Summary
The session’s core message is that TaHiTI gives security teams a structured way to turn threat intelligence into concrete investigative hunting actions, especially when traditional controls may miss abuse of trusted software processes. The speakers frame threat hunting around an “assume breach” mindset: larger organizations with a security operations capability cannot only focus on keeping adversaries out, because malicious activity may already be present. They introduce TaHiTI as a methodology for targeted hunting that integrates threat intelligence, and they use the Shai Hulut 2.0 case to make the method practical rather than theoretical.
Key Topics
5 key topics from Oscar Covers, Bert-Jan Pals, Armand Piers and Hong Gie Ong at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Prioritize hunts using organization-specific intelligence requirements.
- Focus hunting on adversary behavior, not only indicators.
- Split attack chains into testable hunting hypotheses.
- Revisit hypotheses before execution when environments change.
- Map intelligence sources against gaps and overlaps.
“You have to assume they are already in, assume breach.”
Up Next

Next in agenda
ENISA Scales EU Vulnerability Services for Resilience
Stefano De Crescenzo
Also on cybersecurity
A Pragmatic Path to Continuous Purple Teaming
Cas van Cooten

Also on cybersecurity
