SOCLIFE
SOCLIFE

Evidence-led security analysis

Published knowledge

Search SOC//LIFE

SOC analysis

Hunts

Wider-environment searches that scope users, applications, sessions, and follow-on behavior.

Reviewed work

Hunt questions

See the hunt goal, blast-radius pivots, conclusion, and next action.

  • HuntHUNT-001

    Hunt cloud activity after device-code sign-in

    Find other users who completed device-code sign-ins and then showed cloud activity through the same or similarly unexpected applications.

    The wider search found suspicious post-sign-in activity, but missing session identifiers prevented confirmation that the same behavior affected additional users.

  • HuntHUNT-002

    Hunt for ClickFix Exposure Across Endpoints

    Determine whether other users or devices were exposed to the same ClickFix entry path, incident infrastructure, or post-compromise behavior.

    The cited Huntress intrusion demonstrably expanded across 11 hosts. This supports the wider-compromise hypothesis for that source incident, while the reusable queries remain unexecuted against any SOC//LIFE or customer environment.

  • HuntHUNT-003

    Hunt for AiTM Exposure and Session Replay Across Identities

    A SharePoint-style AiTM campaign may have expanded beyond the initially identified identity through additional recipients who clicked, replayed cloud sessions, mailbox concealment, and follow-on phishing from compromised trusted accounts.

    Microsoft's January 2026 source directly documents the recipient-to-click-to-session-to-mailbox-to-follow-on-phishing pattern and additional compromises. The reusable hunt queries remain unexecuted against any SOC//LIFE or customer environment.

  • HuntHUNT-004

    Hunt for Illicit OAuth Consent and Persistent Cloud Access

    One or more users may have authorized an unexpected OAuth application that retained access to Microsoft 365 resources through delegated permissions.

    Microsoft documentation establishes that illicit consent grants can provide account-level cloud access and that password reset or MFA alone does not remediate the external application grant. The reusable hunt queries remain unexecuted against any SOC//LIFE or customer environment.

  • HuntHUNT-005

    Hunt for Smart-Contract C2 Resolution Across Endpoints

    Endpoints or browsers in the environment may be contacting public blockchain RPC infrastructure to resolve attacker-controlled next-stage domains, payloads, or C2 configuration.

    Multiple 2026 first-party investigations independently document public blockchain RPC services and smart contracts being used to resolve or host attacker-controlled next-stage information. The SOC//LIFE hunt is a publication-safe defensive pattern and has not been executed against a customer environment.

  • HuntHUNT-006

    Hunt for Device Code Abuse Across Risky Identities

    One or more medium/high risk identities may have completed attacker-controlled device-code authentication and then been used for token-backed cloud access.

    Microsoft documented large-scale AI-enabled device-code phishing in April 2026 and later observed device-code phishing in July 2026 CaptiveCrunch operations. The SOC//LIFE hunt converts those source-backed behaviors into a risk-first identity workflow and has not been executed against a customer environment.

  • HuntHUNT-007

    Hunt for SSPR Abuse and Cloud Control-Plane Expansion

    One or more users may have been socially engineered through SSPR, had authentication methods replaced, and then been used to enumerate and expand through Microsoft 365 and Azure control planes.

    Microsoft's 2026 Storm-2949 investigation directly documents SSPR social engineering, attacker-controlled Authenticator registration, Graph enumeration, attempted service-principal persistence, Microsoft 365 data theft, and Azure control-plane expansion. The SOC//LIFE hunt converts those source-backed behaviors into a reusable workflow and has not been executed against a customer environment.

  • HuntHUNT-008

    Hunt for Helpdesk Impersonation to Remote Access and Exfiltration

    One or more users may have been socially engineered by external Teams helpdesk personas into launching legitimate remote-support tooling, after which human-operated intrusion activity expanded into internal remote management and data exfiltration.

    Microsoft's April 2026 report documents the full chain from cross-tenant Teams helpdesk impersonation through Quick Assist, shell/recon, trusted application abuse, WinRM, Level RMM, and Rclone exfiltration. A separate March 2026 Teams support-call case reinforces the ongoing abuse of this access path. The SOC//LIFE hunt is publication-safe and has not been executed against a customer environment.

  • HuntHUNT-009

    Hunt for Photo ZIP Node JS Persistence Across Endpoints

    One or more endpoints may have executed photo-masquerading shortcuts that staged a Node JS implant, weakened endpoint protection, established dual registry persistence, and maintained command-and-control through user-space payloads.

    Microsoft directly documented the active two-wave campaign, its evolving PowerShell stage, user-space Node JS implant, Defender exclusions, dual Run/RunOnce persistence, and non-standard C2. This hunt has not been executed against a customer environment.

  • HuntHUNT-010

    Hunt for MacSync Collection and Chunked Exfiltration

    One or more managed Macs may have executed a ClickFix-style shell chain that collected credentials and sensitive files, staged them under temporary paths, and exfiltrated chunked data through rotating web infrastructure.

    Microsoft directly documented shell retrieval, AppleScript-assisted activity, credential and file collection, temporary staging, chunked curl exfiltration, and cleanup. RST Cloud independently documented fast infrastructure rotation and recurring request-shape traits. This hunt has not been executed against a customer environment.