{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "The exploitation of zero-day vulnerabilities in remote access gateways like Citrix NetScaler is a critical risk that leads directly to high-impact ransomware. A hunt is necessary to find post-exploit evidence that standing rules might miss due to the 'dual-use' nature of RMM tools."
      },
      "name": "NetScaler exploitation and RMM-driven ransomware",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1190",
        "attack.t1203",
        "attack.t1486",
        "command and control",
        "execution",
        "impact",
        "initial access"
      ],
      "related": [
        {
          "hunt": "unauthorized-rmm-persistence",
          "reason": "This hunt focuses on the specific ransomware chain; a broader RMM hunt would cover more diverse persistence scenarios.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A simple rule for a hash will miss the attacker if they rotate payloads; a rule for RMM tools will produce too many false positives. This hunt pivots from a vulnerability scope to rare behavioral baselines (RMM prevalence) and cross-correlates them with file impact metrics to find the full intrusion chain.",
      "coverage": [
        {
          "stage": "initial-access-exploit",
          "steps": [
            "scoping-vulnerable-gateways",
            "suspicious-http-patterns"
          ],
          "status": "covered"
        },
        {
          "stage": "backdoor-execution",
          "steps": [
            "backdoor-process-hashes"
          ],
          "status": "covered"
        },
        {
          "stage": "remote-access-abuse",
          "steps": [
            "unauthorized-rmm-usage"
          ],
          "status": "covered"
        },
        {
          "stage": "ransomware-impact",
          "steps": [
            "ransomware-impact-signs"
          ],
          "status": "covered"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Exploitation of Public-Facing Applications",
            "slug": "initial-access-exploit",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "Citrix NetScaler ADC",
              "Citrix NetScaler Gateway",
              "NetScaler zero-day vulnerabilities",
              "Automated AI agent exploitation",
              "Exposed file-sharing servers"
            ]
          },
          {
            "name": "Malware and Backdoor Execution",
            "slug": "backdoor-execution",
            "tactic": "execution",
            "techniques": [
              "T1203"
            ],
            "observables": [
              "Antino backdoor",
              "W32.Injector",
              "sample.exe",
              "tmp00055df5.dll",
              "f_006048.exe",
              "SECOH-QAD.exe",
              "9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507",
              "96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974",
              "90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59",
              "540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8",
              "9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f",
              "w32.9f1f11a708-100.sbx.tg",
              "w32.injector",
              "w32.540080fea9-95.sbx.tg",
              "w32.9896a6fcb9-95.sbx.tg"
            ]
          },
          {
            "name": "Remote Monitoring and Management Abuse",
            "slug": "remote-access-abuse",
            "tactic": "command-and-control",
            "observables": [
              "TeamViewer high-severity flaws",
              "Unauthorized RMM tool use",
              "Dual-use RMM abuse"
            ]
          },
          {
            "name": "Data Encrypted for Impact",
            "slug": "ransomware-impact",
            "tactic": "impact",
            "techniques": [
              "T1486"
            ],
            "observables": [
              "Ransomware-linked malware",
              "OT network data encryption"
            ]
          }
        ],
        "summary": "Threat actors exploit critical vulnerabilities in public-facing infrastructure like Citrix NetScaler or through automated AI agents to gain initial access, subsequently deploying backdoors like Antino and abusing remote management tools like TeamViewer. This activity ultimately leads to data breaches on file-sharing servers and the deployment of ransomware in critical infrastructure OT networks for data encryption."
      },
      "severity": "critical",
      "rationale": "Start with public-facing segments containing Citrix NetScaler or TeamViewer installations. Prioritize hosts with high-severity vulnerabilities first.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An attacker has exploited vulnerabilities in a public-facing gateway or remote access tool to execute a backdoor, followed by establishing persistence via unauthorized RMM software and initiating ransomware file encryption.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Optional list of hostnames to focus the behavioral queries."
        },
        "rmm_software": {
          "type": "list[string]",
          "default": [
            "teamviewer",
            "anydesk",
            "screenconnect",
            "rustdesk",
            "logmein",
            "atera",
            "splashtop"
          ],
          "description": "Names of common RMM tools to monitor for unauthorized usage."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "backdoor_hashes": {
          "from": {
            "ref": "https://blog.talosintelligence.com/give-yourself-room-to-be-human/",
            "kind": "article",
            "observed": "2026-10-01"
          },
          "type": "list[hash]",
          "default": [
            "9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507",
            "96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974",
            "90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59",
            "540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8",
            "9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f"
          ],
          "description": "SHA256 hashes of the Antino backdoor and other malware from the report."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://blog.talosintelligence.com/give-yourself-room-to-be-human/",
          "gates": [
            "dry-run",
            "lint",
            "critic"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://blog.talosintelligence.com/give-yourself-room-to-be-human/",
          "name": "Talos \u2014 Give yourself room to be human"
        }
      ],
      "blind_spots": [
        {
          "id": "limited-ot-visibility",
          "risk": "A negative result on the IT endpoints does not guarantee the OT network is safe if it lacks agent coverage.",
          "owner": "Network Engineering",
          "stage": "ransomware-impact",
          "question": "whether ransomware has successfully encrypted files on the OT segment",
          "requires": "Direct telemetry from OT network devices",
          "remediation": "Integrate OT network flow logs or specialized OT monitoring agents."
        },
        {
          "id": "http-encryption",
          "risk": "Attackers can hide exploit payloads inside encrypted traffic, leaving the hunter to rely only on meta-signals like request frequency or volume.",
          "owner": "Security Architecture",
          "stage": "initial-access-exploit",
          "question": "what specific payloads or exploits were sent to the NetScaler",
          "requires": "TLS decryption/inspection at the gateway",
          "remediation": "Enable SSL/TLS inspection for inbound traffic to public-facing gateways."
        }
      ]
    },
    "name": "NetScaler exploitation and RMM-driven ransomware",
    "description": "This hunt follows the complete attack chain reported by Talos, focusing on the exploitation of Citrix NetScaler and TeamViewer. It begins by identifying vulnerable assets, then moves to detect early-stage backdoor execution via known hashes. Finally, it looks for the aftermath: unauthorized remote management tools and the high-volume file modifications characteristic of ransomware impact."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "coverage": [
          {
            "stage": "initial-access-exploit",
            "steps": [
              "scoping-vulnerable-gateways",
              "suspicious-http-patterns"
            ],
            "status": "covered"
          },
          {
            "stage": "backdoor-execution",
            "steps": [
              "backdoor-process-hashes"
            ],
            "status": "covered"
          },
          {
            "stage": "remote-access-abuse",
            "steps": [
              "unauthorized-rmm-usage"
            ],
            "status": "covered"
          },
          {
            "stage": "ransomware-impact",
            "steps": [
              "ransomware-impact-signs"
            ],
            "status": "covered"
          }
        ],
        "rationale": "An attacker has exploited vulnerabilities in a public-facing gateway or remote access tool to execute a backdoor, followed by establishing persistence via unauthorized RMM software and initiating ransomware file encryption.",
        "blind_spots": [
          {
            "id": "limited-ot-visibility",
            "risk": "A negative result on the IT endpoints does not guarantee the OT network is safe if it lacks agent coverage.",
            "owner": "Network Engineering",
            "stage": "ransomware-impact",
            "question": "whether ransomware has successfully encrypted files on the OT segment",
            "requires": "Direct telemetry from OT network devices",
            "remediation": "Integrate OT network flow logs or specialized OT monitoring agents."
          },
          {
            "id": "http-encryption",
            "risk": "Attackers can hide exploit payloads inside encrypted traffic, leaving the hunter to rely only on meta-signals like request frequency or volume.",
            "owner": "Security Architecture",
            "stage": "initial-access-exploit",
            "question": "what specific payloads or exploits were sent to the NetScaler",
            "requires": "TLS decryption/inspection at the gateway",
            "remediation": "Enable SSL/TLS inspection for inbound traffic to public-facing gateways."
          }
        ],
        "scoping_notes": "Start with public-facing segments containing Citrix NetScaler or TeamViewer installations. Prioritize hosts with high-severity vulnerabilities first.",
        "beyond_detection": "A simple rule for a hash will miss the attacker if they rotate payloads; a rule for RMM tools will produce too many false positives. This hunt pivots from a vulnerability scope to rare behavioral baselines (RMM prevalence) and cross-correlates them with file impact metrics to find the full intrusion chain."
      }
    },
    {
      "id": "scoping-vulnerable-gateways",
      "type": "query",
      "label": "Scope vulnerable gateway and access software",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_uid, cve_uid, affected_package_name, affected_package_version, cvss_score FROM hb_vulnerability_finding WHERE (LOWER(affected_package_name) LIKE '%netscaler%' OR LOWER(affected_package_name) LIKE '%teamviewer%') AND severity_id >= 4",
        "surface": "hb_vulnerability_finding",
        "description": "Identify hosts running software with known high-severity vulnerabilities mentioned in the report (NetScaler, TeamViewer).",
        "expected_signal": "Hosts running vulnerable versions of Citrix NetScaler or TeamViewer. Zero results means no known vulnerable versions are reporting, but unmanaged assets may remain."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Scope vulnerable gateway and access software",
        "reads": [
          "affected_package_name",
          "affected_package_version",
          "cve_uid",
          "cvss_score",
          "device_uid",
          "severity_id"
        ],
        "source": "hb_vulnerability_finding",
        "target": "endpoint",
        "content": "SELECT device_uid, cve_uid, affected_package_name, affected_package_version, cvss_score FROM hb_vulnerability_finding WHERE (LOWER(affected_package_name) LIKE '%netscaler%' OR LOWER(affected_package_name) LIKE '%teamviewer%') AND severity_id >= 4",
        "silence": "not_evidence_of_absence",
        "expected": "Hosts running vulnerable versions of Citrix NetScaler or TeamViewer. Zero results means no known vulnerable versions are reporting, but unmanaged assets may remain.",
        "verified": "dry-run",
        "verified_at": "2026-10-02"
      }
    },
    {
      "id": "suspicious-http-patterns",
      "type": "query",
      "label": "Suspicious HTTP patterns to gateways",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "web",
        "content": "SELECT device_hostname, src_endpoint_ip, url_path, user_agent, COUNT(*) as request_count FROM hb_http_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, src_endpoint_ip, url_path, user_agent HAVING request_count > 100 ORDER BY request_count DESC",
        "surface": "hb_http_activity",
        "description": "Find anomalous HTTP requests to gateway servers that might indicate exploitation attempts, such as high-frequency requests or rare user agents.",
        "expected_signal": "High-frequency requests to specific paths which might correspond to the AI-driven 'loud' attack mentioned in the article."
      },
      "parents": [
        {
          "id": "scoping-vulnerable-gateways"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Suspicious HTTP patterns to gateways",
        "reads": [
          "device_hostname",
          "src_endpoint_ip",
          "time",
          "url_path",
          "user_agent"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT device_hostname, src_endpoint_ip, url_path, user_agent, COUNT(*) as request_count FROM hb_http_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, src_endpoint_ip, url_path, user_agent HAVING request_count > 100 ORDER BY request_count DESC",
        "silence": "not_evidence_of_absence",
        "expected": "High-frequency requests to specific paths which might correspond to the AI-driven 'loud' attack mentioned in the article.",
        "verified": "dry-run",
        "verified_at": "2026-10-02"
      }
    },
    {
      "id": "backdoor-process-hashes",
      "type": "query",
      "label": "Antino backdoor process activity",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, process_hash_sha256, user_name, time FROM hb_process_activity WHERE instr(',' || '{{backdoor_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Directly search for the execution of malware reported by Talos using SHA256 hashes.",
        "expected_signal": "Any execution of the reported hashes indicates a confirmed compromise. Silence indicates this specific payload version is not present."
      },
      "parents": [
        {
          "id": "scoping-vulnerable-gateways"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Antino backdoor process activity",
        "reads": [
          "device_hostname",
          "process_cmd_line",
          "process_hash_sha256",
          "process_name",
          "time",
          "user_name"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, process_hash_sha256, user_name, time FROM hb_process_activity WHERE instr(',' || '{{backdoor_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "evidence_of_absence",
        "expected": "Any execution of the reported hashes indicates a confirmed compromise. Silence indicates this specific payload version is not present.",
        "verified": "dry-run",
        "verified_at": "2026-10-02"
      }
    },
    {
      "id": "assess-initial-compromise",
      "type": "analytic",
      "label": "Assess Initial Compromise",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "web"
        ],
        "context": [
          "scoping-vulnerable-gateways",
          "suspicious-http-patterns",
          "backdoor-process-hashes"
        ],
        "objective": "Determine if any host identified in the scoping query shows signs of exploitation (HTTP anomalies) or execution of the Antino backdoor.",
        "description": "Evaluate if the scoping hits and early execution signs point to a successful breach.",
        "max_iterations": 3,
        "expected_signal": "A list of hosts likely compromised by the initial access technique.",
        "success_criteria": "A verdict per host indicating breach status with citations of suspicious activity."
      },
      "parents": [
        {
          "id": "suspicious-http-patterns",
          "kind": "merge"
        },
        {
          "id": "backdoor-process-hashes",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "unauthorized-rmm-usage",
      "type": "query",
      "label": "Unauthorized RMM usage",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT device_hostname, LOWER(process_name) as p_name, COUNT(DISTINCT device_hostname) as host_count, MIN(time) as first_seen FROM hb_process_activity WHERE (instr(',' || '{{rmm_software}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || '{{rmm_software}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY p_name HAVING host_count < 5",
        "surface": "hb_process_activity",
        "description": "Find RMM tools executed on hosts identified as likely breached, stack-counting to find rare instances.",
        "expected_signal": "RMM tool execution that is rare across the fleet, potentially indicating attacker persistence."
      },
      "parents": [
        {
          "id": "assess-initial-compromise"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Unauthorized RMM usage",
        "reads": [
          "device_hostname",
          "process_name",
          "process_original_file_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, LOWER(process_name) as p_name, COUNT(DISTINCT device_hostname) as host_count, MIN(time) as first_seen FROM hb_process_activity WHERE (instr(',' || '{{rmm_software}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || '{{rmm_software}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY p_name HAVING host_count < 5",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "RMM tool execution that is rare across the fleet, potentially indicating attacker persistence.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_name"
          ],
          "rare_below": 5
        },
        "verified_at": "2026-10-02"
      }
    },
    {
      "id": "ransomware-impact-signs",
      "type": "query",
      "label": "Ransomware impact signs",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, COUNT(*) as file_mod_count, MIN(time) as start_time, MAX(time) as end_time FROM hb_file_activity WHERE activity_id IN (1, 3, 5) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name HAVING file_mod_count > 500 ORDER BY file_mod_count DESC",
        "surface": "hb_file_activity",
        "description": "Identify mass file modification activity on a single host within a narrow time window, typical of ransomware encryption.",
        "expected_signal": "A specific process modifying hundreds or thousands of files in a short burst."
      },
      "parents": [
        {
          "id": "assess-initial-compromise"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Ransomware impact signs",
        "reads": [
          "activity_id",
          "device_hostname",
          "process_name",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, COUNT(*) as file_mod_count, MIN(time) as start_time, MAX(time) as end_time FROM hb_file_activity WHERE activity_id IN (1, 3, 5) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name HAVING file_mod_count > 500 ORDER BY file_mod_count DESC",
        "silence": "not_evidence_of_absence",
        "expected": "A specific process modifying hundreds or thousands of files in a short burst.",
        "verified": "dry-run",
        "verified_at": "2026-10-02"
      }
    },
    {
      "id": "assess-full-chain",
      "type": "analytic",
      "label": "Assess Full Chain Impact",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "web"
        ],
        "context": [
          "assess-initial-compromise",
          "unauthorized-rmm-usage",
          "ransomware-impact-signs"
        ],
        "objective": "Combine the evidence of breach from the first agent with the observations of RMM tools and file encryption spikes. Determine if a ransomware incident is active.",
        "description": "Synthesize the early compromise signs with the follow-on RMM and encryption activity to confirm the ransomware operation.",
        "max_iterations": 4,
        "expected_signal": "A confirmed list of hosts where the entire attack chain has been observed.",
        "success_criteria": "A final verdict citing the progression from vulnerability to impact per host."
      },
      "parents": [
        {
          "id": "unauthorized-rmm-usage",
          "kind": "merge"
        },
        {
          "id": "ransomware-impact-signs",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the assessment confirms both initial compromise and follow-on ransomware-linked behavior",
        "condition": "the assessment confirms both initial compromise and follow-on ransomware-linked behavior",
        "blind_spot": "limited-ot-visibility",
        "confidence": "high",
        "description": "Initiate response if the full-chain assessment confirms malicious activity.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "assess-full-chain"
        }
      ]
    },
    {
      "id": "contain-threat",
      "type": "action",
      "label": "Contain affected hosts",
      "config": {
        "target": "endpoint",
        "description": "Prevent further lateral movement and data destruction by isolating confirmed compromised endpoints.",
        "instructions": "Isolate the host, terminate the malicious process identified in the file activity step, and revoke any sessions associated with the host's users.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "manual-review",
      "type": "task",
      "label": "Manual analyst triage",
      "config": {
        "assignee": "analyst",
        "description": "Final review of the evidence by a human analyst to confirm the agent's findings and identify tuning opportunities.",
        "instructions": "Review the cited rows in the follow-on assessment. Confirm if the RMM usage was authorized and if the file modifications were indeed malicious encryption or benign high-volume tasks like indexing or updates."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "contain-threat"
        }
      ]
    },
    {
      "id": "close-out-report",
      "type": "task",
      "label": "Close out hunt report",
      "config": {
        "assignee": "analyst",
        "description": "Document findings and gaps.",
        "instructions": "Record the number of hosts examined, the number of confirmed compromises, and the coverage of the NetScaler/TeamViewer assets. Note any OT segments that were unreachable."
      },
      "parents": [
        {
          "id": "manual-review"
        }
      ]
    }
  ]
}