{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Star Blizzard (FSB Centre 18) is a sophisticated actor targeting critical policy-making institutions. The RedFlick technique is designed specifically to bypass interactive detections, making a cross-surface behavioral hunt a business necessity."
      },
      "name": "Star Blizzard RedFlick VHDX and SSH-based Malware Delivery",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1566.001",
        "attack.t1566.002",
        "attack.t1204.002",
        "attack.t1059.003",
        "attack.t1105",
        "attack.t1218",
        "attack.t1053.005",
        "attack.t1218.002",
        "defense evasion",
        "execution",
        "initial access",
        "persistence"
      ],
      "related": [
        {
          "hunt": "cosmicpulse-behavioral-backdoor",
          "reason": "This hunt focuses on delivery and persistence; a subsequent hunt should examine the operational behavior of the CosmicPulse backdoor.",
          "relation": "follows"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A single rule on schtasks.exe would be too noisy. This hunt pivots between HTTP lures, hidden-window conhost scripts, and unique SSH command arguments to confirm the specific Star Blizzard infection chain.",
      "coverage": [
        {
          "stage": "phishing-initial-contact",
          "steps": [
            "phishing-contact"
          ],
          "status": "covered"
        },
        {
          "stage": "vhdx-payload-execution",
          "steps": [
            "conhost-script-execution"
          ],
          "status": "covered"
        },
        {
          "stage": "ssh-msi-delivery",
          "steps": [
            "ssh-delivery-mechanism"
          ],
          "status": "covered"
        },
        {
          "stage": "scheduled-task-persistence",
          "steps": [
            "cpl-scheduled-tasks"
          ],
          "status": "covered"
        },
        {
          "stage": "redflick-cpl-loading",
          "steps": [
            "cpl-scheduled-tasks"
          ],
          "status": "covered"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Large-scale Phishing via Compromised Infrastructure",
            "slug": "phishing-initial-contact",
            "tactic": "initial-access",
            "techniques": [
              "T1566.001",
              "T1566.002"
            ],
            "observables": [
              "ukr.net",
              "Password-protected RAR/ZIP archives",
              "Subject: \u041f\u043e\u0432\u0456\u0434\u043e\u043c\u043b\u0435\u043d\u043d\u044f \u043f\u0440\u043e \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0438 \u043f\u043e\u0434\u0430\u0442\u043a\u043e\u0432\u043e\u0457 \u043f\u0435\u0440\u0435\u0432\u0456\u0440\u043a\u0438",
              "Subject: Invitation to an IISS Private Roundtable",
              "Subject: Payment Advice Note",
              "WordPress/cPanel compromised sender accounts"
            ]
          },
          {
            "name": "Malicious VHDX and LNK Execution",
            "slug": "vhdx-payload-execution",
            "tactic": "execution",
            "techniques": [
              "T1204.002",
              "T1059.003"
            ],
            "observables": [
              "VHDX virtual disk file",
              "LNK file masquerading as PDF",
              "conhost.exe (hidden window)",
              "cmd.exe spawning BAT script"
            ]
          },
          {
            "name": "Malware Download via SSH PermitLocalCommand",
            "slug": "ssh-msi-delivery",
            "tactic": "execution",
            "techniques": [
              "T1105",
              "T1218"
            ],
            "observables": [
              "ssh.exe",
              "-o PermitLocalCommand=yes",
              "Execution of remote MSI installer"
            ]
          },
          {
            "name": "Persistence via MSI Installed Task",
            "slug": "scheduled-task-persistence",
            "tactic": "persistence",
            "techniques": [
              "T1053.005"
            ],
            "observables": [
              "schtasks.exe /create",
              "msiexec.exe execution"
            ]
          },
          {
            "name": "RedFlick Loader Execution via Control Panel Applet",
            "slug": "redflick-cpl-loading",
            "tactic": "defense-evasion",
            "techniques": [
              "T1218.002"
            ],
            "observables": [
              "control.exe",
              ".cpl file extension",
              "Remote URL for CPL download",
              "CosmicPulse backdoor"
            ]
          }
        ],
        "summary": "Russian state actor Star Blizzard conducts large-scale phishing campaigns using compromised WordPress and cPanel sites to deliver password-protected archives containing malicious VHDX files. These files initiate an execution chain involving BAT scripts and ssh.exe to download an MSI, which then establishes persistence via a scheduled task that leverages control.exe to execute the RedFlick loader and CosmicPulse backdoor disguised as a Control Panel applet."
      },
      "severity": "high",
      "rationale": "Focus on workstations of researchers, diplomatic staff, and NGOs. Broaden the query if initial HTTP hits are missing, as the actor rotates compromised domains frequently.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary has gained initial access via phishing and is using the RedFlick technique to deliver a backdoor through VHDX-mounted scripts, SSH-based MSI downloads, and CPL-driven scheduled tasks.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Optional list of hosts to narrow follow-on stages based on initial leads."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "campaign_domains": {
          "from": {
            "ref": "msrc-blog-star-blizzard-2026",
            "kind": "article",
            "observed": "2026-09-29"
          },
          "type": "list[domain]",
          "default": [
            "ukr.net"
          ],
          "description": "Domains associated with the initial phishing contact and compromised accounts."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.microsoft.com/en-us/security/blog/2026/09/29/star-blizzard-refines-phishing-and-malware-delivery-with-the-redflick-technique/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.microsoft.com/en-us/security/blog/2026/09/29/star-blizzard-refines-phishing-and-malware-delivery-with-the-redflick-technique/",
          "name": "Star Blizzard refines phishing and malware delivery with the RedFlick technique"
        }
      ],
      "blind_spots": [
        {
          "id": "vhdx-mount-visibility",
          "risk": "The hunt sees the aftermath (script execution), but linking it directly to the specific VHDX file requires telemetry that may not be present on standard configurations.",
          "stage": "vhdx-payload-execution",
          "question": "Which specific VHDX file was mounted by the user?",
          "requires": "Windows Event ID 12 (VHD Mount) or endpoint volume telemetry"
        },
        {
          "id": "msi-payload-blindness",
          "risk": "If the MSI is deleted immediately after creating the task, forensic identification of the loader relies solely on memory or registry remnants.",
          "stage": "ssh-msi-delivery",
          "question": "What was the hash of the MSI installer downloaded via SSH?",
          "requires": "Endpoint file write events with SHA256 of the MSI"
        }
      ]
    },
    "name": "Star Blizzard RedFlick VHDX and SSH-based Malware Delivery",
    "description": "Star Blizzard (FSB Centre 18) has shifted to RedFlick, a multi-stage infection chain. It begins with password-protected archives containing VHDX files which mount to execute BAT scripts. These scripts use ssh.exe with the PermitLocalCommand option to download MSI installers, which then create scheduled tasks that use control.exe to load remote CPL files. This hunt identifies the progression from phishing contact and initial payload execution to persistent backdoor loading."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "coverage": [
          {
            "stage": "phishing-initial-contact",
            "steps": [
              "phishing-contact"
            ],
            "status": "covered"
          },
          {
            "stage": "vhdx-payload-execution",
            "steps": [
              "conhost-script-execution"
            ],
            "status": "covered"
          },
          {
            "stage": "ssh-msi-delivery",
            "steps": [
              "ssh-delivery-mechanism"
            ],
            "status": "covered"
          },
          {
            "stage": "scheduled-task-persistence",
            "steps": [
              "cpl-scheduled-tasks"
            ],
            "status": "covered"
          },
          {
            "stage": "redflick-cpl-loading",
            "steps": [
              "cpl-scheduled-tasks"
            ],
            "status": "covered"
          }
        ],
        "rationale": "An adversary has gained initial access via phishing and is using the RedFlick technique to deliver a backdoor through VHDX-mounted scripts, SSH-based MSI downloads, and CPL-driven scheduled tasks.",
        "blind_spots": [
          {
            "id": "vhdx-mount-visibility",
            "risk": "The hunt sees the aftermath (script execution), but linking it directly to the specific VHDX file requires telemetry that may not be present on standard configurations.",
            "stage": "vhdx-payload-execution",
            "question": "Which specific VHDX file was mounted by the user?",
            "requires": "Windows Event ID 12 (VHD Mount) or endpoint volume telemetry"
          },
          {
            "id": "msi-payload-blindness",
            "risk": "If the MSI is deleted immediately after creating the task, forensic identification of the loader relies solely on memory or registry remnants.",
            "stage": "ssh-msi-delivery",
            "question": "What was the hash of the MSI installer downloaded via SSH?",
            "requires": "Endpoint file write events with SHA256 of the MSI"
          }
        ],
        "scoping_notes": "Focus on workstations of researchers, diplomatic staff, and NGOs. Broaden the query if initial HTTP hits are missing, as the actor rotates compromised domains frequently.",
        "beyond_detection": "A single rule on schtasks.exe would be too noisy. This hunt pivots between HTTP lures, hidden-window conhost scripts, and unique SSH command arguments to confirm the specific Star Blizzard infection chain."
      }
    },
    {
      "id": "software-scoping",
      "type": "query",
      "label": "Identify hosts with relevant software",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT DISTINCT device_hostname, package_name, package_version FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%winrar%' OR LOWER(package_name) LIKE '%7-zip%' OR LOWER(package_name) LIKE '%acrobat%' OR LOWER(package_name) LIKE '%reader%')",
        "surface": "hb_software_inventory",
        "description": "Find workstations that have the software required to interact with the campaign's password-protected archives and decoy PDF lures. This generates context for the agent triage.",
        "expected_signal": "A list of hosts and their installed archive/PDF software. Silence is expected if the estate uses different or unmanaged software."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify hosts with relevant software",
        "reads": [
          "device_hostname",
          "package_name",
          "package_version"
        ],
        "source": "hb_software_inventory",
        "target": "endpoint",
        "content": "SELECT DISTINCT device_hostname, package_name, package_version FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%winrar%' OR LOWER(package_name) LIKE '%7-zip%' OR LOWER(package_name) LIKE '%acrobat%' OR LOWER(package_name) LIKE '%reader%')",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hosts and their installed archive/PDF software. Silence is expected if the estate uses different or unmanaged software.",
        "verified": "dry-run",
        "verified_at": "2026-09-30"
      }
    },
    {
      "id": "phishing-contact",
      "type": "query",
      "label": "Phishing contact HTTP activity",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "web",
        "content": "SELECT device_hostname, url_hostname, url_path, time FROM hb_http_activity WHERE (instr(',' || '{{campaign_domains}}' || ',', ',' || LOWER(url_hostname) || ',') > 0 OR LOWER(url_path) LIKE '%tax audit%' OR LOWER(url_path) LIKE '%payment advice%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_http_activity",
        "description": "Find HTTP requests to the Ukr.net mail provider or URLs containing campaign-themed keywords.",
        "expected_signal": "Hosts that have accessed the specified mail provider or clicked on lure themes. Silence means no web-based interaction was caught."
      },
      "parents": [
        {
          "id": "software-scoping"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Phishing contact HTTP activity",
        "reads": [
          "device_hostname",
          "time",
          "url_hostname",
          "url_path"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT device_hostname, url_hostname, url_path, time FROM hb_http_activity WHERE (instr(',' || '{{campaign_domains}}' || ',', ',' || LOWER(url_hostname) || ',') > 0 OR LOWER(url_path) LIKE '%tax audit%' OR LOWER(url_path) LIKE '%payment advice%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Hosts that have accessed the specified mail provider or clicked on lure themes. Silence means no web-based interaction was caught.",
        "verified": "dry-run",
        "verified_at": "2026-09-30"
      }
    },
    {
      "id": "conhost-script-execution",
      "type": "query",
      "label": "Rare conhost-initiated script execution",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT process_cmd_line, GROUP_CONCAT(DISTINCT device_hostname) AS affected_hosts, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_process_activity WHERE LOWER(parent_process_name) LIKE '%conhost.exe%' AND (LOWER(process_cmd_line) LIKE '%.bat%' OR LOWER(process_cmd_line) LIKE '%.lnk%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_cmd_line HAVING host_count <= 3",
        "surface": "hb_process_activity",
        "description": "Identify rare BAT or LNK scripts launched by conhost, which indicates execution from a mounted VHDX in a hidden window.",
        "expected_signal": "Rare scripts running under conhost. Silence suggests standard environment-wide login scripts or no such activity."
      },
      "parents": [
        {
          "id": "software-scoping"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare conhost-initiated script execution",
        "reads": [
          "device_hostname",
          "parent_process_name",
          "process_cmd_line",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT process_cmd_line, GROUP_CONCAT(DISTINCT device_hostname) AS affected_hosts, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_process_activity WHERE LOWER(parent_process_name) LIKE '%conhost.exe%' AND (LOWER(process_cmd_line) LIKE '%.bat%' OR LOWER(process_cmd_line) LIKE '%.lnk%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_cmd_line HAVING host_count <= 3",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Rare scripts running under conhost. Silence suggests standard environment-wide login scripts or no such activity.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_cmd_line"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-30"
      }
    },
    {
      "id": "early-stage-triage",
      "type": "analytic",
      "label": "Triage early infection stages",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "web"
        ],
        "context": [
          "software-scoping",
          "phishing-contact",
          "conhost-script-execution"
        ],
        "objective": "Evaluate whether the phishing contact leads and conhost script rows indicate a VHDX-based execution chain on any host.",
        "description": "Determine if any host shows both campaign-related contact and the specific hidden script behavior typical of RedFlick.",
        "max_iterations": 4,
        "expected_signal": "A list of hosts exhibiting high-confidence early-stage indicators.",
        "success_criteria": "A verdict citing specific hosts and rows that bridge the network and process telemetry."
      },
      "parents": [
        {
          "id": "phishing-contact",
          "kind": "merge"
        },
        {
          "id": "conhost-script-execution",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "ssh-delivery-mechanism",
      "type": "query",
      "label": "SSH PermitLocalCommand delivery",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_cmd_line, user_name, time FROM hb_process_activity WHERE LOWER(process_name) LIKE '%ssh.exe%' AND LOWER(process_cmd_line) LIKE '%permitlocalcommand=yes%' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Detect the use of ssh.exe with the PermitLocalCommand option, a specific RedFlick indicator used to execute commands upon connection.",
        "expected_signal": "Instances of SSH being used as a downloader. Silence means this specific delivery variant was not used on the checked hosts."
      },
      "parents": [
        {
          "id": "early-stage-triage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "SSH PermitLocalCommand delivery",
        "reads": [
          "device_hostname",
          "process_cmd_line",
          "process_name",
          "time",
          "user_name"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_cmd_line, user_name, time FROM hb_process_activity WHERE LOWER(process_name) LIKE '%ssh.exe%' AND LOWER(process_cmd_line) LIKE '%permitlocalcommand=yes%' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "evidence_of_absence",
        "expected": "Instances of SSH being used as a downloader. Silence means this specific delivery variant was not used on the checked hosts.",
        "verified": "dry-run",
        "verified_at": "2026-09-30"
      }
    },
    {
      "id": "cpl-scheduled-tasks",
      "type": "query",
      "label": "CPL persistence via scheduled tasks",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "endpoint",
        "content": "SELECT device_hostname, job_cmd_line, job_name, time FROM hb_scheduled_job WHERE LOWER(job_cmd_line) LIKE '%control.exe%' AND LOWER(job_cmd_line) LIKE '%.cpl%' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_scheduled_job",
        "description": "Identify scheduled tasks that use control.exe to load .cpl files, representing the RedFlick persistence and downloader stage.",
        "expected_signal": "Scheduled tasks pointing to unusual Control Panel applets. Silence means the persistence mechanism differs or was not established."
      },
      "parents": [
        {
          "id": "early-stage-triage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "CPL persistence via scheduled tasks",
        "reads": [
          "device_hostname",
          "job_cmd_line",
          "job_name",
          "time"
        ],
        "source": "hb_scheduled_job",
        "target": "endpoint",
        "content": "SELECT device_hostname, job_cmd_line, job_name, time FROM hb_scheduled_job WHERE LOWER(job_cmd_line) LIKE '%control.exe%' AND LOWER(job_cmd_line) LIKE '%.cpl%' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Scheduled tasks pointing to unusual Control Panel applets. Silence means the persistence mechanism differs or was not established.",
        "verified": "dry-run",
        "verified_at": "2026-09-30"
      }
    },
    {
      "id": "full-chain-analysis",
      "type": "analytic",
      "label": "Analyze full infection chain",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "web"
        ],
        "context": [
          "early-stage-triage",
          "ssh-delivery-mechanism",
          "cpl-scheduled-tasks"
        ],
        "objective": "Determine if any host exhibits the transition from phishing contact and hidden script execution to SSH-based delivery and CPL persistence.",
        "description": "Correlate the early leads with the specific delivery and persistence evidence to confirm the RedFlick tradecraft.",
        "max_iterations": 6,
        "expected_signal": "High-confidence confirmation of hosts that progressed through the entire RedFlick chain.",
        "success_criteria": "A malicious verdict for hosts showing multiple correlated stages of the RedFlick technique."
      },
      "parents": [
        {
          "id": "ssh-delivery-mechanism",
          "kind": "merge"
        },
        {
          "id": "cpl-scheduled-tasks",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "judgement",
      "type": "checkpoint",
      "label": "Route based on compromise confidence",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the full-chain-analysis verdict is malicious for at least one host",
        "condition": "the full-chain-analysis verdict is malicious for at least one host",
        "blind_spot": "vhdx-mount-visibility",
        "confidence": "high",
        "description": "Route confirmed compromises to isolation and others to manual review.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "full-chain-analysis"
        }
      ]
    },
    {
      "id": "containment",
      "type": "action",
      "label": "Isolate host and revoke sessions",
      "config": {
        "target": "endpoint",
        "description": "Immediately isolate the endpoint to prevent further data exfiltration or lateral movement.",
        "instructions": "Isolate the host at the network level, revoke all active Entra/M365 and SaaS sessions for the local users, and delete the malicious scheduled task and associated .cpl file.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "judgement",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-validation",
      "type": "task",
      "label": "Manual evidence review",
      "config": {
        "assignee": "analyst",
        "description": "Verify the agent's correlation and extract the final loader for further analysis.",
        "instructions": "Review the conhost command lines to locate where the VHDX was mounted. Search the user's temp directory for .rar or .zip files matching the campaign dates. Inspect the MSI logs to confirm which binary was dropped."
      },
      "parents": [
        {
          "id": "judgement",
          "branch": "default"
        },
        {
          "id": "judgement",
          "branch": "on_unavailable"
        },
        {
          "id": "judgement",
          "branch": "on_refutes"
        },
        {
          "id": "containment"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Hunt closure and detection handoff",
      "config": {
        "assignee": "analyst",
        "description": "Finalize the findings and promote the most durable signal to a standing rule.",
        "instructions": "Document the Star Blizzard TTPs observed, list the compromised hosts, and promote the SSH PermitLocalCommand query to a production detection rule."
      },
      "parents": [
        {
          "id": "analyst-validation"
        }
      ]
    }
  ]
}