AIaaS · Attack Infrastructure as a Service · CISO-grade threat manifesto · dark HUD cover · 44 threat actors deliberately share 1 cloud-hosted IP address · a market with 2,097 sellers · 480,897 units of inventory · zero compliance frameworks that cover it · 7 laws of AIaaS chips at bottom

The AIaaS Doctrine · Attack Infrastructure as a Service · What 1.86 Million Cloud-Hosted IOCs Tell Every CISO

// THE AIaaS DOCTRINE · A CISO-GRADE THREAT MANIFESTO · TLP:CLEAR

Attack Infrastructure as a Service: The Market Your CISO Playbook Has Never Named

44 named threat actors deliberately share one single cloud-hosted IP address. That is not a bulletproof hosting anomaly. That is a Fortune-500 hyperscaler. And your allow-list trusts it.

This document coins a term, indicts three authorities the security industry still trusts, and gives you a manifesto to defend against a market that already has 2,097 sellers, 480,897 units of inventory, and zero compliance frameworks that cover it.

Read time · 22 minutes · Empirical basis · 1.86M IOC↔cloud attributions across 60 providers, 10 provider groups, 603 regions, 16 years · Author · HackForLab Cyber Threat Intelligence Research

01 · The Money Quote

“On our worst offender, 44 named threat actors — spanning nation-state clusters, commodity malware families, and independent C2 operators — have all used the same single IP address. Not sequentially. Not by accident. Because that IP sits inside a hyperscaler that runs a rental-by-the-hour billing model your SOC’s allow-list treats as trusted.”
— HackForLab Cohesive Infrastructure Analysis, 2026

This is the finding that reframes every cloud-egress rule your SIEM ships with. If a single IP address routinely hosts dozens of unrelated threat groups, then IP-level blocking is not a defensive control — it is a placebo. And IP-level allow-listing is worse: it is a target selector.

5,884IPs hosting 2+ actors
151IPs hosting 5+ actors
44Max actors · single IP
104Max actors · single CIDR

These are not outliers. They are the expected shape of shared attack infrastructure when adversaries buy from the same rental pools as their targets.

02 · Definition: What AIaaS Actually Is

We define Attack Infrastructure as a Service (AIaaS) as any adversary operation model that satisfies the following five elements:

The AIaaS 5-Element Checklist

  1. Rental, not ownership. The attacker does not own the infrastructure. They rent it, hijack it, or abuse a free tier of it — the same billing model any legitimate tenant uses.
  2. Multi-tenant reuse. The same IP, CIDR, or account resource is used by multiple unrelated adversaries — often within days of each other — because the provider does not (and often cannot) attribute abuse per tenant.
  3. Sub-hour provisioning. New infrastructure can be spun up in minutes. The attacker’s Time-To-Provision is orders of magnitude faster than any defender’s Time-To-Detect.
  4. Deniable geolocation. The attacker can present as any region the provider serves. Traditional geo-IP indicators lose signal.
  5. Blends with legitimate egress. Traffic to the infrastructure looks identical to the workload traffic your own developers, marketing team, and analytics stack generate every minute.

If your adversary operates against you and satisfies 4 or 5 of these — you are being AIaaS’d. Whether you can see it or not.

03 · The Three Broken Clocks

The most damning finding in our data is not any single number. It is the cadence mismatch. Three clocks are ticking against each other, and only one of them is on your side. The other two belong to the attacker and to your vendors.

// ATTACKER CLOCK
~ 8 hours
Median time to provision + weaponise a new cloud CIDR. Sub-hour with automation.
// COMMODITY FEED CLOCK
~ 24 hours
Typical batch cadence of most commercial threat feeds you subscribe to.
// YOUR SIEM CLOCK
7 – 30 days
Median cycle from “new rule proposed” to “rule live in production SIEM/EDR.”

The math does not work. By the time your detection engineer has authored, peer-reviewed, and shipped a rule for a new attacker CIDR, the attacker has rotated through 90 more. Every static IOC list you subscribe to is a lagging indicator, priced as a leading one.

The empirical proof from our data: in the last 180 days, 97.7% of persistent adversaries changed their provider mix at least once. Static enrichment is defending against a target that no longer exists.

04 · The Seven Laws of AIaaS

Every one of the following laws is derived from the same underlying dataset: 1,858,945 IOC↔cloud attributions across 60 providers, 10 functional groups, 2,097 distinct real threat actors, and 603 regions. Every finding is empirical. Every takeaway is what a CISO should walk into the boardroom with.

// LAW 01

The Law of Shared Tenancy

The same infrastructure — down to the individual IP address — is routinely reused by multiple unrelated threat actors. This is not accidental. It is the structural consequence of a rental model that does not attribute abuse per-tenant.

Finding: 5,884 single IPs host 2+ distinct real actors. 151 host 5+. 16 host 10+. The extreme case: 44 named actors on one IP. At CIDR level: 104 actors on a single /24-class CIDR.
CISO takeaway: IP-level blocking is a ritual from an era that ended around 2015. If your SOAR still opens a ticket per malicious IP, you are running a helpdesk, not a defence.
What the platform does: Cohesive-Infrastructure detection surfaces every IP or CIDR where 2+ real actors converge — the strongest possible provider-level bulletproof-tell without waiting for a takedown.
// LAW 02

The Law of Group Preference

Adversaries do not distribute uniformly across the cloud. They cluster. And they cluster differently by adversary type. Command-and-control loves large-tenant hyperscaler groups. Info-stealer campaigns prefer regional VPS constellations. SaaS abuse (using legitimate hosted services as C2 or exfil) is a rapidly-growing pattern that legacy detection cannot see.

Finding: In the cloud functional group alone: 837k C2 attributions from 193 actors, 394k malware attributions from 1,394 actors. In SaaS-abused-as-C2: 76k attributions from 45 distinct actors. In CDN-tier: 62k C2 attributions from just 16 concentrated actors.
CISO takeaway: Your allow-list of “trusted cloud egress” is a target-selector for adversaries. If your web-proxy category rule reads “allow *.hyperscaler-a.com”, you have just allow-listed 837,000 C2 attributions.
What the platform does: Provider-group × adversary-type heatmap. Every provider group, every adversary type, current concentration, current actor list — no allow-list stays trusted longer than the underlying data supports.
// LAW 03

The Law of Actor Mobility

Mature threat actors do not commit to a provider. They hedge. They operate across multiple providers, multiple functional groups, and multiple regions concurrently. The most mobile operators run infrastructure that resembles a global corporation more than a criminal enterprise.

Finding: 41% of 2,097 tracked real actors (867 in total) operate across 2+ providers. 209 span 5+ providers. 74 span 10+. Peak mobility: one single actor uses 31 providers, 7 functional groups, and 132 regions concurrently.
CISO takeaway: “We block ranges from Provider X” is a false comfort. Nearly half your named adversaries are already on Provider Y. And Z. And W.
What the platform does: Per-actor provider-span index + migration timeline. Every actor’s current infra footprint, live.
// LAW 04

The Law of Deliberate Diversification

When you measure the concentration of an actor’s infrastructure (the Herfindahl-Hirschman index adapted to provider count), the overwhelming majority score diversified. This is not opportunism. Mature adversaries deliberately fragment their infrastructure across providers to survive takedowns, sanctions, and detection cycles.

Finding: Of persistent actors with 20+ observations, 76% score as diversified (HHI < 0.5). Median HHI = 0.293. Only 8% are concentrated on one dominant provider. The typical mature actor’s infrastructure looks like a portfolio, not a homestead.
CISO takeaway: Actors design for your takedown. A takedown at Provider X is a marketing event, not a disruption. The infrastructure at Provider Y was already warm before you filed the abuse report.
What the platform does: Per-actor diversification score. Low HHI = mature multi-provider operation = takedown-resistant. High HHI = disposable single-provider tenant = short-lived campaign.
// LAW 05

The Law of CIDR Weaponisation

Most attack infrastructure does not live on lonely, isolated IPs. It lives inside CIDRs that host multiple attacker IPs at once. When we aggregate our attribution data to the CIDR level, the concentration is staggering.

Finding: Of 22,251 attacker-touching CIDRs, 1.26 million attributions (68% of the entire dataset) live on CIDRs that host 2+ distinct real actors. 586 CIDRs host 10+ actors each. Max: 104 actors on a single CIDR. Max attribution volume on one CIDR: 86,021 events.
CISO takeaway: Blocking at IP level scales to nowhere. Blocking at CIDR level, informed by attribution density, scales to 68% coverage overnight. This is the single most cost-effective control decision in the whole document.
What the platform does: CIDR-density enforcement feeds. “Any CIDR with distinct_actors ≥ 3” is a defensible block list. Refreshed continuously.
// LAW 06

The Law of Migration Cadence

Adversaries do not settle. They churn. Every persistent adversary migrates their infrastructure mix on a cadence measured in weeks — not months, not quarters. Any defence sourced from monthly threat reports is defending against last month’s infrastructure.

Finding: Of adversaries active in 3+ of the last 6 months, 97.7% changed their provider mix in that window. Peak: one actor churned through 7 distinct provider combinations in 6 months.
CISO takeaway: Your quarterly board-report metric of “top 10 adversaries blocked” is measuring a moving target with a stopped clock.
What the platform does: Actor-Migration Timeline — stacked-area per adversary showing provider mix month-over-month. When an actor pivots, you see it inside the same cycle they pivoted in.
// LAW 07

The Law of Freshness

Fresh attacker infrastructure — CIDRs first seen within the last 90 days — is disproportionately weaponised, disproportionately active, and disproportionately invisible to detection stacks tuned on historical signatures.

Finding: 623 CIDRs first seen in the last 90 days are already attributed to real actors. 8,429 attacker CIDRs were active in the last 7 days alone. The gap between “provisioned” and “weaponised” is measured in days, sometimes hours.
CISO takeaway: Your “trusted cloud egress” allow-list has a 90-day rot rate. Anything you approved a quarter ago is stale enough to hide an active adversary today.
What the platform does: Fresh-CIDR Feed — every CIDR first seen in the last N days that already correlates with real-actor activity. The one feed detection engineers wish they had.

05 · The AIaaS Menu (Anonymised Attacker Catalog)

Attackers face an attacker economy. That economy has a menu. Below is the menu, reconstructed from what the data shows about which functional-tier of infrastructure attackers actually rent, how many IPs are on offer at each tier, and how many distinct threat actors have been observed operating from each tier. All provider identities are anonymised to functional labels. No brand names appear anywhere on this page.

// THE AIaaS RENTAL CATALOG · 2026 SNAPSHOT · FUNCTIONAL LABELS ONLY

Tier What it is Inventory · IPs Sellers · Actors Typical unit economics
Hyperscaler Cloud (Group A) Large multi-region compute tenancy. Blends with 90%+ of legitimate enterprise egress. ~388,100 1,981 $3 – $15 per VPS-month · sub-minute provisioning · card-only KYC in most regions
SaaS-Abused-as-C2 (Group B) Legitimate hosted services — collaboration, storage, dev-tooling — repurposed for command channels or exfiltration. ~20,420 232 $0 (free tier) – $99 per seat-month · disposable email registration · zero endpoint deployment
CDN Edge (Group C) Edge points of presence used for domain fronting, C2 relay, or high-throughput staging. ~62,864 243 Free tier + per-request pricing · geographic ubiquity built in
VPN / Anonymiser Constellation (Group D) Bulk-purchased VPN endpoints used as attack egress or as scan pivots. ~1,911 35 ~$5 per IP-month wholesale · dominant single operator abusing at scale
Bot-Grade Residential (Group E) Compromised or rented residential / mobile IP pools. ~3,286 5 Per-request pricing · concentrated operators · resembles a market monopoly

Inventory and seller counts are drawn from HackForLab’s IOC↔cloud attribution corpus (n = 1.86M). Tier labels are functional groupings; no brand identity is disclosed anywhere in this document. Unit-economics ranges reflect open-market street pricing signals aggregated across underground forums, not any specific offering.

Read this menu as an economist would: attackers face a rental market with 60 named suppliers, 480,897 units of inventory, and near-zero barriers to entry. Their per-attack cost is measured in dollars. Your per-incident cost is measured in millions. The gross margins of the adversary economy are the highest in any market that has ever existed. And the market is currently entirely unregulated.

06 · The Triple Indictment

AIaaS is not a technical failure. It is a governance failure. Three authorities that every CISO already trusts have failed to notice, name, or price the problem. Each of these is a blind spot large enough to hide a threat-actor economy inside.

Indictment 1 · Compliance frameworks are silent

Search the text of ISO 27001, SOC 2, NIST CSF 2.0, PCI DSS 4.0, HIPAA Security Rule, DORA, NIS2, and the CISA CIRCIA rulebook for a control that treats “traffic to a legitimate cloud provider that also hosts adversary infrastructure” as a governance concern.

  • No control catalog treats shared-tenancy attribution as a risk to inventory.
  • No auditor asks: “How many of your allow-listed egress targets currently host multiple named threat actors?”
  • No control-owner sign-off has ever depended on the answer.

Consequence: Every compliance program in the world has a documented, audited, and signed-off blind spot with 1.86 million IOCs sitting inside it. Every attestation is technically true and functionally worthless.

Indictment 2 · Default detection stacks are structurally blind

The default detection content shipped by every major EDR, MDR, SASE, CNAPP, XDR, CIEM, and next-gen-SIEM vendor makes one assumption in common: egress to a mainstream cloud provider is benign.

  • Their rules do not correlate destination IP to multi-actor CIDR density.
  • Their categorisation feeds do not distinguish between freshly-provisioned attacker-touching CIDRs and legitimate corporate egress to the same provider.
  • Their SOAR playbooks route “egress to cloud” through a low-severity queue that never gets read.

Consequence: The default detection stack you paid seven figures for cannot see AIaaS. It was not designed to. The gap is architectural, not tunable.

Indictment 3 · Cyber-insurance underwriting is mispriced

The pricing model most cyber-insurance carriers still use assumes attacker infrastructure lives on bulletproof hosting — a specialised, marginal market outside the insured’s own provider footprint. Our data proves that model false.

  • 21.2% of all IP IOCs live inside mainstream cloud / hosted infrastructure — the same infrastructure the insured also depends on.
  • Carriers charging bulletproof-era premiums are underwriting a modern-cloud risk profile.
  • First carriers to reprice on empirical AIaaS exposure will move the market. Their competitors will subsidise the difference.

Consequence: The cyber-insurance actuarial model is a decade behind. When the correction arrives — and it will, driven by the first big AIaaS-attributable settlement — every insured who cannot demonstrate cloud-attribution instrumentation will pay for it.

07 · What the Industry Cannot See

Every major security-product category ships default detection that fails on AIaaS. Below is a category-by-category summary of the gap. No vendor is named. The failure is structural to the category, not to any individual product within it.

Product Category What it detects Why it cannot see AIaaS
EDR / XDR Endpoint process behaviour, memory anomalies, endpoint-to-endpoint lateral movement. Egress to cloud provider IP looks like a browser fetch. Endpoint has no visibility into who else uses that IP.
MDR / Managed SOC Analyst-triaged detections from the underlying EDR/SIEM. Inherits the blind spot of the underlying stack. Analyst has no cross-tenant attribution.
SASE / Secure Web Gateway URL categorisation, TLS inspection, category-based egress control. Cloud provider domains are categorised as trusted. Category does not decompose to CIDR density.
CNAPP / CSPM Cloud posture — misconfigurations, exposed buckets, IAM drift. Concerned with your own tenancy. Blind to what other tenants of your provider are doing.
CIEM Identity entitlements, principal-permission drift. Same posture-inward focus. Off-tenancy attacker signal not in scope.
Next-gen SIEM Log correlation with configurable rules. Rules are only as good as their enrichment. Without cloud-attribution enrichment, cloud IP is a black-box string.
Commodity Threat Feeds IP / domain / hash lists refreshed on batch cadence. 24-hour batch cadence vs 8-hour attacker cycle. Structurally behind.

Which category solves AIaaS? None of the above alone. The solution is a fourth-generation layer: attribution-first threat intelligence, aggregated at CIDR level, correlated with actor identity, refreshed at provider-rotation cadence, and delivered as enrichment into the tools you already own. That layer is the entire point of a specialised platform like HuntIntel.

08 · The AIaaS Scorecard · Are You Exposed?

Ten questions. One point per Yes. Score honestly. Nobody outside your organisation will see the number. The whole point is what you do with it internally, on Monday morning.

The 10-Question AIaaS Self-Assessment

  1. Does your SIEM enrich outbound cloud-destination IPs with which other threat actors have been seen on the same CIDR in the last 90 days?
  2. Does your egress-filtering allow-list include whole cloud-provider ranges as “trusted”, with no per-CIDR review cycle?
  3. Can your SOC show, in one query, every internal host that has talked to a CIDR hosting 2+ distinct named adversaries in the last 30 days?
  4. Does your threat-intel program track each named adversary’s provider mix and alert when it changes month-over-month?
  5. Do you have a fresh-CIDR feed — CIDRs first seen weaponised in the last 30 days — plugged into a live block or alert list?
  6. Are your third-party-risk questionnaires asking your critical vendors about their cloud-attribution instrumentation?
  7. Does your cyber-insurance renewal package demonstrate AIaaS-aware controls to the underwriter?
  8. When your SOAR playbook fires on “egress to a cloud provider,” does it escalate based on CIDR density, or does it route to a low-severity queue?
  9. Do you have quarterly threat-model reviews that treat “the cloud we use is also the cloud our adversaries use” as an explicit assumption?
  10. Would your board’s next-quarter cybersecurity update be able to explain the phrase “Attack Infrastructure as a Service” and cite a concrete finding from your own logs?
0 – 2 · CRITICAL — You are AIaaS-blind. Assume active adversary presence on your cloud egress. Start with Law 05.
3 – 5 · EXPOSED — Legacy defence in place. AIaaS is the visible gap. Prioritise Laws 01 + 05 + 07.
6 – 8 · AWARE — Instrumented but not weaponised. Convert insight to enforcement.
9 – 10 · ADVANCED — You are in the top 3% of enterprises defending against modern attack infrastructure. Share this document with a peer.

09 · Three Hunt Queries to Run Tomorrow Morning

Every one of the queries below is written in vendor-agnostic pseudo-SQL. Translate to your SIEM’s query language. None of them require Sigma. All of them assume your outbound-connection log contains a destination IP and that you can join it against a cloud-attribution enrichment source.

// HUNT 01 · MULTI-ACTOR CIDR EGRESS · LAW 01 + LAW 05
SELECT src_host, dst_cidr, distinct_actors_on_cidr, connection_count
FROM outbound_connections c
JOIN cloud_attribution_enrichment e
  ON contains_cidr(e.cidr, c.dst_ip)
WHERE e.distinct_actors_on_cidr >= 3
  AND c.event_time >= now() - interval '30 days'
GROUP BY src_host, dst_cidr, distinct_actors_on_cidr
ORDER BY connection_count DESC
LIMIT 200;

# Interpretation: any internal host with a session to a CIDR hosting
# 3+ named threat actors is a high-priority triage. This is Law 01 + Law 05
# operationalised in one query. Expect to find at least one hit in most enterprises.
// HUNT 02 · FRESH-CIDR EGRESS · LAW 07
SELECT src_host, dst_cidr, first_seen_attributed, adversary_type_top
FROM outbound_connections c
JOIN cloud_attribution_enrichment e
  ON contains_cidr(e.cidr, c.dst_ip)
WHERE e.first_seen_attributed >= now() - interval '30 days'
  AND e.real_actor_count >= 1
  AND c.event_time >= now() - interval '7 days'
ORDER BY e.first_seen_attributed DESC
LIMIT 200;

# Interpretation: any internal host talking to an attacker-touching CIDR
# that entered attribution within the last 30 days. This closes the gap
# that commodity feeds and static allow-lists cannot see.
// HUNT 03 · PROVIDER-GROUP MIGRATION EVENT · LAW 06
-- Track a specific adversary's provider-group footprint across two windows
WITH last_30 AS (
  SELECT actor_norm, array_agg(DISTINCT provider_group) g30
  FROM cloud_attribution
  WHERE detection_date >= now() - interval '30 days'
    AND is_real_actor
  GROUP BY actor_norm
),
prior_30 AS (
  SELECT actor_norm, array_agg(DISTINCT provider_group) gprior
  FROM cloud_attribution
  WHERE detection_date BETWEEN now() - interval '60 days' AND now() - interval '30 days'
    AND is_real_actor
  GROUP BY actor_norm
)
SELECT l.actor_norm, l.g30 AS current_groups, p.gprior AS prior_groups
FROM last_30 l JOIN prior_30 p USING (actor_norm)
WHERE l.g30 <> p.gprior;

# Interpretation: any adversary whose functional-group mix has changed in
# the last 30 days. Migration is a live intel signal, not a historical curiosity.

10 · The 7-Principle AIaaS Defence Doctrine

If you carry one artifact from this document into next quarter’s planning cycle, make it this list. Print it. Pin it. Argue it in your architecture review board. Every principle inverts a legacy assumption that AIaaS has invalidated.

The Doctrine · 7 Principles

  1. Assume shared tenancy. Any IP your workload egresses to is likely shared with an adversary. Design controls that assume this by default.
  2. Enforce at CIDR density, not IP identity. IP-level enforcement is a helpdesk workflow. CIDR-density enforcement is a control.
  3. Trust no allow-list older than 90 days. Every allow-list has a rot rate. Bake in a mandatory review cycle at 90 days or shorter.
  4. Instrument for freshness. A newly-attributed CIDR is more dangerous than an old one. Weight your detection accordingly.
  5. Track adversaries by portfolio, not by IP. An actor’s infrastructure is a portfolio. Understand the shape of the portfolio before you attempt to disrupt any single position in it.
  6. Buy attribution, not lists. Commodity IP lists are a rearview mirror. Attribution intelligence is a windshield.
  7. Report AIaaS exposure quarterly to the board. If your board briefing does not include a slide on AIaaS by end of Q4 2026, you are the last CISO in your peer group not covering it.

11 · Where HuntIntel Fits · Mapped to the 7 Laws

Every law surfaced above corresponds to a capability inside HuntIntel — the HackForLab operator console at huntintel.hackforlab.com. This is not marketing. It is the point-by-point mapping between an empirical finding and the tool that lets you operationalise the finding tomorrow.

Law Empirical Finding HuntIntel Capability
Law 01 Shared Tenancy 44 actors · 1 IP · 104 actors · 1 CIDR Cohesive-Infrastructure view — every IP/CIDR ranked by distinct-actor density.
Law 02 Group Preference C2 concentration in hyperscaler; SaaS-abused-as-C2 pattern Provider-group × adversary-type heatmap. Sankey ribbons from adversary type to provider group.
Law 03 Actor Mobility 41% multi-provider; one actor · 31 providers Per-actor fingerprint — provider span, region span, service span, live.
Law 04 Diversification 76% of persistent actors are diversified (HHI < 0.5) Actor-diversity score + provider-mix concentration index.
Law 05 CIDR Weaponisation 68% of all attributions on multi-actor CIDRs CIDR-density feed for enforcement + fresh-CIDR watch.
Law 06 Migration Cadence 97.7% of persistent actors migrated in 6 months Actor-Migration Timeline (stacked-area, month-over-month).
Law 07 Freshness 8,429 attacker CIDRs active last week Fresh-CIDR Feed (configurable N-day window) for direct SOAR consumption.

Test the AIaaS thesis against your own egress logs

HuntIntel is the operator console the HackForLab CTI team uses to build every finding in this document. Enrich your egress. Query the cohesive-IP feed. See your adversaries’ provider portfolios. Try it today.

Open the Operator Console →

12 · Frequently Asked (CISO) Questions

Isn’t this just another way of saying “attackers use the cloud”?

The observation “attackers use cloud” is over a decade old and offers no operational leverage. AIaaS is different: it is a market-structure claim with quantitative evidence and specific controls. The insight is not that adversaries use cloud — it is that their infrastructure is shared, mobile, diversified, and rotates faster than any commodity threat feed cycle. That converts a truism into a defensible boardroom argument.

Doesn’t Zero Trust already solve this?

Zero Trust solves identity-plane trust. AIaaS is a network-plane and attribution-plane problem. A Zero Trust architecture will still route your workload’s authenticated egress through a proxy that trusts cloud provider destinations by category. Zero Trust is a necessary but insufficient condition for AIaaS defence.

We already have a threat-intelligence subscription. Isn’t this covered?

Commodity threat intelligence ships IP / hash / domain lists on a batch cadence. It does not ship attribution density at CIDR level, actor-portfolio migration, or freshness signals at the granularity that AIaaS demands. The gap is not in your subscription. It is in the product category itself.

Can I detect AIaaS without a specialised platform?

You can approximate it. You will need: (a) a cloud-attribution enrichment source that maps IP → CIDR → provider-group; (b) an actor-attribution corpus large enough to compute density statistics; (c) a refresh cadence that beats the 8-hour attacker cycle. If you can source all three internally, you can build it. If not, use a platform that already has.

What is the single most important control we could implement this quarter?

Enforce Law 05: block or alert on egress to any CIDR that hosts 3+ distinct named adversaries in a rolling 90-day window. This one control converts 68% of the entire empirical dataset into enforcement coverage. No other single decision offers comparable leverage.

Will this generate false positives?

The false-positive rate depends on your industry, your workload mix, and how aggressively you tune the actor-count threshold. In the enterprises we work with, starting at “3+ distinct real actors on a CIDR in 90 days” produces a signal set small enough for human review and dense enough to surface actionable findings. Tune from there.

Is HuntIntel the only source of this data?

HuntIntel is the source we operate. Whether you use us or build it in-house, the doctrine is what matters. If you are a CISO reading this and you build the capability internally, we consider that a win for the industry.

Where does this doctrine go from here?

Future documents in this series will drill into each of the seven laws individually with dedicated hunt guides, sample dashboards, and case-study callouts from our attribution corpus. Subscribe to the HackForLab CTI feed (link at bottom of page) or bookmark huntintel.hackforlab.com for the operator surface.

13 · Close

AIaaS is not a warning shot. It is an already-established, empirically-measured, industry-wide market with 2,097 sellers, 480,897 units of inventory, and no regulator. Every security program that does not name this market and instrument against it is running yesterday’s playbook against tomorrow’s attackers.

The industry’s next taxonomy war is not about frameworks. It is about who names the problem first and who arms defenders for it. This document is HackForLab’s stake in that ground.

Cite this document as: HackForLab CTI Research. “The AIaaS Doctrine: Attack Infrastructure as a Service.” 2026. huntintel.hackforlab.com.

Core Working Areas :- Threat Intelligence, Digital Forensics, Incident Response, Fraud Investigation, Web Application Security Technical Certifications :- Computer Hacking Forensics Investigator | Certified Ethical Hacker | Certified Cyber crime investigator | Certified Professional Hacker | Certified Professional Forensics Analyst | Redhat certified Engineer | Cisco Certified Network Associates | Certified Firewall Solutions | Certified Network Monitoring Solution | Certified Proxy Solutions

Leave a Reply

Your email address will not be published. Required fields are marked *

Enter Captcha Here : *

Reload Image