{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "JavaScript obfuscation is a primary method for hiding credential theft in phishing and malicious packages. A negative result over the estate confirms these deobfuscation primitives are not being abused for local collection."
      },
      "name": "Obfuscated JavaScript and Local Collection",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1566",
        "attack.t1176",
        "attack.t1115",
        "attack.t1041",
        "collection",
        "defense evasion",
        "execution",
        "exfiltration",
        "initial access",
        "persistence"
      ],
      "series": {
        "slug": "javascript-obfuscation-from-party-trick-to-phishing-kit",
        "index": 1,
        "title": "JavaScript obfuscation: From party trick to phishing kit",
        "total": 2
      },
      "related": [
        {
          "hunt": "initial-access-phishing-delivery",
          "reason": "This hunt focuses on execution and collection, not the delivery vector.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "Standard rules may alert on 'atob' or 'eval', but they cannot differentiate between a legitimate minified library and a multi-stage deobfuscation routine. This hunt pivots from npm context to script content and rare extension persistence, distinguishing malice through the attack chain.",
      "coverage": [
        {
          "stage": "execution-npm-install-scripts",
          "steps": [
            "npm-install-scripts"
          ],
          "status": "covered"
        },
        {
          "stage": "defense-evasion-script-obfuscation",
          "steps": [
            "obfuscated-script-content"
          ],
          "status": "covered"
        },
        {
          "stage": "persistence-browser-extensions",
          "steps": [
            "browser-extension-changes"
          ],
          "status": "covered"
        },
        {
          "stage": "collection-credential-and-cookie-theft",
          "steps": [
            "credential-collection-utilities"
          ],
          "status": "covered"
        },
        {
          "stage": "initial-access-phishing-delivery",
          "reason": "Belongs to another part of the 'JavaScript obfuscation: From party trick to phishing kit' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "exfiltration-over-c2",
          "reason": "Belongs to another part of the 'JavaScript obfuscation: From party trick to phishing kit' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Phishing Kit and Social Engineering Delivery",
            "slug": "initial-access-phishing-delivery",
            "tactic": "initial-access",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "phishing kit",
              "fake CAPTCHA",
              "fake update flows",
              "compromised website injections"
            ]
          },
          {
            "name": "Malicious Package Installation",
            "slug": "execution-npm-install-scripts",
            "tactic": "execution",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "npm package install scripts",
              "npm tokens"
            ]
          },
          {
            "name": "JavaScript Obfuscation and Anti-Analysis",
            "slug": "defense-evasion-script-obfuscation",
            "tactic": "defense-evasion",
            "techniques": [
              "T1176"
            ],
            "observables": [
              "eval()",
              "atob()",
              "String.fromCharCode()",
              "atob('ZXZhbA==')",
              "JSFuck",
              "navigator.webdriver",
              "control-flow flattening",
              "_0x identifiers"
            ]
          },
          {
            "name": "Browser Extension Abuse",
            "slug": "persistence-browser-extensions",
            "tactic": "persistence",
            "techniques": [
              "T1176"
            ],
            "observables": [
              "browser extension abuse",
              "malicious software extensions"
            ]
          },
          {
            "name": "Credential and Browser Data Collection",
            "slug": "collection-credential-and-cookie-theft",
            "tactic": "collection",
            "techniques": [
              "T1115"
            ],
            "observables": [
              "window.document.cookie",
              "clipboard contents",
              "clip.exe",
              "pbpaste"
            ]
          },
          {
            "name": "Exfiltration via Web Request",
            "slug": "exfiltration-over-c2",
            "tactic": "exfiltration",
            "techniques": [
              "T1041"
            ],
            "observables": [
              "https://example.com",
              "fetch",
              "?password="
            ]
          }
        ],
        "summary": "Threat actors employ sophisticated JavaScript obfuscation techniques, including packing, encoding, and JSFuck, to conceal malicious payloads in phishing kits, malware loaders, and npm packages. These scripts often include anti-analysis features like browser fingerprinting and control-flow flattening to evade detection while exfiltrating credentials and cookies from victim systems."
      },
      "severity": "high",
      "rationale": "Start with developer-heavy hosts or machines running node.js. Focus on user profiles where browser extensions and npm packages are locally installed.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An intruder is using obfuscated JavaScript within npm install scripts or malicious browser extensions to collect credentials and cookies from the local endpoint while evading static analysis.",
      "parameters": {
        "scope_hosts": {
          "from": {
            "ref": "analyst-scoping",
            "kind": "manual",
            "observed": "2024-05-20"
          },
          "type": "list[host]",
          "default": [],
          "description": "Optional list of hostnames to focus the hunt on."
        },
        "lookback_days": {
          "from": {
            "ref": "standard-retention",
            "kind": "manual",
            "observed": "2024-05-20"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "suspicious_binaries": {
          "from": {
            "ref": "talos-js-obfuscation",
            "kind": "article",
            "observed": "2024-05-20"
          },
          "type": "list[string]",
          "default": [
            "clip.exe",
            "pbpaste",
            "get-clipboard"
          ],
          "description": "Binaries or cmdlets associated with clipboard data collection."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://blog.talosintelligence.com/javascript-obfuscation-from-party-trick-to-phishing-kit/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://blog.talosintelligence.com/javascript-obfuscation-from-party-trick-to-phishing-kit/",
          "name": "Talos \u2014 JavaScript obfuscation: From party trick to phishing kit"
        }
      ],
      "blind_spots": [
        {
          "id": "no-script-visibility",
          "risk": "If the script is deobfuscated only at the final execution sink and logging does not capture the evaluated string, the hunt will only see the obfuscated wrapper.",
          "stage": "defense-evasion-script-obfuscation",
          "question": "whether the deobfuscated script is visible in cleartext",
          "requires": "hb_script_activity with high block resolution"
        },
        {
          "id": "ephemeral-extensions",
          "risk": "A script that installs, steals data, and then uninstalls an extension may leave no footprint in snapshot inventories, relying entirely on file events.",
          "stage": "persistence-browser-extensions",
          "question": "whether the malicious extension was deleted before detection",
          "requires": "hb_file_activity with real-time auditing"
        }
      ]
    },
    "name": "Obfuscated JavaScript and Local Collection",
    "description": "This hunt targets the intersection of developer-focused delivery through npm and client-side credential theft. It identifies suspicious npm install hooks and the use of deobfuscation primitives like atob, String.fromCharCode, and eval within script blocks. The hunt then pivots to look for resulting persistence via browser extensions and the execution of collection utilities like clip.exe, providing a full picture of the attack chain from execution to collection."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "javascript-obfuscation-from-party-trick-to-phishing-kit",
          "index": 1,
          "title": "JavaScript obfuscation: From party trick to phishing kit",
          "total": 2
        },
        "coverage": [
          {
            "stage": "execution-npm-install-scripts",
            "steps": [
              "npm-install-scripts"
            ],
            "status": "covered"
          },
          {
            "stage": "defense-evasion-script-obfuscation",
            "steps": [
              "obfuscated-script-content"
            ],
            "status": "covered"
          },
          {
            "stage": "persistence-browser-extensions",
            "steps": [
              "browser-extension-changes"
            ],
            "status": "covered"
          },
          {
            "stage": "collection-credential-and-cookie-theft",
            "steps": [
              "credential-collection-utilities"
            ],
            "status": "covered"
          },
          {
            "stage": "initial-access-phishing-delivery",
            "reason": "Belongs to another part of the 'JavaScript obfuscation: From party trick to phishing kit' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "exfiltration-over-c2",
            "reason": "Belongs to another part of the 'JavaScript obfuscation: From party trick to phishing kit' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An intruder is using obfuscated JavaScript within npm install scripts or malicious browser extensions to collect credentials and cookies from the local endpoint while evading static analysis.",
        "blind_spots": [
          {
            "id": "no-script-visibility",
            "risk": "If the script is deobfuscated only at the final execution sink and logging does not capture the evaluated string, the hunt will only see the obfuscated wrapper.",
            "stage": "defense-evasion-script-obfuscation",
            "question": "whether the deobfuscated script is visible in cleartext",
            "requires": "hb_script_activity with high block resolution"
          },
          {
            "id": "ephemeral-extensions",
            "risk": "A script that installs, steals data, and then uninstalls an extension may leave no footprint in snapshot inventories, relying entirely on file events.",
            "stage": "persistence-browser-extensions",
            "question": "whether the malicious extension was deleted before detection",
            "requires": "hb_file_activity with real-time auditing"
          }
        ],
        "scoping_notes": "Start with developer-heavy hosts or machines running node.js. Focus on user profiles where browser extensions and npm packages are locally installed.",
        "beyond_detection": "Standard rules may alert on 'atob' or 'eval', but they cannot differentiate between a legitimate minified library and a multi-stage deobfuscation routine. This hunt pivots from npm context to script content and rare extension persistence, distinguishing malice through the attack chain."
      }
    },
    {
      "id": "scope-npm-hosts",
      "type": "query",
      "label": "Scope hosts with npm installed",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT DISTINCT device_hostname, package_name, package_version FROM hb_software_inventory WHERE package_type = 'npm' OR LOWER(package_name) LIKE '%node%'",
        "surface": "hb_software_inventory",
        "description": "Identify machines with npm packages or node.js installed to narrow the search for malicious install scripts.",
        "expected_signal": "A list of hosts likely to run developer workloads or handle npm packages. Silence implies no npm-managed software is in the inventory."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Scope hosts with npm installed",
        "reads": [
          "device_hostname",
          "package_name",
          "package_version"
        ],
        "source": "hb_software_inventory",
        "target": "endpoint",
        "content": "SELECT DISTINCT device_hostname, package_name, package_version FROM hb_software_inventory WHERE package_type = 'npm' OR LOWER(package_name) LIKE '%node%'",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hosts likely to run developer workloads or handle npm packages. Silence implies no npm-managed software is in the inventory.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "npm-install-scripts",
      "type": "query",
      "label": "Suspicious npm install scripts",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, parent_process_name, time FROM hb_process_activity WHERE (LOWER(parent_process_name) LIKE '%npm%' OR LOWER(parent_process_name) LIKE '%node%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Find shells launched from npm during package installation which are commonly used for malware delivery.",
        "expected_signal": "Processes like sh, bash, or cmd.exe running as children of npm or node. Presence of arbitrary commands suggests a malicious hook."
      },
      "parents": [
        {
          "id": "scope-npm-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Suspicious npm install scripts",
        "reads": [
          "device_hostname",
          "process_name",
          "process_cmd_line",
          "parent_process_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, parent_process_name, time FROM hb_process_activity WHERE (LOWER(parent_process_name) LIKE '%npm%' OR LOWER(parent_process_name) LIKE '%node%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Processes like sh, bash, or cmd.exe running as children of npm or node. Presence of arbitrary commands suggests a malicious hook.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "obfuscated-script-content",
      "type": "query",
      "label": "Obfuscated script block detection",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "endpoint",
        "content": "SELECT device_hostname, script_content, script_type, time FROM hb_script_activity WHERE (LOWER(script_content) LIKE '%string.fromcharcode%' OR LOWER(script_content) LIKE '%atob%(' OR LOWER(script_content) LIKE '%navigator.webdriver%' OR LOWER(script_content) LIKE '%eval%(') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_script_activity",
        "description": "Identify script blocks using deobfuscation primitives or anti-analysis signals in the actual script text.",
        "expected_signal": "Script fragments resolving strings at runtime or checking for automated browser environments. Minified libraries may trigger false positives."
      },
      "parents": [
        {
          "id": "scope-npm-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Obfuscated script block detection",
        "reads": [
          "device_hostname",
          "script_content",
          "script_type",
          "time"
        ],
        "source": "hb_script_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, script_content, script_type, time FROM hb_script_activity WHERE (LOWER(script_content) LIKE '%string.fromcharcode%' OR LOWER(script_content) LIKE '%atob%(' OR LOWER(script_content) LIKE '%navigator.webdriver%' OR LOWER(script_content) LIKE '%eval%(') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Script fragments resolving strings at runtime or checking for automated browser environments. Minified libraries may trigger false positives.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "triage-early-stage",
      "type": "analytic",
      "label": "Evaluate execution and obfuscation",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "npm-install-scripts",
          "obfuscated-script-content"
        ],
        "objective": "Identify hosts where npm processes and deobfuscation primitives indicate a high likelihood of malicious script execution.",
        "description": "Determine if the observed npm behavior and script deobfuscation primitives correlate to a single host or campaign.",
        "max_iterations": 3,
        "expected_signal": "A verdict on the suspiciousness of the early stage activity per host.",
        "success_criteria": "A per-host verdict of Malicious, Suspicious, or Benign citing specific script fragments or process chains."
      },
      "parents": [
        {
          "id": "npm-install-scripts",
          "kind": "merge"
        },
        {
          "id": "obfuscated-script-content",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "browser-extension-changes",
      "type": "query",
      "label": "Rare browser extension file activity",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT LOWER(file_path) AS ext_path, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_file_activity WHERE (LOWER(file_path) LIKE '%/extensions/%' OR LOWER(file_path) LIKE '%\\extensions\\%' OR LOWER(file_path) LIKE '%manifest.json%') AND activity_id = 1 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1 HAVING host_count <= 3 ORDER BY host_count ASC",
        "surface": "hb_file_activity",
        "description": "Identify new or modified browser extensions that may have been installed by the obfuscated script.",
        "expected_signal": "Extension paths found on only a few hosts. New manifest files in user profile directories across multiple platforms."
      },
      "parents": [
        {
          "id": "triage-early-stage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare browser extension file activity",
        "reads": [
          "file_path",
          "device_hostname",
          "time",
          "activity_id"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT LOWER(file_path) AS ext_path, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_file_activity WHERE (LOWER(file_path) LIKE '%/extensions/%' OR LOWER(file_path) LIKE '%\\extensions\\%' OR LOWER(file_path) LIKE '%manifest.json%') AND activity_id = 1 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1 HAVING host_count <= 3 ORDER BY host_count ASC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Extension paths found on only a few hosts. New manifest files in user profile directories across multiple platforms.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "ext_path"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "credential-collection-utilities",
      "type": "query",
      "label": "Execution of collection utilities",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, time FROM hb_process_activity WHERE (instr(',' || '{{suspicious_binaries}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || '{{suspicious_binaries}}' || ',', ',' || LOWER(process_cmd_line) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Find the use of standard OS utilities for stealing clipboard data or browser credentials.",
        "expected_signal": "The use of clip.exe or pbpaste on hosts where suspicious JS or npm activity was previously identified."
      },
      "parents": [
        {
          "id": "triage-early-stage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Execution of collection utilities",
        "reads": [
          "device_hostname",
          "process_name",
          "process_cmd_line",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, time FROM hb_process_activity WHERE (instr(',' || '{{suspicious_binaries}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || '{{suspicious_binaries}}' || ',', ',' || LOWER(process_cmd_line) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "The use of clip.exe or pbpaste on hosts where suspicious JS or npm activity was previously identified.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "assess-full-chain",
      "type": "analytic",
      "label": "Final assessment of attack chain",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "triage-early-stage",
          "browser-extension-changes",
          "credential-collection-utilities"
        ],
        "objective": "Determine if any host shows a complete chain from suspicious execution to persistence and collection.",
        "description": "Synthesize the early execution evidence with the follow-on persistence and collection activity to confirm a full intrusion.",
        "max_iterations": 5,
        "expected_signal": "A comprehensive verdict linking npm scripts, obfuscated code, and credential theft.",
        "success_criteria": "A detailed report identifying the compromised host, the malicious package or extension, and the scope of data collected."
      },
      "parents": [
        {
          "id": "browser-extension-changes",
          "kind": "merge"
        },
        {
          "id": "credential-collection-utilities",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "decision-route",
      "type": "checkpoint",
      "label": "Route based on verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the assess-full-chain verdict is malicious for at least one host",
        "condition": "the assess-full-chain verdict is malicious for at least one host",
        "blind_spot": "no-script-visibility",
        "confidence": "high",
        "description": "Decide whether to isolate the host for immediate response or proceed with manual review.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "assess-full-chain"
        }
      ]
    },
    {
      "id": "isolate-endpoint",
      "type": "action",
      "label": "Isolate compromised host",
      "config": {
        "target": "endpoint",
        "description": "Prevent further exfiltration and stop the malicious extension or script from running.",
        "instructions": "Isolate the host immediately. Collect the suspected malicious binary or script before killing any associated processes.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "decision-route",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "manual-review",
      "type": "task",
      "label": "Manual analyst review",
      "config": {
        "assignee": "analyst",
        "description": "Conduct a deep dive into the deobfuscated script content and verify the extent of the collection.",
        "instructions": "Extract the script content from hb_script_activity. Use a controlled sandbox to recover the final payload. Identify any exfiltration endpoints found in the decoded strings."
      },
      "parents": [
        {
          "id": "decision-route",
          "branch": "default"
        },
        {
          "id": "decision-route",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-endpoint"
        }
      ]
    },
    {
      "id": "hunt-closure",
      "type": "task",
      "label": "Hunt closure and documentation",
      "config": {
        "assignee": "analyst",
        "description": "Document findings, tune baseline parameters, and close the hunt.",
        "instructions": "Record all identified IOCs including script hashes and extension IDs. Update prevalence baselines for extensions if legitimate software was flagged."
      },
      "parents": [
        {
          "id": "decision-route",
          "branch": "on_refutes"
        },
        {
          "id": "manual-review"
        }
      ]
    }
  ]
}