{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "UAT-10820 uses sophisticated evasion like rundll32 ordinals and BYOVD to bypass standard detection. A phased hunt is required to correlate early access leads with persistent behavioral indicators."
      },
      "name": "UAT-10820 Multi-Stage Stealer Infection Chain",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1566.002",
        "attack.t1218.011",
        "attack.t1219",
        "attack.t1068",
        "attack.t1562.001",
        "attack.t1555"
      ],
      "series": {
        "slug": "we-ve-got-one-word-for-it-and-it-s-usually-the-wrong-one",
        "index": 1,
        "title": "We've got one word for it, and it's usually the wrong one",
        "total": 2
      },
      "related": [
        {
          "hunt": "uat-10820-c2-blockchain-infrastructure",
          "reason": "This hunt focuses on host-based infection markers; C2 activity via BNB Smart Chain and Google Visualization requires network-level analysis.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A single rule might alert on a rundll32 ordinal, but this hunt connects that lead to earlier social engineering scripts and follow-on persistence from RMM tools, providing the context an analyst needs for a confirmed intrusion verdict.",
      "coverage": [
        {
          "stage": "initial-access-social-engineering-webdav",
          "steps": [
            "webdav-script-leads"
          ],
          "status": "covered"
        },
        {
          "stage": "execution-rundll32-ordinals",
          "steps": [
            "rundll32-ordinal-prevalence"
          ],
          "status": "covered"
        },
        {
          "stage": "defense-evasion-edr-termination",
          "steps": [
            "vulnerable-driver-hunt"
          ],
          "status": "covered"
        },
        {
          "stage": "persistence-netsupport-rmm",
          "steps": [
            "rmm-persistence-hunt"
          ],
          "status": "covered"
        },
        {
          "stage": "credential-access-memory-stealers",
          "reason": "Memory-resident stealers require memory forensics or specialized memory scanning not provided by standard process snapshots.",
          "status": "not_visible",
          "blind_spot": "memory-only-stealers"
        },
        {
          "stage": "c2-blockchain-infrastructure",
          "reason": "Belongs to another part of the \"We've got one word for it, and it's usually the wrong one\" series.",
          "status": "out_of_scope"
        },
        {
          "stage": "initial-access-cisco-fmc-exploitation",
          "reason": "Belongs to another part of the \"We've got one word for it, and it's usually the wrong one\" series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Social engineering via WebDAV and fake CAPTCHA",
            "slug": "initial-access-social-engineering-webdav",
            "tactic": "initial-access",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "fake CAPTCHA prompts",
              "WebDAV infection chain",
              "copying and pasting commands from fake verification prompts"
            ]
          },
          {
            "name": "Rundll32 ordinal execution",
            "slug": "execution-rundll32-ordinals",
            "tactic": "defense-evasion",
            "techniques": [
              "T1218.011"
            ],
            "observables": [
              "rundll32.exe",
              "disguised DLLs",
              "suspicious ordinal calls",
              "tmp00055df5.dll"
            ]
          },
          {
            "name": "EDR termination via BYOVD",
            "slug": "defense-evasion-edr-termination",
            "tactic": "defense-evasion",
            "techniques": [
              "T1068",
              "T1562.001"
            ],
            "observables": [
              "vulnerable driver",
              "terminate EDR software"
            ]
          },
          {
            "name": "Unauthorized RMM installation",
            "slug": "persistence-netsupport-rmm",
            "tactic": "persistence",
            "techniques": [
              "T1219"
            ],
            "observables": [
              "NetSupport Manager",
              "SECOH-QAD.exe"
            ]
          },
          {
            "name": "In-memory credential theft",
            "slug": "credential-access-memory-stealers",
            "tactic": "credential-access",
            "techniques": [
              "T1555"
            ],
            "observables": [
              "Amatera stealer",
              "ZigCryptoStealer"
            ]
          },
          {
            "name": "C2 via BNB Smart Chain",
            "slug": "c2-blockchain-infrastructure",
            "tactic": "command-and-control",
            "techniques": [
              "T1071"
            ],
            "observables": [
              "BNB Smart Chain",
              "bulletproof hosting"
            ]
          },
          {
            "name": "Cisco FMC vulnerability exploitation",
            "slug": "initial-access-cisco-fmc-exploitation",
            "tactic": "initial-access",
            "techniques": [
              "T1190",
              "T1133"
            ],
            "observables": [
              "CVE-2026-20079",
              "CVE-2026-20316",
              "Cisco Secure Firewall Management Center (FMC) Software",
              "crafted HTTP requests",
              "static user credentials"
            ]
          }
        ],
        "summary": "Russian threat actor UAT-10820 targets organizations with a WebDAV-based infection chain that tricks users into executing malicious commands via fake CAPTCHA prompts. The campaign deploys the Amatera and ZigCrypto stealers, utilizing vulnerable drivers to terminate security software and NetSupport Manager for persistent remote access."
      },
      "severity": "high",
      "rationale": "Focus on Windows workstations and servers. The hunt assumes EDR telemetry for script execution and process activity is enabled.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An intruder has infected an endpoint using a WebDAV social engineering chain, followed by the execution of disguised DLLs via rundll32 ordinals and the installation of unauthorized RMM tools for persistence.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Limit the hunt to specific hosts; leave empty to scan the entire Windows estate."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "rmm_filenames": {
          "from": {
            "ref": "Talos \u2014 We've got one word for it",
            "kind": "article",
            "observed": "2026-09-10"
          },
          "type": "list[string]",
          "default": [
            "SECOH-QAD.exe",
            "client32.exe"
          ],
          "description": "Known filenames associated with NetSupport Manager and ProcPatcher."
        },
        "vulnerable_drivers": {
          "from": {
            "ref": "Known BYOVD Driver Lists",
            "kind": "manual",
            "observed": "2024-01-01"
          },
          "type": "list[string]",
          "default": [
            "procexp.sys",
            "iobitvdrv.sys"
          ],
          "description": "Common vulnerable drivers used in BYOVD attacks to terminate EDR."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/",
          "name": "Cisco Talos \u2014 We've got one word for it, and it's usually the wrong one"
        }
      ],
      "blind_spots": [
        {
          "id": "memory-only-stealers",
          "risk": "Since these stealers are often memory-only after injection, standard process snapshots will miss them once the loading process (rundll32) exits.",
          "stage": "credential-access-memory-stealers",
          "question": "Are Amatera or ZigCryptoStealer active in memory?",
          "requires": "Endpoint memory scanning or live forensic dump"
        },
        {
          "id": "webdav-uri-encryption",
          "risk": "Encrypted WebDAV traffic prevents seeing the specific payload paths, making the hunt reliant on script-pasting behavior.",
          "stage": "initial-access-social-engineering-webdav",
          "question": "What were the specific filenames accessed on the WebDAV share?",
          "requires": "TLS-decrypted HTTP/WebDAV logs"
        }
      ]
    },
    "name": "UAT-10820 Multi-Stage Stealer Infection Chain",
    "description": "This hunt identifies the multi-stage infection pattern of UAT-10820, starting with interactive scripts that mount WebDAV shares or paste base64-encoded commands. It pivots to identify rare rundll32.exe executions using ordinal calls instead of named exports, a tactic used to load the Amatera stealer. The second phase corroborates these leads by hunting for unauthorized NetSupport Manager installations in user-writable paths and the presence of vulnerable drivers used for EDR termination. The phased agent-led analysis connects early-stage access signals to persistent, high-impact indicators."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "we-ve-got-one-word-for-it-and-it-s-usually-the-wrong-one",
          "index": 1,
          "title": "We've got one word for it, and it's usually the wrong one",
          "total": 2
        },
        "coverage": [
          {
            "stage": "initial-access-social-engineering-webdav",
            "steps": [
              "webdav-script-leads"
            ],
            "status": "covered"
          },
          {
            "stage": "execution-rundll32-ordinals",
            "steps": [
              "rundll32-ordinal-prevalence"
            ],
            "status": "covered"
          },
          {
            "stage": "defense-evasion-edr-termination",
            "steps": [
              "vulnerable-driver-hunt"
            ],
            "status": "covered"
          },
          {
            "stage": "persistence-netsupport-rmm",
            "steps": [
              "rmm-persistence-hunt"
            ],
            "status": "covered"
          },
          {
            "stage": "credential-access-memory-stealers",
            "reason": "Memory-resident stealers require memory forensics or specialized memory scanning not provided by standard process snapshots.",
            "status": "not_visible",
            "blind_spot": "memory-only-stealers"
          },
          {
            "stage": "c2-blockchain-infrastructure",
            "reason": "Belongs to another part of the \"We've got one word for it, and it's usually the wrong one\" series.",
            "status": "out_of_scope"
          },
          {
            "stage": "initial-access-cisco-fmc-exploitation",
            "reason": "Belongs to another part of the \"We've got one word for it, and it's usually the wrong one\" series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An intruder has infected an endpoint using a WebDAV social engineering chain, followed by the execution of disguised DLLs via rundll32 ordinals and the installation of unauthorized RMM tools for persistence.",
        "blind_spots": [
          {
            "id": "memory-only-stealers",
            "risk": "Since these stealers are often memory-only after injection, standard process snapshots will miss them once the loading process (rundll32) exits.",
            "stage": "credential-access-memory-stealers",
            "question": "Are Amatera or ZigCryptoStealer active in memory?",
            "requires": "Endpoint memory scanning or live forensic dump"
          },
          {
            "id": "webdav-uri-encryption",
            "risk": "Encrypted WebDAV traffic prevents seeing the specific payload paths, making the hunt reliant on script-pasting behavior.",
            "stage": "initial-access-social-engineering-webdav",
            "question": "What were the specific filenames accessed on the WebDAV share?",
            "requires": "TLS-decrypted HTTP/WebDAV logs"
          }
        ],
        "scoping_notes": "Focus on Windows workstations and servers. The hunt assumes EDR telemetry for script execution and process activity is enabled.",
        "beyond_detection": "A single rule might alert on a rundll32 ordinal, but this hunt connects that lead to earlier social engineering scripts and follow-on persistence from RMM tools, providing the context an analyst needs for a confirmed intrusion verdict."
      }
    },
    {
      "id": "scope-windows-endpoints",
      "type": "query",
      "label": "Scope Windows Workstations",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT DISTINCT hostname AS device_hostname FROM hb_devices WHERE LOWER(platform) = 'windows' AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_devices",
        "description": "Filter the estate to Windows endpoints where WebDAV social engineering and rundll32 ordinal execution are viable.",
        "expected_signal": "A list of Windows hostnames. Silence indicates no Windows devices are reporting telemetry."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Scope Windows Workstations",
        "reads": [
          "hostname",
          "platform",
          "time"
        ],
        "source": "hb_devices",
        "target": "endpoint",
        "content": "SELECT DISTINCT hostname AS device_hostname FROM hb_devices WHERE LOWER(platform) = 'windows' AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "A list of Windows hostnames. Silence indicates no Windows devices are reporting telemetry.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "webdav-script-leads",
      "type": "query",
      "label": "WebDAV and Interactive Script Leads",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, actor_user_name, script_content, time FROM hb_script_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(script_content) LIKE '%net use%' OR LOWER(script_content) LIKE '%dav%') AND (LOWER(script_content) LIKE '%rundll32%' OR LOWER(script_content) LIKE '%powershell%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_script_activity",
        "description": "Identify scripts mounting WebDAV shares or running rundll32 from user-pasted commands.",
        "expected_signal": "Script blocks performing remote mounts or using rundll32. Silence means no such interactive script blocks were logged."
      },
      "parents": [
        {
          "id": "scope-windows-endpoints"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "WebDAV and Interactive Script Leads",
        "reads": [
          "device_hostname",
          "actor_user_name",
          "script_content",
          "time"
        ],
        "source": "hb_script_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, actor_user_name, script_content, time FROM hb_script_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(script_content) LIKE '%net use%' OR LOWER(script_content) LIKE '%dav%') AND (LOWER(script_content) LIKE '%rundll32%' OR LOWER(script_content) LIKE '%powershell%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Script blocks performing remote mounts or using rundll32. Silence means no such interactive script blocks were logged.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "rundll32-ordinal-prevalence",
      "type": "query",
      "label": "Rundll32 Ordinal Execution Baseline",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT process_cmd_line, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND LOWER(process_name) LIKE '%rundll32.exe' AND process_cmd_line LIKE '%,#%' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_cmd_line HAVING hosts < 5 ORDER BY hosts ASC",
        "surface": "hb_process_activity",
        "description": "Identify rare rundll32.exe command lines using ordinal calls instead of function names.",
        "expected_signal": "Rare command lines where rundll32 executes an export by its ordinal number (e.g., #1)."
      },
      "parents": [
        {
          "id": "scope-windows-endpoints"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rundll32 Ordinal Execution Baseline",
        "reads": [
          "process_cmd_line",
          "device_hostname",
          "process_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT process_cmd_line, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND LOWER(process_name) LIKE '%rundll32.exe' AND process_cmd_line LIKE '%,#%' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_cmd_line HAVING hosts < 5 ORDER BY hosts ASC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Rare command lines where rundll32 executes an export by its ordinal number (e.g., #1).",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_cmd_line"
          ],
          "rare_below": 5
        },
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "early-triage-agent",
      "type": "analytic",
      "label": "Early Stage Evidence Review",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "webdav-script-leads",
          "rundll32-ordinal-prevalence"
        ],
        "objective": "Determine if the host shows high-confidence signs of the UAT-10820 initial access and execution chain.",
        "description": "Review script and process results to identify hosts with successful initial infection markers.",
        "max_iterations": 3,
        "expected_signal": "A per-host verdict on whether the WebDAV/Rundll32 sequence occurred.",
        "success_criteria": "A per-host verdict of suspicious or malicious based on the presence of WebDAV scripts and rare rundll32 ordinal calls."
      },
      "parents": [
        {
          "id": "webdav-script-leads",
          "kind": "merge"
        },
        {
          "id": "rundll32-ordinal-prevalence",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "rmm-persistence-hunt",
      "type": "query",
      "label": "Unauthorized RMM Process Activity",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_path, process_cmd_line, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_path) LIKE '%\\appdata\\%' OR LOWER(process_path) LIKE '%\\temp\\%' OR LOWER(process_path) LIKE '%\\users\\public\\%') AND (instr(',' || '{{rmm_filenames}}' || ',', ',' || process_name || ',') > 0 OR LOWER(process_name) LIKE '%netsupport%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Identify unauthorized remote access tools running from user-writable directories.",
        "expected_signal": "Processes associated with RMM tools running from non-standard, user-writable locations. None means no such processes were active."
      },
      "parents": [
        {
          "id": "early-triage-agent"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Unauthorized RMM Process Activity",
        "reads": [
          "device_hostname",
          "process_name",
          "process_path",
          "process_cmd_line",
          "user_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_path, process_cmd_line, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_path) LIKE '%\\appdata\\%' OR LOWER(process_path) LIKE '%\\temp\\%' OR LOWER(process_path) LIKE '%\\users\\public\\%') AND (instr(',' || '{{rmm_filenames}}' || ',', ',' || process_name || ',') > 0 OR LOWER(process_name) LIKE '%netsupport%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Processes associated with RMM tools running from non-standard, user-writable locations. None means no such processes were active.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "vulnerable-driver-hunt",
      "type": "query",
      "label": "Vulnerable Driver Loads (BYOVD)",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, driver_path, driver_signature_subject, time FROM hb_kernel_extension_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND instr(',' || '{{vulnerable_drivers}}' || ',', ',' || LOWER(driver_path) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_kernel_extension_activity",
        "description": "Identify loads of known vulnerable drivers used to bypass endpoint security.",
        "expected_signal": "Loads of drivers like procexp.sys or iobitvdrv.sys that are commonly abused for EDR termination."
      },
      "parents": [
        {
          "id": "early-triage-agent"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Vulnerable Driver Loads (BYOVD)",
        "reads": [
          "device_hostname",
          "driver_path",
          "driver_signature_subject",
          "time"
        ],
        "source": "hb_kernel_extension_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, driver_path, driver_signature_subject, time FROM hb_kernel_extension_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND instr(',' || '{{vulnerable_drivers}}' || ',', ',' || LOWER(driver_path) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Loads of drivers like procexp.sys or iobitvdrv.sys that are commonly abused for EDR termination.",
        "verified": "dry-run",
        "verified_at": "2026-09-28"
      }
    },
    {
      "id": "chain-analysis-agent",
      "type": "analytic",
      "label": "Full Intrusion Chain Analysis",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "early-triage-agent",
          "rmm-persistence-hunt",
          "vulnerable-driver-hunt"
        ],
        "objective": "Confirm if the identified host has been compromised by the UAT-10820 chain by linking early-stage findings with persistence markers.",
        "description": "Correlate early stage results with follow-on persistence to confirm a full intrusion chain.",
        "max_iterations": 4,
        "expected_signal": "A comprehensive verdict connecting initial leads to secondary impact.",
        "success_criteria": "A per-host verdict of Malicious | Suspicious | Benign, identifying which stage of the infection each host is in."
      },
      "parents": [
        {
          "id": "rmm-persistence-hunt",
          "kind": "merge"
        },
        {
          "id": "vulnerable-driver-hunt",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-decision",
      "type": "checkpoint",
      "label": "Route on Verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the chain-analysis-agent verdict is malicious for at least one host",
        "condition": "the chain-analysis-agent verdict is malicious for at least one host",
        "blind_spot": "memory-only-stealers",
        "confidence": "high",
        "description": "Initiate response for confirmed intrusions.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "chain-analysis-agent"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate Endpoint",
      "config": {
        "target": "endpoint",
        "description": "Halt the compromise and prevent lateral movement or credential exfiltration.",
        "instructions": "Isolate the host immediately and collect forensic artifacts (memory and disk) for further investigation into Amatera stealer presence.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-decision",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Analyst Forensic Review",
      "config": {
        "assignee": "analyst",
        "description": "Verify the agent's findings and assess the impact on credential security.",
        "instructions": "Analyze the cited rundll32 command lines and RMM activity. Review hb_auth_signin for unusual logins from isolated hosts."
      },
      "parents": [
        {
          "id": "route-decision",
          "branch": "default"
        },
        {
          "id": "route-decision",
          "branch": "on_unavailable"
        },
        {
          "id": "route-decision",
          "branch": "on_refutes"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Hunt Closeout",
      "config": {
        "assignee": "analyst",
        "description": "Document findings and tune the baseline if necessary.",
        "instructions": "Record the results and any tuning notes (e.g., legitimate IT use of NetSupport)."
      },
      "parents": [
        {
          "id": "analyst-review"
        }
      ]
    }
  ]
}