{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "M365 session hijacking via phishing platforms like NovaCookies bypasses traditional MFA. Detecting the subsequent malware execution and ransomware impact on the same user context provides a high-confidence signal for containing intrusions."
      },
      "name": "M365 Session Hijacking and Malware Execution",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1566.002",
        "attack.t1539",
        "attack.t1204.002",
        "attack.t1486"
      ],
      "related": [
        {
          "hunt": "m365-token-theft-browser-forensics",
          "reason": "This hunt focuses on network and authentication anomalies; browser-specific cookie artifacts require a separate forensic hunt.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        },
        "identity": {
          "name": "Identity / sign-in telemetry",
          "category": "identity",
          "telemetry": [
            "identity"
          ]
        }
      },
      "analysis": "A single detection rule on malware hashes is easily bypassed by binary rotation. This hunt correlates cloud identity anomalies with host behavior and file impact, providing context that a single-surface rule cannot achieve.",
      "coverage": [
        {
          "stage": "initial-access-docusign-phishing",
          "steps": [
            "dns-phishing-lures"
          ],
          "status": "covered"
        },
        {
          "stage": "credential-access-session-theft",
          "steps": [
            "m365-auth-anomaly",
            "agent-identity-triage"
          ],
          "status": "covered"
        },
        {
          "stage": "execution-malware-droppers",
          "steps": [
            "malware-execution"
          ],
          "status": "covered"
        },
        {
          "stage": "impact-data-encryption",
          "steps": [
            "ransomware-impact"
          ],
          "status": "covered"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "DocuSign Phishing Lure",
            "slug": "initial-access-docusign-phishing",
            "tactic": "initial-access",
            "techniques": [
              "T1566.002"
            ],
            "observables": [
              "genuine docusign notifications",
              "docusign.net",
              "NovaCookies phishing platform"
            ]
          },
          {
            "name": "M365 Session Hijacking",
            "slug": "credential-access-session-theft",
            "tactic": "credential-access",
            "techniques": [
              "T1539"
            ],
            "observables": [
              "M365 session theft",
              "real-time session hijacking",
              "$320/month phishing kit"
            ]
          },
          {
            "name": "Malware Dropper Execution",
            "slug": "execution-malware-droppers",
            "tactic": "execution",
            "techniques": [
              "T1204.002"
            ],
            "observables": [
              "VID001.exe",
              "client32.exe",
              "WCInstaller_NonAdmin.exe",
              "content.js",
              "SECOH-QAD.exe",
              "d4aa3e7010220ad1b458fac17039c274_62_Exe.exe",
              "ToxicPanda banking trojan"
            ]
          },
          {
            "name": "Data Encryption for Impact",
            "slug": "impact-data-encryption",
            "tactic": "impact",
            "techniques": [
              "T1486"
            ],
            "observables": [
              "ransomware encryption",
              "file renaming",
              "inaccessible user files"
            ]
          }
        ],
        "summary": "The NovaCookies campaign uses genuine DocuSign notifications to lure users into Microsoft 365 session theft via a subscription-based phishing kit. Stolen sessions enable unauthorized access to corporate environments, leading to the deployment of various banking trojans and droppers like ToxicPanda or VID001.exe, and eventually culminating in data encryption for impact."
      },
      "severity": "high",
      "rationale": "Prioritize users with access to sensitive document shares and workstations in departments commonly receiving DocuSign notifications. Start with a 14-day lookback to catch the session theft beachhead.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary has bypassed MFA by stealing M365 session tokens via DocuSign-themed phishing, enabling them to execute malicious droppers and deploy ransomware across the fleet.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Optional list of hostnames to focus the hunt."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "malware_hashes": {
          "from": {
            "ref": "https://blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/",
            "kind": "article",
            "observed": "2026-08-27"
          },
          "type": "list[hash]",
          "default": [
            "9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507",
            "e7e784cae8d37f12a5af0bc9b3975c8d3e668142e9c6b0b365ed4f4e80933c47",
            "c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2",
            "38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55",
            "9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f",
            "a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91"
          ],
          "description": "SHA256 hashes of malware droppers and tools identified by Talos."
        },
        "phishing_domains": {
          "from": {
            "ref": "https://blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/",
            "kind": "article",
            "observed": "2026-08-27"
          },
          "type": "list[domain]",
          "default": [
            "95.sbx.tg",
            "38d053135d-95.sbx.tg",
            "c4dd71e347-95.sbx.tg",
            "9f1f11a708-100.sbx.tg"
          ],
          "description": "DocuSign phishing and sandbox domains observed in the campaign; docusign.net removed to reduce noise."
        },
        "malware_filenames": {
          "from": {
            "ref": "https://blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/",
            "kind": "article",
            "observed": "2026-08-27"
          },
          "type": "list[string]",
          "default": [
            "VID001.exe",
            "client32.exe",
            "WCInstaller_NonAdmin.exe",
            "content.js",
            "SECOH-QAD.exe"
          ],
          "description": "Known filenames of malicious droppers observed in recent telemetry."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/",
          "name": "\u201cSorry, I can\u2019t help with that\u201d: How your guardrails might become the attacker\u2019s best friend"
        },
        {
          "url": "https://blog.blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/",
          "name": "Talos \u2014 Sorry, I can\u2019t help with that: How your guardrails might become the attacker\u2019s best friend"
        }
      ],
      "blind_spots": [
        {
          "id": "missing-endpoint-visibility",
          "risk": "A host without an agent could be executing malware undetected even if identity logs show session hijacking.",
          "stage": "execution-malware-droppers",
          "question": "Are there infected hosts that are not reporting process or file activity?",
          "requires": "endpoint agent coverage"
        },
        {
          "id": "browser-forensic-gap",
          "risk": "This hunt relies on identifying the aftermath (anomalous sign-ins) rather than the direct theft, which may allow stealthy proxy usage to go unnoticed.",
          "stage": "credential-access-session-theft",
          "question": "Can we confirm the browser-level cookie theft event?",
          "requires": "local browser history and cookie artifacts"
        }
      ]
    },
    "name": "M365 Session Hijacking and Malware Execution",
    "description": "This hunt follows an attack lifecycle from initial cloud identity theft to endpoint ransomware impact. It begins by identifying suspicious DocuSign-related phishing activity and anomalous M365 sign-ins that suggest session hijacking using the NovaCookies platform. The hunt then pivots to the endpoint to detect the execution of specific malware droppers identified by Talos telemetry and monitors for high-frequency file operations characteristic of data encryption. By correlating cloud authentication anomalies with host-side process and file artifacts, the hunt identifies compromised users and the specific hosts where malicious code established a beachhead."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "coverage": [
          {
            "stage": "initial-access-docusign-phishing",
            "steps": [
              "dns-phishing-lures"
            ],
            "status": "covered"
          },
          {
            "stage": "credential-access-session-theft",
            "steps": [
              "m365-auth-anomaly",
              "agent-identity-triage"
            ],
            "status": "covered"
          },
          {
            "stage": "execution-malware-droppers",
            "steps": [
              "malware-execution"
            ],
            "status": "covered"
          },
          {
            "stage": "impact-data-encryption",
            "steps": [
              "ransomware-impact"
            ],
            "status": "covered"
          }
        ],
        "rationale": "An adversary has bypassed MFA by stealing M365 session tokens via DocuSign-themed phishing, enabling them to execute malicious droppers and deploy ransomware across the fleet.",
        "blind_spots": [
          {
            "id": "missing-endpoint-visibility",
            "risk": "A host without an agent could be executing malware undetected even if identity logs show session hijacking.",
            "stage": "execution-malware-droppers",
            "question": "Are there infected hosts that are not reporting process or file activity?",
            "requires": "endpoint agent coverage"
          },
          {
            "id": "browser-forensic-gap",
            "risk": "This hunt relies on identifying the aftermath (anomalous sign-ins) rather than the direct theft, which may allow stealthy proxy usage to go unnoticed.",
            "stage": "credential-access-session-theft",
            "question": "Can we confirm the browser-level cookie theft event?",
            "requires": "local browser history and cookie artifacts"
          }
        ],
        "scoping_notes": "Prioritize users with access to sensitive document shares and workstations in departments commonly receiving DocuSign notifications. Start with a 14-day lookback to catch the session theft beachhead.",
        "beyond_detection": "A single detection rule on malware hashes is easily bypassed by binary rotation. This hunt correlates cloud identity anomalies with host behavior and file impact, providing context that a single-surface rule cannot achieve."
      }
    },
    {
      "id": "scope-windows-workstations",
      "type": "query",
      "label": "Scope Windows Workstations",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT hostname, os_name, os_version, last_seen FROM hb_devices WHERE platform = 'windows' AND lifecycle_state = 'active' AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_devices",
        "description": "Identify active Windows hosts that are the primary targets for phishing and subsequent ransomware execution.",
        "expected_signal": "A list of targetable Windows hosts. None means no Windows systems were enrolled or active during the window."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Scope Windows Workstations",
        "reads": [
          "hostname",
          "os_name",
          "os_version",
          "last_seen",
          "time"
        ],
        "source": "hb_devices",
        "target": "endpoint",
        "content": "SELECT hostname, os_name, os_version, last_seen FROM hb_devices WHERE platform = 'windows' AND lifecycle_state = 'active' AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "A list of targetable Windows hosts. None means no Windows systems were enrolled or active during the window.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "dns-phishing-lures",
      "type": "query",
      "label": "DNS Phishing Lures",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, query_hostname, COUNT(*) AS total_lookups, MIN(time) AS first_seen FROM hb_dns_activity WHERE instr(',' || '{{phishing_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY device_hostname, query_hostname",
        "surface": "hb_dns_activity",
        "description": "Detect resolution of DocuSign-themed phishing sites or sandbox domains named in the report.",
        "expected_signal": "Hosts resolving malicious domains; silence means no direct connection to the reported lures occurred."
      },
      "parents": [
        {
          "id": "scope-windows-workstations"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "DNS Phishing Lures",
        "reads": [
          "device_hostname",
          "query_hostname",
          "time"
        ],
        "source": "hb_dns_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, query_hostname, COUNT(*) AS total_lookups, MIN(time) AS first_seen FROM hb_dns_activity WHERE instr(',' || '{{phishing_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY device_hostname, query_hostname",
        "silence": "not_evidence_of_absence",
        "expected": "Hosts resolving malicious domains; silence means no direct connection to the reported lures occurred.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "m365-auth-anomaly",
      "type": "query",
      "label": "M365 Sign-in Anomalies",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "identity",
        "content": "SELECT actor_user_name, src_endpoint_ip, COUNT(*) AS logon_count, MIN(time) AS first_logon, MAX(time) AS last_logon FROM hb_auth_signin WHERE provider = 'm365' AND status_id = 1 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, src_endpoint_ip HAVING logon_count < 5 ORDER BY logon_count ASC",
        "surface": "hb_auth_signin",
        "description": "Find successful M365 logons from unusual IP addresses per user, suggesting session hijacking.",
        "expected_signal": "A rare user/IP combination that differs from historical patterns. A single logon from a new IP for a user is a typical hijacking signal."
      },
      "parents": [
        {
          "id": "scope-windows-workstations"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "M365 Sign-in Anomalies",
        "reads": [
          "actor_user_name",
          "src_endpoint_ip",
          "provider",
          "status_id",
          "time"
        ],
        "source": "hb_auth_signin",
        "target": "identity",
        "content": "SELECT actor_user_name, src_endpoint_ip, COUNT(*) AS logon_count, MIN(time) AS first_logon, MAX(time) AS last_logon FROM hb_auth_signin WHERE provider = 'm365' AND status_id = 1 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, src_endpoint_ip HAVING logon_count < 5 ORDER BY logon_count ASC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A rare user/IP combination that differs from historical patterns. A single logon from a new IP for a user is a typical hijacking signal.",
        "verified": "dry-run",
        "prevalence": {
          "by": "actor_user_name",
          "key": [
            "src_endpoint_ip"
          ],
          "rare_below": 2
        },
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "agent-identity-triage",
      "type": "analytic",
      "label": "Triage Identity Hijack",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity"
        ],
        "context": [
          "dns-phishing-lures",
          "m365-auth-anomaly"
        ],
        "objective": "Identify users who likely fell for a DocuSign phishing lure and subsequently had their M365 session hijacked. Cite the resolved domain and the anomalous logon IP.",
        "description": "Evaluate whether the DNS and Auth leads suggest a high-confidence session theft event.",
        "max_iterations": 4,
        "expected_signal": "A list of suspected compromised users and IPs.",
        "success_criteria": "A list of users with corresponding suspicious IP and DNS evidence."
      },
      "parents": [
        {
          "id": "dns-phishing-lures",
          "kind": "merge"
        },
        {
          "id": "m365-auth-anomaly",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "malware-execution",
      "type": "query",
      "label": "Malware Execution",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_hash_sha256, process_cmd_line, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{malware_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 OR instr(',' || '{{malware_filenames}}' || ',', ',' || LOWER(process_name) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)",
        "surface": "hb_process_activity",
        "description": "Detect the execution of the specific droppers and tools identified by Talos.",
        "expected_signal": "Process executions matching the reported malware. Any match is high confidence."
      },
      "parents": [
        {
          "id": "agent-identity-triage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Malware Execution",
        "reads": [
          "device_hostname",
          "process_name",
          "process_hash_sha256",
          "process_cmd_line",
          "user_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_hash_sha256, process_cmd_line, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{malware_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 OR instr(',' || '{{malware_filenames}}' || ',', ',' || LOWER(process_name) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)",
        "silence": "not_evidence_of_absence",
        "expected": "Process executions matching the reported malware. Any match is high confidence.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "ransomware-impact",
      "type": "query",
      "label": "Ransomware Impact",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "endpoint",
        "content": "SELECT device_hostname, actor_user_name, COUNT(*) AS op_count, MIN(time) AS first_op, MAX(time) AS last_op FROM hb_file_activity WHERE activity_id IN (1, 4, 5) AND (LOWER(file_path) LIKE '%.docx' OR LOWER(file_path) LIKE '%.xlsx' OR LOWER(file_path) LIKE '%.pdf') AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY device_hostname, actor_user_name HAVING op_count > 20",
        "surface": "hb_file_activity",
        "description": "Detect high-frequency file operations on user document types, characteristic of encryption.",
        "expected_signal": "A burst of file creations, deletions, or renames on document files. Silence means no mass encryption events were detected on the targeted surfaces."
      },
      "parents": [
        {
          "id": "agent-identity-triage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Ransomware Impact",
        "reads": [
          "device_hostname",
          "actor_user_name",
          "activity_id",
          "file_path",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, actor_user_name, COUNT(*) AS op_count, MIN(time) AS first_op, MAX(time) AS last_op FROM hb_file_activity WHERE activity_id IN (1, 4, 5) AND (LOWER(file_path) LIKE '%.docx' OR LOWER(file_path) LIKE '%.xlsx' OR LOWER(file_path) LIKE '%.pdf') AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY device_hostname, actor_user_name HAVING op_count > 20",
        "silence": "not_evidence_of_absence",
        "expected": "A burst of file creations, deletions, or renames on document files. Silence means no mass encryption events were detected on the targeted surfaces.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "follow-on-agent",
      "type": "analytic",
      "label": "Final Correlation Agent",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity"
        ],
        "context": [
          "agent-identity-triage",
          "malware-execution",
          "ransomware-impact"
        ],
        "objective": "Determine if compromised identities from the early stage match users or hosts where malware and ransomware impact occurred. Issue a malicious verdict if the killchain is confirmed.",
        "description": "Synthesize early identity evidence with endpoint malware and impact findings.",
        "max_iterations": 6,
        "expected_signal": "A unified timeline of the intrusion.",
        "success_criteria": "A final verdict per host citing the correlation between identity theft and malicious endpoint activity."
      },
      "parents": [
        {
          "id": "malware-execution",
          "kind": "merge"
        },
        {
          "id": "ransomware-impact",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-decision",
      "type": "checkpoint",
      "label": "Route on Final Verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the follow-on-agent verdict is malicious for at least one host",
        "condition": "the follow-on-agent verdict is malicious for at least one host",
        "blind_spot": "missing-endpoint-visibility",
        "confidence": "high",
        "description": "Trigger containment for confirmed intrusions.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "follow-on-agent"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate Host",
      "config": {
        "target": "endpoint",
        "description": "Halt the ransomware execution and session abuse.",
        "instructions": "Isolate the infected host from the network and revoke all M365 session tokens for the affected user account.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-decision",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Analyst Review",
      "config": {
        "assignee": "analyst",
        "description": "Verify the agent's findings and document the incident lifecycle.",
        "instructions": "Review the correlated evidence: DNS lure resolution, anomalous IP sign-in, and endpoint malware execution. Confirm if the file operations align with a ransomware attack."
      },
      "parents": [
        {
          "id": "route-decision",
          "branch": "default"
        },
        {
          "id": "route-decision",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close-out",
      "config": {
        "assignee": "analyst",
        "description": "Finalize documentation and archive the hunt results.",
        "instructions": "Record the hosts and users examined. Note any new phishing domains discovered to update future hunt iterations."
      },
      "parents": [
        {
          "id": "route-decision",
          "branch": "on_refutes"
        },
        {
          "id": "analyst-review"
        }
      ]
    }
  ]
}