{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "AitM phishing bypasses MFA by intercepting the session token directly. A successful compromise allows the adversary full access to research data and internal communications without triggering traditional brute-force alerts."
      },
      "name": "UAT-11985 AitM Phishing and Session Harvesting",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1566",
        "attack.t1071",
        "attack.t1041",
        "attack.t1190",
        "command and control",
        "defense evasion",
        "exfiltration",
        "initial access"
      ],
      "related": [
        {
          "hunt": "quishing-qr-code-analysis",
          "reason": "Detection of physical QR code manipulation requires analysis of file metadata or specialized mail security surfaces not used here.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "network": {
          "name": "Network telemetry",
          "category": "network",
          "telemetry": [
            "network"
          ]
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        },
        "identity": {
          "name": "Identity / sign-in telemetry",
          "category": "identity",
          "telemetry": [
            "identity"
          ]
        }
      },
      "analysis": "A single detection rule for the success-page URI is easily evaded by changing the path. This hunt combines URI artifacts, a rare DNS baseline, and anomalous identity sign-ins to confirm the full attack chain from delivery to session harvesting.",
      "coverage": [
        {
          "stage": "initial-access-phishing-and-quishing",
          "steps": [
            "phishing-success-path",
            "rare-dns-activity"
          ],
          "status": "covered"
        },
        {
          "stage": "defense-evasion-obfuscated-phishing-kit",
          "steps": [
            "phishing-success-path"
          ],
          "status": "covered"
        },
        {
          "stage": "c2-aitm-websocket-orchestration",
          "steps": [
            "aitm-websocket-patterns"
          ],
          "status": "covered"
        },
        {
          "stage": "exfiltration-over-http",
          "steps": [
            "anomalous-google-signins"
          ],
          "status": "covered"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "AI-Assisted Phishing and Quishing",
            "slug": "initial-access-phishing-and-quishing",
            "tactic": "initial-access",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "Google Forms URLs in link text redirecting to actor-controlled domains",
              "Themed posters with malicious QR codes",
              "Emails impersonating Taiwan European Union Centre, NCCU, or Taiwan Research Institute",
              "Geopolitical lures regarding 'global strategic landscape' or 'great-power order'"
            ]
          },
          {
            "name": "Obfuscated Phishing Script Delivery",
            "slug": "defense-evasion-obfuscated-phishing-kit",
            "tactic": "defense-evasion",
            "techniques": [
              "T1071"
            ],
            "observables": [
              "while(!![]) { push/shift } array rotation shuffle loop in HTML",
              "Base64 encoded string arrays in client-side JavaScript",
              "navigator.languages browser check for zh-CN, zh-TW, and en locales",
              "Embedded JavaScript at the end of HTML documents"
            ]
          },
          {
            "name": "AitM Real-time Auth Orchestration",
            "slug": "c2-aitm-websocket-orchestration",
            "tactic": "command-and-control",
            "techniques": [
              "T1071"
            ],
            "observables": [
              "Persistent WebSocket connections for authentication state synchronization",
              "Real-time forwarding of MFA challenges to victim UI",
              "iframe with ID google-success-frame",
              "Asset path /google-login-assets/operation-success.html"
            ]
          },
          {
            "name": "Credential and Session Exfiltration",
            "slug": "exfiltration-over-http",
            "tactic": "exfiltration",
            "techniques": [
              "T1041"
            ],
            "observables": [
              "HTTP POST requests used for stateless data transmission of captured credentials",
              "Authenticated session tokens harvested via AitM proxy",
              "Sign-ins to Google from actor infrastructure using stolen session state"
            ]
          }
        ],
        "summary": "UAT-11985, likely a Chinese-speaking threat actor, targeted Taiwan-based research institutions using AI-generated spear-phishing lures and malicious QR codes. The campaign utilized an advanced Adversary-in-the-Middle (AitM) phishing kit that leveraged WebSockets for real-time authentication orchestration and HTTP POST for data exfiltration to bypass MFA."
      },
      "severity": "high",
      "rationale": "Focus on research departments and administrative staff who are more likely to receive geopolitical event invitations. Ensure coverage for both workstation and mobile browsers if they use the corporate proxy.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary is using an AI-assisted AitM phishing framework to harvest authenticated Google sessions from research personnel, identified by real-time WebSocket orchestration and specific success-page artifacts.",
      "parameters": {
        "scope_hosts": {
          "from": {
            "ref": "hunt-standard",
            "kind": "manual",
            "observed": "2026-10-08"
          },
          "type": "list[host]",
          "default": [],
          "description": "Specific hosts to narrow the hunt; leave empty to scan the entire estate."
        },
        "lookback_days": {
          "from": {
            "ref": "hunt-standard",
            "kind": "manual",
            "observed": "2026-10-08"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "aitm_success_path": {
          "from": {
            "ref": "https://blog.talosintelligence.com/uat-11985/",
            "kind": "article",
            "observed": "2026-10-08"
          },
          "type": "path",
          "default": "/google-login-assets/operation-success.html",
          "description": "Specific path used by the phishing kit to simulate successful authentication."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://blog.talosintelligence.com/uat-11985/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://blog.talosintelligence.com/uat-11985/",
          "name": "UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing"
        }
      ],
      "blind_spots": [
        {
          "id": "missing-auth-logs",
          "risk": "If the sign-in occurs entirely in the cloud from the actor's infrastructure and the identity provider is not enrolled, the impact of session harvesting will be invisible.",
          "stage": "exfiltration-over-http",
          "question": "whether the stolen session was used to sign in from an IP not visible to local endpoint logs",
          "requires": "hb_auth_signin with external identity provider coverage"
        },
        {
          "id": "websocket-encapsulation",
          "risk": "Standard HTTP logs see the initial upgrade request but not the subsequent frames, making real-time MFA orchestration invisible without full packet capture.",
          "stage": "c2-aitm-websocket-orchestration",
          "question": "what commands were sent over the WebSocket channel",
          "requires": "hb_http_activity with WebSocket frame inspection"
        }
      ]
    },
    "name": "UAT-11985 AitM Phishing and Session Harvesting",
    "description": "This hunt targets the UAT-11985 campaign, which use a sophisticated adversary-in-the-middle (AitM) kit. The hunt identifies the delivery of specialized phishing assets, follows the command-and-control behavior of the real-time WebSocket orchestration, and corroborates with unauthorized sign-in activity. It follows a phased flow: first scoping the estate for browser-capable hosts, then identifying the delivery of the obfuscated kit and phishing lures, and finally examining the network and identity surfaces for session-harvesting impact."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "coverage": [
          {
            "stage": "initial-access-phishing-and-quishing",
            "steps": [
              "phishing-success-path",
              "rare-dns-activity"
            ],
            "status": "covered"
          },
          {
            "stage": "defense-evasion-obfuscated-phishing-kit",
            "steps": [
              "phishing-success-path"
            ],
            "status": "covered"
          },
          {
            "stage": "c2-aitm-websocket-orchestration",
            "steps": [
              "aitm-websocket-patterns"
            ],
            "status": "covered"
          },
          {
            "stage": "exfiltration-over-http",
            "steps": [
              "anomalous-google-signins"
            ],
            "status": "covered"
          }
        ],
        "rationale": "An adversary is using an AI-assisted AitM phishing framework to harvest authenticated Google sessions from research personnel, identified by real-time WebSocket orchestration and specific success-page artifacts.",
        "blind_spots": [
          {
            "id": "missing-auth-logs",
            "risk": "If the sign-in occurs entirely in the cloud from the actor's infrastructure and the identity provider is not enrolled, the impact of session harvesting will be invisible.",
            "stage": "exfiltration-over-http",
            "question": "whether the stolen session was used to sign in from an IP not visible to local endpoint logs",
            "requires": "hb_auth_signin with external identity provider coverage"
          },
          {
            "id": "websocket-encapsulation",
            "risk": "Standard HTTP logs see the initial upgrade request but not the subsequent frames, making real-time MFA orchestration invisible without full packet capture.",
            "stage": "c2-aitm-websocket-orchestration",
            "question": "what commands were sent over the WebSocket channel",
            "requires": "hb_http_activity with WebSocket frame inspection"
          }
        ],
        "scoping_notes": "Focus on research departments and administrative staff who are more likely to receive geopolitical event invitations. Ensure coverage for both workstation and mobile browsers if they use the corporate proxy.",
        "beyond_detection": "A single detection rule for the success-page URI is easily evaded by changing the path. This hunt combines URI artifacts, a rare DNS baseline, and anomalous identity sign-ins to confirm the full attack chain from delivery to session harvesting."
      }
    },
    {
      "id": "scope-vulnerable-hosts",
      "type": "query",
      "label": "Identify browser-capable hosts",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_hostname, package_name, package_version, vendor_name FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%chrome%' OR LOWER(package_name) LIKE '%firefox%' OR LOWER(package_name) LIKE '%edge%' OR LOWER(package_name) LIKE '%safari%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)",
        "surface": "hb_software_inventory",
        "description": "Identify hosts in the estate that have web browsers installed, as these are the primary targets for the AitM phishing campaign.",
        "expected_signal": "A list of hosts with active browsers. This establishes the scope for subsequent queries."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify browser-capable hosts",
        "reads": [
          "device_hostname",
          "package_name",
          "package_version",
          "vendor_name"
        ],
        "source": "hb_software_inventory",
        "target": "endpoint",
        "content": "SELECT device_hostname, package_name, package_version, vendor_name FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%chrome%' OR LOWER(package_name) LIKE '%firefox%' OR LOWER(package_name) LIKE '%edge%' OR LOWER(package_name) LIKE '%safari%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hosts with active browsers. This establishes the scope for subsequent queries.",
        "verified": "dry-run",
        "verified_at": "2026-10-09"
      }
    },
    {
      "id": "phishing-success-path",
      "type": "query",
      "label": "Access to phishing kit success assets",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "web",
        "content": "SELECT device_hostname, src_endpoint_ip, url_full, url_hostname, url_path, user_agent, time FROM hb_http_activity WHERE (LOWER(url_path) = LOWER('{{aitm_success_path}}') OR LOWER(url_full) LIKE '%' || LOWER('{{aitm_success_path}}') || '%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_http_activity",
        "description": "Identify hosts accessing the specific operation-success.html asset path reported in the UAT-11985 phishing kit.",
        "expected_signal": "Hosts requesting the success page indicate a completed authentication flow through the AitM proxy."
      },
      "parents": [
        {
          "id": "scope-vulnerable-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Access to phishing kit success assets",
        "reads": [
          "device_hostname",
          "src_endpoint_ip",
          "time",
          "url_full",
          "url_hostname",
          "url_path",
          "user_agent"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT device_hostname, src_endpoint_ip, url_full, url_hostname, url_path, user_agent, time FROM hb_http_activity WHERE (LOWER(url_path) = LOWER('{{aitm_success_path}}') OR LOWER(url_full) LIKE '%' || LOWER('{{aitm_success_path}}') || '%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Hosts requesting the success page indicate a completed authentication flow through the AitM proxy.",
        "verified": "dry-run",
        "verified_at": "2026-10-09"
      }
    },
    {
      "id": "rare-dns-activity",
      "type": "query",
      "label": "Rare DNS resolutions related to potential lures",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT query_hostname, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_dns_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY query_hostname HAVING host_count <= 2 ORDER BY host_count ASC",
        "surface": "hb_dns_activity",
        "description": "Baseline DNS resolutions to identify rare domains queried by the same hosts that may be receiving AI-assisted phishing lures.",
        "expected_signal": "Rarely queried domains that may correspond to actor-controlled infrastructure used in the AitM redirect. Silence proves no rare resolutions were captured."
      },
      "parents": [
        {
          "id": "scope-vulnerable-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare DNS resolutions related to potential lures",
        "reads": [
          "device_hostname",
          "query_hostname",
          "time"
        ],
        "source": "hb_dns_activity",
        "target": "endpoint",
        "content": "SELECT query_hostname, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_dns_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY query_hostname HAVING host_count <= 2 ORDER BY host_count ASC",
        "silence": "evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Rarely queried domains that may correspond to actor-controlled infrastructure used in the AitM redirect. Silence proves no rare resolutions were captured.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "query_hostname"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-10-09"
      }
    },
    {
      "id": "agent-early-triage",
      "type": "analytic",
      "label": "Analyze initial access evidence",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity",
          "network",
          "web"
        ],
        "context": [
          "phishing-success-path",
          "rare-dns-activity"
        ],
        "objective": "Determine if any host has loaded the phishing kit based on the path provided in aitm_success_path and any correlated rare DNS queries.",
        "description": "Evaluate whether the HTTP asset requests and rare DNS resolutions indicate a successful UAT-11985 phishing encounter.",
        "max_iterations": 4,
        "expected_signal": "A per-host verdict on whether the initial access phase was observed.",
        "success_criteria": "A list of hosts with confirmed phishing asset access and their associated infrastructure."
      },
      "parents": [
        {
          "id": "phishing-success-path",
          "kind": "merge"
        },
        {
          "id": "rare-dns-activity",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "aitm-websocket-patterns",
      "type": "query",
      "label": "Persistent network connections for AitM",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "network",
        "content": "SELECT device_hostname, dst_endpoint_ip, dst_endpoint_port, protocol, COUNT(*) AS connection_count, MIN(time) AS start_time, MAX(time) AS end_time FROM hb_network_connection WHERE protocol = 'tcp' AND dst_endpoint_port = 443 AND state_kind = 'log' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, dst_endpoint_ip HAVING connection_count > 15 ORDER BY connection_count DESC",
        "surface": "hb_network_connection",
        "description": "Identify potential WebSocket traffic used for real-time authentication state synchronization by looking for persistent outbound TCP/443 connections in flow logs.",
        "expected_signal": "Long-lived or high-frequency connections to a single destination IP on port 443, consistent with the reported real-time orchestration."
      },
      "parents": [
        {
          "id": "agent-early-triage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Persistent network connections for AitM",
        "reads": [
          "device_hostname",
          "dst_endpoint_ip",
          "dst_endpoint_port",
          "protocol",
          "state_kind",
          "time"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT device_hostname, dst_endpoint_ip, dst_endpoint_port, protocol, COUNT(*) AS connection_count, MIN(time) AS start_time, MAX(time) AS end_time FROM hb_network_connection WHERE protocol = 'tcp' AND dst_endpoint_port = 443 AND state_kind = 'log' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, dst_endpoint_ip HAVING connection_count > 15 ORDER BY connection_count DESC",
        "silence": "not_evidence_of_absence",
        "expected": "Long-lived or high-frequency connections to a single destination IP on port 443, consistent with the reported real-time orchestration.",
        "verified": "dry-run",
        "verified_at": "2026-10-09"
      }
    },
    {
      "id": "anomalous-google-signins",
      "type": "query",
      "label": "Google sign-ins from external infrastructure",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "identity",
        "content": "SELECT device_hostname, actor_user_name, src_endpoint_ip, src_location_country, src_location_city, user_agent, dst_endpoint_name, status, time FROM hb_auth_signin WHERE (LOWER(dst_endpoint_name) LIKE '%google%' OR LOWER(service_name) LIKE '%google%') AND status_id = 1 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_auth_signin",
        "description": "Detect session harvesting by identifying successful Google sign-ins from actor-controlled IPs with geographic context.",
        "expected_signal": "Successful Google authentications that, when correlated with the AitM infrastructure, indicate harvested session tokens."
      },
      "parents": [
        {
          "id": "agent-early-triage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Google sign-ins from external infrastructure",
        "reads": [
          "actor_user_name",
          "device_hostname",
          "dst_endpoint_name",
          "service_name",
          "src_endpoint_ip",
          "src_location_city",
          "src_location_country",
          "status",
          "status_id",
          "time",
          "user_agent"
        ],
        "source": "hb_auth_signin",
        "target": "identity",
        "content": "SELECT device_hostname, actor_user_name, src_endpoint_ip, src_location_country, src_location_city, user_agent, dst_endpoint_name, status, time FROM hb_auth_signin WHERE (LOWER(dst_endpoint_name) LIKE '%google%' OR LOWER(service_name) LIKE '%google%') AND status_id = 1 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Successful Google authentications that, when correlated with the AitM infrastructure, indicate harvested session tokens.",
        "verified": "dry-run",
        "verified_at": "2026-10-09"
      }
    },
    {
      "id": "agent-impact-triage",
      "type": "analytic",
      "label": "Synthesize phishing and session harvesting",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity",
          "network",
          "web"
        ],
        "context": [
          "agent-early-triage",
          "aitm-websocket-patterns",
          "anomalous-google-signins"
        ],
        "objective": "Identify hosts where an initial phishing encounter (agent-early-triage) was followed by either a persistent AitM connection or a successful Google authentication from the same external infrastructure.",
        "description": "Correlate the initial access evidence with the follow-on network and identity activity to confirm session harvesting and credential theft.",
        "max_iterations": 6,
        "expected_signal": "A high-confidence verdict on session compromise per host.",
        "success_criteria": "A final verdict of malicious | suspicious | benign per host, citing the chain of evidence from lure delivery to session usage."
      },
      "parents": [
        {
          "id": "aitm-websocket-patterns",
          "kind": "merge"
        },
        {
          "id": "anomalous-google-signins",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on compromise",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "The agent-impact-triage verdict is malicious for at least one host.",
        "condition": "The agent-impact-triage verdict is malicious for at least one host.",
        "blind_spot": "missing-auth-logs",
        "confidence": "high",
        "description": "Direct the hunt to containment for malicious verdicts or analyst review for suspicious findings.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "agent-impact-triage"
        }
      ]
    },
    {
      "id": "isolate-compromised-host",
      "type": "action",
      "label": "Isolate host and revoke sessions",
      "config": {
        "target": "endpoint",
        "description": "Prevent further exploitation of harvested sessions by isolating the affected host and revoking credentials.",
        "instructions": "Isolate the identified host to prevent AitM state synchronization. Simultaneously, force a logout and revoke all active OIDC/OAuth sessions for the affected user account in Google.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Analyst forensic review",
      "config": {
        "assignee": "analyst",
        "description": "Verify the agent's findings and look for evidence of post-compromise activity.",
        "instructions": "Review the DNS and HTTP requests on the isolated host. Search for additional exfiltration or lateral movement that may have occurred using the harvested session. Verify the geolocation and user-agent for any successful Google sign-ins that occurred during the timeframe of the phishing encounter."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-compromised-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Hunt close-out",
      "config": {
        "assignee": "analyst",
        "description": "Document findings and update detection logic.",
        "instructions": "If malicious activity was confirmed, update the domain blocklist with the identified infrastructure. Record any new URI patterns found in the HTTP logs to refine the detection-candidate query for persistent detection."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "analyst-review"
        }
      ]
    }
  ]
}