Trojanized Utilities and Kernel EDR Impairment
An intruder has gained access via trojanized software containing AI-analysis evasion code, then loaded vulnerable drivers to disable security tools before executing ransomware.
Based on research by Cisco Talos 2026-10-09 12 steps · 5 queries T1027 T1068 T1195.002 T1486 T1562.001
Brief
The Context
Cisco Talos recently published "Making sure the checks get printed" (https://blog.talosintelligence.com/making-sure-the-checks-get-printed/) describing a campaign involving MANTLEMAZE trojans and Warlock ransomware. This threat uses trojanized software to bypass security controls before moving into a destructive ransomware phase.
Phase 1: Identifying the Beachhead
The hunt begins by scoping the fleet for the execution of known trojanized binaries. It identifies processes by hash or specific filenames such as 'kmsauto net.exe' or 'secoh-qad.exe'. It also targets unnamed binaries running from user-writable paths like Temp or Downloads with non-system integrity levels. This scoping step provides the initial list of hosts that warrant deeper investigation.
Phase 2: Network and Persistence Indicators
Once the hunt identifies a potential beachhead, it pivots to concurrent evidence in network and filesystem logs. It looks for DNS queries to known malicious domains or hostnames with suspicious entropy and length. Simultaneously, the hunt checks for the presence of the trojanized files on disk to confirm persistence. This phase helps differentiate an active intrusion from a benign or dormant PUA.
Phase 3: Defense Evasion and Impact Detection
The final technical phase looks for 'Bring Your Own Vulnerable Driver' (BYOVD) activity. It identifies rare kernel driver loads that may indicate an attacker attempting to disable EDR agents. The hunt then correlates these driver loads with mass file modification activity, where a single process changes more than 1,000 files. This behavioral combination is a high-confidence indicator of ransomware encryption.
Why this is a
Hunt This is a hunt rather than a standing detection because individual signals like a PUA hash or a rare driver load often create excessive noise. This playbook correlates signals across process, network, kernel, and filesystem telemetry to identify a specific attack lifecycle. It allows an analyst to weigh evidence before deciding on containment. The process involves an agent or analyst evaluating "A3" evasion indicators—imperative language instructions designed to deceive automated AI analysis engines.
Blind Spots and Limitations
The primary blind spot is telemetry loss. If the adversary successfully impairs the EDR agent using a kernel driver, the subsequent encryption activity may not be recorded. Furthermore, the DNS detection is limited to string-based analysis and may miss sophisticated C2 rotation techniques or low-volume beaconing.
In this series
Steps
-
Scope by trojanized utility execution
Query · scopingIdentify initial beachheads by matching malicious processes by hash, original filename, or behavioral traits in user-writable paths.
reads hb_process_activitysqlSELECT device_hostname, process_name, process_original_file_name, process_hash_sha256, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{trojan_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 OR LOWER(process_original_file_name) IN ('kmsauto net.exe', 'secoh-qad.exe', 'sample.exe', 'f_003914.exe') OR (LOWER(process_name) LIKE '%\kmsauto net.exe' OR LOWER(process_name) LIKE '%\secoh-qad.exe' OR LOWER(process_name) LIKE '%\sample.exe') OR ( (LOWER(process_path) LIKE '%\users\%' OR LOWER(process_path) LIKE '%\temp\%' OR LOWER(process_path) LIKE '%\downloads\%') AND integrity_level != 'System' AND (process_original_file_name IS NULL OR process_original_file_name = '') ) ) AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. A list of hosts running reported malware or suspicious, unnamed binaries from user folders. Results define the scope for the rest of the hunt.
-
DNS queries to C2 or high-entropy domains
Query · enrichmentDetect network beacons to known malicious domains or anomalous high-entropy domains on scoped hosts.
reads hb_dns_activitysqlSELECT device_hostname, query_hostname, process_name, COUNT(*) as lookups, MIN(time) as first_seen FROM hb_dns_activity WHERE (instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 OR (LENGTH(query_hostname) > 24 AND LOWER(query_hostname) NOT LIKE '%.local%' AND LOWER(query_hostname) NOT LIKE '%.internal%')) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1, 2, 3What a hit looks like. DNS resolutions for reported C2 domains or long, complex hostnames which may represent DGA or C2 rotation. Silence suggests the beaconing infrastructure has rotated.
-
Persistent file drops on scoped hosts
Query · enrichmentIdentify filesystem artifacts matching the reported malware hashes on the scoped hosts.
reads hb_file_activitysqlSELECT device_hostname, file_path, file_hash_sha256, process_name, time FROM hb_file_activity WHERE instr(',' || '{{trojan_hashes}}' || ',', ',' || LOWER(file_hash_sha256) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. Confirmed presence of reported trojanized files on disk. Silence means the samples were run in-memory or using different hashes.
-
Early-stage beachhead triage
Agent triageEvaluate whether the initial process, network, and file signals indicate a confirmed infection and look for A3 evasion indicators.
-
Kernel EDR impairment via BYOVD
Query · baselineIdentify rare driver loads across the fleet that may represent the use of vulnerable drivers to disable security agents.
reads hb_kernel_extension_activitysqlSELECT device_hostname, driver_path, driver_signature_subject, COUNT(*) as loads, MIN(time) as first_seen FROM hb_kernel_extension_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1, 2, 3 HAVING COUNT(DISTINCT device_hostname) <= 3What a hit looks like. A list of hosts loading rare drivers. Fleet-wide rarity is a strong indicator of manual BYOVD tampering to impair security tools.
-
High-volume file encryption (Impact)
Query · detection candidateIdentify mass file modification activity indicative of ransomware encryption, grouping by file extension.
reads hb_file_activitysqlSELECT device_hostname, process_name, SUBSTR(file_name, INSTR(file_name, '.') + 1) as extension, COUNT(*) as file_count, MIN(time) as first_op FROM hb_file_activity WHERE activity_id IN (4, 5) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1, 2, 3 HAVING file_count > 1000What a hit looks like. A process modifying over 1000 files, likely with a consistent extension. This distinguishes ransomware from typical application updates or temporary file cleanup.
-
Complete attack chain assessment
Agent triageSynthesize early beachhead evidence with follow-on EDR impairment and encryption signals to confirm a full ransomware intrusion.
-
Route on verdict
DecisionDirect immediate containment for malicious hosts and forensic review for suspicious activity.
-
Isolate infected host
Response actionImmediately contain the host to stop the encryption process and prevent lateral movement.
-
Forensic analyst review
Analyst taskPerform a deep dive into the A3 evasion techniques and the extent of driver tampering.
-
Hunt closure and detection tuning
Analyst taskDocument the hunt outcome and convert effective behavioral signals into standing detections.
Coverage
Scenario coverage
| Stage | Covered | How, or why not |
|---|---|---|
| Trojanised Software Execution T1195 |
Yes | scoping-by-process, file-drops-persistence |
| AI-Analysis Evasion (A3) T1027 |
Yes | early-triage-agent |
| Kernel driver EDR Impairment T1562.001 · T1068 |
Yes | byovd-driver-load |
| Ransomware Encryption T1486 |
Yes | ransomware-impact |
| Citrix NetScaler Vulnerability Exploitation T1190 |
Out of scope | Belongs to another part of the 'Making sure the checks get printed' series. |
| Abuse of Lawful Identity Access T1078 |
Out of scope | Belongs to another part of the 'Making sure the checks get printed' series. |
Blind spots
- Needs EDR driver-load telemetry and kernel activity logs. A successful BYOVD attack may blind the EDR agent, meaning the ransomware impact results would be empty even if encryption occurred. It would answer whether the adversary successfully disabled logging before the encryption phase began.
- Needs native entropy-calculating query functions. DNS detection relies on length and known patterns; true DGA or high-entropy domains might be missed without a specialized analysis surface. It would answer whether a domain is algorithmically generated (DGA) or highly entropic.
Parameters & data
Parameters
| Parameter | Type | Default | What it is |
|---|---|---|---|
c2_domains | list[domain] | w32.9f1f11a708-100.sbx.tg, w32.fed979f93b-95.sbx.tg, w32.9896a6fcb9-95.sbx.tg, pulsebrowser.29kh.in12.talos, w32.58d6fec4ba-95.sbx.tg | Malicious domains used for C2 or infrastructure associated with the campaign. |
lookback_days | number | 14 | Days of history to examine. |
scope_hosts | list[host] | — | Restrict the hunt to these hostnames; leave empty to hunt across the entire estate. |
trojan_hashes | list[hash] | 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507, fed979f93bcaf4e73ebd25748093a92095d5109cbd01d55f97bdc50ce509ad2f, 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f, 73ac1bbfaee6c76c34f655ac0477a4cd930f2aa55e658c8e312ff81aac9a741f, 58d6fec4ba24c32d38c9a0c7c39df3cb0e91f500b323e841121d703c7b718681 | SHA256 hashes of trojanized utilities and MANTLEMAZE samples. |
Telemetry
| Source | Category | Telemetry |
|---|---|---|
| Endpoint telemetry (hb_ surfaces) | endpoint | endpoint |
Source
---
analysis: 'A single rule on a trojan hash might be dismissed as a False Positive or
PUAs. This hunt correlates the initial access with two critical follow-on behaviors:
kernel driver tampering (BYOVD) and mass file encryption. The analyst weighs these
across three different telemetry surfaces to confirm a high-confidence intrusion.'
blind_spots:
- id: telemetry-gap-impairment
question: whether the adversary successfully disabled logging before the encryption
phase began
requires: EDR driver-load telemetry and kernel activity logs
risk: A successful BYOVD attack may blind the EDR agent, meaning the ransomware
impact results would be empty even if encryption occurred.
stage: kernel-driver-edr-impairment
- id: entropy-analysis-limitation
question: whether a domain is algorithmically generated (DGA) or highly entropic
requires: native entropy-calculating query functions
risk: DNS detection relies on length and known patterns; true DGA or high-entropy
domains might be missed without a specialized analysis surface.
stage: trojanized-utility-execution
coverage:
- stage: trojanized-utility-execution
status: covered
steps:
- scoping-by-process
- file-drops-persistence
- stage: ai-analysis-evasion-obfuscation
status: covered
steps:
- early-triage-agent
- stage: kernel-driver-edr-impairment
status: covered
steps:
- byovd-driver-load
- stage: ransomware-data-encryption
status: covered
steps:
- ransomware-impact
- reason: Belongs to another part of the 'Making sure the checks get printed' series.
stage: citrix-netscaler-exploitation
status: out_of_scope
- reason: Belongs to another part of the 'Making sure the checks get printed' series.
stage: lawful-access-identity-abuse
status: out_of_scope
guardrails:
claims: no_unsupported
evidence: citation_required
missing_data: not_benign
telemetry: untrusted
hunt:
applicability: campaign-specific
handoff: promote-to-detection
justification: The MANTLEMAZE and Warlock ransomware chain uses sophisticated AI-evasion
and kernel-impairment techniques that bypass traditional single-point detections.
This phased hunt ensures that even if one stage is evasive, the correlation of
the full attack lifecycle provides a definitive result.
methodology: model-assisted
trigger: intel-report
hypothesis: An intruder has gained access via trojanized software containing AI-analysis
evasion code, then loaded vulnerable drivers to disable security tools before executing
ransomware.
labels:
- hunt
- attack.t1195.002
- attack.t1027
- attack.t1562.001
- attack.t1068
- attack.t1486
- defense evasion
- execution
- impact
- initial access
name: Trojanized Utilities and Kernel EDR Impairment
parameters:
c2_domains:
default:
- w32.9f1f11a708-100.sbx.tg
- w32.fed979f93b-95.sbx.tg
- w32.9896a6fcb9-95.sbx.tg
- pulsebrowser.29kh.in12.talos
- w32.58d6fec4ba-95.sbx.tg
description: Malicious domains used for C2 or infrastructure associated with the
campaign.
from:
kind: article
observed: '2026-10-08'
ref: talos-making-sure-checks-printed
type: list[domain]
lookback_days:
default: '14'
description: Days of history to examine.
from:
kind: manual
observed: '2024-10-25'
ref: standard-retention
type: number
scope_hosts:
default: []
description: Restrict the hunt to these hostnames; leave empty to hunt across
the entire estate.
from:
kind: manual
observed: '2024-10-25'
ref: analyst-defined
type: list[host]
trojan_hashes:
default:
- 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507
- fed979f93bcaf4e73ebd25748093a92095d5109cbd01d55f97bdc50ce509ad2f
- 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f
- 73ac1bbfaee6c76c34f655ac0477a4cd930f2aa55e658c8e312ff81aac9a741f
- 58d6fec4ba24c32d38c9a0c7c39df3cb0e91f500b323e841121d703c7b718681
description: SHA256 hashes of trojanized utilities and MANTLEMAZE samples.
from:
kind: article
observed: '2026-10-08'
ref: talos-making-sure-checks-printed
type: list[hash]
provenance:
authors:
- name: Huntbase hunt generation
org: huntbase.io
generated:
by: huntbase-hunt-generation
from: https://blog.talosintelligence.com/making-sure-the-checks-get-printed/
gates:
- dry-run
- lint
model: hb_google/gemini-3-flash-preview
rationale: Start by identifying any host running the reported hashes or processes
matching the trojan names. Also include a wide behavioral scoop for processes running
from user folders with non-system integrity, as these are common staging areas for
trojanized utilities.
references:
- name: "Cisco Talos \u2014 Making sure the checks get printed"
url: https://blog.talosintelligence.com/making-sure-the-checks-get-printed/
related:
- hunt: citrix-netscaler-zero-day-exploitation
reason: Initial access via Citrix CVE-2026-88779 is a network appliance intrusion
and is handled in a separate hunt.
relation: out-of-scope-alternative
- hunt: perimeter-identity-abuse-hunt
relation: follows
scenario:
stages:
- name: Citrix NetScaler Vulnerability Exploitation
observables:
- CVE-2026-88779
- Memory overflow in Citrix NetScaler
slug: citrix-netscaler-exploitation
tactic: initial-access
techniques:
- T1190
- name: Abuse of Lawful Identity Access
observables:
- Abuse of Danish company lawful access to CPR system
slug: lawful-access-identity-abuse
tactic: initial-access
techniques:
- T1078
- name: Trojanised Software Execution
observables:
- KMSAuto Net.exe
- SECOH-QAD.exe
- PulseBrowser.29kh.in12.Talos
- 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507
- fed979f93bcaf4e73ebd25748093a92095d5109cbd01d55f97bdc50ce509ad2f
- 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f
- 58d6fec4ba24c32d38c9a0c7c39df3cb0e91f500b323e841121d703c7b718681
slug: trojanized-utility-execution
tactic: execution
techniques:
- T1195
- name: AI-Analysis Evasion (A3)
observables:
- Plaintext imperative language instructions in binaries
- Template spraying designed to trick LLMs
- Instructions telling AI to ignore files
slug: ai-analysis-evasion-obfuscation
tactic: defense-evasion
techniques:
- T1027
- name: Kernel driver EDR Impairment
observables:
- Abusing vulnerable drivers to disable EDR from kernel space
- MANTLEMAZE driver abuse
slug: kernel-driver-edr-impairment
tactic: defense-evasion
techniques:
- T1562.001
- T1068
- name: Ransomware Encryption
observables:
- Warlock ransomware activity
- Encryption of water utility and telecom systems
slug: ransomware-data-encryption
tactic: impact
techniques:
- T1486
summary: Mantlemaze and other threat actors are employing 'AI-Analysis Evasion'
(A3) by embedding natural-language instructions in malware to trick automated
scrutiny, often pairing it with kernel-level driver abuse to disable EDR. These
techniques are observed alongside high-impact threats including vulnerabilities
in Citrix NetScaler and ransomware attacks by groups like Warlock.
series:
index: 2
slug: making-sure-the-checks-get-printed
title: Making sure the checks get printed
total: 2
severity: high
targets:
analyst:
name: Tier-2 analyst
role: analyst
endpoint:
category: endpoint
name: Endpoint telemetry (hb_ surfaces)
telemetry:
- endpoint
hunter:
agent: true
name: Hunt agent
tlp: clear
type: investigation
---
# Trojanized Utilities and Kernel EDR Impairment
This hunt identifies the full lifecycle of an endpoint intrusion starting with trojanized utility execution, such as KMSAuto or PulseBrowser, which incorporates A3 (AI-Analysis Evasion) techniques. It follows the chain from initial access to kernel-level defense evasion using BYOVD (Bring Your Own Vulnerable Driver) and concludes with mass file encryption indicative of Warlock ransomware. The phased approach ensures that later impact signals are analyzed in the context of the initial beachhead.
## scoping-by-process
<!-- Scope by trojanized utility execution -->
Identify initial beachheads by matching malicious processes by hash, original filename, or behavioral traits in user-writable paths.
```sqlite target=endpoint role=scoping params=(trojan_hashes=trojan_hashes, lookback_days=lookback_days)
~~~yaml
expected: A list of hosts running reported malware or suspicious, unnamed binaries
from user folders. Results define the scope for the rest of the hunt.
reads:
- device_hostname
- integrity_level
- process_hash_sha256
- process_name
- process_original_file_name
- process_path
- time
- user_name
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT device_hostname, process_name, process_original_file_name, process_hash_sha256, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{trojan_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 OR LOWER(process_original_file_name) IN ('kmsauto net.exe', 'secoh-qad.exe', 'sample.exe', 'f_003914.exe') OR (LOWER(process_name) LIKE '%\kmsauto net.exe' OR LOWER(process_name) LIKE '%\secoh-qad.exe' OR LOWER(process_name) LIKE '%\sample.exe') OR ( (LOWER(process_path) LIKE '%\users\%' OR LOWER(process_path) LIKE '%\temp\%' OR LOWER(process_path) LIKE '%\downloads\%') AND integrity_level != 'System' AND (process_original_file_name IS NULL OR process_original_file_name = '') ) ) AND time >= datetime('now', '-{{lookback_days}} days')
```
## parallel-initial-evidence
<!-- Gather initial intrusion evidence -->
parallel:
- → dns-to-c2
- → file-drops-persistence
join: → early-triage-agent
## dns-to-c2
<!-- DNS queries to C2 or high-entropy domains -->
Detect network beacons to known malicious domains or anomalous high-entropy domains on scoped hosts.
```sqlite target=endpoint role=enrichment params=(c2_domains=c2_domains, scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: DNS resolutions for reported C2 domains or long, complex hostnames which
may represent DGA or C2 rotation. Silence suggests the beaconing infrastructure
has rotated.
reads:
- device_hostname
- process_name
- query_hostname
- time
silence: not_evidence_of_absence
source: hb_dns_activity
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT device_hostname, query_hostname, process_name, COUNT(*) as lookups, MIN(time) as first_seen FROM hb_dns_activity WHERE (instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 OR (LENGTH(query_hostname) > 24 AND LOWER(query_hostname) NOT LIKE '%.local%' AND LOWER(query_hostname) NOT LIKE '%.internal%')) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1, 2, 3
```
## file-drops-persistence
<!-- Persistent file drops on scoped hosts -->
Identify filesystem artifacts matching the reported malware hashes on the scoped hosts.
```sqlite target=endpoint role=enrichment params=(trojan_hashes=trojan_hashes, scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: Confirmed presence of reported trojanized files on disk. Silence means the
samples were run in-memory or using different hashes.
reads:
- device_hostname
- file_hash_sha256
- file_path
- process_name
- time
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT device_hostname, file_path, file_hash_sha256, process_name, time FROM hb_file_activity WHERE instr(',' || '{{trojan_hashes}}' || ',', ',' || LOWER(file_hash_sha256) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```
## early-triage-agent
<!-- Early-stage beachhead triage -->
```agent target=hunter
cite: required
context:
- scoping-by-process
- dns-to-c2
- file-drops-persistence
max_iterations: 3
objective: Determine if the scoped hosts are confirmed beachheads. Specifically look
for evidence of A3 evasion, such as binaries that have been flagged by AV but show
execution, or unusual process trees originating from the trojanized utilities.
success_criteria: A per-host verdict citing specific rows from the process and DNS
results.
tools:
- endpoint
```
## parallel-impact
<!-- Hunt for post-exploitation defense evasion and impact -->
parallel:
- → byovd-driver-load
- → ransomware-impact
join: → follow-on-triage-agent
## byovd-driver-load
<!-- Kernel EDR impairment via BYOVD -->
Identify rare driver loads across the fleet that may represent the use of vulnerable drivers to disable security agents.
```sqlite target=endpoint role=baseline params=(scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
baseline:
compare: first_seen
window: '{{lookback_days}}d'
expected: A list of hosts loading rare drivers. Fleet-wide rarity is a strong indicator
of manual BYOVD tampering to impair security tools.
prevalence:
by: device_hostname
key:
- driver_path
rare_below: 3
reads:
- device_hostname
- driver_path
- driver_signature_subject
- time
silence: not_evidence_of_absence
source: hb_kernel_extension_activity
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT device_hostname, driver_path, driver_signature_subject, COUNT(*) as loads, MIN(time) as first_seen FROM hb_kernel_extension_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1, 2, 3 HAVING COUNT(DISTINCT device_hostname) <= 3
```
## ransomware-impact
<!-- High-volume file encryption (Impact) -->
Identify mass file modification activity indicative of ransomware encryption, grouping by file extension.
```sqlite target=endpoint role=detection-candidate params=(scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: A process modifying over 1000 files, likely with a consistent extension.
This distinguishes ransomware from typical application updates or temporary file
cleanup.
reads:
- activity_id
- device_hostname
- file_name
- process_name
- time
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT device_hostname, process_name, SUBSTR(file_name, INSTR(file_name, '.') + 1) as extension, COUNT(*) as file_count, MIN(time) as first_op FROM hb_file_activity WHERE activity_id IN (4, 5) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1, 2, 3 HAVING file_count > 1000
```
## follow-on-triage-agent
<!-- Complete attack chain assessment -->
```agent target=hunter
cite: required
context:
- early-triage-agent
- byovd-driver-load
- ransomware-impact
max_iterations: 6
objective: Evaluate the full attack chain. Confirm whether hosts with a confirmed
beachhead (from Agent 1) have subsequently loaded rare drivers and performed mass
file encryption.
success_criteria: A per-host verdict of malicious | suspicious, citing drivers and
file counts.
tools:
- endpoint
```
## route-decision
<!-- Route on verdict -->
if~: "the follow-on-triage-agent verdict is malicious for at least one host" (confidence: high, judge=hunter)
then: → isolate-host
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: telemetry-gap-impairment)
else: → closure
## isolate-host
<!-- Isolate infected host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host from the network and revoke any active credentials or administrative sessions that were active on the host at the time of the trojan execution.
```
→ analyst-review
## analyst-review
<!-- Forensic analyst review -->
```manual target=analyst
Review the binaries found on the scoped hosts for imperative language instructions meant to deceive AI analysts. Identify the vulnerable driver and verify whether its use corresponds to a known MANTLEMAZE variant.
```
→ closure
## closure
<!-- Hunt closure and detection tuning -->
```manual target=analyst
Record the hunt findings. If the ransomware-impact query correctly identified an intrusion, promote it to a standing detection rule. If A3 evasion was identified, ensure future analysis pipelines treat extracted sample text as evidence only.
```
→ end
Run it
Take this hunt into your environment.
Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.
Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.