{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Integrity Technology Group is targeting critical infrastructure using a blend of automated scanning and manual exploitation. Identifying the transition from perimeter probe to persistent VPN foothold is critical for preventing data exfiltration."
      },
      "name": "Perimeter Exploitation and Evasive VPN Persistence",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1190",
        "attack.t1059.001",
        "attack.t1059.006",
        "attack.t1133",
        "attack.t1036.003",
        "attack.t1071",
        "collection",
        "command and control",
        "credential access",
        "defense evasion",
        "execution",
        "initial access",
        "persistence"
      ],
      "series": {
        "slug": "chinese-government-linked-cyber-threat-actors-combine-automated-and-hands-on-hacking-tools-to-st",
        "index": 1,
        "title": "Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data",
        "total": 2
      },
      "related": [
        {
          "hunt": "password-spraying-eburst-analysis",
          "reason": "This hunt focuses on vulnerability exploitation; EBurst password spraying belongs to an identity-centric hunt.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "This hunt uses a phased approach to correlate vulnerability presence, masqueraded execution, and persistent C2. It specifically hunts for rare source IPs and 'Living-off-the-Land' masquerading behavior using hash rarity that would be missed by single-surface rules.",
      "coverage": [
        {
          "stage": "initial-access-vulnerability-exploitation",
          "steps": [
            "affected-vulnerable-hosts",
            "web-exploitation-probes"
          ],
          "status": "covered"
        },
        {
          "stage": "execution-malware-payload",
          "steps": [
            "masqueraded-initial-payload"
          ],
          "status": "covered"
        },
        {
          "stage": "persistence-vpn-installation",
          "steps": [
            "vpn-masquerading-persistence"
          ],
          "status": "covered"
        },
        {
          "stage": "defence-evasion-masquerading",
          "steps": [
            "masqueraded-initial-payload",
            "vpn-masquerading-persistence"
          ],
          "status": "covered"
        },
        {
          "stage": "command-and-control-obfuscated-channels",
          "steps": [
            "c2-infrastructure-traffic"
          ],
          "status": "covered"
        },
        {
          "stage": "credential-access-eburst-spraying",
          "reason": "Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "collection-mailbox-exfiltration",
          "reason": "Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Web and Service Exploitation",
            "slug": "initial-access-vulnerability-exploitation",
            "tactic": "initial-access",
            "techniques": [
              "T1190",
              "T1189"
            ],
            "observables": [
              "BBScan",
              "dirsearch",
              "Fscan",
              "ksubdomain",
              "masscan",
              "NMAP",
              "OneForAll",
              "ShuiZe",
              "wpscan",
              "MicroScan",
              "XSS payloads targeting JavaScript",
              "Exploits for CVE-2016-3081",
              "Exploits for CVE-2019-11510",
              "Exploits for CVE-2021-22205",
              "Targeting ports 21, 22, 53, 80, 443, 1080",
              "PHP/ASP enumeration"
            ]
          },
          {
            "name": "Malware Execution",
            "slug": "execution-malware-payload",
            "tactic": "execution",
            "techniques": [
              "T1059.006",
              "T1059.007",
              "T1059.001"
            ],
            "observables": [
              "live700_v1.exe",
              "DiagTrack.exe",
              "Python-based exploit scripts",
              "Go-based exploit utilities",
              "Password-protected .zip files containing executables"
            ]
          },
          {
            "name": "VPN-based Persistence",
            "slug": "persistence-vpn-installation",
            "tactic": "persistence",
            "techniques": [
              "T1133"
            ],
            "observables": [
              "SoftEther VPN installers",
              "conhost.exe (renamed installer)",
              "dllhost.exe (renamed installer)",
              "curl or wget used to download SoftEther on Linux",
              "PowerShell used to download SoftEther on Windows",
              "Automatic reconnection configuration on startup"
            ]
          },
          {
            "name": "Service and Process Masquerading",
            "slug": "defence-evasion-masquerading",
            "tactic": "defence-evasion",
            "techniques": [
              "T1036.003"
            ],
            "observables": [
              "DiagTrack.exe",
              "conhost.exe",
              "dllhost.exe"
            ]
          },
          {
            "name": "EBurst Password Spraying",
            "slug": "credential-access-eburst-spraying",
            "tactic": "credential-access",
            "techniques": [
              "T1110.003",
              "T1110.001"
            ],
            "observables": [
              "EBurst tool",
              "Password spraying against ECP",
              "Password spraying against EWS",
              "Password spraying against OWA",
              "Password spraying against ActiveSync",
              "Password spraying against MAPI/RPC"
            ]
          },
          {
            "name": "Multi-protocol Command and Control",
            "slug": "command-and-control-obfuscated-channels",
            "tactic": "command-and-control",
            "techniques": [
              "T1071"
            ],
            "observables": [
              "dns.studiocloud.xyz",
              "98aiblog.com",
              "hmbcloud.com",
              "hmbcloud.net",
              "hmbiplc-01.com",
              "iepl.node.cm",
              "javacheck.ooguy.com",
              "javaupdate.giize.com",
              "sexytube0.com",
              "twimg.co.uk",
              "HTTP-based C2 communications"
            ]
          },
          {
            "name": "Email Data Collection",
            "slug": "collection-mailbox-exfiltration",
            "tactic": "collection",
            "techniques": [
              "T1041"
            ],
            "observables": [
              "Querying user mailbox data via DiagTrack.exe"
            ]
          }
        ],
        "summary": "Chinese government-linked threat actors, enabled by Integrity Technology Group, use a combination of automated scanning tools like MicroScan and manual exploitation to target global organizations. They establish persistence using legitimate VPN software like SoftEther and perform large-scale password spraying with EBurst to exfiltrate sensitive email data and credentials."
      },
      "severity": "high",
      "rationale": "Begin with hosts identified as vulnerable in the scoping step. If no vulnerable hosts are returned, run the hunt across the entire estate to detect potential use of 0-day exploits or scanner blind spots.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary exploits vulnerable web services to execute masqueraded payloads and establishes persistence through a renamed VPN client with a unique hash communicating with Integrity Tech infrastructure.",
      "parameters": {
        "c2_domains": {
          "from": {
            "ref": "AA26-281A",
            "kind": "article",
            "observed": "2026-10-08"
          },
          "type": "list[domain]",
          "default": [
            "dns.studiocloud.xyz",
            "98aiblog.com",
            "hmbcloud.com",
            "hmbcloud.net",
            "hmbiplc-01.com",
            "iepl.node.cm",
            "javacheck.ooguy.com",
            "javaupdate.giize.com",
            "sexytube0.com",
            "twimg.co.uk"
          ],
          "description": "Infrastructure domains associated with Integrity Technology Group."
        },
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Hostnames to narrow the search; leave empty to hunt across the entire estate."
        },
        "target_cves": {
          "from": {
            "ref": "AA26-281A",
            "kind": "article",
            "observed": "2026-10-08"
          },
          "type": "list[string]",
          "default": [
            "CVE-2014-6278",
            "CVE-2015-3306",
            "CVE-2015-5477",
            "CVE-2016-3081",
            "CVE-2019-11510",
            "CVE-2021-22205",
            "CVE-2021-3199",
            "CVE-2023-22894"
          ],
          "description": "Vulnerabilities frequently targeted by this actor group."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a",
          "name": "CISA AA26-281A: Chinese Government-linked Cyber Threat Actors"
        }
      ],
      "blind_spots": [
        {
          "id": "incomplete-telemetry",
          "risk": "A compromised server without HTTP logging will show payload execution but not the entry vector.",
          "stage": "initial-access-vulnerability-exploitation",
          "question": "whether exploitation attempts occurred on unmonitored web servers",
          "requires": "hb_http_activity on all perimeter servers"
        },
        {
          "id": "obfuscated-vpn-traffic",
          "risk": "Once the VPN tunnel is established, exfiltration within that tunnel is invisible to standard network sensors.",
          "stage": "command-and-control-obfuscated-channels",
          "question": "what activity occurs inside the SoftEther VPN tunnel",
          "requires": "Decrypted network inspection or process-to-network correlation"
        }
      ]
    },
    "name": "Perimeter Exploitation and Evasive VPN Persistence",
    "description": "This hunt targets the phased intrusion tactics of Integrity Technology Group. It begins by identifying vulnerable perimeter assets and looking for rare web exploitation probes or masqueraded payloads like DiagTrack.exe. The hunt then pivots to find evidence of persistence via VPN software (SoftEther) that has been renamed to masquerade as native Windows processes, identifying these by their rare hashes. Finally, it correlates this behavior with network traffic to known malicious infrastructure while excluding benign browser noise."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "chinese-government-linked-cyber-threat-actors-combine-automated-and-hands-on-hacking-tools-to-st",
          "index": 1,
          "title": "Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data",
          "total": 2
        },
        "coverage": [
          {
            "stage": "initial-access-vulnerability-exploitation",
            "steps": [
              "affected-vulnerable-hosts",
              "web-exploitation-probes"
            ],
            "status": "covered"
          },
          {
            "stage": "execution-malware-payload",
            "steps": [
              "masqueraded-initial-payload"
            ],
            "status": "covered"
          },
          {
            "stage": "persistence-vpn-installation",
            "steps": [
              "vpn-masquerading-persistence"
            ],
            "status": "covered"
          },
          {
            "stage": "defence-evasion-masquerading",
            "steps": [
              "masqueraded-initial-payload",
              "vpn-masquerading-persistence"
            ],
            "status": "covered"
          },
          {
            "stage": "command-and-control-obfuscated-channels",
            "steps": [
              "c2-infrastructure-traffic"
            ],
            "status": "covered"
          },
          {
            "stage": "credential-access-eburst-spraying",
            "reason": "Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "collection-mailbox-exfiltration",
            "reason": "Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary exploits vulnerable web services to execute masqueraded payloads and establishes persistence through a renamed VPN client with a unique hash communicating with Integrity Tech infrastructure.",
        "blind_spots": [
          {
            "id": "incomplete-telemetry",
            "risk": "A compromised server without HTTP logging will show payload execution but not the entry vector.",
            "stage": "initial-access-vulnerability-exploitation",
            "question": "whether exploitation attempts occurred on unmonitored web servers",
            "requires": "hb_http_activity on all perimeter servers"
          },
          {
            "id": "obfuscated-vpn-traffic",
            "risk": "Once the VPN tunnel is established, exfiltration within that tunnel is invisible to standard network sensors.",
            "stage": "command-and-control-obfuscated-channels",
            "question": "what activity occurs inside the SoftEther VPN tunnel",
            "requires": "Decrypted network inspection or process-to-network correlation"
          }
        ],
        "scoping_notes": "Begin with hosts identified as vulnerable in the scoping step. If no vulnerable hosts are returned, run the hunt across the entire estate to detect potential use of 0-day exploits or scanner blind spots.",
        "beyond_detection": "This hunt uses a phased approach to correlate vulnerability presence, masqueraded execution, and persistent C2. It specifically hunts for rare source IPs and 'Living-off-the-Land' masquerading behavior using hash rarity that would be missed by single-surface rules."
      }
    },
    {
      "id": "affected-vulnerable-hosts",
      "type": "query",
      "label": "Identify vulnerable perimeter hosts",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_uid, cve_uid, affected_package_name, severity FROM hb_vulnerability_finding WHERE instr(',' || '{{target_cves}}' || ',', ',' || cve_uid || ',') > 0",
        "surface": "hb_vulnerability_finding",
        "description": "Scope the hunt to assets with known vulnerabilities in Jenkins, WordPress, or Exchange mentioned in the advisory.",
        "expected_signal": "A list of device_uids and the specific CVEs they are vulnerable to. Silence means no known vulnerable software is exposed."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify vulnerable perimeter hosts",
        "reads": [
          "affected_package_name",
          "cve_uid",
          "device_uid",
          "severity"
        ],
        "source": "hb_vulnerability_finding",
        "target": "endpoint",
        "content": "SELECT device_uid, cve_uid, affected_package_name, severity FROM hb_vulnerability_finding WHERE instr(',' || '{{target_cves}}' || ',', ',' || cve_uid || ',') > 0",
        "silence": "not_evidence_of_absence",
        "expected": "A list of device_uids and the specific CVEs they are vulnerable to. Silence means no known vulnerable software is exposed.",
        "verified": "dry-run",
        "verified_at": "2026-10-09"
      }
    },
    {
      "id": "web-exploitation-probes",
      "type": "query",
      "label": "Search for web exploitation probes",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "web",
        "content": "SELECT src_endpoint_ip, url_path, user_agent, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_http_activity WHERE (LOWER(url_path) LIKE '%config.php' OR LOWER(url_path) LIKE '%web.config' OR LOWER(user_agent) LIKE '%dirsearch%' OR LOWER(user_agent) LIKE '%fscan%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY src_endpoint_ip, url_path, user_agent HAVING host_count < 3 ORDER BY host_count ASC",
        "surface": "hb_http_activity",
        "description": "Find rare url_path values or access to administrative configuration files from external IPs.",
        "expected_signal": "Rarely accessed configuration files or specific scanner user-agents. Silence suggests no automated probing matched these signatures."
      },
      "parents": [
        {
          "id": "affected-vulnerable-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Search for web exploitation probes",
        "reads": [
          "device_hostname",
          "src_endpoint_ip",
          "time",
          "url_path",
          "user_agent"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT src_endpoint_ip, url_path, user_agent, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_http_activity WHERE (LOWER(url_path) LIKE '%config.php' OR LOWER(url_path) LIKE '%web.config' OR LOWER(user_agent) LIKE '%dirsearch%' OR LOWER(user_agent) LIKE '%fscan%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY src_endpoint_ip, url_path, user_agent HAVING host_count < 3 ORDER BY host_count ASC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Rarely accessed configuration files or specific scanner user-agents. Silence suggests no automated probing matched these signatures.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "url_path"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-10-09"
      }
    },
    {
      "id": "masqueraded-initial-payload",
      "type": "query",
      "label": "Detect masqueraded payload execution",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_path, parent_process_name, on_disk, time FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%\\\\diagtrack.exe' AND (on_disk = 0 OR LOWER(process_path) NOT LIKE 'c:\\\\windows\\\\system32\\\\%')) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Find execution of DiagTrack.exe that is either fileless (injected) or running from a non-standard path.",
        "expected_signal": "DiagTrack.exe running from outside System32 or with on_disk=0 is a high-confidence indicator of masquerading. Silence proves absence on monitored hosts."
      },
      "parents": [
        {
          "id": "affected-vulnerable-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Detect masqueraded payload execution",
        "reads": [
          "device_hostname",
          "on_disk",
          "parent_process_name",
          "process_name",
          "process_path",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_path, parent_process_name, on_disk, time FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%\\\\diagtrack.exe' AND (on_disk = 0 OR LOWER(process_path) NOT LIKE 'c:\\\\windows\\\\system32\\\\%')) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "evidence_of_absence",
        "expected": "DiagTrack.exe running from outside System32 or with on_disk=0 is a high-confidence indicator of masquerading. Silence proves absence on monitored hosts.",
        "verified": "dry-run",
        "verified_at": "2026-10-09"
      }
    },
    {
      "id": "early-stage-triage",
      "type": "analytic",
      "label": "Assess early breach indicators",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "web"
        ],
        "context": [
          "affected-vulnerable-hosts",
          "web-exploitation-probes",
          "masqueraded-initial-payload"
        ],
        "objective": "Determine if any host showing suspicious HTTP traffic also executed a masqueraded binary within a tight time window.",
        "description": "Establish if the web probes and process executions represent a successful initial access and payload delivery.",
        "max_iterations": 4,
        "expected_signal": "A per-host verdict linking the probe to the payload execution.",
        "success_criteria": "A verdict of malicious | suspicious | benign citing specific rows."
      },
      "parents": [
        {
          "id": "web-exploitation-probes",
          "kind": "merge"
        },
        {
          "id": "masqueraded-initial-payload",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "vpn-masquerading-persistence",
      "type": "query",
      "label": "Identify VPN binary masquerading",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT process_hash_sha256, process_name, process_cmd_line, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%\\\\conhost.exe' OR LOWER(process_name) LIKE '%\\\\dllhost.exe') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_hash_sha256, process_name, process_cmd_line HAVING hosts < 3 ORDER BY hosts ASC",
        "surface": "hb_process_activity",
        "description": "Find renamed VPN binaries (conhost.exe, dllhost.exe) by searching for rare hashes that differ from the native Windows files.",
        "expected_signal": "A rare hash for conhost.exe or dllhost.exe. Native Windows binaries will have a very high host count; a renamed SoftEther client will be rare."
      },
      "parents": [
        {
          "id": "early-stage-triage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Identify VPN binary masquerading",
        "reads": [
          "device_hostname",
          "process_cmd_line",
          "process_hash_sha256",
          "process_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT process_hash_sha256, process_name, process_cmd_line, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%\\\\conhost.exe' OR LOWER(process_name) LIKE '%\\\\dllhost.exe') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_hash_sha256, process_name, process_cmd_line HAVING hosts < 3 ORDER BY hosts ASC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A rare hash for conhost.exe or dllhost.exe. Native Windows binaries will have a very high host count; a renamed SoftEther client will be rare.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_hash_sha256"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-10-09"
      }
    },
    {
      "id": "c2-infrastructure-traffic",
      "type": "query",
      "label": "Detect C2 infrastructure traffic",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, query_hostname, time FROM hb_dns_activity WHERE instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND LOWER(process_name) NOT LIKE '%chrome.exe' AND LOWER(process_name) NOT LIKE '%msedge.exe' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_dns_activity",
        "description": "Match DNS requests against infrastructure domains attributed to Integrity Technology Group, excluding benign browser noise.",
        "expected_signal": "DNS resolutions for the specified domains from non-browser processes. Silence proves absence only for these specific IOCs."
      },
      "parents": [
        {
          "id": "early-stage-triage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Detect C2 infrastructure traffic",
        "reads": [
          "device_hostname",
          "process_name",
          "query_hostname",
          "time"
        ],
        "source": "hb_dns_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, query_hostname, time FROM hb_dns_activity WHERE instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND LOWER(process_name) NOT LIKE '%chrome.exe' AND LOWER(process_name) NOT LIKE '%msedge.exe' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "DNS resolutions for the specified domains from non-browser processes. Silence proves absence only for these specific IOCs.",
        "verified": "dry-run",
        "verified_at": "2026-10-09"
      }
    },
    {
      "id": "full-intrusion-triage",
      "type": "analytic",
      "label": "Evaluate full intrusion chain",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "web"
        ],
        "context": [
          "early-stage-triage",
          "vpn-masquerading-persistence",
          "c2-infrastructure-traffic"
        ],
        "objective": "Establish if the suspicious binary execution or VPN persistence is linked to the identified C2 domains or exploitation probes across the Phased flow.",
        "description": "Combine the early access evidence with persistence and C2 signals to provide a definitive intrusion verdict.",
        "max_iterations": 6,
        "expected_signal": "A comprehensive verdict per host correlating the entire attack chain.",
        "success_criteria": "A final verdict citing the linkage between initial execution and persistent C2 behavior."
      },
      "parents": [
        {
          "id": "vpn-masquerading-persistence",
          "kind": "merge"
        },
        {
          "id": "c2-infrastructure-traffic",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the full-intrusion-triage verdict is malicious for at least one host",
        "condition": "the full-intrusion-triage verdict is malicious for at least one host",
        "blind_spot": "incomplete-telemetry",
        "confidence": "high",
        "description": "Direct the hunt towards containment or review based on the triage result.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "full-intrusion-triage"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate host",
      "config": {
        "target": "endpoint",
        "description": "Contain the threat actor and prevent data exfiltration.",
        "instructions": "Isolate the host from the network and collect the masqueraded binaries for forensic analysis.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Analyst review",
      "config": {
        "assignee": "analyst",
        "description": "Review findings and confirm intrusion lifecycle.",
        "instructions": "Review the rows cited by the agents. Verify the rarity of the URL paths and process hashes. Confirm if the 'diagtrack.exe' instances were indeed masqueraded or legitimate telemetry service activity."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out hunt",
      "config": {
        "assignee": "analyst",
        "description": "Document findings and update defensive posture.",
        "instructions": "Summarize the hunt results. If renamed binaries like DiagTrack.exe or rare conhost.exe hashes were confirmed, promote the detection-candidate query to a standing rule and update the local blocklist with the identified SHA256 hashes."
      },
      "parents": [
        {
          "id": "analyst-review"
        }
      ]
    }
  ]
}