{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "AI is accelerating the discovery of vulnerabilities in legacy OT systems that cannot be patched; identifying segmentation bypass attempts is the primary compensatory control for these unpatchable assets."
      },
      "name": "Legacy System Access and Segmentation Bypass",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1190",
        "attack.t1133",
        "attack.t1046",
        "attack.t1021",
        "discovery",
        "initial access",
        "lateral movement"
      ],
      "related": [
        {
          "hunt": "ot-protocol-anomaly-detection",
          "reason": "This hunt focuses on the boundary violation, not the parsing of specific OT protocols like Modbus or DNP3.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "network": {
          "name": "Network telemetry",
          "category": "network",
          "telemetry": [
            "network"
          ]
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        },
        "identity": {
          "name": "Identity / sign-in telemetry",
          "category": "identity",
          "telemetry": [
            "identity"
          ]
        }
      },
      "analysis": "A simple detection rule might alert on a single failed login or a known web exploit; this hunt correlates the perimeter noise with internal network discovery and unauthorized cross-segment connections to find the full intrusion path.",
      "coverage": [
        {
          "stage": "exploit-public-facing-application",
          "steps": [
            "perimeter-exploit-attempts"
          ],
          "status": "covered"
        },
        {
          "stage": "unauthorized-remote-bridge",
          "steps": [
            "suspicious-remote-logins"
          ],
          "status": "covered"
        },
        {
          "stage": "internal-asset-discovery",
          "steps": [
            "internal-discovery-scans"
          ],
          "status": "covered"
        },
        {
          "stage": "segmentation-boundary-violation",
          "steps": [
            "segmentation-violation"
          ],
          "status": "covered"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Exploitation of Unpatched Public Applications",
            "slug": "exploit-public-facing-application",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "Exploit attempts against internet-facing web servers",
              "Traffic targeting legacy or end-of-life software components",
              "Known-vulnerable software versions on public endpoints"
            ]
          },
          {
            "name": "Unauthorized Remote Service Bridge",
            "slug": "unauthorized-remote-bridge",
            "tactic": "initial-access",
            "techniques": [
              "T1133"
            ],
            "observables": [
              "VPN connections from unauthorized or temporary sources",
              "Rogue wireless bridges connected to OT environments",
              "Unauthorized VPN and remote access shortcuts used by staff/contractors"
            ]
          },
          {
            "name": "Internal Discovery of Isolated Systems",
            "slug": "internal-asset-discovery",
            "tactic": "discovery",
            "techniques": [
              "T1046"
            ],
            "observables": [
              "Internal network fingerprinting of legacy systems",
              "Scanning of internal subnets for OT protocols and service ports",
              "Identification of predictable network fingerprints from unpatchable hardware"
            ]
          },
          {
            "name": "Lateral Movement across Segmentation Boundaries",
            "slug": "segmentation-boundary-violation",
            "tactic": "lateral-movement",
            "techniques": [
              "T1021"
            ],
            "observables": [
              "Traffic violating micro-segmentation ACLs or VLAN boundaries",
              "Unauthorized communication from compromised internal hosts to critical OT segments",
              "Deep packet inspection alerts from NGFW/IPS upstream of legacy devices"
            ]
          }
        ],
        "summary": "Threat actors leverage AI-accelerated vulnerability discovery to exploit unpatchable legacy and OT systems, gaining entry through internet-facing application flaws or unauthorized remote access bridges. Once inside, adversaries identify and move laterally to isolated critical assets by bypassing intended air gaps and micro-segmentation boundaries."
      },
      "severity": "medium",
      "rationale": "Focus on subnets containing OT/ICS or legacy infrastructure. The authorized_admin_ips list should be populated with known management workstation or Bastion IP addresses.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary is exploiting unpatchable public-facing services or unauthorized VPN bridges to discover and laterally move toward isolated legacy OT assets.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Optional list of hostnames to focus on; defaults to all discovered vulnerable assets."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "authorized_admin_ips": {
          "from": {
            "ref": "https://blog.talosintelligence.com/securing-the-unpatchable-in-an-age-of-ai-driven-vulnerabilities/",
            "kind": "article",
            "observed": "2026-09-16"
          },
          "type": "list[ip]",
          "default": [
            "10.0.0.50",
            "192.168.1.100"
          ],
          "description": "IP addresses authorized to manage legacy or OT segments."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://blog.talosintelligence.com/securing-the-unpatchable-in-an-age-of-ai-driven-vulnerabilities/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://blog.talosintelligence.com/securing-the-unpatchable-in-an-age-of-ai-driven-vulnerabilities/",
          "name": "Talos \u2014 Securing the unpatchable in an age of AI-driven vulnerabilities"
        }
      ],
      "blind_spots": [
        {
          "id": "limited-segmentation-telemetry",
          "risk": "If an adversary pivots through a host without an agent or into a segment without flow logging, the segmentation violation is invisible.",
          "stage": "segmentation-boundary-violation",
          "question": "Does the hunt see all traffic across VLANs?",
          "requires": "hb_network_connection from both VPC flow logs and endpoint agents"
        },
        {
          "id": "packet-payload-visibility",
          "risk": "hb_http_activity shows the request but not whether an upstream IPS killed the session, leading to false positives.",
          "stage": "exploit-public-facing-application",
          "question": "Was the exploit payload successfully blocked by virtual patching?",
          "requires": "NGFW/IPS logs with deep packet inspection results"
        }
      ]
    },
    "name": "Legacy System Access and Segmentation Bypass",
    "description": "The adversary exploits unpatchable public-facing services or unauthorized VPN bridges to discover and laterally move toward isolated legacy OT assets. This hunt identifies compromised beachheads and their attempts to violate internal network boundaries. It focuses on systems with known vulnerabilities that cannot be patched, searching for exploit attempts on the perimeter followed by internal scanning or unauthorized cross-segment communication. An analyst reviews the resulting intrusion chains to confirm if attackers bypassed micro-segmentation controls."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "coverage": [
          {
            "stage": "exploit-public-facing-application",
            "steps": [
              "perimeter-exploit-attempts"
            ],
            "status": "covered"
          },
          {
            "stage": "unauthorized-remote-bridge",
            "steps": [
              "suspicious-remote-logins"
            ],
            "status": "covered"
          },
          {
            "stage": "internal-asset-discovery",
            "steps": [
              "internal-discovery-scans"
            ],
            "status": "covered"
          },
          {
            "stage": "segmentation-boundary-violation",
            "steps": [
              "segmentation-violation"
            ],
            "status": "covered"
          }
        ],
        "rationale": "An adversary is exploiting unpatchable public-facing services or unauthorized VPN bridges to discover and laterally move toward isolated legacy OT assets.",
        "blind_spots": [
          {
            "id": "limited-segmentation-telemetry",
            "risk": "If an adversary pivots through a host without an agent or into a segment without flow logging, the segmentation violation is invisible.",
            "stage": "segmentation-boundary-violation",
            "question": "Does the hunt see all traffic across VLANs?",
            "requires": "hb_network_connection from both VPC flow logs and endpoint agents"
          },
          {
            "id": "packet-payload-visibility",
            "risk": "hb_http_activity shows the request but not whether an upstream IPS killed the session, leading to false positives.",
            "stage": "exploit-public-facing-application",
            "question": "Was the exploit payload successfully blocked by virtual patching?",
            "requires": "NGFW/IPS logs with deep packet inspection results"
          }
        ],
        "scoping_notes": "Focus on subnets containing OT/ICS or legacy infrastructure. The authorized_admin_ips list should be populated with known management workstation or Bastion IP addresses.",
        "beyond_detection": "A simple detection rule might alert on a single failed login or a known web exploit; this hunt correlates the perimeter noise with internal network discovery and unauthorized cross-segment connections to find the full intrusion path."
      }
    },
    {
      "id": "identify-at-risk-assets",
      "type": "query",
      "label": "Identify unpatchable or EOL assets",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT d.hostname AS device_hostname, v.device_uid, v.affected_package_name, v.affected_package_version, v.severity, v.title FROM hb_vulnerability_finding v JOIN hb_devices d ON v.device_uid = d.device_uid WHERE (v.severity_id >= 4 OR LOWER(v.title) LIKE '%unsupported%' OR LOWER(v.title) LIKE '%end of life%') AND v.status != 'suppressed'",
        "surface": "hb_vulnerability_finding",
        "description": "Define the scope of the hunt by identifying hosts with high-severity vulnerabilities or software versions known to be end-of-life, joining with device inventory to obtain hostnames.",
        "expected_signal": "A list of hostnames and IDs that are vulnerable. Silence means no known-vulnerable assets are indexed, which narrows the scope of this hunt."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify unpatchable or EOL assets",
        "reads": [
          "device_uid",
          "affected_package_name",
          "affected_package_version",
          "severity",
          "title",
          "hostname",
          "severity_id",
          "status"
        ],
        "source": "hb_vulnerability_finding",
        "target": "endpoint",
        "content": "SELECT d.hostname AS device_hostname, v.device_uid, v.affected_package_name, v.affected_package_version, v.severity, v.title FROM hb_vulnerability_finding v JOIN hb_devices d ON v.device_uid = d.device_uid WHERE (v.severity_id >= 4 OR LOWER(v.title) LIKE '%unsupported%' OR LOWER(v.title) LIKE '%end of life%') AND v.status != 'suppressed'",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hostnames and IDs that are vulnerable. Silence means no known-vulnerable assets are indexed, which narrows the scope of this hunt.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "perimeter-exploit-attempts",
      "type": "query",
      "label": "Public-facing exploit attempts",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "web",
        "content": "SELECT device_hostname, src_endpoint_ip, url_path, url_query, user_agent, time FROM hb_http_activity WHERE (LOWER(url_path) LIKE '%../%' OR LOWER(url_path) LIKE '%/etc/%' OR LOWER(url_path) LIKE '%cmd.exe%' OR LOWER(url_path) LIKE '%/bin/sh%') AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)",
        "surface": "hb_http_activity",
        "description": "Identify web requests containing common exploit patterns targeted at potential legacy interfaces, using lowercase literals for broader coverage.",
        "expected_signal": "HTTP requests with directory traversal or shell commands in the path. Silence suggests no common web exploits were observed during the window."
      },
      "parents": [
        {
          "id": "identify-at-risk-assets"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Public-facing exploit attempts",
        "reads": [
          "device_hostname",
          "src_endpoint_ip",
          "url_path",
          "url_query",
          "user_agent",
          "time"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT device_hostname, src_endpoint_ip, url_path, url_query, user_agent, time FROM hb_http_activity WHERE (LOWER(url_path) LIKE '%../%' OR LOWER(url_path) LIKE '%/etc/%' OR LOWER(url_path) LIKE '%cmd.exe%' OR LOWER(url_path) LIKE '%/bin/sh%') AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)",
        "silence": "not_evidence_of_absence",
        "expected": "HTTP requests with directory traversal or shell commands in the path. Silence suggests no common web exploits were observed during the window.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "suspicious-remote-logins",
      "type": "query",
      "label": "Suspicious VPN or remote logins",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "identity",
        "content": "SELECT actor_user_name, src_endpoint_ip, src_location_country, auth_protocol, event_type, time FROM hb_auth_signin WHERE (LOWER(auth_protocol) LIKE '%vpn%' OR LOWER(event_type) LIKE '%vpn%') AND status_id = 1 AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_auth_signin",
        "description": "Find VPN authentications that may represent unauthorized bridges by examining protocol and event types rather than provider metadata.",
        "expected_signal": "Successful VPN logins. The analyst should look for unusual source locations or accounts that do not typically use VPN access."
      },
      "parents": [
        {
          "id": "identify-at-risk-assets"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Suspicious VPN or remote logins",
        "reads": [
          "actor_user_name",
          "src_endpoint_ip",
          "src_location_country",
          "auth_protocol",
          "event_type",
          "time",
          "status_id"
        ],
        "source": "hb_auth_signin",
        "target": "identity",
        "content": "SELECT actor_user_name, src_endpoint_ip, src_location_country, auth_protocol, event_type, time FROM hb_auth_signin WHERE (LOWER(auth_protocol) LIKE '%vpn%' OR LOWER(event_type) LIKE '%vpn%') AND status_id = 1 AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Successful VPN logins. The analyst should look for unusual source locations or accounts that do not typically use VPN access.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "triage-early-access",
      "type": "analytic",
      "label": "Triage early access evidence",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity",
          "network",
          "web"
        ],
        "context": [
          "identify-at-risk-assets",
          "perimeter-exploit-attempts",
          "suspicious-remote-logins"
        ],
        "objective": "Identify potential beachhead hosts based on exploit attempts or suspicious remote access.",
        "description": "Determine if any host identified in the scoping step or via VPN logs shows signs of initial compromise.",
        "max_iterations": 3,
        "expected_signal": "A per-host verdict on whether a beachhead has likely been established.",
        "success_criteria": "A list of hosts and IPs that are candidates for further lateral movement hunting."
      },
      "parents": [
        {
          "id": "perimeter-exploit-attempts",
          "kind": "merge"
        },
        {
          "id": "suspicious-remote-logins",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "internal-discovery-scans",
      "type": "query",
      "label": "Internal discovery and fingerprinting",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "network",
        "content": "SELECT src_endpoint_ip, COUNT(DISTINCT dst_endpoint_port) AS unique_ports, COUNT(DISTINCT dst_endpoint_ip) AS target_ips, MIN(time) AS first_seen FROM hb_network_connection WHERE direction = 'outbound' AND NOT (instr(',' || '{{authorized_admin_ips}}' || ',', ',' || src_endpoint_ip || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY src_endpoint_ip HAVING unique_ports > 10 OR target_ips > 5 ORDER BY unique_ports DESC",
        "surface": "hb_network_connection",
        "description": "Detect hosts performing internal scanning against multiple ports, excluding authorized administrative traffic to reduce false positives.",
        "expected_signal": "A single internal IP connecting to many ports or many different internal targets. Rare behavior stands out from standard client-server traffic."
      },
      "parents": [
        {
          "id": "triage-early-access"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Internal discovery and fingerprinting",
        "reads": [
          "src_endpoint_ip",
          "dst_endpoint_port",
          "dst_endpoint_ip",
          "direction",
          "time"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT src_endpoint_ip, COUNT(DISTINCT dst_endpoint_port) AS unique_ports, COUNT(DISTINCT dst_endpoint_ip) AS target_ips, MIN(time) AS first_seen FROM hb_network_connection WHERE direction = 'outbound' AND NOT (instr(',' || '{{authorized_admin_ips}}' || ',', ',' || src_endpoint_ip || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY src_endpoint_ip HAVING unique_ports > 10 OR target_ips > 5 ORDER BY unique_ports DESC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A single internal IP connecting to many ports or many different internal targets. Rare behavior stands out from standard client-server traffic.",
        "verified": "dry-run",
        "prevalence": {
          "by": "dst_endpoint_port",
          "key": [
            "src_endpoint_ip"
          ],
          "rare_below": 10
        },
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "segmentation-violation",
      "type": "query",
      "label": "Segmentation boundary violations",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "network",
        "content": "SELECT src_endpoint_ip, dst_endpoint_ip, dst_endpoint_port, device_hostname, time FROM hb_network_connection WHERE direction = 'inbound' AND NOT (instr(',' || '{{authorized_admin_ips}}' || ',', ',' || src_endpoint_ip || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_network_connection",
        "description": "Identify traffic to legacy assets from unauthorized source IPs, indicating a bypass of micro-segmentation controls.",
        "expected_signal": "Traffic destined for unpatchable hosts from IPs not in the authorized list. This indicates the micro-segmentation is either failing or being circumvented."
      },
      "parents": [
        {
          "id": "triage-early-access"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Segmentation boundary violations",
        "reads": [
          "src_endpoint_ip",
          "dst_endpoint_ip",
          "dst_endpoint_port",
          "device_hostname",
          "time",
          "direction"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT src_endpoint_ip, dst_endpoint_ip, dst_endpoint_port, device_hostname, time FROM hb_network_connection WHERE direction = 'inbound' AND NOT (instr(',' || '{{authorized_admin_ips}}' || ',', ',' || src_endpoint_ip || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Traffic destined for unpatchable hosts from IPs not in the authorized list. This indicates the micro-segmentation is either failing or being circumvented.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "triage-intrusion-chain",
      "type": "analytic",
      "label": "Triage the full intrusion chain",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity",
          "network",
          "web"
        ],
        "context": [
          "triage-early-access",
          "internal-discovery-scans",
          "segmentation-violation"
        ],
        "objective": "Determine if a correlated intrusion chain exists from initial access to segmentation violation.",
        "description": "Synthesize the early-stage beachhead evidence with the follow-on movement to confirm a breach of isolated segments.",
        "max_iterations": 6,
        "expected_signal": "A confirmed path from perimeter exploit or VPN shortcut to internal OT discovery.",
        "success_criteria": "A final verdict of malicious if a host identified as a beachhead is seen attempting segmentation bypass."
      },
      "parents": [
        {
          "id": "internal-discovery-scans",
          "kind": "merge"
        },
        {
          "id": "segmentation-violation",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage-intrusion-chain verdict is malicious for a specific beachhead host",
        "condition": "the triage-intrusion-chain verdict is malicious for a specific beachhead host",
        "blind_spot": "limited-segmentation-telemetry",
        "confidence": "high",
        "description": "Route to containment if an intrusion chain is confirmed.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-intrusion-chain"
        }
      ]
    },
    {
      "id": "isolate-beachhead",
      "type": "action",
      "label": "Isolate beachhead host",
      "config": {
        "target": "endpoint",
        "description": "Contain the adversary by isolating the compromised workstation or server used to pivot.",
        "instructions": "Isolate the host identified in triage-intrusion-chain and revoke any active VPN sessions for associated users.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "manual-analyst-review",
      "type": "task",
      "label": "Manual analyst review",
      "config": {
        "assignee": "analyst",
        "description": "Investigate the nature of the segmentation violation and the source of the exploit attempts.",
        "instructions": "Verify the vulnerability status of the destination hosts and cross-reference with NGFW/IPS logs to see if packet-level virtual patching is firing."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-beachhead"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out and document",
      "config": {
        "assignee": "analyst",
        "description": "Record findings and update authorized IP lists or segmentation policies.",
        "instructions": "If no malicious activity was found, document the verified authorized management patterns to tune future runs."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        }
      ]
    }
  ]
}