{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Professional social engineering lures are effective at bypassing technical perimeters; a phased hunt that connects human-initiated execution with advanced evasion and theft is required to protect high-access personnel."
      },
      "name": "Socially Engineered Endpoint Infection and Evasion",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1566",
        "attack.t1204",
        "attack.t1562.001",
        "attack.t1555",
        "attack.t1071"
      ],
      "series": {
        "slug": "trust-and-the-enticing-consultancy-offer",
        "index": 1,
        "title": "Trust and the enticing consultancy offer",
        "total": 2
      },
      "related": [
        {
          "hunt": "autonomous-ai-malware-analysis",
          "reason": "The dossier mentions CLOSEDQUORUM, which represents a separate autonomous AI C2 phase follow-on to initial infection.",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A simple detection rule for these hashes is easily defeated by the attacker re-building the trojanised installer. This hunt correlates the specific lure behavior (parents, paths) with subsequent kernel-level evasion and credential theft patterns across multiple surfaces.",
      "coverage": [
        {
          "stage": "social-engineering-elicitation",
          "reason": "Initial social media messaging occurs off-network and is not captured in internal telemetry.",
          "status": "not_visible",
          "blind_spot": "external-lure-blindness"
        },
        {
          "stage": "trojanised-software-execution",
          "steps": [
            "scope-potential-infections",
            "lure-execution-behavior",
            "file-drops-by-lure"
          ],
          "status": "covered"
        },
        {
          "stage": "defense-evasion-edr-killer",
          "steps": [
            "edr-killer-driver-loads"
          ],
          "status": "covered"
        },
        {
          "stage": "credential-access-infostealer",
          "steps": [
            "browser-credential-theft"
          ],
          "status": "covered"
        },
        {
          "stage": "command-and-control-autonomous-ai",
          "reason": "Belongs to another part of the 'Trust and the enticing consultancy offer' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "impact-ransomware-encryption",
          "reason": "Belongs to another part of the 'Trust and the enticing consultancy offer' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Consultancy and Job Lure",
            "slug": "social-engineering-elicitation",
            "tactic": "initial-access",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "Social media messages offering $300/hour for consultancy",
              "Sparse consultant profiles with no employer footprint",
              "Fake job offers requiring candidate software installation"
            ]
          },
          {
            "name": "Execution of Trojanised Installer",
            "slug": "trojanised-software-execution",
            "tactic": "execution",
            "techniques": [
              "T1204",
              "T1566"
            ],
            "observables": [
              "Fake LastPass Authenticator installers",
              "SECOH-QAD.exe",
              "KMSAuto.exe",
              "sample.exe",
              "f_000bc7.exe",
              "content.js",
              "Distribution via GitHub repositories"
            ]
          },
          {
            "name": "Kernel-Level Security Evasion",
            "slug": "defense-evasion-edr-killer",
            "tactic": "defense-evasion",
            "techniques": [
              "T1562.001"
            ],
            "observables": [
              "Rapuncel kernel-level EDR killer payload",
              "Disabling of remote access and alarms"
            ]
          },
          {
            "name": "Rapuncel Infostealing",
            "slug": "credential-access-infostealer",
            "tactic": "credential-access",
            "techniques": [
              "T1555"
            ],
            "observables": [
              "Rapuncel stealer searching for credentials",
              "Accessing protected systems via found credentials"
            ]
          },
          {
            "name": "Autonomous AI-Driven C2",
            "slug": "command-and-control-autonomous-ai",
            "tactic": "command-and-control",
            "techniques": [
              "T1071"
            ],
            "observables": [
              "CLOSEDQUORUM malware binary",
              "Delegation of actions to LLM panels via API calls",
              "Autonomous C2 decision making"
            ]
          },
          {
            "name": "Data Encryption and Impact",
            "slug": "impact-ransomware-encryption",
            "tactic": "impact",
            "techniques": [
              "T1486"
            ],
            "observables": [
              "Qilin ransomware incidents",
              "The Gentlemen leak-site listings",
              "Encryption of files and manipulation of pumping cycles in utility systems"
            ]
          }
        ],
        "summary": "This social engineering campaign targets technical professionals with fake consultancy and job offers to distribute trojanised software via platforms like GitHub. Successful infections deploy kernel-level EDR killers and 'Rapuncel' infostealers, while advanced variants utilize 'CLOSEDQUORUM' for autonomous AI-driven command-and-control before final ransomware deployment."
      },
      "severity": "high",
      "rationale": "Prioritize technical staff, project leads, and personnel with external social media presence (e.g., speakers, researchers) who are high-value targets for consultancy lures.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An attacker uses social engineering lures such as consultancy offers to trick users into running trojanised software that installs an EDR killer and steals credentials.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Filter results to these hosts; leave empty to hunt across the entire estate."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine for lure execution and follow-on activity."
        },
        "known_browsers": {
          "type": "list[string]",
          "default": [
            "chrome.exe",
            "msedge.exe",
            "firefox.exe",
            "brave.exe"
          ],
          "description": "Legitimate browser processes to exclude from file-read monitoring."
        },
        "lure_filenames": {
          "from": {
            "ref": "talos",
            "kind": "article",
            "observed": "2026-09-24"
          },
          "type": "list[string]",
          "default": [
            "sample.exe",
            "secoh-qad.exe",
            "f_000bc7.exe",
            "kmsauto.exe",
            "content.js"
          ],
          "description": "Filenames of lures reported in the Talos article."
        },
        "sensitive_files": {
          "from": {
            "ref": "common-browser-paths",
            "kind": "manual",
            "observed": "2026-09-24"
          },
          "type": "list[string]",
          "default": [
            "login data",
            "cookies",
            "web data",
            "local state"
          ],
          "description": "Browser data files targeted by the Rapuncel infostealer."
        },
        "malicious_hashes": {
          "from": {
            "ref": "talos",
            "kind": "article",
            "observed": "2026-09-24"
          },
          "type": "list[hash]",
          "default": [
            "9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507",
            "9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f",
            "540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8",
            "cfa1997682e4ed41bc691ba848d845abbe0b75ec97e640c2b015b4d1624a108a",
            "38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55"
          ],
          "description": "Hashes of reported trojanised software from the dossier."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://blog.talosintelligence.com/trust-and-the-enticing-consultancy-offer/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://blog.talosintelligence.com/trust-and-the-enticing-consultancy-offer/",
          "name": "Talos \u2014 Trust and the enticing consultancy offer"
        }
      ],
      "blind_spots": [
        {
          "id": "edr-blinding-gap",
          "risk": "A host that reports the initial lure execution and then stops all telemetry is likely blinded, creating a critical blind spot.",
          "stage": "defense-evasion-edr-killer",
          "question": "Did the driver successfully terminate the security agent?",
          "requires": "Endpoint telemetry persistence"
        },
        {
          "id": "external-lure-blindness",
          "risk": "Internal telemetry cannot see the conversation on social media; we only see the resulting malware execution.",
          "stage": "social-engineering-elicitation",
          "question": "What was the content of the initial social engineering lure?",
          "requires": "Social media logs"
        }
      ]
    },
    "name": "Socially Engineered Endpoint Infection and Evasion",
    "description": "This hunt follows the attack chain from the initial human-targeted social engineering lure to the execution of local payloads. It identifies the execution of reported trojanised software, correlates it with the loading of unsigned kernel drivers designed to disable security software, and detects unauthorized access to browser credential stores. By using a phased approach, the hunt connects the initial lure to subsequent high-impact evasion and theft behaviors."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "trust-and-the-enticing-consultancy-offer",
          "index": 1,
          "title": "Trust and the enticing consultancy offer",
          "total": 2
        },
        "coverage": [
          {
            "stage": "social-engineering-elicitation",
            "reason": "Initial social media messaging occurs off-network and is not captured in internal telemetry.",
            "status": "not_visible",
            "blind_spot": "external-lure-blindness"
          },
          {
            "stage": "trojanised-software-execution",
            "steps": [
              "scope-potential-infections",
              "lure-execution-behavior",
              "file-drops-by-lure"
            ],
            "status": "covered"
          },
          {
            "stage": "defense-evasion-edr-killer",
            "steps": [
              "edr-killer-driver-loads"
            ],
            "status": "covered"
          },
          {
            "stage": "credential-access-infostealer",
            "steps": [
              "browser-credential-theft"
            ],
            "status": "covered"
          },
          {
            "stage": "command-and-control-autonomous-ai",
            "reason": "Belongs to another part of the 'Trust and the enticing consultancy offer' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "impact-ransomware-encryption",
            "reason": "Belongs to another part of the 'Trust and the enticing consultancy offer' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An attacker uses social engineering lures such as consultancy offers to trick users into running trojanised software that installs an EDR killer and steals credentials.",
        "blind_spots": [
          {
            "id": "edr-blinding-gap",
            "risk": "A host that reports the initial lure execution and then stops all telemetry is likely blinded, creating a critical blind spot.",
            "stage": "defense-evasion-edr-killer",
            "question": "Did the driver successfully terminate the security agent?",
            "requires": "Endpoint telemetry persistence"
          },
          {
            "id": "external-lure-blindness",
            "risk": "Internal telemetry cannot see the conversation on social media; we only see the resulting malware execution.",
            "stage": "social-engineering-elicitation",
            "question": "What was the content of the initial social engineering lure?",
            "requires": "Social media logs"
          }
        ],
        "scoping_notes": "Prioritize technical staff, project leads, and personnel with external social media presence (e.g., speakers, researchers) who are high-value targets for consultancy lures.",
        "beyond_detection": "A simple detection rule for these hashes is easily defeated by the attacker re-building the trojanised installer. This hunt correlates the specific lure behavior (parents, paths) with subsequent kernel-level evasion and credential theft patterns across multiple surfaces."
      }
    },
    {
      "id": "scope-potential-infections",
      "type": "query",
      "label": "Scope potentially infected hosts",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_original_file_name, process_hash_sha256, COUNT(*) as execution_count FROM hb_process_activity WHERE (instr(',' || '{{malicious_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 OR instr(',' || '{{lure_filenames}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1, 2, 3",
        "surface": "hb_process_activity",
        "description": "Identify hosts that have executed binaries matching reported hashes or original filenames.",
        "expected_signal": "A list of hosts that executed known indicators. Silence proves that these specific lures did not run."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Scope potentially infected hosts",
        "reads": [
          "device_hostname",
          "process_original_file_name",
          "process_hash_sha256",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_original_file_name, process_hash_sha256, COUNT(*) as execution_count FROM hb_process_activity WHERE (instr(',' || '{{malicious_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 OR instr(',' || '{{lure_filenames}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1, 2, 3",
        "silence": "evidence_of_absence",
        "expected": "A list of hosts that executed known indicators. Silence proves that these specific lures did not run.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "lure-execution-behavior",
      "type": "query",
      "label": "Lure execution behavior",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, parent_process_name, process_hash_sha256, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{malicious_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 OR instr(',' || '{{lure_filenames}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Examine the launch context of the reported lures, including parents and command lines.",
        "expected_signal": "Execution events where parents like browser or messaging apps suggest social engineering delivery."
      },
      "parents": [
        {
          "id": "scope-potential-infections"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Lure execution behavior",
        "reads": [
          "device_hostname",
          "process_name",
          "process_original_file_name",
          "process_cmd_line",
          "parent_process_name",
          "process_hash_sha256",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, parent_process_name, process_hash_sha256, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{malicious_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 OR instr(',' || '{{lure_filenames}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Execution events where parents like browser or messaging apps suggest social engineering delivery.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "file-drops-by-lure",
      "type": "query",
      "label": "File drops by lure processes",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, file_path, file_name, process_name, file_hash_sha256, time FROM hb_file_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND instr(',' || '{{lure_filenames}}' || ',', ',' || REPLACE(LOWER(process_name), RTRIM(LOWER(process_name), REPLACE(LOWER(process_name), '\\', '')), '') || ',') > 0 AND activity_id = 1 AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_file_activity",
        "description": "Identify secondary payloads or scripts dropped by the initial lure binary.",
        "expected_signal": "Creation of new files by processes matching the lure list, indicating installer or dropper behavior."
      },
      "parents": [
        {
          "id": "scope-potential-infections"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "File drops by lure processes",
        "reads": [
          "device_hostname",
          "file_path",
          "file_name",
          "process_name",
          "file_hash_sha256",
          "time",
          "activity_id"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, file_path, file_name, process_name, file_hash_sha256, time FROM hb_file_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND instr(',' || '{{lure_filenames}}' || ',', ',' || REPLACE(LOWER(process_name), RTRIM(LOWER(process_name), REPLACE(LOWER(process_name), '\\', '')), '') || ',') > 0 AND activity_id = 1 AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Creation of new files by processes matching the lure list, indicating installer or dropper behavior.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "early-stage-read",
      "type": "analytic",
      "label": "Early stage read",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "scope-potential-infections",
          "lure-execution-behavior",
          "file-drops-by-lure"
        ],
        "objective": "Determine if the execution of reported lures is confirmed on the scoped hosts.",
        "description": "Confirm the initial execution of trojanised software before hunting follow-on stages.",
        "max_iterations": 3,
        "expected_signal": "A per-host verdict on the likelihood of initial compromise via lure.",
        "success_criteria": "A verdict citing specific process and file events."
      },
      "parents": [
        {
          "id": "lure-execution-behavior",
          "kind": "merge"
        },
        {
          "id": "file-drops-by-lure",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "edr-killer-driver-loads",
      "type": "query",
      "label": "EDR killer driver loads",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "endpoint",
        "content": "SELECT device_hostname, driver_path, driver_signature_status, driver_signature_subject, time FROM hb_kernel_extension_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (driver_signed = 'false' OR driver_signature_status != 'Valid') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_kernel_extension_activity",
        "description": "Find unsigned or suspicious drivers loading, characteristic of the Rapuncel payload.",
        "expected_signal": "Loads of unsigned drivers; these are highly anomalous and used to blind security agents."
      },
      "parents": [
        {
          "id": "early-stage-read"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "EDR killer driver loads",
        "reads": [
          "device_hostname",
          "driver_path",
          "driver_signature_status",
          "driver_signed",
          "time"
        ],
        "source": "hb_kernel_extension_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, driver_path, driver_signature_status, driver_signature_subject, time FROM hb_kernel_extension_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (driver_signed = 'false' OR driver_signature_status != 'Valid') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Loads of unsigned drivers; these are highly anomalous and used to blind security agents.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "browser-credential-theft",
      "type": "query",
      "label": "Browser credential theft",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "endpoint",
        "content": "SELECT device_hostname, file_path, file_name, process_name, time FROM hb_file_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND instr(',' || '{{sensitive_files}}' || ',', ',' || LOWER(file_name) || ',') > 0 AND NOT (instr(',' || '{{known_browsers}}' || ',', ',' || REPLACE(LOWER(process_name), RTRIM(LOWER(process_name), REPLACE(LOWER(process_name), '\\', '')), '') || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_file_activity",
        "description": "Detect unauthorized access to browser data files by non-browser processes.",
        "expected_signal": "Non-browser processes reading sensitive Login Data or Cookies files."
      },
      "parents": [
        {
          "id": "early-stage-read"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Browser credential theft",
        "reads": [
          "device_hostname",
          "file_path",
          "file_name",
          "process_name",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, file_path, file_name, process_name, time FROM hb_file_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND instr(',' || '{{sensitive_files}}' || ',', ',' || LOWER(file_name) || ',') > 0 AND NOT (instr(',' || '{{known_browsers}}' || ',', ',' || REPLACE(LOWER(process_name), RTRIM(LOWER(process_name), REPLACE(LOWER(process_name), '\\', '')), '') || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Non-browser processes reading sensitive Login Data or Cookies files.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "follow-on-read",
      "type": "analytic",
      "label": "Follow-on read",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "early-stage-read",
          "edr-killer-driver-loads",
          "browser-credential-theft"
        ],
        "objective": "Assess the relationship between initial infection (from early-stage-read) and the observed driver loads or credential access events.",
        "description": "Synthesize the entire attack chain from lure to credential theft.",
        "max_iterations": 4,
        "expected_signal": "A high-confidence assessment of the full intrusion per host.",
        "success_criteria": "A final verdict identifying compromised hosts with multiple stage hits."
      },
      "parents": [
        {
          "id": "edr-killer-driver-loads",
          "kind": "merge"
        },
        {
          "id": "browser-credential-theft",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the verdict is malicious for at least one host demonstrating multiple stages of the attack chain",
        "condition": "the verdict is malicious for at least one host demonstrating multiple stages of the attack chain",
        "blind_spot": "edr-blinding-gap",
        "confidence": "high",
        "description": "Determine whether to contain the host based on the confirmed attack chain.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "follow-on-read"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate host",
      "config": {
        "target": "endpoint",
        "description": "Halt the attack by isolating the infected endpoint.",
        "instructions": "Isolate the host and notify the user's manager of a potential social engineering incident.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Analyst review",
      "config": {
        "assignee": "analyst",
        "description": "Verify the agent's findings and document the social engineering context.",
        "instructions": "Review the process and kernel driver evidence. Interview the user to confirm the social media lure source and timing."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out",
      "config": {
        "assignee": "analyst",
        "description": "Document findings and negative results.",
        "instructions": "Log the negative results and confirm if any scoped hosts failed to report telemetry during the window."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        }
      ]
    }
  ]
}