{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "PaperCut is a high-value target for ransomware groups due to its widespread use and common internet exposure. A negative result confirms that the zero-day exploit chain has not been successfully used in the current lookback window."
      },
      "name": "PaperCut NG/MF Auth Bypass to RCE and Ransomware",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1190",
        "attack.t1486",
        "attack.t1203",
        "attack.t1562.001"
      ],
      "related": [
        {
          "hunt": "configuration-tampering-db-lookup",
          "reason": "Direct monitoring of PaperCut configuration database files or registry keys is a separate forensic task not covered by this behavioral hunt.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A static rule for shells spawned by PaperCut is easily bypassed by different interpreters. This hunt correlates the specific HTTP bypass patterns with evasion (log tampering) and organizational impact (mass encryption), providing the necessary context for emergency response.",
      "coverage": [
        {
          "stage": "initial-access-tapestry-auth-bypass",
          "steps": [
            "tapestry-auth-bypass-requests"
          ],
          "status": "covered"
        },
        {
          "stage": "remote-code-execution-nashorn",
          "steps": [
            "papercut-shell-execution"
          ],
          "status": "covered"
        },
        {
          "stage": "defense-evasion-log-tampering",
          "steps": [
            "papercut-log-tampering"
          ],
          "status": "covered"
        },
        {
          "stage": "data-encryption-ransomware",
          "steps": [
            "ransomware-file-impact"
          ],
          "status": "covered"
        },
        {
          "stage": "configuration-tampering-db-lookup",
          "reason": "Not examined by this hunt; belongs to a separate hunt.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Apache Tapestry Authentication Bypass",
            "slug": "initial-access-tapestry-auth-bypass",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "POST /app?service=direct/1/Error/ConfigEditor/quickFindForm",
              "POST /app?service=direct/1/Error/ConfigEditor/$Form",
              "POST /app?service=direct/1/Error/UserList/$QuickFind.$Form",
              "POST /app?service=direct/1/Exception/ConfigEditor/",
              "POST /app?service=direct/1/Home/ConfigEditor/"
            ]
          },
          {
            "name": "Malicious Database Lookup Configuration",
            "slug": "configuration-tampering-db-lookup",
            "tactic": "persistence",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "Modification of user-lookup.db-driver",
              "Modification of user-lookup.db-url",
              "Modification of user-lookup.id-to-username-sql",
              "Modification of user-lookup.enabled",
              "JDBC string: jdbc:no:x"
            ]
          },
          {
            "name": "Remote Code Execution via Nashorn Engine",
            "slug": "remote-code-execution-nashorn",
            "tactic": "execution",
            "techniques": [
              "T1203"
            ],
            "observables": [
              "pc-app.exe spawning cmd.exe",
              "pc-app.exe spawning /bin/sh",
              "Nashorn JavaScript-backed database trigger execution",
              "Apache Derby foreignViews feature activation",
              "H2 JDBC URL with INIT statement"
            ]
          },
          {
            "name": "Application Log Tampering",
            "slug": "defense-evasion-log-tampering",
            "tactic": "defense-evasion",
            "techniques": [
              "T1562.001"
            ],
            "observables": [
              "Deletion of PaperCut server.log",
              "Truncation of PaperCut server.log"
            ]
          },
          {
            "name": "Data Encrypted for Impact",
            "slug": "data-encryption-ransomware",
            "tactic": "impact",
            "techniques": [
              "T1486"
            ],
            "observables": [
              "Mass file encryption by pc-app.exe or its children"
            ]
          }
        ],
        "summary": "Attackers exploit a critical authentication bypass in PaperCut NG/MF to manipulate internal configuration settings, enabling remote code execution via unsafe JDBC class loading and the Nashorn JavaScript engine. This exploit chain, comprising CVE-2026-81578 and CVE-2026-82078, is frequently used by ransomware operators to gain initial access and encrypt server data."
      },
      "severity": "high",
      "rationale": "Start with internet-facing PaperCut servers identified in the inventory. If the HTTP surface is empty, focus on behavioral process execution signs (PaperCut processes spawning shells) as the bypass may be encrypted.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An attacker has exploited the PaperCut NG/MF authentication bypass vulnerabilities to reconfigure external database lookups and execute arbitrary code, leading to log tampering or ransomware deployment.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Target specific hostnames if PaperCut servers are already known."
        },
        "shell_names": {
          "type": "list[string]",
          "default": [
            "cmd.exe",
            "sh",
            "powershell.exe",
            "pwsh.exe",
            "bash",
            "zsh"
          ],
          "description": "Common shell interpreters used for post-exploitation execution across all platforms."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine for exploitation and post-compromise activity."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.rapid7.com/blog/post/etr-papercut-ng-mf-critical-zero-day-exploited-in-the-wild",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.rapid7.com/blog/post/etr-papercut-ng-mf-critical-zero-day-exploited-in-the-wild",
          "name": "Rapid7 \u2014 PaperCut NG/MF Critical Zero-Day Exploited in the Wild"
        }
      ],
      "blind_spots": [
        {
          "id": "http-tls-visibility",
          "risk": "If PaperCut uses HTTPS and we lack decryption, hb_http_activity will not show the url_query substrings used for the bypass.",
          "stage": "initial-access-tapestry-auth-bypass",
          "question": "whether the URI bypass attempts were visible in network traffic",
          "requires": "TLS decryption or server-side HTTP logs"
        },
        {
          "id": "nashorn-in-memory-execution",
          "risk": "We only see the aftermath (the spawned shell). The initial Nashorn execution inside the PaperCut process is invisible to process activity logs.",
          "stage": "remote-code-execution-nashorn",
          "question": "whether the malicious JavaScript execution occurred within the Java process",
          "requires": "JVM-level instrumentation"
        }
      ]
    },
    "name": "PaperCut NG/MF Auth Bypass to RCE and Ransomware",
    "description": "This hunt investigates the zero-day exploit chain affecting PaperCut NG and PaperCut MF (CVE-2026-81578 and CVE-2026-82078). The hunt follows a phased flow: first scoping PaperCut application servers, then detecting initial access via specific HTTP bypass URIs and subsequent shell execution from the PaperCut process across Windows, Linux, and macOS platforms. Finally, it identifies follow-on impact including application log tampering and high-volume file modification characteristic of ransomware activity."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "coverage": [
          {
            "stage": "initial-access-tapestry-auth-bypass",
            "steps": [
              "tapestry-auth-bypass-requests"
            ],
            "status": "covered"
          },
          {
            "stage": "remote-code-execution-nashorn",
            "steps": [
              "papercut-shell-execution"
            ],
            "status": "covered"
          },
          {
            "stage": "defense-evasion-log-tampering",
            "steps": [
              "papercut-log-tampering"
            ],
            "status": "covered"
          },
          {
            "stage": "data-encryption-ransomware",
            "steps": [
              "ransomware-file-impact"
            ],
            "status": "covered"
          },
          {
            "stage": "configuration-tampering-db-lookup",
            "reason": "Not examined by this hunt; belongs to a separate hunt.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An attacker has exploited the PaperCut NG/MF authentication bypass vulnerabilities to reconfigure external database lookups and execute arbitrary code, leading to log tampering or ransomware deployment.",
        "blind_spots": [
          {
            "id": "http-tls-visibility",
            "risk": "If PaperCut uses HTTPS and we lack decryption, hb_http_activity will not show the url_query substrings used for the bypass.",
            "stage": "initial-access-tapestry-auth-bypass",
            "question": "whether the URI bypass attempts were visible in network traffic",
            "requires": "TLS decryption or server-side HTTP logs"
          },
          {
            "id": "nashorn-in-memory-execution",
            "risk": "We only see the aftermath (the spawned shell). The initial Nashorn execution inside the PaperCut process is invisible to process activity logs.",
            "stage": "remote-code-execution-nashorn",
            "question": "whether the malicious JavaScript execution occurred within the Java process",
            "requires": "JVM-level instrumentation"
          }
        ],
        "scoping_notes": "Start with internet-facing PaperCut servers identified in the inventory. If the HTTP surface is empty, focus on behavioral process execution signs (PaperCut processes spawning shells) as the bypass may be encrypted.",
        "beyond_detection": "A static rule for shells spawned by PaperCut is easily bypassed by different interpreters. This hunt correlates the specific HTTP bypass patterns with evasion (log tampering) and organizational impact (mass encryption), providing the necessary context for emergency response."
      }
    },
    {
      "id": "scope-papercut-servers",
      "type": "query",
      "label": "Scope PaperCut application servers",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_hostname, package_name, package_version, install_path FROM hb_software_inventory WHERE LOWER(package_name) LIKE '%papercut%'",
        "surface": "hb_software_inventory",
        "description": "Locate the hosts running PaperCut to focus the behavioral search.",
        "expected_signal": "Hosts with PaperCut NG or MF installed. Silence means PaperCut is not indexed on any monitored host."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Scope PaperCut application servers",
        "reads": [
          "device_hostname",
          "package_name",
          "package_version",
          "install_path"
        ],
        "source": "hb_software_inventory",
        "target": "endpoint",
        "content": "SELECT device_hostname, package_name, package_version, install_path FROM hb_software_inventory WHERE LOWER(package_name) LIKE '%papercut%'",
        "silence": "not_evidence_of_absence",
        "expected": "Hosts with PaperCut NG or MF installed. Silence means PaperCut is not indexed on any monitored host.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "tapestry-auth-bypass-requests",
      "type": "query",
      "label": "Detect Apache Tapestry auth bypass attempts",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "web",
        "content": "SELECT device_hostname, src_endpoint_ip, url_path, url_query, time FROM hb_http_activity WHERE url_path = '/app' AND http_method = 'POST' AND LOWER(url_query) LIKE '%service=direct%' AND (LOWER(url_query) LIKE '%configeditor%' OR LOWER(url_query) LIKE '%userlist%') AND (LOWER(url_query) LIKE '%error%' OR LOWER(url_query) LIKE '%exception%' OR LOWER(url_query) LIKE '%home%') AND (LOWER(url_query) LIKE '%user-lookup.db%' OR LOWER(url_query) LIKE '%user-lookup.id%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_http_activity",
        "description": "Search for HTTP POST requests targeting administrative components via public bypass pages and specific configuration identifiers.",
        "expected_signal": "A request to /app with query parameters referencing ConfigEditor or UserList via the Error, Exception, or Home pages including targeted database configuration strings. This is a high-fidelity exploit indicator."
      },
      "parents": [
        {
          "id": "scope-papercut-servers"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Detect Apache Tapestry auth bypass attempts",
        "reads": [
          "device_hostname",
          "src_endpoint_ip",
          "url_path",
          "url_query",
          "time"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT device_hostname, src_endpoint_ip, url_path, url_query, time FROM hb_http_activity WHERE url_path = '/app' AND http_method = 'POST' AND LOWER(url_query) LIKE '%service=direct%' AND (LOWER(url_query) LIKE '%configeditor%' OR LOWER(url_query) LIKE '%userlist%') AND (LOWER(url_query) LIKE '%error%' OR LOWER(url_query) LIKE '%exception%' OR LOWER(url_query) LIKE '%home%') AND (LOWER(url_query) LIKE '%user-lookup.db%' OR LOWER(url_query) LIKE '%user-lookup.id%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "A request to /app with query parameters referencing ConfigEditor or UserList via the Error, Exception, or Home pages including targeted database configuration strings. This is a high-fidelity exploit indicator.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "papercut-shell-execution",
      "type": "query",
      "label": "Detect PaperCut spawning shells",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, parent_process_name, time FROM hb_process_activity WHERE LOWER(parent_process_name) LIKE '%pc-app%' AND instr(',' || '{{shell_names}}' || ',', ',' || LOWER(process_name) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Identify instances where a PaperCut application server process spawns a command shell to detect how attackers use the vulnerability for code execution.",
        "expected_signal": "A command interpreter running with a PaperCut process as its parent across Windows, Linux, or macOS. This strongly suggests remote code execution."
      },
      "parents": [
        {
          "id": "scope-papercut-servers"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Detect PaperCut spawning shells",
        "reads": [
          "device_hostname",
          "process_name",
          "process_cmd_line",
          "parent_process_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, parent_process_name, time FROM hb_process_activity WHERE LOWER(parent_process_name) LIKE '%pc-app%' AND instr(',' || '{{shell_names}}' || ',', ',' || LOWER(process_name) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "A command interpreter running with a PaperCut process as its parent across Windows, Linux, or macOS. This strongly suggests remote code execution.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "agent-triage-early",
      "type": "analytic",
      "label": "Triage initial access and execution",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "web"
        ],
        "context": [
          "tapestry-auth-bypass-requests",
          "papercut-shell-execution"
        ],
        "objective": "Determine if any host shows both the authentication bypass HTTP requests and subsequent shell execution from the PaperCut process.",
        "description": "Correlate HTTP bypass attempts with follow-on shell execution on the same server.",
        "max_iterations": 3,
        "expected_signal": "A per-host verdict on whether the initial exploit phase has succeeded.",
        "success_criteria": "A list of hosts with confirmed shell execution following HTTP bypass attempts."
      },
      "parents": [
        {
          "id": "tapestry-auth-bypass-requests",
          "kind": "merge"
        },
        {
          "id": "papercut-shell-execution",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "papercut-log-tampering",
      "type": "query",
      "label": "Detect PaperCut server log tampering",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, file_name, file_path, activity_name, time FROM hb_file_activity WHERE LOWER(file_name) = 'server.log' AND activity_id IN (3, 4) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_file_activity",
        "description": "Identify when the server.log is updated or deleted, indicating defense evasion.",
        "expected_signal": "An update or deletion of server.log. Silence may mean no tampering occurred, or the agent missed the event before the file was removed."
      },
      "parents": [
        {
          "id": "agent-triage-early"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Detect PaperCut server log tampering",
        "reads": [
          "device_hostname",
          "process_name",
          "file_name",
          "file_path",
          "activity_name",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, file_name, file_path, activity_name, time FROM hb_file_activity WHERE LOWER(file_name) = 'server.log' AND activity_id IN (3, 4) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "An update or deletion of server.log. Silence may mean no tampering occurred, or the agent missed the event before the file was removed.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "ransomware-file-impact",
      "type": "query",
      "label": "Detect high-volume file activity by PaperCut",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, COUNT(DISTINCT file_path) AS affected_files, MIN(time) AS first_seen FROM hb_file_activity WHERE (LOWER(process_name) LIKE '%pc-app%' OR LOWER(parent_process_name) LIKE '%pc-app%') AND activity_id IN (1, 3, 5) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name HAVING affected_files > 100",
        "surface": "hb_file_activity",
        "description": "Find signs of mass file encryption or modification initiated by PaperCut processes or their children to determine the final stage of the attack.",
        "expected_signal": "A PaperCut process modifying more than 100 distinct files on a single host. This is a behavioral outlier for a print server."
      },
      "parents": [
        {
          "id": "agent-triage-early"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Detect high-volume file activity by PaperCut",
        "reads": [
          "device_hostname",
          "process_name",
          "file_path",
          "activity_id",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, COUNT(DISTINCT file_path) AS affected_files, MIN(time) AS first_seen FROM hb_file_activity WHERE (LOWER(process_name) LIKE '%pc-app%' OR LOWER(parent_process_name) LIKE '%pc-app%') AND activity_id IN (1, 3, 5) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name HAVING affected_files > 100",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A PaperCut process modifying more than 100 distinct files on a single host. This is a behavioral outlier for a print server.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_name"
          ],
          "rare_below": 2
        },
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "agent-triage-follow-on",
      "type": "analytic",
      "label": "Triage breach impact",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "web"
        ],
        "context": [
          "agent-triage-early",
          "papercut-log-tampering",
          "ransomware-file-impact"
        ],
        "objective": "Analyze the full attack chain from initial HTTP bypass to process execution and the final file-system impact, using the context from the earlier triage step.",
        "description": "Correlate the initial access verdict with evidence of subsequent log tampering and data impact.",
        "max_iterations": 4,
        "expected_signal": "A final verdict on whether the host has been compromised and whether encryption has occurred.",
        "success_criteria": "A detailed per-host report citing the specific URIs, spawned shells, and the follow-on file impact."
      },
      "parents": [
        {
          "id": "papercut-log-tampering",
          "kind": "merge"
        },
        {
          "id": "ransomware-file-impact",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-impact",
      "type": "checkpoint",
      "label": "Route on impact verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "The agent-triage-follow-on verdict confirms a complete attack chain from initial HTTP bypass to process execution and subsequent file-system impact.",
        "condition": "The agent-triage-follow-on verdict confirms a complete attack chain from initial HTTP bypass to process execution and subsequent file-system impact.",
        "blind_spot": "http-tls-visibility",
        "confidence": "high",
        "description": "Decide whether to isolate the host based on the confirmed attack chain.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "agent-triage-follow-on"
        }
      ]
    },
    {
      "id": "isolate-compromised-server",
      "type": "action",
      "label": "Isolate compromised server",
      "config": {
        "target": "endpoint",
        "description": "Halt active ransomware encryption and prevent lateral movement.",
        "instructions": "Isolate the compromised PaperCut server from the network immediately using the EDR containment action.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-impact",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-forensic-review",
      "type": "task",
      "label": "Analyst forensic review",
      "config": {
        "assignee": "analyst",
        "description": "Analyze the extent of the damage and confirm the malicious SQL and JS components used.",
        "instructions": "Review the shell commands spawned by the PaperCut process and identify any malicious JDBC URLs configured in the application. Document the impact of the mass file modifications."
      },
      "parents": [
        {
          "id": "route-on-impact",
          "branch": "default"
        },
        {
          "id": "route-on-impact",
          "branch": "on_unavailable"
        },
        {
          "id": "route-on-impact",
          "branch": "on_refutes"
        },
        {
          "id": "isolate-compromised-server"
        }
      ]
    },
    {
      "id": "patch-and-remediate",
      "type": "task",
      "label": "Patch and remediate",
      "config": {
        "assignee": "analyst",
        "description": "Restore the server and apply the final vendor patch to prevent re-exploitation.",
        "instructions": "Apply the third emergency patch version released by PaperCut and restrict the administrative interface to known internal IP ranges only."
      },
      "parents": [
        {
          "id": "analyst-forensic-review"
        }
      ]
    }
  ]
}