{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Storm-2570 moves quickly from establishing remote access to ransomware deployment. Detecting their persistent bridges early is the most effective way to disrupt the chain before data encryption."
      },
      "name": "Storm-2570 Persistent Remote Access and Discovery",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1021.006",
        "attack.t1572",
        "attack.t1018",
        "attack.t1046"
      ],
      "series": {
        "slug": "beyond-the-ransomware-tracking-storm-2570-s-consistent-tradecraft-across-deployments",
        "index": 1,
        "title": "Beyond the ransomware: Tracking Storm-2570\u2019s consistent tradecraft across deployments",
        "total": 3
      },
      "related": [
        {
          "hunt": "storm-2570-lateral-movement-psexec",
          "reason": "This hunt focuses on persistence and discovery; a follow-on hunt is required for PsExec and RDP movement.",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "network": {
          "name": "Network telemetry",
          "category": "network",
          "telemetry": [
            "network"
          ]
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "While single rules may fire on 'ngrok.exe', this hunt pivots between inventory, renamed binary execution (via original file name), and network outbound traffic to distinguish attacker activity from legitimate IT administration.",
      "coverage": [
        {
          "stage": "rmm-persistence-and-execution",
          "steps": [
            "scoping-rmm-inventory",
            "rmm-execution-activity"
          ],
          "status": "covered"
        },
        {
          "stage": "c2-protocol-tunneling",
          "steps": [
            "tunnel-and-discovery-network"
          ],
          "status": "covered"
        },
        {
          "stage": "network-and-file-discovery",
          "steps": [
            "tunnel-and-discovery-network"
          ],
          "status": "covered"
        },
        {
          "stage": "credential-dumping-ad",
          "reason": "Belongs to another part of the 'Beyond the ransomware: Tracking Storm-2570\u2019s consistent tradecraft across deployments' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "defense-evasion-tampering",
          "reason": "Belongs to another part of the 'Beyond the ransomware: Tracking Storm-2570\u2019s consistent tradecraft across deployments' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "lateral-movement-psexec-rdp",
          "reason": "Belongs to another part of the 'Beyond the ransomware: Tracking Storm-2570\u2019s consistent tradecraft across deployments' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "exfiltration-cloud-storage",
          "reason": "Belongs to another part of the 'Beyond the ransomware: Tracking Storm-2570\u2019s consistent tradecraft across deployments' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "ransomware-impact",
          "reason": "Belongs to another part of the 'Beyond the ransomware: Tracking Storm-2570\u2019s consistent tradecraft across deployments' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Persistence via RMM Tooling",
            "slug": "rmm-persistence-and-execution",
            "tactic": "persistence",
            "techniques": [
              "T1021.006"
            ],
            "observables": [
              "meshagent64.exe",
              "AteraAgent.exe",
              "Splashtop Streamer",
              "NinjaRMM",
              "Remotely_Agent",
              "MeshAgent-related binaries renamed to victim-themed names like meshagent64-[organization].exe",
              "Base64-encoded command execution via RMM"
            ]
          },
          {
            "name": "Persistent Outbound Tunneling",
            "slug": "c2-protocol-tunneling",
            "tactic": "command-and-control",
            "techniques": [
              "T1572"
            ],
            "observables": [
              "Cloudflared.exe installed as a service under LocalSystem",
              "ngrok exposing TCP 3389",
              "Persistent Cloudflare Tunnel service creation"
            ]
          },
          {
            "name": "Internal Discovery",
            "slug": "network-and-file-discovery",
            "tactic": "discovery",
            "techniques": [
              "T1018",
              "T1046"
            ],
            "observables": [
              "NetScan.exe",
              "SoftPerfect Network Scanner Portable",
              "nmap.exe",
              "Native Windows discovery commands for host identification"
            ]
          },
          {
            "name": "Active Directory Database Dumping",
            "slug": "credential-dumping-ad",
            "tactic": "credential-access",
            "techniques": [
              "T1003",
              "T1003.001"
            ],
            "observables": [
              "ntdsutil.exe",
              "ntdsutil 'ac i ntds' 'ifm' 'create full C:\\Windows\\Temp\\'",
              "ntds.dit extraction",
              "Mimikatz",
              "LaZagne",
              "pypykatz"
            ]
          },
          {
            "name": "Security Software Tampering",
            "slug": "defense-evasion-tampering",
            "tactic": "defense-evasion",
            "techniques": [
              "T1562.001"
            ],
            "observables": [
              "Microsoft Defender exclusions for C:\\PerfLogs",
              "Registry value DisableAntiSpyware set to 1",
              "Registry value DisableRealtimeMonitoring set to 1",
              "Modification of WinDefend service keys"
            ]
          },
          {
            "name": "Lateral Movement and Remote Execution",
            "slug": "lateral-movement-psexec-rdp",
            "tactic": "lateral-movement",
            "techniques": [
              "T1021.001",
              "T1021.002"
            ],
            "observables": [
              "PsExec.exe using host lists like @ip.txt",
              "rdp.bat enabling RDP access",
              "NetExec SMB commands",
              "Impacket offensive framework",
              "reg add Terminal Server /v fDenyTSConnections /d 0",
              "netsh advfirewall firewall add rule name=\"Remote Desktop\" localport=3389"
            ]
          },
          {
            "name": "Data Staging and Exfiltration",
            "slug": "exfiltration-cloud-storage",
            "tactic": "exfiltration",
            "techniques": [
              "T1041",
              "T1567.002"
            ],
            "observables": [
              "s5cmd.exe",
              "rclone.exe",
              "Outbound data transfers to cloud storage providers"
            ]
          },
          {
            "name": "Data Encryption for Impact",
            "slug": "ransomware-impact",
            "tactic": "impact",
            "techniques": [
              "T1486"
            ],
            "observables": [
              "Qilin ransomware",
              "DragonForce ransomware",
              "Anubis ransomware",
              "BERT ransomware"
            ]
          }
        ],
        "summary": "Storm-2570 is a ransomware affiliate that employs a consistent set of RMM tools, tunneling utilities, and hands-on-keyboard techniques to deploy payloads like Qilin and DragonForce. They prioritize persistent remote access via MeshAgent and Cloudflared tunnels before moving to Active Directory credential dumping and broad lateral movement using PsExec and RDP."
      },
      "severity": "high",
      "rationale": "Focus on servers and admin jump hosts where unauthorized RMM tools would have the highest impact. Use the inventory query to narrow down hosts with known RMM software first to prioritize analysis.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An intruder has established redundant persistent access using commercial RMM tools and outbound tunneling utilities to bypass firewalls and conduct internal reconnaissance.",
      "parameters": {
        "rmm_tools": {
          "from": {
            "ref": "msrc-blog-storm-2570",
            "kind": "article",
            "observed": "2026-09-24"
          },
          "type": "list[string]",
          "default": [
            "ateraagent.exe",
            "remotely_agent.exe",
            "ninjarmm.exe",
            "splashtop.exe",
            "screenconnect.exe",
            "meshagent64.exe"
          ],
          "description": "Known RMM tool binary names mentioned in the Storm-2570 research."
        },
        "scope_hosts": {
          "from": {
            "ref": "scoping-input",
            "kind": "manual",
            "observed": "2026-09-24"
          },
          "type": "list[host]",
          "default": [],
          "description": "List of hostnames to focus the search; leave empty to run across the whole estate."
        },
        "lookback_days": {
          "from": {
            "ref": "standard-lookback",
            "kind": "manual",
            "observed": "2026-09-24"
          },
          "type": "number",
          "default": "14",
          "description": "Days of activity history to examine."
        },
        "tunnel_endpoints": {
          "from": {
            "ref": "msrc-blog-storm-2570",
            "kind": "article",
            "observed": "2026-09-24"
          },
          "type": "list[domain]",
          "default": [
            "tunnel.us.ngrok.com",
            "tunnel.eu.ngrok.com",
            "trycloudflare.com",
            "ngrok-free.app"
          ],
          "description": "Common domains associated with tunneling services."
        },
        "tunnel_discovery_tools": {
          "from": {
            "ref": "msrc-blog-storm-2570",
            "kind": "article",
            "observed": "2026-09-24"
          },
          "type": "list[string]",
          "default": [
            "cloudflared.exe",
            "ngrok.exe",
            "netscan.exe",
            "nmap.exe",
            "netexec.exe"
          ],
          "description": "Outbound tunneling and internal network discovery tools used by the actor."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.microsoft.com/en-us/security/blog/2026/09/24/beyond-ransomware-tracking-storm-2570-consistent-tradecraft-across-deployments/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.microsoft.com/en-us/security/blog/2026/09/24/beyond-ransomware-tracking-storm-2570-consistent-tradecraft-across-deployments/",
          "name": "Beyond the ransomware: Tracking Storm-2570\u2019s consistent tradecraft across deployments"
        }
      ],
      "blind_spots": [
        {
          "id": "incomplete-telemetry",
          "risk": "An intruder could establish persistence on an unmanaged server that remains invisible to this hunt.",
          "stage": "rmm-persistence-and-execution",
          "question": "Are there hosts in the estate not reporting software inventory or process events?",
          "requires": "Complete endpoint agent coverage"
        },
        {
          "id": "ephemeral-processes",
          "risk": "Short-lived scanning activity like Nmap might be missed if the data source only provides point-in-time snapshots.",
          "stage": "network-and-file-discovery",
          "question": "Did discovery tools run and terminate between snapshot intervals?",
          "requires": "High-fidelity process event stream"
        }
      ]
    },
    "name": "Storm-2570 Persistent Remote Access and Discovery",
    "description": "Storm-2570 (a ransomware affiliate for Qilin and BERT) consistently establishes redundant backdoors using remote monitoring and management tools like MeshAgent and Atera. They often rename these tools to blend into the environment and pair them with tunneling utilities like Cloudflared to create encrypted outbound channels. This hunt identifies the installation and execution of these persistent agents and correlates their presence with network activity targeting known tunnel endpoints or internal scanning patterns."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "beyond-the-ransomware-tracking-storm-2570-s-consistent-tradecraft-across-deployments",
          "index": 1,
          "title": "Beyond the ransomware: Tracking Storm-2570\u2019s consistent tradecraft across deployments",
          "total": 3
        },
        "coverage": [
          {
            "stage": "rmm-persistence-and-execution",
            "steps": [
              "scoping-rmm-inventory",
              "rmm-execution-activity"
            ],
            "status": "covered"
          },
          {
            "stage": "c2-protocol-tunneling",
            "steps": [
              "tunnel-and-discovery-network"
            ],
            "status": "covered"
          },
          {
            "stage": "network-and-file-discovery",
            "steps": [
              "tunnel-and-discovery-network"
            ],
            "status": "covered"
          },
          {
            "stage": "credential-dumping-ad",
            "reason": "Belongs to another part of the 'Beyond the ransomware: Tracking Storm-2570\u2019s consistent tradecraft across deployments' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "defense-evasion-tampering",
            "reason": "Belongs to another part of the 'Beyond the ransomware: Tracking Storm-2570\u2019s consistent tradecraft across deployments' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "lateral-movement-psexec-rdp",
            "reason": "Belongs to another part of the 'Beyond the ransomware: Tracking Storm-2570\u2019s consistent tradecraft across deployments' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "exfiltration-cloud-storage",
            "reason": "Belongs to another part of the 'Beyond the ransomware: Tracking Storm-2570\u2019s consistent tradecraft across deployments' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "ransomware-impact",
            "reason": "Belongs to another part of the 'Beyond the ransomware: Tracking Storm-2570\u2019s consistent tradecraft across deployments' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An intruder has established redundant persistent access using commercial RMM tools and outbound tunneling utilities to bypass firewalls and conduct internal reconnaissance.",
        "blind_spots": [
          {
            "id": "incomplete-telemetry",
            "risk": "An intruder could establish persistence on an unmanaged server that remains invisible to this hunt.",
            "stage": "rmm-persistence-and-execution",
            "question": "Are there hosts in the estate not reporting software inventory or process events?",
            "requires": "Complete endpoint agent coverage"
          },
          {
            "id": "ephemeral-processes",
            "risk": "Short-lived scanning activity like Nmap might be missed if the data source only provides point-in-time snapshots.",
            "stage": "network-and-file-discovery",
            "question": "Did discovery tools run and terminate between snapshot intervals?",
            "requires": "High-fidelity process event stream"
          }
        ],
        "scoping_notes": "Focus on servers and admin jump hosts where unauthorized RMM tools would have the highest impact. Use the inventory query to narrow down hosts with known RMM software first to prioritize analysis.",
        "beyond_detection": "While single rules may fire on 'ngrok.exe', this hunt pivots between inventory, renamed binary execution (via original file name), and network outbound traffic to distinguish attacker activity from legitimate IT administration."
      }
    },
    {
      "id": "scoping-rmm-inventory",
      "type": "query",
      "label": "Inventory of RMM Software",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT DISTINCT device_hostname, package_name, vendor_name FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%screenconnect%' OR LOWER(package_name) LIKE '%atera%' OR LOWER(package_name) LIKE '%meshagent%' OR LOWER(package_name) LIKE '%splashtop%' OR LOWER(package_name) LIKE '%ninja%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)",
        "surface": "hb_software_inventory",
        "description": "Identify hosts with installed RMM software mentioned in the report to focus the behavioral search.",
        "expected_signal": "A list of hosts that have these management tools installed. Silence means none of the specific named packages are present in the current inventory."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Inventory of RMM Software",
        "reads": [
          "device_hostname",
          "package_name",
          "vendor_name"
        ],
        "source": "hb_software_inventory",
        "target": "endpoint",
        "content": "SELECT DISTINCT device_hostname, package_name, vendor_name FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%screenconnect%' OR LOWER(package_name) LIKE '%atera%' OR LOWER(package_name) LIKE '%meshagent%' OR LOWER(package_name) LIKE '%splashtop%' OR LOWER(package_name) LIKE '%ninja%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hosts that have these management tools installed. Silence means none of the specific named packages are present in the current inventory.",
        "verified": "dry-run",
        "verified_at": "2026-09-25"
      }
    },
    {
      "id": "rmm-execution-activity",
      "type": "query",
      "label": "Execution of RMM Tools",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_original_file_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{rmm_tools}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0 OR instr(',' || '{{rmm_tools}}' || ',', ',' || LOWER(replace(process_name, rtrim(process_name, replace(process_name, '\\', '')), '')) || ',') > 0 OR LOWER(process_name) LIKE '%meshagent%' OR LOWER(process_name) LIKE '%ateraagent%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Find the execution of RMM agents, specifically identifying renamed binaries using the original filename and path-insensitive matching.",
        "expected_signal": "Processes executing RMM binaries regardless of path or file renaming. Silence proves absence of these agents executing during the window."
      },
      "parents": [
        {
          "id": "scoping-rmm-inventory"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Execution of RMM Tools",
        "reads": [
          "device_hostname",
          "process_name",
          "process_original_file_name",
          "process_cmd_line",
          "user_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_original_file_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{rmm_tools}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0 OR instr(',' || '{{rmm_tools}}' || ',', ',' || LOWER(replace(process_name, rtrim(process_name, replace(process_name, '\\', '')), '')) || ',') > 0 OR LOWER(process_name) LIKE '%meshagent%' OR LOWER(process_name) LIKE '%ateraagent%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "evidence_of_absence",
        "expected": "Processes executing RMM binaries regardless of path or file renaming. Silence proves absence of these agents executing during the window.",
        "verified": "dry-run",
        "verified_at": "2026-09-25"
      }
    },
    {
      "id": "tunnel-and-discovery-network",
      "type": "query",
      "label": "Tunnel and Discovery Network Footprint",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "network",
        "content": "SELECT device_hostname, process_name, dst_endpoint_hostname, dst_endpoint_port, COUNT(*) AS conn_count, MIN(time) AS first_seen FROM hb_network_connection WHERE (instr(',' || '{{tunnel_discovery_tools}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || '{{tunnel_endpoints}}' || ',', ',' || LOWER(dst_endpoint_hostname) || ',') > 0 OR (dst_endpoint_port = 3389 AND direction = 'outbound')) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name, dst_endpoint_hostname, dst_endpoint_port",
        "surface": "hb_network_connection",
        "description": "Identify network connections from tunneling or discovery tools, specifically highlighting outbound traffic to tunnel providers or internal scanners.",
        "expected_signal": "Outbound connections to tunnel services or unusual internal RDP traffic. Silence means no such connections were logged."
      },
      "parents": [
        {
          "id": "scoping-rmm-inventory"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Tunnel and Discovery Network Footprint",
        "reads": [
          "device_hostname",
          "process_name",
          "dst_endpoint_hostname",
          "dst_endpoint_port",
          "time"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT device_hostname, process_name, dst_endpoint_hostname, dst_endpoint_port, COUNT(*) AS conn_count, MIN(time) AS first_seen FROM hb_network_connection WHERE (instr(',' || '{{tunnel_discovery_tools}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || '{{tunnel_endpoints}}' || ',', ',' || LOWER(dst_endpoint_hostname) || ',') > 0 OR (dst_endpoint_port = 3389 AND direction = 'outbound')) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name, dst_endpoint_hostname, dst_endpoint_port",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Outbound connections to tunnel services or unusual internal RDP traffic. Silence means no such connections were logged.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_name",
            "dst_endpoint_hostname"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-25"
      }
    },
    {
      "id": "storm-2570-triage",
      "type": "analytic",
      "label": "Triage Storm-2570 Activity",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "network"
        ],
        "context": [
          "rmm-execution-activity",
          "tunnel-and-discovery-network"
        ],
        "objective": "Determine if any host is running unauthorized RMM tools or tunneling utilities that match the Storm-2570 pattern of persistent remote access and discovery, correlating the presence of a binary with its outbound network footprint.",
        "description": "Evaluate RMM execution and tool network footprints to identify unauthorized persistent access.",
        "max_iterations": 4,
        "expected_signal": "A confirmed verdict per host.",
        "success_criteria": "A verdict of malicious, suspicious, or benign per host, citing the relevant process and network rows."
      },
      "parents": [
        {
          "id": "rmm-execution-activity",
          "kind": "merge"
        },
        {
          "id": "tunnel-and-discovery-network",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "verdict-decision",
      "type": "checkpoint",
      "label": "Verdict Decision",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage verdict is malicious for at least one host based on correlated RMM execution and tunnel traffic",
        "condition": "the triage verdict is malicious for at least one host based on correlated RMM execution and tunnel traffic",
        "blind_spot": "incomplete-telemetry",
        "confidence": "high",
        "description": "Route the hunt based on the agent's triage result.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "storm-2570-triage"
        }
      ]
    },
    {
      "id": "isolate-endpoint",
      "type": "action",
      "label": "Isolate Endpoint",
      "config": {
        "target": "endpoint",
        "description": "Sever the attacker's remote connection immediately upon confirmation of malicious activity.",
        "instructions": "Isolate the host from the network and revoke any active sessions for the users observed running the unauthorized tools.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "verdict-decision",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "manual-forensic-review",
      "type": "task",
      "label": "Manual Forensic Review",
      "config": {
        "assignee": "analyst",
        "description": "Investigate the entry point and full scope of the RMM installation.",
        "instructions": "Examine the file system for the RMM binary and its configuration directory. Review authentication logs to determine which account installed the agent and if lateral movement occurred."
      },
      "parents": [
        {
          "id": "verdict-decision",
          "branch": "default"
        },
        {
          "id": "verdict-decision",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-endpoint"
        }
      ]
    },
    {
      "id": "hunt-close-out",
      "type": "task",
      "label": "Hunt Close-out",
      "config": {
        "assignee": "analyst",
        "description": "Document results and refine hunt parameters.",
        "instructions": "Record the findings. If benign RMM tools were found, add them to an exclusion list for future runs. Document any unmanaged assets discovered during the scoping phase."
      },
      "parents": [
        {
          "id": "verdict-decision",
          "branch": "on_refutes"
        },
        {
          "id": "manual-forensic-review"
        }
      ]
    }
  ]
}