Category: Cyber Threat
The TaHiTI Finalize Doctrine · Why 90% of Threat Hunting Programs Never Compound (and the 5-Deliverable Playbook That Fixes It)
TaHiTI Part 3. Initialize creates fuel. Hunt burns it. Finalize turns exhaust into tomorrow’s fuel. 90% of hunting programs skip it — which is why they never mature. The 5-deliverable Finalize checklist, the 50-operator backlog governance playbook, four maturity metrics, and three copy-paste handoff templates.
The AIaaS Doctrine · Attack Infrastructure as a Service · What 1.86 Million Cloud-Hosted IOCs Tell Every CISO
Attack Infrastructure as a Service (AIaaS) is coined. 44 threat actors deliberately share one cloud-hosted IP. 76% of persistent adversaries are deliberately diversified. Your allow-list is a target selector. A CISO-grade manifesto with 7 laws, a 10-question scorecard, and a 7-principle defence doctrine.
The TaHiTI Investigation Abstract: Turning Threat Intelligence Into Targeted Hunts
Part 2 of the TaHiTI series. The investigation abstract is the Phase-I artefact that converts a raw threat-intelligence trigger into an executable hunt. This walkthrough covers all five components of the abstract, the five characteristics of a good hypothesis (per the official FI-ISAC methodology), the three anti-patterns that derail hunt programs, and three worked examples that convert this week’s live threat intelligence into methodology-faithful abstracts.
Stop Searching, Start Hunting: A TaHiTI Hunt-Program Walkthrough Against This Week’s Threat Surface
TaHiTI (Targeted Hunting integrating Threat Intelligence) is the structured, hypothesis-driven hunting framework developed by the Dutch Financial ISAC. Part 1 of an 8-part series: the framework in full depth, the ABLE hypothesis quality standard, hunt backlog engineering, and a worked example that converts this week’s live threat intelligence into five executable hunt hypotheses — one taken end-to-end from hypothesis to Sigma rule.
The Complete AWS Threat Hunting Library: 27 Cloud Hunts, 7 Flagship Playbooks, and the Full Archive (2026)
The definitive AWS threat hunting reference — indexing all 27 published AWS hunting posts on hackforlab.com. 7 flagship 2026 hunts (CloudTrail blind spots, KMS ransomware, GuardDuty evasion, CI/CD compromise, native messaging C2, Athena data lake exfiltration, multi-account federation), plus 19 archive posts covering AWS identity attacks, Bedrock CloudTrail playbook, VPC Flow Log analytics, cloud malware case studies, and the foundational AWS attack-chain detection content.









