{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "External remote services remain a critical entry point; a multi-surface hunt is required to distinguish legitimate administration from unauthorized persistence using the same tools."
      },
      "name": "Remote access and persistence via scheduled tasks",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1133",
        "attack.t1053.005",
        "execution",
        "initial access",
        "persistence"
      ],
      "related": [
        {
          "hunt": "registry-persistence-via-uncommon-tools",
          "reason": "Attackers may also persist via Run keys which requires hb_registry_activity.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        },
        "identity": {
          "name": "Identity / sign-in telemetry",
          "category": "identity",
          "telemetry": [
            "identity"
          ]
        }
      },
      "analysis": "A standard rule cannot differentiate between an IT admin using a management tool and an attacker using it after a geographic sign-in anomaly; this hunt uses multi-step correlation and fleet-wide prevalence to provide the necessary context.",
      "coverage": [
        {
          "stage": "external-remote-access",
          "steps": [
            "scoping-remote-logons"
          ],
          "status": "covered"
        },
        {
          "stage": "remote-admin-tool-execution",
          "steps": [
            "rare-admin-tools"
          ],
          "status": "covered"
        },
        {
          "stage": "scheduled-task-persistence",
          "steps": [
            "new-scripted-tasks"
          ],
          "status": "covered"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "External Remote Service Access",
            "slug": "external-remote-access",
            "tactic": "initial-access",
            "techniques": [
              "T1133"
            ],
            "observables": [
              "VPN connections",
              "logins from supplier remote services",
              "administrative activity from unusual geographic locations or corporate networks"
            ]
          },
          {
            "name": "Remote Administration Tool Execution",
            "slug": "remote-admin-tool-execution",
            "tactic": "execution",
            "techniques": [
              "T1133"
            ],
            "observables": [
              "execution of remote administration software",
              "unusual administrative commands",
              "network traffic from management tools to unexpected endpoints"
            ]
          },
          {
            "name": "Persistence via Scheduled Task",
            "slug": "scheduled-task-persistence",
            "tactic": "persistence",
            "techniques": [
              "T1053.005"
            ],
            "observables": [
              "schtasks.exe",
              "creation of new scheduled tasks by service accounts",
              "tasks running recurring scripts or admin binaries",
              "C:\\Windows\\System32\\Tasks"
            ]
          }
        ],
        "summary": "This campaign involves attackers gaining initial access via external remote services like VPNs, followed by the execution of remote administration tools to manage the environment and establishing long-term persistence using scheduled tasks."
      },
      "severity": "medium",
      "rationale": "Focus on administrative users and hosts with direct internet exposure first. Ensure the permitted_countries list is customized for the specific organization or business unit being hunted. Include rows where country data is missing to capture masked origins.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An attacker has gained access via an external remote service and established persistence using a scheduled task that executes a remote administration tool or a malicious script.",
      "parameters": {
        "scope_hosts": {
          "from": {
            "ref": "analyst-scoping",
            "kind": "manual",
            "observed": "2024-01-01"
          },
          "type": "list[host]",
          "default": [],
          "description": "Optional list of hosts from the lead query to focus the fan-out."
        },
        "lookback_days": {
          "from": {
            "ref": "hunt-standard",
            "kind": "manual",
            "observed": "2024-01-01"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "remote_admin_tools": {
          "from": {
            "ref": "sekoia-blog",
            "kind": "article",
            "observed": "2026-09-10"
          },
          "type": "list[string]",
          "default": [
            "anydesk.exe",
            "teamviewer.exe",
            "screenconnect.exe",
            "rustdesk.exe",
            "logmein.exe"
          ],
          "description": "Common remote management tool filenames to flag."
        },
        "permitted_countries": {
          "from": {
            "ref": "soc-policy",
            "kind": "manual",
            "observed": "2024-01-01"
          },
          "type": "list[string]",
          "default": [
            "US",
            "GB",
            "FR",
            "DE"
          ],
          "description": "ISO country codes where logins are expected."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.sekoia.com/blog/why-multi-tenant-socs-need-multi-level-agents",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.sekoia.com/blog/why-multi-tenant-socs-need-multi-level-agents",
          "name": "Sekoia \u2014 Why One SOC Agent Is Not Enough for Every Customer"
        }
      ],
      "blind_spots": [
        {
          "id": "no-geo-data",
          "risk": "A login from a proxy or VPN originating from a permitted country will bypass the lead query.",
          "owner": "Identity Provider Team",
          "stage": "external-remote-access",
          "question": "whether the source location is actually unauthorized",
          "requires": "IP-to-location enrichment in hb_auth_signin",
          "remediation": "Enable high-fidelity geo-enrichment on the auth logging service."
        },
        {
          "id": "no-endpoint-visibility",
          "risk": "An intruder on a server without a functioning agent will persist invisibly through the scheduler.",
          "owner": "IT Operations",
          "stage": "scheduled-task-persistence",
          "question": "whether the host is reporting its task configuration",
          "requires": "endpoint agent reporting hb_scheduled_job",
          "remediation": "Audit endpoint agent health and coverage on all outward-facing servers."
        }
      ]
    },
    "name": "Remote access and persistence via scheduled tasks",
    "description": "This hunt identifies potential intruders who use external-facing services for initial entry, followed by the installation of persistence via Windows Task Scheduler. It follows a gated flow: a cheap lead query first identifies successful logins from unauthorized geographic locations or potential VPN services. If an agent confirms the risk, the hunt fans out to gather evidence of newly created scheduled tasks running scripts and the execution of rare remote management tools across the fleet. A final triage weighs the combined evidence to determine if an intrusion chain is active."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "coverage": [
          {
            "stage": "external-remote-access",
            "steps": [
              "scoping-remote-logons"
            ],
            "status": "covered"
          },
          {
            "stage": "remote-admin-tool-execution",
            "steps": [
              "rare-admin-tools"
            ],
            "status": "covered"
          },
          {
            "stage": "scheduled-task-persistence",
            "steps": [
              "new-scripted-tasks"
            ],
            "status": "covered"
          }
        ],
        "rationale": "An attacker has gained access via an external remote service and established persistence using a scheduled task that executes a remote administration tool or a malicious script.",
        "blind_spots": [
          {
            "id": "no-geo-data",
            "risk": "A login from a proxy or VPN originating from a permitted country will bypass the lead query.",
            "owner": "Identity Provider Team",
            "stage": "external-remote-access",
            "question": "whether the source location is actually unauthorized",
            "requires": "IP-to-location enrichment in hb_auth_signin",
            "remediation": "Enable high-fidelity geo-enrichment on the auth logging service."
          },
          {
            "id": "no-endpoint-visibility",
            "risk": "An intruder on a server without a functioning agent will persist invisibly through the scheduler.",
            "owner": "IT Operations",
            "stage": "scheduled-task-persistence",
            "question": "whether the host is reporting its task configuration",
            "requires": "endpoint agent reporting hb_scheduled_job",
            "remediation": "Audit endpoint agent health and coverage on all outward-facing servers."
          }
        ],
        "scoping_notes": "Focus on administrative users and hosts with direct internet exposure first. Ensure the permitted_countries list is customized for the specific organization or business unit being hunted. Include rows where country data is missing to capture masked origins.",
        "beyond_detection": "A standard rule cannot differentiate between an IT admin using a management tool and an attacker using it after a geographic sign-in anomaly; this hunt uses multi-step correlation and fleet-wide prevalence to provide the necessary context."
      }
    },
    {
      "id": "scoping-remote-logons",
      "type": "query",
      "label": "Suspicious Remote Service Logons",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "identity",
        "content": "SELECT device_hostname, actor_user_name, src_endpoint_ip, src_location_country, logon_type, auth_protocol, time FROM hb_auth_signin WHERE status_id = 1 AND (src_location_country IS NULL OR instr(',' || '{{permitted_countries}}' || ',', ',' || src_location_country || ',') = 0) AND (logon_type IN ('Remote Interactive', 'Network') OR LOWER(auth_protocol) LIKE '%vpn%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_auth_signin",
        "description": "Identify successful logins from unauthorized countries or potential VPN protocols that could represent a beachhead.",
        "expected_signal": "Rows show logins from non-permitted countries or unknown origins. Silence suggests no geographic anomalies occurred during the window."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Suspicious Remote Service Logons",
        "reads": [
          "device_hostname",
          "actor_user_name",
          "src_endpoint_ip",
          "src_location_country",
          "logon_type",
          "auth_protocol",
          "time"
        ],
        "source": "hb_auth_signin",
        "target": "identity",
        "content": "SELECT device_hostname, actor_user_name, src_endpoint_ip, src_location_country, logon_type, auth_protocol, time FROM hb_auth_signin WHERE status_id = 1 AND (src_location_country IS NULL OR instr(',' || '{{permitted_countries}}' || ',', ',' || src_location_country || ',') = 0) AND (logon_type IN ('Remote Interactive', 'Network') OR LOWER(auth_protocol) LIKE '%vpn%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Rows show logins from non-permitted countries or unknown origins. Silence suggests no geographic anomalies occurred during the window.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "evaluate-lead",
      "type": "analytic",
      "label": "Evaluate Logon Lead",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity"
        ],
        "context": [
          "scoping-remote-logons"
        ],
        "objective": "Determine if any successful sign-ins represent unauthorized access by reviewing the source country and actor history.",
        "description": "Judge if the geographic or service anomalies warrant an expensive fan-out into persistence activity.",
        "max_iterations": 3,
        "expected_signal": "A risk verdict on the identified logons.",
        "success_criteria": "A per-host verdict on whether the login is suspicious."
      },
      "parents": [
        {
          "id": "scoping-remote-logons"
        }
      ]
    },
    {
      "id": "gate-on-lead",
      "type": "checkpoint",
      "label": "Gate on Risk",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "The evaluate-lead agent identifies a session as suspicious or from an unauthorized location.",
        "condition": "The evaluate-lead agent identifies a session as suspicious or from an unauthorized location.",
        "blind_spot": "no-geo-data",
        "confidence": "high",
        "description": "Route to the fan-out only if a real risk is identified, saving telemetry costs.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "evaluate-lead"
        }
      ]
    },
    {
      "id": "new-scripted-tasks",
      "type": "query",
      "label": "New Scripted Scheduled Tasks",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, job_name, job_cmd_line, job_user_name, time FROM hb_scheduled_job WHERE activity_id = 1 AND (LOWER(job_cmd_line) LIKE '%powershell%' OR LOWER(job_cmd_line) LIKE '%cmd.exe%' OR LOWER(job_cmd_line) LIKE '%cscript%' OR LOWER(job_cmd_line) LIKE '%wscript%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_scheduled_job",
        "description": "Identify new tasks that execute script interpreters often used for persistence.",
        "expected_signal": "A list of new scripted tasks. Suspicious matches include commands that download and execute code."
      },
      "parents": [
        {
          "id": "gate-on-lead",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "New Scripted Scheduled Tasks",
        "reads": [
          "device_hostname",
          "job_name",
          "job_cmd_line",
          "job_user_name",
          "time"
        ],
        "source": "hb_scheduled_job",
        "target": "endpoint",
        "content": "SELECT device_hostname, job_name, job_cmd_line, job_user_name, time FROM hb_scheduled_job WHERE activity_id = 1 AND (LOWER(job_cmd_line) LIKE '%powershell%' OR LOWER(job_cmd_line) LIKE '%cmd.exe%' OR LOWER(job_cmd_line) LIKE '%cscript%' OR LOWER(job_cmd_line) LIKE '%wscript%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "A list of new scripted tasks. Suspicious matches include commands that download and execute code.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "rare-admin-tools",
      "type": "query",
      "label": "Rare Remote Administration Tools",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT LOWER(process_name) AS tool_path, process_original_file_name, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_process_activity WHERE (instr(',' || '{{remote_admin_tools}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0 OR instr(',' || '{{remote_admin_tools}}' || ',', ',' || LOWER(process_name) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY tool_path, process_original_file_name HAVING hosts <= 3 ORDER BY hosts ASC",
        "surface": "hb_process_activity",
        "description": "Find rare execution of management tools by matching basenames or paths against the known tool list.",
        "expected_signal": "Tools appearing on very few hosts. A tool used fleet-wide is likely a business standard; a tool on one host is a lead."
      },
      "parents": [
        {
          "id": "gate-on-lead",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare Remote Administration Tools",
        "reads": [
          "process_name",
          "process_original_file_name",
          "device_hostname",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT LOWER(process_name) AS tool_path, process_original_file_name, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_process_activity WHERE (instr(',' || '{{remote_admin_tools}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0 OR instr(',' || '{{remote_admin_tools}}' || ',', ',' || LOWER(process_name) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY tool_path, process_original_file_name HAVING hosts <= 3 ORDER BY hosts ASC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Tools appearing on very few hosts. A tool used fleet-wide is likely a business standard; a tool on one host is a lead.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_original_file_name"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "triage-intrusion",
      "type": "analytic",
      "label": "Triage Intrusion Chain",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity"
        ],
        "context": [
          "evaluate-lead",
          "new-scripted-tasks",
          "rare-admin-tools"
        ],
        "objective": "Determine if the suspicious logon identified earlier correlates with the creation of a task or the execution of a rare management tool on the same host.",
        "description": "Correlate the access lead with the persistence evidence to confirm an active breach.",
        "max_iterations": 6,
        "expected_signal": "A high-confidence verdict per host.",
        "success_criteria": "A malicious, suspicious, or benign verdict citing the cross-surface rows."
      },
      "parents": [
        {
          "id": "new-scripted-tasks",
          "kind": "merge"
        },
        {
          "id": "rare-admin-tools",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on Verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "The triage-intrusion verdict is malicious for at least one host.",
        "condition": "The triage-intrusion verdict is malicious for at least one host.",
        "blind_spot": "no-endpoint-visibility",
        "confidence": "high",
        "description": "Trigger isolation for malicious findings or close out benign ones.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-intrusion"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate Host",
      "config": {
        "target": "endpoint",
        "description": "Immediately contain the breach to prevent data exfiltration.",
        "instructions": "Isolate the host and rotate the credentials for the account involved in the suspicious logon.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Analyst Review",
      "config": {
        "assignee": "analyst",
        "description": "Verify the agent findings and adjust the local context as needed.",
        "instructions": "Review the cited rows. Determine if the identified remote management tool is an undocumented but approved tool for this specific business unit. Update the parameters if needed."
      },
      "parents": [
        {
          "id": "gate-on-lead",
          "branch": "default"
        },
        {
          "id": "gate-on-lead",
          "branch": "on_unavailable"
        },
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close Out",
      "config": {
        "assignee": "analyst",
        "description": "Document the negative result or the non-malicious findings.",
        "instructions": "Record the results. If common false positives were found, update the remote_admin_tools list to exclude them from future runs."
      },
      "parents": [
        {
          "id": "gate-on-lead",
          "branch": "on_refutes"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        }
      ]
    }
  ]
}