{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "The transition to Post-Quantum Cryptography is a multi-year requirement to mitigate 'harvest now, decrypt later' risks. Monitoring the organization's testing activity ensures the PKI infrastructure is modernized in a controlled fashion and identifies shadow testing that could disrupt production services."
      },
      "name": "Post-Quantum Authentication Readiness Monitoring",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1195",
        "initial access"
      ],
      "related": [
        {
          "hunt": "pqc-handshake-performance-degradation",
          "reason": "This hunt focuses on inventory and readiness, not the performance impact of larger PQC certificate chains on network traffic.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "While a detection rule can alert on a specific OS build, this hunt correlates build capability with actual certificate presence and network activity to pilot CAs, providing a holistic view of the testing environment that isolated rules cannot capture.",
      "coverage": [
        {
          "stage": "pqc-supply-chain-inventory",
          "steps": [
            "scope-pqc-capable-hosts",
            "detect-pqc-certificates"
          ],
          "status": "covered"
        },
        {
          "stage": "pqc-pilot-interoperability-testing",
          "steps": [
            "dns-pqc-traffic",
            "triage-pqc-readiness"
          ],
          "status": "covered"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "PQC Supply Chain and Infrastructure Inventory",
            "slug": "pqc-supply-chain-inventory",
            "tactic": "initial-access",
            "techniques": [
              "T1195"
            ],
            "observables": [
              "ML-DSA-87 algorithm support",
              "embedded devices",
              "operational technology systems",
              "KB5101681",
              "KB5101684",
              "OS Build 28000.2608",
              "OS Build 26200.8973",
              "OS Build 26100.8973"
            ]
          },
          {
            "name": "PQC Pilot Interoperability and Connectivity",
            "slug": "pqc-pilot-interoperability-testing",
            "tactic": "initial-access",
            "techniques": [
              "T1195"
            ],
            "observables": [
              "ML-DSA-87 certificate chains",
              "aka.ms/rootcert",
              "ssl.com",
              "asp.net",
              "ComSign pilot roots",
              "DigiCert pilot roots",
              "HARICA pilot roots",
              "IdenTrust Services pilot roots",
              "Sectigo pilot roots",
              "Shanghai Electronic Certification Authority pilot roots"
            ]
          }
        ],
        "summary": "Organizations are initiating post-quantum authentication (PQC) readiness assessments to identify and mitigate 'harvest now, decrypt later' threats and supply chain dependencies. The process involves auditing infrastructure for ML-DSA-87 support and testing certificate interoperability through the Microsoft PQC TLS Pilot Program using non-production pilot roots."
      },
      "severity": "medium",
      "rationale": "Prioritize developer workstations, security lab hosts, and Windows 11 systems recently updated after July 2026. Focus scoping on hosts that handle internal PKI or external TLS authentication.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "Organizations participating in post-quantum authentication testing will exhibit specific Windows build versions, the presence of ML-DSA-87 pilot root certificates, and network activity to designated pilot CA coordination domains.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Optional list of hosts to narrow the hunt."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine for network activity."
        },
        "pilot_domains": {
          "from": {
            "ref": "msrc-blog-pqc-tls-pilot",
            "kind": "article",
            "observed": "2026-10-08"
          },
          "type": "list[domain]",
          "default": [
            "ssl.com",
            "aka.ms",
            "asp.net"
          ],
          "description": "Domains associated with the PQC Pilot Program and coordination."
        },
        "pqc_build_strings": {
          "from": {
            "ref": "msrc-blog-pqc-tls-pilot",
            "kind": "article",
            "observed": "2026-10-08"
          },
          "type": "list[string]",
          "default": [
            "28000.2608",
            "26200.8973",
            "26100.8973"
          ],
          "description": "Windows OS builds known to support ML-DSA-87 in the pilot."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.microsoft.com/en-us/security/blog/2026/10/08/post-quantum-authentication-why-organizations-should-start-testing-certificate-ecosystems-now/",
          "gates": [
            "dry-run",
            "lint",
            "critic"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.microsoft.com/en-us/security/blog/2026/10/08/post-quantum-authentication-why-organizations-should-start-testing-certificate-ecosystems-now/",
          "name": "Microsoft Security Blog \u2014 Post-quantum authentication: Why organizations should start testing certificate ecosystems now"
        }
      ],
      "blind_spots": [
        {
          "id": "incomplete-certificate-visibility",
          "risk": "The current hb_certificates schema does not provide a direct hostname column, requiring an analyst to correlate cert findings with other telemetry by timing or certificate owner.",
          "stage": "pqc-supply-chain-inventory",
          "question": "Which specific hosts have installed the ML-DSA pilot certificates?",
          "requires": "hb_certificates with device_hostname linkage"
        },
        {
          "id": "hsm-blind-spot",
          "risk": "Certificates stored exclusively on HSMs or in specialized appliance stores are invisible to endpoint-based certificate inventory.",
          "stage": "pqc-supply-chain-inventory",
          "question": "Is the cryptographic hardware generating PQC keys that never reach the endpoint trust store?",
          "requires": "Direct logging from Hardware Security Modules (HSMs)"
        }
      ]
    },
    "name": "Post-Quantum Authentication Readiness Monitoring",
    "description": "This hunt identifies hosts and infrastructure already engaging with Post-Quantum Cryptography (PQC) testing. It focuses on identifying the prerequisites for the Microsoft PQC TLS Pilot Program, such as specific Windows 11 builds (KB5101681, KB5101684) and the presence of non-production pilot root certificates from CAs like SSL.com and DigiCert. By inventorying these capabilities and correlating them with network traffic to pilot endpoints, we map the organization's PQC supply chain and readiness posture."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "coverage": [
          {
            "stage": "pqc-supply-chain-inventory",
            "steps": [
              "scope-pqc-capable-hosts",
              "detect-pqc-certificates"
            ],
            "status": "covered"
          },
          {
            "stage": "pqc-pilot-interoperability-testing",
            "steps": [
              "dns-pqc-traffic",
              "triage-pqc-readiness"
            ],
            "status": "covered"
          }
        ],
        "rationale": "Organizations participating in post-quantum authentication testing will exhibit specific Windows build versions, the presence of ML-DSA-87 pilot root certificates, and network activity to designated pilot CA coordination domains.",
        "blind_spots": [
          {
            "id": "incomplete-certificate-visibility",
            "risk": "The current hb_certificates schema does not provide a direct hostname column, requiring an analyst to correlate cert findings with other telemetry by timing or certificate owner.",
            "stage": "pqc-supply-chain-inventory",
            "question": "Which specific hosts have installed the ML-DSA pilot certificates?",
            "requires": "hb_certificates with device_hostname linkage"
          },
          {
            "id": "hsm-blind-spot",
            "risk": "Certificates stored exclusively on HSMs or in specialized appliance stores are invisible to endpoint-based certificate inventory.",
            "stage": "pqc-supply-chain-inventory",
            "question": "Is the cryptographic hardware generating PQC keys that never reach the endpoint trust store?",
            "requires": "Direct logging from Hardware Security Modules (HSMs)"
          }
        ],
        "scoping_notes": "Prioritize developer workstations, security lab hosts, and Windows 11 systems recently updated after July 2026. Focus scoping on hosts that handle internal PKI or external TLS authentication.",
        "beyond_detection": "While a detection rule can alert on a specific OS build, this hunt correlates build capability with actual certificate presence and network activity to pilot CAs, providing a holistic view of the testing environment that isolated rules cannot capture."
      }
    },
    {
      "id": "scope-pqc-capable-hosts",
      "type": "query",
      "label": "Scope PQC-Capable Windows Hosts",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT hostname, os_version, last_seen FROM hb_devices WHERE platform = 'Windows' AND (instr(',' || '{{pqc_build_strings}}' || ',', ',' || os_version || ',') > 0 OR os_version LIKE '%28000.2608%' OR os_version LIKE '%26200.8973%' OR os_version LIKE '%26100.8973%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_devices",
        "description": "Identify hosts running the specific Windows 11 builds required for ML-DSA-87 pilot testing.",
        "expected_signal": "Hosts running Windows 11 with the July 2026 updates or later. Silence suggests no hosts are currently ready for PQC pilot testing."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Scope PQC-Capable Windows Hosts",
        "reads": [
          "hostname",
          "os_version",
          "last_seen",
          "platform",
          "time"
        ],
        "source": "hb_devices",
        "target": "endpoint",
        "content": "SELECT hostname, os_version, last_seen FROM hb_devices WHERE platform = 'Windows' AND (instr(',' || '{{pqc_build_strings}}' || ',', ',' || os_version || ',') > 0 OR os_version LIKE '%28000.2608%' OR os_version LIKE '%26200.8973%' OR os_version LIKE '%26100.8973%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Hosts running Windows 11 with the July 2026 updates or later. Silence suggests no hosts are currently ready for PQC pilot testing.",
        "verified": "dry-run",
        "verified_at": "2026-10-09"
      }
    },
    {
      "id": "detect-pqc-certificates",
      "type": "query",
      "label": "Detect PQC Pilot Certificates",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT common_name, issuer, signature_algorithm, status, owner FROM hb_certificates WHERE (LOWER(signature_algorithm) LIKE '%ml-dsa%' OR LOWER(common_name) LIKE '%pqc%' OR LOWER(issuer) LIKE '%ssl.com%' OR LOWER(issuer) LIKE '%comsign%' OR LOWER(issuer) LIKE '%digicert%' OR LOWER(issuer) LIKE '%sectigo%' OR LOWER(issuer) LIKE '%harica%')",
        "surface": "hb_certificates",
        "description": "Search for certificates using ML-DSA or issued by the designated pilot CAs in the trust store.",
        "expected_signal": "Presence of non-production pilot root certificates or ML-DSA signed certificates. Silence means no pilot certificates are installed."
      },
      "parents": [
        {
          "id": "scope-pqc-capable-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Detect PQC Pilot Certificates",
        "reads": [
          "common_name",
          "issuer",
          "signature_algorithm",
          "status",
          "owner"
        ],
        "source": "hb_certificates",
        "target": "endpoint",
        "content": "SELECT common_name, issuer, signature_algorithm, status, owner FROM hb_certificates WHERE (LOWER(signature_algorithm) LIKE '%ml-dsa%' OR LOWER(common_name) LIKE '%pqc%' OR LOWER(issuer) LIKE '%ssl.com%' OR LOWER(issuer) LIKE '%comsign%' OR LOWER(issuer) LIKE '%digicert%' OR LOWER(issuer) LIKE '%sectigo%' OR LOWER(issuer) LIKE '%harica%')",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "30d",
          "compare": "first_seen"
        },
        "expected": "Presence of non-production pilot root certificates or ML-DSA signed certificates. Silence means no pilot certificates are installed.",
        "verified": "dry-run",
        "prevalence": {
          "by": "owner",
          "key": [
            "issuer",
            "signature_algorithm"
          ],
          "rare_below": 5
        },
        "verified_at": "2026-10-09"
      }
    },
    {
      "id": "dns-pqc-traffic",
      "type": "query",
      "label": "DNS Traffic to Pilot Domains",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, query_hostname, COUNT(*) as lookup_count FROM hb_dns_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND instr(',' || '{{pilot_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, query_hostname",
        "surface": "hb_dns_activity",
        "description": "Identify hosts resolving domains mentioned in the PQC pilot program, narrowed by scoped hosts.",
        "expected_signal": "DNS lookups for pilot domains like aka.ms or ssl.com during the test window. Silence means no network-based pilot activity observed."
      },
      "parents": [
        {
          "id": "scope-pqc-capable-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "DNS Traffic to Pilot Domains",
        "reads": [
          "device_hostname",
          "query_hostname",
          "time"
        ],
        "source": "hb_dns_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, query_hostname, COUNT(*) as lookup_count FROM hb_dns_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND instr(',' || '{{pilot_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, query_hostname",
        "silence": "not_evidence_of_absence",
        "expected": "DNS lookups for pilot domains like aka.ms or ssl.com during the test window. Silence means no network-based pilot activity observed.",
        "verified": "dry-run",
        "verified_at": "2026-10-09"
      }
    },
    {
      "id": "triage-pqc-readiness",
      "type": "analytic",
      "label": "Triage PQC Testing Context",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "scope-pqc-capable-hosts",
          "detect-pqc-certificates",
          "dns-pqc-traffic"
        ],
        "objective": "Determine which hosts are actively testing post-quantum certificates and whether their infrastructure dependencies match the PQC TLS Pilot Program profile.",
        "description": "Weigh OS version capability, certificate presence, and network activity to determine if a host is actively participating in PQC testing.",
        "max_iterations": 3,
        "expected_signal": "A verdict characterizing each host as either a PQC tester, a PQC-ready host, or unrelated.",
        "success_criteria": "A list of hosts with confirmed PQC capabilities or active testing status, citing the specific build numbers and certificate issuers found."
      },
      "parents": [
        {
          "id": "detect-pqc-certificates",
          "kind": "merge"
        },
        {
          "id": "dns-pqc-traffic",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-pqc-findings",
      "type": "checkpoint",
      "label": "Route Based on Testing Activity",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "The triage verdict identifies at least one host as an active PQC tester with ML-DSA certificates or CA traffic.",
        "condition": "The triage verdict identifies at least one host as an active PQC tester with ML-DSA certificates or CA traffic.",
        "blind_spot": "incomplete-certificate-visibility",
        "confidence": "high",
        "description": "Direct confirmed PQC testers to tagging and documentation steps.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-pqc-readiness"
        }
      ]
    },
    {
      "id": "tag-pqc-hosts",
      "type": "action",
      "label": "Tag PQC Testing Hosts",
      "config": {
        "target": "endpoint",
        "description": "Mark identified hosts in the inventory as active PQC pilot participants for future monitoring.",
        "instructions": "Tag identified hosts in the asset inventory with PQC_Pilot_Tester to ensure they are excluded from production performance baselines.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-pqc-findings",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "pki-analyst-review",
      "type": "task",
      "label": "Analyst Review of PQC Findings",
      "config": {
        "assignee": "analyst",
        "description": "Validate the findings with the PKI team and document any shadow testing.",
        "instructions": "Review the identified hosts and certificates with the PKI administrator to confirm authorization. Update the PQC transition roadmap with any newly discovered dependencies."
      },
      "parents": [
        {
          "id": "route-pqc-findings",
          "branch": "default"
        },
        {
          "id": "route-pqc-findings",
          "branch": "on_unavailable"
        },
        {
          "id": "tag-pqc-hosts"
        }
      ]
    },
    {
      "id": "update-readiness-report",
      "type": "task",
      "label": "Update Readiness Report",
      "config": {
        "assignee": "analyst",
        "description": "Finalize the hunt by updating the organizational PQC readiness documentation.",
        "instructions": "Document the PQC-capable host count and the presence of pilot certificates in the quarterly security readiness report."
      },
      "parents": [
        {
          "id": "pki-analyst-review"
        }
      ]
    },
    {
      "id": "close-out-task",
      "type": "task",
      "label": "Close Out",
      "config": {
        "assignee": "analyst",
        "description": "Finalize the hunt when no active PQC testing is identified.",
        "instructions": "Record that no PQC pilot activity was detected. Schedule a re-run for next month as pilot adoption is expected to increase."
      },
      "parents": [
        {
          "id": "route-pqc-findings",
          "branch": "on_refutes"
        }
      ]
    }
  ]
}