sydney
@letswastetime.bsky.social
📤 139
📥 42
📝 89
| search "thrunter" | eval specialty="Purple Team, Treat Hunter, Lifting Heavy Things"
November’s
@thorcollective.bsky.social
Dispatch Debrief is live with SCADA weirdness, Taylor’s Version SOC vibes, and purple team chaos. Come thrunt with us.
dispatch.thorcollective.com/p/dispatch-d...
11 days ago
1
0
0
reposted by
sydney
16 days ago
🚨New post on @THOR_Collective Dispatch🚨 “Aligning Risk Management and Threat-Informed Defense Practices (Part 2)” by Micah VanFossen What happens when you sync risk, controls, and threat intel to drive real-security outcomes.
dispatch.thorcollective.com/p/aligning-r...
#thrunting
#grc
loading . . .
Aligning Risk Management and Threat-Informed Defense Practices (Part 2)
We’re back with part two of a series analyzing how to align common GRC tasks/teams with SecOps and threat-informed defense practices.
https://dispatch.thorcollective.com/p/aligning-risk-management-and-threat-a55
0
2
1
reposted by
sydney
18 days ago
🚨New post on @THOR_Collective Dispatch🚨 Purple teaming isn’t shiny. It’s delays, blockers, tickets & pivots. And that’s okay.
open.substack.com/pub/thorcoll...
#thrunting
#PurpleTeaming
loading . . .
Purple Teaming in the Real World: When Everything Goes Off the Rails (and That’s Normal)
People love the glossy version of purple teaming:
https://open.substack.com/pub/thorcollective/p/purple-teaming-in-the-real-world?r=56ij68&utm_campaign=post&utm_medium=web&showWelcomeOnShare=true
0
1
1
Have you ever run the best hunt of your life and then forget how two weeks later? Same. Meet the PEAK Threat Hunting Template. Built to make your hunts repeatable, reviewable, and impossible to lose. 👉 Read on THOR Collective Dispatch -
dispatch.thorcollective.com/p/the-peak-t...
23 days ago
1
1
0
🎤 The Autonomous SOC (Taylor’s Version) Guest post with
@kassafras09.bsky.social
AI hype is loud. Most teams are just automating chaos. Fix the basics first. Then scale the magic. Read it on
@thorcollective.bsky.social
Dispatch.
dispatch.thorcollective.com/p/the-autono...
loading . . .
The Autonomous SOC (Taylor’s Version)
Opening Act: Welcome to the SOC Show
https://dispatch.thorcollective.com/p/the-autonomous-soc-taylors-version
25 days ago
1
1
0
In the latest
@thorcollective.bsky.social
guest post, Sam Hanson breaks down two TTP-driven hunts — KurtLar_SCADA and a weird .NET Modbus binary — proving simple hypotheses > chasing IOCs. IOCs show where the fire was. TTPs show where it will be.
dispatch.thorcollective.com/p/hunting-be...
loading . . .
https://dispatch.thorcollective.com/p/hunting-beyond-indicators-part-2
30 days ago
1
1
0
October delivered AI agents, time mastery, and purple team curveballs. From scaling hunts like code to aligning GRC with threat-informed defense, this month’s Dispatch lineup from
@thorcollective.bsky.social
hit every layer of the stack. Full recap here:
dispatch.thorcollective.com/p/dispatch-d...
loading . . .
Dispatch Debrief: October 2025
Seven Dispatch drops that prove hunting smarter beats hunting harder.
https://dispatch.thorcollective.com/p/dispatch-debrief-october-2025
about 1 month ago
1
2
1
Finding nothing ≠ failing the hunt. Sometimes “nothing” is the loudest signal that your defenses worked.
@jotunvillur.bsky.social
breaks down how to measure the quiet wins in in one of my favorite
@thorcollective.bsky.social
Dispatch posts:
dispatch.thorcollective.com/p/measuring-...
loading . . .
Measuring the Hunt When You Find “Nothing”
Because sometimes success looks like silence.
https://dispatch.thorcollective.com/p/measuring-the-hunt-when-you-find
about 1 month ago
0
0
0
In this week’s
@thorcollective.bsky.social
Dispatch, Sam Hanson lays out how to move beyond indicator-based hunting and build detection muscle that actually scales. 👉
dispatch.thorcollective.com/p/hunting-be...
about 2 months ago
1
1
1
If tstats gives you speed and eventstats gives you context...timechart gives you shape. This week’s
@thorcollective.bsky.social
SPL Dispatch breaks down how to use timechart to uncover rhythm, automation, and the a cron job masquerading as “normal.”
dispatch.thorcollective.com/p/the-shape-...
loading . . .
https://dispatch.thorcollective.com/p/the-shape-of-time-mastering-timechart
about 2 months ago
1
1
1
Threat hunting falls apart when your “docs” live in Slack threads. Part 2 of the
@thorcollective.bsky.social
Dispatch Agentic Threat Hunting series covers the first step to scaling: put your hunts in a GitHub repo and give your AI bestie memory.
dispatch.thorcollective.com/p/agentic-th...
2 months ago
1
2
2
✨ To get you ready for Taylor Swift’s latest album… ✨ 🎶 Check out Life of a Detection Girl - a playlist I created inspired by Taylor Swift and Alex Hurtado, with a touch of cyber woven in. Give it a listen and let me know your favorite track!
suno.com/playlist/5cf...
loading . . .
Life of a Detection Girl by @letswastetime | Suno
✨ inspo by alex hurtado & taylor swift ✨
https://suno.com/playlist/5cf27de7-59ba-493b-861a-e37088af7909
2 months ago
0
0
0
reposted by
sydney
LP
2 months ago
We at
@thorcollective.bsky.social
are waking you up before September ends, because a new Ask-a-Thrunt3r episode just dropped with: 2K subscriber milestone 🎉 15 baseline examples The great data vs. data debate Plus: Is Git the future of hunting collab? 🎧:
dispatch.thorcollective.com/p/ask-a-thru...
loading . . .
Ask-a-Thrunt3r: September 2025 Recap 🐏
Mainly ramblings. And maybe some wisdom.
https://dispatch.thorcollective.com/p/ask-a-thrunt3r-september-2025-recap
0
2
2
From temporal to behavioral, baselines are the thrunter’s compass. September’s Dispatch from
@thorcollective.bsky.social
shows how to use them to sharpen the hunt and includes ten baseline hunts you should be running now. 🔗
dispatch.thorcollective.com/p/dispatch-d...
2 months ago
1
3
2
reposted by
sydney
LP
2 months ago
You can’t find weird if you don’t know normal.
@thorcollective.bsky.social
just dropped 10 baseline hunts you can shine in the dark parts of your env and magnify the adversaries from the noise. Join us for all the thrunting 👉:
open.substack.com/pub/thorcoll...
#threathunting
#infosec
0
2
2
✨ Representation is STILL a security issue. ✨
@thorcollective.bsky.social
Dispatch with
@kassafras09.bsky.social
from March. The message still stands. • Fix biased job reqs • Put diverse voices on panels • Mentor future hackers • Model inclusive leadership
dispatch.thorcollective.com/p/why-we-nee...
loading . . .
Why We Need More Women and Intersectional Diversity in Cyber (And How to Get There)
Representation matters in cybersecurity. Here’s why—and what we can do about it.
https://dispatch.thorcollective.com/p/why-we-need-more-women-and-intersectional-diversity-in-cyber
3 months ago
1
2
1
Cybersecurity needs more than hackers in hoodies. In this week’s
@thorcollective.bsky.social
Dispatch, Courtney Shar shares how project management skills like risk alignment, process design, and team coordination directly strengthen security programs. 👉
dispatch.thorcollective.com/p/beyond-hac...
loading . . .
https://dispatch.thorcollective.com/p/beyond-hackers-in-hoodies
3 months ago
1
6
3
reposted by
sydney
3 months ago
🚨New post on
@thorcollective.bsky.social
Dispatch 🚨 Certis Foster didn't hunt for it. It revealed itself. The key? Plotting behavior in 3D space: 🕒 Time 🗺️ Terrain 🎯 Behavior Outliers can’t hide in 3D.
dispatch.thorcollective.com/p/cant-hide-...
#threathunting
#thrunting
#THORcollective
loading . . .
Can't Hide in 3D
In a sea of millions of security events, one workstation literally stood out, floating high above all the others when I transformed flat logs into a 3D visualization.
https://dispatch.thorcollective.com/p/cant-hide-in-3d
0
1
1
If you don’t know what “normal” looks like in your environment, you’re not hunting...you’re hoping. Our latest
@thorcollective.bsky.social
Dispatch post breaks down 5 baselines every thrunter needs. Map normal. Track drift. Catch threats. Read here:
dispatch.thorcollective.com/p/you-cant-f...
loading . . .
You Can't Find Weird If You Don't Know Normal
Five baselines with hunt queries you can run today
https://dispatch.thorcollective.com/p/you-cant-find-weird-if-you-dont-know-normal
3 months ago
1
2
1
Summertime sadness hit the Dispatch hard: sunscreen > screen time. 🌞 But the hunts never stopped, and this month we’re back with fresh chaos, AI wisdom, and a noob’s-eye view of DEF CON. 👉 Catch the
@thorcollective.bsky.social
August Dispatch:
dispatch.thorcollective.com/p/dispatch-d...
3 months ago
1
1
1
The Quiet War isn’t loud breaches or ransomware. It’s subtle. AI-driven adversaries are blending in and evading detection. Hunters must shift: hunt intent, not just indicators. 👉 New guest post by Damien Lewke on
@thorcollective.bsky.social
Dispatch:
dispatch.thorcollective.com/p/the-quiet-...
4 months ago
0
1
1
What happens when you throw yourself into DEFCON for the very first time? You get Line Con, Noob Village wisdom, hacker merch battles, Flipper Zero impulse buys, Hacker Jeopardy chaos, and the realization that DEFCON is not just a con, it is a community.
dispatch.thorcollective.com/p/my-first-d...
4 months ago
1
3
1
It’s here! 🎉
@dr-fett.bsky.social
and I coauthored The Threat Hunter’s Cookbook and we’re thrilled to finally share it. Built for defenders at every level with hunting methods from simple filtering to advanced clustering. 👉 Get the eBook:
www.splunk.com/en_us/form/t...
loading . . .
Introducing… The Threat Hunter’s Cookbook! | Splunk
The security experts on the SURGe team have released The Threat Hunter’s Cookbook, a hands-on guide for security practitioners that features actionable insights into threat hunting methods,…
https://www.splunk.com/en_us/blog/security/threat-hunters-cookbook-guide.html
4 months ago
1
1
0
The Hacker Summer Camp starter pack: ⚡ Stickers ⚡ Patches ⚡ Coins ⚡ Wristbands ⚡ Temporary THRUNT tattoos Find the
@thorcollective.bsky.social
crew in Vegas. Say hi and get some swag 👀
4 months ago
1
1
1
reposted by
sydney
THOR Collective
4 months ago
Shoutout to our fam Elipscion, who's spinning live at DEF CON 33 this Friday at 8pm on the DEF CON stage. 🎧 Listen here:
open.spotify.com/artist/2tgPZ...
🔥 Join our
@thorcollective.bsky.social
meetup during his set. Say hi, talk hunts, and grab some free swag. See you there!
loading . . .
ELIPSCION
Artist · 10 monthly listeners.
https://open.spotify.com/artist/2tgPZpjIPEU2ZbfEE0C6dM?si=sSSrwkgaQky2PF2hT_lbHw
1
3
3
🌵 Calm before the Hacker Summer Camp storm. July’s Dispatch Debrief is light on posts, heavy on hot takes — from agentic AI to making pentest findings sting. Catch up before Vegas 👉
dispatch.thorcollective.com/p/dispatch-d...
loading . . .
Dispatch Debrief: July 2025
Consider this the calm before the Hacker Summer Camp storm.
https://dispatch.thorcollective.com/p/dispatch-debrief-july-2025
4 months ago
1
1
1
Threat hunting is broken. We can’t out-query adversaries who automate everything. Enter the agentic threat hunter. An AI that thinks, hypothesizes, investigates, and scales. In the latest
@thorcollective.bsky.social
Dispatch, we explore this shift: 📌
dispatch.thorcollective.com/p/the-agenti...
4 months ago
1
3
3
Heading to hacker summer camp? I wrote a survival guide for DEF CON, Black Hat, etc. - Pick your purpose - Villages > talks - Hallway track is real - You belong here 👽
dispatch.thorcollective.com/p/con-101-ho...
@thorcollective.bsky.social
will be out there with thrunting stickers—come say hi.
4 months ago
1
2
1
reposted by
sydney
THOR Collective
5 months ago
We’re giving away another THOR Collective Challenge Coin. Ask-a-Thrunter drops early August (recording July 31). Hacker Summer Camp vibes guaranteed. 🎟️ Join our paid sub for giveaways + Discord. 💬 Questions? Drop ’em.
radio.thorcollective.com
loading . . .
Redirecting…
If you’re not redirected, click here.
https://radio.thorcollective.com/
1
1
1
New from
@thorcollective.bsky.social
Dispatch: If You Like It Then You Should’ve Put a timechart on It We’re diving into why timechart is a threat hunter’s best friend. From beaconing to privilege spikes, baselines, and more. Read it here 👉
dispatch.thorcollective.com/p/if-you-lik...
loading . . .
If You Like It Then You Should've Put a timechart on It
Hey thrunters, gather ’round: timechart’s up
https://dispatch.thorcollective.com/p/if-you-like-it-then-you-shouldve-put-a-timechart-on-it
5 months ago
1
3
3
The Threat Hunter’s Cookbook drops at
#BlackHat
! Huge thanks to my co-author
@dr-fett.bsky.social
for bringing this project to life and
@meansec.bsky.social
for the forward. Come celebrate with
#SURGe
and grab a signed copy at
#Splunk’s
After Party! 🖤
splunk.swoogo.com/splunkafterp...
loading . . .
Home
Splunk AfterParty and Book Signing with Co-Sponsors Cisco and Contrast Security
https://splunk.swoogo.com/splunkafterpartyBH
5 months ago
1
5
2
reposted by
sydney
THOR Collective
5 months ago
No
@thorcollective.bsky.social
Dispatch posts this week. We’re taking a breather to rest and recharge. We'll be back next week, ready to thrunt.
#threathunting
#thrunting
#THORcollective
#cybersecurity
#infosec
0
1
1
THRUNTING isn’t just a buzzword. It’s a mindset. 🐑 Inspired by Tim Peters’ 19 aphorisms for Python,
@thorcollective.bsky.social
Dispatch introduces "The Zen of Thrunting."
dispatch.thorcollective.com/p/the-zen-of...
Stay curious. Happy thrunting.
loading . . .
The Zen of Thrunting
Abstract
https://dispatch.thorcollective.com/p/the-zen-of-thrunting
5 months ago
1
4
3
Dispatch Debrief: June 2025 Everything’s fine… until it isn’t. This month’s
@thorcollective.bsky.social
Dispatch served up a spicy mix of threat hunting, plugin paranoia, purple teaming insights, and a few thrunting curveballs to keep you sharp. 🌶️
dispatch.thorcollective.com/p/dispatch-d...
loading . . .
Dispatch Debrief: June 2025
Because "Everything's Fine" is Just Another Way of Saying "I Haven't Looked Yet"
https://dispatch.thorcollective.com/p/dispatch-debrief-june-2025
5 months ago
1
3
2
🔌 That browser extension? That IDE plugin? Might not be doing what you think. New on
@thorcollective.bsky.social
Dispatch: five hunt ideas + a PEAK deep dive into sneaky plugin abuse. Start with visibility. Hunt what blends in. 📖
dispatch.thorcollective.com/p/your-plugi...
loading . . .
Your Plugins and Extensions Are (Probably) Fine. Hunt Them Anyway.
Five hunt ideas (and one deep dive) for abuse hiding in plain sight.
https://dispatch.thorcollective.com/p/your-plugins-and-extensions-are-probably-fine
5 months ago
1
2
2
New guest post on
thorcollective.bsky.social
Dispatch from
infosecsherpa.bsky.social
: Don’t Let Mis(s) Information Take the Crown 👑 This post shows how to apply the Intelligence Cycle to news and help you filter bias. Read it here:
dispatch.thorcollective.com/p/dont-let-m...
loading . . .
Don't Let Mis(s) Information Take the Crown
Sherpa Intelligence: Your Guide Up a Mountain of Information!
https://dispatch.thorcollective.com/p/dont-let-miss-information-take-the-crown
6 months ago
1
4
4
reposted by
sydney
THOR Collective
6 months ago
#thrunting
#thrunt
#threathunting
#THORcollective
#infosec
#cybersecurity
0
1
1
reposted by
sydney
THOR Collective
6 months ago
This month’s Dispatch Giveaway is live! 🔥 One lucky paid subscriber will win a
thorcollective.bsky.social
challenge coin! 🗓️ June 26 @ 7PM PT Streaming live in our private Discord Podcast drops for everyone the following week ➡️ Join the Collective:
dispatch.thorcollective.com
loading . . .
THOR Collective Dispatch | Sydney Marrone | Substack
A hub for threat hunters (thrunters) and security professionals. Explore cutting-edge ideas, practical frameworks, and community-driven insights in cybersecurity. Powered by collaboration,…
https://dispatch.thorcollective.com
1
2
1
reposted by
sydney
LP
6 months ago
⚡ New
@thorcollective.bsky.social
Dispatch drop No hallucinations here. Just TTPs that quietly defined Q1 2025. 🔐 OAuth abuse 📦 Malicious packages 🖥️ SimpleHelp RMM exploits Stay ahead with what to hunt & where to look. 👉
dispatch.thorcollective.com/p/from-the-f...
#THORCollective
#threathunting
loading . . .
From the Fire: Q1FY25
TTPs that sparked, spread, and still burn for those paying attention.
https://dispatch.thorcollective.com/p/from-the-fire-q1fy25
0
4
3
reposted by
sydney
6 months ago
🚨 New post on
@thorcollective.bsky.social
Dispatch🚨 Red with Benefits: Purple Teaming with Sliver Beacons Sliver isn’t just for flexing during pentests, it’s your new favorite detection engineering wingman. 👇
dispatch.thorcollective.com/p/red-with-b...
loading . . .
Red with Benefits: Purple Teaming with Sliver Beacons
How to turn a modern post-exploitation tool into your next detection engineering best friend.
https://dispatch.thorcollective.com/p/red-with-benefits-purple-teaming
0
1
1
The May Dispatch is live. Fresh insights from
@thorcollective.bsky.social
and guest contributors on detection in depth, AI in the SOC, career overlaps, and making your hunts actually matter. Plus memes. Obviously. 👉
dispatch.thorcollective.com/p/dispatch-d...
loading . . .
Dispatch Debrief: May 2025
Quiet logs, loud analysts, and AI besties. Just another month in the hunt.
https://dispatch.thorcollective.com/p/dispatch-debrief-may-2025
6 months ago
1
3
2
reposted by
sydney
LP
6 months ago
✨ New THOR Collective post ✨ Introducing Threat Hunting Relevancy Factors (THRF!) These factors can help you create relevant hunts and tangible impact for your organization. Show your business that you mean bzns. 📈 Join us at 👉:
dispatch.thorcollective.com/p/threat-hun...
#threathunting
loading . . .
Making Your Hunts Matter: Introducing Threat Hunting Relevancy Factors
Don’t just hunt, hunt with purpose.
https://dispatch.thorcollective.com/p/threat-hunting-relevancy-factors
0
5
4
reposted by
sydney
THOR Collective
7 months ago
🐏 Ask a Thrunter AMA + Giveaway! Join
@thorcollective.bsky.social
live next THORsday, May 29th @ 7pm PT in Discord. We’ve got a special announcement + we’ll reveal the monthly giveaway winner (all paid Dispatch subscribers automatically entered!). Submit your questions early👇
0
3
2
Introverts rewrite detection rules repeatedly, while extroverts demo them mid-draft. In cybersecurity, you need both. Today's
@thorcollective.bsky.social
Dispatch features Alex Hurtado, highlighting how embracing differences strengthens SOC teams. 👉 :
dispatch.thorcollective.com/p/quiet-loud...
loading . . .
Quiet, Loud, and in the Logfiles: The Detection Duo You Didn’t Know You Needed
Filed under: Things your agent can’t do but Linda from SecOps does without breaking a sweat.
https://dispatch.thorcollective.com/p/quiet-loud-and-in-the-logfiles
7 months ago
0
1
2
reposted by
sydney
7 months ago
🚨 New guest drop on @THOR_Collective Dispatch! 🚨 "Exploring Cybersecurity Career Paths and How They Work Together" by Audra Streetman Whether you're into offense, intel, or cyber defense, there's a path for you! Read it here:
dispatch.thorcollective.com/p/exploring-...
0
2
3
💥 New SPL Dispatch drop from
@thorcollective.bsky.social
: eventstats 💥 Want to flag weird behavior without losing raw data? eventstats lets you compare each event to the group without rolling things up. Read it here 👉
dispatch.thorcollective.com/p/every-even...
loading . . .
Every Event for Itself…Until You Run eventstats
SPL Dispatch #2 - 05/13/2025
https://dispatch.thorcollective.com/p/every-event-for-itself-until-you-run-eventstats
7 months ago
1
2
2
💡 New guest drop on
@thorcollective.bsky.social
Dispatch: "Detection-in-Depth" by Day Johnson. Day covers how to build resilient detection systems that handle real-world challenges, from fine-tuning rules to threat emulation and kill chain coverage.
dispatch.thorcollective.com/p/detection-...
loading . . .
Detection-In-Depth
Eliminating detection blind spots through a multi-layered defense approach
https://dispatch.thorcollective.com/p/detection-in-depth
7 months ago
1
2
3
🎧 Ask-a-Thrunter: Episode 1 is live!
@thorcollective.bsky.social
covered everything from hunt standups to VirusTotal vs. behavioral hunting and announced our April giveaway winner! Replay:
dispatch.thorcollective.com/p/ask-a-thru...
Should we make this monthly? Drop a comment below.
loading . . .
Ask-a-Thrunter: The Recap Is Here 🐏
Mainly ramblings. And maybe some wisdom.
https://dispatch.thorcollective.com/p/ask-a-thrunter-05012025
7 months ago
1
1
1
🔥 Dispatch Debrief: April 2025 is live 🔥 Explore star sign-inspired hunting techniques, organizing your hunt squad, and the value of finding "nothing." Discover this month's insights from
@thorcollective.bsky.social
Dispatch -
dispatch.thorcollective.com/p/april-debr...
loading . . .
Dispatch Debrief: April 2025
What We Hunted, Learned, and Loved This Month
https://dispatch.thorcollective.com/p/april-debrief-2025
7 months ago
1
4
4
Ask-a-Thrunter is live this THORsday, May 1 @ 7pm PDT — paid subscribers only. Join us in the
@thorcollective.bsky.social
Discord for solid answers, spicy takes, and the April giveaway winner reveal. Drop your questions below. Not subscribed? Replay drops next week. Come thrunt with us 🐏
7 months ago
1
4
2
Load more
feeds!
log in