Perimeter Exploitation and Evasive VPN Persistence
An adversary exploits vulnerable web services to execute masqueraded payloads and establishes persistence through a renamed VPN client with a unique hash communicating with Integrity Tech infrastructure.
Based on research by CISA 2026-10-09 12 steps · 5 queries T1036.003 T1059.001 T1059.006 T1071 T1133 T1190
Brief
Why this hunt matters
CISA recently released advisory AA26-281A (https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a) detailing the activities of the Integrity Technology Group. This actor group combines automated vulnerability scanning with manual exploitation to compromise sensitive environments. Our new hunt targets the specific lifecycle of these intrusions, focusing on how they move from an initial web shell or vulnerability exploit to a long-term foothold using masqueraded VPN software.
How the Hunt Flows
The hunt begins with a scoping phase using the hb_vulnerability_finding surface. We identify every host in the environment that is susceptible to the specific CVEs cited in the advisory, such as those affecting Jenkins, WordPress, and Microsoft Exchange. This narrows our search area to the most likely entry points and critical perimeter assets. Next, the hunt pivots to hb_http_activity to find evidence of exploitation. We search for rare URL paths and specific scanner user-agents that indicate an adversary is probing for configuration files or directory structures. This phase uses frequency analysis to find outliers across the environment that suggest automated discovery efforts or successful web shell interaction. Simultaneously, we search for the execution of masqueraded payloads via hb_process_activity. The adversary often uses the name DiagTrack.exe to hide their presence and avoid detection by simple process name rules. We look for this process name running from non-standard directories or executing as a fileless process, which provides a high-confidence signal of malicious activity following an exploit. Once a foothold is established, the adversary installs persistence. This hunt uses a hash rarity check on the hb_process_activity surface to find renamed VPN binaries used for long-term access. By looking for processes named conhost.exe or dllhost.exe that have hashes seen on fewer than three hosts, we identify the SoftEther VPN client masquerading as a native Windows process. Finally, we correlate this host behavior with hb_dns_activity. We check for resolutions of known command-and-control domains attributed to the actor group, while filtering out common browser traffic from Chrome and Edge to reduce false positives. This multi-stage correlation allows an analyst to confirm a full intrusion chain from entry to exfiltration.
What This Hunt Cannot See
This hunt has two primary blind spots. First, it relies on HTTP activity logs for the initial vector. If a web server is compromised but does not have telemetry enabled, we see the subsequent payload execution but lack visibility into the initial exploitation vector. Second, once the SoftEther VPN tunnel is established, we cannot see the activity occurring inside that encrypted channel. Data exfiltration or lateral movement performed within the tunnel remains invisible to standard network sensors.
In this series
Steps
-
Identify vulnerable perimeter hosts
Query · scopingScope the hunt to assets with known vulnerabilities in Jenkins, WordPress, or Exchange mentioned in the advisory.
reads hb_vulnerability_findingsqlSELECT device_uid, cve_uid, affected_package_name, severity FROM hb_vulnerability_finding WHERE instr(',' || '{{target_cves}}' || ',', ',' || cve_uid || ',') > 0What a hit looks like. A list of device_uids and the specific CVEs they are vulnerable to. Silence means no known vulnerable software is exposed.
-
Search for web exploitation probes
Query · baselineFind rare url_path values or access to administrative configuration files from external IPs.
reads hb_http_activitysqlSELECT src_endpoint_ip, url_path, user_agent, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_http_activity WHERE (LOWER(url_path) LIKE '%config.php' OR LOWER(url_path) LIKE '%web.config' OR LOWER(user_agent) LIKE '%dirsearch%' OR LOWER(user_agent) LIKE '%fscan%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY src_endpoint_ip, url_path, user_agent HAVING host_count < 3 ORDER BY host_count ASCWhat a hit looks like. Rarely accessed configuration files or specific scanner user-agents. Silence suggests no automated probing matched these signatures.
-
Detect masqueraded payload execution
Query · detection candidateFind execution of DiagTrack.exe that is either fileless (injected) or running from a non-standard path.
reads hb_process_activitysqlSELECT device_hostname, process_name, process_path, parent_process_name, on_disk, time FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%\\diagtrack.exe' AND (on_disk = 0 OR LOWER(process_path) NOT LIKE 'c:\\windows\\system32\\%')) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. DiagTrack.exe running from outside System32 or with on_disk=0 is a high-confidence indicator of masquerading. Silence proves absence on monitored hosts.
-
Assess early breach indicators
Agent triageEstablish if the web probes and process executions represent a successful initial access and payload delivery.
-
Identify VPN binary masquerading
Query · baselineFind renamed VPN binaries (conhost.exe, dllhost.exe) by searching for rare hashes that differ from the native Windows files.
reads hb_process_activitysqlSELECT process_hash_sha256, process_name, process_cmd_line, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%\\conhost.exe' OR LOWER(process_name) LIKE '%\\dllhost.exe') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_hash_sha256, process_name, process_cmd_line HAVING hosts < 3 ORDER BY hosts ASCWhat a hit looks like. A rare hash for conhost.exe or dllhost.exe. Native Windows binaries will have a very high host count; a renamed SoftEther client will be rare.
-
Detect C2 infrastructure traffic
Query · triageMatch DNS requests against infrastructure domains attributed to Integrity Technology Group, excluding benign browser noise.
reads hb_dns_activitysqlSELECT device_hostname, process_name, query_hostname, time FROM hb_dns_activity WHERE instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND LOWER(process_name) NOT LIKE '%chrome.exe' AND LOWER(process_name) NOT LIKE '%msedge.exe' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. DNS resolutions for the specified domains from non-browser processes. Silence proves absence only for these specific IOCs.
-
Evaluate full intrusion chain
Agent triageCombine the early access evidence with persistence and C2 signals to provide a definitive intrusion verdict.
-
Route on verdict
DecisionDirect the hunt towards containment or review based on the triage result.
-
Isolate host
Response actionContain the threat actor and prevent data exfiltration.
-
Analyst review
Analyst taskReview findings and confirm intrusion lifecycle.
-
Close out hunt
Analyst taskDocument findings and update defensive posture.
Coverage
Scenario coverage
| Stage | Covered | How, or why not |
|---|---|---|
| Web and Service Exploitation T1190 · T1189 |
Yes | affected-vulnerable-hosts, web-exploitation-probes |
| Malware Execution T1059.006 · T1059.007 · T1059.001 |
Yes | masqueraded-initial-payload |
| VPN-based Persistence T1133 |
Yes | vpn-masquerading-persistence |
| Service and Process Masquerading T1036.003 |
Yes | masqueraded-initial-payload, vpn-masquerading-persistence |
| Multi-protocol Command and Control T1071 |
Yes | c2-infrastructure-traffic |
| EBurst Password Spraying T1110.003 · T1110.001 |
Out of scope | Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series. |
| Email Data Collection T1041 |
Out of scope | Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series. |
Blind spots
- Needs hb_http_activity on all perimeter servers. A compromised server without HTTP logging will show payload execution but not the entry vector. It would answer whether exploitation attempts occurred on unmonitored web servers.
- Needs Decrypted network inspection or process-to-network correlation. Once the VPN tunnel is established, exfiltration within that tunnel is invisible to standard network sensors. It would answer what activity occurs inside the SoftEther VPN tunnel.
Parameters & data
Parameters
| Parameter | Type | Default | What it is |
|---|---|---|---|
c2_domains | list[domain] | dns.studiocloud.xyz, 98aiblog.com, hmbcloud.com, hmbcloud.net, hmbiplc-01.com, iepl.node.cm, javacheck.ooguy.com, javaupdate.giize.com, sexytube0.com, twimg.co.uk | Infrastructure domains associated with Integrity Technology Group. |
lookback_days | number | 14 | Days of history to examine. |
scope_hosts | list[host] | — | Hostnames to narrow the search; leave empty to hunt across the entire estate. |
target_cves | list[string] | CVE-2014-6278, CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2019-11510, CVE-2021-22205, CVE-2021-3199, CVE-2023-22894 | Vulnerabilities frequently targeted by this actor group. |
Telemetry
| Source | Category | Telemetry |
|---|---|---|
| Endpoint telemetry (hb_ surfaces) | endpoint | endpoint |
| Web server / proxy logs | siem | network |
Source
---
analysis: This hunt uses a phased approach to correlate vulnerability presence, masqueraded
execution, and persistent C2. It specifically hunts for rare source IPs and 'Living-off-the-Land'
masquerading behavior using hash rarity that would be missed by single-surface rules.
blind_spots:
- id: incomplete-telemetry
question: whether exploitation attempts occurred on unmonitored web servers
requires: hb_http_activity on all perimeter servers
risk: A compromised server without HTTP logging will show payload execution but
not the entry vector.
stage: initial-access-vulnerability-exploitation
- id: obfuscated-vpn-traffic
question: what activity occurs inside the SoftEther VPN tunnel
requires: Decrypted network inspection or process-to-network correlation
risk: Once the VPN tunnel is established, exfiltration within that tunnel is invisible
to standard network sensors.
stage: command-and-control-obfuscated-channels
coverage:
- stage: initial-access-vulnerability-exploitation
status: covered
steps:
- affected-vulnerable-hosts
- web-exploitation-probes
- stage: execution-malware-payload
status: covered
steps:
- masqueraded-initial-payload
- stage: persistence-vpn-installation
status: covered
steps:
- vpn-masquerading-persistence
- stage: defence-evasion-masquerading
status: covered
steps:
- masqueraded-initial-payload
- vpn-masquerading-persistence
- stage: command-and-control-obfuscated-channels
status: covered
steps:
- c2-infrastructure-traffic
- reason: Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors
Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series.
stage: credential-access-eburst-spraying
status: out_of_scope
- reason: Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors
Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series.
stage: collection-mailbox-exfiltration
status: out_of_scope
guardrails:
claims: no_unsupported
evidence: citation_required
missing_data: not_benign
telemetry: untrusted
hunt:
applicability: campaign-specific
handoff: promote-to-detection
justification: Integrity Technology Group is targeting critical infrastructure using
a blend of automated scanning and manual exploitation. Identifying the transition
from perimeter probe to persistent VPN foothold is critical for preventing data
exfiltration.
methodology: model-assisted
trigger: intel-report
hypothesis: An adversary exploits vulnerable web services to execute masqueraded payloads
and establishes persistence through a renamed VPN client with a unique hash communicating
with Integrity Tech infrastructure.
labels:
- hunt
- attack.t1190
- attack.t1059.001
- attack.t1059.006
- attack.t1133
- attack.t1036.003
- attack.t1071
- collection
- command and control
- credential access
- defense evasion
- execution
- initial access
- persistence
name: Perimeter Exploitation and Evasive VPN Persistence
parameters:
c2_domains:
default:
- dns.studiocloud.xyz
- 98aiblog.com
- hmbcloud.com
- hmbcloud.net
- hmbiplc-01.com
- iepl.node.cm
- javacheck.ooguy.com
- javaupdate.giize.com
- sexytube0.com
- twimg.co.uk
description: Infrastructure domains associated with Integrity Technology Group.
from:
kind: article
observed: '2026-10-08'
ref: AA26-281A
type: list[domain]
lookback_days:
default: '14'
description: Days of history to examine.
type: number
scope_hosts:
default: []
description: Hostnames to narrow the search; leave empty to hunt across the entire
estate.
type: list[host]
target_cves:
default:
- CVE-2014-6278
- CVE-2015-3306
- CVE-2015-5477
- CVE-2016-3081
- CVE-2019-11510
- CVE-2021-22205
- CVE-2021-3199
- CVE-2023-22894
description: Vulnerabilities frequently targeted by this actor group.
from:
kind: article
observed: '2026-10-08'
ref: AA26-281A
type: list[string]
provenance:
authors:
- name: Huntbase hunt generation
org: huntbase.io
generated:
by: huntbase-hunt-generation
from: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a
gates:
- dry-run
- lint
model: hb_google/gemini-3-flash-preview
rationale: Begin with hosts identified as vulnerable in the scoping step. If no vulnerable
hosts are returned, run the hunt across the entire estate to detect potential use
of 0-day exploits or scanner blind spots.
references:
- name: 'CISA AA26-281A: Chinese Government-linked Cyber Threat Actors'
url: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a
related:
- hunt: password-spraying-eburst-analysis
reason: This hunt focuses on vulnerability exploitation; EBurst password spraying
belongs to an identity-centric hunt.
relation: out-of-scope-alternative
scenario:
stages:
- name: Web and Service Exploitation
observables:
- BBScan
- dirsearch
- Fscan
- ksubdomain
- masscan
- NMAP
- OneForAll
- ShuiZe
- wpscan
- MicroScan
- XSS payloads targeting JavaScript
- Exploits for CVE-2016-3081
- Exploits for CVE-2019-11510
- Exploits for CVE-2021-22205
- Targeting ports 21, 22, 53, 80, 443, 1080
- PHP/ASP enumeration
slug: initial-access-vulnerability-exploitation
tactic: initial-access
techniques:
- T1190
- T1189
- name: Malware Execution
observables:
- live700_v1.exe
- DiagTrack.exe
- Python-based exploit scripts
- Go-based exploit utilities
- Password-protected .zip files containing executables
slug: execution-malware-payload
tactic: execution
techniques:
- T1059.006
- T1059.007
- T1059.001
- name: VPN-based Persistence
observables:
- SoftEther VPN installers
- conhost.exe (renamed installer)
- dllhost.exe (renamed installer)
- curl or wget used to download SoftEther on Linux
- PowerShell used to download SoftEther on Windows
- Automatic reconnection configuration on startup
slug: persistence-vpn-installation
tactic: persistence
techniques:
- T1133
- name: Service and Process Masquerading
observables:
- DiagTrack.exe
- conhost.exe
- dllhost.exe
slug: defence-evasion-masquerading
tactic: defence-evasion
techniques:
- T1036.003
- name: EBurst Password Spraying
observables:
- EBurst tool
- Password spraying against ECP
- Password spraying against EWS
- Password spraying against OWA
- Password spraying against ActiveSync
- Password spraying against MAPI/RPC
slug: credential-access-eburst-spraying
tactic: credential-access
techniques:
- T1110.003
- T1110.001
- name: Multi-protocol Command and Control
observables:
- dns.studiocloud.xyz
- 98aiblog.com
- hmbcloud.com
- hmbcloud.net
- hmbiplc-01.com
- iepl.node.cm
- javacheck.ooguy.com
- javaupdate.giize.com
- sexytube0.com
- twimg.co.uk
- HTTP-based C2 communications
slug: command-and-control-obfuscated-channels
tactic: command-and-control
techniques:
- T1071
- name: Email Data Collection
observables:
- Querying user mailbox data via DiagTrack.exe
slug: collection-mailbox-exfiltration
tactic: collection
techniques:
- T1041
summary: Chinese government-linked threat actors, enabled by Integrity Technology
Group, use a combination of automated scanning tools like MicroScan and manual
exploitation to target global organizations. They establish persistence using
legitimate VPN software like SoftEther and perform large-scale password spraying
with EBurst to exfiltrate sensitive email data and credentials.
series:
index: 1
slug: chinese-government-linked-cyber-threat-actors-combine-automated-and-hands-on-hacking-tools-to-st
title: Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on
Hacking Tools to Steal Sensitive Data
total: 2
severity: high
targets:
analyst:
name: Tier-2 analyst
role: analyst
endpoint:
category: endpoint
name: Endpoint telemetry (hb_ surfaces)
telemetry:
- endpoint
hunter:
agent: true
name: Hunt agent
web:
category: siem
name: Web server / proxy logs
telemetry:
- network
tlp: clear
type: investigation
---
# Perimeter Exploitation and Evasive VPN Persistence
This hunt targets the phased intrusion tactics of Integrity Technology Group. It begins by identifying vulnerable perimeter assets and looking for rare web exploitation probes or masqueraded payloads like DiagTrack.exe. The hunt then pivots to find evidence of persistence via VPN software (SoftEther) that has been renamed to masquerade as native Windows processes, identifying these by their rare hashes. Finally, it correlates this behavior with network traffic to known malicious infrastructure while excluding benign browser noise.
## affected-vulnerable-hosts
<!-- Identify vulnerable perimeter hosts -->
Scope the hunt to assets with known vulnerabilities in Jenkins, WordPress, or Exchange mentioned in the advisory.
```sqlite target=endpoint role=scoping params=(target_cves=target_cves)
~~~yaml
expected: A list of device_uids and the specific CVEs they are vulnerable to. Silence
means no known vulnerable software is exposed.
reads:
- affected_package_name
- cve_uid
- device_uid
- severity
silence: not_evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT device_uid, cve_uid, affected_package_name, severity FROM hb_vulnerability_finding WHERE instr(',' || '{{target_cves}}' || ',', ',' || cve_uid || ',') > 0
```
## early-indicators
<!-- Hunt for early breach indicators -->
parallel:
- → web-exploitation-probes
- → masqueraded-initial-payload
join: → early-stage-triage
## web-exploitation-probes
<!-- Search for web exploitation probes -->
Find rare url_path values or access to administrative configuration files from external IPs.
```sqlite target=web role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
compare: first_seen
window: '{{lookback_days}}d'
expected: Rarely accessed configuration files or specific scanner user-agents. Silence
suggests no automated probing matched these signatures.
prevalence:
by: device_hostname
key:
- url_path
rare_below: 3
reads:
- device_hostname
- src_endpoint_ip
- time
- url_path
- user_agent
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT src_endpoint_ip, url_path, user_agent, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_http_activity WHERE (LOWER(url_path) LIKE '%config.php' OR LOWER(url_path) LIKE '%web.config' OR LOWER(user_agent) LIKE '%dirsearch%' OR LOWER(user_agent) LIKE '%fscan%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY src_endpoint_ip, url_path, user_agent HAVING host_count < 3 ORDER BY host_count ASC
```
## masqueraded-initial-payload
<!-- Detect masqueraded payload execution -->
Find execution of DiagTrack.exe that is either fileless (injected) or running from a non-standard path.
```sqlite target=endpoint role=detection-candidate params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: DiagTrack.exe running from outside System32 or with on_disk=0 is a high-confidence
indicator of masquerading. Silence proves absence on monitored hosts.
reads:
- device_hostname
- on_disk
- parent_process_name
- process_name
- process_path
- time
silence: evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT device_hostname, process_name, process_path, parent_process_name, on_disk, time FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%\\diagtrack.exe' AND (on_disk = 0 OR LOWER(process_path) NOT LIKE 'c:\\windows\\system32\\%')) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```
## early-stage-triage
<!-- Assess early breach indicators -->
```agent target=hunter
cite: required
context:
- affected-vulnerable-hosts
- web-exploitation-probes
- masqueraded-initial-payload
max_iterations: 4
objective: Determine if any host showing suspicious HTTP traffic also executed a masqueraded
binary within a tight time window.
success_criteria: A verdict of malicious | suspicious | benign citing specific rows.
tools:
- endpoint
- web
```
## follow-on-indicators
<!-- Hunt for persistence and C2 -->
parallel:
- → vpn-masquerading-persistence
- → c2-infrastructure-traffic
join: → full-intrusion-triage
## vpn-masquerading-persistence
<!-- Identify VPN binary masquerading -->
Find renamed VPN binaries (conhost.exe, dllhost.exe) by searching for rare hashes that differ from the native Windows files.
```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
compare: first_seen
window: '{{lookback_days}}d'
expected: A rare hash for conhost.exe or dllhost.exe. Native Windows binaries will
have a very high host count; a renamed SoftEther client will be rare.
prevalence:
by: device_hostname
key:
- process_hash_sha256
rare_below: 3
reads:
- device_hostname
- process_cmd_line
- process_hash_sha256
- process_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT process_hash_sha256, process_name, process_cmd_line, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%\\conhost.exe' OR LOWER(process_name) LIKE '%\\dllhost.exe') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_hash_sha256, process_name, process_cmd_line HAVING hosts < 3 ORDER BY hosts ASC
```
## c2-infrastructure-traffic
<!-- Detect C2 infrastructure traffic -->
Match DNS requests against infrastructure domains attributed to Integrity Technology Group, excluding benign browser noise.
```sqlite target=endpoint role=triage params=(lookback_days=lookback_days, c2_domains=c2_domains, scope_hosts=scope_hosts)
~~~yaml
expected: DNS resolutions for the specified domains from non-browser processes. Silence
proves absence only for these specific IOCs.
reads:
- device_hostname
- process_name
- query_hostname
- time
silence: not_evidence_of_absence
source: hb_dns_activity
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT device_hostname, process_name, query_hostname, time FROM hb_dns_activity WHERE instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND LOWER(process_name) NOT LIKE '%chrome.exe' AND LOWER(process_name) NOT LIKE '%msedge.exe' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```
## full-intrusion-triage
<!-- Evaluate full intrusion chain -->
```agent target=hunter
cite: required
context:
- early-stage-triage
- vpn-masquerading-persistence
- c2-infrastructure-traffic
max_iterations: 6
objective: Establish if the suspicious binary execution or VPN persistence is linked
to the identified C2 domains or exploitation probes across the Phased flow.
success_criteria: A final verdict citing the linkage between initial execution and
persistent C2 behavior.
tools:
- endpoint
- web
```
## route-on-verdict
<!-- Route on verdict -->
if~: "the full-intrusion-triage verdict is malicious for at least one host" (confidence: high, judge=hunter)
then: → isolate-host
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: incomplete-telemetry)
else: → analyst-review
## isolate-host
<!-- Isolate host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host from the network and collect the masqueraded binaries for forensic analysis.
```
→ analyst-review
## analyst-review
<!-- Analyst review -->
```manual target=analyst
Review the rows cited by the agents. Verify the rarity of the URL paths and process hashes. Confirm if the 'diagtrack.exe' instances were indeed masqueraded or legitimate telemetry service activity.
```
→ close-out
## close-out
<!-- Close out hunt -->
```manual target=analyst
Summarize the hunt results. If renamed binaries like DiagTrack.exe or rare conhost.exe hashes were confirmed, promote the detection-candidate query to a standing rule and update the local blocklist with the identified SHA256 hashes.
```
→ end
Run it
Take this hunt into your environment.
Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.
Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.