Category: Cyber Threat

TaHiTI Part 2 · The Investigation Abstract · turning threat intelligence into targeted hunts · emerald + navy palette · HackForLab cyber threat intelligence · hunt methodology
0 3
Posted in Cyber Threat

The TaHiTI Investigation Abstract: Turning Threat Intelligence Into Targeted Hunts

Part 2 of the TaHiTI series. The investigation abstract is the Phase-I artefact that converts a raw threat-intelligence trigger into an executable hunt. This walkthrough covers all five components of the abstract, the five characteristics of a good hypothesis (per the official FI-ISAC methodology), the three anti-patterns that derail hunt programs, and three worked examples that convert this week’s live threat intelligence into methodology-faithful abstracts.

TaHiTI · Targeted Hunting integrating Threat Intelligence · Stop searching, start hunting · opening post of a weekly TaHiTI series · HackForLab cyber threat intelligence · hunt methodology cover
0 25
Posted in Cyber Threat

Stop Searching, Start Hunting: A TaHiTI Hunt-Program Walkthrough Against This Week’s Threat Surface

TaHiTI (Targeted Hunting integrating Threat Intelligence) is the structured, hypothesis-driven hunting framework developed by the Dutch Financial ISAC. Part 1 of an 8-part series: the framework in full depth, the ABLE hypothesis quality standard, hunt backlog engineering, and a worked example that converts this week’s live threat intelligence into five executable hunt hypotheses — one taken end-to-end from hypothesis to Sigma rule.

The AWS Threat Hunting Library — 7 hunts every cloud SOC should run · HackForLab AWS Threat Hunting series hub
0 51
Posted in Cyber Threat

The Complete AWS Threat Hunting Library: 27 Cloud Hunts, 7 Flagship Playbooks, and the Full Archive (2026)

The definitive AWS threat hunting reference — indexing all 27 published AWS hunting posts on hackforlab.com. 7 flagship 2026 hunts (CloudTrail blind spots, KMS ransomware, GuardDuty evasion, CI/CD compromise, native messaging C2, Athena data lake exfiltration, multi-account federation), plus 19 archive posts covering AWS identity attacks, Bedrock CloudTrail playbook, VPC Flow Log analytics, cloud malware case studies, and the foundational AWS attack-chain detection content.

AWS Organizations Compromise — hunting the multi-account federation attack · HackForLab AWS Threat Hunting Part 7
0 47
Posted in Cyber Threat

AWS Organizations Compromise: Hunting the Multi-Account Federation Attack

AWS Organizations centralises governance — and that centralisation creates a high-value attack target. This article covers the four most-exploited multi-account compromise patterns, the cross-account telemetry stitching required to detect them, and the response strategies for organisation-level incident response.

Athena and S3 Data Lake Exfiltration — hunting the SQL-powered data heist · HackForLab AWS Threat Hunting Part 6
0 43
Posted in Cyber Threat

Athena and S3 Data Lake Exfiltration: Hunting the SQL-Powered Data Heist

AWS Athena lets adversaries run massive SELECT queries against S3-stored data lakes — and the resulting data exfiltration leaves a trail that most cloud SOCs do not monitor. This article catalogues the three Athena exfiltration patterns and ships the detection queries that surface them.