{"generated_at":"2026-08-09T00:30:32.382Z","count":89,"alerts":[{"key":"hunt:CVE8451-HUNT-001","type":"hunt","severity":"high","title":"Hunt CVE8451-HUNT-001","reason":"3 hypotheses: NetScaler SAML sequential scanning, probe-then-exploit timing, stolen NSC_TASS session token reuse. See 04-hunts.json for full detail.","href":"/reports","timestamp":null},{"key":"hunt:CVE8451-HUNT-002","type":"hunt","severity":"high","title":"Hunt CVE8451-HUNT-002","reason":"3 hypotheses: NetScaler SAML sequential scanning, probe-then-exploit timing, stolen NSC_TASS session token reuse. See 04-hunts.json for full detail.","href":"/reports","timestamp":null},{"key":"hunt:CVE8451-HUNT-003","type":"hunt","severity":"high","title":"Hunt CVE8451-HUNT-003","reason":"3 hypotheses: NetScaler SAML sequential scanning, probe-then-exploit timing, stolen NSC_TASS session token reuse. See 04-hunts.json for full detail.","href":"/reports","timestamp":null},{"key":"hunt:FB-HUNT-001","type":"hunt","severity":"high","title":"Hunt FB-HUNT-001","reason":"9 hypotheses: FortiGate mass scanning, lateral movement via harvested credentials, AD credential spray (spray_da.py), spider.py AD enumeration, hashpanel.log artifact, ad_full_audit.py execution, smb_test.py probing, ransomware pre-staging (INC/Lynx), IAB credential handoff. See 04-hunts.json for full detail.","href":"/reports","timestamp":null},{"key":"hunt:FB-HUNT-002","type":"hunt","severity":"high","title":"Hunt FB-HUNT-002","reason":"9 hypotheses: FortiGate mass scanning, lateral movement via harvested credentials, AD credential spray (spray_da.py), spider.py AD enumeration, hashpanel.log artifact, ad_full_audit.py execution, smb_test.py probing, ransomware pre-staging (INC/Lynx), IAB credential handoff. See 04-hunts.json for full detail.","href":"/reports","timestamp":null},{"key":"hunt:FB-HUNT-003","type":"hunt","severity":"high","title":"Hunt FB-HUNT-003","reason":"9 hypotheses: FortiGate mass scanning, lateral movement via harvested credentials, AD credential spray (spray_da.py), spider.py AD enumeration, hashpanel.log artifact, ad_full_audit.py execution, smb_test.py probing, ransomware pre-staging (INC/Lynx), IAB credential handoff. See 04-hunts.json for full detail.","href":"/reports","timestamp":null},{"key":"hunt:FB-HUNT-004","type":"hunt","severity":"high","title":"Hunt FB-HUNT-004","reason":"9 hypotheses: FortiGate mass scanning, lateral movement via harvested credentials, AD credential spray (spray_da.py), spider.py AD enumeration, hashpanel.log artifact, ad_full_audit.py execution, smb_test.py probing, ransomware pre-staging (INC/Lynx), IAB credential handoff. See 04-hunts.json for full detail.","href":"/reports","timestamp":null},{"key":"hunt:FB-HUNT-005","type":"hunt","severity":"high","title":"Hunt FB-HUNT-005","reason":"9 hypotheses: FortiGate mass scanning, lateral movement via harvested credentials, AD credential spray (spray_da.py), spider.py AD enumeration, hashpanel.log artifact, ad_full_audit.py execution, smb_test.py probing, ransomware pre-staging (INC/Lynx), IAB credential handoff. See 04-hunts.json for full detail.","href":"/reports","timestamp":null},{"key":"hunt:FB-HUNT-006","type":"hunt","severity":"high","title":"Hunt FB-HUNT-006","reason":"9 hypotheses: FortiGate mass scanning, lateral movement via harvested credentials, AD credential spray (spray_da.py), spider.py AD enumeration, hashpanel.log artifact, ad_full_audit.py execution, smb_test.py probing, ransomware pre-staging (INC/Lynx), IAB credential handoff. See 04-hunts.json for full detail.","href":"/reports","timestamp":null},{"key":"hunt:FB-HUNT-007","type":"hunt","severity":"high","title":"Hunt FB-HUNT-007","reason":"9 hypotheses: FortiGate mass scanning, lateral movement via harvested credentials, AD credential spray (spray_da.py), spider.py AD enumeration, hashpanel.log artifact, ad_full_audit.py execution, smb_test.py probing, ransomware pre-staging (INC/Lynx), IAB credential handoff. See 04-hunts.json for full detail.","href":"/reports","timestamp":null},{"key":"hunt:FB-HUNT-008","type":"hunt","severity":"high","title":"Hunt FB-HUNT-008","reason":"9 hypotheses: FortiGate mass scanning, lateral movement via harvested credentials, AD credential spray (spray_da.py), spider.py AD enumeration, hashpanel.log artifact, ad_full_audit.py execution, smb_test.py probing, ransomware pre-staging (INC/Lynx), IAB credential handoff. See 04-hunts.json for full detail.","href":"/reports","timestamp":null},{"key":"hunt:FB-HUNT-009","type":"hunt","severity":"high","title":"Hunt FB-HUNT-009","reason":"9 hypotheses: FortiGate mass scanning, lateral movement via harvested credentials, AD credential spray (spray_da.py), spider.py AD enumeration, hashpanel.log artifact, ad_full_audit.py execution, smb_test.py probing, ransomware pre-staging (INC/Lynx), IAB credential handoff. See 04-hunts.json for full detail.","href":"/reports","timestamp":null},{"key":"hunt:HC-SONICWALL-001","type":"hunt","severity":"high","title":"Hunt HC-SONICWALL-001","reason":"Post-exploitation credential extraction from SMA1000 filesystem — atime forensics on admin credential/VPN session/TOTP seed paths; requires pre-image forensic acquisition","href":"/reports","timestamp":null},{"key":"hunt:HC-SONICWALL-002","type":"hunt","severity":"high","title":"Hunt HC-SONICWALL-002","reason":"VPN session token replay from unusual IPs — impossible-travel and anomalous ASN/geo detection on VPN auth logs for scoped SMA1000 account set","href":"/reports","timestamp":null},{"key":"hunt:HC-SONICWALL-003","type":"hunt","severity":"high","title":"Hunt HC-SONICWALL-003","reason":"TOTP MFA bypass via seed extraction — hunt for TOTP successes at anomalous velocity/hours/geo for SMA1000 accounts; clean result is inconclusive (seeds may be extracted but unused)","href":"/reports","timestamp":null},{"key":"hunt:HC-SONICWALL-004","type":"hunt","severity":"high","title":"Hunt HC-SONICWALL-004","reason":"Retroactive pre-disclosure compromise hunt (June 14, 2026+) — /wsproxy HTTP 101 anomalies → appliance reboot correlation → conf.json mtime → subsequent AD anomalies; log retention may be limiting","href":"/reports","timestamp":null},{"key":"hunt:HC-SONICWALL-005","type":"hunt","severity":"high","title":"Hunt HC-SONICWALL-005","reason":"Appliance fleet sweep for conf.json persistence backdoor — definitive indicator: /__api__/login or /__api__/logout routes in /var/lib/unit/conf.json; positive = confirmed compromise, re-image required","href":"/reports","timestamp":null},{"key":"hunt:HC-ACRSTEALER-001","type":"hunt","severity":"high","title":"Hunt HC-ACRSTEALER-001","reason":"ClickFix RunMRU artifact sweep — RunMRU registry key retains ClickFix-triggered cmd.exe commands; fleet-queryable, survives execution","href":"/reports","timestamp":null},{"key":"hunt:HC-ACRSTEALER-002","type":"hunt","severity":"high","title":"Hunt HC-ACRSTEALER-002","reason":"Process lineage: explorer.exe/conhost.exe spawning rundll32 with UNC path or mshta with remote URI — Sysmon EID 1/4688","href":"/reports","timestamp":null},{"key":"hunt:HC-ACRSTEALER-003","type":"hunt","severity":"high","title":"Hunt HC-ACRSTEALER-003","reason":"Obfuscated PowerShell with ServicePointManager CertificatePolicy bypass and ConsoleHost_history deletion — EID 4104 Script Block Logging","href":"/reports","timestamp":null},{"key":"hunt:HC-ACRSTEALER-007","type":"hunt","severity":"high","title":"Hunt HC-ACRSTEALER-007","reason":"LogiOptionsPlus masquerade — AppData\\Local\\Temp\\LogiOptionsPlus\\ directory + Autoupdate* scheduled task invoking pythonw.exe","href":"/reports","timestamp":null},{"key":"hunt:HC-ACRSTEALER-010","type":"hunt","severity":"high","title":"Hunt HC-ACRSTEALER-010","reason":"Browser credential database access by scripting engine — SRUM for retrospective coverage; SRUM 30-60 day retention boundary urgent for April-June 2026 campaign window","href":"/reports","timestamp":null},{"key":"hunt:HC-UAT11795-001","type":"hunt","severity":"high","title":"Hunt HC-UAT11795-001","reason":"Trojanized installer behavioral hunt — zoom_setup.exe/webex_install.exe/mobaxterm.exe etc. as ParentImage spawning python.exe or dropping .bat/.ps1 to %TEMP%; no file hashes available in IOC set","href":"/reports","timestamp":null},{"key":"hunt:HC-UAT11795-002","type":"hunt","severity":"high","title":"Hunt HC-UAT11795-002","reason":"Starland RAT HWID URL path — HTTP POST from python.exe with spoofed Chrome UA where URL path ends in 8-char hex segment (volume serial format); WLDR PowerShell beacon interval analysis","href":"/reports","timestamp":null},{"key":"hunt:HC-UAT11795-003","type":"hunt","severity":"high","title":"Hunt HC-UAT11795-003","reason":"Shellcode loader AMSI/ETW patching — Sysmon EID 8 to amsi.dll/ntdll.dll as memory acquisition trigger; YARA rules UAT11795_Shellcode_HashAPI_Resolver + Starland_RAT_XOR_Key_helo1_InMemory in 04-hunts.json","href":"/reports","timestamp":null},{"key":"hunt:HC-ASYNCAPI-002","type":"hunt","severity":"high","title":"Hunt HC-ASYNCAPI-002","reason":"pwn-request misconfiguration sweep — scan all org GitHub Actions workflows for pull_request_target + untrusted ref checkout anti-pattern; proactive, not reactive","href":"/reports","timestamp":null},{"key":"hunt:HC-ASYNCAPI-003","type":"hunt","severity":"high","title":"Hunt HC-ASYNCAPI-003","reason":"pull_request_target workflow abuse — same root cause as HC-002; scan for manual-netlify-preview.yml pattern across repos","href":"/reports","timestamp":null},{"key":"hunt:HC-IRAN-001","type":"hunt","severity":"high","title":"Hunt HC-IRAN-001","reason":"AI-accelerated ICS recon — correlate mass EtherNet/IP/Modbus scanning against Rockwell-exposed assets; sectoral targeting pattern (water/wastewater/energy) in Gulf region","href":"/reports","timestamp":null},{"key":"hunt:HC-IRAN-002","type":"hunt","severity":"high","title":"Hunt HC-IRAN-002","reason":"GhostFetch anti-analysis evasion — mouse-movement/screen-res/debugger/VM checks before payload execution; requires sandbox detonation or EDR behavioral analysis","href":"/reports","timestamp":null},{"key":"hunt:HC-IRAN-003","type":"hunt","severity":"high","title":"Hunt HC-IRAN-003","reason":"Fileless GhostBackDoor/HTTP_VIP/CHAR delivery — in-memory execution via GhostFetch; requires EDR with kernel-level visibility or memory forensics on candidate endpoints","href":"/reports","timestamp":null},{"key":"hunt:CA-HUNT-003","type":"hunt","severity":"high","title":"Hunt CA-HUNT-003","reason":"Engineering workstation compromise — off-hours logons, unexpected remote-access tool installation, engineering software launched by non-engineer accounts, sequential multi-PLC connections (<15 min)","href":"/reports","timestamp":null},{"key":"hunt:CA-HUNT-004","type":"hunt","severity":"high","title":"Hunt CA-HUNT-004","reason":"IOCONTROL artifact sweep on Linux IoT/OT devices — process name 'iocontrol', S93InitSystemd.sh boot script, UPX-packed ELF in non-standard paths, outbound TCP 8883, Dropbear SSH; any positive = confirmed compromise","href":"/reports","timestamp":null},{"key":"hunt:CI-HUNT-002","type":"hunt","severity":"high","title":"Hunt CI-HUNT-002","reason":"node.exe spawned via npm run from transient directories (Downloads/Desktop/Temp) — BeaverTail triggers on npm run dev/npm start; correlate working directory creation timestamp","href":"/reports","timestamp":null},{"key":"hunt:CI-HUNT-003","type":"hunt","severity":"high","title":"Hunt CI-HUNT-003","reason":"Trojanized npm repo artifacts — serverValidation.js, country-flag SVG directories (>20 SVG files), ZIP archives named next-ecommerce/shopping-platform/ecommerce-platform","href":"/reports","timestamp":null},{"key":"hunt:CI-HUNT-004","type":"hunt","severity":"high","title":"Hunt CI-HUNT-004","reason":"node.exe reading >10 SVG files within 5s window followed by outbound network connection — Base64/eval sequence from SVG HTML comment payloads; requires EDR file-read telemetry","href":"/reports","timestamp":null},{"key":"hunt:CI-HUNT-005","type":"hunt","severity":"high","title":"Hunt CI-HUNT-005","reason":"SVG files in assets/public/static directories >5KB — country flag SVGs are typically <2KB; YARA rule for HTML comment blocks with >200-char Base64 content","href":"/reports","timestamp":null},{"key":"hunt:CI-HUNT-006","type":"hunt","severity":"high","title":"Hunt CI-HUNT-006","reason":"node.exe or npm-cache reading browser credential stores (Chrome Login Data, Firefox profiles, crypto wallets) — npm-cache masquerade is near-direct fingerprint","href":"/reports","timestamp":null},{"key":"hunt:CI-HUNT-010","type":"hunt","severity":"high","title":"Hunt CI-HUNT-010","reason":"C2 beaconing to rightwidth.dev subdomains (controller/upload/ldb/file) from node.exe/npm-cache — WebSocket/Socket.IO; any hit = high-confidence compromise, escalate to IR immediately","href":"/reports","timestamp":null},{"key":"hunt:MS-HUNT-001","type":"hunt","severity":"high","title":"Hunt MS-HUNT-001","reason":"ClickUp CDN / pixeldrain phishing link delivery — hunt EmailUrlInfo for non-blocked emails with t[0-9]+.p.clickup-attachments.com or pixeldrain.com URLs pointing to executable extensions","href":"/reports","timestamp":null},{"key":"hunt:MS-HUNT-002","type":"hunt","severity":"high","title":"Hunt MS-HUNT-002","reason":"AiTM session token reuse — interactive auth IP vs. non-interactive token use IP differ within 30 min on same CorrelationId in SigninLogs; AiTM inferred from Tycoon2FA aftermath","href":"/reports","timestamp":null},{"key":"hunt:MS-HUNT-003","type":"hunt","severity":"high","title":"Hunt MS-HUNT-003","reason":"MFA bypass artifacts — successful MFA via SMS/phone call with Entra risk signals, or MFA required in token but authMethod field absent (ghost satisfaction); correlate with MS-HUNT-002","href":"/reports","timestamp":null},{"key":"hunt:CI-HUNT-009","type":"hunt","severity":"high","title":"Hunt CI-HUNT-009","reason":"Compound: npm startup → credential reads AND file enumeration AND outbound network within 30s from same PID — three-category correlation rules out legitimate dev workflows","href":"/reports","timestamp":null},{"key":"hunt:MS-HUNT-004","type":"hunt","severity":"high","title":"Hunt MS-HUNT-004","reason":"BEC lookalike domain detection — EmailEvents inbound to financial role mailboxes where DMARC/SPF fails or sender matches known BEC IOC domains: 9i6pokerdepot.com, ecajovna.sk, ilyff.com, j-gmails.com, x2mails.com, compliance-protectionoutlook.de, businesshellosign.de","href":"/reports","timestamp":null},{"key":"hunt:MS-HUNT-005","type":"hunt","severity":"high","title":"Hunt MS-HUNT-005","reason":"External Teams tenants with generic infrastructure display names (support/helpdesk/IT/security/azure/365) contacting internal users — focus on 14:00-20:00 UTC concentration window","href":"/reports","timestamp":null},{"key":"hunt:MS-HUNT-006","type":"hunt","severity":"high","title":"Hunt MS-HUNT-006","reason":"Compromised internal accounts as BEC relay — anomalous outbound email volume, unique external recipient count, BEC financial keywords, off-hours activity","href":"/reports","timestamp":null},{"key":"hunt:MS-HUNT-007","type":"hunt","severity":"high","title":"Hunt MS-HUNT-007","reason":"ClickUp CDN / pixeldrain download → cmd.exe/PowerShell execution within 5 min — Financial_report.bat kill chain; known SHA-256 hashes in 04-hunts.json","href":"/reports","timestamp":null},{"key":"hunt:CP-HUNT-001","type":"hunt","severity":"high","title":"Hunt CP-HUNT-001","reason":"Vishing precursor to Salesforce OAuth approval — Teams external call to IT/finance/exec roles within 30 min preceding non-admin AppAuthorization event; IOC IPs 138.226.246.94 / 212.86.125.24 / 213.111.148.90 / 94.154.32.160 in SourceIp = confirmed ShinyHunters","href":"/reports","timestamp":null},{"key":"hunt:CP-HUNT-002","type":"hunt","severity":"high","title":"Hunt CP-HUNT-002","reason":"Vendor OAuth foothold (Salesloft/Gainsight/Klue) — bulk Salesforce API calls by these vendor connected apps deviating from 90-day baseline volume or running off-hours","href":"/reports","timestamp":null},{"key":"hunt:CP-HUNT-004","type":"hunt","severity":"high","title":"Hunt CP-HUNT-004","reason":"CylindricalCanine DigiCert-signed binary audit — MDE DeviceProcessEvents where Signer has 'DigiCert' and SignatureState in (Revoked/Invalid/Unknown); window 90 days back (April-June 2026)","href":"/reports","timestamp":null},{"key":"hunt:CP-HUNT-006","type":"hunt","severity":"high","title":"Hunt CP-HUNT-006","reason":"WAF/IDS CVE probe hits without downstream exploitation alert (detection gap) — SharePoint /_api/ and WordPress /wp-json/batch/v1 POST patterns; HTTP 200/201 on unauthenticated POST = possible silent exploit success","href":"/reports","timestamp":null},{"key":"hunt:CP-HUNT-007","type":"hunt","severity":"high","title":"Hunt CP-HUNT-007","reason":"ShinyHunters OAuth token geographic anomaly — Salesforce API calls from IPs outside user historical login set; IOC IPs are immediate escalation trigger regardless of volume","href":"/reports","timestamp":null},{"key":"hunt:CP-HUNT-008","type":"hunt","severity":"high","title":"Hunt CP-HUNT-008","reason":"Spirals ransomware precursor chain — w3wp.exe→cmd/PS spawn + WmiPrvSE.exe lateral exec + PSEXESVC install + destruction commands (vssadmin/bcdedit/wbadmin) in compressed window","href":"/reports","timestamp":null},{"key":"hunt:CP-HUNT-009","type":"hunt","severity":"high","title":"Hunt CP-HUNT-009","reason":"WMI persistence subscriptions (Filter/Consumer/Binding triplets) and off-hours mofcomp.exe — Sysmon EID 19/20/21 or WMI-Activity 5861; note WMI-Activity/Operational logging must be explicitly enabled","href":"/reports","timestamp":null},{"key":"hunt:MK-HUNT-001","type":"hunt","severity":"high","title":"Hunt MK-HUNT-001","reason":"LinkedIn social engineering recruitment phishing — extended pre-attack rapport building (weeks-to-months); no cold-phish pattern; identity-validation and insider threat controls","href":"/reports","timestamp":null},{"key":"hunt:MK-HUNT-002","type":"hunt","severity":"high","title":"Hunt MK-HUNT-002","reason":"ISO-delivered NightLedger implant staging — AppVShNotify.exe outside system paths after ISO mount from non-C drive","href":"/reports","timestamp":null},{"key":"hunt:MK-HUNT-003","type":"hunt","severity":"high","title":"Hunt MK-HUNT-003","reason":"Remote command execution via NightLedger C2 — process execution from AppVShNotify.exe context via DoH-resolved C2 channel","href":"/reports","timestamp":null},{"key":"hunt:MK-HUNT-007","type":"hunt","severity":"high","title":"Hunt MK-HUNT-007","reason":"BridgeHead SOCKS5 relay traffic pattern — long-duration TCP tunnel through AppVShNotify.exe or BridgeHead process to aecert.org infrastructure","href":"/reports","timestamp":null},{"key":"hunt:MK-HUNT-009","type":"hunt","severity":"critical","title":"Hunt MK-HUNT-009","reason":"DoH tunneling to non-browser resolver endpoints — non-browser process HTTPS to cloudflare-dns.com/dns-query or dns.google/resolve; any non-browser DoH = anomaly","href":"/reports","timestamp":null},{"key":"hunt:TS-HUNT-001","type":"hunt","severity":"high","title":"Hunt TS-HUNT-001","reason":"ISO-packaged software delivery lure — disk mount followed by execution of RegSchdTask.exe or GoProAlertService.exe from non-C drive","href":"/reports","timestamp":null},{"key":"hunt:CA-HUNT-001","type":"hunt","severity":"high","title":"Hunt CA-HUNT-001","reason":"Shodan/Censys OT reconnaissance of exposed engineering ports (44818, 102, 2404) — self-query org IP ranges and correlate with subsequent firewall connection attempts","href":"/reports","timestamp":null},{"key":"hunt:CA-HUNT-004","type":"hunt","severity":"high","title":"Hunt CA-HUNT-004","reason":"HMI view manipulation to mask setpoint changes — HMI display value divergence from PLC historian values","href":"/reports","timestamp":null},{"key":"hunt:CA-HUNT-005","type":"hunt","severity":"critical","title":"Hunt CA-HUNT-005","reason":"Coordinated multi-utility disruption timing patterns — simultaneous EtherNet/IP connection events across multiple water/energy sites within a 30-minute window","href":"/reports","timestamp":null},{"key":"hunt:CPW-HUNT-001","type":"hunt","severity":"high","title":"Hunt CPW-HUNT-001","reason":"AI-generated phishing / LNK delivery infrastructure — LNK or HTA file downloads from corporate endpoints; any .lnk/.hta in Downloads/Temp/Desktop","href":"/reports","timestamp":null},{"key":"hunt:CPW-HUNT-004","type":"hunt","severity":"high","title":"Hunt CPW-HUNT-004","reason":"Browser credential theft (Chromium) — BeaverTail/OmniStealer access to Chrome Login Data SQLite from node.exe or python.exe","href":"/reports","timestamp":null},{"key":"hunt:CPW-HUNT-005","type":"hunt","severity":"high","title":"Hunt CPW-HUNT-005","reason":"Telegram tdata session theft — file read of %APPDATA%\\Telegram Desktop\\tdata\\* by non-Telegram process","href":"/reports","timestamp":null},{"key":"hunt:CPW-HUNT-008","type":"hunt","severity":"high","title":"Hunt CPW-HUNT-008","reason":"BeaverTail obfuscated JavaScript staging — node.exe executing heavily base64-encoded/eval-wrapped scripts from %TEMP%","href":"/reports","timestamp":null},{"key":"hunt:CPW-HUNT-009","type":"hunt","severity":"high","title":"Hunt CPW-HUNT-009","reason":"OmniStealer Python stealer execution — python.exe reading browser credential DBs and SSH key files, exfiltrating to api.telegram.org","href":"/reports","timestamp":null},{"key":"hunt:CPW-HUNT-010","type":"hunt","severity":"high","title":"Hunt CPW-HUNT-010","reason":"Cross-platform credential theft pattern — macOS/Linux python3 accessing browser credential stores (Keychain, .mozilla/firefox)","href":"/reports","timestamp":null},{"key":"hunt:CPW-HUNT-012","type":"hunt","severity":"critical","title":"Hunt CPW-HUNT-012","reason":"PolinRider npm package registry monitoring — any install of packages matching Check Point Research IOC list; integrate with Socket.dev/Snyk feed","href":"/reports","timestamp":null},{"key":"hunt:CPW-HUNT-013","type":"hunt","severity":"high","title":"Hunt CPW-HUNT-013","reason":"Blockchain dead-drop C2 resolution pattern — non-browser process HTTPS to tronscan.org, bscscan.com, aptoslabs.com, trongrid.io, infura.io","href":"/reports","timestamp":null},{"key":"hunt:TALOSQ2-HUNT-001","type":"hunt","severity":"critical","title":"Hunt TALOSQ2-HUNT-001","reason":"AitM proxy patterns — dual IP sign-in within 5 min for same UPN; Evilginx/Modlishka reverse proxy fingerprinting","href":"/reports","timestamp":null},{"key":"hunt:TALOSQ2-HUNT-002","type":"hunt","severity":"high","title":"Hunt TALOSQ2-HUNT-002","reason":"ARToken PhaaS OAuth app registrations in Entra ID — unusual app registrations with Mail.Read/Files.Read permissions; device-code flow enabled","href":"/reports","timestamp":null},{"key":"hunt:TALOSQ2-HUNT-003","type":"hunt","severity":"high","title":"Hunt TALOSQ2-HUNT-003","reason":"Device-code phishing lures via email header analysis — emails containing 'deviceauth' or XXXX-XXXX device code pattern","href":"/reports","timestamp":null},{"key":"hunt:TALOSQ2-HUNT-004","type":"hunt","severity":"high","title":"Hunt TALOSQ2-HUNT-004","reason":"Post-AitM M365 mass email access — MailItemsAccessed >500 items/session or from unusual IP/UA (requires E5/Purview Audit Premium)","href":"/reports","timestamp":null},{"key":"hunt:TALOSQ2-HUNT-006","type":"hunt","severity":"high","title":"Hunt TALOSQ2-HUNT-006","reason":"Ransomware staging — network share enumeration; single host connecting to port 445 across >20 unique targets in 10 minutes","href":"/reports","timestamp":null},{"key":"hunt:TALOSQ2-HUNT-011","type":"hunt","severity":"critical","title":"Hunt TALOSQ2-HUNT-011","reason":"Warlock ransomware SharePoint exploitation artifacts — w3wp.exe spawning cmd.exe/powershell.exe; web shell drops to SharePoint LAYOUTS path","href":"/reports","timestamp":null},{"key":"hunt:TALOSQ2-HUNT-012","type":"hunt","severity":"high","title":"Hunt TALOSQ2-HUNT-012","reason":"Machine key reuse persistence on patched SharePoint — POST to _layouts/_vti_bin with anomalous ViewState and no preceding auth session","href":"/reports","timestamp":null},{"key":"hunt:TALOSQ2-HUNT-017","type":"hunt","severity":"critical","title":"Hunt TALOSQ2-HUNT-017","reason":"Mirage Kitten NightLedger C2 IOC correlation (cross-case) — any connection to aecert.org, realhealthshop.com, or tjconsultingservices.com; immediate isolation","href":"/reports","timestamp":null},{"key":"hunt:TALOSQ2-HUNT-007","type":"hunt","severity":"critical","title":"Hunt TALOSQ2-HUNT-007","reason":"Volume Shadow Copy deletion (vssadmin/wmic/PowerShell) — automate host isolation response on any positive; near-zero FP","href":"/reports","timestamp":null},{"key":"hunt:TALOSQ2-HUNT-008","type":"hunt","severity":"high","title":"Hunt TALOSQ2-HUNT-008","reason":"Lateral movement via Pass-the-Hash post NTDS dump — privileged account NTLM LogonType 3 from non-primary workstations","href":"/reports","timestamp":null},{"key":"hunt:TALOSQ2-HUNT-009","type":"hunt","severity":"high","title":"Hunt TALOSQ2-HUNT-009","reason":"BeaverTail JS staging via npm postinstall hook — node.exe spawned by npm/yarn with 'postinstall' then connecting to blockchain RPC endpoint","href":"/reports","timestamp":null},{"key":"hunt:TALOSQ2-HUNT-010","type":"hunt","severity":"high","title":"Hunt TALOSQ2-HUNT-010","reason":"OmniStealer Python payload execution — python.exe reading browser credential DBs, SSH keys, and connecting to api.telegram.org or g.api.mega.co.nz","href":"/reports","timestamp":null},{"key":"hunt:TALOSQ2-HUNT-013","type":"hunt","severity":"critical","title":"Hunt TALOSQ2-HUNT-013","reason":"Check Point CVE-2026-16232 exploitation artifacts — SmartConsole API calls from non-admin subnet; token generation without preceding cert auth","href":"/reports","timestamp":null},{"key":"hunt:TALOSQ2-HUNT-014","type":"hunt","severity":"high","title":"Hunt TALOSQ2-HUNT-014","reason":"PureRAT blockchain dead-drop C2 — non-browser process connecting to infura.io/alchemyapi.io/trongrid.io/tronscan.org; especially from hollowed explorer.exe/svchost.exe","href":"/reports","timestamp":null},{"key":"hunt:TALOSQ2-HUNT-016","type":"hunt","severity":"high","title":"Hunt TALOSQ2-HUNT-016","reason":"TeleShim ASUS/GoPro ISO staging (cross-case) — RegSchdTask.exe or GoProAlertService.exe executing from non-C drive after ISO mount","href":"/reports","timestamp":null},{"key":"imp-vps:ibeg.com","type":"impersonation","severity":"high","title":"ibeg.com on operator hosting","reason":"Lookalike of CIB Egypt on non-parking hosting with a live SSH service — actively provisioned, not a parked domain.","href":"/signals","timestamp":null},{"key":"imp-vps:adnoc.click","type":"impersonation","severity":"high","title":"adnoc.click on operator hosting","reason":"Lookalike of ADNOC on non-parking hosting with a live SSH service — actively provisioned, not a parked domain.","href":"/signals","timestamp":null},{"key":"imp-vps:raamco.com","type":"impersonation","severity":"high","title":"raamco.com on operator hosting","reason":"Lookalike of Saudi Aramco on non-parking hosting with a live SSH service — actively provisioned, not a parked domain.","href":"/signals","timestamp":null},{"key":"imp-vps:cibeg.online","type":"impersonation","severity":"high","title":"cibeg.online on operator hosting","reason":"Lookalike of CIB Egypt on non-parking hosting with a live SSH service — actively provisioned, not a parked domain.","href":"/signals","timestamp":null}],"errors":[]}