← All hunts high TLP:CLEAR Part 2 of 2

Trojanized Utilities and Kernel EDR Impairment

An intruder has gained access via trojanized software containing AI-analysis evasion code, then loaded vulnerable drivers to disable security tools before executing ransomware.

Based on research by Cisco Talos 2026-10-09 12 steps · 5 queries T1027 T1068 T1195.002 T1486 T1562.001

Brief

The Context

Cisco Talos recently published "Making sure the checks get printed" (https://blog.talosintelligence.com/making-sure-the-checks-get-printed/) describing a campaign involving MANTLEMAZE trojans and Warlock ransomware. This threat uses trojanized software to bypass security controls before moving into a destructive ransomware phase.

Phase 1: Identifying the Beachhead

The hunt begins by scoping the fleet for the execution of known trojanized binaries. It identifies processes by hash or specific filenames such as 'kmsauto net.exe' or 'secoh-qad.exe'. It also targets unnamed binaries running from user-writable paths like Temp or Downloads with non-system integrity levels. This scoping step provides the initial list of hosts that warrant deeper investigation.

Phase 2: Network and Persistence Indicators

Once the hunt identifies a potential beachhead, it pivots to concurrent evidence in network and filesystem logs. It looks for DNS queries to known malicious domains or hostnames with suspicious entropy and length. Simultaneously, the hunt checks for the presence of the trojanized files on disk to confirm persistence. This phase helps differentiate an active intrusion from a benign or dormant PUA.

Phase 3: Defense Evasion and Impact Detection

The final technical phase looks for 'Bring Your Own Vulnerable Driver' (BYOVD) activity. It identifies rare kernel driver loads that may indicate an attacker attempting to disable EDR agents. The hunt then correlates these driver loads with mass file modification activity, where a single process changes more than 1,000 files. This behavioral combination is a high-confidence indicator of ransomware encryption.

Why this is a

Hunt This is a hunt rather than a standing detection because individual signals like a PUA hash or a rare driver load often create excessive noise. This playbook correlates signals across process, network, kernel, and filesystem telemetry to identify a specific attack lifecycle. It allows an analyst to weigh evidence before deciding on containment. The process involves an agent or analyst evaluating "A3" evasion indicators—imperative language instructions designed to deceive automated AI analysis engines.

Blind Spots and Limitations

The primary blind spot is telemetry loss. If the adversary successfully impairs the EDR agent using a kernel driver, the subsequent encryption activity may not be recorded. Furthermore, the DNS detection is limited to string-based analysis and may miss sophisticated C2 rotation techniques or low-volume beaconing.

In this series

Steps

  1. Scope by trojanized utility execution

    Query · scoping

    Identify initial beachheads by matching malicious processes by hash, original filename, or behavioral traits in user-writable paths.

    reads hb_process_activitysql
    SELECT device_hostname, process_name, process_original_file_name, process_hash_sha256, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{trojan_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 OR LOWER(process_original_file_name) IN ('kmsauto net.exe', 'secoh-qad.exe', 'sample.exe', 'f_003914.exe') OR (LOWER(process_name) LIKE '%\kmsauto net.exe' OR LOWER(process_name) LIKE '%\secoh-qad.exe' OR LOWER(process_name) LIKE '%\sample.exe') OR ( (LOWER(process_path) LIKE '%\users\%' OR LOWER(process_path) LIKE '%\temp\%' OR LOWER(process_path) LIKE '%\downloads\%') AND integrity_level != 'System' AND (process_original_file_name IS NULL OR process_original_file_name = '') ) ) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. A list of hosts running reported malware or suspicious, unnamed binaries from user folders. Results define the scope for the rest of the hunt.

  2. DNS queries to C2 or high-entropy domains

    Query · enrichment

    Detect network beacons to known malicious domains or anomalous high-entropy domains on scoped hosts.

    reads hb_dns_activitysql
    SELECT device_hostname, query_hostname, process_name, COUNT(*) as lookups, MIN(time) as first_seen FROM hb_dns_activity WHERE (instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 OR (LENGTH(query_hostname) > 24 AND LOWER(query_hostname) NOT LIKE '%.local%' AND LOWER(query_hostname) NOT LIKE '%.internal%')) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1, 2, 3

    What a hit looks like. DNS resolutions for reported C2 domains or long, complex hostnames which may represent DGA or C2 rotation. Silence suggests the beaconing infrastructure has rotated.

  3. Persistent file drops on scoped hosts

    Query · enrichment

    Identify filesystem artifacts matching the reported malware hashes on the scoped hosts.

    reads hb_file_activitysql
    SELECT device_hostname, file_path, file_hash_sha256, process_name, time FROM hb_file_activity WHERE instr(',' || '{{trojan_hashes}}' || ',', ',' || LOWER(file_hash_sha256) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Confirmed presence of reported trojanized files on disk. Silence means the samples were run in-memory or using different hashes.

  4. Early-stage beachhead triage

    Agent triage

    Evaluate whether the initial process, network, and file signals indicate a confirmed infection and look for A3 evasion indicators.

  5. Kernel EDR impairment via BYOVD

    Query · baseline

    Identify rare driver loads across the fleet that may represent the use of vulnerable drivers to disable security agents.

    reads hb_kernel_extension_activitysql
    SELECT device_hostname, driver_path, driver_signature_subject, COUNT(*) as loads, MIN(time) as first_seen FROM hb_kernel_extension_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1, 2, 3 HAVING COUNT(DISTINCT device_hostname) <= 3

    What a hit looks like. A list of hosts loading rare drivers. Fleet-wide rarity is a strong indicator of manual BYOVD tampering to impair security tools.

  6. High-volume file encryption (Impact)

    Query · detection candidate

    Identify mass file modification activity indicative of ransomware encryption, grouping by file extension.

    reads hb_file_activitysql
    SELECT device_hostname, process_name, SUBSTR(file_name, INSTR(file_name, '.') + 1) as extension, COUNT(*) as file_count, MIN(time) as first_op FROM hb_file_activity WHERE activity_id IN (4, 5) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1, 2, 3 HAVING file_count > 1000

    What a hit looks like. A process modifying over 1000 files, likely with a consistent extension. This distinguishes ransomware from typical application updates or temporary file cleanup.

  7. Complete attack chain assessment

    Agent triage

    Synthesize early beachhead evidence with follow-on EDR impairment and encryption signals to confirm a full ransomware intrusion.

  8. Route on verdict

    Decision

    Direct immediate containment for malicious hosts and forensic review for suspicious activity.

  9. Isolate infected host

    Response action

    Immediately contain the host to stop the encryption process and prevent lateral movement.

  10. Forensic analyst review

    Analyst task

    Perform a deep dive into the A3 evasion techniques and the extent of driver tampering.

  11. Hunt closure and detection tuning

    Analyst task

    Document the hunt outcome and convert effective behavioral signals into standing detections.

Coverage

Scenario coverage

StageCoveredHow, or why not
Trojanised Software Execution
T1195
Yes scoping-by-process, file-drops-persistence
AI-Analysis Evasion (A3)
T1027
Yes early-triage-agent
Kernel driver EDR Impairment
T1562.001 · T1068
Yes byovd-driver-load
Ransomware Encryption
T1486
Yes ransomware-impact
Citrix NetScaler Vulnerability Exploitation
T1190
Out of scope Belongs to another part of the 'Making sure the checks get printed' series.
Abuse of Lawful Identity Access
T1078
Out of scope Belongs to another part of the 'Making sure the checks get printed' series.

Blind spots

  • Needs EDR driver-load telemetry and kernel activity logs. A successful BYOVD attack may blind the EDR agent, meaning the ransomware impact results would be empty even if encryption occurred. It would answer whether the adversary successfully disabled logging before the encryption phase began.
  • Needs native entropy-calculating query functions. DNS detection relies on length and known patterns; true DGA or high-entropy domains might be missed without a specialized analysis surface. It would answer whether a domain is algorithmically generated (DGA) or highly entropic.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
c2_domainslist[domain]w32.9f1f11a708-100.sbx.tg, w32.fed979f93b-95.sbx.tg, w32.9896a6fcb9-95.sbx.tg, pulsebrowser.29kh.in12.talos, w32.58d6fec4ba-95.sbx.tgMalicious domains used for C2 or infrastructure associated with the campaign.
lookback_daysnumber14Days of history to examine.
scope_hostslist[host]—Restrict the hunt to these hostnames; leave empty to hunt across the entire estate.
trojan_hasheslist[hash]9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507, fed979f93bcaf4e73ebd25748093a92095d5109cbd01d55f97bdc50ce509ad2f, 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f, 73ac1bbfaee6c76c34f655ac0477a4cd930f2aa55e658c8e312ff81aac9a741f, 58d6fec4ba24c32d38c9a0c7c39df3cb0e91f500b323e841121d703c7b718681SHA256 hashes of trojanized utilities and MANTLEMAZE samples.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: 'A single rule on a trojan hash might be dismissed as a False Positive or
  PUAs. This hunt correlates the initial access with two critical follow-on behaviors:
  kernel driver tampering (BYOVD) and mass file encryption. The analyst weighs these
  across three different telemetry surfaces to confirm a high-confidence intrusion.'
blind_spots:
- id: telemetry-gap-impairment
  question: whether the adversary successfully disabled logging before the encryption
    phase began
  requires: EDR driver-load telemetry and kernel activity logs
  risk: A successful BYOVD attack may blind the EDR agent, meaning the ransomware
    impact results would be empty even if encryption occurred.
  stage: kernel-driver-edr-impairment
- id: entropy-analysis-limitation
  question: whether a domain is algorithmically generated (DGA) or highly entropic
  requires: native entropy-calculating query functions
  risk: DNS detection relies on length and known patterns; true DGA or high-entropy
    domains might be missed without a specialized analysis surface.
  stage: trojanized-utility-execution
coverage:
- stage: trojanized-utility-execution
  status: covered
  steps:
  - scoping-by-process
  - file-drops-persistence
- stage: ai-analysis-evasion-obfuscation
  status: covered
  steps:
  - early-triage-agent
- stage: kernel-driver-edr-impairment
  status: covered
  steps:
  - byovd-driver-load
- stage: ransomware-data-encryption
  status: covered
  steps:
  - ransomware-impact
- reason: Belongs to another part of the 'Making sure the checks get printed' series.
  stage: citrix-netscaler-exploitation
  status: out_of_scope
- reason: Belongs to another part of the 'Making sure the checks get printed' series.
  stage: lawful-access-identity-abuse
  status: out_of_scope
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: promote-to-detection
  justification: The MANTLEMAZE and Warlock ransomware chain uses sophisticated AI-evasion
    and kernel-impairment techniques that bypass traditional single-point detections.
    This phased hunt ensures that even if one stage is evasive, the correlation of
    the full attack lifecycle provides a definitive result.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An intruder has gained access via trojanized software containing AI-analysis
  evasion code, then loaded vulnerable drivers to disable security tools before executing
  ransomware.
labels:
- hunt
- attack.t1195.002
- attack.t1027
- attack.t1562.001
- attack.t1068
- attack.t1486
- defense evasion
- execution
- impact
- initial access
name: Trojanized Utilities and Kernel EDR Impairment
parameters:
  c2_domains:
    default:
    - w32.9f1f11a708-100.sbx.tg
    - w32.fed979f93b-95.sbx.tg
    - w32.9896a6fcb9-95.sbx.tg
    - pulsebrowser.29kh.in12.talos
    - w32.58d6fec4ba-95.sbx.tg
    description: Malicious domains used for C2 or infrastructure associated with the
      campaign.
    from:
      kind: article
      observed: '2026-10-08'
      ref: talos-making-sure-checks-printed
    type: list[domain]
  lookback_days:
    default: '14'
    description: Days of history to examine.
    from:
      kind: manual
      observed: '2024-10-25'
      ref: standard-retention
    type: number
  scope_hosts:
    default: []
    description: Restrict the hunt to these hostnames; leave empty to hunt across
      the entire estate.
    from:
      kind: manual
      observed: '2024-10-25'
      ref: analyst-defined
    type: list[host]
  trojan_hashes:
    default:
    - 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507
    - fed979f93bcaf4e73ebd25748093a92095d5109cbd01d55f97bdc50ce509ad2f
    - 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f
    - 73ac1bbfaee6c76c34f655ac0477a4cd930f2aa55e658c8e312ff81aac9a741f
    - 58d6fec4ba24c32d38c9a0c7c39df3cb0e91f500b323e841121d703c7b718681
    description: SHA256 hashes of trojanized utilities and MANTLEMAZE samples.
    from:
      kind: article
      observed: '2026-10-08'
      ref: talos-making-sure-checks-printed
    type: list[hash]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://blog.talosintelligence.com/making-sure-the-checks-get-printed/
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Start by identifying any host running the reported hashes or processes
  matching the trojan names. Also include a wide behavioral scoop for processes running
  from user folders with non-system integrity, as these are common staging areas for
  trojanized utilities.
references:
- name: "Cisco Talos \u2014 Making sure the checks get printed"
  url: https://blog.talosintelligence.com/making-sure-the-checks-get-printed/
related:
- hunt: citrix-netscaler-zero-day-exploitation
  reason: Initial access via Citrix CVE-2026-88779 is a network appliance intrusion
    and is handled in a separate hunt.
  relation: out-of-scope-alternative
- hunt: perimeter-identity-abuse-hunt
  relation: follows
scenario:
  stages:
  - name: Citrix NetScaler Vulnerability Exploitation
    observables:
    - CVE-2026-88779
    - Memory overflow in Citrix NetScaler
    slug: citrix-netscaler-exploitation
    tactic: initial-access
    techniques:
    - T1190
  - name: Abuse of Lawful Identity Access
    observables:
    - Abuse of Danish company lawful access to CPR system
    slug: lawful-access-identity-abuse
    tactic: initial-access
    techniques:
    - T1078
  - name: Trojanised Software Execution
    observables:
    - KMSAuto Net.exe
    - SECOH-QAD.exe
    - PulseBrowser.29kh.in12.Talos
    - 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507
    - fed979f93bcaf4e73ebd25748093a92095d5109cbd01d55f97bdc50ce509ad2f
    - 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f
    - 58d6fec4ba24c32d38c9a0c7c39df3cb0e91f500b323e841121d703c7b718681
    slug: trojanized-utility-execution
    tactic: execution
    techniques:
    - T1195
  - name: AI-Analysis Evasion (A3)
    observables:
    - Plaintext imperative language instructions in binaries
    - Template spraying designed to trick LLMs
    - Instructions telling AI to ignore files
    slug: ai-analysis-evasion-obfuscation
    tactic: defense-evasion
    techniques:
    - T1027
  - name: Kernel driver EDR Impairment
    observables:
    - Abusing vulnerable drivers to disable EDR from kernel space
    - MANTLEMAZE driver abuse
    slug: kernel-driver-edr-impairment
    tactic: defense-evasion
    techniques:
    - T1562.001
    - T1068
  - name: Ransomware Encryption
    observables:
    - Warlock ransomware activity
    - Encryption of water utility and telecom systems
    slug: ransomware-data-encryption
    tactic: impact
    techniques:
    - T1486
  summary: Mantlemaze and other threat actors are employing 'AI-Analysis Evasion'
    (A3) by embedding natural-language instructions in malware to trick automated
    scrutiny, often pairing it with kernel-level driver abuse to disable EDR. These
    techniques are observed alongside high-impact threats including vulnerabilities
    in Citrix NetScaler and ransomware attacks by groups like Warlock.
series:
  index: 2
  slug: making-sure-the-checks-get-printed
  title: Making sure the checks get printed
  total: 2
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
tlp: clear
type: investigation
---


# Trojanized Utilities and Kernel EDR Impairment

This hunt identifies the full lifecycle of an endpoint intrusion starting with trojanized utility execution, such as KMSAuto or PulseBrowser, which incorporates A3 (AI-Analysis Evasion) techniques. It follows the chain from initial access to kernel-level defense evasion using BYOVD (Bring Your Own Vulnerable Driver) and concludes with mass file encryption indicative of Warlock ransomware. The phased approach ensures that later impact signals are analyzed in the context of the initial beachhead.

## scoping-by-process
<!-- Scope by trojanized utility execution -->
Identify initial beachheads by matching malicious processes by hash, original filename, or behavioral traits in user-writable paths.

```sqlite target=endpoint role=scoping params=(trojan_hashes=trojan_hashes, lookback_days=lookback_days)
~~~yaml
expected: A list of hosts running reported malware or suspicious, unnamed binaries
  from user folders. Results define the scope for the rest of the hunt.
reads:
- device_hostname
- integrity_level
- process_hash_sha256
- process_name
- process_original_file_name
- process_path
- time
- user_name
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT device_hostname, process_name, process_original_file_name, process_hash_sha256, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{trojan_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 OR LOWER(process_original_file_name) IN ('kmsauto net.exe', 'secoh-qad.exe', 'sample.exe', 'f_003914.exe') OR (LOWER(process_name) LIKE '%\kmsauto net.exe' OR LOWER(process_name) LIKE '%\secoh-qad.exe' OR LOWER(process_name) LIKE '%\sample.exe') OR ( (LOWER(process_path) LIKE '%\users\%' OR LOWER(process_path) LIKE '%\temp\%' OR LOWER(process_path) LIKE '%\downloads\%') AND integrity_level != 'System' AND (process_original_file_name IS NULL OR process_original_file_name = '') ) ) AND time >= datetime('now', '-{{lookback_days}} days')
```

## parallel-initial-evidence
<!-- Gather initial intrusion evidence -->
parallel:
- → dns-to-c2
- → file-drops-persistence
join: → early-triage-agent

## dns-to-c2
<!-- DNS queries to C2 or high-entropy domains -->
Detect network beacons to known malicious domains or anomalous high-entropy domains on scoped hosts.

```sqlite target=endpoint role=enrichment params=(c2_domains=c2_domains, scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: DNS resolutions for reported C2 domains or long, complex hostnames which
  may represent DGA or C2 rotation. Silence suggests the beaconing infrastructure
  has rotated.
reads:
- device_hostname
- process_name
- query_hostname
- time
silence: not_evidence_of_absence
source: hb_dns_activity
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT device_hostname, query_hostname, process_name, COUNT(*) as lookups, MIN(time) as first_seen FROM hb_dns_activity WHERE (instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 OR (LENGTH(query_hostname) > 24 AND LOWER(query_hostname) NOT LIKE '%.local%' AND LOWER(query_hostname) NOT LIKE '%.internal%')) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1, 2, 3
```

## file-drops-persistence
<!-- Persistent file drops on scoped hosts -->
Identify filesystem artifacts matching the reported malware hashes on the scoped hosts.

```sqlite target=endpoint role=enrichment params=(trojan_hashes=trojan_hashes, scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: Confirmed presence of reported trojanized files on disk. Silence means the
  samples were run in-memory or using different hashes.
reads:
- device_hostname
- file_hash_sha256
- file_path
- process_name
- time
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT device_hostname, file_path, file_hash_sha256, process_name, time FROM hb_file_activity WHERE instr(',' || '{{trojan_hashes}}' || ',', ',' || LOWER(file_hash_sha256) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## early-triage-agent
<!-- Early-stage beachhead triage -->
```agent target=hunter
cite: required
context:
- scoping-by-process
- dns-to-c2
- file-drops-persistence
max_iterations: 3
objective: Determine if the scoped hosts are confirmed beachheads. Specifically look
  for evidence of A3 evasion, such as binaries that have been flagged by AV but show
  execution, or unusual process trees originating from the trojanized utilities.
success_criteria: A per-host verdict citing specific rows from the process and DNS
  results.
tools:
- endpoint
```

## parallel-impact
<!-- Hunt for post-exploitation defense evasion and impact -->
parallel:
- → byovd-driver-load
- → ransomware-impact
join: → follow-on-triage-agent

## byovd-driver-load
<!-- Kernel EDR impairment via BYOVD -->
Identify rare driver loads across the fleet that may represent the use of vulnerable drivers to disable security agents.

```sqlite target=endpoint role=baseline params=(scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: A list of hosts loading rare drivers. Fleet-wide rarity is a strong indicator
  of manual BYOVD tampering to impair security tools.
prevalence:
  by: device_hostname
  key:
  - driver_path
  rare_below: 3
reads:
- device_hostname
- driver_path
- driver_signature_subject
- time
silence: not_evidence_of_absence
source: hb_kernel_extension_activity
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT device_hostname, driver_path, driver_signature_subject, COUNT(*) as loads, MIN(time) as first_seen FROM hb_kernel_extension_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1, 2, 3 HAVING COUNT(DISTINCT device_hostname) <= 3
```

## ransomware-impact
<!-- High-volume file encryption (Impact) -->
Identify mass file modification activity indicative of ransomware encryption, grouping by file extension.

```sqlite target=endpoint role=detection-candidate params=(scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: A process modifying over 1000 files, likely with a consistent extension.
  This distinguishes ransomware from typical application updates or temporary file
  cleanup.
reads:
- activity_id
- device_hostname
- file_name
- process_name
- time
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT device_hostname, process_name, SUBSTR(file_name, INSTR(file_name, '.') + 1) as extension, COUNT(*) as file_count, MIN(time) as first_op FROM hb_file_activity WHERE activity_id IN (4, 5) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1, 2, 3 HAVING file_count > 1000
```

## follow-on-triage-agent
<!-- Complete attack chain assessment -->
```agent target=hunter
cite: required
context:
- early-triage-agent
- byovd-driver-load
- ransomware-impact
max_iterations: 6
objective: Evaluate the full attack chain. Confirm whether hosts with a confirmed
  beachhead (from Agent 1) have subsequently loaded rare drivers and performed mass
  file encryption.
success_criteria: A per-host verdict of malicious | suspicious, citing drivers and
  file counts.
tools:
- endpoint
```

## route-decision
<!-- Route on verdict -->
if~: "the follow-on-triage-agent verdict is malicious for at least one host" (confidence: high, judge=hunter)
then: → isolate-host
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: telemetry-gap-impairment)
else: → closure

## isolate-host
<!-- Isolate infected host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host from the network and revoke any active credentials or administrative sessions that were active on the host at the time of the trojan execution.
```
→ analyst-review

## analyst-review
<!-- Forensic analyst review -->
```manual target=analyst
Review the binaries found on the scoped hosts for imperative language instructions meant to deceive AI analysts. Identify the vulnerable driver and verify whether its use corresponds to a known MANTLEMAZE variant.
```
→ closure

## closure
<!-- Hunt closure and detection tuning -->
```manual target=analyst
Record the hunt findings. If the ransomware-impact query correctly identified an intrusion, promote it to a standing detection rule. If A3 evasion was identified, ensure future analysis pipelines treat extracted sample text as evidence only.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.