Coining Hunt-Debt. 5-level TaHiTI Maturity Model (L1 Reactive → L5 Optimized). 30-question CISO Self-Assessment scoring your program out of 90. 90-Day Operator Playbook to move from Level 1/2 to Level 3+. Anti-patterns per level. Sept 2026 threat-surface case study. Risk-register wording ready for ERM paste. Complete Part 4 of the TaHiTI series.
TaHiTI Part 3. Initialize creates fuel. Hunt burns it. Finalize turns exhaust into tomorrow’s fuel. 90% of hunting programs skip it — which is why they never mature. The 5-deliverable Finalize checklist, the 50-operator backlog governance playbook, four maturity metrics, and three copy-paste handoff templates.
Attack Infrastructure as a Service (AIaaS) is coined. 44 threat actors deliberately share one cloud-hosted IP. 76% of persistent adversaries are deliberately diversified. Your allow-list is a target selector. A CISO-grade manifesto with 7 laws, a 10-question scorecard, and a 7-principle defence doctrine.
Part 2 of the TaHiTI series. The investigation abstract is the Phase-I artefact that converts a raw threat-intelligence trigger into an executable hunt. This walkthrough covers all five components of the abstract, the five characteristics of a good hypothesis (per the official FI-ISAC methodology), the three anti-patterns that derail hunt programs, and three worked examples that convert this week’s live threat intelligence into methodology-faithful abstracts.
TaHiTI (Targeted Hunting integrating Threat Intelligence) is the structured, hypothesis-driven hunting framework developed by the Dutch Financial ISAC. Part 1 of an 8-part series: the framework in full depth, the ABLE hypothesis quality standard, hunt backlog engineering, and a worked example that converts this week’s live threat intelligence into five executable hunt hypotheses — one taken end-to-end from hypothesis to Sigma rule.