← All hunts high TLP:CLEAR Part 1 of 2

Perimeter Exploitation and Evasive VPN Persistence

An adversary exploits vulnerable web services to execute masqueraded payloads and establishes persistence through a renamed VPN client with a unique hash communicating with Integrity Tech infrastructure.

Based on research by CISA 2026-10-09 12 steps · 5 queries T1036.003 T1059.001 T1059.006 T1071 T1133 T1190

Brief

Why this hunt matters

CISA recently released advisory AA26-281A (https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a) detailing the activities of the Integrity Technology Group. This actor group combines automated vulnerability scanning with manual exploitation to compromise sensitive environments. Our new hunt targets the specific lifecycle of these intrusions, focusing on how they move from an initial web shell or vulnerability exploit to a long-term foothold using masqueraded VPN software.

How the Hunt Flows

The hunt begins with a scoping phase using the hb_vulnerability_finding surface. We identify every host in the environment that is susceptible to the specific CVEs cited in the advisory, such as those affecting Jenkins, WordPress, and Microsoft Exchange. This narrows our search area to the most likely entry points and critical perimeter assets. Next, the hunt pivots to hb_http_activity to find evidence of exploitation. We search for rare URL paths and specific scanner user-agents that indicate an adversary is probing for configuration files or directory structures. This phase uses frequency analysis to find outliers across the environment that suggest automated discovery efforts or successful web shell interaction. Simultaneously, we search for the execution of masqueraded payloads via hb_process_activity. The adversary often uses the name DiagTrack.exe to hide their presence and avoid detection by simple process name rules. We look for this process name running from non-standard directories or executing as a fileless process, which provides a high-confidence signal of malicious activity following an exploit. Once a foothold is established, the adversary installs persistence. This hunt uses a hash rarity check on the hb_process_activity surface to find renamed VPN binaries used for long-term access. By looking for processes named conhost.exe or dllhost.exe that have hashes seen on fewer than three hosts, we identify the SoftEther VPN client masquerading as a native Windows process. Finally, we correlate this host behavior with hb_dns_activity. We check for resolutions of known command-and-control domains attributed to the actor group, while filtering out common browser traffic from Chrome and Edge to reduce false positives. This multi-stage correlation allows an analyst to confirm a full intrusion chain from entry to exfiltration.

What This Hunt Cannot See

This hunt has two primary blind spots. First, it relies on HTTP activity logs for the initial vector. If a web server is compromised but does not have telemetry enabled, we see the subsequent payload execution but lack visibility into the initial exploitation vector. Second, once the SoftEther VPN tunnel is established, we cannot see the activity occurring inside that encrypted channel. Data exfiltration or lateral movement performed within the tunnel remains invisible to standard network sensors.

In this series

Steps

  1. Identify vulnerable perimeter hosts

    Query · scoping

    Scope the hunt to assets with known vulnerabilities in Jenkins, WordPress, or Exchange mentioned in the advisory.

    reads hb_vulnerability_findingsql
    SELECT device_uid, cve_uid, affected_package_name, severity FROM hb_vulnerability_finding WHERE instr(',' || '{{target_cves}}' || ',', ',' || cve_uid || ',') > 0

    What a hit looks like. A list of device_uids and the specific CVEs they are vulnerable to. Silence means no known vulnerable software is exposed.

  2. Search for web exploitation probes

    Query · baseline

    Find rare url_path values or access to administrative configuration files from external IPs.

    reads hb_http_activitysql
    SELECT src_endpoint_ip, url_path, user_agent, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_http_activity WHERE (LOWER(url_path) LIKE '%config.php' OR LOWER(url_path) LIKE '%web.config' OR LOWER(user_agent) LIKE '%dirsearch%' OR LOWER(user_agent) LIKE '%fscan%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY src_endpoint_ip, url_path, user_agent HAVING host_count < 3 ORDER BY host_count ASC

    What a hit looks like. Rarely accessed configuration files or specific scanner user-agents. Silence suggests no automated probing matched these signatures.

  3. Detect masqueraded payload execution

    Query · detection candidate

    Find execution of DiagTrack.exe that is either fileless (injected) or running from a non-standard path.

    reads hb_process_activitysql
    SELECT device_hostname, process_name, process_path, parent_process_name, on_disk, time FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%\\diagtrack.exe' AND (on_disk = 0 OR LOWER(process_path) NOT LIKE 'c:\\windows\\system32\\%')) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. DiagTrack.exe running from outside System32 or with on_disk=0 is a high-confidence indicator of masquerading. Silence proves absence on monitored hosts.

  4. Assess early breach indicators

    Agent triage

    Establish if the web probes and process executions represent a successful initial access and payload delivery.

  5. Identify VPN binary masquerading

    Query · baseline

    Find renamed VPN binaries (conhost.exe, dllhost.exe) by searching for rare hashes that differ from the native Windows files.

    reads hb_process_activitysql
    SELECT process_hash_sha256, process_name, process_cmd_line, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%\\conhost.exe' OR LOWER(process_name) LIKE '%\\dllhost.exe') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_hash_sha256, process_name, process_cmd_line HAVING hosts < 3 ORDER BY hosts ASC

    What a hit looks like. A rare hash for conhost.exe or dllhost.exe. Native Windows binaries will have a very high host count; a renamed SoftEther client will be rare.

  6. Detect C2 infrastructure traffic

    Query · triage

    Match DNS requests against infrastructure domains attributed to Integrity Technology Group, excluding benign browser noise.

    reads hb_dns_activitysql
    SELECT device_hostname, process_name, query_hostname, time FROM hb_dns_activity WHERE instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND LOWER(process_name) NOT LIKE '%chrome.exe' AND LOWER(process_name) NOT LIKE '%msedge.exe' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. DNS resolutions for the specified domains from non-browser processes. Silence proves absence only for these specific IOCs.

  7. Evaluate full intrusion chain

    Agent triage

    Combine the early access evidence with persistence and C2 signals to provide a definitive intrusion verdict.

  8. Route on verdict

    Decision

    Direct the hunt towards containment or review based on the triage result.

  9. Isolate host

    Response action

    Contain the threat actor and prevent data exfiltration.

  10. Analyst review

    Analyst task

    Review findings and confirm intrusion lifecycle.

  11. Close out hunt

    Analyst task

    Document findings and update defensive posture.

Coverage

Scenario coverage

StageCoveredHow, or why not
Web and Service Exploitation
T1190 · T1189
Yes affected-vulnerable-hosts, web-exploitation-probes
Malware Execution
T1059.006 · T1059.007 · T1059.001
Yes masqueraded-initial-payload
VPN-based Persistence
T1133
Yes vpn-masquerading-persistence
Service and Process Masquerading
T1036.003
Yes masqueraded-initial-payload, vpn-masquerading-persistence
Multi-protocol Command and Control
T1071
Yes c2-infrastructure-traffic
EBurst Password Spraying
T1110.003 · T1110.001
Out of scope Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series.
Email Data Collection
T1041
Out of scope Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series.

Blind spots

  • Needs hb_http_activity on all perimeter servers. A compromised server without HTTP logging will show payload execution but not the entry vector. It would answer whether exploitation attempts occurred on unmonitored web servers.
  • Needs Decrypted network inspection or process-to-network correlation. Once the VPN tunnel is established, exfiltration within that tunnel is invisible to standard network sensors. It would answer what activity occurs inside the SoftEther VPN tunnel.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
c2_domainslist[domain]dns.studiocloud.xyz, 98aiblog.com, hmbcloud.com, hmbcloud.net, hmbiplc-01.com, iepl.node.cm, javacheck.ooguy.com, javaupdate.giize.com, sexytube0.com, twimg.co.ukInfrastructure domains associated with Integrity Technology Group.
lookback_daysnumber14Days of history to examine.
scope_hostslist[host]—Hostnames to narrow the search; leave empty to hunt across the entire estate.
target_cveslist[string]CVE-2014-6278, CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2019-11510, CVE-2021-22205, CVE-2021-3199, CVE-2023-22894Vulnerabilities frequently targeted by this actor group.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint
Web server / proxy logssiemnetwork

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: This hunt uses a phased approach to correlate vulnerability presence, masqueraded
  execution, and persistent C2. It specifically hunts for rare source IPs and 'Living-off-the-Land'
  masquerading behavior using hash rarity that would be missed by single-surface rules.
blind_spots:
- id: incomplete-telemetry
  question: whether exploitation attempts occurred on unmonitored web servers
  requires: hb_http_activity on all perimeter servers
  risk: A compromised server without HTTP logging will show payload execution but
    not the entry vector.
  stage: initial-access-vulnerability-exploitation
- id: obfuscated-vpn-traffic
  question: what activity occurs inside the SoftEther VPN tunnel
  requires: Decrypted network inspection or process-to-network correlation
  risk: Once the VPN tunnel is established, exfiltration within that tunnel is invisible
    to standard network sensors.
  stage: command-and-control-obfuscated-channels
coverage:
- stage: initial-access-vulnerability-exploitation
  status: covered
  steps:
  - affected-vulnerable-hosts
  - web-exploitation-probes
- stage: execution-malware-payload
  status: covered
  steps:
  - masqueraded-initial-payload
- stage: persistence-vpn-installation
  status: covered
  steps:
  - vpn-masquerading-persistence
- stage: defence-evasion-masquerading
  status: covered
  steps:
  - masqueraded-initial-payload
  - vpn-masquerading-persistence
- stage: command-and-control-obfuscated-channels
  status: covered
  steps:
  - c2-infrastructure-traffic
- reason: Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors
    Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series.
  stage: credential-access-eburst-spraying
  status: out_of_scope
- reason: Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors
    Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series.
  stage: collection-mailbox-exfiltration
  status: out_of_scope
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: promote-to-detection
  justification: Integrity Technology Group is targeting critical infrastructure using
    a blend of automated scanning and manual exploitation. Identifying the transition
    from perimeter probe to persistent VPN foothold is critical for preventing data
    exfiltration.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An adversary exploits vulnerable web services to execute masqueraded payloads
  and establishes persistence through a renamed VPN client with a unique hash communicating
  with Integrity Tech infrastructure.
labels:
- hunt
- attack.t1190
- attack.t1059.001
- attack.t1059.006
- attack.t1133
- attack.t1036.003
- attack.t1071
- collection
- command and control
- credential access
- defense evasion
- execution
- initial access
- persistence
name: Perimeter Exploitation and Evasive VPN Persistence
parameters:
  c2_domains:
    default:
    - dns.studiocloud.xyz
    - 98aiblog.com
    - hmbcloud.com
    - hmbcloud.net
    - hmbiplc-01.com
    - iepl.node.cm
    - javacheck.ooguy.com
    - javaupdate.giize.com
    - sexytube0.com
    - twimg.co.uk
    description: Infrastructure domains associated with Integrity Technology Group.
    from:
      kind: article
      observed: '2026-10-08'
      ref: AA26-281A
    type: list[domain]
  lookback_days:
    default: '14'
    description: Days of history to examine.
    type: number
  scope_hosts:
    default: []
    description: Hostnames to narrow the search; leave empty to hunt across the entire
      estate.
    type: list[host]
  target_cves:
    default:
    - CVE-2014-6278
    - CVE-2015-3306
    - CVE-2015-5477
    - CVE-2016-3081
    - CVE-2019-11510
    - CVE-2021-22205
    - CVE-2021-3199
    - CVE-2023-22894
    description: Vulnerabilities frequently targeted by this actor group.
    from:
      kind: article
      observed: '2026-10-08'
      ref: AA26-281A
    type: list[string]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Begin with hosts identified as vulnerable in the scoping step. If no vulnerable
  hosts are returned, run the hunt across the entire estate to detect potential use
  of 0-day exploits or scanner blind spots.
references:
- name: 'CISA AA26-281A: Chinese Government-linked Cyber Threat Actors'
  url: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a
related:
- hunt: password-spraying-eburst-analysis
  reason: This hunt focuses on vulnerability exploitation; EBurst password spraying
    belongs to an identity-centric hunt.
  relation: out-of-scope-alternative
scenario:
  stages:
  - name: Web and Service Exploitation
    observables:
    - BBScan
    - dirsearch
    - Fscan
    - ksubdomain
    - masscan
    - NMAP
    - OneForAll
    - ShuiZe
    - wpscan
    - MicroScan
    - XSS payloads targeting JavaScript
    - Exploits for CVE-2016-3081
    - Exploits for CVE-2019-11510
    - Exploits for CVE-2021-22205
    - Targeting ports 21, 22, 53, 80, 443, 1080
    - PHP/ASP enumeration
    slug: initial-access-vulnerability-exploitation
    tactic: initial-access
    techniques:
    - T1190
    - T1189
  - name: Malware Execution
    observables:
    - live700_v1.exe
    - DiagTrack.exe
    - Python-based exploit scripts
    - Go-based exploit utilities
    - Password-protected .zip files containing executables
    slug: execution-malware-payload
    tactic: execution
    techniques:
    - T1059.006
    - T1059.007
    - T1059.001
  - name: VPN-based Persistence
    observables:
    - SoftEther VPN installers
    - conhost.exe (renamed installer)
    - dllhost.exe (renamed installer)
    - curl or wget used to download SoftEther on Linux
    - PowerShell used to download SoftEther on Windows
    - Automatic reconnection configuration on startup
    slug: persistence-vpn-installation
    tactic: persistence
    techniques:
    - T1133
  - name: Service and Process Masquerading
    observables:
    - DiagTrack.exe
    - conhost.exe
    - dllhost.exe
    slug: defence-evasion-masquerading
    tactic: defence-evasion
    techniques:
    - T1036.003
  - name: EBurst Password Spraying
    observables:
    - EBurst tool
    - Password spraying against ECP
    - Password spraying against EWS
    - Password spraying against OWA
    - Password spraying against ActiveSync
    - Password spraying against MAPI/RPC
    slug: credential-access-eburst-spraying
    tactic: credential-access
    techniques:
    - T1110.003
    - T1110.001
  - name: Multi-protocol Command and Control
    observables:
    - dns.studiocloud.xyz
    - 98aiblog.com
    - hmbcloud.com
    - hmbcloud.net
    - hmbiplc-01.com
    - iepl.node.cm
    - javacheck.ooguy.com
    - javaupdate.giize.com
    - sexytube0.com
    - twimg.co.uk
    - HTTP-based C2 communications
    slug: command-and-control-obfuscated-channels
    tactic: command-and-control
    techniques:
    - T1071
  - name: Email Data Collection
    observables:
    - Querying user mailbox data via DiagTrack.exe
    slug: collection-mailbox-exfiltration
    tactic: collection
    techniques:
    - T1041
  summary: Chinese government-linked threat actors, enabled by Integrity Technology
    Group, use a combination of automated scanning tools like MicroScan and manual
    exploitation to target global organizations. They establish persistence using
    legitimate VPN software like SoftEther and perform large-scale password spraying
    with EBurst to exfiltrate sensitive email data and credentials.
series:
  index: 1
  slug: chinese-government-linked-cyber-threat-actors-combine-automated-and-hands-on-hacking-tools-to-st
  title: Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on
    Hacking Tools to Steal Sensitive Data
  total: 2
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  web:
    category: siem
    name: Web server / proxy logs
    telemetry:
    - network
tlp: clear
type: investigation
---


# Perimeter Exploitation and Evasive VPN Persistence

This hunt targets the phased intrusion tactics of Integrity Technology Group. It begins by identifying vulnerable perimeter assets and looking for rare web exploitation probes or masqueraded payloads like DiagTrack.exe. The hunt then pivots to find evidence of persistence via VPN software (SoftEther) that has been renamed to masquerade as native Windows processes, identifying these by their rare hashes. Finally, it correlates this behavior with network traffic to known malicious infrastructure while excluding benign browser noise.

## affected-vulnerable-hosts
<!-- Identify vulnerable perimeter hosts -->
Scope the hunt to assets with known vulnerabilities in Jenkins, WordPress, or Exchange mentioned in the advisory.

```sqlite target=endpoint role=scoping params=(target_cves=target_cves)
~~~yaml
expected: A list of device_uids and the specific CVEs they are vulnerable to. Silence
  means no known vulnerable software is exposed.
reads:
- affected_package_name
- cve_uid
- device_uid
- severity
silence: not_evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT device_uid, cve_uid, affected_package_name, severity FROM hb_vulnerability_finding WHERE instr(',' || '{{target_cves}}' || ',', ',' || cve_uid || ',') > 0
```

## early-indicators
<!-- Hunt for early breach indicators -->
parallel:
- → web-exploitation-probes
- → masqueraded-initial-payload
join: → early-stage-triage

## web-exploitation-probes
<!-- Search for web exploitation probes -->
Find rare url_path values or access to administrative configuration files from external IPs.

```sqlite target=web role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: Rarely accessed configuration files or specific scanner user-agents. Silence
  suggests no automated probing matched these signatures.
prevalence:
  by: device_hostname
  key:
  - url_path
  rare_below: 3
reads:
- device_hostname
- src_endpoint_ip
- time
- url_path
- user_agent
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT src_endpoint_ip, url_path, user_agent, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_http_activity WHERE (LOWER(url_path) LIKE '%config.php' OR LOWER(url_path) LIKE '%web.config' OR LOWER(user_agent) LIKE '%dirsearch%' OR LOWER(user_agent) LIKE '%fscan%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY src_endpoint_ip, url_path, user_agent HAVING host_count < 3 ORDER BY host_count ASC
```

## masqueraded-initial-payload
<!-- Detect masqueraded payload execution -->
Find execution of DiagTrack.exe that is either fileless (injected) or running from a non-standard path.

```sqlite target=endpoint role=detection-candidate params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: DiagTrack.exe running from outside System32 or with on_disk=0 is a high-confidence
  indicator of masquerading. Silence proves absence on monitored hosts.
reads:
- device_hostname
- on_disk
- parent_process_name
- process_name
- process_path
- time
silence: evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT device_hostname, process_name, process_path, parent_process_name, on_disk, time FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%\\diagtrack.exe' AND (on_disk = 0 OR LOWER(process_path) NOT LIKE 'c:\\windows\\system32\\%')) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## early-stage-triage
<!-- Assess early breach indicators -->
```agent target=hunter
cite: required
context:
- affected-vulnerable-hosts
- web-exploitation-probes
- masqueraded-initial-payload
max_iterations: 4
objective: Determine if any host showing suspicious HTTP traffic also executed a masqueraded
  binary within a tight time window.
success_criteria: A verdict of malicious | suspicious | benign citing specific rows.
tools:
- endpoint
- web
```

## follow-on-indicators
<!-- Hunt for persistence and C2 -->
parallel:
- → vpn-masquerading-persistence
- → c2-infrastructure-traffic
join: → full-intrusion-triage

## vpn-masquerading-persistence
<!-- Identify VPN binary masquerading -->
Find renamed VPN binaries (conhost.exe, dllhost.exe) by searching for rare hashes that differ from the native Windows files.

```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: A rare hash for conhost.exe or dllhost.exe. Native Windows binaries will
  have a very high host count; a renamed SoftEther client will be rare.
prevalence:
  by: device_hostname
  key:
  - process_hash_sha256
  rare_below: 3
reads:
- device_hostname
- process_cmd_line
- process_hash_sha256
- process_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT process_hash_sha256, process_name, process_cmd_line, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%\\conhost.exe' OR LOWER(process_name) LIKE '%\\dllhost.exe') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_hash_sha256, process_name, process_cmd_line HAVING hosts < 3 ORDER BY hosts ASC
```

## c2-infrastructure-traffic
<!-- Detect C2 infrastructure traffic -->
Match DNS requests against infrastructure domains attributed to Integrity Technology Group, excluding benign browser noise.

```sqlite target=endpoint role=triage params=(lookback_days=lookback_days, c2_domains=c2_domains, scope_hosts=scope_hosts)
~~~yaml
expected: DNS resolutions for the specified domains from non-browser processes. Silence
  proves absence only for these specific IOCs.
reads:
- device_hostname
- process_name
- query_hostname
- time
silence: not_evidence_of_absence
source: hb_dns_activity
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT device_hostname, process_name, query_hostname, time FROM hb_dns_activity WHERE instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND LOWER(process_name) NOT LIKE '%chrome.exe' AND LOWER(process_name) NOT LIKE '%msedge.exe' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## full-intrusion-triage
<!-- Evaluate full intrusion chain -->
```agent target=hunter
cite: required
context:
- early-stage-triage
- vpn-masquerading-persistence
- c2-infrastructure-traffic
max_iterations: 6
objective: Establish if the suspicious binary execution or VPN persistence is linked
  to the identified C2 domains or exploitation probes across the Phased flow.
success_criteria: A final verdict citing the linkage between initial execution and
  persistent C2 behavior.
tools:
- endpoint
- web
```

## route-on-verdict
<!-- Route on verdict -->
if~: "the full-intrusion-triage verdict is malicious for at least one host" (confidence: high, judge=hunter)
then: → isolate-host
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: incomplete-telemetry)
else: → analyst-review

## isolate-host
<!-- Isolate host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host from the network and collect the masqueraded binaries for forensic analysis.
```
→ analyst-review

## analyst-review
<!-- Analyst review -->
```manual target=analyst
Review the rows cited by the agents. Verify the rarity of the URL paths and process hashes. Confirm if the 'diagtrack.exe' instances were indeed masqueraded or legitimate telemetry service activity.
```
→ close-out

## close-out
<!-- Close out hunt -->
```manual target=analyst
Summarize the hunt results. If renamed binaries like DiagTrack.exe or rare conhost.exe hashes were confirmed, promote the detection-candidate query to a standing rule and update the local blocklist with the identified SHA256 hashes.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.