{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Executives are high-yield targets whose compromise can lead to material impact; a dedicated monthly hunt provides the 'magnifying glass' required to catch stealthy APT-style attacks that standard alerts miss."
      },
      "name": "Detection of Targeted Executive Asset Compromise",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1190",
        "attack.t1566",
        "attack.t1059",
        "attack.t1530",
        "attack.t1213",
        "collection",
        "execution",
        "initial access"
      ],
      "related": [
        {
          "hunt": "whaling-phishing-infrastructure-monitoring",
          "reason": "Monitoring for external phishing infrastructure targeting the organization requires external DNS and brand monitoring surfaces not covered here.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        },
        "identity": {
          "name": "Identity / sign-in telemetry",
          "category": "identity",
          "telemetry": [
            "identity"
          ]
        }
      },
      "analysis": "A rule fires on the Run value; the hunt asks whether the binary is rare, whether it runs, and whether it talks \u2014 three surfaces, one decision.",
      "coverage": [
        {
          "stage": "initial-access-executive-targeting",
          "steps": [
            "lead-executive-auth",
            "assess-lead-auth"
          ],
          "status": "covered"
        },
        {
          "stage": "evasive-lotl-execution",
          "steps": [
            "rare-lotl-behavior"
          ],
          "status": "covered"
        },
        {
          "stage": "sensitive-data-collection",
          "steps": [
            "sensitive-keyword-access"
          ],
          "status": "covered"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Executive Targeted Initial Access",
            "slug": "initial-access-executive-targeting",
            "tactic": "initial-access",
            "techniques": [
              "T1190",
              "T1566"
            ],
            "observables": [
              "phishing kits designed to bypass MFA",
              "zero-day exploits",
              "vulnerable browser versions",
              "outdated software",
              "highly targeted whaling campaigns"
            ]
          },
          {
            "name": "Stealthy LoTL Execution",
            "slug": "evasive-lotl-execution",
            "tactic": "execution",
            "techniques": [
              "T1059"
            ],
            "observables": [
              "living-off-the-land techniques",
              "use of legitimate system tools to hide tracks",
              "anomalous process behavior"
            ]
          },
          {
            "name": "Sensitive Data Collection",
            "slug": "sensitive-data-collection",
            "tactic": "collection",
            "techniques": [
              "T1530",
              "T1213"
            ],
            "observables": [
              "access to sensitive financial data",
              "access to intellectual property",
              "access to strategic roadmap communications"
            ]
          }
        ],
        "summary": "Sophisticated threat actors target executive-level assets using personalized phishing and zero-day exploitation to bypass traditional enterprise defenses. Once access is gained, they employ stealthy living-off-the-land (LoTL) techniques to maintain a persistent presence and exfiltrate high-yield corporate data, including financial records and intellectual property."
      },
      "severity": "medium",
      "rationale": "Scope to the designated high-value principals (CEO, CFO, Board members). Use the identified source IP and device_hostname from authentication logs to narrow the expensive process and file queries.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary targets high-value executive assets using whaling and MFA bypass to access sensitive corporate roadmaps and financial data via stealthy living-off-the-land techniques.",
      "parameters": {
        "lotl_tools": {
          "from": {
            "ref": "talos-lotl-intelligence",
            "kind": "article",
            "observed": "2026-09-29"
          },
          "type": "list[string]",
          "default": [
            "powershell.exe",
            "certutil.exe",
            "mshta.exe",
            "wscript.exe",
            "bitsadmin.exe",
            "curl.exe",
            "vssadmin.exe"
          ],
          "description": "Legitimate system utilities frequently repurposed for evasive execution."
        },
        "scope_hosts": {
          "from": {
            "ref": "analyst-triage",
            "kind": "manual",
            "observed": "2026-09-29"
          },
          "type": "list[host]",
          "default": [],
          "description": "List of hostnames identified in the lead query to scope the behavioral fan-out."
        },
        "lookback_days": {
          "from": {
            "ref": "monthly-hunt-cycle",
            "kind": "manual",
            "observed": "2026-09-29"
          },
          "type": "number",
          "default": "14",
          "description": "Days of authentication and activity logs to analyze; 30 is typical for ETD monthly reports."
        },
        "sensitive_keywords": {
          "from": {
            "ref": "corporate-high-value-keywords",
            "kind": "manual",
            "observed": "2026-09-29"
          },
          "type": "list[string]",
          "default": [
            "merger",
            "acquisition",
            "financial",
            "roadmap",
            "payroll",
            "board",
            "strategy"
          ],
          "description": "Keywords that indicate access to high-value executive-level data."
        },
        "executive_usernames": {
          "from": {
            "ref": "executive-asset-registry",
            "kind": "manual",
            "observed": "2026-09-29"
          },
          "type": "list[string]",
          "default": [
            "ceo@example.com",
            "cfo@example.com",
            "cto@example.com",
            "board-chair@example.com"
          ],
          "description": "Usernames of the principals enrolled in the executive protection program."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://blog.talosintelligence.com/securing-the-keys-to-the-kingdom-announcing-executive-threat-detection/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://blog.talosintelligence.com/securing-the-keys-to-the-kingdom-announcing-executive-threat-detection/",
          "name": "Securing the keys to the kingdom: Announcing Executive Threat Detection"
        }
      ],
      "blind_spots": [
        {
          "id": "mfa-telemetry-gap",
          "risk": "If the identity provider returns NULL or 'other' for MFA status, the gate might fail to identify an MFA bypass, missing the initial access event.",
          "stage": "initial-access-executive-targeting",
          "question": "Whether a sign-in event successfully satisfied MFA requirements",
          "requires": "Reliable MFA status code in hb_auth_signin"
        },
        {
          "id": "command-line-truncation",
          "risk": "Adversaries often use very long encoded commands; truncation by the EDR surface may prevent keyword matching or prevalence analysis from identifying the malicious intent.",
          "stage": "evasive-lotl-execution",
          "question": "The specific script or encoded payload executed via LoTL utilities",
          "requires": "Full process_cmd_line length from endpoint agent"
        }
      ]
    },
    "name": "Detection of Targeted Executive Asset Compromise",
    "description": "Sophisticated actors target executive accounts as high-yield entry points into the corporate network. This hunt implements the Executive Threat Detection methodology: first, the hunt performs a low-cost audit of executive authentication patterns. If the lead agent identifies anomalies like MFA bypass or geolocational mismatches, the hunt gates into an expensive behavioral analysis phase. During this phase, the hunt stack-counts living-off-the-land utility usage and monitors for sensitive keyword access (e.g., 'merger', 'financials') specifically on the hosts associated with the executive's session. Finally, an agent differentiates routine executive travel or administrative tasks from a targeted, long-term breach."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "coverage": [
          {
            "stage": "initial-access-executive-targeting",
            "steps": [
              "lead-executive-auth",
              "assess-lead-auth"
            ],
            "status": "covered"
          },
          {
            "stage": "evasive-lotl-execution",
            "steps": [
              "rare-lotl-behavior"
            ],
            "status": "covered"
          },
          {
            "stage": "sensitive-data-collection",
            "steps": [
              "sensitive-keyword-access"
            ],
            "status": "covered"
          }
        ],
        "rationale": "An adversary targets high-value executive assets using whaling and MFA bypass to access sensitive corporate roadmaps and financial data via stealthy living-off-the-land techniques.",
        "blind_spots": [
          {
            "id": "mfa-telemetry-gap",
            "risk": "If the identity provider returns NULL or 'other' for MFA status, the gate might fail to identify an MFA bypass, missing the initial access event.",
            "stage": "initial-access-executive-targeting",
            "question": "Whether a sign-in event successfully satisfied MFA requirements",
            "requires": "Reliable MFA status code in hb_auth_signin"
          },
          {
            "id": "command-line-truncation",
            "risk": "Adversaries often use very long encoded commands; truncation by the EDR surface may prevent keyword matching or prevalence analysis from identifying the malicious intent.",
            "stage": "evasive-lotl-execution",
            "question": "The specific script or encoded payload executed via LoTL utilities",
            "requires": "Full process_cmd_line length from endpoint agent"
          }
        ],
        "scoping_notes": "Scope to the designated high-value principals (CEO, CFO, Board members). Use the identified source IP and device_hostname from authentication logs to narrow the expensive process and file queries.",
        "beyond_detection": "A rule fires on the Run value; the hunt asks whether the binary is rare, whether it runs, and whether it talks \u2014 three surfaces, one decision."
      }
    },
    {
      "id": "lead-executive-auth",
      "type": "query",
      "label": "Lead: Executive Authentication Anomalies",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "identity",
        "content": "SELECT actor_user_name, src_endpoint_ip, src_location_country, mfa, auth_protocol, status_detail, device_hostname, dst_endpoint_name, time FROM hb_auth_signin WHERE instr(',' || '{{executive_usernames}}' || ',', ',' || actor_user_name || ',') > 0 AND status_id = 1 AND time >= datetime('now', '-{{lookback_days}} days') ORDER BY time DESC",
        "surface": "hb_auth_signin",
        "description": "Identify successful executive logins to establish a set of beachhead hosts for behavioral analysis.",
        "expected_signal": "A list of successful login events per executive. No results suggest no activity in the window."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Lead: Executive Authentication Anomalies",
        "reads": [
          "actor_user_name",
          "src_endpoint_ip",
          "mfa",
          "auth_protocol",
          "status_detail",
          "device_hostname",
          "time",
          "status_id"
        ],
        "source": "hb_auth_signin",
        "target": "identity",
        "content": "SELECT actor_user_name, src_endpoint_ip, src_location_country, mfa, auth_protocol, status_detail, device_hostname, dst_endpoint_name, time FROM hb_auth_signin WHERE instr(',' || '{{executive_usernames}}' || ',', ',' || actor_user_name || ',') > 0 AND status_id = 1 AND time >= datetime('now', '-{{lookback_days}} days') ORDER BY time DESC",
        "silence": "not_evidence_of_absence",
        "expected": "A list of successful login events per executive. No results suggest no activity in the window.",
        "verified": "dry-run",
        "verified_at": "2026-09-30"
      }
    },
    {
      "id": "assess-lead-auth",
      "type": "analytic",
      "label": "Assess lead for sign-in risk",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity"
        ],
        "context": [
          "lead-executive-auth"
        ],
        "objective": "Review executive authentication events for anomalies: logins without MFA, unusual source countries, or protocols not typically used by these users. Explicitly generate the list of target hostnames from the lead-executive-auth results to populate the scope_hosts parameter for the subsequent parallel-deep-dive.",
        "description": "Identify suspicious logins that warrant an expensive behavioral deep-dive.",
        "max_iterations": 3,
        "expected_signal": "A per-session verdict of suspicious or benign.",
        "success_criteria": "A per-session assessment identifying which assets require deeper inspection and a clear list of target hostnames."
      },
      "parents": [
        {
          "id": "lead-executive-auth"
        }
      ]
    },
    {
      "id": "gate-on-suspicion",
      "type": "checkpoint",
      "label": "Gate on Authentication Suspicion",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the assess-lead-auth agent identifies at least one suspicious sign-in event for an enrolled executive",
        "condition": "the assess-lead-auth agent identifies at least one suspicious sign-in event for an enrolled executive",
        "blind_spot": "mfa-telemetry-gap",
        "confidence": "medium",
        "description": "Only trigger the expensive behavioral fan-out if the executive login is assessed as suspicious.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "assess-lead-auth"
        }
      ]
    },
    {
      "id": "rare-lotl-behavior",
      "type": "query",
      "label": "Rare LoTL Utility Usage",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT LOWER(process_cmd_line) AS cmd, process_name, device_hostname, user_name, on_disk, time FROM hb_process_activity WHERE (('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)) AND instr(',' || '{{lotl_tools}}' || ',', ',' || LOWER(REPLACE(process_name, RTRIM(process_name, 'abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789.'), '')) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY cmd, process_name, device_hostname, user_name, on_disk",
        "surface": "hb_process_activity",
        "description": "Find living-off-the-land tools running with command lines unique to the fleet, indicating tailored adversary execution.",
        "expected_signal": "A set of rare process command lines. Silence over the window provides evidence of absence for common LoTL patterns."
      },
      "parents": [
        {
          "id": "gate-on-suspicion",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Rare LoTL Utility Usage",
        "reads": [
          "process_cmd_line",
          "process_name",
          "device_hostname",
          "user_name",
          "on_disk",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT LOWER(process_cmd_line) AS cmd, process_name, device_hostname, user_name, on_disk, time FROM hb_process_activity WHERE (('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)) AND instr(',' || '{{lotl_tools}}' || ',', ',' || LOWER(REPLACE(process_name, RTRIM(process_name, 'abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789.'), '')) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY cmd, process_name, device_hostname, user_name, on_disk",
        "silence": "evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A set of rare process command lines. Silence over the window provides evidence of absence for common LoTL patterns.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_cmd_line"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-30"
      }
    },
    {
      "id": "sensitive-keyword-access",
      "type": "query",
      "label": "Sensitive Keyword Data Access",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, actor_user_name, file_path, file_name, activity_name, time FROM hb_file_activity WHERE (('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)) AND (instr(',' || '{{sensitive_keywords}}' || ',', ',' || LOWER(file_name) || ',') > 0 OR instr(',' || '{{sensitive_keywords}}' || ',', ',' || LOWER(file_path) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') ORDER BY time DESC",
        "surface": "hb_file_activity",
        "description": "Identify access to high-value files that an adversary would target following an executive account takeover.",
        "expected_signal": "Access to files matching corporate risk keywords on the scoped hosts."
      },
      "parents": [
        {
          "id": "gate-on-suspicion",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Sensitive Keyword Data Access",
        "reads": [
          "device_hostname",
          "actor_user_name",
          "file_path",
          "file_name",
          "activity_name",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, actor_user_name, file_path, file_name, activity_name, time FROM hb_file_activity WHERE (('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)) AND (instr(',' || '{{sensitive_keywords}}' || ',', ',' || LOWER(file_name) || ',') > 0 OR instr(',' || '{{sensitive_keywords}}' || ',', ',' || LOWER(file_path) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') ORDER BY time DESC",
        "silence": "not_evidence_of_absence",
        "expected": "Access to files matching corporate risk keywords on the scoped hosts.",
        "verified": "dry-run",
        "verified_at": "2026-09-30"
      }
    },
    {
      "id": "triage-combined-evidence",
      "type": "analytic",
      "label": "Synthesize Executive Breach Evidence",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity"
        ],
        "context": [
          "assess-lead-auth",
          "rare-lotl-behavior",
          "sensitive-keyword-access"
        ],
        "objective": "Determine if the suspicious login established a beachhead for the observed LoTL behavior and subsequent sensitive data access. Distinguish between legitimate administrative activity and adversary operations targeting executive data.",
        "description": "Analyze the correlated signals to confirm if the executive asset is compromised.",
        "max_iterations": 6,
        "expected_signal": "A final verdict of malicious, suspicious, or benign per host.",
        "success_criteria": "A final verdict citing the rare command lines and keyword-matching file paths."
      },
      "parents": [
        {
          "id": "rare-lotl-behavior",
          "kind": "merge"
        },
        {
          "id": "sensitive-keyword-access",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on Final Verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage-combined-evidence agent returns a malicious verdict for any executive asset",
        "condition": "the triage-combined-evidence agent returns a malicious verdict for any executive asset",
        "confidence": "high",
        "description": "Initiate response for confirmed breaches or close out the monthly cadence.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-combined-evidence"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate Compromised Asset",
      "config": {
        "target": "endpoint",
        "description": "Halt data exfiltration and contain the threat on the executive workstation.",
        "instructions": "Isolate the identified workstation and revoke all active cloud/SaaS sessions for the affected executive account.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-incident-review",
      "type": "task",
      "label": "Analyst Incident Review",
      "config": {
        "assignee": "analyst",
        "description": "Verify the automated findings and coordinate emergency response.",
        "instructions": "Review the triage verdict and cited rows. If a targeted intrusion is confirmed, escalate to an Emergency Response engagement via the Talos IR portal immediately."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "monthly-cadence-report",
      "type": "task",
      "label": "Monthly Cadence Reporting",
      "config": {
        "assignee": "analyst",
        "description": "Document findings for the ETD Monthly Report for leadership review.",
        "instructions": "Log the hunt results, including any baseline anomalies that were assessed as benign, into the Monthly ETD Report. Include strategic recommendations for hardening the executive environment."
      },
      "parents": [
        {
          "id": "gate-on-suspicion",
          "branch": "default"
        },
        {
          "id": "gate-on-suspicion",
          "branch": "on_unavailable"
        },
        {
          "id": "gate-on-suspicion",
          "branch": "on_refutes"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        }
      ]
    }
  ]
}