{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "The 2026 Digital Defense Report shows government sectors are the primary target for identity-led ransomware. A negative result confirms that while initial probes may occur, they are not maturing into high-impact encryption events."
      },
      "name": "Identity-Led Intrusion and Ransomware Impact",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1078",
        "attack.t1195",
        "attack.t1486",
        "attack.t1566",
        "credential access",
        "impact",
        "initial access"
      ],
      "related": [
        {
          "hunt": "lateral-movement-via-rdp",
          "reason": "This hunt focuses on the ransomware impact phase; RDP movement is a sibling stage requiring hb_auth_signin with logon type 10.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        },
        "identity": {
          "name": "Identity / sign-in telemetry",
          "category": "identity",
          "telemetry": [
            "identity"
          ]
        }
      },
      "analysis": "A detection rule might catch a dumping tool, but it cannot see the correlation between a rare domain contact, an anomalous sign-in, and a spike in file modifications. This hunt pivots across four surfaces to confirm the full attack chain.",
      "coverage": [
        {
          "stage": "initial-access-phishing-and-supply-chain",
          "steps": [
            "phishing-traffic"
          ],
          "status": "covered"
        },
        {
          "stage": "identity-compromise-valid-accounts",
          "steps": [
            "anomalous-logons"
          ],
          "status": "covered"
        },
        {
          "stage": "post-compromise-credential-theft",
          "steps": [
            "credential-dumping"
          ],
          "status": "covered"
        },
        {
          "stage": "ransomware-and-data-impact",
          "steps": [
            "ransomware-file-spikes"
          ],
          "status": "covered"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Phishing and Supply Chain Entry",
            "slug": "initial-access-phishing-and-supply-chain",
            "tactic": "initial-access",
            "techniques": [
              "T1566",
              "T1195"
            ],
            "observables": [
              "HTTP requests to phishing domains",
              "Compromised software updates",
              "Social engineering links"
            ]
          },
          {
            "name": "Valid Account Abuse",
            "slug": "identity-compromise-valid-accounts",
            "tactic": "initial-access",
            "techniques": [
              "T1078"
            ],
            "observables": [
              "Sign-ins from anomalous source IPs",
              "Logons using unusual user agents",
              "Authentication via password or session token abuse"
            ]
          },
          {
            "name": "Secondary Credential Harvesting",
            "slug": "post-compromise-credential-theft",
            "tactic": "credential-access",
            "techniques": [
              "T1078"
            ],
            "observables": [
              "Abuse of legitimate administrative tools for credential dumping",
              "Unauthorized access to password stores",
              "Lateral movement using secondary compromised accounts"
            ]
          },
          {
            "name": "Data Encryption and Impact",
            "slug": "ransomware-and-data-impact",
            "tactic": "impact",
            "techniques": [
              "T1486"
            ],
            "observables": [
              "Mass file modification or encryption",
              "Process activity involving ransomware binaries",
              "Access to sensitive files for exfiltration"
            ]
          }
        ],
        "summary": "Government agencies in 2026 are increasingly targeted by nation-state actors and cybercriminals using phishing and supply chain compromises to gain initial footholds. These attackers leverage compromised identities and valid accounts to perform secondary credential theft, often leading to ransomware encryption or sensitive data exfiltration."
      },
      "severity": "high",
      "rationale": "Focus on servers and workstations running productivity software or VPN clients. The analyst uses the identify-targets step to populate scope_hosts, narrowing the hunt to the most likely entry points.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary has compromised a government identity via phishing, leveraged valid accounts to harvest credentials, and is now encrypting files for impact.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Restrict the hunt to specific hosts; leave empty for fleet-wide."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "phishing_domains": {
          "from": {
            "ref": "msrc-2026-report",
            "kind": "article",
            "observed": "2026-10-01"
          },
          "type": "list[domain]",
          "default": [
            "login-gov-verify.com",
            "secure-portal-update.net",
            "m365-security-update.org"
          ],
          "description": "Reported or suspected phishing domains."
        },
        "cred_dump_strings": {
          "type": "list[string]",
          "default": [
            "mimikatz",
            "nanodump",
            "procdump",
            "ntdsutil"
          ],
          "description": "Keywords associated with credential dumping tools."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://blogs.microsoft.com/on-the-issues/2026/10/01/preparing-governments-for-an-era-of-interconnected-cyber-risk/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://blogs.microsoft.com/on-the-issues/2026/10/01/preparing-governments-for-an-era-of-interconnected-cyber-risk/",
          "name": "MSRC Blog \u2014 Preparing governments for an era of interconnected cyber risk"
        }
      ],
      "blind_spots": [
        {
          "id": "no-file-telemetry",
          "risk": "A host without file-level logging will show no results in the impact step, causing a false negative for encryption.",
          "stage": "ransomware-and-data-impact",
          "question": "whether the file modification volume on an isolated host matches ransomware encryption",
          "requires": "hb_file_activity on the host"
        },
        {
          "id": "session-hijacking",
          "risk": "Legitimate-looking sign-ins using session tokens bypass source IP anomalies if the attacker is in a similar geography.",
          "stage": "identity-compromise-valid-accounts",
          "question": "whether a successful sign-in used MFA or a hijacked session token",
          "requires": "hb_auth_signin with mfa column populated"
        }
      ]
    },
    "name": "Identity-Led Intrusion and Ransomware Impact",
    "description": "According to the 2026 Microsoft Digital Defense Report, government institutions are increasingly targeted by identity-based intrusions. The hunt identifies initial compromise via phishing or supply chain signals, then pivots to detect follow-on credential harvesting and mass file encryption. Finally, the analyst reviews the evidence to confirm if a beachhead has matured into a full-scale encryption event."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "coverage": [
          {
            "stage": "initial-access-phishing-and-supply-chain",
            "steps": [
              "phishing-traffic"
            ],
            "status": "covered"
          },
          {
            "stage": "identity-compromise-valid-accounts",
            "steps": [
              "anomalous-logons"
            ],
            "status": "covered"
          },
          {
            "stage": "post-compromise-credential-theft",
            "steps": [
              "credential-dumping"
            ],
            "status": "covered"
          },
          {
            "stage": "ransomware-and-data-impact",
            "steps": [
              "ransomware-file-spikes"
            ],
            "status": "covered"
          }
        ],
        "rationale": "An adversary has compromised a government identity via phishing, leveraged valid accounts to harvest credentials, and is now encrypting files for impact.",
        "blind_spots": [
          {
            "id": "no-file-telemetry",
            "risk": "A host without file-level logging will show no results in the impact step, causing a false negative for encryption.",
            "stage": "ransomware-and-data-impact",
            "question": "whether the file modification volume on an isolated host matches ransomware encryption",
            "requires": "hb_file_activity on the host"
          },
          {
            "id": "session-hijacking",
            "risk": "Legitimate-looking sign-ins using session tokens bypass source IP anomalies if the attacker is in a similar geography.",
            "stage": "identity-compromise-valid-accounts",
            "question": "whether a successful sign-in used MFA or a hijacked session token",
            "requires": "hb_auth_signin with mfa column populated"
          }
        ],
        "scoping_notes": "Focus on servers and workstations running productivity software or VPN clients. The analyst uses the identify-targets step to populate scope_hosts, narrowing the hunt to the most likely entry points.",
        "beyond_detection": "A detection rule might catch a dumping tool, but it cannot see the correlation between a rare domain contact, an anomalous sign-in, and a spike in file modifications. This hunt pivots across four surfaces to confirm the full attack chain."
      }
    },
    {
      "id": "identify-targets",
      "type": "query",
      "label": "Identify targets via software inventory",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT DISTINCT device_hostname FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%office%' OR LOWER(package_name) LIKE '%browser%' OR LOWER(package_name) LIKE '%outlook%' OR LOWER(package_name) LIKE '%vpn%')",
        "surface": "hb_software_inventory",
        "description": "Search software inventory for apps like browsers and VPNs. The analyst populates the scope_hosts parameter with these discovered hostnames to focus the subsequent queries.",
        "expected_signal": "A list of hostnames. Silence suggests inventory collection is missing."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify targets via software inventory",
        "reads": [
          "device_hostname",
          "package_name"
        ],
        "source": "hb_software_inventory",
        "target": "endpoint",
        "content": "SELECT DISTINCT device_hostname FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%office%' OR LOWER(package_name) LIKE '%browser%' OR LOWER(package_name) LIKE '%outlook%' OR LOWER(package_name) LIKE '%vpn%')",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hostnames. Silence suggests inventory collection is missing.",
        "verified": "dry-run",
        "verified_at": "2026-10-02"
      }
    },
    {
      "id": "phishing-traffic",
      "type": "query",
      "label": "Rare or known phishing domain traffic",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "web",
        "content": "SELECT url_hostname, device_hostname, COUNT(*) as request_count FROM hb_http_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY url_hostname, device_hostname HAVING url_hostname IN (SELECT url_hostname FROM hb_http_activity GROUP BY url_hostname HAVING COUNT(DISTINCT device_hostname) < 3) OR instr(',' || '{{phishing_domains}}' || ',', ',' || LOWER(url_hostname) || ',') > 0",
        "surface": "hb_http_activity",
        "description": "Identify hosts contacting suspected phishing domains or rare domains seen on fewer than 3 unique hosts across the fleet.",
        "expected_signal": "Rare domain requests per host. Silence proves no targeted domains were contacted."
      },
      "parents": [
        {
          "id": "identify-targets"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare or known phishing domain traffic",
        "reads": [
          "device_hostname",
          "url_hostname",
          "time"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT url_hostname, device_hostname, COUNT(*) as request_count FROM hb_http_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY url_hostname, device_hostname HAVING url_hostname IN (SELECT url_hostname FROM hb_http_activity GROUP BY url_hostname HAVING COUNT(DISTINCT device_hostname) < 3) OR instr(',' || '{{phishing_domains}}' || ',', ',' || LOWER(url_hostname) || ',') > 0",
        "silence": "evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Rare domain requests per host. Silence proves no targeted domains were contacted.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "url_hostname"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-10-02"
      }
    },
    {
      "id": "anomalous-logons",
      "type": "query",
      "label": "Anomalous authentication patterns",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "identity",
        "content": "SELECT actor_user_name, src_endpoint_ip, dst_endpoint_hostname, COUNT(*) as signin_count, MIN(time) as first_seen FROM hb_auth_signin WHERE status_id = 1 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, src_endpoint_ip, dst_endpoint_hostname HAVING signin_count < 3",
        "surface": "hb_auth_signin",
        "description": "Identify credentials used from rare source IPs or to rare destinations, suggesting valid account abuse.",
        "expected_signal": "A list of rare authentications. Silence suggests sign-ins match historical patterns."
      },
      "parents": [
        {
          "id": "identify-targets"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Anomalous authentication patterns",
        "reads": [
          "actor_user_name",
          "src_endpoint_ip",
          "dst_endpoint_hostname",
          "time",
          "status_id"
        ],
        "source": "hb_auth_signin",
        "target": "identity",
        "content": "SELECT actor_user_name, src_endpoint_ip, dst_endpoint_hostname, COUNT(*) as signin_count, MIN(time) as first_seen FROM hb_auth_signin WHERE status_id = 1 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, src_endpoint_ip, dst_endpoint_hostname HAVING signin_count < 3",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A list of rare authentications. Silence suggests sign-ins match historical patterns.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "actor_user_name",
            "src_endpoint_ip"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-10-02"
      }
    },
    {
      "id": "early-triage",
      "type": "analytic",
      "label": "Early stage evidence triage",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity",
          "web"
        ],
        "context": [
          "phishing-traffic",
          "anomalous-logons"
        ],
        "objective": "Evaluate if the phishing traffic and anomalous sign-ins on a host suggest a successful initial compromise.",
        "description": "The agent determines if any host shows combined signs of identity compromise and malicious network traffic.",
        "max_iterations": 3,
        "expected_signal": "Verdicts identifying hosts as suspicious or malicious beachheads.",
        "success_criteria": "A per-host verdict citing specific rows from both queries where they overlap."
      },
      "parents": [
        {
          "id": "phishing-traffic",
          "kind": "merge"
        },
        {
          "id": "anomalous-logons",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "credential-dumping",
      "type": "query",
      "label": "In-memory credential dumping",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE on_disk = 0 AND (instr('{{cred_dump_strings}}', LOWER(process_name)) > 0 OR instr('{{cred_dump_strings}}', LOWER(process_cmd_line)) > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Find execution of tools used to harvest credentials, specifically filtering for processes running from memory (on_disk = 0).",
        "expected_signal": "In-memory processes associated with credential harvesting. Silence means no known strings were matched."
      },
      "parents": [
        {
          "id": "early-triage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "In-memory credential dumping",
        "reads": [
          "device_hostname",
          "process_name",
          "process_cmd_line",
          "user_name",
          "on_disk",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE on_disk = 0 AND (instr('{{cred_dump_strings}}', LOWER(process_name)) > 0 OR instr('{{cred_dump_strings}}', LOWER(process_cmd_line)) > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "In-memory processes associated with credential harvesting. Silence means no known strings were matched.",
        "verified": "dry-run",
        "verified_at": "2026-10-02"
      }
    },
    {
      "id": "ransomware-file-spikes",
      "type": "query",
      "label": "Mass file modification spikes",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT device_hostname, actor_user_name, COUNT(*) as file_ops, MIN(time) as first_op FROM hb_file_activity WHERE activity_id IN (3, 4) AND LOWER(file_path) NOT LIKE '%\\\\cache\\\\%' AND LOWER(file_path) NOT LIKE '%\\\\temp\\\\%' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, actor_user_name HAVING file_ops > 500",
        "surface": "hb_file_activity",
        "description": "Identify hosts experiencing abnormal volumes of file updates or deletions, excluding common cache and temp directories.",
        "expected_signal": "Spikes in file operations per host and user. Silence suggests no mass encryption occurred."
      },
      "parents": [
        {
          "id": "early-triage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Mass file modification spikes",
        "reads": [
          "device_hostname",
          "actor_user_name",
          "activity_id",
          "file_path",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, actor_user_name, COUNT(*) as file_ops, MIN(time) as first_op FROM hb_file_activity WHERE activity_id IN (3, 4) AND LOWER(file_path) NOT LIKE '%\\\\cache\\\\%' AND LOWER(file_path) NOT LIKE '%\\\\temp\\\\%' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, actor_user_name HAVING file_ops > 500",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "new_this_window"
        },
        "expected": "Spikes in file operations per host and user. Silence suggests no mass encryption occurred.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "file_ops"
          ],
          "rare_below": 2
        },
        "verified_at": "2026-10-02"
      }
    },
    {
      "id": "full-chain-triage",
      "type": "analytic",
      "label": "Full chain intrusion triage",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity",
          "web"
        ],
        "context": [
          "early-triage",
          "credential-dumping",
          "ransomware-file-spikes"
        ],
        "objective": "Evaluate if the suspicious beachheads identified in early-triage have now progressed to credential theft and mass file encryption.",
        "description": "Correlate early access verdicts with follow-on tool use and file impact to confirm a mature ransomware intrusion.",
        "max_iterations": 5,
        "expected_signal": "A comprehensive verdict for each impacted host.",
        "success_criteria": "A final malicious verdict for any host showing the progression from compromise to impact."
      },
      "parents": [
        {
          "id": "credential-dumping",
          "kind": "merge"
        },
        {
          "id": "ransomware-file-spikes",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-impact",
      "type": "checkpoint",
      "label": "Route based on intrusion depth",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the full-chain-triage verdict is malicious for at least one host and shows file impact evidence",
        "condition": "the full-chain-triage verdict is malicious for at least one host and shows file impact evidence",
        "blind_spot": "no-file-telemetry",
        "confidence": "high",
        "description": "The decision isolates the host if the intrusion has matured into file encryption.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "full-chain-triage"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate endpoint",
      "config": {
        "target": "endpoint",
        "description": "Sever the network connection of the compromised host to halt ransomware encryption.",
        "instructions": "Isolate the host via the EDR to stop lateral movement and encryption. Proceed to forensic analysis.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-impact",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Forensic review and recovery",
      "config": {
        "assignee": "analyst",
        "description": "Verify the extent of the encryption and identify any data exfiltration paths.",
        "instructions": "Review the hb_file_activity results for the specific file paths touched. Check for staging directories and verify the actor account permissions."
      },
      "parents": [
        {
          "id": "route-on-impact",
          "branch": "default"
        },
        {
          "id": "route-on-impact",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Hunt close-out",
      "config": {
        "assignee": "analyst",
        "description": "Document findings and update phishing domain parameters for future hunts.",
        "instructions": "Record the malicious or benign outcome. Update the phishing_domains parameter with any new domains identified during the hunt."
      },
      "parents": [
        {
          "id": "route-on-impact",
          "branch": "on_refutes"
        },
        {
          "id": "analyst-review"
        }
      ]
    }
  ]
}