{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "The theft of millions of patient records through vishing-driven SSO takeover is a confirmed high-impact threat; verifying the integrity of MFA-less sessions is a business requirement."
      },
      "name": "SSO Takeover and Data Impact",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1555",
        "attack.t1486",
        "attack.t1566"
      ],
      "series": {
        "slug": "the-story-behind-the-intelligence",
        "index": 2,
        "title": "The story behind the intelligence",
        "total": 2
      },
      "related": [
        {
          "hunt": "infostealer-browser-artifact-cleanup",
          "reason": "Identifying the initial infostealer malware that harvested the credentials is the focus of a separate hunt.",
          "relation": "out-of-scope-alternative"
        },
        {
          "hunt": "infostealer-execution-browser-credential-harvesting",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        },
        "identity": {
          "name": "Identity / sign-in telemetry",
          "category": "identity",
          "telemetry": [
            "identity"
          ]
        }
      },
      "analysis": "Detecting every new Okta login location creates significant noise. This hunt solves that by pivoting to cross-surface behavioral impact\u2014bulk cloud API reads and ransomware command-line markers\u2014to confirm intent.",
      "coverage": [
        {
          "stage": "credential-access-sso-takeover",
          "steps": [
            "okta-mfa-less-logons"
          ],
          "status": "covered"
        },
        {
          "stage": "impact-data-theft-and-encryption",
          "steps": [
            "bulk-data-access",
            "ransomware-behavioral-markers"
          ],
          "status": "covered"
        },
        {
          "stage": "initial-access-social-engineering",
          "reason": "Belongs to another part of the 'The story behind the intelligence' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "execution-infostealer-malware",
          "reason": "Belongs to another part of the 'The story behind the intelligence' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "credential-access-browser-harvesting",
          "reason": "Belongs to another part of the 'The story behind the intelligence' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Vishing and Phishing Kits",
            "slug": "initial-access-social-engineering",
            "tactic": "initial-access",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "vishing calls to employees",
              "obfuscated JavaScript phishing kits",
              "content.js",
              "malicious unofficial downloads"
            ]
          },
          {
            "name": "Infostealer and Tool Execution",
            "slug": "execution-infostealer-malware",
            "tactic": "execution",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "VID001.exe",
              "NetGuard.exe",
              "SECOH-QAD.exe",
              "sample.exe",
              "d4aa3e7010220ad1b458fac17039c274_62_Exe.exe",
              "w32.9f1f11a708-100.sbx.tg",
              "win.dropper.miner"
            ]
          },
          {
            "name": "Browser Credential and Cookie Harvesting",
            "slug": "credential-access-browser-harvesting",
            "tactic": "credential-access",
            "techniques": [
              "T1555"
            ],
            "observables": [
              "saved browser passwords",
              "browser login cookies",
              "credentials for local applications"
            ]
          },
          {
            "name": "Okta SSO Account Takeover",
            "slug": "credential-access-sso-takeover",
            "tactic": "credential-access",
            "techniques": [
              "T1555"
            ],
            "observables": [
              "stolen credentials used for Okta single sign-on accounts",
              "unauthorized Okta session established"
            ]
          },
          {
            "name": "Data Exfiltration and Ransomware",
            "slug": "impact-data-theft-and-encryption",
            "tactic": "impact",
            "techniques": [
              "T1486"
            ],
            "observables": [
              "284 million patient records stolen",
              "Azim sucks text string in ransomware code",
              "unauthorized file encryption"
            ]
          }
        ],
        "summary": "Threat actors such as ShinyHunters leverage vishing and obfuscated JavaScript phishing kits to harvest credentials and session cookies from employees. These stolen identities are then utilized to bypass Okta SSO protections, enabling large-scale data exfiltration and the deployment of infostealers or ransomware."
      },
      "severity": "high",
      "rationale": "Focus the initial lead query on successful Okta sign-ins. If results are sparse, widen the scope to include failed logins with status_detail indicating MFA was required but not completed.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary has bypassed SSO protections using stolen credentials and is now performing bulk data exfiltration or deploying ransomware across the environment.",
      "parameters": {
        "scope_hosts": {
          "from": {
            "ref": "hunt-input",
            "kind": "manual",
            "observed": "2026-09-03"
          },
          "type": "list[host]",
          "default": [],
          "description": "List of hostnames identified in the lead query to focus the search; leave empty to scan the entire estate."
        },
        "lookback_days": {
          "from": {
            "ref": "standard-retention",
            "kind": "manual",
            "observed": "2026-09-03"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "impact_markers": {
          "from": {
            "ref": "talos-beers-with-talos",
            "kind": "article",
            "observed": "2026-09-03"
          },
          "type": "list[string]",
          "default": [
            "vssadmin.exe",
            "wbadmin.exe",
            "bcdedit.exe",
            "cipher.exe"
          ],
          "description": "Process names associated with shadow copy deletion or volume modification during ransomware impact."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://blog.talosintelligence.com/the-story-behind-the-intelligence/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://blog.talosintelligence.com/the-story-behind-the-intelligence/",
          "name": "Cisco Talos \u2014 The story behind the intelligence"
        }
      ],
      "blind_spots": [
        {
          "id": "limited-endpoint-visibility",
          "risk": "A host without process logging could perform mass encryption without being detected by the behavioral query.",
          "stage": "impact-data-theft-and-encryption",
          "question": "whether ransomware markers exist on hosts without EDR coverage",
          "requires": "hb_process_activity with command line support on all hosts"
        },
        {
          "id": "vishing-visibility",
          "risk": "The hunt can see the successful takeover login but lacks visibility into the social engineering attempt that preceded it.",
          "stage": "credential-access-sso-takeover",
          "question": "the initial vishing call that enabled the credential theft",
          "requires": "corporate VOIP or phone logs"
        }
      ]
    },
    "name": "SSO Takeover and Data Impact",
    "description": "This hunt investigates the critical sequence from identity compromise to high-impact data operations. It starts by identifying successful Okta sign-ins that occurred without MFA, establishing a baseline of potentially compromised accounts and the hosts used for access. The hunt then branches into two parallel investigations of adversary intent: mass data access in cloud environments and the presence of ransomware-specific process markers on the identified hosts. An agent evaluates the combined evidence to determine if the sign-ins correlate with malicious impact, specifically looking for actor-specific strings like azim sucks and bulk record theft."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "the-story-behind-the-intelligence",
          "index": 2,
          "title": "The story behind the intelligence",
          "total": 2
        },
        "coverage": [
          {
            "stage": "credential-access-sso-takeover",
            "steps": [
              "okta-mfa-less-logons"
            ],
            "status": "covered"
          },
          {
            "stage": "impact-data-theft-and-encryption",
            "steps": [
              "bulk-data-access",
              "ransomware-behavioral-markers"
            ],
            "status": "covered"
          },
          {
            "stage": "initial-access-social-engineering",
            "reason": "Belongs to another part of the 'The story behind the intelligence' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "execution-infostealer-malware",
            "reason": "Belongs to another part of the 'The story behind the intelligence' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "credential-access-browser-harvesting",
            "reason": "Belongs to another part of the 'The story behind the intelligence' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary has bypassed SSO protections using stolen credentials and is now performing bulk data exfiltration or deploying ransomware across the environment.",
        "blind_spots": [
          {
            "id": "limited-endpoint-visibility",
            "risk": "A host without process logging could perform mass encryption without being detected by the behavioral query.",
            "stage": "impact-data-theft-and-encryption",
            "question": "whether ransomware markers exist on hosts without EDR coverage",
            "requires": "hb_process_activity with command line support on all hosts"
          },
          {
            "id": "vishing-visibility",
            "risk": "The hunt can see the successful takeover login but lacks visibility into the social engineering attempt that preceded it.",
            "stage": "credential-access-sso-takeover",
            "question": "the initial vishing call that enabled the credential theft",
            "requires": "corporate VOIP or phone logs"
          }
        ],
        "scoping_notes": "Focus the initial lead query on successful Okta sign-ins. If results are sparse, widen the scope to include failed logins with status_detail indicating MFA was required but not completed.",
        "beyond_detection": "Detecting every new Okta login location creates significant noise. This hunt solves that by pivoting to cross-surface behavioral impact\u2014bulk cloud API reads and ransomware command-line markers\u2014to confirm intent."
      }
    },
    {
      "id": "okta-mfa-less-logons",
      "type": "query",
      "label": "Identify MFA-less Okta sign-ins",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "identity",
        "content": "SELECT device_hostname, actor_user_name, src_endpoint_ip, event_type, mfa, time FROM hb_auth_signin WHERE provider = 'okta' AND status_id = 1 AND (mfa IS NULL OR mfa = 'false' OR mfa = 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_auth_signin",
        "description": "Identify successful Okta logins where MFA was not utilized, establishing a lead for potential account takeover using stolen credentials.",
        "expected_signal": "A list of hostnames and usernames that successfully authenticated without MFA. Silence means every successful Okta login during the window recorded an MFA check."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify MFA-less Okta sign-ins",
        "reads": [
          "device_hostname",
          "actor_user_name",
          "src_endpoint_ip",
          "event_type",
          "mfa",
          "time"
        ],
        "source": "hb_auth_signin",
        "target": "identity",
        "content": "SELECT device_hostname, actor_user_name, src_endpoint_ip, event_type, mfa, time FROM hb_auth_signin WHERE provider = 'okta' AND status_id = 1 AND (mfa IS NULL OR mfa = 'false' OR mfa = 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hostnames and usernames that successfully authenticated without MFA. Silence means every successful Okta login during the window recorded an MFA check.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "bulk-data-access",
      "type": "query",
      "label": "Detect bulk cloud read operations",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT actor_user_name, api_operation, COUNT(*) AS call_count, MIN(time) AS first_seen FROM hb_cloud_api_activity WHERE activity_id = 2 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, api_operation HAVING call_count > 1000 ORDER BY call_count DESC",
        "surface": "hb_cloud_api_activity",
        "description": "Find users performing an unusually high volume of read operations, which is indicative of automated exfiltration following an SSO takeover.",
        "expected_signal": "Specific accounts making thousands of read requests in a short window. Silence indicates no mass-read behavior was recorded."
      },
      "parents": [
        {
          "id": "okta-mfa-less-logons"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Detect bulk cloud read operations",
        "reads": [
          "actor_user_name",
          "api_operation",
          "time"
        ],
        "source": "hb_cloud_api_activity",
        "target": "endpoint",
        "content": "SELECT actor_user_name, api_operation, COUNT(*) AS call_count, MIN(time) AS first_seen FROM hb_cloud_api_activity WHERE activity_id = 2 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, api_operation HAVING call_count > 1000 ORDER BY call_count DESC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Specific accounts making thousands of read requests in a short window. Silence indicates no mass-read behavior was recorded.",
        "verified": "dry-run",
        "prevalence": {
          "by": "api_operation",
          "key": [
            "actor_user_name"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "ransomware-behavioral-markers",
      "type": "query",
      "label": "Ransomware behavioral markers",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, user_name, process_name, process_cmd_line, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{impact_markers}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR LOWER(process_cmd_line) LIKE '%azim%sucks%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Identify process execution that matches common ransomware patterns or contains actor-specific strings on the scoped hosts.",
        "expected_signal": "Rows containing ransomware utility execution or the specific azim sucks string. Silence suggests no such markers were observed on the specified hosts."
      },
      "parents": [
        {
          "id": "okta-mfa-less-logons"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Ransomware behavioral markers",
        "reads": [
          "device_hostname",
          "user_name",
          "process_name",
          "process_cmd_line",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, user_name, process_name, process_cmd_line, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{impact_markers}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR LOWER(process_cmd_line) LIKE '%azim%sucks%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Rows containing ransomware utility execution or the specific azim sucks string. Silence suggests no such markers were observed on the specified hosts.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "triage-agent",
      "type": "analytic",
      "label": "Weigh sign-in and impact evidence",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity"
        ],
        "context": [
          "okta-mfa-less-logons",
          "bulk-data-access",
          "ransomware-behavioral-markers"
        ],
        "objective": "Determine if any host or user account from the lead query is responsible for the bulk cloud reads or endpoint ransomware markers.",
        "description": "Correlate the MFA-less identity leads with subsequent cloud exfiltration or ransomware execution markers.",
        "max_iterations": 4,
        "expected_signal": "A per-host verdict that evaluates the link between the compromised account and the observed impact.",
        "success_criteria": "A verdict of malicious, suspicious, or benign per host, citing the exact rows from all context steps."
      },
      "parents": [
        {
          "id": "bulk-data-access",
          "kind": "merge"
        },
        {
          "id": "ransomware-behavioral-markers",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "response-decision",
      "type": "checkpoint",
      "label": "Route on triage verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage-agent verdict is malicious for at least one host or user",
        "condition": "the triage-agent verdict is malicious for at least one host or user",
        "blind_spot": "limited-endpoint-visibility",
        "confidence": "high",
        "description": "Direct the response based on the agent's confidence in the identity-to-impact intrusion chain.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-agent"
        }
      ]
    },
    {
      "id": "isolate-endpoint",
      "type": "action",
      "label": "Isolate compromised host",
      "config": {
        "target": "endpoint",
        "description": "Prevent further encryption or data exfiltration by removing the confirmed beachhead from the network.",
        "instructions": "Isolate the identified host and revoke the associated Okta session and user credentials.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "response-decision",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-forensic-review",
      "type": "task",
      "label": "Analyst forensic review",
      "config": {
        "assignee": "analyst",
        "description": "Verify the agent's correlation and perform manual investigation into the specific objects accessed in the cloud.",
        "instructions": "Examine the specific S3 buckets or mailbox objects accessed in the bulk-data-access query and verify the integrity of the process binaries that emitted ransomware markers."
      },
      "parents": [
        {
          "id": "response-decision",
          "branch": "default"
        },
        {
          "id": "response-decision",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-endpoint"
        }
      ]
    },
    {
      "id": "close-out-hunt",
      "type": "task",
      "label": "Close out hunt",
      "config": {
        "assignee": "analyst",
        "description": "Record final dispositions and document telemetry gaps identified during the hunt.",
        "instructions": "Summarize the number of MFA-less logins analyzed and identify any regions or accounts missing hb_cloud_api_activity coverage."
      },
      "parents": [
        {
          "id": "response-decision",
          "branch": "on_refutes"
        },
        {
          "id": "analyst-forensic-review"
        }
      ]
    }
  ]
}