HYPOTHESIS
12 hypotheses: WEL1DROPPER credential harvesting post-npm (T1003/T1552.001), Cloudflare Workers dead-drop C2 (T1102.001), ENDLESSDOORS firmware backdoor TCP 7000 beacon ~35s interval CRITICAL (T1195.003/T1071.001), ENDLESSDOORS root shell access (T1219), ProKYC AI synthetic identity forensics (T1656), ProKYC fraudulent account velocity correlation (T1585), Cisco SD-WAN post-exploitation hunting (T1068/T1190), Hugging Face covert exfil via download counters (T1048), TP-Link Omada hardcoded private key (T1552.004), MITM provisioning via hardcoded key abuse (T1557), TP-Link Omada ZTP exploitation (T1190), NC Ports ransomware precursor sweep Cisco IOS XE (T1486/T1489/T1490). See 04-hunts.json for full detail.
Full hunt detail (hypothesis reasoning + how-to-run query concept) syncs from the case's 04-hunts.json on the next intel refresh.