{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "AI-driven attacks use speed to move from initial access to full compromise in minutes; securing the identity and perimeter ingress plane is a critical business obligation to prevent mass compromise."
      },
      "name": "Machine-Speed Perimeter and Identity Ingress",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1133",
        "attack.t1190",
        "attack.t1566",
        "attack.t1078"
      ],
      "series": {
        "slug": "ai-attacks-move-faster-huntress-agentic-soc-keeps-up",
        "index": 1,
        "title": "AI Attacks Move Faster. Huntress\u2019 Agentic SOC Keeps Up",
        "total": 2
      },
      "related": [
        {
          "hunt": "mfa-bypass-geo-anomalies",
          "reason": "Both hunts examine authentication anomalies, but this hunt specifically correlates them with the external attack surface and critical gateway vulnerabilities.",
          "relation": "alternative"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        },
        "identity": {
          "name": "Identity / sign-in telemetry",
          "category": "identity",
          "telemetry": [
            "identity"
          ]
        }
      },
      "analysis": "A standard detection rule fires on a single impossible travel event; this hunt pivots to the external attack surface and vulnerability findings to prioritize ingress points that are both unpatched and showing anomalous authentication traffic, weighing the correlation across multiple surfaces.",
      "coverage": [
        {
          "stage": "ai-enhanced-phishing",
          "steps": [
            "rare-auth-geolocations",
            "triage-ingress"
          ],
          "status": "covered"
        },
        {
          "stage": "external-service-compromise",
          "steps": [
            "identify-perimeter",
            "gateway-vulnerabilities",
            "triage-ingress"
          ],
          "status": "covered"
        },
        {
          "stage": "automated-internal-discovery",
          "reason": "Belongs to another part of the 'AI Attacks Move Faster. Huntress\u2019 Agentic SOC Keeps Up' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "credential-and-token-theft",
          "reason": "Belongs to another part of the 'AI Attacks Move Faster. Huntress\u2019 Agentic SOC Keeps Up' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "rapid-data-triage-and-encryption",
          "reason": "Belongs to another part of the 'AI Attacks Move Faster. Huntress\u2019 Agentic SOC Keeps Up' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "AI-Enhanced Phishing and Social Engineering",
            "slug": "ai-enhanced-phishing",
            "tactic": "initial-access",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "Phishing emails with AI-refined language",
              "Video calls with AI-altered faces (deepfakes)",
              "Compromised accounts used for high-volume phishing"
            ]
          },
          {
            "name": "Compromise of External Remote Services",
            "slug": "external-service-compromise",
            "tactic": "initial-access",
            "techniques": [
              "T1133",
              "T1190"
            ],
            "observables": [
              "Anomalous VPN authentications without MFA",
              "Connections from unusual geolocations via VPN",
              "Exploitation of vulnerable network appliances or firewalls",
              "Exposed services on ports 443 or 1194"
            ]
          },
          {
            "name": "Automated Internal Reconnaissance",
            "slug": "automated-internal-discovery",
            "tactic": "discovery",
            "techniques": [
              "T1083",
              "T1018"
            ],
            "observables": [
              "High-speed internal network scanning and enumeration",
              "Rapid execution of system discovery commands",
              "Unusual outbound internal traffic patterns from recently accessed hosts"
            ]
          },
          {
            "name": "Credential Dumping and Session Token Theft",
            "slug": "credential-and-token-theft",
            "tactic": "credential-access",
            "techniques": [
              "T1003"
            ],
            "observables": [
              "Theft of API keys and session tokens for AI models (e.g., Anthropic, OpenAI)",
              "Memory dumping of lsass.exe",
              "Loading of dbghelp.dll or dbgcore.dll from non-standard paths",
              "Access to local credential stores or browser profile directories"
            ]
          },
          {
            "name": "Automated Data Triage and Impact",
            "slug": "rapid-data-triage-and-encryption",
            "tactic": "impact",
            "techniques": [
              "T1486"
            ],
            "observables": [
              "AI-assisted scanning of files for PII, PHI, or intellectual property",
              "Rapid traversal of file shares and local directories",
              "Bulk file encryption and renaming (ransomware activity)",
              "Execution of scripts or binaries for automated data classification"
            ]
          }
        ],
        "summary": "Attackers are utilizing AI to accelerate traditional tradecraft, moving from initial access via compromised VPNs or firewalls to rapid internal discovery and automated data triage. While AI enhances the speed of reconnaissance and phishing, the core post-exploitation behaviors such as credential dumping and lateral movement remain observable through endpoint and identity telemetry."
      },
      "severity": "high",
      "rationale": "Focus on the internet-exposed perimeter. The scoping query identifies domains and IPs; analysts should use these values to populate the scope_hosts parameter for identity and vulnerability queries. Ensure VPN and gateway logs are forwarding to the authentication surface.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An automated attacker is exploiting unpatched perimeter services or using AI-refined phishing to compromise identities, resulting in successful sign-ins from rare geolocations that correlate with known gateway vulnerabilities.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "List of hostnames or IPs to narrow the hunt; paste identifiers from the scoping step here."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine for authentication and exposure events."
        },
        "gateway_products": {
          "from": {
            "ref": "huntress-ai-attackers-machine-speed",
            "kind": "article",
            "observed": "2026-09-22"
          },
          "type": "list[string]",
          "default": [
            "vpn",
            "fortinet",
            "cisco",
            "anyconnect",
            "citrix",
            "globalprotect",
            "firewall",
            "gateway"
          ],
          "description": "Keywords identifying remote access products in logs."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.huntress.com/blog/ai-attackers-machine-speed-huntress-athena",
          "gates": [
            "dry-run",
            "lint",
            "critic"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.huntress.com/blog/ai-attackers-machine-speed-huntress-athena",
          "name": "Huntress \u2014 Inside the Agentic Huntress Platform: Beating Adversaries at Machine Speed"
        }
      ],
      "blind_spots": [
        {
          "id": "missing-auth-geolocation",
          "risk": "Without geographic context, automated ingress from distant locations is indistinguishable from standard remote work until after lateral movement occurs.",
          "stage": "ai-enhanced-phishing",
          "question": "Was this login part of an impossible travel sequence or a geo-fenced violation?",
          "requires": "hb_auth_signin with src_location_country and MFA status"
        },
        {
          "id": "unmonitored-gateways",
          "risk": "If gateway logs are not forwarded, the 'front door' remains a black box until an attacker reaches a managed endpoint.",
          "stage": "external-service-compromise",
          "question": "Which users are authenticating specifically through the VPN vs. SaaS directly?",
          "requires": "VPN/Firewall logs integrated into hb_auth_signin"
        }
      ]
    },
    "name": "Machine-Speed Perimeter and Identity Ingress",
    "description": "This hunt targets the initial ingress points where AI-driven automation significantly compresses the time between initial access and lateral movement. It identifies exposed remote access infrastructure, correlates it with known critical vulnerabilities, and examines authentication patterns for signs of identity compromise or MFA bypass. By fanning out to evaluate perimeter risk and authentication anomalies simultaneously, an agent determines if an ingress event is part of a machine-speed automated attack."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "ai-attacks-move-faster-huntress-agentic-soc-keeps-up",
          "index": 1,
          "title": "AI Attacks Move Faster. Huntress\u2019 Agentic SOC Keeps Up",
          "total": 2
        },
        "coverage": [
          {
            "stage": "ai-enhanced-phishing",
            "steps": [
              "rare-auth-geolocations",
              "triage-ingress"
            ],
            "status": "covered"
          },
          {
            "stage": "external-service-compromise",
            "steps": [
              "identify-perimeter",
              "gateway-vulnerabilities",
              "triage-ingress"
            ],
            "status": "covered"
          },
          {
            "stage": "automated-internal-discovery",
            "reason": "Belongs to another part of the 'AI Attacks Move Faster. Huntress\u2019 Agentic SOC Keeps Up' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "credential-and-token-theft",
            "reason": "Belongs to another part of the 'AI Attacks Move Faster. Huntress\u2019 Agentic SOC Keeps Up' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "rapid-data-triage-and-encryption",
            "reason": "Belongs to another part of the 'AI Attacks Move Faster. Huntress\u2019 Agentic SOC Keeps Up' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An automated attacker is exploiting unpatched perimeter services or using AI-refined phishing to compromise identities, resulting in successful sign-ins from rare geolocations that correlate with known gateway vulnerabilities.",
        "blind_spots": [
          {
            "id": "missing-auth-geolocation",
            "risk": "Without geographic context, automated ingress from distant locations is indistinguishable from standard remote work until after lateral movement occurs.",
            "stage": "ai-enhanced-phishing",
            "question": "Was this login part of an impossible travel sequence or a geo-fenced violation?",
            "requires": "hb_auth_signin with src_location_country and MFA status"
          },
          {
            "id": "unmonitored-gateways",
            "risk": "If gateway logs are not forwarded, the 'front door' remains a black box until an attacker reaches a managed endpoint.",
            "stage": "external-service-compromise",
            "question": "Which users are authenticating specifically through the VPN vs. SaaS directly?",
            "requires": "VPN/Firewall logs integrated into hb_auth_signin"
          }
        ],
        "scoping_notes": "Focus on the internet-exposed perimeter. The scoping query identifies domains and IPs; analysts should use these values to populate the scope_hosts parameter for identity and vulnerability queries. Ensure VPN and gateway logs are forwarding to the authentication surface.",
        "beyond_detection": "A standard detection rule fires on a single impossible travel event; this hunt pivots to the external attack surface and vulnerability findings to prioritize ingress points that are both unpatched and showing anomalous authentication traffic, weighing the correlation across multiple surfaces."
      }
    },
    {
      "id": "identify-perimeter",
      "type": "query",
      "label": "Identify exposed perimeter assets",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT domain_or_ip, product, port, discovered_at FROM hb_exposed_assets WHERE (instr(',' || '{{gateway_products}}' || ',', ',' || LOWER(product) || ',') > 0) AND discovered_at >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_exposed_assets",
        "description": "Define the external attack surface by locating every internet-exposed gateway or VPN service.",
        "expected_signal": "A list of IP addresses and domains running remote access software. Absence indicates no such assets were discovered by external scanning."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify exposed perimeter assets",
        "reads": [
          "domain_or_ip",
          "product",
          "port",
          "discovered_at"
        ],
        "source": "hb_exposed_assets",
        "target": "endpoint",
        "content": "SELECT domain_or_ip, product, port, discovered_at FROM hb_exposed_assets WHERE (instr(',' || '{{gateway_products}}' || ',', ',' || LOWER(product) || ',') > 0) AND discovered_at >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "A list of IP addresses and domains running remote access software. Absence indicates no such assets were discovered by external scanning.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "rare-auth-geolocations",
      "type": "query",
      "label": "Identify rare authentication geolocations",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "identity",
        "content": "SELECT actor_user_name, src_location_country, mfa, COUNT(*) AS login_count, MIN(time) AS first_seen FROM hb_auth_signin WHERE status_id = 1 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, src_location_country HAVING login_count <= 2 ORDER BY login_count ASC",
        "surface": "hb_auth_signin",
        "description": "Find successful sign-ins from locations that are rare for a specific user, indicating potential identity compromise.",
        "expected_signal": "Logins from countries that a user does not typically inhabit. Silence suggests authentication patterns follow historical baselines."
      },
      "parents": [
        {
          "id": "identify-perimeter"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Identify rare authentication geolocations",
        "reads": [
          "actor_user_name",
          "src_location_country",
          "mfa",
          "status_id",
          "device_hostname",
          "time"
        ],
        "source": "hb_auth_signin",
        "target": "identity",
        "content": "SELECT actor_user_name, src_location_country, mfa, COUNT(*) AS login_count, MIN(time) AS first_seen FROM hb_auth_signin WHERE status_id = 1 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, src_location_country HAVING login_count <= 2 ORDER BY login_count ASC",
        "silence": "evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Logins from countries that a user does not typically inhabit. Silence suggests authentication patterns follow historical baselines.",
        "verified": "dry-run",
        "prevalence": {
          "by": "actor_user_name",
          "key": [
            "src_location_country"
          ],
          "rare_below": 2
        },
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "gateway-vulnerabilities",
      "type": "query",
      "label": "Check for critical gateway vulnerabilities",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_uid, cve_uid, affected_package_name, severity, collected_at FROM hb_vulnerability_finding WHERE severity_id >= 4 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_uid || ',') > 0) AND (instr(',' || '{{gateway_products}}' || ',', ',' || LOWER(affected_package_name) || ',') > 0) AND collected_at >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_vulnerability_finding",
        "description": "Enrich the hunt with known exploitable vulnerabilities on the remote access assets identified in scoping.",
        "expected_signal": "Vulnerability findings on the perimeter. High-severity results combined with rare logins indicate a high-risk ingress event."
      },
      "parents": [
        {
          "id": "identify-perimeter"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Check for critical gateway vulnerabilities",
        "reads": [
          "device_uid",
          "cve_uid",
          "affected_package_name",
          "severity",
          "severity_id",
          "collected_at"
        ],
        "source": "hb_vulnerability_finding",
        "target": "endpoint",
        "content": "SELECT device_uid, cve_uid, affected_package_name, severity, collected_at FROM hb_vulnerability_finding WHERE severity_id >= 4 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_uid || ',') > 0) AND (instr(',' || '{{gateway_products}}' || ',', ',' || LOWER(affected_package_name) || ',') > 0) AND collected_at >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Vulnerability findings on the perimeter. High-severity results combined with rare logins indicate a high-risk ingress event.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "triage-ingress",
      "type": "analytic",
      "label": "Triage machine-speed ingress risk",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity"
        ],
        "context": [
          "identify-perimeter",
          "rare-auth-geolocations",
          "gateway-vulnerabilities"
        ],
        "objective": "Determine if successful sign-ins from rare geolocations occur on users with single-factor auth or target systems with known critical perimeter vulnerabilities. Identify if multiple distant geolocations appear for one user within the lookback window.",
        "description": "Analyze whether the rare authentications target vulnerable gateways or represent impossible travel patterns.",
        "max_iterations": 5,
        "expected_signal": "A per-account and per-host verdict citing specific rows from authentication and vulnerability data.",
        "success_criteria": "A verdict of malicious, suspicious, or benign per host and account, citing the evidence from all contexts."
      },
      "parents": [
        {
          "id": "rare-auth-geolocations",
          "kind": "merge"
        },
        {
          "id": "gateway-vulnerabilities",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-risk",
      "type": "checkpoint",
      "label": "Route on ingress risk",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "The triage verdict is malicious for at least one account or host based on rare geolocation or unpatched gateway exploitation.",
        "condition": "The triage verdict is malicious for at least one account or host based on rare geolocation or unpatched gateway exploitation.",
        "blind_spot": "missing-auth-geolocation",
        "confidence": "high",
        "description": "The decision routes the result to containment if the agent confirms a malicious ingress.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-ingress"
        }
      ]
    },
    {
      "id": "isolate-or-revoke",
      "type": "action",
      "label": "Isolate host or revoke identity",
      "config": {
        "target": "identity",
        "description": "Halt the intrusion immediately to prevent further lateral movement.",
        "instructions": "Revoke active sessions and reset passwords for compromised accounts; isolate hosts if the agent found evidence of host-level vulnerability exploitation.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-risk",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Analyst review and verification",
      "config": {
        "assignee": "analyst",
        "description": "Confirm the agent's verdict and document the attack path for future tuning.",
        "instructions": "Examine the auth_signin rows for flagged users; check for shared source IPs and geolocation proximity. Verify the presence of critical vulnerabilities on the target gateways."
      },
      "parents": [
        {
          "id": "route-risk",
          "branch": "default"
        },
        {
          "id": "route-risk",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-or-revoke"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Hunt close-out",
      "config": {
        "assignee": "analyst",
        "description": "Finalize the hunt and record findings.",
        "instructions": "Record the number of vulnerable assets and rare sign-ins observed. Note users who frequently trigger geolocation anomalies for allow-listing or policy adjustment."
      },
      "parents": [
        {
          "id": "route-risk",
          "branch": "on_refutes"
        },
        {
          "id": "analyst-review"
        }
      ]
    }
  ]
}