesting sites."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.sekoia.com/blog/ai-soc-integrations-6-capabilities-worth-connecting",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.sekoia.com/blog/ai-soc-integrations-6-capabilities-worth-connecting",
          "name": "6 AI SOC Integrations Actually Worth Connecting"
        }
      ],
      "blind_spots": [
        {
          "id": "insufficient-proxy-visibility",
          "risk": "A domain-level hit is a lead, but without path visibility, we cannot distinguish a visit from a successful harvest.",
          "owner": "Network Engineering",
          "stage": "initial-access-phishing-portals",
          "question": "Whether the user submitted credentials on the phishing subpath.",
          "requires": "hb_http_activity with decrypted SSL traffic",
          "remediation": "Enable SSL decryption for known risky categories on the forward proxy."
        },
        {
          "id": "identity-log-gaps",
          "risk": "Silverfort context is high-quality, but if the hunt lacks visibility into on-prem DCs, legacy protocol abuse remains a blind spot.",
          "owner": "Identity Team",
          "stage": "credential-abuse-and-mfa-evasion",
          "question": "Whether the adversary used legacy protocols to bypass MFA.",
          "requires": "hb_auth_signin including on-prem legacy logs",
          "remediation": "Onboard domain controller logs into the identity surface via Silverfort connector."
        }
      ]
    },
    "name": "Identity Access and Exposure Investigation",
    "description": "Identifies traffic to phishing portals and correlates hits with critical asset vulnerabilities and rare authentication anomalies to detect credential abuse or MFA evasion."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "6-ai-soc-integrations-actually-worth-connecting",
          "index": 1,
          "title": "6 AI SOC Integrations Actually Worth Connecting",
          "total": 2
        },
        "coverage": [
          {
            "stage": "initial-access-phishing-portals",
            "steps": [
              "phishing-lead",
              "agent-triage-lead"
            ],
            "status": "covered"
          },
          {
            "stage": "vulnerability-and-exposure-discovery",
            "steps": [
              "vulnerability-lookup"
            ],
            "status": "covered"
          },
          {
            "stage": "credential-abuse-and-mfa-evasion",
            "steps": [
              "rare-auth-anomalies"
            ],
            "status": "covered"
          },
          {
            "stage": "suspicious-cloud-runtime-execution",
            "reason": "Belongs to another part of the '6 AI SOC Integrations Actually Worth Connecting' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "lateral-movement-segmentation-violation",
            "reason": "Belongs to another part of the '6 AI SOC Integrations Actually Worth Connecting' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "data-encryption-for-impact",
            "reason": "Belongs to another part of the '6 AI SOC Integrations Actually Worth Connecting' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "incident-alerting-and-response",
            "reason": "Belongs to another part of the '6 AI SOC Integrations Actually Worth Connecting' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary has harvested credentials through a phishing portal and is now using them to access vulnerable assets while attempting to evade multi-factor authentication.",
        "blind_spots": [
          {
            "id": "insufficient-proxy-visibility",
            "risk": "A domain-level hit is a lead, but without path visibility, we cannot distinguish a visit from a successful harvest.",
            "owner": "Network Engineering",
            "stage": "initial-access-phishing-portals",
            "question": "Whether the user submitted credentials on the phishing subpath.",
            "requires": "hb_http_activity with decrypted SSL traffic",
            "remediation": "Enable SSL decryption for known risky categories on the forward proxy."
          },
          {
            "id": "identity-log-gaps",
            "risk": "Silverfort context is high-quality, but if the hunt lacks visibility into on-prem DCs, legacy protocol abuse remains a blind spot.",
            "owner": "Identity Team",
            "stage": "credential-abuse-and-mfa-evasion",
            "question": "Whether the adversary used legacy protocols to bypass MFA.",
            "requires": "hb_auth_signin including on-prem legacy logs",
            "remediation": "Onboard domain controller logs into the identity surface via Silverfort connector."
          }
        ],
        "scoping_notes": "Start with public-facing users and servers. Focus on assets with recent high-severity vulnerability findings reported by Holm Security.",
        "beyond_detection": "A detection rule alerts on the domain visit; this hunt is required because it joins intent with host vulnerability and the statistical rarity of authentication behavior. A single rule cannot weigh whether a phishing hit on a high-risk host with rare MFA-less logins constitutes a confirmed breach."
      }
    },
    {
      "id": "phishing-lead",
      "type": "query",
      "label": "Traffic to phishing portals",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "web",
        "content": "SELECT device_hostname, actor_user_name, url_hostname, url_path, time FROM hb_http_activity WHERE LOWER(url_hostname) IN ('{{phishing_domains}}') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_http_activity",
        "description": "Identify hosts and users interacting with known credential harvesting domains to establish a lead.",
        "expected_signal": "Hostnames and users visiting suspicious domains. Silence means no recorded interaction with the indicators."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Traffic to phishing portals",
        "reads": [
          "device_hostname",
          "actor_user_name",
          "url_hostname",
          "url_path",
          "time"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT device_hostname, actor_user_name, url_hostname, url_path, time FROM hb_http_activity WHERE LOWER(url_hostname) IN ('{{phishing_domains}}') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Hostnames and users visiting suspicious domains. Silence means no recorded interaction with the indicators.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "agent-triage-lead",
      "type": "analytic",
      "label": "Evaluate phishing lead",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity",
          "web"
        ],
        "context": [
          "phishing-lead"
        ],
        "objective": "Determine if the observed phishing interactions are credible threats needing deeper investigation.",
        "description": "Decide if the HTTP traffic warrants searching into vulnerabilities and authentication logs.",
        "max_iterations": 3,
        "expected_signal": "A verdict per host on whether the traffic matches credential-harvesting behavior.",
        "success_criteria": "A verdict of investigate for any confirmed portal hits."
      },
      "parents": [
        {
          "id": "phishing-lead"
        }
      ]
    },
    {
      "id": "gate-decision",
      "type": "checkpoint",
      "label": "Gate on phishing",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the agent verdict is to investigate for at least one host",
        "condition": "the agent verdict is to investigate for at least one host",
        "blind_spot": "insufficient-proxy-visibility",
        "confidence": "medium",
        "description": "Route the hunt based on the quality of the initial lead to save resources.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "agent-triage-lead"
        }
      ]
    },
    {
      "id": "vulnerability-lookup",
      "type": "query",
      "label": "Affected asset vulnerability findings",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT v.device_uid, d.hostname, v.cve_uid, v.severity, v.title FROM hb_vulnerability_finding v JOIN hb_devices d ON v.device_uid = d.device_uid WHERE v.severity_id >= 4 AND (('{{target_hosts}}' = '') OR (instr(',' || '{{target_hosts}}' || ',', ',' || d.hostname || ',') > 0))",
        "surface": "hb_vulnerability_finding",
        "description": "Correlate the phishing lead with host vulnerability using Holm Security data.",
        "expected_signal": "Critical or High findings on the target host. Silence means no severe vulnerabilities are present."
      },
      "parents": [
        {
          "id": "gate-decision",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Affected asset vulnerability findings",
        "reads": [
          "device_uid",
          "cve_uid",
          "severity",
          "title",
          "severity_id"
        ],
        "source": "hb_vulnerability_finding",
        "target": "endpoint",
        "content": "SELECT v.device_uid, d.hostname, v.cve_uid, v.severity, v.title FROM hb_vulnerability_finding v JOIN hb_devices d ON v.device_uid = d.device_uid WHERE v.severity_id >= 4 AND (('{{target_hosts}}' = '') OR (instr(',' || '{{target_hosts}}' || ',', ',' || d.hostname || ',') > 0))",
        "silence": "not_evidence_of_absence",
        "expected": "Critical or High findings on the target host. Silence means no severe vulnerabilities are present.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "rare-auth-anomalies",
      "type": "query",
      "label": "Rare authentication anomalies",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "identity",
        "content": "SELECT actor_user_name, auth_protocol, status_detail, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_auth_signin WHERE (status_id = 2 OR (status_id = 1 AND (mfa = 'false' OR mfa IS NULL))) AND (('{{target_users}}' = '') OR (instr(',' || '{{target_users}}' || ',', ',' || actor_user_name || ',') > 0)) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, auth_protocol, status_detail HAVING host_count <= 2",
        "surface": "hb_auth_signin",
        "description": "Identify rare login failures or successful logins without MFA to detect credential abuse.",
        "expected_signal": "Rare failure patterns or MFA bypasses for the user. Silence means the authentication pattern is fleet-wide noise."
      },
      "parents": [
        {
          "id": "gate-decision",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare authentication anomalies",
        "reads": [
          "actor_user_name",
          "auth_protocol",
          "status_detail",
          "device_hostname",
          "time",
          "status_id",
          "mfa"
        ],
        "source": "hb_auth_signin",
        "target": "identity",
        "content": "SELECT actor_user_name, auth_protocol, status_detail, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_auth_signin WHERE (status_id = 2 OR (status_id = 1 AND (mfa = 'false' OR mfa IS NULL))) AND (('{{target_users}}' = '') OR (instr(',' || '{{target_users}}' || ',', ',' || actor_user_name || ',') > 0)) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, auth_protocol, status_detail HAVING host_count <= 2",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Rare failure patterns or MFA bypasses for the user. Silence means the authentication pattern is fleet-wide noise.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "actor_user_name",
            "auth_protocol",
            "status_detail"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "final-triage",
      "type": "analytic",
      "label": "Cross-surface triage",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity",
          "web"
        ],
        "context": [
          "agent-triage-lead",
          "vulnerability-lookup",
          "rare-auth-anomalies"
        ],
        "objective": "Determine if the harvested credentials target vulnerable assets with suspicious login patterns.",
        "description": "Correlate phishing intent, host vulnerability, and auth behavior to confirm an active intrusion.",
        "max_iterations": 6,
        "expected_signal": "A malicious verdict citing rows from three surfaces.",
        "success_criteria": "A per-host verdict weighing vulnerabilities against the phishing hit."
      },
      "parents": [
        {
          "id": "vulnerability-lookup",
          "kind": "merge"
        },
        {
          "id": "rare-auth-anomalies",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-decision",
      "type": "checkpoint",
      "label": "Route on evidence",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the final triage verdict is malicious for at least one host or user",
        "condition": "the final triage verdict is malicious for at least one host or user",
        "blind_spot": "identity-log-gaps",
        "confidence": "high",
        "description": "Trigger containment for malicious hits or manual review for suspicious ones.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "final-triage"
        }
      ]
    },
    {
      "id": "isolate-and-suspend",
      "type": "action",
      "label": "Isolate host and suspend account",
      "config": {
        "target": "endpoint",
        "description": "Contain the breach once credential abuse on a vulnerable asset is confirmed.",
        "instructions": "Isolate the involved host and suspend the user identity in the primary provider.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-decision",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "manual-review",
      "type": "task",
      "label": "Analyst manual review",
      "config": {
        "assignee": "analyst",
        "description": "Confirm agentic findings and perform detailed incident response.",
        "instructions": "Review correlated evidence: verify the phishing portal URL, specific vulnerabilities, and rarity of authentication events. Adjust detections based on findings."
      },
      "parents": [
        {
          "id": "gate-decision",
          "branch": "default"
        },
        {
          "id": "gate-decision",
          "branch": "on_unavailable"
        },
        {
          "id": "route-decision",
          "branch": "default"
        },
        {
          "id": "route-decision",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-and-suspend"
        }
      ]
    },
    {
      "id": "negative-close-out",
      "type": "task",
      "label": "Negative close-out",
      "config": {
        "assignee": "analyst",
        "description": "Record hunt results when no confirmed threat is found.",
        "instructions": "Log the negative result; verify if blind spots significantly limited the search."
      },
      "parents": [
        {
          "id": "gate-decision",
          "branch": "on_refutes"
        },
        {
          "id": "route-decision",
          "branch": "on_refutes"
        }
      ]
    }
  ]
}