{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "The MANTLEMAZE and Warlock ransomware chain uses sophisticated AI-evasion and kernel-impairment techniques that bypass traditional single-point detections. This phased hunt ensures that even if one stage is evasive, the correlation of the full attack lifecycle provides a definitive result."
      },
      "name": "Trojanized Utilities and Kernel EDR Impairment",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1195.002",
        "attack.t1027",
        "attack.t1562.001",
        "attack.t1068",
        "attack.t1486",
        "defense evasion",
        "execution",
        "impact",
        "initial access"
      ],
      "series": {
        "slug": "making-sure-the-checks-get-printed",
        "index": 2,
        "title": "Making sure the checks get printed",
        "total": 2
      },
      "related": [
        {
          "hunt": "citrix-netscaler-zero-day-exploitation",
          "reason": "Initial access via Citrix CVE-2026-88779 is a network appliance intrusion and is handled in a separate hunt.",
          "relation": "out-of-scope-alternative"
        },
        {
          "hunt": "perimeter-identity-abuse-hunt",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A single rule on a trojan hash might be dismissed as a False Positive or PUAs. This hunt correlates the initial access with two critical follow-on behaviors: kernel driver tampering (BYOVD) and mass file encryption. The analyst weighs these across three different telemetry surfaces to confirm a high-confidence intrusion.",
      "coverage": [
        {
          "stage": "trojanized-utility-execution",
          "steps": [
            "scoping-by-process",
            "file-drops-persistence"
          ],
          "status": "covered"
        },
        {
          "stage": "ai-analysis-evasion-obfuscation",
          "steps": [
            "early-triage-agent"
          ],
          "status": "covered"
        },
        {
          "stage": "kernel-driver-edr-impairment",
          "steps": [
            "byovd-driver-load"
          ],
          "status": "covered"
        },
        {
          "stage": "ransomware-data-encryption",
          "steps": [
            "ransomware-impact"
          ],
          "status": "covered"
        },
        {
          "stage": "citrix-netscaler-exploitation",
          "reason": "Belongs to another part of the 'Making sure the checks get printed' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "lawful-access-identity-abuse",
          "reason": "Belongs to another part of the 'Making sure the checks get printed' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Citrix NetScaler Vulnerability Exploitation",
            "slug": "citrix-netscaler-exploitation",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "CVE-2026-88779",
              "Memory overflow in Citrix NetScaler"
            ]
          },
          {
            "name": "Abuse of Lawful Identity Access",
            "slug": "lawful-access-identity-abuse",
            "tactic": "initial-access",
            "techniques": [
              "T1078"
            ],
            "observables": [
              "Abuse of Danish company lawful access to CPR system"
            ]
          },
          {
            "name": "Trojanised Software Execution",
            "slug": "trojanized-utility-execution",
            "tactic": "execution",
            "techniques": [
              "T1195"
            ],
            "observables": [
              "KMSAuto Net.exe",
              "SECOH-QAD.exe",
              "PulseBrowser.29kh.in12.Talos",
              "9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507",
              "fed979f93bcaf4e73ebd25748093a92095d5109cbd01d55f97bdc50ce509ad2f",
              "9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f",
              "58d6fec4ba24c32d38c9a0c7c39df3cb0e91f500b323e841121d703c7b718681"
            ]
          },
          {
            "name": "AI-Analysis Evasion (A3)",
            "slug": "ai-analysis-evasion-obfuscation",
            "tactic": "defense-evasion",
            "techniques": [
              "T1027"
            ],
            "observables": [
              "Plaintext imperative language instructions in binaries",
              "Template spraying designed to trick LLMs",
              "Instructions telling AI to ignore files"
            ]
          },
          {
            "name": "Kernel driver EDR Impairment",
            "slug": "kernel-driver-edr-impairment",
            "tactic": "defense-evasion",
            "techniques": [
              "T1562.001",
              "T1068"
            ],
            "observables": [
              "Abusing vulnerable drivers to disable EDR from kernel space",
              "MANTLEMAZE driver abuse"
            ]
          },
          {
            "name": "Ransomware Encryption",
            "slug": "ransomware-data-encryption",
            "tactic": "impact",
            "techniques": [
              "T1486"
            ],
            "observables": [
              "Warlock ransomware activity",
              "Encryption of water utility and telecom systems"
            ]
          }
        ],
        "summary": "Mantlemaze and other threat actors are employing 'AI-Analysis Evasion' (A3) by embedding natural-language instructions in malware to trick automated scrutiny, often pairing it with kernel-level driver abuse to disable EDR. These techniques are observed alongside high-impact threats including vulnerabilities in Citrix NetScaler and ransomware attacks by groups like Warlock."
      },
      "severity": "high",
      "rationale": "Start by identifying any host running the reported hashes or processes matching the trojan names. Also include a wide behavioral scoop for processes running from user folders with non-system integrity, as these are common staging areas for trojanized utilities.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An intruder has gained access via trojanized software containing AI-analysis evasion code, then loaded vulnerable drivers to disable security tools before executing ransomware.",
      "parameters": {
        "c2_domains": {
          "from": {
            "ref": "talos-making-sure-checks-printed",
            "kind": "article",
            "observed": "2026-10-08"
          },
          "type": "list[domain]",
          "default": [
            "w32.9f1f11a708-100.sbx.tg",
            "w32.fed979f93b-95.sbx.tg",
            "w32.9896a6fcb9-95.sbx.tg",
            "pulsebrowser.29kh.in12.talos",
            "w32.58d6fec4ba-95.sbx.tg"
          ],
          "description": "Malicious domains used for C2 or infrastructure associated with the campaign."
        },
        "scope_hosts": {
          "from": {
            "ref": "analyst-defined",
            "kind": "manual",
            "observed": "2024-10-25"
          },
          "type": "list[host]",
          "default": [],
          "description": "Restrict the hunt to these hostnames; leave empty to hunt across the entire estate."
        },
        "lookback_days": {
          "from": {
            "ref": "standard-retention",
            "kind": "manual",
            "observed": "2024-10-25"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "trojan_hashes": {
          "from": {
            "ref": "talos-making-sure-checks-printed",
            "kind": "article",
            "observed": "2026-10-08"
          },
          "type": "list[hash]",
          "default": [
            "9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507",
            "fed979f93bcaf4e73ebd25748093a92095d5109cbd01d55f97bdc50ce509ad2f",
            "9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f",
            "73ac1bbfaee6c76c34f655ac0477a4cd930f2aa55e658c8e312ff81aac9a741f",
            "58d6fec4ba24c32d38c9a0c7c39df3cb0e91f500b323e841121d703c7b718681"
          ],
          "description": "SHA256 hashes of trojanized utilities and MANTLEMAZE samples."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://blog.talosintelligence.com/making-sure-the-checks-get-printed/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://blog.talosintelligence.com/making-sure-the-checks-get-printed/",
          "name": "Cisco Talos \u2014 Making sure the checks get printed"
        }
      ],
      "blind_spots": [
        {
          "id": "telemetry-gap-impairment",
          "risk": "A successful BYOVD attack may blind the EDR agent, meaning the ransomware impact results would be empty even if encryption occurred.",
          "stage": "kernel-driver-edr-impairment",
          "question": "whether the adversary successfully disabled logging before the encryption phase began",
          "requires": "EDR driver-load telemetry and kernel activity logs"
        },
        {
          "id": "entropy-analysis-limitation",
          "risk": "DNS detection relies on length and known patterns; true DGA or high-entropy domains might be missed without a specialized analysis surface.",
          "stage": "trojanized-utility-execution",
          "question": "whether a domain is algorithmically generated (DGA) or highly entropic",
          "requires": "native entropy-calculating query functions"
        }
      ]
    },
    "name": "Trojanized Utilities and Kernel EDR Impairment",
    "description": "This hunt identifies the full lifecycle of an endpoint intrusion starting with trojanized utility execution, such as KMSAuto or PulseBrowser, which incorporates A3 (AI-Analysis Evasion) techniques. It follows the chain from initial access to kernel-level defense evasion using BYOVD (Bring Your Own Vulnerable Driver) and concludes with mass file encryption indicative of Warlock ransomware. The phased approach ensures that later impact signals are analyzed in the context of the initial beachhead."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "making-sure-the-checks-get-printed",
          "index": 2,
          "title": "Making sure the checks get printed",
          "total": 2
        },
        "coverage": [
          {
            "stage": "trojanized-utility-execution",
            "steps": [
              "scoping-by-process",
              "file-drops-persistence"
            ],
            "status": "covered"
          },
          {
            "stage": "ai-analysis-evasion-obfuscation",
            "steps": [
              "early-triage-agent"
            ],
            "status": "covered"
          },
          {
            "stage": "kernel-driver-edr-impairment",
            "steps": [
              "byovd-driver-load"
            ],
            "status": "covered"
          },
          {
            "stage": "ransomware-data-encryption",
            "steps": [
              "ransomware-impact"
            ],
            "status": "covered"
          },
          {
            "stage": "citrix-netscaler-exploitation",
            "reason": "Belongs to another part of the 'Making sure the checks get printed' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "lawful-access-identity-abuse",
            "reason": "Belongs to another part of the 'Making sure the checks get printed' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An intruder has gained access via trojanized software containing AI-analysis evasion code, then loaded vulnerable drivers to disable security tools before executing ransomware.",
        "blind_spots": [
          {
            "id": "telemetry-gap-impairment",
            "risk": "A successful BYOVD attack may blind the EDR agent, meaning the ransomware impact results would be empty even if encryption occurred.",
            "stage": "kernel-driver-edr-impairment",
            "question": "whether the adversary successfully disabled logging before the encryption phase began",
            "requires": "EDR driver-load telemetry and kernel activity logs"
          },
          {
            "id": "entropy-analysis-limitation",
            "risk": "DNS detection relies on length and known patterns; true DGA or high-entropy domains might be missed without a specialized analysis surface.",
            "stage": "trojanized-utility-execution",
            "question": "whether a domain is algorithmically generated (DGA) or highly entropic",
            "requires": "native entropy-calculating query functions"
          }
        ],
        "scoping_notes": "Start by identifying any host running the reported hashes or processes matching the trojan names. Also include a wide behavioral scoop for processes running from user folders with non-system integrity, as these are common staging areas for trojanized utilities.",
        "beyond_detection": "A single rule on a trojan hash might be dismissed as a False Positive or PUAs. This hunt correlates the initial access with two critical follow-on behaviors: kernel driver tampering (BYOVD) and mass file encryption. The analyst weighs these across three different telemetry surfaces to confirm a high-confidence intrusion."
      }
    },
    {
      "id": "scoping-by-process",
      "type": "query",
      "label": "Scope by trojanized utility execution",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_original_file_name, process_hash_sha256, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{trojan_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 OR LOWER(process_original_file_name) IN ('kmsauto net.exe', 'secoh-qad.exe', 'sample.exe', 'f_003914.exe') OR (LOWER(process_name) LIKE '%\\kmsauto net.exe' OR LOWER(process_name) LIKE '%\\secoh-qad.exe' OR LOWER(process_name) LIKE '%\\sample.exe') OR ( (LOWER(process_path) LIKE '%\\users\\%' OR LOWER(process_path) LIKE '%\\temp\\%' OR LOWER(process_path) LIKE '%\\downloads\\%') AND integrity_level != 'System' AND (process_original_file_name IS NULL OR process_original_file_name = '') ) ) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Identify initial beachheads by matching malicious processes by hash, original filename, or behavioral traits in user-writable paths.",
        "expected_signal": "A list of hosts running reported malware or suspicious, unnamed binaries from user folders. Results define the scope for the rest of the hunt."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Scope by trojanized utility execution",
        "reads": [
          "device_hostname",
          "integrity_level",
          "process_hash_sha256",
          "process_name",
          "process_original_file_name",
          "process_path",
          "time",
          "user_name"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_original_file_name, process_hash_sha256, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{trojan_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 OR LOWER(process_original_file_name) IN ('kmsauto net.exe', 'secoh-qad.exe', 'sample.exe', 'f_003914.exe') OR (LOWER(process_name) LIKE '%\\kmsauto net.exe' OR LOWER(process_name) LIKE '%\\secoh-qad.exe' OR LOWER(process_name) LIKE '%\\sample.exe') OR ( (LOWER(process_path) LIKE '%\\users\\%' OR LOWER(process_path) LIKE '%\\temp\\%' OR LOWER(process_path) LIKE '%\\downloads\\%') AND integrity_level != 'System' AND (process_original_file_name IS NULL OR process_original_file_name = '') ) ) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hosts running reported malware or suspicious, unnamed binaries from user folders. Results define the scope for the rest of the hunt.",
        "verified": "dry-run",
        "verified_at": "2026-10-09"
      }
    },
    {
      "id": "dns-to-c2",
      "type": "query",
      "label": "DNS queries to C2 or high-entropy domains",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, query_hostname, process_name, COUNT(*) as lookups, MIN(time) as first_seen FROM hb_dns_activity WHERE (instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 OR (LENGTH(query_hostname) > 24 AND LOWER(query_hostname) NOT LIKE '%.local%' AND LOWER(query_hostname) NOT LIKE '%.internal%')) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1, 2, 3",
        "surface": "hb_dns_activity",
        "description": "Detect network beacons to known malicious domains or anomalous high-entropy domains on scoped hosts.",
        "expected_signal": "DNS resolutions for reported C2 domains or long, complex hostnames which may represent DGA or C2 rotation. Silence suggests the beaconing infrastructure has rotated."
      },
      "parents": [
        {
          "id": "scoping-by-process"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "DNS queries to C2 or high-entropy domains",
        "reads": [
          "device_hostname",
          "process_name",
          "query_hostname",
          "time"
        ],
        "source": "hb_dns_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, query_hostname, process_name, COUNT(*) as lookups, MIN(time) as first_seen FROM hb_dns_activity WHERE (instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 OR (LENGTH(query_hostname) > 24 AND LOWER(query_hostname) NOT LIKE '%.local%' AND LOWER(query_hostname) NOT LIKE '%.internal%')) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1, 2, 3",
        "silence": "not_evidence_of_absence",
        "expected": "DNS resolutions for reported C2 domains or long, complex hostnames which may represent DGA or C2 rotation. Silence suggests the beaconing infrastructure has rotated.",
        "verified": "dry-run",
        "verified_at": "2026-10-09"
      }
    },
    {
      "id": "file-drops-persistence",
      "type": "query",
      "label": "Persistent file drops on scoped hosts",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, file_path, file_hash_sha256, process_name, time FROM hb_file_activity WHERE instr(',' || '{{trojan_hashes}}' || ',', ',' || LOWER(file_hash_sha256) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_file_activity",
        "description": "Identify filesystem artifacts matching the reported malware hashes on the scoped hosts.",
        "expected_signal": "Confirmed presence of reported trojanized files on disk. Silence means the samples were run in-memory or using different hashes."
      },
      "parents": [
        {
          "id": "scoping-by-process"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Persistent file drops on scoped hosts",
        "reads": [
          "device_hostname",
          "file_hash_sha256",
          "file_path",
          "process_name",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, file_path, file_hash_sha256, process_name, time FROM hb_file_activity WHERE instr(',' || '{{trojan_hashes}}' || ',', ',' || LOWER(file_hash_sha256) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Confirmed presence of reported trojanized files on disk. Silence means the samples were run in-memory or using different hashes.",
        "verified": "dry-run",
        "verified_at": "2026-10-09"
      }
    },
    {
      "id": "early-triage-agent",
      "type": "analytic",
      "label": "Early-stage beachhead triage",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "scoping-by-process",
          "dns-to-c2",
          "file-drops-persistence"
        ],
        "objective": "Determine if the scoped hosts are confirmed beachheads. Specifically look for evidence of A3 evasion, such as binaries that have been flagged by AV but show execution, or unusual process trees originating from the trojanized utilities.",
        "description": "Evaluate whether the initial process, network, and file signals indicate a confirmed infection and look for A3 evasion indicators.",
        "max_iterations": 3,
        "expected_signal": "A per-host verdict of suspicious or malicious based on early intrusion evidence.",
        "success_criteria": "A per-host verdict citing specific rows from the process and DNS results."
      },
      "parents": [
        {
          "id": "dns-to-c2",
          "kind": "merge"
        },
        {
          "id": "file-drops-persistence",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "byovd-driver-load",
      "type": "query",
      "label": "Kernel EDR impairment via BYOVD",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT device_hostname, driver_path, driver_signature_subject, COUNT(*) as loads, MIN(time) as first_seen FROM hb_kernel_extension_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1, 2, 3 HAVING COUNT(DISTINCT device_hostname) <= 3",
        "surface": "hb_kernel_extension_activity",
        "description": "Identify rare driver loads across the fleet that may represent the use of vulnerable drivers to disable security agents.",
        "expected_signal": "A list of hosts loading rare drivers. Fleet-wide rarity is a strong indicator of manual BYOVD tampering to impair security tools."
      },
      "parents": [
        {
          "id": "early-triage-agent"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Kernel EDR impairment via BYOVD",
        "reads": [
          "device_hostname",
          "driver_path",
          "driver_signature_subject",
          "time"
        ],
        "source": "hb_kernel_extension_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, driver_path, driver_signature_subject, COUNT(*) as loads, MIN(time) as first_seen FROM hb_kernel_extension_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1, 2, 3 HAVING COUNT(DISTINCT device_hostname) <= 3",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A list of hosts loading rare drivers. Fleet-wide rarity is a strong indicator of manual BYOVD tampering to impair security tools.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "driver_path"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-10-09"
      }
    },
    {
      "id": "ransomware-impact",
      "type": "query",
      "label": "High-volume file encryption (Impact)",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, SUBSTR(file_name, INSTR(file_name, '.') + 1) as extension, COUNT(*) as file_count, MIN(time) as first_op FROM hb_file_activity WHERE activity_id IN (4, 5) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1, 2, 3 HAVING file_count > 1000",
        "surface": "hb_file_activity",
        "description": "Identify mass file modification activity indicative of ransomware encryption, grouping by file extension.",
        "expected_signal": "A process modifying over 1000 files, likely with a consistent extension. This distinguishes ransomware from typical application updates or temporary file cleanup."
      },
      "parents": [
        {
          "id": "early-triage-agent"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "High-volume file encryption (Impact)",
        "reads": [
          "activity_id",
          "device_hostname",
          "file_name",
          "process_name",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, SUBSTR(file_name, INSTR(file_name, '.') + 1) as extension, COUNT(*) as file_count, MIN(time) as first_op FROM hb_file_activity WHERE activity_id IN (4, 5) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1, 2, 3 HAVING file_count > 1000",
        "silence": "not_evidence_of_absence",
        "expected": "A process modifying over 1000 files, likely with a consistent extension. This distinguishes ransomware from typical application updates or temporary file cleanup.",
        "verified": "dry-run",
        "verified_at": "2026-10-09"
      }
    },
    {
      "id": "follow-on-triage-agent",
      "type": "analytic",
      "label": "Complete attack chain assessment",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "early-triage-agent",
          "byovd-driver-load",
          "ransomware-impact"
        ],
        "objective": "Evaluate the full attack chain. Confirm whether hosts with a confirmed beachhead (from Agent 1) have subsequently loaded rare drivers and performed mass file encryption.",
        "description": "Synthesize early beachhead evidence with follow-on EDR impairment and encryption signals to confirm a full ransomware intrusion.",
        "max_iterations": 6,
        "expected_signal": "A definitive malicious verdict for any host that shows the full progression from trojan to impact.",
        "success_criteria": "A per-host verdict of malicious | suspicious, citing drivers and file counts."
      },
      "parents": [
        {
          "id": "byovd-driver-load",
          "kind": "merge"
        },
        {
          "id": "ransomware-impact",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-decision",
      "type": "checkpoint",
      "label": "Route on verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the follow-on-triage-agent verdict is malicious for at least one host",
        "condition": "the follow-on-triage-agent verdict is malicious for at least one host",
        "blind_spot": "telemetry-gap-impairment",
        "confidence": "high",
        "description": "Direct immediate containment for malicious hosts and forensic review for suspicious activity.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "follow-on-triage-agent"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate infected host",
      "config": {
        "target": "endpoint",
        "description": "Immediately contain the host to stop the encryption process and prevent lateral movement.",
        "instructions": "Isolate the host from the network and revoke any active credentials or administrative sessions that were active on the host at the time of the trojan execution.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-decision",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Forensic analyst review",
      "config": {
        "assignee": "analyst",
        "description": "Perform a deep dive into the A3 evasion techniques and the extent of driver tampering.",
        "instructions": "Review the binaries found on the scoped hosts for imperative language instructions meant to deceive AI analysts. Identify the vulnerable driver and verify whether its use corresponds to a known MANTLEMAZE variant."
      },
      "parents": [
        {
          "id": "route-decision",
          "branch": "default"
        },
        {
          "id": "route-decision",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "closure",
      "type": "task",
      "label": "Hunt closure and detection tuning",
      "config": {
        "assignee": "analyst",
        "description": "Document the hunt outcome and convert effective behavioral signals into standing detections.",
        "instructions": "Record the hunt findings. If the ransomware-impact query correctly identified an intrusion, promote it to a standing detection rule. If A3 evasion was identified, ensure future analysis pipelines treat extracted sample text as evidence only."
      },
      "parents": [
        {
          "id": "route-decision",
          "branch": "on_refutes"
        },
        {
          "id": "analyst-review"
        }
      ]
    }
  ]
}