PLAYBOOKS NET HOST ATTRIB DETECT
[TONK] Hunt Playbooks
Curated hunt sequences for when intel drops an actor name, a detection fires, or you need to scope an environment. Each playbook is a prioritized checklist linking into the NET and HOST detection references.
start here
Quick Start: Where to Begin
NOT SURE WHERE TO START?
10 universal hunt checks that work in every environment. No prior intel required, no actor hypothesis, no specialized tools. Authentication anomalies, DNS, outbound connections, LOLBin abuse, persistence mechanisms, data movement, and exposed services. If something is wrong on your network, at least one of these will show it. Start here, specialize later.
environment-agnostic · 10 checks · cross-links to every specialized playbook
Import Scan: Generate Hunt Playbook
GOT A SCAN?
Drop in an nmap XML or host-port CSV. This compiles a right-now hunt plan from what the scan actually exposed, routed into NET techniques and PLAYBOOKS exploits. Ranked by signal, with ICS/OT protocol exposure surfaced first. It generates hypotheses to chase, not findings.
nmap XML or CSV · correlated to ATT&CK · cross-links to every specialized playbook
by threat actor
CN Volt Typhoon
VOLT TYPHOON
Operational Profile: China-nexus pre-positioning on US critical infrastructure. VOLTZITE (Dragos) achieved Stage 2 ICS capability in 2025 through direct engineering workstation manipulation.
Key TTPs: Pure LOTL: valid credentials, native OS tools, no custom malware. SYLVANITE initial access team rapidly weaponizes edge CVEs. SOHO router botnets (KV Botnet). Control-loop mapping via Sierra Wireless Airlink compromise.
CN · PLA · G1017 · 12-step hunt checklist · 6 CVEs · documented LOTL commands
CN Salt Typhoon
SALT TYPHOON
Operational Profile: PRC-affiliated. Executed the worst telecom breach in US history. Compromised lawful intercept (CALEA) systems across nine carriers, intercepting presidential communications.
Key TTPs: Custom GhostSpider malware operating at network infrastructure level. Exploitation of carrier-grade routing and switching infrastructure. Persistent access across 80+ countries. Intelligence collection at the backbone, not the endpoint.
CN · PRC · 10-step checklist · 9 carriers · 80+ countries · CALEA exploitation
CN APT41 / Winnti
APT41 / WINNTI
Operational Profile: High-capability China-nexus group executing parallel state-sponsored espionage and financially motivated operations. Highly adept at pivoting across enterprise IT into OT control paths.
Key TTPs: SQL injection to shell for initial access. PlugX/ShadowPad side-loading via legitimate binaries. Kerberoasting for privilege escalation. systemd (Linux) and service manipulation (Windows) for persistence.
CN · MSS / Chengdu 404 · G0096 · 10-step checklist · dual-mandate · 40+ countries
RU Sandworm / APT44
SANDWORM / APT44
Operational Profile: Russia GRU Unit 74455. The most operationally experienced infrastructure-disrupting adversary in the world. Paired model: KAMACITE builds access, ELECTRUM executes destruction.
Key TTPs: Nine wiper families (CaddyWiper through PathWiper). ICS protocol exploitation (Industroyer). Coordination of cyber effects with kinetic military strikes. Expanded into Poland DER targeting (Dec 2025).
RU · GRU 74455 · G0034 · 10-step checklist · 8 wiper families · ICS protocol expertise
RU APT29 / Cozy Bear
APT29 / COZY BEAR
Operational Profile: Russia SVR. The quietest long-dwell operator in the dataset, specializing in supply chain compromise and cloud identity exploitation for intelligence collection.
Key TTPs: Supply chain compromise (SolarWinds-class). Golden SAML and OAuth abuse for cloud persistence. Residential proxy networks to blend with legitimate traffic. Minimal tooling footprint during lateral movement.
RU · SVR · G0016 · 10-step hunt checklist · cloud identity focus
RU APT28 / Fancy Bear
APT28 / FANCY BEAR
Operational Profile: Russia GRU Unit 26165. Fast, noisy, and aggressive compared to APT29. Favors speed over stealth with rapid exploitation and credential phishing at scale.
Key TTPs: Drovorub Linux rootkit. GooseEgg Windows privilege escalation. LAMEHUG LLM-enabled malware for automated recon. Exchange and Outlook exploitation (CVE-2023-23397). OCEANMAP C2 backdoor.
RU · GRU 26165 · G0007 · 10-step hunt checklist · 7 CVEs · 8 custom tools
IR APT35 / Charming Kitten
APT35 / CHARMING KITTEN
Operational Profile: IRGC-affiliated political espionage targeting government, defense, media, and NGOs. Pioneered multi-week relationship-based social engineering ("catfishing") for credential theft.
Key TTPs: Weeks-long fake persona correspondence before delivering credential harvesting links. 2024 US election interference (both campaigns). Fox Kitten crossover: state actor moonlighting as ransomware IAB selling VPN access.
IR · IRGC · Mint Sandstorm · 6-step checklist · catfishing tradecraft · Fox Kitten IAB crossover
IR APT42
APT42
Operational Profile: IRGC Intelligence Organization. Specialized surveillance unit targeting individual human beings: dissidents, activists, journalists, and academics. The target is a person, not a network.
Key TTPs: Custom Android spyware (PINEFLOWER, VINETHORN) for call recording, GPS tracking, and microphone activation. Cloud-native C2 via Cloudflare Workers and Firebase. NICECURL/TAMECAT desktop backdoors.
IR · IRGC-IO · 6-step checklist · mobile spyware · individual surveillance · cloud-native C2
IR MuddyWater
MUDDYWATER
Operational Profile: Iran MOIS. High-volume, persistent operations targeting government, telecom, and energy sectors across the Middle East and Europe. Trades sophistication for scale.
Key TTPs: Spearphishing with maldoc lures (OneNote, PDF, archive). PowerShell-native at every stage (MuddyC2Go framework). Legitimate RMM tool abuse (Atera, SimpleHelp, ScreenConnect) for persistence.
IR · MOIS · Mango Sandstorm · 6-step checklist · MuddyC2Go · PowerShell-native
KP Lazarus / HIDDEN COBRA
LAZARUS / HIDDEN COBRA
Operational Profile: DPRK RGB. The only nation-state APT that funds weapons programs through cybercrime. Cryptocurrency theft ($5B+), SWIFT fraud, ransomware, and destructive wipers, all under one umbrella.
Key TTPs: Developer-targeted social engineering (Operation DreamJob). Trojanized trading apps (AppleJeus). FAMOUS CHOLLIMA planted insiders via AI-generated resumes. PRESSURE CHOLLIMA supply chain attacks ($1.46B Bybit).
KP · RGB · G0032 · 10-step checklist · $5B+ crypto stolen · 3 subgroups
eCrime and hacktivist
Scattered Spider
SCATTERED SPIDER
Operational Profile: English-speaking eCrime collective targeting identity infrastructure. The group that proved a phone call to the help desk scales better than a zero-day. MGM ($100M+), Caesars ($15M), M&S/Co-op/Harrods (2025).
Key TTPs: Help desk vishing and SIM swap for initial access. Okta/Entra ID admin takeover. ESXi hypervisor targeting for ransomware deployment. RaaS affiliate model (BlackCat, RansomHub, DragonForce).
UNC3944 · Octo Tempest · 8-step checklist · DragonForce affiliate
The RaaS Ecosystem
THE RAAS ECOSYSTEM
Operational Profile: Not one group. The machine. A modular cybercrime supply chain where each role (infostealer, IAB, affiliate, RaaS platform) is independent, replaceable, and operating at industrial scale.
Key Statistics: 119 ransomware groups active in 2025. 3,300+ industrial victims. 29-minute average breakout time (27 seconds fastest). 82% of intrusions malware-free. The affiliate playbook is the same regardless of brand.
LockBit · Cl0p · DragonForce · Akira · Play · the affiliate playbook is the same every time
Hacktivist Operations
HACKTIVIST OPERATIONS
Threat Spectrum: Three tiers from opportunistic script kiddies to state-aligned pseudo-hacktivists. DDoS, HMI defacement, and direct ICS protocol manipulation. EU now formally sanctions the proxy hacktivist ecosystem.
Key Developments (2025-2026): Adoption of Cobalt Strike and LOTL techniques. Proven ICS manipulation at US water facilities. Convergence with state actor capabilities blurring the line between vandalism and warfare.
CyberArmyofRussia · CyberAv3ngers · Z-Pentest · KillNet · 8-step checklist · 3-tier spectrum
exploit reference
EternalBlue (MS17-010)
ETERNALBLUE (MS17-010)
Vulnerability: SMBv1 buffer overflow (CVE-2017-0144). Unauthenticated, wormable, SYSTEM-level RCE on TCP 445. Six related CVEs in the MS17-010 family.
Impact: WannaCry (Lazarus, 200K+ systems, NHS crippled). NotPetya (Sandworm, $10B+, Maersk/Merck/FedEx). Nine years old and still present on legacy OT, healthcare, and manufacturing systems.
CVE-2017-0144 · 8-step checklist · Suricata/Zeek/Arkime detection · network-detectable
SharePoint CVE Chain (July 2026)
SHAREPOINT CVE CHAIN (JULY 2026)
Vulnerability: Three chained CVEs: auth bypass (CVE-2026-32201), deserialization RCE (CVE-2026-45659), and privilege escalation (CVE-2026-56164). CISA KEV. Actively exploited.
Impact: IIS machine key theft enables forged authentication cookies that persist without C2. Fully functional inside air-gapped networks. LeakFang backdoor. ~10,000 exposed servers, 800+ unpatched.
CVE-2026-32201 + 45659 + 56164 · 10-step checklist · air-gap implications · actively exploited
PrintNightmare (CVE-2021-34527)
PRINTNIGHTMARE (CVE-2021-34527)
Vulnerability: Windows Print Spooler RpcAddPrinterDriverEx() allows any authenticated domain user to load a malicious DLL as SYSTEM. Local privilege escalation and remote RCE. Enabled by default on every Windows system, including DCs.
Impact: Domain user to SYSTEM in one step. On a DC: domain user to domain compromise. Integrated into Mimikatz and Metasploit. Patch alone was insufficient without disabling Point and Print.
CVE-2021-34527 + CVE-2021-1675 · 6-step checklist · spoolsv.exe child processes · DC compromise path
Log4Shell (CVE-2021-44228)
LOG4SHELL (CVE-2021-44228)
Vulnerability: JNDI injection via log message in Apache Log4j 2.x. A single string (${jndi:ldap://...}) in any logged field achieves unauthenticated RCE. CVSS 10.0. Embedded in hundreds of thousands of Java applications as a transitive dependency.
Impact: Mass exploitation within hours of disclosure. Nation-state (APT35, APT41, Lazarus) and commodity actors simultaneously. The dependency-of-a-dependency problem.
CVE-2021-44228 · 6-step checklist · JNDI/LDAP/RMI callbacks · java.exe child processes
ProxyLogon (CVE-2021-26855)
PROXYLOGON (CVE-2021-26855)
Vulnerability: Unauthenticated SSRF in Exchange Server chained with arbitrary file write for web shell deployment. Exploited as a zero-day by Hafnium (China) two months before disclosure.
Impact: 30,000+ Exchange servers compromised within a week. Full mailbox access plus domain credential exposure. Followed by ProxyShell, ProxyOracle, ProxyNotShell, all exploiting the same architectural flaw.
CVE-2021-26855 + 26857 + 26858 + 27065 · 6-step checklist · w3wp.exe web shells · Exchange proxy architecture
Citrix Bleed (CVE-2023-4966)
CITRIX BLEED (CVE-2023-4966)
Vulnerability: Unauthenticated buffer over-read in Citrix NetScaler ADC/Gateway. Crafted HTTP GET leaks system memory including active session cookies. Complete MFA bypass via session replay.
Impact: Stolen session cookies bypass MFA entirely. No credentials needed. LockBit industrialized this for critical infrastructure campaigns. The attacker and the legitimate user operate simultaneously.
CVE-2023-4966 · 4-step checklist · session hijack · MFA bypass · impossible travel detection
PetitPotam to AD CS (ESC1)
PETITPOTAM TO AD CS (ESC1)
Vulnerability: NTLM coercion via MS-EFSR relayed to misconfigured AD CS enrollment endpoint. Unauthenticated attacker requests a certificate as the Domain Controller's machine account.
Impact: Unauthenticated to Domain Admin in seconds. Certificate-based TGT minting enables full domain compromise. ESC1 is a misconfiguration, not a bug, so patching alone doesn't fix it.
CVE-2021-36942 + AD CS ESC1 · 4-step checklist · NTLM relay · certificate abuse · DC impersonation
Ivanti Connect Secure Chain
IVANTI CONNECT SECURE CHAIN
Vulnerability: Authentication bypass via path traversal (CVE-2023-46805) chained with command injection (CVE-2024-21887). Unauthenticated SYSTEM-level RCE on the VPN perimeter.
Impact: Persistent web shells, session cookie theft (MFA bypass), and internal network sweep from the VPN gateway. CISA ordered emergency disconnection. Ivanti's own integrity checker failed to detect compromises.
CVE-2023-46805 + CVE-2024-21887 · 5-step checklist · VPN perimeter RCE · CISA Emergency Directive
VMware ESXi Exploitation Chain
VMWARE ESXI EXPLOITATION CHAIN
Vulnerability: Multiple attack paths to hypervisor admin: NTLM relay to ESXi management, AD "ESX Admins" group abuse, and direct SSH access. Guest-level EDR is completely bypassed.
Impact: esxcli mass VM kill followed by direct .vmdk encryption from the hypervisor shell. One compromised ESXi host takes down every VM it hosts. Scattered Spider, LockBit, Akira, BlackCat, and Fog all target this.
ESXi / vCenter · 6-step checklist · ESX Admins group · .vmdk encryption · guest EDR bypass
PanOS and FortiGate VPN Bypasses
PANOS AND FORTIGATE VPN BYPASSES
Vulnerability: Palo Alto GlobalProtect command injection (CVE-2024-3400, CVSS 10.0) and FortiGate SSL-VPN RCE (CVE-2024-21762) plus FortiManager "FortiJump" (CVE-2024-47575). The other two pillars of enterprise edge perimeters.
Impact: Unauthenticated RCE on the firewall/VPN. Reverse shell from a device with visibility into every network segment. FortiBleed exposed 73,000+ admin credentials (June 2026).
CVE-2024-3400 + CVE-2024-21762 + CVE-2024-47575 · 5-step checklist · config extraction · firmware persistence
by environment
Air-Gapped Networks
AIR-GAPPED NETWORKS
Environment: Classified enclaves, secure government networks, disconnected labs, and any infrastructure intentionally isolated from the internet. Every tool that phones home stops working. You hunt with what you brought.
Key Attack Paths: Cross-domain transfer exploitation. Contaminated removable media (Stuxnet/Agent.BTZ pattern). Patch delivery supply chain. Data staging to USB. Unauthorized network bridges. SharePoint CVE chain is fully functional here.
no internet · sneakernet · offline tools only · 8-step checklist · 5 tripwires
ICS / SCADA / OT
ICS / SCADA / OT
Environment: Industrial control systems at Purdue Level 0-3. PLCs, HMIs, engineering workstations, and ICS protocols (Modbus, DNP3, S7comm, OPC UA) that were designed for reliability, not security. May be air-gapped, minimally connected, or exposed.
Key Threats (2025-2026): VOLTZITE Stage 2 EWS manipulation. KAMACITE control-loop mapping. PLC_Controller.exe S7comm STOP commands. Modbus PowerShell tools. <10% of OT networks have monitoring.
Purdue model · ICS protocols · Zeek/Suricata · physical process integrity · 10-step checklist
Hybrid AD Enterprise
HYBRID AD ENTERPRISE
Environment: On-premises Active Directory synced to Azure AD / Entra ID. The attack surface spans both worlds: on-prem compromise to cloud escalation and cloud-to-on-prem reverse paths.
Key Attack Paths: Golden SAML for cloud persistence. AD Connect credential extraction. PTA agent abuse. OAuth app consent phishing. Six trust boundaries between on-prem and cloud identity.
AD + Entra · hybrid identity · 10-step checklist · 6 trust boundaries
Linux Server Fleet
LINUX SERVER FLEET
Environment: All-Linux infrastructure: web servers, databases, containers, CI/CD pipelines. No Windows telemetry. Primary detection sources: auditd, Sysmon for Linux, osquery.
Key Attack Paths: SSH lateral movement with harvested keys. cron/systemd persistence. /etc/shadow targeting for credential access. Container escape to host. Rootkit detection via kernel module auditing.
auditd · Sysmon for Linux · osquery
Kubernetes and Container
KUBERNETES AND CONTAINER
Environment: Ephemeral container workloads on K8s. Telemetry dies with the container unless captured at the kernel level via eBPF. Developers run privileged by default, mount host filesystems, and leave API tokens accessible.
Key Attack Paths: Container escape to node. K8s API abuse for rogue pod deployment. Service account token theft. Namespace lateral movement. Image supply chain compromise.
eBPF / Falco / Tetragon · K8s audit logs · 8-step checklist
Cloud Control Plane
CLOUD CONTROL PLANE (AWS / AZURE / GCP)
Environment: Identity is the perimeter. Every action is an API call authenticated by an identity. No firewalls blocking internal movement if IAM is misconfigured. 37% increase in cloud-conscious intrusions (CrowdStrike 2026).
Key Attack Paths: Credential theft and session hijacking. Shadow admin IAM escalation. Snapshot exfil to external accounts. OAuth consent abuse. Logging pipeline disruption.
CloudTrail / Activity Logs · IAM audit · 8-step checklist
macOS Developer Fleet
MACOS DEVELOPER FLEET
Environment: macOS-heavy engineering organizations where developers hold SSH keys, AWS credentials, Git tokens, and Docker configs on machines with minimal endpoint telemetry. The gap between assumed security and actual exposure is enormous.
Key Attack Paths: Keychain dumping. Credential file harvesting (~/.ssh, ~/.aws). TCC bypass via dylib injection. Trojanized developer tools (Lazarus AppleJeus). LaunchAgent persistence.
Endpoint Security API · Unified Log · osquery · 7-step checklist
SOHO Router and Home Edge
SOHO ROUTER AND HOME EDGE
Environment: Consumer routers with no endpoint telemetry. Nation-state actors (Volt Typhoon KV Botnet, APT28 EdgeRouter campaigns, Sandworm Cyclops Blink) compromise SOHO devices to build proxy networks blending with residential ISP traffic.
Key Attack Paths: Web management command injection. Firmware modification with static SSH keys. DNS hijacking. UPnP abuse. Reverse proxy installation (FRP). Hunting is network-artifact-only.
NetFlow / IPFIX · DNS monitoring · no EDR · 8-step checklist · firmware integrity
AI Engineering and LLM Orchestration
AI ENGINEERING AND LLM ORCHESTRATION
Environment: Internal LLM pipelines, vector databases, model staging nodes, and AI orchestration frameworks deployed without standard telemetry. APT28 already uses LLM-enabled malware (LAMEHUG).
Key Attack Paths: Prompt injection against public-facing LLM endpoints. API token theft from .env files. Bulk vector database scraping for proprietary training data exfiltration. Model supply chain (backdoored weights, malicious pickle files).
LangChain · vector DBs · prompt injection · model supply chain · 6-step checklist
incident triage: tier 1 · you will see these
Ransomware Detected
RANSOMWARE DETECTED
Trigger: Encryption observed or extortion note received. 70%+ now exfiltrate before encrypting. 29-minute average breakout time.
Priority Actions: Determine blast radius and deployment mechanism. Establish whether data was exfiltrated (regulatory notification trigger). Check for ESXi/hypervisor targeting. 3,300+ industrial orgs hit in 2025, with widespread OT misclassification as IT-only.
reactive · time-critical · 13-step checklist · 3 phases
Compromised Credentials
COMPROMISED CREDENTIALS
Trigger: Valid credentials in use by an unauthorized actor. No malware, no exploitation. 82% of 2025 detections were malware-free (CrowdStrike 2026 GTR).
Priority Actions: Identify credential source (infostealer, vishing +442%, ClickFix +563%, AiTM phishing, device code phishing, credential stuffing). Scope all systems the credential can access. Trace lateral movement timeline.
reactive · identity-based · 13-step checklist · 3 phases
C2 Beacon Found
C2 BEACON FOUND
Trigger: Confirmed command-and-control implant on a single host. The host you found it on is never the only one.
Priority Actions: Scope outward through credential access, lateral movement, and data staging. Identify the C2 protocol and infrastructure. Determine dwell time. The question is not "what is on this host" but "where else did they go from here."
reactive · single host confirmed · 12-step checklist · 3 phases
Business Email Compromise
BUSINESS EMAIL COMPROMISE
Trigger: Compromised mailbox or email-based fraud in progress. Phishing remains #1 initial access (35%, Talos Q1 2026). 76% of phishing cases escalate to BEC.
Priority Actions: Audit mailbox rules for external forwarding. Check for OAuth app consent grants. Assess financial fraud exposure. Delivery vectors evolving: ClickFix (+563%), vishing (+442%), device code phishing bypasses FIDO2.
reactive · identity + email · 13-step checklist · 3 phases
incident triage: tier 2 · common and growing
Edge Device Compromised
EDGE DEVICE COMPROMISED
Trigger: VPN, firewall, or web appliance exploited. 40% of China-nexus exploited vulns targeted edge devices. 42% exploited before public disclosure.
Priority Actions: The appliance is the foothold, not the target. Check for credential harvest, config dump, tunnel establishment, and pivot to internal systems. Covers FortiGate, Ivanti, PanOS, Cisco, Citrix, F5, SonicWall, SAP NetWeaver.
reactive · perimeter breach · 10-step checklist · 7 platform CVEs
Supply Chain Indicator
SUPPLY CHAIN INDICATOR
Trigger: Third-party compromise, SaaS OAuth abuse, or vendor software backdoored. Supply chain attacks quadrupled over 5 years.
Priority Actions: Assess exposure: shared credentials, OAuth tokens, API integrations, and how many environments the compromised vendor touches. Four subtypes: software supply chain, SaaS/OAuth, vendor credential, and hardware/firmware.
reactive · third-party · 10-step checklist · 4 supply chain subtypes
Data Exfiltration Detected
DATA EXFILTRATION DETECTED
Trigger: Outbound data movement found in proxy, DLP, or network telemetry.
Priority Actions: Reconstruct what left, how (HTTPS, DNS, cloud storage, code repo, USB), when it started, and whether the channel is still active. Work backward from the exfil point to the staging host to the initial compromise. Six exfil channel types covered.
reactive · data loss · 10-step checklist · 6 exfil channel types
SaaS Tenant Hijack
SAAS TENANT HIJACK / OAUTH PERSISTENCE
Trigger: The identity provider itself is compromised. Not a mailbox, not a user: the Okta tenant, the Entra ID directory, the entire identity plane.
Priority Actions: Terminate unauthorized admin sessions via token revocation. Enumerate rogue Enterprise Applications. Check for shadow federation trusts (backdoor IdPs). Audit Global Admin roles and cross-tenant sync. Rotate all signing certificates.
reactive · clock-stopping · 7-step checklist · IdP takeover · OAuth persistence · shadow federation
incident triage: tier 3 · specialized, high-impact
Living-off-the-Land Activity
LIVING-OFF-THE-LAND ACTIVITY
Trigger: Suspicious use of legitimate tools. No malware, no IOCs. Every artifact individually looks normal. The Volt Typhoon pattern.
Priority Actions: Confirmation requires behavioral sequencing, not signatures. Map LOLBin command chains against known actor playbooks. Detect RMM tool abuse. Differentiate legitimate admin activity from adversary tradecraft through timing, context, and sequence.
reactive · no IOCs · 10-step checklist · behavioral confirmation
Infostealer Infection
INFOSTEALER INFECTION
Trigger: Credential harvester detected on an endpoint or your credentials appeared on a dark web monitoring feed. 300K+ ChatGPT creds for sale in 2025 alone.
Priority Actions: Assess what was stolen: browser passwords, session cookies, SSH keys, cloud tokens. Map every system where each stolen credential is valid. Check for BYOD/personal device as the infection source feeding the IAB pipeline.
reactive · credential exposure · 11-step checklist · blast radius assessment
Insider Threat
INSIDER THREAT
Trigger: Authorized user exhibiting anomalous access patterns. No exploitation, no malware, no IOCs. Detection is entirely behavioral baseline deviation.
Priority Actions: Establish 60-90 day access baseline. Check for bulk data collection, personal channel exfiltration, and access outside role. HR/legal coordination mandatory before investigation. FAMOUS CHOLLIMA planted operatives represent a nation-state variant.
reactive or proactive · behavioral only · 10-step checklist · legal coordination required