Remote access abuse and red-team implants
An intruder accessed the environment via an external remote service using a single-factor credential and deployed red-team framework implants to maintain command and control.
Based on research by Cisco Talos 2026-09-28 9 steps · 3 queries T1071.001 T1078 T1133
Brief
The Rise of Automated Initial Access
Recent research from Talos, "Should you care about an AI slowdown?", suggests that ransomware actors increasingly use AI-assisted scripts to streamline the exploitation of external remote services. These attackers do not rely on complex zero-days; instead, they target weaknesses in identity controls, such as single-factor authentication on VPNs. Once they gain access, they deploy red-team frameworks like AdaptixC2 to maintain command and control. This hunt identifies the intersection of these two behaviors: compromised credentials and the subsequent execution of offensive implants.
Scoping the VPN Footprint
The hunt begins by identifying the attack surface. The first phase queries the host software inventory to list devices running VPN software, including Cisco AnyConnect or generic VPN clients. By narrowing the scope to these hosts, the hunt focuses its resources on the primary targets for external remote service abuse. This scoping step is essential for reducing noise in large environments.
Correlating Identity and Endpoint Signals
The second phase runs two analytical leads in parallel. First, we investigate authentication logs for successful sign-ins that lack multi-factor authentication. To separate routine administrative work from potential threats, the hunt filters for sign-ins that are rare across the fleet, specifically those targeting only one or two hosts.
Simultaneously, the hunt searches for the execution of specific malicious binaries identified in the Talos research. This includes known filenames like vid001.exe and content.js. Any process execution event matching these filenames on a host identified in the scoping phase represents a high-confidence lead.
Automated Triage and Verdicts
Because identity gaps and red-team tools can exist independently in a complex network, this hunt employs an agent to correlate the findings. The agent looks for temporal overlap, specifically seeking instances where an unprotected sign-in occurred within 24 hours of a malicious process execution on the same host. This correlation transforms isolated alerts into a confirmed intrusion path, allowing the hunt to prioritize active threats over general hygiene issues.
Blind Spots
This hunt has two known blind spots. First, it relies on VPN providers to accurately export MFA status in authentication logs. If this data is missing from the logs, the hunt may generate false positives by assuming a lack of reported MFA means a lack of the control. Second, the hunt depends on known filenames for implants. If an adversary renames their components or uses ephemeral scripts, the process execution queries will not see the activity.
Running the Playbook
This hunt is a hunt.md playbook that you can import into Huntbase or any compatible runtime. It allows for parameter adjustments, such as lookback windows and custom filename lists, to adapt to new intelligence. The playbook provides a structured flow from initial scoping to host isolation, ensuring a consistent response to remote access threats.
In this series
Steps
-
Find hosts with VPN software
Query · scopingIdentify the hosts most likely to be targets for external remote service abuse by looking for installed VPN clients.
reads hb_software_inventorysqlSELECT device_hostname, package_name, package_version, vendor_name FROM hb_software_inventory WHERE (LOWER(vendor_name) LIKE '%cisco%' OR LOWER(package_name) LIKE '%anyconnect%' OR LOWER(package_name) LIKE '%secure client%' OR LOWER(package_name) LIKE '%vpn%')What a hit looks like. The query lists hosts running VPN clients. These hosts represent the primary attack surface for external access abuse.
-
Rare remote sign-ins without MFA
Query · baselineFind successful remote logons that lacked MFA and are rare across the fleet, suggesting a possible beachhead.
reads hb_auth_signinsqlSELECT actor_user_name, src_endpoint_ip, device_hostname, logon_type, MIN(time) AS first_seen, COUNT(DISTINCT device_hostname) AS host_count FROM hb_auth_signin WHERE (mfa = 'false' OR mfa IS NULL) AND status_id = 1 AND (LOWER(logon_type) IN ('remote interactive', 'network') OR LOWER(event_type) LIKE '%vpn%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, src_endpoint_ip HAVING host_count <= 2What a hit looks like. A row identifies a user and IP that logged in successfully without MFA to only one or two hosts. Fleet-wide logins are likely authorized exceptions.
-
Implant execution from Talos research
Query · detection candidateIdentify the execution of specific binaries and red-team tools used by ransomware actors.
reads hb_process_activitysqlSELECT device_hostname, process_name, process_cmd_line, process_original_file_name, user_name, time FROM hb_process_activity WHERE (instr(',' || LOWER('{{malicious_filenames}}') || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || LOWER('{{malicious_filenames}}') || ',', ',' || LOWER(process_original_file_name) || ',') > 0 OR instr(LOWER(process_cmd_line), 'content.js') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. Process events for known AdaptixC2 or Procpatcher filenames. Any hit on a host from the scoping step is a high-confidence lead.
-
Triage access and execution
Agent triageThe agent evaluates whether the rare, unprotected sign-ins and the execution of red-team tools on the same host indicate a successful intrusion.
-
Route on triage verdict
DecisionDirect the hunt to containment or manual review based on the agent verdict.
-
Isolate compromised host
Response actionStop the adversary from moving laterally or deploying ransomware by network-isolating the host.
-
Analyst review
Analyst taskManually verify the threat and document the attack path.
-
Close out
Analyst taskSummarize the hunt and record gaps in security hygiene.
Coverage
Scenario coverage
| Stage | Covered | How, or why not |
|---|---|---|
| VPN Access and Credential Abuse T1133 |
Yes | find-vpn-endpoints, rare-unprotected-logons |
| AdaptixC2 Command and Control T1071 |
Yes | detect-implant-execution |
| System Patching and Bypass Tools T1562 |
Out of scope | Belongs to another part of the 'Should you care about an “AI slowdown?”' series. |
| AI-Driven Destructive Scripting T1059 |
Out of scope | Belongs to another part of the 'Should you care about an “AI slowdown?”' series. |
| Data Encryption and Double Extortion T1486 |
Out of scope | Belongs to another part of the 'Should you care about an “AI slowdown?”' series. |
Blind spots
- Needs VPN provider MFA status fields. Some providers do not export MFA status in authentication logs, which could lead to false positives if the hunt assumes absence of the field means absence of the control. It would answer whether MFA was actually bypassed or just not reported.
- Needs hb_process_activity or hb_file_activity. Adversaries often rename tools like AdaptixC2 components; the hunt relies on known filenames which may be rotated. It would answer whether the adversary used non-prevalent filenames.
Parameters & data
Parameters
| Parameter | Type | Default | What it is |
|---|---|---|---|
lookback_days | number | 14 | Days of history to examine for sign-ins and process execution. |
malicious_filenames | list[string] | vid001.exe, wcinstaller_nonadmin.exe, secoh-qad.exe, aact.exe, content.js | Implant and tool filenames identified in Talos telemetry. |
scope_hosts | list[host] | — | Target hosts found in the scoping step; leave empty to hunt across the full estate. |
Telemetry
| Source | Category | Telemetry |
|---|---|---|
| Endpoint telemetry (hb_ surfaces) | endpoint | endpoint |
| Identity / sign-in telemetry | identity | identity |
Source
---
analysis: A simple rule triggers on a filename; this hunt correlates the absence of
identity controls (MFA) with the prevalence-weighted execution of those tools across
a scoped asset inventory, providing the context an analyst needs to confirm an intrusion.
blind_spots:
- id: mfa-reporting-gap
question: whether MFA was actually bypassed or just not reported
requires: VPN provider MFA status fields
risk: Some providers do not export MFA status in authentication logs, which could
lead to false positives if the hunt assumes absence of the field means absence
of the control.
stage: initial-access-external-remote-services
- id: ephemeral-tooling
question: whether the adversary used non-prevalent filenames
requires: hb_process_activity or hb_file_activity
risk: Adversaries often rename tools like AdaptixC2 components; the hunt relies
on known filenames which may be rotated.
stage: c2-red-team-tooling
coverage:
- stage: initial-access-external-remote-services
status: covered
steps:
- find-vpn-endpoints
- rare-unprotected-logons
- stage: c2-red-team-tooling
status: covered
steps:
- detect-implant-execution
- reason: "Belongs to another part of the 'Should you care about an \u201CAI slowdown?\u201D\
' series."
stage: persistence-and-defense-evasion-patchers
status: out_of_scope
- reason: "Belongs to another part of the 'Should you care about an \u201CAI slowdown?\u201D\
' series."
stage: execution-ai-generated-scripts
status: out_of_scope
- reason: "Belongs to another part of the 'Should you care about an \u201CAI slowdown?\u201D\
' series."
stage: impact-double-extortion-ransomware
status: out_of_scope
guardrails:
claims: no_unsupported
evidence: citation_required
missing_data: not_benign
telemetry: untrusted
hunt:
applicability: campaign-specific
handoff: promote-to-detection
justification: External remote services are the primary entry point for the ransomware
actors described in the Talos research. Validating that these services are protected
by MFA and free of red-team implants is a critical baseline defense.
methodology: model-assisted
trigger: intel-report
hypothesis: An intruder accessed the environment via an external remote service using
a single-factor credential and deployed red-team framework implants to maintain
command and control.
labels:
- hunt
- attack.t1133
- attack.t1071.001
- attack.t1078
name: Remote access abuse and red-team implants
parameters:
lookback_days:
default: '14'
description: Days of history to examine for sign-ins and process execution.
type: number
malicious_filenames:
default:
- vid001.exe
- wcinstaller_nonadmin.exe
- secoh-qad.exe
- aact.exe
- content.js
description: Implant and tool filenames identified in Talos telemetry.
from:
kind: article
observed: '2026-09-17'
ref: talos-ai-slowdown-2026
type: list[string]
scope_hosts:
default: []
description: Target hosts found in the scoping step; leave empty to hunt across
the full estate.
type: list[host]
provenance:
authors:
- name: Huntbase hunt generation
org: huntbase.io
generated:
by: huntbase-hunt-generation
from: https://blog.talosintelligence.com/should-you-care-about-an-ai-slowdown/
gates:
- dry-run
- lint
model: hb_google/gemini-3-flash-preview
rationale: Start by identifying hosts running Cisco AnyConnect or other VPN software
to narrow the scope of remote access investigations.
references:
- name: "Talos \u2014 Should you care about an AI slowdown?"
url: https://blog.talosintelligence.com/should-you-care-about-an-ai-slowdown/
related:
- hunt: lateral-movement-red-team-tools
reason: This hunt focuses on initial access via VPN; lateral movement would require
analysis of internal authentication and SMB traffic.
relation: out-of-scope-alternative
scenario:
stages:
- name: VPN Access and Credential Abuse
observables:
- External-facing VPN services
- Administrative account logins
- Sign-ins without multi-factor authentication (MFA)
slug: initial-access-external-remote-services
tactic: initial-access
techniques:
- T1133
- name: AdaptixC2 Command and Control
observables:
- AdaptixC2 framework
- VID001.exe
- WCInstaller_NonAdmin.exe
- w32.9f1f11a708-100.sbx.tg
- w32.c4dd71e347-95.sbx.tg
slug: c2-red-team-tooling
tactic: command-and-control
techniques:
- T1071
- name: System Patching and Bypass Tools
observables:
- SECOH-QAD.exe
- AAct.exe
- win.tool.procpatcher
- w32.fed979f93b-95.sbx.tg
slug: persistence-and-defense-evasion-patchers
tactic: persistence
techniques:
- T1562
- name: AI-Driven Destructive Scripting
observables:
- content.js
- w32.38d053135d-95.sbx.tg
- LLM-generated destructive scripts
slug: execution-ai-generated-scripts
tactic: execution
techniques:
- T1059
- name: Data Encryption and Double Extortion
observables:
- Encryption of local and remote drives
- Attempts to disable backup systems
- Double-extortion communications
slug: impact-double-extortion-ransomware
tactic: impact
techniques:
- T1486
summary: The Qilin and The Gentlemen ransomware groups are targeting Japanese SMEs
using a combination of AI-generated destructive scripts and the AdaptixC2 red-teaming
framework. Initial access is typically gained via external remote services like
VPNs, leading to lateral movement, data theft, and double-extortion ransomware
attacks.
series:
index: 1
slug: should-you-care-about-an-ai-slowdown
title: "Should you care about an \u201CAI slowdown?\u201D"
total: 2
severity: high
targets:
analyst:
name: Tier-2 analyst
role: analyst
endpoint:
category: endpoint
name: Endpoint telemetry (hb_ surfaces)
telemetry:
- endpoint
hunter:
agent: true
name: Hunt agent
identity:
category: identity
name: Identity / sign-in telemetry
telemetry:
- identity
tlp: clear
type: investigation
---
# Remote access abuse and red-team implants
This hunt examines the intersection of identity and endpoint security following research into ransomware actors that use AI-assisted scripts and red-team frameworks like AdaptixC2. The hunt first identifies hosts running VPN clients, then searches for successful sign-ins without multi-factor authentication and the execution of specific implants identified by Talos. An agent weighs these independent signals to identify potential beachheads where defensive fundamentals were bypassed. Analysts then review the findings to isolate confirmed threats.
## find-vpn-endpoints
<!-- Find hosts with VPN software -->
Identify the hosts most likely to be targets for external remote service abuse by looking for installed VPN clients.
```sqlite target=endpoint role=scoping
~~~yaml
expected: The query lists hosts running VPN clients. These hosts represent the primary
attack surface for external access abuse.
reads:
- device_hostname
- package_name
- package_version
- vendor_name
silence: not_evidence_of_absence
source: hb_software_inventory
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, package_name, package_version, vendor_name FROM hb_software_inventory WHERE (LOWER(vendor_name) LIKE '%cisco%' OR LOWER(package_name) LIKE '%anyconnect%' OR LOWER(package_name) LIKE '%secure client%' OR LOWER(package_name) LIKE '%vpn%')
```
## parallel-leads
<!-- Search for sign-in and execution leads -->
parallel:
- → rare-unprotected-logons
- → detect-implant-execution
join: → triage-verdict
## rare-unprotected-logons
<!-- Rare remote sign-ins without MFA -->
Find successful remote logons that lacked MFA and are rare across the fleet, suggesting a possible beachhead.
```sqlite target=identity role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
compare: first_seen
window: '{{lookback_days}}d'
expected: A row identifies a user and IP that logged in successfully without MFA to
only one or two hosts. Fleet-wide logins are likely authorized exceptions.
prevalence:
by: device_hostname
key:
- actor_user_name
- src_endpoint_ip
rare_below: 3
reads:
- actor_user_name
- device_hostname
- event_type
- logon_type
- mfa
- src_endpoint_ip
- status_id
- time
silence: not_evidence_of_absence
source: hb_auth_signin
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT actor_user_name, src_endpoint_ip, device_hostname, logon_type, MIN(time) AS first_seen, COUNT(DISTINCT device_hostname) AS host_count FROM hb_auth_signin WHERE (mfa = 'false' OR mfa IS NULL) AND status_id = 1 AND (LOWER(logon_type) IN ('remote interactive', 'network') OR LOWER(event_type) LIKE '%vpn%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, src_endpoint_ip HAVING host_count <= 2
```
## detect-implant-execution
<!-- Implant execution from Talos research -->
Identify the execution of specific binaries and red-team tools used by ransomware actors.
```sqlite target=endpoint role=detection-candidate params=(lookback_days=lookback_days, malicious_filenames=malicious_filenames, scope_hosts=scope_hosts)
~~~yaml
expected: Process events for known AdaptixC2 or Procpatcher filenames. Any hit on
a host from the scoping step is a high-confidence lead.
reads:
- device_hostname
- process_cmd_line
- process_name
- process_original_file_name
- time
- user_name
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, process_name, process_cmd_line, process_original_file_name, user_name, time FROM hb_process_activity WHERE (instr(',' || LOWER('{{malicious_filenames}}') || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || LOWER('{{malicious_filenames}}') || ',', ',' || LOWER(process_original_file_name) || ',') > 0 OR instr(LOWER(process_cmd_line), 'content.js') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```
## triage-verdict
<!-- Triage access and execution -->
```agent target=hunter
cite: required
context:
- rare-unprotected-logons
- detect-implant-execution
max_iterations: 4
objective: Determine if any host showing unprotected VPN sign-ins subsequently executed
malicious binaries identified in the Talos report within a 24-hour window.
success_criteria: A per-host verdict of malicious, suspicious, or benign based on
temporal correlation between access and execution.
tools:
- endpoint
- identity
```
## route
<!-- Route on triage verdict -->
if~: "the triage verdict is malicious for at least one host correlating remote access and red-team tooling" (confidence: high, judge=hunter)
then: → isolate-host
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: mfa-reporting-gap)
else: → close-out
## isolate-host
<!-- Isolate compromised host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host and revoke the credentials of the user account found in the sign-in query. Collect the malicious binary for further analysis.
```
→ analyst-review
## analyst-review
<!-- Analyst review -->
```manual target=analyst
Review the cited rows. Verify if the source IP of the sign-in is known-malicious or geolocates to an unusual region. Check for secondary persistence like new services or scheduled tasks.
```
→ close-out
## close-out
<!-- Close out -->
```manual target=analyst
Document the findings. If the hunt was negative, confirm that remote services are strictly following MFA policies and identify any administrative accounts that should be enrolled.
```
→ end
Run it
Take this hunt into your environment.
Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.
Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.