TaHiTI Part 2 · The Investigation Abstract · turning threat intelligence into targeted hunts · emerald + navy palette · HackForLab cyber threat intelligence · hunt methodology
0 24
Posted in Cyber Threat

The TaHiTI Investigation Abstract: Turning Threat Intelligence Into Targeted Hunts

Part 2 of the TaHiTI series. The investigation abstract is the Phase-I artefact that converts a raw threat-intelligence trigger into an executable hunt. This walkthrough covers all five components of the abstract, the five characteristics of a good hypothesis (per the official FI-ISAC methodology), the three anti-patterns that derail hunt programs, and three worked examples that convert this week’s live threat intelligence into methodology-faithful abstracts.

0 34
Posted in Threat Intelligence

Weekly Threat Advisory: Framework-C2 Surge + Emerging Supply-Chain Wave (Jul 27 – Aug 2, 2026)

54,763 unique indicators across 107 tracked clusters this cycle. Dominant signal: framework-C2 infrastructure surge with 25+ concentrated /24 subnet anchors. Emerging supply-chain wave — fake npm packages, fake installers, developer-ecosystem targeting. macOS malware surge across three concurrent families. Three ransomware operators active. Iranian-linked APT clusters continue. Full ATT&CK-per-tactic pressure roll-up, four production-ready Sigma rules, subnet anchors, top IOCs per type.

TaHiTI · Targeted Hunting integrating Threat Intelligence · Stop searching, start hunting · opening post of a weekly TaHiTI series · HackForLab cyber threat intelligence · hunt methodology cover
0 45
Posted in Cyber Threat

Stop Searching, Start Hunting: A TaHiTI Hunt-Program Walkthrough Against This Week’s Threat Surface

TaHiTI (Targeted Hunting integrating Threat Intelligence) is the structured, hypothesis-driven hunting framework developed by the Dutch Financial ISAC. Part 1 of an 8-part series: the framework in full depth, the ABLE hypothesis quality standard, hunt backlog engineering, and a worked example that converts this week’s live threat intelligence into five executable hunt hypotheses — one taken end-to-end from hypothesis to Sigma rule.

HackForLab Weekly Threat Advisory · Jul 20-26 2026 · APT Storm cover · sanitised v2 · deep charcoal + crimson + gold palette · 77,118 indicators · 155 clusters · 25 attributed APT clusters · category-based footprint chart (C2 infrastructure, malware activity, APT, botnet, phishing) · this-week defining signals (15,000 loader hashes, 3 ICS/OT anchor blocks, SVG new-delivery vector)
0 49
Posted in Threat Intelligence

Weekly Threat Advisory: APT Storm — 25 Clusters Active, Polymorphic Loader Surge, ICS/OT Threat Surface (Jul 20-26, 2026)

77,118 unique IOCs across 155 clusters this cycle. 25 attributed APT clusters ran concurrently — the widest APT footprint observed year-to-date. Two loader families produced ~15,000 unique hashes combined (polymorphic-build-farm signal). ICS/OT threat surfaced — PLC-targeted exploitation campaign with three concentrated subnet anchors. DPRK-adjacent activity double-tracked (cryptocurrency-focus + IT-worker infiltration). Russian-aligned and Middle East regional operations active. Novel SVG-embedded script delivery vector. Full ATT&CK-per-tactic pressure roll-up, four production-ready Sigma rules, subnet anchors, top IOCs per indicator type.

HackForLab Weekly Threat Advisory · Jul 13-19 2026 · Weekly Intelligence Briefing sanitised cover · deep charcoal + crimson + gold palette · 59,935 indicators · 116 clusters · 4 attributed APT clusters · 20+ ransomware families · category-based footprint chart · this-week defining signals: novel blockchain-resolved C2, attributed APT concurrent, ransomware family surge
0 330
Posted in Threat Intelligence

Weekly Threat Advisory: Intel Briefing — Polygon-Based C2, 4 Chinese-Aligned APTs, 20+ Ransomware Families (Jul 13-19, 2026)

59,935 unique IOCs across 116 clusters this cycle. Polygon-based C2 surfaced (314 IOCs, novel blockchain-resolved command channel — following the TON pattern). Four Chinese-aligned APT clusters active in parallel (APT-C-60 with 121 IOCs full 5-type spread, UAT-11795, APT-C-35, APT-Q-27). 20+ ransomware families concurrent (RAWorld 213, Trigona 115, Qilin 56, MedusaLocker, Medusa, Fog, WORLDLEAKS, Spirals, Sorry + more). Package-registry supply-chain double strike (game-cheat + Go module). macOS threat layer matured (AppleScript infostealer + macOS-focused stealer + ClickFix variants). TencShell C2 operator with 4 subnet anchors (16 IPs concentrated). Full ATT&CK mapping per cluster, subnet anchors, top 15 IOCs per indicator type, four production-ready Sigma rules.