I published a follow-up to my THOR Collective guest post on hunting beyond Indicators of Compromise. Part 2 puts the methodology into practice with two examples from ICS/OT-focused threat hunting: KurtLar_SCADA and a strange .NET Modbus binary.
The post walks through the hypotheses that led to those discoveries, how I triaged noisy hunting results, and why evidence-based assessment matters when suspicious behavior is not enough to confidently call something ICS malware.
Give it a read if behavior-based threat hunting, ICS protocols, or weird malware-adjacent binaries are your thing.