Spamhaus Technology and abuse.ch Logo
Solutions
Data
Email & Network
Cyber Threat Intelligence
Resources
About
Back to Previous Page

Resource

A hunting platform, built with the people who hunt

Posted on
June 22, 2026
Author
Sarah Miller
Read time
3 mins

Introduction

Introduction

Have you ever felt like wrangling YARA at scale was a boss fight? Know the feeling of wanting to run a YARA rule against datasets you care about, with control over scope and guidance onsomething that guides whether expensive Sandbox time should be used? Then you’ll know that tooling for this is patchier than it should be.

We're building a CTI hunting platform to address these challenges and more. We're also wanting to ensure it solves real-life problems, so we’re building it with input from a small group of experienced YARA rule writers, who already live in this workflow, and understand the challenges we want to fix.

The CTI platform that you can help shape

While we’re keeping specific details under wraps for now, our team has developed a robust concept to resolve the challenges we, and many others in the community, frequently encounter. This platform directly addresses the common frustrations shared by hunters across various forums and events.

Some of the challenges this platform will solve:

  • For Detection Engineers: Scaling detection is broken. You are hampered by slow performance, restrictive queue limits, and prohibitively expensive retrohunts, all while lacking the necessary control to scope what is actually being scanned.

  • For SOC / MDR Analysts: Results are too noisy to be actionable. Without rule validation, platforms are flooded with false positives and inefficient rules that degrade performance, making it nearly impossible to distinguish true threats from noise.

  • For CTI Specialists & Independent Researchers: A match is not the same as intelligence. A YARA hit only tells you "this file looks like X," forcing you to rely on separate tools and manual reverse engineering to extract the critical C2 infrastructure, configurations, and campaign context required to respond.

Now, we acknowledge we’re not explaining how we’re going to solve these challenges. But hopefully we’ve piqued your interest enough to learn more? If so, keep reading to see how to get involved and influence the solution’s MVP and ongoing roadmap.

Joining the Founding Research Partners

It’d be fair to say that our CTI Focus Unit working on this is at the top of its game. But it’s your real-world experience that will challenge their solution and put it to the test, validate value against your most cited pain points, and help ensure the right functionality is being prioritised.

What you get:

  • Direct input into a platform you'll actually use. Not focus-group input - design-partner input, on workflows, capabilities, the governance model, and what we cut.

  • Early access when the MVP ships (early 2027), through a structured beta.

  • Honest visibility into the build process. We'll tell you what we're doing, why, and what's not making it in.

What we're not promising:

  • A free production tier in perpetuity. We don't know what the commercial model looks like yet; we're not going to pretend we do.

  • That every piece of feedback gets shipped. We'll tell you why, when it doesn't.

  • The MVP will be polished. It won't. That's the point.

Want to be considered?

Complete this contact form, select “Other” and someone from our team will be in touch. Heads-up - there will be a screening form as part of this process - it’s approx twenty questions, and will take about ten minutes. Some are quick (org, contact, time zone); some are deeper (how you run YARA at scale, what breaks in your workflow etc). It’s to ensure the fit is right for both sides.

That’s everything you need to know - we look forward to working together.