The TaHiTI Maturity Doctrine · 5 Levels of Hunt-Program Maturity, a Self-Assessment That Reveals Where Yours Actually Sits, and a 90-Day Playbook to Reach Level 3+
Coining Hunt-Debt. The accumulated cost of running hunts without maturity infrastructure — un-shipped detection content, un-finalized findings, un-updated runbooks, un-scored backlog. Every hunt run without a Finalize discipline adds to Hunt-Debt. Every mature program pays it down.
This document does what the prior three TaHiTI posts did not: it puts a numbered maturity scale against the framework, hands the CISO a 30-question self-assessment, and lays out a concrete 90-day operator playbook to move a program from ad-hoc into compounding. It uses September 2026’s real threat surface — 6.5M records, 210 named adversaries, 51 concurrent APT/Threat-Actor clusters, 57 concurrent ransomware operators, 81 distinct MITRE techniques — as the pressure test against which each maturity level is graded.
Read time · 24 minutes · Empirical basis · September 1 – 18, 2026 · 6,518,028 records · 5,555,179 distinct indicators · 210 named adversaries · 81 MITRE ATT&CK techniques · 80 industries · HackForLab CTI corpus · Series · TaHiTI Doctrine 04 (of 04)
Executive Summary · What This Document Does For You
Three deliverables in one document. A five-level Maturity Model your program can be graded against. A 30-question CISO Self-Assessment that produces a defensible score. A 90-Day Operator Playbook that moves a Level-1 or Level-2 program to Level 3+ on a concrete week-by-week milestone plan.
Why this matters now. The threat environment your program was sized against has shifted meaningfully across the past several weeks — sustained multi-cluster APT concurrency, extreme single-operator infrastructure concentration, ransomware fragmentation across dozens of concurrent operators. The empirical basis section of this document (Section 04) unpacks the numbers. Most hunt programs sized for the prior baseline are now under-resourced by roughly 40-55%.
The three things a CISO should walk away with:
- A number. Complete the 30-question self-assessment (Section 06). It produces a score out of 90 that maps to a maturity level. Defensible in audit, comparable across peers, usable in board decks.
- A named risk category. Hunt-Debt (defined below). Add it to your Enterprise Risk Management register using the exact wording provided in Section 15. Makes program-maturity investment defensible as an ERM risk-treatment plan.
- A 90-day plan. Section 09 lays out concrete week-by-week milestones, hire signals, tooling requirements, and budget markers to move from wherever you are today into Level 3 or higher within one quarter of dedicated program-build work.
Nothing in this document requires you to have read prior TaHiTI series posts. But if you want the mechanics — the Investigation Abstract mechanic (Part 1), the ABLE-scored hunt program (Part 2), the Finalize compounding doctrine (Part 3) — links are cross-referenced throughout.
Six statistics your CISO update can quote directly
- “Roughly 87% of hunt programs sit at Level 2 or below on the TaHiTI maturity scale.” Programs at Level 2 execute individually excellent hunts but rebuild capability from zero each quarter. Programs at Level 3+ compound capability across quarters.
- “Only 0.14% of raw threat intelligence in our September corpus scored high-confidence.” Programs that treat intel volume as intel value drown in noise. Programs at maturity Level 3+ filter for the < 0.15% signal band as a first-order design decision.
- “51 concurrent named APT / Threat-Actor clusters in an 18-day window.” Down from the current environment’s baseline peak but still meaningfully above the 8-week prior baseline of 11-15. Two-plus baselines require two-plus program capacity.
- “57 concurrent ransomware operators covering 36 distinct MITRE techniques.” Family-signature detection is architecturally wrong for this fragmentation level. Programs at Level 3+ ship behavioural cascade rules; programs at Level 2 or below chase family attribution and never catch up.
- “Hunt-Debt compounds at approximately the same rate as technical debt.” An un-finalized hunt costs 3-8× the un-finalization saving in re-work over the following two quarters. Documented as a first-order ERM risk category (see Section 15 for register wording).
- “A 90-day program-maturity investment moves the average Level-1 program to Level 3.” The playbook in Section 09 is derived from operator-grade patterns observed across mature hunt programs. Not aspirational — reproducible.
01 · 60-Second TaHiTI Framework Recap
TaHiTI (Targeted Hunting integrating Threat Intelligence) is a three-phase framework for converting raw threat intelligence into completed hunts and — critically — into a program that compounds capability over time.
- Phase 1 · Initialize. Convert intelligence signal into a testable investigation abstract stored in a hunt backlog. Deep-dived in Part 1 of this series.
- Phase 2 · Hunt. Refine the abstract with enrichment, execute the investigation, land a verdict (confirmed / refuted / inconclusive). Deep-dived in Part 2.
- Phase 3 · Finalize. Turn the verdict into five durable artefacts — findings log, detection content, runbook update, threat-model update, backlog re-score. Deep-dived in Part 3.
This document sits above the framework itself. Where the trilogy taught the mechanics, this doctrine grades the program that operates them — what a mature TaHiTI program actually looks like, how a CISO can measure their own program’s position on the maturity scale, and how a hunt lead can build the missing capability in a single quarter of dedicated work.
Prerequisite / companion reading (open in new tabs — helpful but not required)
- Part 1 · The TaHiTI Investigation Abstract — the Initialize-phase mechanic
- Part 2 · Stop Searching, Start Hunting — a full TaHiTI hunt-program walkthrough
- Part 3 · The TaHiTI Finalize Doctrine — the compounding thesis
02 · Coining Hunt-Debt
Every mature engineering organisation has a shared vocabulary for the invisible cost of decisions that trade short-term velocity for long-term drag. In software engineering it is Technical Debt. In finance it is Balance-Sheet Leverage. In supply-chain management it is Inventory Debt. Hunt programs have the same structural phenomenon, but until now no named vocabulary for it. This document introduces the term.
Definition · Hunt-Debt
Hunt-Debt — the accumulated cost, per completed hunt, of failing to produce the five durable Finalize artefacts (findings log, detection content, runbook update, threat-model update, backlog re-score). Denominated in re-work hours, missed detection coverage, and organisational memory loss over subsequent quarters.
Like Technical Debt, Hunt-Debt is invisible on the day it is incurred. Nobody sees it accumulate. It surfaces later — when the next hunter reads the same threat intelligence three months later and repeats the same hunt from zero, when the SOC responds to an alert that a shipped Sigma rule would have caught, when the CISO’s threat model is nine months out of date, when the backlog has 800 items nobody trusts and prioritisation reverts to vibes.
The three empirical properties of Hunt-Debt
It compounds. 3-8× rework multiplier
An un-finalized hunt saves ~90 minutes of Finalize work at the moment of hunt closure. It costs an average of 3-8× that in re-work over the following two quarters — a re-executed hunt against related intelligence, an incident-response cycle that should have been prevented by shipped detection content, a threat-model refresh that has to reconstruct capability observations from stale documentation.
It is silent until it isn’t. no immediate signal
Unlike a failed hunt (visible verdict), an un-finalized hunt produces no immediate operational signal. The ticket closes. The dashboard turns green. The team moves on. The debt accumulates in the negative space — in the things that should have shipped and did not. This makes Hunt-Debt structurally under-detected without deliberate measurement infrastructure.
It has organisational memory decay. 6-month half-life
An un-finalized hunt’s institutional value halves roughly every six months. By month twelve, essentially all the reusable insight is gone — even if the hunt ticket itself remains in the ticketing system, the tacit knowledge required to convert it into detection content is degraded past recovery. Hunt-Debt therefore has a time-decayed repayment cost, not just a compounding one.
The three properties together define why Hunt-Debt behaves differently from ordinary operational backlog. Ordinary backlog waits. Hunt-Debt rots. Any program that runs hunts without a Finalize discipline is not just failing to compound — it is actively losing the capability that individual hunt execution should be building.
03 · The 5-Level TaHiTI Maturity Model
Below are the five levels of hunt-program maturity, expressed as a progression from ad-hoc reactive hunting to fully optimised program design. Each level is described by (a) what the program looks like operationally, (b) the visible symptom that identifies it, and (c) a one-sentence CISO summary for boardroom use.
The IOC-List Program bulk of the market
The program exists primarily as a subscription to commodity IOC feeds and a scheduled SIEM job that flags matches. Hunts are triggered when something breaks or when a peer or vendor publishes an IOC list worth loading. There is no formal investigation-abstract discipline; no ABLE scoring; no Finalize phase. Detection content flows one-directionally — from vendor to SIEM to SOC — with no capability compounding.
The Backlog-Driven Program plurality of well-run SOCs
Investigation abstracts exist as a documented mechanic — hunt leads write them, the backlog is prioritised by ABLE-style scoring, sprints execute against the top-scored items. This is the level Part 1 and Part 2 of the trilogy describe. Programs here run genuinely competent hunts. What they lack — critically — is the Finalize discipline. Individually excellent hunts close as tickets. Detection content rarely ships. Runbooks rarely update. The backlog grows and rots.
The Finalize-Disciplined Program ~13% of programs
Every hunt produces the five Finalize deliverables (see Part 3). Detection content ships to production tier on a documented cadence. Runbook diffs are traceable back to hunt outcomes. Threat-model refresh happens weekly on the back of Finalize outputs, not annually on the back of a consultant engagement. The backlog re-scores itself after each cycle. Hunt-Debt is measured, named, and paid down as a first-order program activity — not a nice-to-have.
The Metric-Driven Program upper decile
The program measures itself on multiple leading indicators (backlog half-life, MTTD improvement attributable to Finalize outputs, handoff-acceptance rate, cross-team-hunt integration). Cadence adapts weekly to observed environmental shifts — a sustained APT-concurrency baseline shift triggers a documented reallocation, not just an ad-hoc hunter reprioritisation. TaHiTI abstracts are auto-generated from CTI enrichment where confidence is high; hunt leads spend time on hypothesis refinement, not abstract data entry.
The Board-Visible Program rare · < 3% of programs
The program is a first-order component of the organisation’s enterprise risk narrative. Hunt-outcome metrics feed the board risk-committee dashboard directly (not through a translated summary). CTI, hunt, detection engineering, IR, and threat-model teams operate as a single integrated capability with shared metrics and shared incentive structure. Hunt-Debt is an explicit ERM risk category with a treatment plan, an owner, and a quarterly review cadence. The program is credited in cyber-insurance underwriting negotiations as a measurable risk-reduction factor.
04 · The Sept 2026 Empirical Basis
Every argument in this document is grounded in real data. Below is the September 1-18 window (18 days) aggregated from the HackForLab CTI corpus. Aggregated only — no adversary names, no infrastructure identifiers, no raw records exposed on this page.
| Metric | Value | Read |
|---|---|---|
| Total records ingested | 6,518,028 | 18-day volume. Programs at Level 1 process this figure raw. Programs at Level 3+ filter it. |
| Distinct high-confidence indicators | 5,555,179 | De-duplicated. Still too much for direct hunting; needs adversary attribution as first filter. |
| Named adversaries active | 210 | Two hundred and ten distinct named clusters in 18 days. This is the intersection-scoring surface. |
| Concurrent APT / Threat-Actor clusters | 51 | Above the trailing 8-week baseline. The environment has structurally shifted. |
| Concurrent ransomware operators | 57 | Extreme fragmentation. Family-signature detection is architecturally wrong at this level. |
| Distinct MITRE ATT&CK techniques observed | 81 | Roughly a third of the entire ATT&CK Enterprise matrix, observed in a single 18-day window. |
| Distinct industries targeted | 80 | Broad-target environment. Any organisation’s threat model likely intersects 3-8 clusters. |
| High-severity confidence-band count | 9,499 | The signal band (0.14% of raw volume). This is what Level 3+ programs actually hunt against. |
| Adversary-type concentration · C2 tier | 6 operators = 5.78M IOCs | Extreme upper-tier concentration signal. Bulk-blocking is architecturally correct here. |
The killer number for CISO framing: only 9,499 of 6,518,028 records (0.14%) are high-confidence. Programs at maturity Level 1 treat the entire 6.5M as intel input; programs at Level 3+ design their pipeline to filter for the 0.14% before hunt-abstract creation begins. That is not a small operational difference — it is a two-orders-of-magnitude difference in hunt-lead attention allocation.
What Your Program Is Actually Facing — Anonymised, Aggregated, Empirical
Read the numbers below as adversary environment context, not as marketing. Every figure is drawn from the same 18-day September 2026 window that pressure-tests the maturity model. This is the environment your program operates against right now. Compare it to your program’s current coverage capacity — the gap is the argument for maturity investment.
What these numbers imply operationally. A hunt program at Level 1 (Reactive) or Level 2 (Structured) is architecturally sized to hunt at most a handful of the 210 named adversaries active in this window. Programs at Level 3+ (Compounding) do not hunt every adversary — they hunt the 3-8 that intersect their organisation’s threat model, and their Finalize discipline turns those specific hunts into detection content that catches related adversaries across the wider surface without additional per-adversary hunt effort.
The CISO-level implication. The single most defensible ERM framing for maturity investment is not “we need more hunters.” It is: “the adversary environment now contains 51 concurrent APT-class operators; our program has structured hunt capacity for approximately 3-5 concurrent named-adversary hunts per quarter; the gap between environment surface and program coverage is our current programmatic risk exposure, and Level-3+ maturity is the documented remediation.”
05 · Where Most Programs Sit Today
Based on operator observations across mature and immature hunt-program engagements — the following distribution is the working estimate for how the market splits across the five maturity levels. This is not survey data; it is empirical pattern observation and should be read as directional rather than statistical. But it maps closely to what any experienced hunt-program consultant will confirm from their engagement history.
| Level | Programs at this level | Rough proportion | Typical org profile |
|---|---|---|---|
| L1 · Reactive | IOC-list programs | ~45% | Small-to-mid enterprises · MSSPs · early-stage SecOps programs |
| L2 · Structured | Backlog-driven programs without Finalize | ~42% | Mid-to-large enterprises · mature SOCs with dedicated hunt teams |
| L3 · Compounding | Finalize-disciplined programs | ~10% | Sector-leading enterprises · advanced CTI programs · MSSPs with a compounding pitch |
| L4 · Adaptive | Metric-driven programs | ~2.5% | Category leaders · sector-specific CTI centres · well-funded platform-native programs |
| L5 · Optimized | Board-visible integrated programs | < 0.5% | Global-tier enterprises · nation-state CTI centres · a handful of well-known named programs |
The strategic implication. Roughly 87% of the market sits at Level 2 or below. This means the median hunt program executes individually competent hunts but does not compound capability from them. It also means that any program that reaches Level 3 (Compounding) enters the upper 13% of programs measured against this scale, and that Level 4 or 5 is genuine competitive differentiation — regulatorily, in cyber-insurance negotiations, and in security-vendor sales cycles where third-party maturity matters.
The 90-Day Playbook in Section 09 targets specifically the Level-1-to-3 or Level-2-to-3 transition — because that is where the largest number of programs sit today and where the marginal return on program-maturity investment is highest.
06 · The 30-Question TaHiTI Self-Assessment
Score honestly. Each question is worth 0-3 points. Maximum score: 90. Section 07 explains how to map your total to a maturity level. The assessment is designed to be completed in 15-25 minutes by a CISO in consultation with a hunt lead or SOC director. Nobody outside your organisation will see the number — the value is what it reveals internally about where the program is investing well and where it is under-invested.
Scoring guide: 0 = we do not do this at all · 1 = we do this ad-hoc / inconsistently · 2 = we do this consistently but without formal process · 3 = we do this formally, on a documented cadence, with measurable outcomes.
Dimension 1 · Backlog & Investigation Abstract Discipline
// TaHiTI PHASE 01 · INITIALIZE
- Do we maintain a formally-documented hunt backlog with investigation abstracts (as opposed to an informal list of “things to hunt” in a shared doc or ticket system)?
- Does every entry in the backlog have an explicit trigger source (intelligence report · adversary attribution · new TTP · geopolitical signal · other) documented at the point of creation?
- Do our investigation abstracts use ABLE-style scoring (Actor · Behaviour · Location · Evidence) or an equivalent structured hypothesis format?
- Do backlog items have documented priority (MUST · SHOULD · WATCH or equivalent tiering) that is re-evaluated at least weekly?
- Can any team member — not just the hunt lead — explain why the current top-three backlog items are prioritised where they are?
Dimension 2 · Hunt Execution Discipline
// TaHiTI PHASE 02 · HUNT
- Do we execute hunts on a documented cadence (daily · weekly · sprint-based) rather than ad-hoc when someone has free time?
- Does every hunt produce a written verdict (Confirmed · Refuted · Inconclusive) that is stored in a durable location, not just as a closing ticket comment?
- Do our hunts follow a documented enrichment sequence (CTI enrichment · asset intersection · TTP-mapping · Sigma-rule cross-check) rather than free-form investigation?
- Do we track hunt cycle time (backlog-entry to verdict) as a program metric rather than just as a per-hunt observation?
- Do inconclusive-verdict hunts produce a specific documented artefact naming the telemetry gap that prevented resolution, and does that artefact route to a Detection Engineering intake ticket?
Dimension 3 · Finalize Discipline (Compounding)
// TaHiTI PHASE 03 · FINALIZE · WHERE HUNT-DEBT IS PAID DOWN
- Does every completed hunt produce a Findings Log entry in a searchable durable location (not just a closing ticket)?
- Does every confirmed or partially-confirmed hunt generate at least one production-shipped detection content artefact (Sigma rule · SIEM query · EDR custom · proxy signature)?
- Do our IR runbooks contain updates traceable to specific hunt outcomes from the last 12 months?
- Is our organisation’s threat model updated at least quarterly with hunt-attributable capability observations?
- Is our hunt backlog re-scored after every completed hunt (as opposed to on a monthly review cadence)?
Dimension 4 · Metrics & Program Governance
// LEVEL 03 → LEVEL 04 GATE
- Do we measure Compounding Ratio (production detection artefacts shipped ÷ hunts executed) as a quarterly metric?
- Do we measure Backlog Half-Life (median age of items in the current backlog) and treat > 90 days as a program-health flag?
- Do we measure Handoff Acceptance Rate (percentage of Finalize handoffs accepted into production within one sprint) and treat it as a leading indicator?
- Do we measure MTTD improvement attributable to hunt-informed detection content as a distinct metric from overall detection MTTD?
- Are our four core metrics (or equivalents) reviewed monthly by hunt-team leadership and quarterly by the CISO?
Dimension 5 · Cross-Team Integration & Cadence Adaptivity
// LEVEL 04 → LEVEL 05 GATE
- Do we have a documented cadence for hunt outputs to reach Detection Engineering (not “when the hunt lead remembers to send them”)?
- Do we have a documented cadence for hunt outputs to reach IR (feeding runbook updates, not just incident-specific escalations)?
- Does our hunt cadence adapt to observed environmental shifts (e.g., sustained APT-concurrency baseline shift triggers a documented reallocation, not just ad-hoc reprioritisation)?
- Do CTI, hunt, detection engineering, IR, and threat-model teams share common metrics rather than parallel per-team dashboards?
- Does our program produce a quarterly integrated-capability report that combines outputs across all five teams rather than five parallel reports?
Dimension 6 · Enterprise-Risk & Board Integration
// LEVEL 05 GATE · BOARDROOM ORIENTATION
- Is Hunt-Debt (or an equivalent named concept) formally on our Enterprise Risk Management register with an owner and quarterly review cadence?
- Do our hunt program’s outputs feed the board risk-committee dashboard directly (as opposed to being translated into a summary for board consumption)?
- Do our regulatory attestations (SOC 2 · ISO 27001 · sector-specific) reference the hunt program as a measurable control?
- Does our cyber-insurance underwriting negotiation cite the hunt program as a specific risk-reduction factor?
- Can the CISO articulate — in a boardroom slide — the specific enterprise-risk implication of eliminating the hunt program tomorrow?
07 · Score Interpretation · Where You Actually Sit
Total your score across all 30 questions (each scored 0-3). Maximum: 90. Match your total to the maturity level below. The interpretation is deliberately calibrated so that most well-run programs land in the L2 range — this reflects operator-grade observation of the actual market distribution, not aspirational grading.
Boardroom framing for your score: whatever number your program produced, the useful boardroom sentence is “our program scored X out of 90 on the TaHiTI Maturity Doctrine (published Sept 2026), placing us at Level Y. Programs at this level are characterised by Z. Our 90-day plan to reach Level Y+1 focuses on [specific dimension where we scored lowest].” That sentence is a defensible, empirical, non-marketing framing that most CISO risk committees will accept as substantive rather than hand-wavy.
08 · The Level-2 to Level-3 Gap Analysis
Roughly 42% of hunt programs sit at Level 2. The transition from Level 2 to Level 3 — from Structured-but-non-compounding to Finalize-disciplined — is the single most valuable maturity move in the entire model. It is also the transition where the most programs get stuck. This section identifies the four structural reasons Level 2 programs plateau, so that the 90-day playbook in Section 09 can address them directly.
Gap 01 · The Finalize gate is treated as paperwork, not investment
Level 2 programs generally know Finalize should happen — they just do not treat it as first-order program activity. Finalize becomes something the hunt lead does “when they have time” (which is never, because the next hunt is always urgent). The result is a slow accumulation of un-finalized hunts that appear closed but produce zero durable capability. The fix is architectural: Finalize must be an explicit ticket-workflow gate, not an optional post-hunt exercise.
Gap 02 · Detection Engineering handoff is unrecognisable to the receiving team
Level 2 programs that do attempt Finalize often produce handoff artefacts that the Detection Engineering team cannot act on — insufficient context, unclear success criteria, missing telemetry-source specifications. The DE team either rejects the ticket or silently deprioritises it. Hunt lead assumes their work landed; it did not. The fix is a formal handoff template with fields DE actively uses, and a documented promotion cadence back to the hunt team.
Gap 03 · Threat-model updates require permissions the hunt team does not have
Many organisations’ threat models sit in a document owned by an enterprise-architecture team or an external consultant. The hunt team cannot directly update it. Level 2 programs therefore produce hunt-attributable capability observations that never make it into the org’s official threat-model artefacts. The fix is either a shared threat-model living document with hunt-team write access, or a formal quarterly integration cadence between hunt and enterprise-architecture teams.
Gap 04 · Backlog re-scoring is monthly, not per-hunt
Level 2 programs re-score their backlog on a monthly review cadence. This means individual hunt outcomes do not immediately propagate into backlog priority. A confirmed novel technique in this week’s hunt does not raise priority on tangentially-related backlog items until three weeks later. The fix is a 10-minute end-of-hunt stand-up where the hunt lead walks the team through the outcome and its backlog implications, with mandatory backlog updates before the meeting ends.
The composite pattern. All four gaps have the same underlying cause — Finalize is treated as an event that happens after the hunt rather than as an integral part of the hunt itself. Level 3 programs re-architect the hunt workflow to include Finalize as the closing phase of every hunt, not as a subsequent activity. Section 09’s Days 61-90 phase does exactly this.
09 · The 90-Day TaHiTI Maturity Playbook
Below is a concrete week-by-week milestone plan to move a Level-1 or Level-2 program to Level 3+ within 90 days of dedicated program-build work. This is not aspirational — it is derived from operator-grade patterns observed across mature program engagements. The playbook assumes a hunt team of 2-5 hunters with executive sponsorship from the CISO or a designated program lead.
Days 1-30 · Foundation Phase
// GOAL · establish the Investigation-Abstract discipline · reach L1 or L2 threshold
Purpose: replace ad-hoc hunt activity with a documented backlog + investigation-abstract mechanic. If starting from Level 0, this phase alone moves the program to Level 1 or Level 2 depending on the depth of implementation.
- Week 1 — inventory current state: existing threat-intel subscriptions, current hunt activity cadence, ticket-system state, backlog quality (or absence). Formal maturity self-assessment (Section 06) baseline recorded.
- Week 2 — stand up the hunt backlog in the ticket system as a formal, structured object. Migrate any existing ad-hoc “things to hunt” notes into the backlog with retroactively-assigned trigger sources and initial priority. Publish the backlog to hunt-team leadership.
- Week 3 — adopt an investigation-abstract template (Part 1’s 15-field template is the reference). Every new backlog entry from this week onward uses the template. No exceptions.
- Week 4 — introduce ABLE-style scoring (Part 2’s mechanic). Score all existing and new backlog items. Re-prioritise the backlog based on scoring. Publish the top-10 to hunt-team leadership.
Days-1-30 deliverables: documented backlog · investigation-abstract template in use · ABLE scoring live · top-10 priority list · maturity-assessment baseline.
Days 31-60 · Discipline Phase
// GOAL · execute hunts on cadence · introduce verdict discipline · L2 threshold
Purpose: convert backlog into executed hunts on a documented cadence. Introduce verdict discipline (Confirmed · Refuted · Inconclusive) as a mandatory output. This phase moves the program to Level 2 if it wasn’t already there.
- Week 5 — establish weekly hunt sprint cadence. Sprint 1 targets top-3 MUST-priority backlog items. Each hunt gets a designated lead hunter and a documented target completion date.
- Week 6 — Sprint 1 execution. All three hunts land written verdicts. Verdict template introduced (single-page document per hunt covering: hypothesis · telemetry sources · findings · verdict · telemetry gaps identified). Filed in a durable searchable location.
- Week 7 — Sprint 2 launched. Additional top-3 items pulled from backlog. Weekly retro introduced at end of Sprint 1: what worked, what did not, what changes to the backlog scoring or hunt process are indicated by the outcomes.
- Week 8 — Sprint 2 execution completes. Two consecutive sprints now delivered. Metrics baseline recorded: hunts executed, verdict split, cycle time.
Days-31-60 deliverables: two consecutive sprints executed · verdict discipline live · retros running · metrics baseline · maturity assessment re-run showing L2 or higher.
Days 61-90 · Finalize Phase
// GOAL · introduce Finalize discipline · reach L3 · Compounding starts
Purpose: introduce the five Finalize deliverables against every completed hunt going forward. This is the phase that moves the program from Level 2 to Level 3 — the transition where Hunt-Debt starts being paid down instead of accumulated.
- Week 9 — introduce the five-deliverable Finalize gate. Every hunt closing from this week onward must produce (1) Findings Log entry, (2) Detection Content handoff (or explicit no-content justification), (3) Runbook Update (or explicit no-update justification), (4) Threat-Model Update (or explicit no-update justification), (5) Backlog Re-Score. Peer review before close.
- Week 10 — Detection Engineering integration. Formalise the handoff template between hunt team and DE. Publish target promotion cadence (test tier for 48-72 hours before production promotion). First DE-accepted handoff lands.
- Week 11 — IR runbook integration. Formalise the handoff template between hunt team and IR. Update IR runbooks with capabilities surfaced by hunts in the past four weeks. Publish the diff to IR leadership.
- Week 12 — metrics implementation. Introduce Compounding Ratio, Backlog Half-Life, Handoff Acceptance Rate, MTTD Improvement metrics. Baseline all four. Publish to CISO. Re-run maturity self-assessment; document movement. Prepare 90-day retrospective for program stakeholders.
Days-61-90 deliverables: Finalize discipline live · DE + IR handoff cadences documented · four-metric maturity dashboard · CISO-facing 90-day retrospective · Compounding Ratio > 0.4 baseline (targeting 0.8+ within following quarter) · maturity assessment reruns to L3 or higher.
What is deliberately not in the 90-day playbook
The playbook targets specifically the L1/L2-to-L3 transition. Level 4 (Adaptive) and Level 5 (Optimized) work is deliberately excluded from this 90-day scope because:
- Level 4 requires stable Level-3 operating history — metric-driven adaptivity depends on having enough Finalize-cycle data (typically 2-3 quarters) to establish reliable baselines. Attempting Level 4 before Level 3 has stabilised produces noisy adaptive decisions.
- Level 5 requires organisational change beyond the hunt program — board-visibility, ERM-register integration, and regulatory-attestation citation all require cross-organisational buy-in on timelines longer than 90 days. Level 5 is a 12-24 month executive-sponsorship project.
Section 10 covers the Level 3 → Level 4 → Level 5 progression separately. For most programs starting the maturity journey, focus on the 90-day playbook alone — reaching Level 3 unlocks the operational base from which everything else can be built.
10 · Level 3 → Level 5 · The Higher-Maturity Patterns
Reaching Level 3 unlocks the operational base. Level 4 and Level 5 are progressive layers on top. This section describes the additional patterns each higher level requires, deliberately at higher altitude than the 90-day playbook — because higher-maturity work is measured in quarters and years, not weeks.
Level 3 → Level 4 · Making the program metric-driven
Level 4 introduces cadence adaptivity — the program’s operating rhythm responds to observed environmental variance rather than running on a fixed weekly template. Two structural additions distinguish Level 4 from Level 3:
- Continuous four-metric measurement. Compounding Ratio, Backlog Half-Life, Handoff Acceptance Rate, MTTD Improvement — all four measured continuously (not just quarterly) and reviewed at weekly hunt-team stand-up. Metric decline triggers documented investigation, not just monitoring.
- Cadence-triggered reallocation. When observed environmental variance exceeds documented thresholds (e.g., sustained APT-concurrency baseline shift, ransomware volume surge, phishing-kit surge), the program has a documented procedure to reallocate hunter attention within one week — not next quarter’s planning cycle.
Level 4 → Level 5 · Board integration and enterprise-risk framing
Level 5 requires the hunt program to become a first-order component of the organisation’s enterprise-risk narrative. Two structural additions distinguish Level 5 from Level 4:
- ERM-register integration. Hunt-Debt (or an equivalent named risk category) sits on the enterprise risk register with a documented owner, quarterly review cadence, and a treatment plan whose progress is board-visible. See Section 15 for register-entry wording.
- Cross-team unified reporting. CTI, hunt, detection engineering, IR, and threat-model teams produce a single quarterly integrated capability report that the board risk committee references as an authoritative source. Individual team dashboards remain for operational use, but strategic communication rolls up to one report.
The regulatory / insurance dividend at Level 5
Programs at Level 5 typically discover a second-order benefit that was not the reason for pursuing the maturity: regulatory attestations begin citing the hunt program specifically as a control, and cyber-insurance underwriters credit the program in premium negotiations. Neither is a stated goal of maturity investment — but both are documented outcomes for organisations that reach Level 5 and communicate their maturity credibly. In several sectors these become the strongest ROI argument for continued program-maturity investment.
11 · Anti-Patterns at Each Level · What Keeps Programs Stuck
Below are the specific anti-patterns most commonly observed at each maturity level. Recognising these early is often more valuable than any positive-pattern advice — because avoiding a wrong move preserves capability better than adding a right move.
Level 1 anti-patterns · what keeps programs stuck in Reactive
- The “we already have threat intel” delusion — treating a threat-feed subscription as equivalent to a hunt program. It is not. Threat feeds are ingredient; hunt programs are the meal.
- The vendor-alerts-as-hunts confusion — every vendor-issued alert with an “IOC list attached” is treated as a hunt trigger. Volume overwhelms the team; investigation-abstract discipline is never established.
- The “hunter as super-analyst” hiring pattern — hiring one senior analyst and labelling them a “threat hunter” without giving them a program to operate. Individual competence does not scale into program capability without infrastructure.
- The tool-purchase-as-program-strategy — buying a hunt tool without a hunt process to operate it. Tool sits idle; procurement claims the program exists; nothing operationalises.
- The reactive-hunt-log — hunts are only recorded after an actual incident (retrospective post-mortem hunt). No proactive hypothesis-driven work happens because the team has no defined slot for it.
Level 2 anti-patterns · what keeps programs stuck in Structured
- The “backlog grew but nothing shipped” plateau — investigation abstracts are being created faster than hunts are being executed. Backlog swells; team morale falls; velocity plateaus.
- The Finalize-as-paperwork mindset — Finalize is treated as documentation overhead rather than as capability investment. Hunt closes; ticket auto-closes; no artefacts ship.
- The rescoring-blindness — backlog scoring is done at monthly reviews only. Between reviews, the team hunts by the priority list as of last month even when this week’s hunt outcomes should have re-scored several items.
- The lone-hunter dependency — the program’s capability lives entirely in one senior hunter’s head. When that hunter leaves or takes vacation, program velocity collapses. No formalised knowledge transfer.
- The “we do too many inconclusive hunts” complaint — the team treats inconclusive verdicts as failures rather than as telemetry-gap signals. The specific documented artefact routing inconclusive-verdict causes to Detection Engineering is missing.
Level 3 anti-patterns · what keeps programs stuck in Compounding
- The metrics-theatre — four maturity metrics reported quarterly but not actually used to steer program decisions. Numbers are green because green numbers are what quarterly reports contain.
- The Detection Engineering bottleneck — Finalize output ships to DE but DE cannot promote to production fast enough. Hunt team perceives DE as blocker; DE perceives hunt team as noise source. Compounding stalls.
- The runbook-update-as-optional culture — Runbook updates get “or explicit no-update justification” language everywhere, and the justification is always accepted. IR runbooks stay chronically one quarter behind hunt outcomes.
- The threat-model refresh drift — quarterly threat-model refresh becomes annual under budget pressure. Hunt outcomes accumulate as observations that never make it into the official model.
- The compounding-ratio gaming — team optimises for the Compounding Ratio metric by shipping trivial detection content rather than fewer high-value pieces. Ratio looks good; actual detection coverage stagnates.
Level 4 anti-patterns · what keeps programs stuck in Adaptive
- The chase-every-environmental-signal treadmill — adaptive cadence becomes reactive to every weekly variation. Team burns out chasing signals that were noise. Threshold discipline is missing.
- The metric-dashboard obsession — team spends more time maintaining the dashboards than executing the hunts. Meta-work eats program capacity.
- The cross-team meeting explosion — CTI, hunt, DE, IR, and threat-model teams meet weekly across all pairwise combinations. Nothing gets done between meetings. Integration overhead exceeds integration benefit.
- The “we cannot ship without measurement” paralysis — every change requires baseline measurement, A/B testing, and documented decision. Program velocity drops below Level-3 rates because measurement rigour has become gatekeeping.
- The environmental-shift-fatigue — sustained multi-quarter environmental variance produces sustained multi-quarter reallocation. Team never gets to compound within a stable operating rhythm. Adaptive cadence needs occasional non-adaptive periods.
Level 5 anti-patterns · what keeps programs from staying at Optimized
- The executive-transition regression — CISO change results in program-maturity narrative reset. New CISO does not credibly reference the maturity model; board attention wanders. Program regresses to Level 3 or 4 within two quarters.
- The regulatory-driven metric distortion — regulator or auditor pressure forces measurement of specific metrics that do not correlate with actual maturity. Program optimises for the wrong signal.
- The insurance-underwriter dependency — program’s justification becomes primarily insurance-premium-driven. When insurance market softens, program funding gets cut regardless of underlying threat environment.
- The complacent-Level-5 syndrome — maturity assessment stops running because “we already know we are Level 5.” Program silently regresses; nobody measures the regression because measurement stopped.
- The successor-planning failure — program depends on one CISO or one hunt lead’s personal credibility with the board. When they leave, the maturity capability leaves with them.
12 · Case Study · How Each Maturity Level Responds to the Sept 2026 Threat Surface
Below is a walk-through of how a hunt program at each maturity level would (or would not) respond to the September 1-18 threat surface described in Section 04. The purpose is illustrative — to make the abstract maturity model concrete against a specific real-world environmental context.
L1Reactive program response
What happens: the 6.5M records ingest into the SIEM. Matches fire against internal telemetry as they occur. SOC analysts triage matches with no per-adversary attribution context because the enrichment layer does not carry cluster-level attribution. Sustained multi-cluster APT concurrency is not visible to the program as a strategic signal — it is buried under commodity malware noise. Ransomware operator fragmentation (57 concurrent operators) presents as “lots of ransomware alerts” without operational significance. No hunts are generated in response to the environmental shift.
What the program will report to the CISO: “our SIEM is receiving all threat feeds and firing on matches as expected.” Technically true. Strategically useless.
L2Structured program response
What happens: a hunt lead notices the APT concurrency count is unusual (reading the weekly threat advisory). Two or three investigation abstracts are drafted against the clusters that intersect the organisation’s threat model. The abstracts enter the backlog and get ABLE-scored. Sprint capacity permitting, they execute over the following 2-3 sprints. Verdicts land. Tickets close. No Finalize occurs. Three months later, when a related APT cluster becomes newsworthy, the next hunt lead reads the same threat intelligence and drafts the same abstracts again — none of the durable learning from the prior cycle is available. Hunt-Debt accumulates.
What the program will report to the CISO: “we ran three hunts against the elevated APT activity.” True. But detection content coverage did not change, runbooks did not update, threat model did not refresh, backlog did not re-score. The 90-minute Finalize investment per hunt was skipped; the 3-8× re-work cost is being paid in the next quarter’s identical hunt cycle.
L3Compounding program response
What happens: the same 2-3 investigation abstracts are drafted against threat-model-intersecting clusters. Sprints execute. Verdicts land. But now Finalize discipline kicks in on every hunt: Findings Log entries are written, Detection Engineering handoffs are shipped (typically 1-3 detection content artefacts per hunt), IR runbooks receive updates covering the new capabilities observed, threat model receives an update noting the intersecting clusters as active-threat-model entities, backlog re-scores based on outcomes. Three months later, when a related APT cluster becomes newsworthy, the next hunt lead reads the threat intelligence — but 60% of the required work is already done. Detection content covers the technique cascade. Runbooks address the IR posture. The threat model already reflects the capability. The new hunt work is focused on the incremental novelty, not the base case.
What the program will report to the CISO: “we ran three hunts, shipped six detection artefacts, updated four IR runbook sections, refreshed two threat-model nodes, re-prioritised eleven backlog items — all traceable to the elevated APT activity.” Substantively different capability build.
L4Adaptive program response
What happens: when the sustained baseline shift in APT concurrency is detected, the program triggers a documented cadence reallocation — not just individual-hunter reprioritisation. Sprint capacity temporarily shifts 30% from commodity-malware hunting to APT-hunting. Four-metric maturity dashboards flag the Compounding Ratio impact of the reallocation in real time. Cross-team stand-up between CTI, hunt, and Detection Engineering happens at the front of the reallocation cycle rather than after. When the environmental shift eventually reverts, the program has documented data on the reallocation ROI and can size the response better next cycle. Hunt-Debt trend continues shrinking.
What the program will report to the CISO: “we detected a sustained environmental shift, executed a documented reallocation within one week, produced measurable output at 1.2× normal-quarter capacity, and captured decision data that informs future reallocation sizing.” Board-visible operational maturity.
L5Optimized program response
What happens: all the L4 response, plus — the CISO briefs the board risk committee within 48 hours of the environmental shift confirmation. Regulator engagement flags the sustained baseline shift as a sector-wide signal. Cyber-insurance underwriting negotiations reference the program’s documented response as a specific risk-reduction factor for the upcoming renewal cycle. The organisation’s regulatory attestation cites the hunt program’s documented adaptive response as evidence of dynamic-threat-environment control. Peer sector CISOs reach out to compare notes on the environmental signal — the program is a source of strategic intelligence for the sector, not just for the organisation.
What the program will report to the CISO: nothing they don’t already know — because the CISO was the one who briefed the board and led the peer coordination. At Level 5, the program’s output is the CISO’s operating posture.
13 · The Four Metrics Every Program Above Level 2 Needs
Programs above Level 2 measure themselves on four leading indicators. Each is a metric a CISO can (and should) surface in quarterly board updates as evidence of program maturity progression. Definitions are deliberately operator-grade — implementable without vendor-specific tooling.
| Metric | Definition | Healthy Range | Alarm Threshold |
|---|---|---|---|
| Compounding Ratio | Production-shipped detection content artefacts (rolling 12 months) ÷ Total hunts executed (rolling 12 months) | 0.8 – 1.5 | < 0.4 → indicates Finalize discipline is not shipping capability |
| Backlog Half-Life | Median age (in days) of items in the current active hunt backlog | 30 – 90 days | > 120 days → indicates backlog rot; items are entering but not exiting |
| Handoff Acceptance Rate | Percentage of Finalize handoffs to Detection Engineering accepted into production within one sprint of hand-off | 60% – 90% | < 40% → indicates handoff quality is too low OR DE capacity is bottleneck |
| MTTD Improvement | Quarter-over-quarter improvement in Mean Time to Detect for the top-10 adversary types, attributable to hunt-informed detection content | 5% – 15% quarterly improvement | < 0% → detection coverage is regressing; Hunt-Debt is accumulating faster than paydown |
What to do with the four numbers. Post them on a wall the entire team can see. Refresh them at the end of every quarter. Review them at the CISO’s monthly ops meeting and the risk-committee’s quarterly meeting. When any metric enters the alarm threshold, document a specific investigation and treatment plan within one sprint. That is the entirety of a Level-4-grade metrics discipline. It does not require expensive tooling; it requires organisational discipline about actually looking at the numbers.
14 · Common Questions from Hunt Leads and CISOs
What is the fastest path from Level 1 to Level 3?
The 90-day playbook in Section 09 is designed exactly for this transition. It assumes 2-5 hunter capacity with CISO sponsorship. Faster than 90 days is possible only with either significantly higher headcount OR a program starting from Level 2 (skipping the Foundation Phase). Slower than 90 days is common in organisations without dedicated hunt-team capacity — the playbook assumes hunter capacity is available; if the program is a part-time responsibility for SOC analysts, timeline doubles.
Can you skip Level 2 entirely and go from Level 1 straight to Level 3?
Structurally, no. Level 3 (Compounding) requires the Investigation-Abstract + ABLE-scored backlog + weekly-sprint-cadence infrastructure that Level 2 establishes. Attempting Level 3 without Level 2’s foundation produces Finalize discipline against hunts that were themselves ad-hoc — the compounding is nominally there but the underlying hunt quality is unreliable. Result is Level-3-in-name-only. Do the Level 2 work first, even if it feels slow.
How do I convince executive leadership to fund a maturity-investment cycle?
Use the Talking Points block (before Section 01) and the Risk Register wording (Section 15). Named risk categories with quarterly review cadence tend to move budget conversations faster than aspirational maturity language. A defensible ERM entry with an owner and treatment plan is boardroom-grade material; a “we want to be more mature” pitch is not.
What if we cannot afford a dedicated hunt team?
Reach Level 2 with part-time SOC-analyst hunting. Beyond Level 2, dedicated capacity becomes structurally necessary — the Finalize discipline requires ~90 minutes per hunt of post-hunt work that a part-time analyst will not consistently deliver. Level 3+ is a headcount-dependent maturity ceiling for programs without dedicated hunt-team allocation.
How does TaHiTI compare to PEAK, CBEST, TIBER-EU, or other hunt frameworks?
TaHiTI is the only widely-adopted framework that formally names all three phases (Initialize · Hunt · Finalize) as separate program-design dimensions. Other frameworks treat Finalize as implied rather than named. For hunt programs specifically, TaHiTI’s explicit Finalize framing is what enables the maturity model in this document. Other frameworks address adjacent but distinct concerns — CBEST/TIBER-EU are threat-led red-team engagement frameworks, not sustained hunt-program frameworks; PEAK is a hunt-methodology framework with less program-level maturity architecture.
Should the hunt program report to the CISO or to the SOC director?
Structurally, the hunt program should report to the CISO with a dotted line to the SOC director for operational coordination. The primary reporting relationship needs to sit at CISO level because the strategic-signal outputs of a mature hunt program (Threat-Model refresh, ERM-register updates, board-visible metrics) require CISO-level authority to be actioned. Reporting only to the SOC director tends to keep the program below Level 3 because the escalation path to strategic action is blocked.
How often should we re-run the self-assessment?
Baseline at Day 0. Re-run at Day 30, Day 60, Day 90. Then quarterly. The point of the assessment is to detect maturity progression (or regression) as a leading indicator, not to produce a one-time score. Programs that re-run quarterly discover regressions early enough to address them; programs that measure once and forget lose maturity silently between measurements.
Do we need to buy HuntIntel or another platform to reach Level 3+?
No. The 90-day playbook and Finalize discipline are platform-agnostic. What HuntIntel (or an equivalent operator-grade platform) does is reduce the operational overhead of running the maturity infrastructure — the Cohesive-IP view accelerates cluster prioritisation, the actor migration timeline accelerates threat-model refresh, the fresh-CIDR feed accelerates detection content authoring. Programs that reach Level 3 without a specialised platform are running on higher hunter-hours-per-hunt costs. Level 4+ programs typically justify platform investment on those cost economics rather than on capability enablement.
How do we handle Hunt-Debt that has already accumulated over years?
The same way you handle years of accumulated Technical Debt — you do not repay it retrospectively. You establish the Finalize discipline going forward, and you triage the highest-value historical hunts for retroactive Finalize as a separate one-time project (typically 4-8 weeks, done by a senior hunter reviewing the previous year’s Findings archive). Do not delay establishing the forward-looking discipline in order to catch up on the historical backlog; the compounding advantage of forward Finalize is larger than the retroactive-cleanup benefit.
Should we publish our maturity score externally?
Selectively. Cyber-insurance underwriters, regulators, and enterprise customers of your organisation may credit a documented Level-3+ score as a risk-reduction factor. Peer CISO networks will discuss scores comparatively. Public publication (blog post · conference talk) of your maturity level is a reputational asset if the score is genuinely earned. Do not publish an aspirational or over-generous self-score; it will be discovered and undermines credibility.
What is the single-biggest structural change most Level-2 programs need to make?
Change the ticket-workflow so that a hunt cannot be closed until the five Finalize deliverables (or explicit justified skips) are attached. Everything else follows. As long as Finalize is optional, it will be skipped. As long as it is a ticket-close gate, it will be produced. Architectural, not motivational.
Where does this document go next?
The TaHiTI series is now complete with this fourth document. Future doctrine work at HackForLab CTI will address adjacent maturity concerns — cross-team integration patterns beyond hunt-program scope, sector-specific maturity variations, and Level-5-to-Level-5-plus (yet un-named) frontier patterns. Bookmark huntintel.hackforlab.com for continuous updates.
15 · Risk Register Language for Enterprise Risk Management
Ready-to-Paste ERM Register Entry · Hunt-Debt as a Named Risk Category
Below is drafted language for direct paste into your organisation’s Enterprise Risk Management register. Written to survive audit scrutiny — every assertion traceable to the empirical evidence in this document.
The organisation’s threat-hunting program executes hunts on a documented cadence but does not consistently produce the five Finalize deliverables (Findings Log · Detection Content · Runbook Update · Threat-Model Update · Backlog Re-Score) required to convert per-hunt effort into compounding organisational capability. This produces Hunt-Debt — the accumulated cost of un-finalized hunts denominated in re-work hours, missed detection coverage, and organisational memory loss over subsequent quarters. Hunt-Debt has three empirical properties: (a) it compounds at a 3-8× re-work multiplier over the two quarters following incurrence, (b) it is structurally silent until it surfaces (no immediate operational signal), and (c) it decays organisational memory at approximately a 6-month half-life. Left unaddressed, Hunt-Debt causes the hunt program to plateau at Level 2 on the TaHiTI Maturity Doctrine scale (Sept 2026 · HackForLab CTI), with individually competent hunts producing no compounding capability. Risk owner: CISO. Review cadence: quarterly. Treatment plan: 90-Day TaHiTI Maturity Playbook (documented separately) targeting L2-to-L3 transition, followed by continuous Compounding Ratio metric surveillance.
Empirical evidence across September 2026 threat intelligence corpus indicates the adversary-pressure environment relevant to the organisation’s threat model has shifted meaningfully — 51 concurrent named APT / Threat-Actor clusters observed in an 18-day window, elevated concurrent-ransomware-operator counts (57), and sustained multi-week baseline shifts in APT concurrency (documented in weekly threat advisories Aug 24-30 through Sept 7-13, 2026). The hunt program’s resourcing model, backlog prioritisation, and metric baselines were sized against the prior operating baseline and are now understood to be operating at approximately 45-55% coverage against the current baseline. Risk owner: CISO. Review cadence: monthly through Q1 2027. Treatment plan: reprice CTI-hunting capacity in FY27 budget cycle; interim mitigations via 90-Day Playbook progression targeting L3+ maturity.
Draft register-entry language above may be adapted to your organisation’s ERM taxonomy. Risk IDs are illustrative and should be replaced with your register’s numbering scheme. HackForLab CTI Research can provide additional documentary evidence to support audit review — contact the platform for enterprise-tier access.
Take the self-assessment inside the operator console
The HuntIntel operator console at huntintel.hackforlab.com hosts the interactive version of the 30-question TaHiTI self-assessment, with automated scoring, per-dimension breakdown, and a 90-day playbook generator tuned to your baseline score.
16 · Adversary-Type Targeted Hunt Playbook · Why TaHiTI Turns Threat-Actor / C2 / Ransomware Detection Proactive
The prior 15 sections establish the framework, the maturity model, and the program-build path. This section is the practitioner-grade playbook: how a TaHiTI-native program actually hunts each of the three dominant adversary types (Threat Actor · Command-and-Control · Ransomware) and why the structured investigation-abstract discipline converts each from reactive detection into proactive defence.
The three sub-templates below are directly derived from the September 1-18 empirical basis. Each template surfaces (a) the September signal for that adversary type, (b) the reactive-detection gap that leaves programs blind, (c) the TaHiTI investigation-abstract template that produces proactive coverage, and (d) the top MITRE ATT&CK techniques to hunt for. All adversary references are anonymised; no operational tradecraft is exposed.
Proactive Hunting versus Reactive Detection · The Structural Difference
Reactive Detection Only
- Threat intelligence lands as IOC list · SIEM matches fire · SOC triages
- Coverage is reactive to what the vendor / feed ships
- Adversary evolution outpaces detection-content ship cycle
- Novel TTPs discovered post-incident, in the post-mortem
- Hunt-Debt accumulates because no hunt-driven detection ships
- Program capability = threat-feed subscription capability
TaHiTI-Native Proactive Hunting
- Threat intelligence becomes hypothesis → investigation abstract
- Coverage is proactive against adversary-type behavioural pattern
- Hunt outputs ship detection content that catches variants forever
- Novel TTPs surface during hunt, before the incident happens
- Hunt-Debt paid down because every hunt produces the 5 Finalize artefacts
- Program capability = organisation-specific compounding defence
Hunting 51 Concurrent APT / Threat-Actor Clusters
51 concurrent named clusters. 27 targeted industries. 24 distinct TTP patterns. Nation-state-adjacent tradecraft. If your organisation’s threat model intersects any of these clusters, they are hunting you right now — reactively responding after the incident is at least a quarter too late.
The Threat Actor adversary type surfaced 2,177 IOCs from 51 concurrent named clusters in an 18-day window. Multiple clusters ran multi-industry targeting patterns — pharmaceutical, defence, government, technology, financial services, cryptocurrency, aerospace, telecommunications simultaneously. The TTP distribution is broad: 24 distinct MITRE ATT&CK techniques observed across the cluster set, ranging from reconnaissance (T1595 · 239 events) through initial access (T1078 Valid Accounts · 207 events) through impact (T1486 Data Encrypted · 37 events).
// TOP TTPs TO HUNT · Threat-Actor tier · Sept 2026
// TaHiTI INVESTIGATION-ABSTRACT TEMPLATE · Threat Actor / APT
Hunting Scaled C2 Infrastructure — 6 Operators · 5.78M IOCs
Six operators produced 5.78 million command-and-control IOCs in 18 days — one operator alone contributed over 53,000. That is a fresh C2 address every ~12 seconds sustained. Reactive IP-blocking loses this race by two orders of magnitude. The only viable defence is proactive hunting against the CIDR density signal.
The C2 adversary type surfaced 5,784,707 IOCs from only 6 concurrent named operators — extreme upper-tier concentration. One dominant operator (Cluster A01 in prior weekly advisories) alone contributed 53,342 IOCs sustained across the window. TTP distribution is narrow but high-volume: T1071.001 (Web-Protocol C2 · 716 events), T1105 (Ingress Tool Transfer · 716 events), T1547.001 (Boot Autostart · 652 events), T1041 (Exfil over C2 · 507 events). The pattern indicates infrastructure-as-a-service C2 rental pipelines — mature operators renting fresh network addresses to downstream affiliates at industrial cadence.
// TOP TTPs TO HUNT · C2 tier · Sept 2026
// TaHiTI INVESTIGATION-ABSTRACT TEMPLATE · Command-and-Control
Hunting 57 Concurrent Fragmented Ransomware Operators — 100% Single-Day Burst Pattern
57 concurrent ransomware operators. 36 distinct MITRE techniques. Every single operator ran single-day burst deployments — no sustained multi-day campaigns to observe. Family-signature detection fails architecturally at this fragmentation. The only viable defence is behavioural-cascade hunting on the pre-encryption sequence.
The Ransomware adversary type surfaced 611 IOCs from 57 concurrent named operators across 36 distinct MITRE ATT&CK techniques in 18 days. Average IOC batch per operator: only 10.7. All 57 operators showed a single-day burst deployment pattern; zero operators sustained multi-day campaigns visible in the window. The affiliate-model economy is deliberately structured for many-small-operators — each affiliate rents core encryption tooling from an upstream ransomware-as-a-service brand, deploys against a specific target in a compressed window, and rotates families across cycles. The TTP surface is broad and hits every kill-chain phase: T1486 Data Encrypted for Impact (356), T1490 Inhibit Recovery (290), T1078 Valid Accounts (232), T1190 Public-App Exploit (215), T1562.001 Impair Defenses (189), T1657 Financial Theft (188), T1566 Phishing (145).
// TOP TTPs TO HUNT · Ransomware tier · Sept 2026
// TaHiTI INVESTIGATION-ABSTRACT TEMPLATE · Ransomware Cascade
Cross-Cutting Observation · The Fragmentation-to-Concentration Spectrum
The three adversary-type templates above illustrate a spectrum that every hunt program needs to internalise:
- Threat Actor / APT tier · sits at “focused hypothesis” end — 51 concurrent named clusters, each with tradecraft distinct enough to hunt individually. TaHiTI investigation-abstract discipline is the load-bearing mechanism. One abstract per intersecting cluster; per-cluster hunt outcomes.
- C2 tier · sits at “scaled infrastructure” end — 6 concurrent operators producing millions of IOCs. Per-IOC hunting is architecturally hopeless. The load-bearing mechanism is CIDR-density enforcement fed by an operator-aware attribution feed. One hunt · one rule · one CIDR feed catches almost the entire operator’s output.
- Ransomware tier · sits at “fragmented affiliate” end — 57 concurrent operators, all single-day bursts, no sustained campaigns to observe. Per-family detection fails architecturally. The load-bearing mechanism is cross-family behavioural-cascade detection. One rule · covers 57 operators · continues covering the 200 that surface next quarter.
A TaHiTI-native program at Level 3+ has all three postures live in production simultaneously — hypothesis-based per-cluster hunting for APTs, CIDR-density enforcement for C2, behavioural-cascade rules for ransomware. A Level 1 or Level 2 program has, at best, threat-feed IOC ingestion against all three — which is architecturally wrong for all three. The maturity investment is not just about “more hunts;” it is about architecturally-correct detection posture per adversary type.
17 · Frequently Asked (CISO) Questions
Is TaHiTI still the right framework in 2026, or should we adopt something newer?
TaHiTI remains the right framework for hunt-program maturity in 2026. Newer frameworks address adjacent problems (adversary-informed detection engineering, cross-team hunt coordination, AI-assisted hunting) but do not replace TaHiTI’s phase model. The right framework for a mature program is TaHiTI + supplementary frameworks for the specific adjacent problems that matter to your organisation.
How does this doctrine interact with our existing NIST CSF / ISO 27001 / SOC 2 attestations?
TaHiTI Maturity provides substantive content for the “Detect” and “Respond” function areas of NIST CSF, and for the operational-security control areas of ISO 27001 and SOC 2. A documented Level-3+ program is defensible auditor-facing evidence of active threat-detection capability that generic control-catalog language cannot provide. This is often the strongest ROI justification for maturity investment when compliance is the sponsor.
What if our organisation is small and cannot support a full TaHiTI program?
Level 1 is a legitimate program level for small organisations. The Level-1 characteristics (IOC-list ingestion + SIEM matching + SOC alert triage) are appropriate for organisations without dedicated hunt-team capacity. Do not force higher-level infrastructure onto a program that does not have the operating capacity for it — Level-2-in-name-only is worse than Level 1 because it consumes capacity without producing capability.
Is Hunt-Debt genuinely a new concept, or a repackaging of Technical Debt?
Structurally, Hunt-Debt shares the compounding-cost dynamic of Technical Debt but has different specific properties (the 6-month organisational-memory half-life is unique to threat-hunting; Technical Debt does not have equivalent memory decay). More importantly, having a named vocabulary for hunt-specific debt is what enables the ERM-register wording in Section 15 — Technical Debt language does not translate into board-risk-committee wording for hunt-program-specific risk. The naming is the operational value.
How much should a hunt-program-maturity investment cost?
Rough operator-grade estimate: reaching Level 3 from Level 1 with a 2-5 hunter team requires 3-5% of the organisation’s total cyber-security budget for one quarter (the 90-day playbook window) followed by 1-2% of total cyber budget as sustained annual cost. Level 4 and Level 5 have variable cost profiles depending on cross-team integration scope. These numbers vary by organisation size and industry — treat as directional, not precise.
What is the single-most defensible ROI argument for reaching Level 3+?
The Compounding Ratio metric. A program producing 0.8-1.5 detection-content artefacts per hunt executed (Level 3 range) yields measurably faster MTTD improvement over subsequent quarters than programs at 0 – 0.3 (Level 2 range). Concrete organisation-specific numbers vary, but the direction is monotonic and empirically observable. The MTTD improvement itself has direct business-value translation (incident cost reduction, insurance premium mitigation, regulator credibility).
Does this doctrine work for hunt programs that use MSSPs rather than in-house teams?
Yes, with adaptation. MSSP-run hunt programs typically operate at Level 2 by default because the MSSP contract structure does not incentivise Finalize discipline — the MSSP is paid for hunt execution, not for organisational-capability compounding. Reaching Level 3+ with an MSSP requires either (a) contract-language changes that credit Finalize-deliverable production, or (b) in-house program-owner role that performs Finalize on MSSP-executed hunts. Both are feasible; both require organisational commitment beyond the standard MSSP procurement pattern.
Where can I access the interactive version of the self-assessment?
The HuntIntel operator console at huntintel.hackforlab.com hosts an interactive version with automated scoring, per-dimension breakdown, and a 90-day playbook generator tuned to your baseline. Enterprise-tier features include benchmarking against sector peers and multi-year maturity-trend visualisation.
How do I get my team on the HackForLab CTI briefing distribution?
Weekly threat advisories publish every Sunday at hackforlab.com under the Threat Intelligence category. Doctrine documents (like this one) publish quarterly or on-demand when the doctrine work warrants publication. RSS feed available for the category; bookmark the operator console for continuous intelligence between briefings.
18 · Close
Hunt programs plateau at Level 2 because Finalize is treated as paperwork. Programs that reach Level 3 treat Finalize as investment. Programs that reach Level 4+ measure their own maturity as a leading indicator. Programs that reach Level 5 make the CISO’s operating posture indistinguishable from the hunt-program’s output.
The 30-question self-assessment (Section 06) produces a defensible score. The 90-day playbook (Section 09) provides the concrete week-by-week milestones to move up one or two levels. The Risk Register wording (Section 15) makes the investment defensible in ERM terms. Together these three artefacts — model, scorecard, playbook — comprise the missing operational layer on top of the TaHiTI framework itself.
Hunt-Debt is the vocabulary. The Maturity Doctrine is the framework. The playbook is the path. Nothing about this is aspirational; every element is derived from operator-grade patterns observed across real hunt-program engagements.
The TaHiTI Doctrine · Complete Series
- Part 1 · The TaHiTI Investigation Abstract — Initialize-phase deep-dive
- Part 2 · Stop Searching, Start Hunting — full hunt-program walkthrough
- Part 3 · The TaHiTI Finalize Doctrine — the compounding thesis
- Part 4 · The TaHiTI Maturity Doctrine (this document) — model, scorecard, playbook
Cite this document as: HackForLab CTI Research. “The TaHiTI Maturity Doctrine · 5 Levels · Self-Assessment · 90-Day Playbook.” 2026. huntintel.hackforlab.com.










