← All hunts high TLP:CLEAR Part 2 of 3

UAT-10147: Host Elevation and Evasion

An adversary is executing automated staging scripts to deploy privilege escalation tools and blind security software on compromised web servers.

Based on research by Cisco Talos 2026-09-20 12 steps · 5 queries T1021.001 T1053.005 T1059.001 T1068 T1505.003 T1562.001

Brief

Why now

Recent reporting from Cisco Talos in UAT-10147 integrates agentic AI into post-compromise operations (https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/) describes an adversary using automated playbooks to scale their post-exploitation tasks. While much of the initial noise occurs at the network and web shell layer, the adversary quickly moves to secure the host. They use standardized batch scripts to download tools, elevate privileges, and modify the local environment to avoid detection. This hunt focuses on those host-side artifacts that appear once the intruder moves past the initial web exploit.

How the hunt flows

The hunt begins by scoping the environment. The first query identifies hosts running web server software like IIS, Nacos, or Nginx. This limits the search to the surfaces most likely to host the initial exploit. By narrowing the scope to these specific workloads, the hunt reduces noise and focuses on the high-risk perimeter.

Once the scope is set, the hunt runs two searches in parallel. One search looks for specific filenames used by UAT-10147 to stage their tools, such as back.bat and user.bat. The other search monitors for rare process executions involving privilege escalation tools like EfsPotato or exploits for CVE-2022-0995. These tools are often the first things an intruder runs after gaining a low-privilege shell.

The next phase pivots into defense evasion. The adversary modifies the Windows Registry to add specific IIS directories to the Windows Defender exclusion list. This ensures that their malicious modules remain undetected during routine scans. The hunt specifically checks for registry writes targeting these exclusion paths, which are highly unusual in standard server operations.

Finally, the hunt looks for persistence and discovery. It searches for deceptive scheduled tasks, such as 'Google Chrome Start', which the adversary uses to maintain access. It also looks for the use of appcmd to enumerate IIS site configurations. An analyst then correlates these disparate events—the script drop, the elevation attempt, the registry change, and the new task—to confirm a successful compromise.

What the hunt cannot see

This hunt depends on endpoint telemetry. If a web server does not have EDR coverage, the adversary can execute their elevation chain without generating process logs. While registry and file artifacts might remain, the specific execution context is lost. Additionally, if the adversary renames their staging scripts or uses environment variable expansion to obfuscate command strings, simple filename matching will fail. The hunt assumes the adversary follows the observed pattern of using standardized filenames in their automation.

In this series

Steps

  1. Identify web server scope

    Query · scoping

    Focus the hunt on hosts running web server software or frameworks targeted by UAT-10147.

    reads hb_software_inventorysql
    SELECT DISTINCT device_hostname FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%iis%' OR LOWER(package_name) LIKE '%apache%' OR LOWER(package_name) LIKE '%nginx%' OR LOWER(package_name) LIKE '%nacos%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)

    What a hit looks like. A list of hostnames acting as web servers. Silence indicates no managed web servers are visible in inventory.

  2. Staged script drops

    Query · triage

    Detect the creation of the reported staging batch scripts on scoped hosts.

    reads hb_file_activitysql
    SELECT device_hostname, file_name, file_path, time FROM hb_file_activity WHERE instr(',' || '{{staged_scripts}}' || ',', ',' || LOWER(file_name) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)

    What a hit looks like. File creation events for scripts like back.bat or user.bat. Silence for these exact names over 14 days is evidence of absence.

  3. Rare elevation tool execution

    Query · baseline

    Identify rare process execution involving reported privilege escalation tools such as EfsPotato or Linux exploit strings.

    reads hb_process_activitysql
    SELECT LOWER(process_cmd_line) AS cmd, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_process_activity WHERE (LOWER(process_cmd_line) LIKE '%prcc1.rar%' OR LOWER(process_cmd_line) LIKE '%efspotato%' OR LOWER(process_cmd_line) LIKE '%cve-2022-0995%' OR LOWER(process_cmd_line) LIKE '%cve-2021-3156%') AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY cmd HAVING hosts < 3

    What a hit looks like. Execution of known elevation tools seen on fewer than three hosts. A hit confirms an active exploitation attempt.

  4. Evaluate early intrusion signs

    Agent triage

    Assess whether the script drops and elevation commands indicate the start of a UAT-10147 intrusion.

  5. Defender exclusion modifications

    Query · detection candidate

    Identify Registry modifications that add the malicious IIS directories to Windows Defender exclusions.

    reads hb_registry_activitysql
    SELECT device_hostname, reg_target, reg_value_name, time FROM hb_registry_activity WHERE LOWER(reg_target) LIKE '%windows defender\exclusions\paths%' AND instr(',' || '{{exclusion_paths}}' || ',', ',' || LOWER(reg_value_name) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)

    What a hit looks like. Registry writes that blind Defender for the exact paths where BadIIS modules are dropped. Single-host occurrences are critical findings.

  6. Persistence and discovery tasks

    Query · enrichment

    Detect the reported 'Google Chrome Start' scheduled task and use of appcmd for reconnaissance.

    reads hb_scheduled_jobsql
    SELECT device_hostname, job_name, job_cmd_line, time FROM hb_scheduled_job WHERE (LOWER(job_name) = 'google chrome start' OR LOWER(job_cmd_line) LIKE '%appcmd%list%site%') AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)

    What a hit looks like. Deceptive scheduled jobs or IIS configuration enumeration. Hits indicate established persistence.

  7. Full chain intrusion correlation

    Agent triage

    Correlate early staged script execution with follow-on evasion and persistence to confirm a complete UAT-10147 intrusion lifecycle.

  8. Route on verdict

    Decision

    Isolate the host if the agent confirms a high-confidence intrusion chain.

  9. Isolate host

    Response action

    Contain the compromised web server to prevent automated data theft.

  10. Forensic validation

    Analyst task

    Verify the identified artifacts and confirm the presence of rogue IIS modules.

  11. Hunt closeout

    Analyst task

    Document findings and transition the behavioral signatures to standing detections.

Coverage

Scenario coverage

StageCoveredHow, or why not
Automated Foothold Execution
T1059 · T1059.001
Yes staged-script-drops
Privilege Escalation Exploits
T1059
Yes rare-elevation-commands
Antivirus Exclusion Evasion
T1059.001
Yes evasion-registry-activity
IIS Server Discovery
T1059
Yes persistence-scheduled-jobs
Persistence Mechanisms
T1053.005 · T1505.003 · T1021.001
Yes persistence-scheduled-jobs
Web Application Exploitation
T1190
Out of scope Belongs to another part of the 'UAT-10147 integrates agentic AI into post-compromise operations' series.
C2 Implant Communication
T1071 · T1090.003
Out of scope Belongs to another part of the 'UAT-10147 integrates agentic AI into post-compromise operations' series.
System Telemetry Exfiltration
T1041
Out of scope Belongs to another part of the 'UAT-10147 integrates agentic AI into post-compromise operations' series.

Blind spots

  • Needs EDR agent coverage (hb_process_activity) on every web server. A compromised host without EDR coverage can execute the elevation chain without generating process logs, leaving only the registry or file aftermath. It would answer whether elevation tools were executed on unmanaged servers.
  • Needs hb_script_activity content de-obfuscation. If the adversary renames scripts and obfuscates command strings, simple filename matching will fail to identify the foothold. It would answer what instructions were executed if batch scripts use environment variable expansion.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
exclusion_pathslist[path]c:\windows\syswow64\inetsrv, c:\windows\system32\inetsrvDirectories the adversary excludes from Windows Defender.
lookback_daysnumber14Days of history to examine.
scope_hostslist[host]Optional hostnames to narrow the search.
staged_scriptslist[path]back.bat, back.txt, user.bat, bai.batReported filenames of the staging batch scripts.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: A single rule cannot connect the drop of a batch script to a subsequent
  Defender exclusion and a deceptive scheduled task. This hunt uses a phased approach
  to pivot across file, process, registry, and job surfaces to weigh the entire chain.
blind_spots:
- id: no-process-telemetry
  question: whether elevation tools were executed on unmanaged servers
  requires: EDR agent coverage (hb_process_activity) on every web server
  risk: A compromised host without EDR coverage can execute the elevation chain without
    generating process logs, leaving only the registry or file aftermath.
  stage: privilege-escalation-exploits
- id: obfuscated-script-content
  question: what instructions were executed if batch scripts use environment variable
    expansion
  requires: hb_script_activity content de-obfuscation
  risk: If the adversary renames scripts and obfuscates command strings, simple filename
    matching will fail to identify the foothold.
  stage: automated-foothold-execution
coverage:
- stage: automated-foothold-execution
  status: covered
  steps:
  - staged-script-drops
- stage: privilege-escalation-exploits
  status: covered
  steps:
  - rare-elevation-commands
- stage: antivirus-exclusion-evasion
  status: covered
  steps:
  - evasion-registry-activity
- stage: iis-server-discovery
  status: covered
  steps:
  - persistence-scheduled-jobs
- stage: persistence-mechanisms
  status: covered
  steps:
  - persistence-scheduled-jobs
- reason: Belongs to another part of the 'UAT-10147 integrates agentic AI into post-compromise
    operations' series.
  stage: web-application-exploitation
  status: out_of_scope
- reason: Belongs to another part of the 'UAT-10147 integrates agentic AI into post-compromise
    operations' series.
  stage: c2-implant-communication
  status: out_of_scope
- reason: Belongs to another part of the 'UAT-10147 integrates agentic AI into post-compromise
    operations' series.
  stage: system-telemetry-exfiltration
  status: out_of_scope
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: promote-to-detection
  justification: UAT-10147 is a financially motivated actor using AI to automate complex
    post-compromise tasks. Detecting the elevation and evasion chain stops the actor
    before they deploy persistent web shells or exfiltrate data.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An adversary is executing automated staging scripts to deploy privilege
  escalation tools and blind security software on compromised web servers.
labels:
- hunt
- attack.t1059.001
- attack.t1068
- attack.t1562.001
- attack.t1053.005
- attack.t1505.003
- attack.t1021.001
name: 'UAT-10147: Host Elevation and Evasion'
parameters:
  exclusion_paths:
    default:
    - c:\windows\syswow64\inetsrv
    - c:\windows\system32\inetsrv
    description: Directories the adversary excludes from Windows Defender.
    from:
      kind: article
      observed: '2026-01-20'
      ref: UAT-10147 blog
    type: list[path]
  lookback_days:
    default: '14'
    description: Days of history to examine.
    type: number
  scope_hosts:
    default: []
    description: Optional hostnames to narrow the search.
    type: list[host]
  staged_scripts:
    default:
    - back.bat
    - back.txt
    - user.bat
    - bai.bat
    description: Reported filenames of the staging batch scripts.
    from:
      kind: article
      observed: '2026-01-20'
      ref: UAT-10147 blog
    type: list[path]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Focus on internet-exposed web servers. Narrow the hunt by prioritizing
  servers where hb_software_inventory shows IIS, Nacos, or ASP.NET components.
references:
- name: "Cisco Talos \u2014 UAT-10147 integrates agentic AI into post-compromise operations"
  url: https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/
related:
- hunt: uat-10147-initial-access
  reason: Initial web-level exploitation occurs before these host-centric scripts
    run.
  relation: precedes
- hunt: uat-10147-c2-and-exfiltration
  reason: Exfiltration over the Nacos C2 channel happens after the host foothold is
    secured.
  relation: follows
- hunt: web-exploit-telemetry-theft-uat-10147
  relation: follows
scenario:
  stages:
  - name: Web Application Exploitation
    observables:
    - CVE-2022-27925
    - CVE-2021-23758
    - CVE-2019-18935
    - adminapi.tippusoni.in
    - exploitation of Zimbra Collaboration Suite
    - exploitation of AjaxPro
    - exploitation of Telerik UI for ASP.NET AJAX
    slug: web-application-exploitation
    tactic: initial-access
    techniques:
    - T1190
  - name: Automated Foothold Execution
    observables:
    - back.bat
    - back.txt
    - user.bat
    - bai.bat
    - certutil -urlcache -split -f
    - Runtime.exec()
    - dll.zip
    - prcc1.rar
    slug: automated-foothold-execution
    tactic: execution
    techniques:
    - T1059
    - T1059.001
  - name: Privilege Escalation Exploits
    observables:
    - EfsPotato
    - CVE-2022-0995
    - CVE-2021-3156
    - CVE-2015-5287
    - CVE-2015-3246
    - CVE-2010-3904
    - CVE-2022-0847
    - Dirty Pipe exploitation
    slug: privilege-escalation-exploits
    tactic: privilege-escalation
    techniques:
    - T1059
  - name: Antivirus Exclusion Evasion
    observables:
    - Add-MpPreference -ExclusionPath C:\Windows\SysWOW64\inetsrv
    - Add-MpPreference -ExclusionPath C:\Windows\System32\inetsrv
    - reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths"
    - powershell.exe Add-MpPreference
    slug: antivirus-exclusion-evasion
    tactic: defense-evasion
    techniques:
    - T1059.001
  - name: IIS Server Discovery
    observables:
    - appcmd list site /config /xml
    - C:\Windows\system32\inetsrv\appcmd
    slug: iis-server-discovery
    tactic: discovery
    techniques:
    - T1059
  - name: Persistence Mechanisms
    observables:
    - Google Chrome Start
    - BadIIS
    - addition of user to Remote Desktop Users group
    - rogue local user account creation
    - System32\inetsrv\BadIIS.dll
    slug: persistence-mechanisms
    tactic: persistence
    techniques:
    - T1053.005
    - T1505.003
    - T1021.001
  - name: C2 Implant Communication
    observables:
    - 139.180.197.150
    - svchosts.exe
    - QuasarRAT
    - NoodleRAT
    - SPECTRE
    - Gh0stCringe
    - Meterpreter
    slug: c2-implant-communication
    tactic: command-and-control
    techniques:
    - T1071
    - T1090.003
  - name: System Telemetry Exfiltration
    observables:
    - HTTP POST to Nacos configuration server
    - exfiltration of id and hostname
    - exfiltration of %USERNAME% and %COMPUTERNAME%
    slug: system-telemetry-exfiltration
    tactic: exfiltration
    techniques:
    - T1041
  summary: UAT-10147 targets Windows and Linux web servers globally, integrating agentic
    AI to optimize exploit development and post-compromise orchestration. The campaign
    leverages high-volume vulnerability exploitation followed by automated privilege
    escalation, defense evasion through antivirus exclusions, and persistence via
    rogue IIS modules and scheduled tasks.
series:
  index: 2
  slug: uat-10147-integrates-agentic-ai-into-post-compromise-operations
  title: UAT-10147 integrates agentic AI into post-compromise operations
  total: 3
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
tlp: clear
type: investigation
---


# UAT-10147: Host Elevation and Evasion

This hunt targets the endpoint-centric phase of UAT-10147 operations, where an adversary uses semi-autonomous playbooks to operationalize offensive tradecraft. The actor deploys multi-stage batch scripts to download privilege escalation tools like EfsPotato, modifies the Windows Registry to exclude malicious IIS directories from Defender scans, and establishes persistence through deceptive scheduled tasks. The hunt follows a phased flow: it first identifies initial foothold scripts and rare elevation commands, then pivots to look for the subsequent defense evasion and persistence mechanisms that secure the intruder's presence.

## scope-web-servers
<!-- Identify web server scope -->
Focus the hunt on hosts running web server software or frameworks targeted by UAT-10147.

```sqlite target=endpoint role=scoping params=(scope_hosts=scope_hosts)
~~~yaml
expected: A list of hostnames acting as web servers. Silence indicates no managed
  web servers are visible in inventory.
reads:
- device_hostname
- package_name
silence: not_evidence_of_absence
source: hb_software_inventory
verified: dry-run
verified_at: '2026-09-20'
~~~
SELECT DISTINCT device_hostname FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%iis%' OR LOWER(package_name) LIKE '%apache%' OR LOWER(package_name) LIKE '%nginx%' OR LOWER(package_name) LIKE '%nacos%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)
```

## early-stage-parallel
<!-- Search for foothold and elevation -->
parallel:
- → staged-script-drops
- → rare-elevation-commands
join: → early-stage-agent

## staged-script-drops
<!-- Staged script drops -->
Detect the creation of the reported staging batch scripts on scoped hosts.

```sqlite target=endpoint role=triage params=(staged_scripts=staged_scripts, lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: File creation events for scripts like back.bat or user.bat. Silence for
  these exact names over 14 days is evidence of absence.
reads:
- device_hostname
- file_name
- file_path
- time
silence: evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-09-20'
~~~
SELECT device_hostname, file_name, file_path, time FROM hb_file_activity WHERE instr(',' || '{{staged_scripts}}' || ',', ',' || LOWER(file_name) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)
```

## rare-elevation-commands
<!-- Rare elevation tool execution -->
Identify rare process execution involving reported privilege escalation tools such as EfsPotato or Linux exploit strings.

```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: Execution of known elevation tools seen on fewer than three hosts. A hit
  confirms an active exploitation attempt.
prevalence:
  by: device_hostname
  key:
  - cmd
  rare_below: 3
reads:
- device_hostname
- process_cmd_line
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-20'
~~~
SELECT LOWER(process_cmd_line) AS cmd, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_process_activity WHERE (LOWER(process_cmd_line) LIKE '%prcc1.rar%' OR LOWER(process_cmd_line) LIKE '%efspotato%' OR LOWER(process_cmd_line) LIKE '%cve-2022-0995%' OR LOWER(process_cmd_line) LIKE '%cve-2021-3156%') AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY cmd HAVING hosts < 3
```

## early-stage-agent
<!-- Evaluate early intrusion signs -->
```agent target=hunter
cite: required
context:
- staged-script-drops
- rare-elevation-commands
max_iterations: 4
objective: Determine if any host shows evidence of staging script drops or privilege
  escalation execution consistent with UAT-10147 tradecraft.
success_criteria: A per-host verdict citing specific script names or elevation commands.
tools:
- endpoint
```

## follow-on-parallel
<!-- Search for evasion and persistence -->
parallel:
- → evasion-registry-activity
- → persistence-scheduled-jobs
join: → full-chain-agent

## evasion-registry-activity
<!-- Defender exclusion modifications -->
Identify Registry modifications that add the malicious IIS directories to Windows Defender exclusions.

```sqlite target=endpoint role=detection-candidate params=(exclusion_paths=exclusion_paths, lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: Registry writes that blind Defender for the exact paths where BadIIS modules
  are dropped. Single-host occurrences are critical findings.
reads:
- device_hostname
- reg_target
- reg_value_name
- time
silence: not_evidence_of_absence
source: hb_registry_activity
verified: dry-run
verified_at: '2026-09-20'
~~~
SELECT device_hostname, reg_target, reg_value_name, time FROM hb_registry_activity WHERE LOWER(reg_target) LIKE '%windows defender\exclusions\paths%' AND instr(',' || '{{exclusion_paths}}' || ',', ',' || LOWER(reg_value_name) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)
```

## persistence-scheduled-jobs
<!-- Persistence and discovery tasks -->
Detect the reported 'Google Chrome Start' scheduled task and use of appcmd for reconnaissance.

```sqlite target=endpoint role=enrichment params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: Deceptive scheduled jobs or IIS configuration enumeration. Hits indicate
  established persistence.
reads:
- device_hostname
- job_cmd_line
- job_name
- time
silence: not_evidence_of_absence
source: hb_scheduled_job
verified: dry-run
verified_at: '2026-09-20'
~~~
SELECT device_hostname, job_name, job_cmd_line, time FROM hb_scheduled_job WHERE (LOWER(job_name) = 'google chrome start' OR LOWER(job_cmd_line) LIKE '%appcmd%list%site%') AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)
```

## full-chain-agent
<!-- Full chain intrusion correlation -->
```agent target=hunter
cite: required
context:
- early-stage-agent
- evasion-registry-activity
- persistence-scheduled-jobs
max_iterations: 6
objective: 'Identify hosts where the UAT-10147 chain is complete: early elevation
  combined with subsequent Defender blinding and deceptive scheduled jobs.'
success_criteria: A malicious verdict citing the linkage between early stage tools
  and follow-on persistence.
tools:
- endpoint
```

## route-on-verdict
<!-- Route on verdict -->
if~: "the full-chain-agent verdict is malicious and identifies a link between privilege escalation and follow-on evasion" (confidence: high, judge=hunter)
then: → isolate-host
indeterminate: → forensic-validation
unavailable: → forensic-validation (blind_spot: no-process-telemetry)
else: → forensic-validation

## isolate-host
<!-- Isolate host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host immediately. Terminate active cmd.exe or powershell.exe shells and prepare for forensic evidence collection.
```
→ forensic-validation

## forensic-validation
<!-- Forensic validation -->
```manual target=analyst
1. Inspect C:\Windows\System32\inetsrv and SysWOW64\inetsrv for unexpected DLLs. 2. Verify the 'Google Chrome Start' scheduled task. 3. Check for new local users in the Administrators and Remote Desktop Users groups.
```
→ hunt-closeout

## hunt-closeout
<!-- Hunt closeout -->
```manual target=analyst
Document the identified compromised hosts and promote the Defender exclusion registry query to a permanent detection rule for unauthorized exclusion paths.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.