{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "AI-generated applications are appearing in environments without formal security vetting, introducing risks like missing rate-limiting and input validation; finding these before they are exploited is a critical exposure check for modern developer environments."
      },
      "name": "Exploitation of AI-Generated Vibe-Coded Applications",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1190",
        "attack.t1110",
        "credential access",
        "discovery",
        "execution",
        "initial access"
      ],
      "related": [
        {
          "hunt": "hardcoded-secrets-in-scripts",
          "reason": "Searching for secrets in file content requires hb_file_activity with data capture or hb_script_activity, which is a separate hunt.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        },
        "identity": {
          "name": "Identity / sign-in telemetry",
          "category": "identity",
          "telemetry": [
            "identity"
          ]
        }
      },
      "analysis": "A simple rule cannot link the presence of an AI-generated package to its specific unvalidated URI paths and a subsequent brute-force spike. This hunt pivots across inventory, vulnerabilities, HTTP, and auth logs using a phased flow to confirm a full attack chain.",
      "coverage": [
        {
          "stage": "vulnerability-discovery",
          "steps": [
            "scope-vibe-apps",
            "vuln-findings"
          ],
          "status": "covered"
        },
        {
          "stage": "exploit-vibe-coded-backend",
          "steps": [
            "http-injection"
          ],
          "status": "covered"
        },
        {
          "stage": "brute-force-credential-access",
          "steps": [
            "signin-brute-force"
          ],
          "status": "covered"
        },
        {
          "stage": "malicious-app-installation",
          "steps": [
            "rare-process-execution"
          ],
          "status": "covered"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Identification of Insecure AI Apps",
            "slug": "vulnerability-discovery",
            "tactic": "discovery",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "vulnerabilities in Lovable-hosted apps",
              "missing input validation",
              "hardcoded API keys",
              "weak encryption settings",
              "public-by-default access controls"
            ]
          },
          {
            "name": "Exploitation of Web Vulnerabilities",
            "slug": "exploit-vibe-coded-backend",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "malicious prompt injection",
              "unauthorized web requests to application endpoints",
              "manipulation of input fields due to missing validation",
              "extraction of sensitive user data from backend databases"
            ]
          },
          {
            "name": "Brute Force Against Unprotected Logins",
            "slug": "brute-force-credential-access",
            "tactic": "credential-access",
            "techniques": [
              "T1110"
            ],
            "observables": [
              "repeated login failures without rate limiting",
              "automated password guessing attempts",
              "high volume of auth requests from single IP",
              "leaked session tokens"
            ]
          },
          {
            "name": "Malicious App Execution",
            "slug": "malicious-app-installation",
            "tactic": "execution",
            "observables": [
              "unauthorized malware installation",
              "suspicious process launches from app directories",
              "apps requesting excessive camera or data permissions",
              "factory reset indicators on Android devices"
            ]
          }
        ],
        "summary": "AI-generated 'vibe coded' applications often lack fundamental security controls like rate limiting and input validation, exposing them to brute force and exploitation. This scenario covers the identification of these vulnerable applications and the subsequent credential access or exploitation attempts by malicious actors."
      },
      "severity": "medium",
      "rationale": "Focus on developer workstations and servers hosting internal prototypes. Narrow the lookback if the HTTP traffic volume is high.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An attacker is exploiting vulnerabilities in AI-generated applications\u2014such as missing input validation or hardcoded secrets\u2014to gain initial access, brute-force credentials, or execute code from user-writable directories.",
      "parameters": {
        "scope_hosts": {
          "type": "list[host]",
          "default": [],
          "description": "Hosts to narrow the follow-on search; the analyst should populate this from the scoping step results."
        },
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "vibe_platforms": {
          "from": {
            "ref": "eset-research",
            "kind": "article",
            "observed": "2026-09-25"
          },
          "type": "list[string]",
          "default": [
            "lovable",
            "replit",
            "vibe",
            "bolt.new",
            "cursor"
          ],
          "description": "Keywords or vendor names associated with AI-coding platforms."
        },
        "brute_force_limit": {
          "type": "number",
          "default": "20",
          "description": "Threshold for login failures from a single IP to indicate brute forcing."
        },
        "injection_patterns": {
          "type": "list[string]",
          "default": [
            "/api/ai/chat",
            "/api/generate",
            "/v1/completions",
            "/prompt"
          ],
          "description": "Specific URI paths commonly used by AI-integrated backends that are targets for injection."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.welivesecurity.com/en/mobile-security/is-new-vibe-coded-app-safe-5-questions-ask-first/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.welivesecurity.com/en/mobile-security/is-new-vibe-coded-app-safe-5-questions-ask-first/",
          "name": "Is that vibe coded app safe? 5 checks before you download"
        }
      ],
      "blind_spots": [
        {
          "id": "no-http-body-telemetry",
          "risk": "Attackers can hide malicious prompts in the HTTP request body which is not captured by standard proxy or server logs.",
          "stage": "exploit-vibe-coded-backend",
          "question": "Are prompt injection payloads hidden in POST bodies?",
          "requires": "hb_http_activity with request body capture"
        },
        {
          "id": "os-agnostic-vulnerabilities",
          "risk": "Software inventory and vulnerability findings only see what is already known; new vibe-coded apps have bespoke flaws not yet indexed.",
          "stage": "vulnerability-discovery",
          "question": "Does the app contain hardcoded secrets not yet known to scanners?",
          "requires": "Source code scanning integration"
        }
      ]
    },
    "name": "Exploitation of AI-Generated Vibe-Coded Applications",
    "description": "Vibe coding allows rapid application development but often bypasses traditional security reviews, leading to critical flaws such as missing input validation and rate limiting. This hunt identifies the presence of apps from popular AI-coding platforms, detects early signs of web-based exploitation like prompt injection, and correlates these with follow-on credential access or suspicious host activity. By phasing the analysis, we distinguish between generic noise and targeted exploitation of insecurely built internal tools that lack production-grade security controls."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "coverage": [
          {
            "stage": "vulnerability-discovery",
            "steps": [
              "scope-vibe-apps",
              "vuln-findings"
            ],
            "status": "covered"
          },
          {
            "stage": "exploit-vibe-coded-backend",
            "steps": [
              "http-injection"
            ],
            "status": "covered"
          },
          {
            "stage": "brute-force-credential-access",
            "steps": [
              "signin-brute-force"
            ],
            "status": "covered"
          },
          {
            "stage": "malicious-app-installation",
            "steps": [
              "rare-process-execution"
            ],
            "status": "covered"
          }
        ],
        "rationale": "An attacker is exploiting vulnerabilities in AI-generated applications\u2014such as missing input validation or hardcoded secrets\u2014to gain initial access, brute-force credentials, or execute code from user-writable directories.",
        "blind_spots": [
          {
            "id": "no-http-body-telemetry",
            "risk": "Attackers can hide malicious prompts in the HTTP request body which is not captured by standard proxy or server logs.",
            "stage": "exploit-vibe-coded-backend",
            "question": "Are prompt injection payloads hidden in POST bodies?",
            "requires": "hb_http_activity with request body capture"
          },
          {
            "id": "os-agnostic-vulnerabilities",
            "risk": "Software inventory and vulnerability findings only see what is already known; new vibe-coded apps have bespoke flaws not yet indexed.",
            "stage": "vulnerability-discovery",
            "question": "Does the app contain hardcoded secrets not yet known to scanners?",
            "requires": "Source code scanning integration"
          }
        ],
        "scoping_notes": "Focus on developer workstations and servers hosting internal prototypes. Narrow the lookback if the HTTP traffic volume is high.",
        "beyond_detection": "A simple rule cannot link the presence of an AI-generated package to its specific unvalidated URI paths and a subsequent brute-force spike. This hunt pivots across inventory, vulnerabilities, HTTP, and auth logs using a phased flow to confirm a full attack chain."
      }
    },
    {
      "id": "scope-vibe-apps",
      "type": "query",
      "label": "Scope hosts with AI-generated apps",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_hostname, device_uid, package_name, vendor_name, package_version FROM hb_software_inventory WHERE (instr(',' || '{{vibe_platforms}}' || ',', ',' || LOWER(package_name) || ',') > 0 OR instr(',' || '{{vibe_platforms}}' || ',', ',' || LOWER(vendor_name) || ',') > 0) AND asset_scope = 'endpoint'",
        "surface": "hb_software_inventory",
        "description": "Identify hosts where software from AI-generation platforms is installed to narrow the hunt to relevant assets.",
        "expected_signal": "A list of hosts and software packages. Silence means no known vibe-coding platforms were found in the software inventory."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Scope hosts with AI-generated apps",
        "reads": [
          "device_hostname",
          "device_uid",
          "package_name",
          "vendor_name",
          "package_version"
        ],
        "source": "hb_software_inventory",
        "target": "endpoint",
        "content": "SELECT device_hostname, device_uid, package_name, vendor_name, package_version FROM hb_software_inventory WHERE (instr(',' || '{{vibe_platforms}}' || ',', ',' || LOWER(package_name) || ',') > 0 OR instr(',' || '{{vibe_platforms}}' || ',', ',' || LOWER(vendor_name) || ',') > 0) AND asset_scope = 'endpoint'",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hosts and software packages. Silence means no known vibe-coding platforms were found in the software inventory.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "vuln-findings",
      "type": "query",
      "label": "Vulnerability findings for insecure code",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_uid, title, severity, affected_package_name FROM hb_vulnerability_finding WHERE instr(',' || '{{scope_hosts}}' || ',', ',' || device_uid || ',') > 0 AND (LOWER(title) LIKE '%validation%' OR LOWER(title) LIKE '%encryption%')",
        "surface": "hb_vulnerability_finding",
        "description": "Narrow the search to findings related to input validation or encryption on hosts already identified as having AI-generated apps.",
        "expected_signal": "Findings indicating insecure development practices on target hosts. Silence means no validation-related CVEs are currently open on those assets."
      },
      "parents": [
        {
          "id": "scope-vibe-apps"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Vulnerability findings for insecure code",
        "reads": [
          "device_uid",
          "title",
          "severity",
          "affected_package_name"
        ],
        "source": "hb_vulnerability_finding",
        "target": "endpoint",
        "content": "SELECT device_uid, title, severity, affected_package_name FROM hb_vulnerability_finding WHERE instr(',' || '{{scope_hosts}}' || ',', ',' || device_uid || ',') > 0 AND (LOWER(title) LIKE '%validation%' OR LOWER(title) LIKE '%encryption%')",
        "silence": "evidence_of_absence",
        "expected": "Findings indicating insecure development practices on target hosts. Silence means no validation-related CVEs are currently open on those assets.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "http-injection",
      "type": "query",
      "label": "HTTP traffic to AI endpoints",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "web",
        "content": "SELECT device_hostname, src_endpoint_ip, url_full, http_method, time FROM hb_http_activity WHERE instr(',' || '{{injection_patterns}}' || ',', ',' || LOWER(url_path) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_http_activity",
        "description": "Find traffic targeting AI-related URI paths where prompt injection often occurs, indicating possible backend exploitation attempts.",
        "expected_signal": "Requests to AI-specific backend paths. Silence means no tracked endpoints were accessed during the lookback window."
      },
      "parents": [
        {
          "id": "scope-vibe-apps"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "HTTP traffic to AI endpoints",
        "reads": [
          "device_hostname",
          "src_endpoint_ip",
          "url_full",
          "http_method",
          "url_path",
          "time"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT device_hostname, src_endpoint_ip, url_full, http_method, time FROM hb_http_activity WHERE instr(',' || '{{injection_patterns}}' || ',', ',' || LOWER(url_path) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Requests to AI-specific backend paths. Silence means no tracked endpoints were accessed during the lookback window.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "early-triage",
      "type": "analytic",
      "label": "Early stage exposure analysis",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity",
          "web"
        ],
        "context": [
          "scope-vibe-apps",
          "vuln-findings",
          "http-injection"
        ],
        "objective": "Determine if any host has a combination of AI apps and either known vulnerabilities or suspicious traffic patterns indicating a beachhead.",
        "description": "Determine if any host shows a combination of AI apps and either known vulnerabilities or suspicious traffic patterns before looking for impact.",
        "max_iterations": 4,
        "expected_signal": "A per-host verdict on whether initial access attempts or exposures are present.",
        "success_criteria": "A per-host verdict on the likelihood of initial access attempts."
      },
      "parents": [
        {
          "id": "vuln-findings",
          "kind": "merge"
        },
        {
          "id": "http-injection",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "signin-brute-force",
      "type": "query",
      "label": "Brute force against unprotected logins",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "identity",
        "content": "SELECT dst_endpoint_name, src_endpoint_ip, actor_user_name, COUNT(*) as failures FROM hb_auth_signin WHERE activity_id = 5 AND instr(',' || '{{scope_hosts}}' || ',', ',' || dst_endpoint_name || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_name, src_endpoint_ip, actor_user_name HAVING failures >= {{brute_force_limit}}",
        "surface": "hb_auth_signin",
        "description": "Detect failed login spikes scoped to the identified AI-app hosts, where rate-limiting is likely missing.",
        "expected_signal": "Hosts or IPs showing excessive failed logins. Silence indicates no password guessing was observed on these specific hosts."
      },
      "parents": [
        {
          "id": "early-triage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Brute force against unprotected logins",
        "reads": [
          "dst_endpoint_name",
          "src_endpoint_ip",
          "actor_user_name",
          "time",
          "activity_id"
        ],
        "source": "hb_auth_signin",
        "target": "identity",
        "content": "SELECT dst_endpoint_name, src_endpoint_ip, actor_user_name, COUNT(*) as failures FROM hb_auth_signin WHERE activity_id = 5 AND instr(',' || '{{scope_hosts}}' || ',', ',' || dst_endpoint_name || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_name, src_endpoint_ip, actor_user_name HAVING failures >= {{brute_force_limit}}",
        "silence": "not_evidence_of_absence",
        "expected": "Hosts or IPs showing excessive failed logins. Silence indicates no password guessing was observed on these specific hosts.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "rare-process-execution",
      "type": "query",
      "label": "Rare execution from app directories",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_path, process_cmd_line, user_name, time FROM hb_process_activity WHERE instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0 AND (LOWER(process_path) LIKE '%\\appdata\\%' OR LOWER(process_path) LIKE '/tmp/%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Find rare processes launched from user-writable paths specifically on the hosts hosting AI apps.",
        "expected_signal": "A process launched from a user profile on a scoped host. Silence proves no rare processes launched from these paths in the current snapshot."
      },
      "parents": [
        {
          "id": "early-triage"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare execution from app directories",
        "reads": [
          "device_hostname",
          "process_name",
          "process_path",
          "process_cmd_line",
          "user_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_path, process_cmd_line, user_name, time FROM hb_process_activity WHERE instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0 AND (LOWER(process_path) LIKE '%\\appdata\\%' OR LOWER(process_path) LIKE '/tmp/%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A process launched from a user profile on a scoped host. Silence proves no rare processes launched from these paths in the current snapshot.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_name"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "impact-assessment",
      "type": "analytic",
      "label": "Final impact assessment",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity",
          "web"
        ],
        "context": [
          "early-triage",
          "signin-brute-force",
          "rare-process-execution"
        ],
        "objective": "Determine if an attacker transitioned from exploiting a vulnerable AI app to gaining credential access or executing code, using context from the early triage.",
        "description": "Consolidate the early-stage findings with follow-on brute force or suspicious process activity to confirm an intrusion chain.",
        "max_iterations": 6,
        "expected_signal": "A comprehensive per-host verdict on whether an attacker successfully pivoted from a vulnerable AI app.",
        "success_criteria": "A final verdict citing the specific host and evidence of compromise."
      },
      "parents": [
        {
          "id": "signin-brute-force",
          "kind": "merge"
        },
        {
          "id": "rare-process-execution",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on final verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the impact-assessment verdict is malicious for at least one host",
        "condition": "the impact-assessment verdict is malicious for at least one host",
        "blind_spot": "no-http-body-telemetry",
        "confidence": "high",
        "description": "Determine whether to contain the host based on the high-confidence agent verdict.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "impact-assessment"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate host",
      "config": {
        "target": "endpoint",
        "description": "Contain confirmed intrusion to prevent lateral movement or data exfiltration.",
        "instructions": "Isolate the compromised host and revoke any session tokens or passwords used by the AI application.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-validation",
      "type": "task",
      "label": "Analyst validation",
      "config": {
        "assignee": "analyst",
        "description": "Review the agent's findings and verify the malicious activity.",
        "instructions": "Review the cited logs, verify the injection patterns, and confirm whether the detected software is authorized and secure according to policy."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out",
      "config": {
        "assignee": "analyst",
        "description": "Finalize the hunt and record improvements.",
        "instructions": "Document the findings, update software inventory policies for AI apps, and submit tuning notes if false positives occurred."
      },
      "parents": [
        {
          "id": "analyst-validation"
        }
      ]
    }
  ]
}