{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Infostealers are a high-risk precursor to enterprise data breaches. A negative result across the enrolled estate provides assurance that current campaigns targeting browser credentials have not gained a foothold."
      },
      "name": "Infostealer execution and browser credential harvesting",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1566",
        "attack.t1555",
        "attack.t1486"
      ],
      "series": {
        "slug": "the-story-behind-the-intelligence",
        "index": 1,
        "title": "The story behind the intelligence",
        "total": 2
      },
      "related": [
        {
          "hunt": "sso-session-cookie-reuse",
          "reason": "This hunt finds the harvesting of cookies; the sibling hunt looks for their use in Okta or Azure AD sign-ins.",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "While static rules alert on the malware hashes, this hunt pivots into the behavioral aftermath: non-browser processes accessing SQLite files in browser profiles and rare processes communicating with 'sbx.tg' domains. It connects the execution to the behavioral context of credential theft.",
      "coverage": [
        {
          "stage": "initial-access-social-engineering",
          "steps": [
            "phishing-kit-indicators"
          ],
          "status": "covered"
        },
        {
          "stage": "execution-infostealer-malware",
          "steps": [
            "lead-indicator-execution",
            "c2-dns-activity"
          ],
          "status": "covered"
        },
        {
          "stage": "credential-access-browser-harvesting",
          "steps": [
            "credential-file-access"
          ],
          "status": "covered"
        },
        {
          "stage": "credential-access-sso-takeover",
          "reason": "Belongs to another part of the 'The story behind the intelligence' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "impact-data-theft-and-encryption",
          "reason": "Belongs to another part of the 'The story behind the intelligence' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Vishing and Phishing Kits",
            "slug": "initial-access-social-engineering",
            "tactic": "initial-access",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "vishing calls to employees",
              "obfuscated JavaScript phishing kits",
              "content.js",
              "malicious unofficial downloads"
            ]
          },
          {
            "name": "Infostealer and Tool Execution",
            "slug": "execution-infostealer-malware",
            "tactic": "execution",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "VID001.exe",
              "NetGuard.exe",
              "SECOH-QAD.exe",
              "sample.exe",
              "d4aa3e7010220ad1b458fac17039c274_62_Exe.exe",
              "w32.9f1f11a708-100.sbx.tg",
              "win.dropper.miner"
            ]
          },
          {
            "name": "Browser Credential and Cookie Harvesting",
            "slug": "credential-access-browser-harvesting",
            "tactic": "credential-access",
            "techniques": [
              "T1555"
            ],
            "observables": [
              "saved browser passwords",
              "browser login cookies",
              "credentials for local applications"
            ]
          },
          {
            "name": "Okta SSO Account Takeover",
            "slug": "credential-access-sso-takeover",
            "tactic": "credential-access",
            "techniques": [
              "T1555"
            ],
            "observables": [
              "stolen credentials used for Okta single sign-on accounts",
              "unauthorized Okta session established"
            ]
          },
          {
            "name": "Data Exfiltration and Ransomware",
            "slug": "impact-data-theft-and-encryption",
            "tactic": "impact",
            "techniques": [
              "T1486"
            ],
            "observables": [
              "284 million patient records stolen",
              "Azim sucks text string in ransomware code",
              "unauthorized file encryption"
            ]
          }
        ],
        "summary": "Threat actors such as ShinyHunters leverage vishing and obfuscated JavaScript phishing kits to harvest credentials and session cookies from employees. These stolen identities are then utilized to bypass Okta SSO protections, enabling large-scale data exfiltration and the deployment of infostealers or ransomware."
      },
      "severity": "high",
      "rationale": "The hunt begins by identifying all hosts with browser installations using software inventory, then narrows the scope to these hosts for behavioral queries. This focuses the investigation on potential targets for credential harvesting.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary has successfully phished a user and executed an infostealer, which is now harvesting browser credentials and cookies from local SQLite databases for exfiltration.",
      "parameters": {
        "c2_domains": {
          "from": {
            "ref": "https://blog.talosintelligence.com/the-story-behind-the-intelligence/",
            "kind": "article",
            "observed": "2026-09-03"
          },
          "type": "list[domain]",
          "default": [
            "w32.9f1f11a708-100.sbx.tg",
            "w32.228c316455-95.sbx.tg",
            "95.sbx.tg",
            "w32.c4dd71e347-95.sbx.tg",
            "w32.38d053135d-95.sbx.tg"
          ],
          "description": "Sandbox-associated C2 domains identified in the research."
        },
        "scope_hosts": {
          "from": {
            "ref": "hunt-standard",
            "kind": "manual",
            "observed": "2026-09-03"
          },
          "type": "list[host]",
          "default": [],
          "description": "Optional list of hosts to narrow the investigation based on the scoping step."
        },
        "lookback_days": {
          "from": {
            "ref": "hunt-standard",
            "kind": "manual",
            "observed": "2026-09-03"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine for process, file, and network activity."
        },
        "infostealer_hashes": {
          "from": {
            "ref": "https://blog.talosintelligence.com/the-story-behind-the-intelligence/",
            "kind": "article",
            "observed": "2026-09-03"
          },
          "type": "list[hash]",
          "default": [
            "9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507",
            "228c316455d5ed69232adcbe9acd033092f200014cfa7ed40d6c382f07b19b82",
            "a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91",
            "c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2",
            "38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55",
            "9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f"
          ],
          "description": "Infostealer SHA256 hashes identified by Talos telemetry."
        },
        "infostealer_filenames": {
          "from": {
            "ref": "https://blog.talosintelligence.com/the-story-behind-the-intelligence/",
            "kind": "article",
            "observed": "2026-09-03"
          },
          "type": "list[path]",
          "default": [
            "VID001.exe",
            "NetGuard.exe",
            "SECOH-QAD.exe",
            "sample.exe",
            "content.js"
          ],
          "description": "Known filenames associated with malicious infostealer and phishing kit drops."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://blog.talosintelligence.com/the-story-behind-the-intelligence/",
          "gates": [
            "dry-run",
            "lint",
            "critic"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://blog.talosintelligence.com/the-story-behind-the-intelligence/",
          "name": "Talos \u2014 The story behind the intelligence"
        }
      ],
      "blind_spots": [
        {
          "id": "no-process-visibility",
          "risk": "A negative result only covers the enrolled estate; unmanaged servers may remain infected.",
          "owner": "Infrastructure",
          "stage": "execution-infostealer-malware",
          "question": "whether the infostealer ran on unmanaged or legacy systems",
          "requires": "an endpoint agent on every host",
          "remediation": "Audit device inventory against hb_devices and enroll missing endpoints."
        },
        {
          "id": "obfuscated-js-visibility",
          "risk": "The hunt finds the script drop, but cannot observe the in-memory execution of its payload.",
          "owner": "Detection Engineering",
          "stage": "initial-access-social-engineering",
          "question": "what the specific commands inside the obfuscated content.js script were",
          "requires": "hb_script_activity with de-obfuscation",
          "remediation": "Enable PowerShell script block logging and ensure script content is captured in hb_script_activity."
        }
      ]
    },
    "name": "Infostealer execution and browser credential harvesting",
    "description": "This hunt targets the endpoint-centric phase of infostealer campaigns, where initial malware execution leads to local credential theft. It uses a gated flow: first identifying systems with vulnerable browser targets, then looking for known malware execution. If confirmed, it expands to behavioral queries that identify rare processes accessing browser login data or communicating with sandbox-associated C2 infrastructure. This sequence identifies the activity before stolen session cookies are used to bypass MFA in subsequent SSO takeovers."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "the-story-behind-the-intelligence",
          "index": 1,
          "title": "The story behind the intelligence",
          "total": 2
        },
        "coverage": [
          {
            "stage": "initial-access-social-engineering",
            "steps": [
              "phishing-kit-indicators"
            ],
            "status": "covered"
          },
          {
            "stage": "execution-infostealer-malware",
            "steps": [
              "lead-indicator-execution",
              "c2-dns-activity"
            ],
            "status": "covered"
          },
          {
            "stage": "credential-access-browser-harvesting",
            "steps": [
              "credential-file-access"
            ],
            "status": "covered"
          },
          {
            "stage": "credential-access-sso-takeover",
            "reason": "Belongs to another part of the 'The story behind the intelligence' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "impact-data-theft-and-encryption",
            "reason": "Belongs to another part of the 'The story behind the intelligence' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary has successfully phished a user and executed an infostealer, which is now harvesting browser credentials and cookies from local SQLite databases for exfiltration.",
        "blind_spots": [
          {
            "id": "no-process-visibility",
            "risk": "A negative result only covers the enrolled estate; unmanaged servers may remain infected.",
            "owner": "Infrastructure",
            "stage": "execution-infostealer-malware",
            "question": "whether the infostealer ran on unmanaged or legacy systems",
            "requires": "an endpoint agent on every host",
            "remediation": "Audit device inventory against hb_devices and enroll missing endpoints."
          },
          {
            "id": "obfuscated-js-visibility",
            "risk": "The hunt finds the script drop, but cannot observe the in-memory execution of its payload.",
            "owner": "Detection Engineering",
            "stage": "initial-access-social-engineering",
            "question": "what the specific commands inside the obfuscated content.js script were",
            "requires": "hb_script_activity with de-obfuscation",
            "remediation": "Enable PowerShell script block logging and ensure script content is captured in hb_script_activity."
          }
        ],
        "scoping_notes": "The hunt begins by identifying all hosts with browser installations using software inventory, then narrows the scope to these hosts for behavioral queries. This focuses the investigation on potential targets for credential harvesting.",
        "beyond_detection": "While static rules alert on the malware hashes, this hunt pivots into the behavioral aftermath: non-browser processes accessing SQLite files in browser profiles and rare processes communicating with 'sbx.tg' domains. It connects the execution to the behavioral context of credential theft."
      }
    },
    {
      "id": "scoping-browsers",
      "type": "query",
      "label": "Find hosts with browser installations",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_hostname, package_name, package_version, vendor_name FROM hb_software_inventory WHERE LOWER(package_name) LIKE '%chrome%' OR LOWER(package_name) LIKE '%edge%'",
        "surface": "hb_software_inventory",
        "description": "Identify hosts that serve as primary targets for infostealer harvesting by locating Chrome and Edge installations.",
        "expected_signal": "A list of hosts with installed browsers. Silence means no browsers are inventoried, which is unlikely in an enterprise environment."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Find hosts with browser installations",
        "reads": [
          "device_hostname",
          "package_name",
          "package_version",
          "vendor_name"
        ],
        "source": "hb_software_inventory",
        "target": "endpoint",
        "content": "SELECT device_hostname, package_name, package_version, vendor_name FROM hb_software_inventory WHERE LOWER(package_name) LIKE '%chrome%' OR LOWER(package_name) LIKE '%edge%'",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hosts with installed browsers. Silence means no browsers are inventoried, which is unlikely in an enterprise environment.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "lead-indicator-execution",
      "type": "query",
      "label": "Lead infostealer hash execution",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_path, process_hash_sha256, user_name, time FROM hb_process_activity WHERE instr(',' || '{{infostealer_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Identify hosts where known malicious binaries from the Talos report have executed.",
        "expected_signal": "Rows mapping known malicious hashes to execution on specific hosts. Silence means these specific variants did not run."
      },
      "parents": [
        {
          "id": "scoping-browsers"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Lead infostealer hash execution",
        "reads": [
          "device_hostname",
          "process_name",
          "process_path",
          "process_hash_sha256",
          "user_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_path, process_hash_sha256, user_name, time FROM hb_process_activity WHERE instr(',' || '{{infostealer_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Rows mapping known malicious hashes to execution on specific hosts. Silence means these specific variants did not run.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "lead-gatekeeper",
      "type": "analytic",
      "label": "Evaluate lead evidence",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "lead-indicator-execution"
        ],
        "objective": "Review the lead-indicator-execution results and decide if any malicious hashes executed on the estate.",
        "description": "Determine if the findings in the lead query are sufficiently suspicious to warrant expensive behavioral analysis.",
        "max_iterations": 3,
        "expected_signal": "A decision on whether the found hashes represent a validated infostealer infection.",
        "success_criteria": "A verdict of malicious or suspicious for at least one host."
      },
      "parents": [
        {
          "id": "lead-indicator-execution"
        }
      ]
    },
    {
      "id": "gate-decision",
      "type": "checkpoint",
      "label": "Gate the behavioral investigation",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the lead-gatekeeper verdict is malicious or suspicious for at least one host",
        "condition": "the lead-gatekeeper verdict is malicious or suspicious for at least one host",
        "confidence": "high",
        "description": "Stop the hunt early if no malicious execution is found, or open behavioral queries if it is.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "lead-gatekeeper"
        }
      ]
    },
    {
      "id": "credential-file-access",
      "type": "query",
      "label": "Rare processes reading browser stores",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, file_path, COUNT(*) AS access_count, MIN(time) AS first_seen FROM hb_file_activity WHERE (LOWER(file_path) LIKE '%\\\\user data\\\\default\\\\login data%' OR LOWER(file_path) LIKE '%\\\\user data\\\\default\\\\cookies%') AND activity_id = 2 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name, file_path HAVING access_count < 15",
        "surface": "hb_file_activity",
        "description": "Identify processes other than the browser itself reading sensitive SQLite databases containing passwords and session cookies.",
        "expected_signal": "A process (like a dropped executable or script) reading browser database files. Normal browser use generates high access counts; rare processes with low counts stand out."
      },
      "parents": [
        {
          "id": "gate-decision",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Rare processes reading browser stores",
        "reads": [
          "device_hostname",
          "process_name",
          "file_path",
          "activity_id",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, file_path, COUNT(*) AS access_count, MIN(time) AS first_seen FROM hb_file_activity WHERE (LOWER(file_path) LIKE '%\\\\user data\\\\default\\\\login data%' OR LOWER(file_path) LIKE '%\\\\user data\\\\default\\\\cookies%') AND activity_id = 2 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name, file_path HAVING access_count < 15",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A process (like a dropped executable or script) reading browser database files. Normal browser use generates high access counts; rare processes with low counts stand out.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_name"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "c2-dns-activity",
      "type": "query",
      "label": "DNS activity to sandbox domains",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, query_hostname, process_name, COUNT(*) AS lookups, MIN(time) AS first_seen FROM hb_dns_activity WHERE (instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 OR LOWER(query_hostname) LIKE '%.sbx.tg') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, query_hostname, process_name",
        "surface": "hb_dns_activity",
        "description": "Identify network communication with the sandbox-derived C2 domains named in the report.",
        "expected_signal": "DNS queries for sandbox-generated domains (e.g., w32.c4dd...sbx.tg). Silence says nothing if indicators have rotated."
      },
      "parents": [
        {
          "id": "gate-decision",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "DNS activity to sandbox domains",
        "reads": [
          "device_hostname",
          "query_hostname",
          "process_name",
          "time"
        ],
        "source": "hb_dns_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, query_hostname, process_name, COUNT(*) AS lookups, MIN(time) AS first_seen FROM hb_dns_activity WHERE (instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 OR LOWER(query_hostname) LIKE '%.sbx.tg') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, query_hostname, process_name",
        "silence": "not_evidence_of_absence",
        "expected": "DNS queries for sandbox-generated domains (e.g., w32.c4dd...sbx.tg). Silence says nothing if indicators have rotated.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "phishing-kit-indicators",
      "type": "query",
      "label": "Phishing kit file drops",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, file_name, file_path, actor_user_name, time FROM hb_file_activity WHERE instr(',' || '{{infostealer_filenames}}' || ',', ',' || LOWER(file_name) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_file_activity",
        "description": "Search for the presence of the content.js phishing script or other dropped files mentioned in the Talos research.",
        "expected_signal": "The creation of files like content.js in user profiles, typically preceding the harvesting phase."
      },
      "parents": [
        {
          "id": "gate-decision",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Phishing kit file drops",
        "reads": [
          "device_hostname",
          "file_name",
          "file_path",
          "actor_user_name",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, file_name, file_path, actor_user_name, time FROM hb_file_activity WHERE instr(',' || '{{infostealer_filenames}}' || ',', ',' || LOWER(file_name) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "The creation of files like content.js in user profiles, typically preceding the harvesting phase.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "combined-triage",
      "type": "analytic",
      "label": "Combined behavioral triage",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "lead-gatekeeper",
          "credential-file-access",
          "c2-dns-activity",
          "phishing-kit-indicators"
        ],
        "objective": "Determine if the evidence supports an active infostealer infection currently harvesting credentials on any host.",
        "description": "Weigh the evidence from initial execution against observed file access and network patterns to reach a final verdict.",
        "max_iterations": 6,
        "expected_signal": "A detailed per-host verdict citing rows across execution, file, and DNS steps.",
        "success_criteria": "Verdicts (malicious | suspicious | benign) with specific citations for every identified host."
      },
      "parents": [
        {
          "id": "credential-file-access",
          "kind": "merge"
        },
        {
          "id": "c2-dns-activity",
          "kind": "merge"
        },
        {
          "id": "phishing-kit-indicators",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-verdict",
      "type": "checkpoint",
      "label": "Route on final verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the combined-triage verdict is malicious for at least one host",
        "condition": "the combined-triage verdict is malicious for at least one host",
        "blind_spot": "no-process-visibility",
        "confidence": "high",
        "description": "Initiate automated containment for confirmed infections or route to an analyst for further review.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "combined-triage"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate compromised host",
      "config": {
        "target": "endpoint",
        "description": "Sever network connectivity for infected hosts to prevent credential exfiltration.",
        "instructions": "Isolate the host and initiate a password reset for the logged-in user to invalidate potentially harvested session cookies.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Post-hunt analyst review",
      "config": {
        "assignee": "analyst",
        "description": "Perform manual validation of suspicious findings and extract new indicators.",
        "instructions": "Review the cited evidence of browser store access and DNS activity. If confirmed, identify any secondary payloads or lateral movement attempts and update the C2 indicator list."
      },
      "parents": [
        {
          "id": "route-verdict",
          "branch": "default"
        },
        {
          "id": "route-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "route-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Hunt close-out",
      "config": {
        "assignee": "analyst",
        "description": "Document the findings for a negative hunt result.",
        "instructions": "Record that zero matches were found for the specific infostealer variants and behavioral patterns during the examination period."
      },
      "parents": [
        {
          "id": "gate-decision",
          "branch": "default"
        },
        {
          "id": "gate-decision",
          "branch": "on_unavailable"
        },
        {
          "id": "gate-decision",
          "branch": "on_refutes"
        }
      ]
    }
  ]
}