{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Microsoft Teams vishing exploits the high-trust nature of internal communications platforms. This hunt identifies the coordination between external lures and endpoint tradecraft that traditional signature-based rules often miss."
      },
      "name": "Microsoft Teams Vishing and Malicious Payload Execution",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1566.003",
        "attack.t1204.002",
        "attack.t1219",
        "attack.t1547",
        "attack.t1027",
        "attack.t1562.001",
        "attack.t1176",
        "attack.t1033",
        "attack.t1069.002"
      ],
      "series": {
        "slug": "spring-ring-an-inside-look-at-voice-phishing-campaigns-in-microsoft-teams",
        "index": 1,
        "title": "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams",
        "total": 2
      },
      "related": [
        {
          "hunt": "lateral-movement-ntlm-relay",
          "reason": "The NTLM relay and PetitPotam phase requires specific Domain Controller telemetry and is handled by a sibling hunt.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A single rule on Quick Assist or PowerShell obfuscation is noisy; this hunt pivots from external DNS lures to correlated RMM execution and follow-on persistence, creating a high-confidence chain that requires cross-surface analysis.",
      "coverage": [
        {
          "stage": "initial-access-teams-vishing",
          "steps": [
            "dns-vishing-lures"
          ],
          "status": "covered"
        },
        {
          "stage": "execution-rmm-and-custom-payloads",
          "steps": [
            "rmm-and-payload-execution"
          ],
          "status": "covered"
        },
        {
          "stage": "persistence-staging-temp",
          "steps": [
            "temp-directory-persistence"
          ],
          "status": "covered"
        },
        {
          "stage": "defense-evasion-obfuscation-and-hijack",
          "steps": [
            "script-based-discovery"
          ],
          "status": "covered"
        },
        {
          "stage": "discovery-host-and-domain",
          "steps": [
            "script-based-discovery"
          ],
          "status": "covered"
        },
        {
          "stage": "lateral-movement-ntlm-relay",
          "reason": "Belongs to another part of the 'Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "command-and-control-rat",
          "reason": "Belongs to another part of the 'Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Teams Vishing and Impersonation",
            "slug": "initial-access-teams-vishing",
            "tactic": "initial-access",
            "techniques": [
              "T1566.003"
            ],
            "observables": [
              "internalsystemsdaily.onmicrosoft.com",
              "itprotectiondepartment.onmicrosoft.com",
              "mandatorynetworkmonitoring.onmicrosoft.com",
              "internalusahelpdeskit.onmicrosoft.com",
              "certifiedupdatenetwork.onmicrosoft.com",
              "infrastructureopsdesk.onmicrosoft.com",
              "systemdeploymentcenter.onmicrosoft.com",
              "systemsupportoperations.onmicrosoft.com"
            ]
          },
          {
            "name": "User Execution of RMM and Payloads",
            "slug": "execution-rmm-and-custom-payloads",
            "tactic": "execution",
            "techniques": [
              "T1204.002",
              "T1219"
            ],
            "observables": [
              "Quick Assist",
              "s3.us-west-2.amazonaws.com",
              "*-org-filters-update-*.exe",
              "san-sid.com"
            ]
          },
          {
            "name": "Staging and Persistence",
            "slug": "persistence-staging-temp",
            "tactic": "persistence",
            "techniques": [
              "T1547"
            ],
            "observables": [
              "\\Temp\\vhlp-*.exe",
              "\\Temp\\scnr-*.exe"
            ]
          },
          {
            "name": "Bypassing AMSI and Browser Hijacking",
            "slug": "defense-evasion-obfuscation-and-hijack",
            "tactic": "defense-evasion",
            "techniques": [
              "T1027",
              "T1562.001",
              "T1176"
            ],
            "observables": [
              "amsiInitFailed",
              "Headless Microsoft Edge",
              "Sideloaded Edge extension",
              "Obfuscated PowerShell script"
            ]
          },
          {
            "name": "Host and Domain Discovery",
            "slug": "discovery-host-and-domain",
            "tactic": "discovery",
            "techniques": [
              "T1033",
              "T1069.002"
            ],
            "observables": [
              "whoami /groups",
              "net group /dom"
            ]
          },
          {
            "name": "NTLM Relay and PetitPotam",
            "slug": "lateral-movement-ntlm-relay",
            "tactic": "lateral-movement",
            "techniques": [
              "T1557.001",
              "T1210"
            ],
            "observables": [
              "C:\\ProgramData\\IntegrityData\\python.exe",
              "Port 445 SMB scanning",
              "PetitPotam coercion against Domain Controllers"
            ]
          },
          {
            "name": "PowerShell RAT C2 Beaconing",
            "slug": "command-and-control-rat",
            "tactic": "command-and-control",
            "techniques": [
              "T1071.001"
            ],
            "observables": [
              "san-sid.com"
            ]
          }
        ],
        "summary": "Spring Ring is a social engineering campaign that leverages external Microsoft Teams accounts to impersonate IT help desks via vishing calls. Attackers coerce employees into running remote management tools or custom malware, leading to domain enumeration and NTLM relay attacks (PetitPotam) intended to compromise domain controllers."
      },
      "severity": "high",
      "rationale": "The hunt targets hosts with Microsoft Teams. If the software inventory is empty, widen the scope to all Windows workstations to account for unmanaged Teams installations.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary is using external Microsoft Teams accounts to masquerade as IT support and coerce employees into executing RMM tools or custom payloads that perform discovery and persistence.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Targeted hostnames for the hunt; leave empty to search the full estate."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine for activity."
        },
        "teams_lure_domains": {
          "from": {
            "ref": "unit-42-spring-ring",
            "kind": "article",
            "observed": "2026-08-31"
          },
          "type": "list[domain]",
          "default": [
            "internalsystemsdaily.onmicrosoft.com",
            "itprotectiondepartment.onmicrosoft.com",
            "mandatorynetworkmonitoring.onmicrosoft.com",
            "internalusahelpdeskit.onmicrosoft.com",
            "certifiedupdatenetwork.onmicrosoft.com",
            "infrastructureopsdesk.onmicrosoft.com",
            "systemdeploymentcenter.onmicrosoft.com",
            "systemsupportoperations.onmicrosoft.com"
          ],
          "description": "External Microsoft Teams tenant domains used for impersonation lures."
        },
        "malware_host_domains": {
          "from": {
            "ref": "unit-42-spring-ring",
            "kind": "article",
            "observed": "2026-08-31"
          },
          "type": "list[domain]",
          "default": [
            "san-sid.com"
          ],
          "description": "Adversary-controlled domains used for hosting malicious payloads."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/",
          "name": "Unit 42 \u2014 Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams"
        }
      ],
      "blind_spots": [
        {
          "id": "teams-voice-content-gap",
          "risk": "An adversary could verbally capture credentials or perform MFA fatigue without immediate endpoint activity, leaving the initial hook invisible to behavior-based hunting.",
          "stage": "initial-access-teams-vishing",
          "question": "What was the verbal content of the vishing call?",
          "requires": "Microsoft Teams Voice Recording or Call Metadata"
        },
        {
          "id": "browser-extension-visibility",
          "risk": "A sideloaded extension can steal session cookies or manipulate browser DOM silently, bypassing process-based detection.",
          "stage": "defense-evasion-obfuscation-and-hijack",
          "question": "What actions did the sideloaded Edge extension perform?",
          "requires": "hb_browser_extension_activity"
        }
      ]
    },
    "name": "Microsoft Teams Vishing and Malicious Payload Execution",
    "description": "The Spring Ring campaign leverages the inherent trust in SaaS collaboration platforms to initiate vishing calls via external Teams accounts. This hunt first identifies the initial social engineering phase by tracking DNS lookups to suspicious onmicrosoft.com subdomains and subsequent execution of RMM tools like Quick Assist or tailored payloads. It then follows the attack chain to look for follow-on behaviors including AMSI bypass attempts, discovery commands, and persistence established in temporary directories."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "spring-ring-an-inside-look-at-voice-phishing-campaigns-in-microsoft-teams",
          "index": 1,
          "title": "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams",
          "total": 2
        },
        "coverage": [
          {
            "stage": "initial-access-teams-vishing",
            "steps": [
              "dns-vishing-lures"
            ],
            "status": "covered"
          },
          {
            "stage": "execution-rmm-and-custom-payloads",
            "steps": [
              "rmm-and-payload-execution"
            ],
            "status": "covered"
          },
          {
            "stage": "persistence-staging-temp",
            "steps": [
              "temp-directory-persistence"
            ],
            "status": "covered"
          },
          {
            "stage": "defense-evasion-obfuscation-and-hijack",
            "steps": [
              "script-based-discovery"
            ],
            "status": "covered"
          },
          {
            "stage": "discovery-host-and-domain",
            "steps": [
              "script-based-discovery"
            ],
            "status": "covered"
          },
          {
            "stage": "lateral-movement-ntlm-relay",
            "reason": "Belongs to another part of the 'Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "command-and-control-rat",
            "reason": "Belongs to another part of the 'Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary is using external Microsoft Teams accounts to masquerade as IT support and coerce employees into executing RMM tools or custom payloads that perform discovery and persistence.",
        "blind_spots": [
          {
            "id": "teams-voice-content-gap",
            "risk": "An adversary could verbally capture credentials or perform MFA fatigue without immediate endpoint activity, leaving the initial hook invisible to behavior-based hunting.",
            "stage": "initial-access-teams-vishing",
            "question": "What was the verbal content of the vishing call?",
            "requires": "Microsoft Teams Voice Recording or Call Metadata"
          },
          {
            "id": "browser-extension-visibility",
            "risk": "A sideloaded extension can steal session cookies or manipulate browser DOM silently, bypassing process-based detection.",
            "stage": "defense-evasion-obfuscation-and-hijack",
            "question": "What actions did the sideloaded Edge extension perform?",
            "requires": "hb_browser_extension_activity"
          }
        ],
        "scoping_notes": "The hunt targets hosts with Microsoft Teams. If the software inventory is empty, widen the scope to all Windows workstations to account for unmanaged Teams installations.",
        "beyond_detection": "A single rule on Quick Assist or PowerShell obfuscation is noisy; this hunt pivots from external DNS lures to correlated RMM execution and follow-on persistence, creating a high-confidence chain that requires cross-surface analysis."
      }
    },
    {
      "id": "scope-teams-hosts",
      "type": "query",
      "label": "Identify hosts with Microsoft Teams",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT DISTINCT device_hostname FROM hb_software_inventory WHERE LOWER(package_name) LIKE '%teams%'",
        "surface": "hb_software_inventory",
        "description": "Define the target scope by finding every host currently running or having Microsoft Teams installed.",
        "expected_signal": "A list of hosts likely to be targeted by Teams-based vishing. Silence means Teams is not detected in the software inventory."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify hosts with Microsoft Teams",
        "reads": [
          "device_hostname",
          "package_name"
        ],
        "source": "hb_software_inventory",
        "target": "endpoint",
        "content": "SELECT DISTINCT device_hostname FROM hb_software_inventory WHERE LOWER(package_name) LIKE '%teams%'",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hosts likely to be targeted by Teams-based vishing. Silence means Teams is not detected in the software inventory.",
        "verified": "dry-run",
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "dns-vishing-lures",
      "type": "query",
      "label": "DNS lookups to vishing domains",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, query_hostname, process_name, time FROM hb_dns_activity WHERE (instr(',' || '{{teams_lure_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 OR instr(',' || '{{malware_host_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_dns_activity",
        "description": "Find hosts that resolved domains associated with the external Teams tenants or malware hosting sites.",
        "expected_signal": "Hosts communicating with known vishing tenants or malicious payload sites. Silence proves no resolution for these specific domains occurred."
      },
      "parents": [
        {
          "id": "scope-teams-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "DNS lookups to vishing domains",
        "reads": [
          "device_hostname",
          "query_hostname",
          "process_name",
          "time"
        ],
        "source": "hb_dns_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, query_hostname, process_name, time FROM hb_dns_activity WHERE (instr(',' || '{{teams_lure_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 OR instr(',' || '{{malware_host_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "evidence_of_absence",
        "expected": "Hosts communicating with known vishing tenants or malicious payload sites. Silence proves no resolution for these specific domains occurred.",
        "verified": "dry-run",
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "rmm-and-payload-execution",
      "type": "query",
      "label": "Execution of RMM or tailored payloads",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, time, user_name FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%quickassist.exe' OR LOWER(process_cmd_line) LIKE '%-org-filters-update-%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Detect the launch of remote monitoring tools like Quick Assist or executables matching the campaign's tailored naming convention.",
        "expected_signal": "A process event showing either Quick Assist or a specific campaign payload launched by a user."
      },
      "parents": [
        {
          "id": "scope-teams-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Execution of RMM or tailored payloads",
        "reads": [
          "device_hostname",
          "process_name",
          "process_cmd_line",
          "time",
          "user_name"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, time, user_name FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%quickassist.exe' OR LOWER(process_cmd_line) LIKE '%-org-filters-update-%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "A process event showing either Quick Assist or a specific campaign payload launched by a user.",
        "verified": "dry-run",
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "triage-initial-lure",
      "type": "analytic",
      "label": "Evaluate early-stage vishing success",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "dns-vishing-lures",
          "rmm-and-payload-execution"
        ],
        "objective": "Determine if any host resolved a vishing domain and immediately launched an RMM tool or the specific campaign payload.",
        "description": "Analyze whether the DNS lures and process executions on the same host indicate a successful vishing engagement.",
        "max_iterations": 3,
        "expected_signal": "A verdict per host determining if social engineering behavior is present.",
        "success_criteria": "A per-host verdict of social-engineering-likely or benign."
      },
      "parents": [
        {
          "id": "dns-vishing-lures",
          "kind": "merge"
        },
        {
          "id": "rmm-and-payload-execution",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "temp-directory-persistence",
      "type": "query",
      "label": "Rare binaries running from Temp directory",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT LOWER(process_name) AS process, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_process_activity WHERE (LOWER(process_path) LIKE '%\\\\temp\\\\vhlp-%' OR LOWER(process_path) LIKE '%\\\\temp\\\\scnr-%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process HAVING host_count < 3",
        "surface": "hb_process_activity",
        "description": "Find execution of persistent binaries moved to Temp with the vhlp- or scnr- naming convention, and stack-count to identify rare occurrences.",
        "expected_signal": "Persistent binaries running from Temp that are unique to a few hosts. Fleet-wide files are likely benign system components."
      },
      "parents": [
        {
          "id": "triage-initial-lure"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare binaries running from Temp directory",
        "reads": [
          "device_hostname",
          "process_path",
          "process_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT LOWER(process_name) AS process, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_process_activity WHERE (LOWER(process_path) LIKE '%\\\\temp\\\\vhlp-%' OR LOWER(process_path) LIKE '%\\\\temp\\\\scnr-%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process HAVING host_count < 3",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Persistent binaries running from Temp that are unique to a few hosts. Fleet-wide files are likely benign system components.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_name"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "script-based-discovery",
      "type": "query",
      "label": "Discovery and AMSI bypass scripts",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "endpoint",
        "content": "SELECT device_hostname, script_content, time FROM hb_script_activity WHERE (LOWER(script_content) LIKE '%amsiinitfailed%' OR LOWER(script_content) LIKE '%whoami /groups%' OR LOWER(script_content) LIKE '%net group /dom%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_script_activity",
        "description": "Identify script blocks attempting to disable AMSI or enumerate domain groups and users.",
        "expected_signal": "Script contents matching the campaign's discovery and evasion tradecraft. Silence proofs no such script blocks were logged."
      },
      "parents": [
        {
          "id": "triage-initial-lure"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Discovery and AMSI bypass scripts",
        "reads": [
          "device_hostname",
          "script_content",
          "time"
        ],
        "source": "hb_script_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, script_content, time FROM hb_script_activity WHERE (LOWER(script_content) LIKE '%amsiinitfailed%' OR LOWER(script_content) LIKE '%whoami /groups%' OR LOWER(script_content) LIKE '%net group /dom%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "evidence_of_absence",
        "expected": "Script contents matching the campaign's discovery and evasion tradecraft. Silence proofs no such script blocks were logged.",
        "verified": "dry-run",
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "triage-full-chain",
      "type": "analytic",
      "label": "Weigh full-chain evidence",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "triage-initial-lure",
          "temp-directory-persistence",
          "script-based-discovery"
        ],
        "objective": "Determine if the hosts with suspicious early vishing lures also show definitive signs of payload persistence and domain discovery.",
        "description": "Review the early social engineering verdict alongside the follow-on persistence and discovery evidence.",
        "max_iterations": 5,
        "expected_signal": "A final verdict identifying hosts undergoing a complete Spring Ring attack lifecycle.",
        "success_criteria": "A per-host verdict of malicious | suspicious | benign."
      },
      "parents": [
        {
          "id": "temp-directory-persistence",
          "kind": "merge"
        },
        {
          "id": "script-based-discovery",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on final verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage-full-chain verdict is malicious for at least one host",
        "condition": "the triage-full-chain verdict is malicious for at least one host",
        "blind_spot": "teams-voice-content-gap",
        "confidence": "high",
        "description": "Route to containment if a malicious verdict is reached.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-full-chain"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate host and capture payloads",
      "config": {
        "target": "endpoint",
        "description": "Isolate the compromised endpoint to prevent lateral movement and capture the persistent binaries for analysis.",
        "instructions": "Isolate the host from the network. Capture any executables located in the user's Temp directory matching the vhlp-* or scnr-* naming convention.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Review vishing evidence",
      "config": {
        "assignee": "analyst",
        "description": "A human analyst reviews the agent's work and host context to confirm a vishing event.",
        "instructions": "Verify the DNS resolutions to external tenants and the Quick Assist launch. Interview the user to confirm they received a call from an 'IT Technician' and were guided to launch specific software."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out hunt",
      "config": {
        "assignee": "analyst",
        "description": "Record findings for the periodic hunt cycle.",
        "instructions": "Record the absence of Spring Ring activity. If Quick Assist launches were found without corresponding DNS lures, consider these for exclusion or lower-severity monitoring."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        }
      ]
    }
  ]
}