LP
@jotunvillur.bsky.social
📤 179
📥 50
📝 30
Ultrarunner with a powerlifting problem. Sometimes I do cybersecurity.
reposted by
LP
sydney
2 months ago
Threat hunting falls apart when your “docs” live in Slack threads. Part 2 of the
@thorcollective.bsky.social
Dispatch Agentic Threat Hunting series covers the first step to scaling: put your hunts in a GitHub repo and give your AI bestie memory.
dispatch.thorcollective.com/p/agentic-th...
1
2
2
We at
@thorcollective.bsky.social
are waking you up before September ends, because a new Ask-a-Thrunt3r episode just dropped with: 2K subscriber milestone 🎉 15 baseline examples The great data vs. data debate Plus: Is Git the future of hunting collab? 🎧:
dispatch.thorcollective.com/p/ask-a-thru...
loading . . .
Ask-a-Thrunt3r: September 2025 Recap 🐏
Mainly ramblings. And maybe some wisdom.
https://dispatch.thorcollective.com/p/ask-a-thrunt3r-september-2025-recap
2 months ago
0
2
2
You can’t find weird if you don’t know normal.
@thorcollective.bsky.social
just dropped 10 baseline hunts you can shine in the dark parts of your env and magnify the adversaries from the noise. Join us for all the thrunting 👉:
open.substack.com/pub/thorcoll...
#threathunting
#infosec
2 months ago
0
2
2
reposted by
LP
sydney
3 months ago
Cybersecurity needs more than hackers in hoodies. In this week’s
@thorcollective.bsky.social
Dispatch, Courtney Shar shares how project management skills like risk alignment, process design, and team coordination directly strengthen security programs. 👉
dispatch.thorcollective.com/p/beyond-hac...
loading . . .
https://dispatch.thorcollective.com/p/beyond-hackers-in-hoodies
1
6
3
🚨 Think your browser extensions are harmless? Join
@johntuckner.me
for
@thorcollective.bsky.social
and learn how to hunt the dangerous ones before they hunt you:
thorcollective.substack.com/p/even-if-ma...
#cybersecurity
#infosec
#threathunting
#thrunting
loading . . .
Even if many plugins are fine, the bad ones are BAD
Sydney recently wrote a great piece about extensions and hunting for IDE plugins.
https://thorcollective.substack.com/p/even-if-many-plugins-are-fine-the
3 months ago
0
3
2
reposted by
LP
tuckner
3 months ago
Not subscribed to the THOR Collective Dispatch yet? You might've missed my guest piece on hunting for bad browser extensions. Check if the extension your CFO installed to change text to Comic Sans is also taking screenshots of his Salesforce reports.
dispatch.thorcollective.com/p/even-if-ma...
0
2
1
📻 Ask a Thrunt3r August is here! DEF CON wisdom unlocked: 🔓 Why your SecOps model isn't working anymore 🎯 Supply chain attacks via AI coding tools 🛠️ One tool @THOR_Collective wishes you knew about (hint: it's Sliver)
dispatch.thorcollective.com/p/ask-a-thru...
#threathunting
#cybersecurity
loading . . .
Ask-a-Thrunt3r: August 2025 Recap 🐏
Mainly ramblings. And maybe some wisdom.
https://dispatch.thorcollective.com/p/ask-a-thrunt3r-august-2025-recap
3 months ago
0
3
1
reposted by
LP
tuckner
3 months ago
Six malicious extensions listed in Cursor and hosted on Open VSX. All are squatting on other packages and are showing above the safe versions they target.
2
15
6
reposted by
LP
Ben Goerz
4 months ago
If you are around DEF CON today, join me at 5pm for “Sh*t Show Triage: An Honest Panel on Incident Response”
btv-dc33.sessionize.com/session/966539
loading . . .
Sh*t Show Triage: An Honest Panel on Incident Response
You can start with the best intentions, solid tools, and all the right policies, but what happens when your network moves from “effing around” straight into “finding out”? Join a panel of variously tr...
https://btv-dc33.sessionize.com/session/966539
0
3
1
reposted by
LP
THOR Collective
4 months ago
Shoutout to our fam Elipscion, who's spinning live at DEF CON 33 this Friday at 8pm on the DEF CON stage. 🎧 Listen here:
open.spotify.com/artist/2tgPZ...
🔥 Join our
@thorcollective.bsky.social
meetup during his set. Say hi, talk hunts, and grab some free swag. See you there!
loading . . .
ELIPSCION
Artist · 10 monthly listeners.
https://open.spotify.com/artist/2tgPZpjIPEU2ZbfEE0C6dM?si=sSSrwkgaQky2PF2hT_lbHw
1
3
3
reposted by
LP
archwisp
4 months ago
Oh hey! Did I mention I’m speaking on Saturday? I’ll be in track 1 at 2:30!
defcon.org/html/defcon-...
loading . . .
DEF CON® Hacking Conference - Speakers
https://defcon.org/html/defcon-33/dc-33-speakers.html
1
3
2
reposted by
LP
sydney
4 months ago
🌵 Calm before the Hacker Summer Camp storm. July’s Dispatch Debrief is light on posts, heavy on hot takes — from agentic AI to making pentest findings sting. Catch up before Vegas 👉
dispatch.thorcollective.com/p/dispatch-d...
loading . . .
Dispatch Debrief: July 2025
Consider this the calm before the Hacker Summer Camp storm.
https://dispatch.thorcollective.com/p/dispatch-debrief-july-2025
1
1
1
reposted by
LP
sydney
4 months ago
Threat hunting is broken. We can’t out-query adversaries who automate everything. Enter the agentic threat hunter. An AI that thinks, hypothesizes, investigates, and scales. In the latest
@thorcollective.bsky.social
Dispatch, we explore this shift: 📌
dispatch.thorcollective.com/p/the-agenti...
1
3
3
reposted by
LP
Ann Johnson
5 months ago
msrc.microsoft.com/blog/2025/07...
Microsoft is aware of active attacks targeting on-premises SharePoint Server customers. The attacks are exploiting a variant of CVE-2025-49706. This vulnerability has been assigned CVE-2025-53770. SharePoint Online in Microsoft 365 is not impacted
loading . . .
Customer guidance for SharePoint vulnerability CVE-2025-53770 | MSRC Blog | Microsoft Security Response Center
Customer guidance for SharePoint vulnerability CVE-2025-53770
https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/
0
11
4
reposted by
LP
sydney
5 months ago
THRUNTING isn’t just a buzzword. It’s a mindset. 🐑 Inspired by Tim Peters’ 19 aphorisms for Python,
@thorcollective.bsky.social
Dispatch introduces "The Zen of Thrunting."
dispatch.thorcollective.com/p/the-zen-of...
Stay curious. Happy thrunting.
loading . . .
The Zen of Thrunting
Abstract
https://dispatch.thorcollective.com/p/the-zen-of-thrunting
1
4
3
reposted by
LP
sydney
6 months ago
🔌 That browser extension? That IDE plugin? Might not be doing what you think. New on
@thorcollective.bsky.social
Dispatch: five hunt ideas + a PEAK deep dive into sneaky plugin abuse. Start with visibility. Hunt what blends in. 📖
dispatch.thorcollective.com/p/your-plugi...
loading . . .
Your Plugins and Extensions Are (Probably) Fine. Hunt Them Anyway.
Five hunt ideas (and one deep dive) for abuse hiding in plain sight.
https://dispatch.thorcollective.com/p/your-plugins-and-extensions-are-probably-fine
1
2
2
reposted by
LP
sydney
6 months ago
New guest post on
thorcollective.bsky.social
Dispatch from
infosecsherpa.bsky.social
: Don’t Let Mis(s) Information Take the Crown 👑 This post shows how to apply the Intelligence Cycle to news and help you filter bias. Read it here:
dispatch.thorcollective.com/p/dont-let-m...
loading . . .
Don't Let Mis(s) Information Take the Crown
Sherpa Intelligence: Your Guide Up a Mountain of Information!
https://dispatch.thorcollective.com/p/dont-let-miss-information-take-the-crown
1
4
4
⚡ New
@thorcollective.bsky.social
Dispatch drop No hallucinations here. Just TTPs that quietly defined Q1 2025. 🔐 OAuth abuse 📦 Malicious packages 🖥️ SimpleHelp RMM exploits Stay ahead with what to hunt & where to look. 👉
dispatch.thorcollective.com/p/from-the-f...
#THORCollective
#threathunting
loading . . .
From the Fire: Q1FY25
TTPs that sparked, spread, and still burn for those paying attention.
https://dispatch.thorcollective.com/p/from-the-fire-q1fy25
6 months ago
0
4
3
✨ New THOR Collective post ✨ Introducing Threat Hunting Relevancy Factors (THRF!) These factors can help you create relevant hunts and tangible impact for your organization. Show your business that you mean bzns. 📈 Join us at 👉:
dispatch.thorcollective.com/p/threat-hun...
#threathunting
loading . . .
Making Your Hunts Matter: Introducing Threat Hunting Relevancy Factors
Don’t just hunt, hunt with purpose.
https://dispatch.thorcollective.com/p/threat-hunting-relevancy-factors
6 months ago
0
5
4
reposted by
LP
THOR Collective
7 months ago
🐏 Ask a Thrunter AMA + Giveaway! Join
@thorcollective.bsky.social
live next THORsday, May 29th @ 7pm PT in Discord. We’ve got a special announcement + we’ll reveal the monthly giveaway winner (all paid Dispatch subscribers automatically entered!). Submit your questions early👇
0
3
2
reposted by
LP
sydney
7 months ago
Introverts rewrite detection rules repeatedly, while extroverts demo them mid-draft. In cybersecurity, you need both. Today's
@thorcollective.bsky.social
Dispatch features Alex Hurtado, highlighting how embracing differences strengthens SOC teams. 👉 :
dispatch.thorcollective.com/p/quiet-loud...
loading . . .
Quiet, Loud, and in the Logfiles: The Detection Duo You Didn’t Know You Needed
Filed under: Things your agent can’t do but Linda from SecOps does without breaking a sweat.
https://dispatch.thorcollective.com/p/quiet-loud-and-in-the-logfiles
0
1
2
Sierra Ferrell, yeehaw! 🤠
7 months ago
0
0
0
reposted by
LP
7 months ago
🚨 New guest drop on @THOR_Collective Dispatch! 🚨 "Exploring Cybersecurity Career Paths and How They Work Together" by Audra Streetman Whether you're into offense, intel, or cyber defense, there's a path for you! Read it here:
dispatch.thorcollective.com/p/exploring-...
0
2
3
reposted by
LP
sydney
7 months ago
💡 New guest drop on
@thorcollective.bsky.social
Dispatch: "Detection-in-Depth" by Day Johnson. Day covers how to build resilient detection systems that handle real-world challenges, from fine-tuning rules to threat emulation and kill chain coverage.
dispatch.thorcollective.com/p/detection-...
loading . . .
Detection-In-Depth
Eliminating detection blind spots through a multi-layered defense approach
https://dispatch.thorcollective.com/p/detection-in-depth
1
2
3
reposted by
LP
sydney
7 months ago
🔥 Dispatch Debrief: April 2025 is live 🔥 Explore star sign-inspired hunting techniques, organizing your hunt squad, and the value of finding "nothing." Discover this month's insights from
@thorcollective.bsky.social
Dispatch -
dispatch.thorcollective.com/p/april-debr...
loading . . .
Dispatch Debrief: April 2025
What We Hunted, Learned, and Loved This Month
https://dispatch.thorcollective.com/p/april-debrief-2025
1
4
4
reposted by
LP
sydney
7 months ago
Ask-a-Thrunter is live this THORsday, May 1 @ 7pm PDT — paid subscribers only. Join us in the
@thorcollective.bsky.social
Discord for solid answers, spicy takes, and the April giveaway winner reveal. Drop your questions below. Not subscribed? Replay drops next week. Come thrunt with us 🐏
1
4
2
reposted by
LP
Andrew Morris
8 months ago
TL;DR - Attackers still use these old ass vulns because they're STILL WORKING
www.greynoise.io/blog/greynoi...
loading . . .
GreyNoise Uncovers Unique Risks From Resurgent Cybersecurity Vulnerabilities
Attackers from every corner of the internet are exploiting a uniquely dangerous class of cyber flaws: resurgent vulnerabilities.
https://www.greynoise.io/blog/greynoise-uncovers-unique-risks-from-resurgent-cybersecurity-vulnerabilities
1
19
10
reposted by
LP
sydney
8 months ago
When incidents hit, how you communicate shapes the outcome. This week’s
@thorcollective.bsky.social
Dispatch features
@audrastreetman.bsky.social
, former journalist turned cyber intel analyst.
dispatch.thorcollective.com/p/how-commun...
loading . . .
How Communication Shapes the Outcome of Cybersecurity Incidents
Why the timing and transparency of messaging can make or break your incident response
https://dispatch.thorcollective.com/p/how-communication-shapes-the-outcome
1
5
3
This is my final campaign gift to my party and I highly recommend Hieu!
add a skeleton here at some point
8 months ago
0
3
0
reposted by
LP
It's Just Hieu
8 months ago
Group artwork for a DnD party. Tyranny of Dragons 🐉👿🧙
#illustration
#drawing
1
87
19
reposted by
LP
8 months ago
Simulate. Detect. Tune. Repeat
dispatch.thorcollective.com/p/simulate-d...
loading . . .
Simulate. Detect. Tune. Repeat
Purple Teaming with Atomic Red Team and ATT&CK
https://dispatch.thorcollective.com/p/simulate-detect-tune-repeat?r=56ij68&utm_campaign=post&utm_medium=web&showWelcomeOnShare=false
0
2
2
reposted by
LP
sydney
8 months ago
@thorcollective.bsky.social
Dispatch time! Part 2 is live of
@cyb3rhawk.bsky.social
's post on the LAYER approach! This discusses using real BlackBasta leak data to guide smarter, more targeted hunts.
dispatch.thorcollective.com/p/the-power-...
loading . . .
The Power of Trio - Part 2
Practical Implementation of the LAYER approach
https://dispatch.thorcollective.com/p/the-power-of-the-trio-part-2
0
2
3
✨Did you feel something shift in the universe? It’s a new THOR post.✨ Twelve signs. Twelve threat patterns. One cosmic thrunt shift. Join us for an evidence based article on the zodiac signs as threat hunts.
dispatch.thorcollective.com/p/the-threat...
#threathunting
#thrunting
#THORCollective
loading . . .
https://dispatch.thorcollective.com/p/the-threat-hunts-in-our-stars…
8 months ago
0
4
1
Getting the urge to try a new hobby again. Maybe it’s time for… golf?
9 months ago
0
0
0
reposted by
LP
sydney
9 months ago
🚨 New Dispatch Drop 🚨 Attackers will get in—just give them time. In this week's
@thorcollective.bsky.social
Dispatch, we talk why security teams must test their defenses:
dispatch.thorcollective.com/p/why-cybers...
#threathunting
#thrunting
#cybersecurity
#infosec
#purpleteam
#THORcollective
loading . . .
Why Cybersecurity Teams Need to Break Their Own Defenses
If you’re not testing your security, you don’t have security.
https://dispatch.thorcollective.com/p/why-cybersecurity-teams-need-to-test
0
2
2
reposted by
LP
sydney
9 months ago
🚨 New THOR Collective Dispatch post 🚨 In Part 5 of
@jotunvillur.bsky.social
and my DEATHCon Thrunting Workshop series, we use advanced data analysis to find threats in HTTP datasets. Full post here:
dispatch.thorcollective.com/p/a-deathcon...
#infosec
#threathunting
#thrunting
#THORCollective
loading . . .
A DEATHCON Thrunting Workshop Overview Part 5: Model-Assisted Threat Hunting (M-ATH)
Machine learning, statistics, and HTTP events…oh my!
https://dispatch.thorcollective.com/p/a-deathcon-thrunting-workshop-overview-a4b
0
1
1
reposted by
LP
sydney
10 months ago
Tired of getting ghosted by endless events? The five-number summary is your threat-hunting sidekick. Check out our latest
@thorcollective.bsky.social
Dispatch. Join us👉:
dispatch.thorcollective.com/p/stop-chasi...
#threathunting
#thrunting
#cybersecurity
#mathiscool
#THORCollective
loading . . .
Stop Chasing Ghosts: How Five-Number Summaries Reveal Real Anomalies
Boo. No séance required.
https://dispatch.thorcollective.com/p/stop-chasing-ghosts-how-five-number
0
2
2
🚀 THOR Collective Drop! 🚀 We’re back with pt 4 of the thrunting workshop series
@letswastetime.bsky.social
and I led at DEATHCon! We’re diving into baseline hunting & the fun you’ll find when you shine a light in places you haven’t before. 🔦 Join us at:
dispatch.thorcollective.com/p/a-deathcon...
loading . . .
A DEATHCON Thrunting Workshop Overview Part 4: Baseline Hunting
Detecting normal versus abnormal applications in your environment
https://dispatch.thorcollective.com/p/a-deathcon-thrunting-workshop-overview-pt4
10 months ago
0
1
1
reposted by
LP
sydney
10 months ago
🐘 Let’s address the elephant in the room —
#thrunting
is a thing now, and it stuck. Why? Because thrunting has that perfect blend of
#hacker
culture & "I dare you to question this term" energy. 🔥 Keep thrunting. 👉
dispatch.thorcollective.com/p/the-case-f...
#threathunting
#cybersecurity
#infosec
loading . . .
The Case for Thrunting
Why Thrunting Is Here to Stay
https://dispatch.thorcollective.com/p/the-case-for-thrunting
1
3
3
reposted by
LP
sydney
10 months ago
@thorcollective.bsky.social
dropped part two of
@jotunvillur.bsky.social
and my
@deathcon.io
workshop blog series on
#threathunting
with the
#PEAK
framework. 🎯 Check it out at:
dispatch.thorcollective.com/p/a-deathcon...
#cybersecurity
#thrunting
#THORCollective
loading . . .
A DEATHCON Thrunting Workshop Overview Part 2: Exploring Data Sources
aka index=* 'thrunting'
https://dispatch.thorcollective.com/p/a-deathcon-thrunting-workshop-overview
0
4
1
reposted by
LP
sydney
10 months ago
🚀 Attention Thrunters!🚀 Part 3 of the DEATHCon thrunting workshop is live!
@jotunvillur.bsky.social
and I break down a hypothesis-driven scenario step by step. Grab your hammer and sharpen your skills! 🛠️ Read now:
dispatch.thorcollective.com/p/a-deathcon...
#threathunting
#thrunting
#cybersecurity
loading . . .
A DEATHCON Thrunting Workshop Overview Part 3: ⚡ Hypothesis-Driven Threat Hunting
Detecting /etc/passwd File Access and Exfiltration in HTTP Traffic
https://dispatch.thorcollective.com/p/a-deathcon-thrunting-workshop-overview-part-3
0
3
2
@thorcollective.bsky.social
dropped a new blog "Helloooooooo, Thrunters!" 😤 It kicks off a series from a workshop
@letswastetime.bsky.social
and I gave at
#DEATHCon
on
#threathunting
with the PEAK framework. Read at:
thorcollective.com/helloooooooo...
#cybersecurity
#thrunting
#THORCollective
loading . . .
Helloooooooo thrunters 👋
A DEATHCON Thrunting Workshop Overview
https://thorcollective.com/helloooooooo-thrunters-c654b3c88ccb
10 months ago
0
4
3
reposted by
LP
sydney
10 months ago
@thorcollective.bsky.social
dropped a new blog "Helloooooooo, Thrunters!" 😤 It kicks off a series from a workshop
@jotunvillur.bsky.social
and I gave at
#DEATHCon
on
#threathunting
with the PEAK framework. Start reading:
thorcollective.com/helloooooooo...
#cybersecurity
#thrunting
#THORCollective
loading . . .
Helloooooooo thrunters 👋
A DEATHCON Thrunting Workshop Overview
https://thorcollective.com/helloooooooo-thrunters-c654b3c88ccb
0
3
2
This was such an amazing event. Definitely will be back!
add a skeleton here at some point
11 months ago
0
2
2
reposted by
LP
Hackers on the Hill
11 months ago
Thank you to the dozens of volunteers and ambassadors who helped plan, set up, and run Hackers on the Hill this year, as well as the ~150 hackers who attended and the 20+ staffers who were gracious enough to host us (many on a day their office was officially closed). ❤️ A few special thank yous
3
14
11
reposted by
LP
tuckner
11 months ago
Up to 13 confirmed extensions with the same behaviors as Cyberhaven. Right now over 670,000 users with these related extensions installed. Some have been patched, some removed from the web store. Including dates so folks can understand timelines.
1
3
2
reposted by
LP
tuckner
11 months ago
Tracking an additional 8 confirmed extensions with similar attack code to the Cyberhaven incident dating back to July 17th so this is not a single occurrence. Continuing to update here:
secureannex.com/blog/cyberha...
loading . . .
Cyberhaven Extension Compromise
How the Cyberhaven extension was compromised and what it means for your organization.
https://secureannex.com/blog/cyberhaven-extension-compromise/
0
4
3
Don’t forget to leave a pcap and memory dump out for the SOC Analysts tonight.
12 months ago
1
4
2
Powerlifting training has begun. Let’s get strong.
over 2 years ago
0
3
0
Load more
feeds!
log in