HTF™ Methodology

The threats have evolved.
Our defenses must too.

HTF Comparison Panel
Conventional AML vs. Hybrid Threat Finance™
Conventional AML
  • Detects transaction patterns
  • Three-stage typology model
  • Asks: what happened?
  • Static rules, manual updates
  • Optimized for audit trail
HTF™ Methodology
  • Maps actor behavior
  • Five-stage criminal lifecycle
  • Asks: who is behind it?
  • Dynamic, continuously updated
  • Optimized for identifying crime
Hybrid Threat Finance™ (HTF) is Section 2’s proprietary framework for detecting
and investigating financial crime. It is the study of how specific threat networks use money and financial products in their operations — translating criminal business
models into intelligence that organizations can act on.
The HTF™ Criminal Lifecycle
Five stages. One complete picture.

Where conventional AML models stop at three stages — Placement, Layering, Integration — HTF™ maps five. This expanded framework captures the full operational arc of a criminal financial enterprise, from the first dollar earned to the infrastructure that keeps it running.

01
Revenue Generation
Where the criminal lifecycle begins
HTF™ Addition Collapse ▲

The first stage maps the illicit income streams that initiate the financial crime lifecycle. This includes the primary criminal activity — drug trafficking, cybercrime, fraud — and the mechanisms through which value is first extracted. HTF™ analysis at this stage identifies the revenue model of the criminal enterprise, not just the transactions it generates.

Cash-intensive business patterns Structured deposits Point-of-sale manipulation Crypto on-ramps Trade invoice fraud
02
Placement
How value enters the financial system
Expand ▼

The second stage traces how illicit value first enters the financial system. HTF™ maps the organizational structure and actor network facilitating placement — not just the transactions themselves — enabling earlier detection at the point of entry.

Correspondent banking chains Shell company layers Cross-border wires Crypto mixing Hawala networks
03
Layering
Where illicit value is obscured and moved
Expand ▼

The third stage detects asset movement across jurisdictions and instruments — the mechanisms through which criminal actors obscure the origin of funds while preserving and protecting accumulated value through real estate, commodities, securities, and other vehicles.

Real estate acquisitions Commodity holdings Investment accounts Luxury asset purchases Trust structures
04
Integration
Transforming illicit value into legitimate appearance
Expand ▼

The fourth stage maps the mechanisms through which illicit value is converted into apparently legitimate form. HTF™ analysis identifies the specific conversion vehicles used and the actor networks that facilitate them — enabling earlier detection before the money fully disappears into the legitimate economy.

Business revenue inflation Loan-back schemes Asset resale Crypto off-ramps Invoice manipulation
05
Operational Sustainment
The financial infrastructure that keeps the enterprise running
HTF™ Addition Expand ▼

The fifth stage — unique to HTF™ — identifies the financial infrastructure that sustains ongoing criminal operations. This is the stage conventional AML doesn't see: the procurement of operational resources, the payment of criminal network personnel, and the reinvestment of proceeds into expanding criminal capacity. Detecting this stage enables proactive interdiction before the next revenue generation cycle begins.

Operational procurement Network compensation Reinvestment patterns Corruption payments Counter-surveillance spend
Not a Replacement — An Intelligence Layer
Hybrid Threat Finance™ (HTF™) Taxonomy makes your existing infrastructure dramatically more effective.

Rather than replacing your existing detection infrastructure, TENet™,built on Hybrid Threat Central and powered by the HTF™ Taxonomy, acts as the intelligence layer that makes it dramatically more effective. TENet injects dynamic, human-intelligence-derived signals directly into your existing AML detection engines.

The result: your rules engines and ML models stop generating noise from patterns they were never trained to see and start producing case-quality alerts derived from threat signals grounded in how criminal enterprises actually operate.

Explore the Platform →
HTC™ Integration Architecture
Your Existing AML Platform
Napier · Actimize · Verafin · Others
↕ API / SFTP
TENet™ Intelligence Layer
HTC™ powered · Daily updates
↕ Intelligence Feed
ML Models & Rules Engines
Enriched signals
↓ Output
Case - Candidates & SAR Narratives
Via HTF Assist™
Analyst & FIU Impact
Connect your analysts to real investigative impact.

By using the HTF™ investigation methodology and surfacing case-quality alerts, your team gains a clear understanding of the individuals involved and the nature of the potential crime — not just a transaction flag without context.

Through a structured, intelligence-led process and feedback loops, your FIU begins to see the true impact of its work — and builds an increasingly sophisticated picture of the threat networks operating in your institution's risk environment.

01
Transform noise into actionable signals
HTF™-enriched detection converts high-volume, low-quality alerts into a smaller set of case-ready signals grounded in documented criminal typologies.
02
Understand who is behind the transaction
Actor-centric investigation surfaces the organizational network behind flagged activity — enabling investigators to build cases, not just file SARs.
03
Build a defensible, exam-ready program
HTF™ methodology alignment provides the documented framework regulators expect — and the investigative depth that demonstrates genuine program sophistication.
HTF™ in Practice
Human Trafficking
Link payment patterns to exploitation

Detect trafficking by linking payment patterns, recruitment activity, and travel data through HTF™ behavioral typologies.

Drug Networks
Map the financial supply chain

Trace revenue generation through obfuscation and storage to identify the full financial infrastructure of trafficking organizations.

Sanctions Evasion
Identify actors, not just accounts

Surface the organizational networks behind sanctions evasion — shell companies, front entities, and their beneficial owners.

Nation State Finance
Detect strategic financial abuse

Identify state-sponsored laundering, kleptocracy networks, and adversarial nations weaponizing financial infrastructure.

See how HTF™ powers Hybrid Threat Central™ in practice.

A 30-minute demo will show you how the HTF™ methodology translates into detection intelligence — and what it would produce against your alert queue.