{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "RMM tools are the dual-use weapon of choice for ransomware groups; detecting them alongside behavioral follow-ons provides the highest probability of stopping an attack before encryption impact."
      },
      "name": "Unauthorized RMM and Ransomware Precursors",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1003.001",
        "attack.t1133",
        "attack.t1486",
        "credential access",
        "discovery",
        "impact",
        "initial access",
        "persistence"
      ],
      "series": {
        "slug": "the-fine-art-of-frustrating-the-adversary",
        "index": 2,
        "title": "The Fine Art of Frustrating the Adversary",
        "total": 2
      },
      "related": [
        {
          "hunt": "social-engineering-lure-detection",
          "reason": "Initial access via phishing is handled in a separate hunt focused on hb_http_activity.",
          "relation": "out-of-scope-alternative"
        },
        {
          "hunt": "cloud-identity-ai-agent-anomalies",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A simple rule for AnyDesk is too noisy. This hunt pivots from the tool discovery to verify harmful follow-on actions including LSASS dumping and mass file operations, providing the context needed for high-confidence isolation.",
      "coverage": [
        {
          "stage": "unauthorized-rmm-persistence",
          "steps": [
            "find-unauthorized-rmm"
          ],
          "status": "covered"
        },
        {
          "stage": "credential-harvesting-lsass",
          "steps": [
            "lsass-credential-access"
          ],
          "status": "covered"
        },
        {
          "stage": "data-encrypted-for-impact",
          "steps": [
            "mass-file-activity"
          ],
          "status": "covered"
        },
        {
          "stage": "initial-access-social-engineering",
          "reason": "Belongs to another part of the 'The Fine Art of Frustrating the Adversary' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "exploitation-public-facing-apps",
          "reason": "Belongs to another part of the 'The Fine Art of Frustrating the Adversary' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "ai-agent-discovery-c2",
          "reason": "Belongs to another part of the 'The Fine Art of Frustrating the Adversary' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Phishing and Social Engineering",
            "slug": "initial-access-social-engineering",
            "tactic": "initial-access",
            "techniques": [
              "T1204.002"
            ],
            "observables": [
              "Lures sent from expired domains",
              "Communication with fictional employee profiles",
              "Urgency-based messaging (unpaid taxes, injured relatives)"
            ]
          },
          {
            "name": "Exploitation of Public-Facing Apps",
            "slug": "exploitation-public-facing-apps",
            "tactic": "initial-access",
            "techniques": [
              "T1190",
              "T1133"
            ],
            "observables": [
              "Unauthorized sign-ins to critical servers",
              "Connections to Kubernetes API servers",
              "Access to exposed VPN gateways"
            ]
          },
          {
            "name": "Persistence via RMM Software",
            "slug": "unauthorized-rmm-persistence",
            "tactic": "persistence",
            "techniques": [
              "T1133"
            ],
            "observables": [
              "Zoho Unattended Agent",
              "AnyDesk",
              "ScreenConnect",
              "Atera",
              "Unauthorized remote technician sessions"
            ]
          },
          {
            "name": "LSASS Credential Access",
            "slug": "credential-harvesting-lsass",
            "tactic": "credential-access",
            "techniques": [
              "T1003.001"
            ],
            "observables": [
              "Mimikatz",
              "comsvcs.dll",
              "procdump -ma lsass.exe",
              "Direct access to LSASS memory"
            ]
          },
          {
            "name": "Agentic Malactivity and Discovery",
            "slug": "ai-agent-discovery-c2",
            "tactic": "discovery",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "Unexpected writes to package registries",
              "Repository creation and dataset commits",
              "API calls to Kubernetes interfaces",
              "DNS-over-HTTPS relays usage",
              "Access to cloud metadata services"
            ]
          },
          {
            "name": "Ransomware Encryption",
            "slug": "data-encrypted-for-impact",
            "tactic": "impact",
            "techniques": [
              "T1486"
            ],
            "observables": [
              "Execution of ransomware encryptor",
              "High-volume file modification / renaming"
            ]
          }
        ],
        "summary": "This scenario outlines the diverse set of adversary behaviors described by Cisco Talos, moving from initial access via social engineering or service exploitation to persistence using legitimate remote-management tools. It concludes with credential harvesting from LSASS memory, data encryption for impact, and emerging malicious activity from misconfigured AI agents targeting cloud infrastructure."
      },
      "severity": "medium",
      "rationale": "Start with servers and executive workstations where the impact of ransomware is highest. Filter out known IT admin accounts and authorized IP ranges.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary is using unauthorized remote management tools to maintain persistence and is performing credential harvesting or staging ransomware encryption.",
      "parameters": {
        "rmm_names": {
          "from": {
            "ref": "talos-frustrating-adversary",
            "kind": "article",
            "observed": "2026-10-01"
          },
          "type": "list[string]",
          "default": [
            "anydesk.exe",
            "screenconnect.exe",
            "zoho.exe",
            "atera.exe",
            "connectwise.exe",
            "teamviewer.exe",
            "logmein.exe"
          ],
          "description": "Common RMM process names to identify in the scoping step."
        },
        "scope_hosts": {
          "from": {
            "ref": "analyst-scoping",
            "kind": "manual",
            "observed": "2024-01-01"
          },
          "type": "list[host]",
          "default": [],
          "description": "List of hosts identified in the scoping step; paste them here to narrow the follow-on queries."
        },
        "lookback_days": {
          "from": {
            "ref": "hunt-parameters",
            "kind": "manual",
            "observed": "2024-01-01"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://blog.talosintelligence.com/the-fine-art-of-frustrating-the-adversary/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://blog.talosintelligence.com/the-fine-art-of-frustrating-the-adversary/",
          "name": "Cisco Talos \u2014 The Fine Art of Frustrating the Adversary"
        }
      ],
      "blind_spots": [
        {
          "id": "unmanaged-devices",
          "risk": "A host without an agent will not appear in hb_process_activity, leaving a visibility gap on unmanaged network segments.",
          "question": "Are unauthorized tools running on unmanaged or shadow IT devices?",
          "requires": "an endpoint agent on every host in scope"
        },
        {
          "id": "in-memory-credential-access",
          "risk": "Sophisticated tools can bypass command-line based detection of credential harvesting by using direct API calls.",
          "stage": "credential-harvesting-lsass",
          "question": "Is the adversary using direct ReadProcessMemory calls from a custom binary?",
          "requires": "hb_module_activity with memory access logs"
        }
      ]
    },
    "name": "Unauthorized RMM and Ransomware Precursors",
    "description": "Adversaries often use legitimate Remote Monitoring and Management (RMM) tools like AnyDesk, ScreenConnect, and Atera to establish a persistent, low-noise foothold. This hunt identifies the presence of unauthorized RMM software and then looks for immediate high-risk follow-on activities: credential harvesting via LSASS memory dumping and high-volume file modifications indicative of ransomware encryption. By correlating the presence of these tools with behavioral indicators of impact, we can interrupt the attack chain before final data encryption."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "the-fine-art-of-frustrating-the-adversary",
          "index": 2,
          "title": "The Fine Art of Frustrating the Adversary",
          "total": 2
        },
        "coverage": [
          {
            "stage": "unauthorized-rmm-persistence",
            "steps": [
              "find-unauthorized-rmm"
            ],
            "status": "covered"
          },
          {
            "stage": "credential-harvesting-lsass",
            "steps": [
              "lsass-credential-access"
            ],
            "status": "covered"
          },
          {
            "stage": "data-encrypted-for-impact",
            "steps": [
              "mass-file-activity"
            ],
            "status": "covered"
          },
          {
            "stage": "initial-access-social-engineering",
            "reason": "Belongs to another part of the 'The Fine Art of Frustrating the Adversary' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "exploitation-public-facing-apps",
            "reason": "Belongs to another part of the 'The Fine Art of Frustrating the Adversary' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "ai-agent-discovery-c2",
            "reason": "Belongs to another part of the 'The Fine Art of Frustrating the Adversary' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary is using unauthorized remote management tools to maintain persistence and is performing credential harvesting or staging ransomware encryption.",
        "blind_spots": [
          {
            "id": "unmanaged-devices",
            "risk": "A host without an agent will not appear in hb_process_activity, leaving a visibility gap on unmanaged network segments.",
            "question": "Are unauthorized tools running on unmanaged or shadow IT devices?",
            "requires": "an endpoint agent on every host in scope"
          },
          {
            "id": "in-memory-credential-access",
            "risk": "Sophisticated tools can bypass command-line based detection of credential harvesting by using direct API calls.",
            "stage": "credential-harvesting-lsass",
            "question": "Is the adversary using direct ReadProcessMemory calls from a custom binary?",
            "requires": "hb_module_activity with memory access logs"
          }
        ],
        "scoping_notes": "Start with servers and executive workstations where the impact of ransomware is highest. Filter out known IT admin accounts and authorized IP ranges.",
        "beyond_detection": "A simple rule for AnyDesk is too noisy. This hunt pivots from the tool discovery to verify harmful follow-on actions including LSASS dumping and mass file operations, providing the context needed for high-confidence isolation."
      }
    },
    {
      "id": "find-unauthorized-rmm",
      "type": "query",
      "label": "Identify hosts running RMM software",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_path, process_cmd_line, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{rmm_names}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || '{{rmm_names}}' || ',', ',' || LOWER(process_path) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Find every host running remote management software that might not be part of the authorized IT toolkit.",
        "expected_signal": "A list of hosts and their RMM processes. Silence means no such tools were running in the window."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Identify hosts running RMM software",
        "reads": [
          "device_hostname",
          "process_name",
          "process_path",
          "process_cmd_line",
          "user_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_path, process_cmd_line, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{rmm_names}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || '{{rmm_names}}' || ',', ',' || LOWER(process_path) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hosts and their RMM processes. Silence means no such tools were running in the window.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_name"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-10-02"
      }
    },
    {
      "id": "lsass-credential-access",
      "type": "query",
      "label": "Credential harvesting via LSASS dumping",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_cmd_line) LIKE '%comsvcs.dll%minidump%' OR LOWER(process_cmd_line) LIKE '%procdump%lsass%' OR LOWER(process_original_file_name) = 'mimikatz.exe') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Detect the use of comsvcs.dll or procdump to target LSASS on hosts identified as having RMM presence.",
        "expected_signal": "Any row showing LSASS memory access on an RMM-equipped host. Silence means no such commands were captured."
      },
      "parents": [
        {
          "id": "find-unauthorized-rmm"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Credential harvesting via LSASS dumping",
        "reads": [
          "device_hostname",
          "process_name",
          "process_cmd_line",
          "user_name",
          "time",
          "process_original_file_name"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_cmd_line) LIKE '%comsvcs.dll%minidump%' OR LOWER(process_cmd_line) LIKE '%procdump%lsass%' OR LOWER(process_original_file_name) = 'mimikatz.exe') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Any row showing LSASS memory access on an RMM-equipped host. Silence means no such commands were captured.",
        "verified": "dry-run",
        "verified_at": "2026-10-02"
      }
    },
    {
      "id": "mass-file-activity",
      "type": "query",
      "label": "Mass file modification for encryption",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT device_hostname, COUNT(DISTINCT file_path) AS unique_files, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_file_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND activity_id IN (3, 5) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname HAVING unique_files > 500",
        "surface": "hb_file_activity",
        "description": "Find hosts with an anomalous volume of renames or updates, typical of ransomware encryption activity.",
        "expected_signal": "A list of hosts where a large number of unique files were renamed or updated in a short window."
      },
      "parents": [
        {
          "id": "find-unauthorized-rmm"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Mass file modification for encryption",
        "reads": [
          "device_hostname",
          "file_path",
          "activity_id",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, COUNT(DISTINCT file_path) AS unique_files, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_file_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND activity_id IN (3, 5) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname HAVING unique_files > 500",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A list of hosts where a large number of unique files were renamed or updated in a short window.",
        "verified": "dry-run",
        "verified_at": "2026-10-02"
      }
    },
    {
      "id": "triage-endpoint-risk",
      "type": "analytic",
      "label": "Triage endpoint risk indicators",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "find-unauthorized-rmm",
          "lsass-credential-access",
          "mass-file-activity"
        ],
        "objective": "Determine if the RMM tool presence correlates with observed credential harvesting or mass file activity to confirm an active intrusion.",
        "description": "Correlate RMM presence with credential harvesting and encryption behaviors to determine if an active intrusion is occurring.",
        "max_iterations": 4,
        "expected_signal": "A per-host verdict citing RMM presence and follow-on actions.",
        "success_criteria": "A verdict of malicious, suspicious, or benign for every host found in the scoping step."
      },
      "parents": [
        {
          "id": "lsass-credential-access",
          "kind": "merge"
        },
        {
          "id": "mass-file-activity",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-risk",
      "type": "checkpoint",
      "label": "Route on risk verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage verdict is malicious for at least one host based on the correlation of RMM and follow-on behaviors",
        "condition": "the triage verdict is malicious for at least one host based on the correlation of RMM and follow-on behaviors",
        "blind_spot": "unmanaged-devices",
        "confidence": "high",
        "description": "Route to containment if an active threat is identified.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-endpoint-risk"
        }
      ]
    },
    {
      "id": "isolate-compromised-host",
      "type": "action",
      "label": "Isolate compromised host",
      "config": {
        "target": "endpoint",
        "description": "Prevent further movement or completion of encryption by isolating the host.",
        "instructions": "Isolate the host immediately via the EDR platform. Do not reboot the machine.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-risk",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "manual-authorization-check",
      "type": "task",
      "label": "Verify RMM authorization",
      "config": {
        "assignee": "analyst",
        "description": "Confirm with asset owners or IT if the identified RMM tool was an authorized exception.",
        "instructions": "Cross-reference the host and user against the approved software list and ticket history."
      },
      "parents": [
        {
          "id": "route-on-risk",
          "branch": "default"
        },
        {
          "id": "route-on-risk",
          "branch": "on_unavailable"
        },
        {
          "id": "route-on-risk",
          "branch": "on_refutes"
        },
        {
          "id": "isolate-compromised-host"
        }
      ]
    },
    {
      "id": "hunt-closeout",
      "type": "task",
      "label": "Close out hunt",
      "config": {
        "assignee": "analyst",
        "description": "Document findings and propose tuning.",
        "instructions": "Record the number of false positives. If malicious, document the time from RMM execution to LSASS dump for alerting thresholds."
      },
      "parents": [
        {
          "id": "manual-authorization-check"
        }
      ]
    }
  ]
}