The TaHiTI Investigation Abstract: Turning Threat Intelligence Into Targeted Hunts
Part 2 of the TaHiTI series. The investigation abstract is the Phase-I artefact that converts a raw threat-intelligence trigger into an executable hunt. This walkthrough covers all five components of the abstract, the five characteristics of a good hypothesis (per the official FI-ISAC methodology), the three anti-patterns that derail hunt programs, and three worked examples that convert this week’s live threat intelligence into methodology-faithful abstracts.
Weekly Threat Advisory: Framework-C2 Surge + Emerging Supply-Chain Wave (Jul 27 – Aug 2, 2026)
54,763 unique indicators across 107 tracked clusters this cycle. Dominant signal: framework-C2 infrastructure surge with 25+ concentrated /24 subnet anchors. Emerging supply-chain wave — fake npm packages, fake installers, developer-ecosystem targeting. macOS malware surge across three concurrent families. Three ransomware operators active. Iranian-linked APT clusters continue. Full ATT&CK-per-tactic pressure roll-up, four production-ready Sigma rules, subnet anchors, top IOCs per type.
Stop Searching, Start Hunting: A TaHiTI Hunt-Program Walkthrough Against This Week’s Threat Surface
TaHiTI (Targeted Hunting integrating Threat Intelligence) is the structured, hypothesis-driven hunting framework developed by the Dutch Financial ISAC. Part 1 of an 8-part series: the framework in full depth, the ABLE hypothesis quality standard, hunt backlog engineering, and a worked example that converts this week’s live threat intelligence into five executable hunt hypotheses — one taken end-to-end from hypothesis to Sigma rule.
Weekly Threat Advisory: APT Storm — 25 Clusters Active, Polymorphic Loader Surge, ICS/OT Threat Surface (Jul 20-26, 2026)
77,118 unique IOCs across 155 clusters this cycle. 25 attributed APT clusters ran concurrently — the widest APT footprint observed year-to-date. Two loader families produced ~15,000 unique hashes combined (polymorphic-build-farm signal). ICS/OT threat surfaced — PLC-targeted exploitation campaign with three concentrated subnet anchors. DPRK-adjacent activity double-tracked (cryptocurrency-focus + IT-worker infiltration). Russian-aligned and Middle East regional operations active. Novel SVG-embedded script delivery vector. Full ATT&CK-per-tactic pressure roll-up, four production-ready Sigma rules, subnet anchors, top IOCs per indicator type.
Weekly Threat Advisory: Intel Briefing — Polygon-Based C2, 4 Chinese-Aligned APTs, 20+ Ransomware Families (Jul 13-19, 2026)
59,935 unique IOCs across 116 clusters this cycle. Polygon-based C2 surfaced (314 IOCs, novel blockchain-resolved command channel — following the TON pattern). Four Chinese-aligned APT clusters active in parallel (APT-C-60 with 121 IOCs full 5-type spread, UAT-11795, APT-C-35, APT-Q-27). 20+ ransomware families concurrent (RAWorld 213, Trigona 115, Qilin 56, MedusaLocker, Medusa, Fog, WORLDLEAKS, Spirals, Sorry + more). Package-registry supply-chain double strike (game-cheat + Go module). macOS threat layer matured (AppleScript infostealer + macOS-focused stealer + ClickFix variants). TencShell C2 operator with 4 subnet anchors (16 IPs concentrated). Full ATT&CK mapping per cluster, subnet anchors, top 15 IOCs per indicator type, four production-ready Sigma rules.









