{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Adversaries are bypassing modern MFA through passkey-themed lures; a negative result confirms that these lures did not lead to data theft within the lookback window."
      },
      "name": "Microsoft Graph and Cloud Application Exfiltration",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1041",
        "attack.t1078"
      ],
      "series": {
        "slug": "passkey-themed-social-engineering-leads-to-identity-and-cloud-compromise",
        "index": 2,
        "title": "Passkey-themed social engineering leads to identity and cloud compromise",
        "total": 2
      },
      "related": [
        {
          "hunt": "mfa-persistence-registration-hunt",
          "reason": "Detection of unauthorized MFA factor addition is a persistent persistence mechanism handled in a sibling hunt.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        },
        "identity": {
          "name": "Identity / sign-in telemetry",
          "category": "identity",
          "telemetry": [
            "identity"
          ]
        }
      },
      "analysis": "A single rule might alert on a login to 'My Apps', but this hunt connects that signal to automated Graph API variety and high-volume file counts that exceed a user's unique daily baseline.",
      "coverage": [
        {
          "stage": "cloud-application-reconnaissance",
          "steps": [
            "portal-recon-lead",
            "graph-api-recon"
          ],
          "status": "covered"
        },
        {
          "stage": "data-enumeration-exfiltration",
          "steps": [
            "high-volume-file-exfil"
          ],
          "status": "covered"
        },
        {
          "stage": "passkey-themed-phishing",
          "reason": "Belongs to another part of the 'Passkey-themed social engineering leads to identity and cloud compromise' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "identity-compromise-aitm",
          "reason": "Belongs to another part of the 'Passkey-themed social engineering leads to identity and cloud compromise' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "mfa-persistence-registration",
          "reason": "Belongs to another part of the 'Passkey-themed social engineering leads to identity and cloud compromise' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Passkey-themed phishing domains",
            "slug": "passkey-themed-phishing",
            "tactic": "initial-access",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "company-name.integratedsso.com",
              "company-name.secure-passkey.com",
              "companyname.maliciousdomain.com",
              "contoso.add-passkey.com",
              "passkeyhelpdesk.com",
              "secure-passkey.com",
              "setupmypasskey.com",
              "add-passkey.com",
              "integratedsso.com",
              "oktasession.com",
              "keysyncos.com",
              "oskeysync.com",
              "oskeysetup.com",
              "oskeyregister.com",
              "syncmykey.com",
              "myconnectkey.com",
              "oskeyconnect.com",
              "validationsetupac.com",
              "portalsetuphub.com"
            ]
          },
          {
            "name": "Identity compromise via AiTM or Device Code",
            "slug": "identity-compromise-aitm",
            "tactic": "initial-access",
            "techniques": [
              "T1078",
              "T1090.003"
            ],
            "observables": [
              "Anomalous sign-in to OfficeHome from unmanaged context",
              "Sign-in error 50074 (MFA required)",
              "Sign-in error 50140 (Keep-me-signed-in interruption)",
              "Device code flow authentication",
              "Chrome user agent in anomalous session"
            ]
          },
          {
            "name": "MFA method registration for persistence",
            "slug": "mfa-persistence-registration",
            "tactic": "persistence",
            "techniques": [
              "T1078"
            ],
            "observables": [
              "New phone number registration",
              "New authenticator application registration",
              "Registration of software-based OTP token",
              "Update user events with StrongAuthenticationPhoneAppOTP"
            ]
          },
          {
            "name": "Cloud application and identity reconnaissance",
            "slug": "cloud-application-reconnaissance",
            "tactic": "discovery",
            "techniques": [
              "T1078"
            ],
            "observables": [
              "Access to My Apps application store",
              "Access to My Profile organizational info",
              "Access to Microsoft Approval Management",
              "Access to Microsoft Account Controls V2",
              "Access to My SignIns security information",
              "Access to OCaaS application catalogue"
            ]
          },
          {
            "name": "Data enumeration and exfiltration",
            "slug": "data-enumeration-exfiltration",
            "tactic": "exfiltration",
            "techniques": [
              "T1041",
              "T1078"
            ],
            "observables": [
              "SharePoint Online site and document requests",
              "OneDrive file enumeration via Graph API",
              "Outlook Web mailbox services access",
              "OwaDownloadAttachments requests",
              "M365ChatClient access",
              "High-volume Microsoft Graph activity"
            ]
          }
        ],
        "summary": "Threat actors use passkey-themed social engineering via vishing and SMS to lure users to AiTM phishing sites or device-code authentication flows. Following compromise, the actors establish MFA persistence by registering new authentication factors and conduct extensive cloud reconnaissance and data exfiltration from SharePoint, OneDrive, and Exchange using the Microsoft Graph API."
      },
      "severity": "high",
      "rationale": "Target hosts running Microsoft 365 or Office suites as they are the primary targets for this campaign's exfiltration phase. Prioritize any users who have reported suspicious IT helpdesk calls or SMS lures.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary is using automated Graph API tools to enumerate organizational resources and exfiltrate SharePoint/OneDrive data after obtaining a cloud session via passkey-themed social engineering.",
      "parameters": {
        "scope_hosts": {
          "from": {
            "ref": "default",
            "kind": "manual",
            "observed": "2026-09-09"
          },
          "type": "list[host]",
          "default": [],
          "description": "Optional: Limit the hunt to these hostnames; leave empty to hunt across the estate."
        },
        "lookback_days": {
          "from": {
            "ref": "default",
            "kind": "manual",
            "observed": "2026-09-09"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "targeted_apps": {
          "from": {
            "ref": "msrc-blog-2026-09-09",
            "kind": "article",
            "observed": "2026-09-09"
          },
          "type": "list[string]",
          "default": [
            "OfficeHome",
            "My Apps",
            "My Profile",
            "My SignIns",
            "Microsoft Account Controls V2",
            "Microsoft Approval Management",
            "OCaaS",
            "M365ChatClient",
            "OwaDownloadAttachments"
          ],
          "description": "Identity and management portals targeted during reconnaissance."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/",
          "name": "MSRC \u2014 Passkey-themed social engineering leads to identity and cloud compromise"
        }
      ],
      "blind_spots": [
        {
          "id": "m365-audit-latency",
          "risk": "M365 audit logs often have a delay of several hours, meaning the exfiltration may be complete before the hunt observes the activity.",
          "stage": "data-enumeration-exfiltration",
          "question": "whether exfiltration is currently occurring",
          "requires": "Real-time M365 audit streaming"
        },
        {
          "id": "personal-mobile-visibility",
          "risk": "The initial social engineering phase targets personal mobile devices that are not enrolled, making the early attack markers invisible.",
          "stage": "cloud-application-reconnaissance",
          "question": "whether the phishing link was accessed on a mobile phone",
          "requires": "Endpoint telemetry on non-managed mobile devices"
        }
      ]
    },
    "name": "Microsoft Graph and Cloud Application Exfiltration",
    "description": "This hunt identifies post-compromise activity following passkey-themed social engineering. It focuses on the specific sequence of discovery where an actor accesses identity portals (My Apps, My SignIns) and then uses automated systems (Node.js/Microsoft Graph) to enumerate document libraries and download content. By correlating portal sign-ins with high-volume Graph API traffic and file access counts that deviate from a user's normal baseline, the hunt distinguishes targeted exfiltration from legitimate cloud usage."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "passkey-themed-social-engineering-leads-to-identity-and-cloud-compromise",
          "index": 2,
          "title": "Passkey-themed social engineering leads to identity and cloud compromise",
          "total": 2
        },
        "coverage": [
          {
            "stage": "cloud-application-reconnaissance",
            "steps": [
              "portal-recon-lead",
              "graph-api-recon"
            ],
            "status": "covered"
          },
          {
            "stage": "data-enumeration-exfiltration",
            "steps": [
              "high-volume-file-exfil"
            ],
            "status": "covered"
          },
          {
            "stage": "passkey-themed-phishing",
            "reason": "Belongs to another part of the 'Passkey-themed social engineering leads to identity and cloud compromise' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "identity-compromise-aitm",
            "reason": "Belongs to another part of the 'Passkey-themed social engineering leads to identity and cloud compromise' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "mfa-persistence-registration",
            "reason": "Belongs to another part of the 'Passkey-themed social engineering leads to identity and cloud compromise' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary is using automated Graph API tools to enumerate organizational resources and exfiltrate SharePoint/OneDrive data after obtaining a cloud session via passkey-themed social engineering.",
        "blind_spots": [
          {
            "id": "m365-audit-latency",
            "risk": "M365 audit logs often have a delay of several hours, meaning the exfiltration may be complete before the hunt observes the activity.",
            "stage": "data-enumeration-exfiltration",
            "question": "whether exfiltration is currently occurring",
            "requires": "Real-time M365 audit streaming"
          },
          {
            "id": "personal-mobile-visibility",
            "risk": "The initial social engineering phase targets personal mobile devices that are not enrolled, making the early attack markers invisible.",
            "stage": "cloud-application-reconnaissance",
            "question": "whether the phishing link was accessed on a mobile phone",
            "requires": "Endpoint telemetry on non-managed mobile devices"
          }
        ],
        "scoping_notes": "Target hosts running Microsoft 365 or Office suites as they are the primary targets for this campaign's exfiltration phase. Prioritize any users who have reported suspicious IT helpdesk calls or SMS lures.",
        "beyond_detection": "A single rule might alert on a login to 'My Apps', but this hunt connects that signal to automated Graph API variety and high-volume file counts that exceed a user's unique daily baseline."
      }
    },
    {
      "id": "identify-vulnerable-scope",
      "type": "query",
      "label": "Scope to Microsoft 365 environments",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT DISTINCT device_hostname FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%microsoft 365%' OR LOWER(package_name) LIKE '%office%' OR LOWER(package_name) LIKE '%outlook%')",
        "surface": "hb_software_inventory",
        "description": "Identify hosts that have Microsoft 365 or Office software installed to narrow the hunt scope.",
        "expected_signal": "A list of hosts with the targeted productivity software. Silence indicates no such software was found in the inventory."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Scope to Microsoft 365 environments",
        "reads": [
          "device_hostname",
          "package_name"
        ],
        "source": "hb_software_inventory",
        "target": "endpoint",
        "content": "SELECT DISTINCT device_hostname FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%microsoft 365%' OR LOWER(package_name) LIKE '%office%' OR LOWER(package_name) LIKE '%outlook%')",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hosts with the targeted productivity software. Silence indicates no such software was found in the inventory.",
        "verified": "dry-run",
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "portal-recon-lead",
      "type": "query",
      "label": "Identity portal reconnaissance",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "identity",
        "content": "SELECT actor_user_name, src_endpoint_ip, dst_endpoint_name, time FROM hb_auth_signin WHERE status_id = 1 AND instr(',' || '{{targeted_apps}}' || ',', ',' || dst_endpoint_name || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days') ORDER BY time ASC",
        "surface": "hb_auth_signin",
        "description": "Identify successful sign-ins to portals used to discover applications and organizational info.",
        "expected_signal": "Signs of a single user account accessing multiple identity and management portals in a tight sequence. Silence indicates no portal access was logged."
      },
      "parents": [
        {
          "id": "identify-vulnerable-scope"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Identity portal reconnaissance",
        "reads": [
          "actor_user_name",
          "src_endpoint_ip",
          "dst_endpoint_name",
          "time",
          "status_id"
        ],
        "source": "hb_auth_signin",
        "target": "identity",
        "content": "SELECT actor_user_name, src_endpoint_ip, dst_endpoint_name, time FROM hb_auth_signin WHERE status_id = 1 AND instr(',' || '{{targeted_apps}}' || ',', ',' || dst_endpoint_name || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days') ORDER BY time ASC",
        "silence": "evidence_of_absence",
        "expected": "Signs of a single user account accessing multiple identity and management portals in a tight sequence. Silence indicates no portal access was logged.",
        "verified": "dry-run",
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "graph-api-recon",
      "type": "query",
      "label": "Automated Graph API reconnaissance",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "web",
        "content": "SELECT actor_user_name, device_hostname, COUNT(DISTINCT url_path) as unique_paths, COUNT(*) as total_requests, MIN(time) as start, MAX(time) as end FROM hb_http_activity WHERE url_hostname = 'graph.microsoft.com' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, device_hostname HAVING unique_paths > 10 ORDER BY unique_paths DESC",
        "surface": "hb_http_activity",
        "description": "Find high-variety calls to the Microsoft Graph API indicating automated discovery tools.",
        "expected_signal": "A single context making many distinct Graph API requests in a short window. Silence proves no automated Graph tools were detected."
      },
      "parents": [
        {
          "id": "identify-vulnerable-scope"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Automated Graph API reconnaissance",
        "reads": [
          "actor_user_name",
          "device_hostname",
          "url_hostname",
          "url_path",
          "time"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT actor_user_name, device_hostname, COUNT(DISTINCT url_path) as unique_paths, COUNT(*) as total_requests, MIN(time) as start, MAX(time) as end FROM hb_http_activity WHERE url_hostname = 'graph.microsoft.com' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, device_hostname HAVING unique_paths > 10 ORDER BY unique_paths DESC",
        "silence": "evidence_of_absence",
        "expected": "A single context making many distinct Graph API requests in a short window. Silence proves no automated Graph tools were detected.",
        "verified": "dry-run",
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "high-volume-file-exfil",
      "type": "query",
      "label": "High-volume M365 exfiltration",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT actor_user_name, device_hostname, strftime('%Y-%m-%d', time) as day, COUNT(DISTINCT file_path) as file_count FROM hb_file_activity WHERE provider = 'm365' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, device_hostname, day HAVING file_count > 50 ORDER BY file_count DESC",
        "surface": "hb_file_activity",
        "description": "Stack-count file touches to find accounts exceeding typical daily document access volumes.",
        "expected_signal": "An account accessing more than 50 unique SharePoint/OneDrive files in a day. Silence indicates no account reached this baseline threshold."
      },
      "parents": [
        {
          "id": "identify-vulnerable-scope"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "High-volume M365 exfiltration",
        "reads": [
          "actor_user_name",
          "device_hostname",
          "file_path",
          "provider",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT actor_user_name, device_hostname, strftime('%Y-%m-%d', time) as day, COUNT(DISTINCT file_path) as file_count FROM hb_file_activity WHERE provider = 'm365' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, device_hostname, day HAVING file_count > 50 ORDER BY file_count DESC",
        "silence": "evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "new_this_window"
        },
        "expected": "An account accessing more than 50 unique SharePoint/OneDrive files in a day. Silence indicates no account reached this baseline threshold.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "actor_user_name"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "triage-agent",
      "type": "analytic",
      "label": "Triage session activity",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity",
          "web"
        ],
        "context": [
          "portal-recon-lead",
          "graph-api-recon",
          "high-volume-file-exfil"
        ],
        "objective": "Determine if any user account shows a sign-in sequence to identity portals followed by automated Graph discovery and high-volume file exfiltration.",
        "description": "Synthesize sign-ins, Graph API variety, and file volume to confirm a malicious takeover.",
        "max_iterations": 5,
        "expected_signal": "A per-user verdict identifying the transition from reconnaissance to theft.",
        "success_criteria": "A per-user verdict of malicious | suspicious | benign citing specific portal access times and file counts."
      },
      "parents": [
        {
          "id": "portal-recon-lead",
          "kind": "merge"
        },
        {
          "id": "graph-api-recon",
          "kind": "merge"
        },
        {
          "id": "high-volume-file-exfil",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage-agent verdict is malicious for at least one user",
        "condition": "the triage-agent verdict is malicious for at least one user",
        "blind_spot": "m365-audit-latency",
        "confidence": "high",
        "description": "Route the workflow based on the agent's verdict.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-agent"
        }
      ]
    },
    {
      "id": "isolate-and-revoke",
      "type": "action",
      "label": "Revoke sessions and isolate",
      "config": {
        "target": "identity",
        "description": "Stop ongoing exfiltration by terminating the session.",
        "instructions": "Revoke all active sessions and refresh tokens for the identified users; initiate a password reset and review recently added MFA factors.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "manual-incident-review",
      "type": "task",
      "label": "Manual incident review",
      "config": {
        "assignee": "analyst",
        "description": "Verify the impact and assess the data exfiltrated.",
        "instructions": "Examine the specific file paths in hb_file_activity to determine content sensitivity. Check the source IP reputation for proxy or TOR associations. Verify if the Graph API activity indicates enumeration of the entire tenant directory."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-and-revoke"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out",
      "config": {
        "assignee": "analyst",
        "description": "Finalize findings and documentation.",
        "instructions": "Record the total number of accounts reviewed and the volume of baseline activity. Summarize confirmed compromises or negative results for the security leadership report."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "manual-incident-review"
        }
      ]
    }
  ]
}