Sign in

drterdnugget.bsky.social

@drterdnugget.bsky.social
5 followers 11 following 9 posts
PostsRepliesMedia
Reposted by @drterdnugget.bsky.social
sydney @letswastetime.bsky.social · 27/01/2026
You don’t need a desk to build. I used AI more from my phone last month than from my desk. What mattered was removing friction and building where ideas show up. 👉 New on @thorcollective.bsky.social Dispatch: dispatch.thorcollective.com/p/you-dont-n...
111
Reposted by @drterdnugget.bsky.social
sydney @letswastetime.bsky.social · 20/01/2026
“I’m not a developer” is a self-imposed limit. If you’ve written a query, a script, or an automation to fix a problem, you’re already building. In the latest @thorcollective.bsky.social Dispatch, we talk about why building is a core security skill. dispatch.thorcollective.com/p/why-you-sh...
111
drterdnugget.bsky.social @drterdnugget.bsky.social · 20/11/2025
🚨New post on @THOR_Collective Dispatch🚨 “Aligning Risk Management and Threat-Informed Defense Practices (Part 2)” by Micah VanFossen What happens when you sync risk, controls, and threat intel to drive real-security outcomes. dispatch.thorcollective.com/p/aligning-r... #thrunting #grc
dispatch.thorcollective.com
Aligning Risk Management and Threat-Informed Defense Practices (Part 2)
We’re back with part two of a series analyzing how to align common GRC tasks/teams with SecOps and threat-informed defense practices.
021
drterdnugget.bsky.social @drterdnugget.bsky.social · 18/11/2025
🚨New post on @THOR_Collective Dispatch🚨 Purple teaming isn’t shiny. It’s delays, blockers, tickets & pivots. And that’s okay. open.substack.com/pub/thorcoll... #thrunting #PurpleTeaming
open.substack.com
Purple Teaming in the Real World: When Everything Goes Off the Rails (and That’s Normal)
People love the glossy version of purple teaming:
011
drterdnugget.bsky.social @drterdnugget.bsky.social · 14/10/2025
🚨New post on @THOR_Collective Dispatch🚨 Meet Sliver Armory BOFs. Tiny in-memory payloads you run from a beacon to test technique-based detections, not filenames. Cleaner telemetry, repeatable tests, real thrunting value. Read here: dispatch.thorcollective.com/p/sliver-bof...
dispatch.thorcollective.com
Sliver BOFs in Action: Bringing Sliver Armory BOFs to Purple Teaming
When I first wrote about Sliver beacons in purple teaming, the point was simple: implants aren’t just red-team toys, they’re teaching tools for defenders.
000
Reposted by @drterdnugget.bsky.social
sydney @letswastetime.bsky.social · 09/10/2025
In this week’s @thorcollective.bsky.social Dispatch, Sam Hanson lays out how to move beyond indicator-based hunting and build detection muscle that actually scales. 👉 dispatch.thorcollective.com/p/hunting-be...
111
Reposted by @drterdnugget.bsky.social
sydney @letswastetime.bsky.social · 08/10/2025
If tstats gives you speed and eventstats gives you context...timechart gives you shape. This week’s @thorcollective.bsky.social SPL Dispatch breaks down how to use timechart to uncover rhythm, automation, and the a cron job masquerading as “normal.” dispatch.thorcollective.com/p/the-shape-...
dispatch.thorcollective.com
111
Reposted by @drterdnugget.bsky.social
sydney @letswastetime.bsky.social · 02/10/2025
Threat hunting falls apart when your “docs” live in Slack threads. Part 2 of the @thorcollective.bsky.social Dispatch Agentic Threat Hunting series covers the first step to scaling: put your hunts in a GitHub repo and give your AI bestie memory. dispatch.thorcollective.com/p/agentic-th...
122
Reposted by @drterdnugget.bsky.social
sydney @letswastetime.bsky.social · 26/09/2025
From temporal to behavioral, baselines are the thrunter’s compass. September’s Dispatch from @thorcollective.bsky.social shows how to use them to sharpen the hunt and includes ten baseline hunts you should be running now. 🔗 dispatch.thorcollective.com/p/dispatch-d...
132
Reposted by @drterdnugget.bsky.social
LP @jotunvillur.bsky.social · 23/09/2025
You can’t find weird if you don’t know normal. @thorcollective.bsky.social just dropped 10 baseline hunts you can shine in the dark parts of your env and magnify the adversaries from the noise. Join us for all the thrunting 👉: open.substack.com/pub/thorcoll... #threathunting #infosec
022
Reposted by @drterdnugget.bsky.social
sydney @letswastetime.bsky.social · 16/09/2025
Cybersecurity needs more than hackers in hoodies. In this week’s @thorcollective.bsky.social Dispatch, Courtney Shar shares how project management skills like risk alignment, process design, and team coordination directly strengthen security programs. 👉 dispatch.thorcollective.com/p/beyond-hac...
dispatch.thorcollective.com
163
Reposted by @drterdnugget.bsky.social
LP @jotunvillur.bsky.social · 12/09/2025
🚨 Think your browser extensions are harmless? Join @johntuckner.me for @thorcollective.bsky.social and learn how to hunt the dangerous ones before they hunt you: thorcollective.substack.com/p/even-if-ma... #cybersecurity #infosec #threathunting #thrunting
thorcollective.substack.com
Even if many plugins are fine, the bad ones are BAD
Sydney recently wrote a great piece about extensions and hunting for IDE plugins.
032
drterdnugget.bsky.social @drterdnugget.bsky.social · 05/09/2025
🚨New post on @thorcollective.bsky.social Dispatch 🚨 Certis Foster didn't hunt for it. It revealed itself. The key? Plotting behavior in 3D space: 🕒 Time 🗺️ Terrain 🎯 Behavior Outliers can’t hide in 3D. dispatch.thorcollective.com/p/cant-hide-... #threathunting #thrunting #THORcollective
dispatch.thorcollective.com
Can't Hide in 3D
In a sea of millions of security events, one workstation literally stood out, floating high above all the others when I transformed flat logs into a 3D visualization.
011
Reposted by @drterdnugget.bsky.social
sydney @letswastetime.bsky.social · 02/09/2025
If you don’t know what “normal” looks like in your environment, you’re not hunting...you’re hoping. Our latest @thorcollective.bsky.social Dispatch post breaks down 5 baselines every thrunter needs. Map normal. Track drift. Catch threats. Read here: dispatch.thorcollective.com/p/you-cant-f...
dispatch.thorcollective.com
You Can't Find Weird If You Don't Know Normal
Five baselines with hunt queries you can run today
121
Reposted by @drterdnugget.bsky.social
sydney @letswastetime.bsky.social · 28/08/2025
Summertime sadness hit the Dispatch hard: sunscreen > screen time. 🌞 But the hunts never stopped, and this month we’re back with fresh chaos, AI wisdom, and a noob’s-eye view of DEF CON. 👉 Catch the @thorcollective.bsky.social August Dispatch: dispatch.thorcollective.com/p/dispatch-d...
111
Reposted by @drterdnugget.bsky.social
sydney @letswastetime.bsky.social · 21/08/2025
The Quiet War isn’t loud breaches or ransomware. It’s subtle. AI-driven adversaries are blending in and evading detection. Hunters must shift: hunt intent, not just indicators. 👉 New guest post by Damien Lewke on @thorcollective.bsky.social Dispatch: dispatch.thorcollective.com/p/the-quiet-...
011
Reposted by @drterdnugget.bsky.social
sydney @letswastetime.bsky.social · 19/08/2025
What happens when you throw yourself into DEFCON for the very first time? You get Line Con, Noob Village wisdom, hacker merch battles, Flipper Zero impulse buys, Hacker Jeopardy chaos, and the realization that DEFCON is not just a con, it is a community. dispatch.thorcollective.com/p/my-first-d...
131
Reposted by @drterdnugget.bsky.social
THOR Collective @thorcollective.bsky.social · 04/08/2025
Shoutout to our fam Elipscion, who's spinning live at DEF CON 33 this Friday at 8pm on the DEF CON stage. 🎧 Listen here: open.spotify.com/artist/2tgPZ... 🔥 Join our @thorcollective.bsky.social meetup during his set. Say hi, talk hunts, and grab some free swag. See you there!
open.spotify.com
ELIPSCION
Artist · 10 monthly listeners.
133
Reposted by @drterdnugget.bsky.social
sydney @letswastetime.bsky.social · 27/07/2025
Threat hunting is broken. We can’t out-query adversaries who automate everything. Enter the agentic threat hunter. An AI that thinks, hypothesizes, investigates, and scales. In the latest @thorcollective.bsky.social Dispatch, we explore this shift: 📌 dispatch.thorcollective.com/p/the-agenti...
133
Reposted by @drterdnugget.bsky.social
sydney @letswastetime.bsky.social · 24/07/2025
Heading to hacker summer camp? I wrote a survival guide for DEF CON, Black Hat, etc. - Pick your purpose - Villages > talks - Hallway track is real - You belong here 👽 dispatch.thorcollective.com/p/con-101-ho... @thorcollective.bsky.social will be out there with thrunting stickers—come say hi.
121
drterdnugget.bsky.social @drterdnugget.bsky.social · 22/07/2025
🚨New post on @thorcollective.bsky.social Dispatch🚨 Tired of getting ignored after dropping a valid XSS vuln? Stop showing alert(1) pop-ups & start stealing sessions. Make it real. Bring a bit of pain. Read it here 👉 open.substack.com/pub/thorcoll...
open.substack.com
Make It Hurt (a Little): Why Showing Real Impact in Pentest Findings Matters
“Cool alert box, bro. Now what?”
011
Reposted by @drterdnugget.bsky.social
sydney @letswastetime.bsky.social · 15/07/2025
New from @thorcollective.bsky.social Dispatch: If You Like It Then You Should’ve Put a timechart on It We’re diving into why timechart is a threat hunter’s best friend. From beaconing to privilege spikes, baselines, and more. Read it here 👉 dispatch.thorcollective.com/p/if-you-lik...
dispatch.thorcollective.com
If You Like It Then You Should've Put a timechart on It
Hey thrunters, gather ’round: timechart’s up
133
Reposted by @drterdnugget.bsky.social
sydney @letswastetime.bsky.social · 03/07/2025
THRUNTING isn’t just a buzzword. It’s a mindset. 🐑 Inspired by Tim Peters’ 19 aphorisms for Python, @thorcollective.bsky.social Dispatch introduces "The Zen of Thrunting." dispatch.thorcollective.com/p/the-zen-of... Stay curious. Happy thrunting.
dispatch.thorcollective.com
The Zen of Thrunting
Abstract
143
Reposted by @drterdnugget.bsky.social
sydney @letswastetime.bsky.social · 26/06/2025
Dispatch Debrief: June 2025 Everything’s fine… until it isn’t. This month’s @thorcollective.bsky.social Dispatch served up a spicy mix of threat hunting, plugin paranoia, purple teaming insights, and a few thrunting curveballs to keep you sharp. 🌶️ dispatch.thorcollective.com/p/dispatch-d...
dispatch.thorcollective.com
Dispatch Debrief: June 2025
Because "Everything's Fine" is Just Another Way of Saying "I Haven't Looked Yet"
132
Reposted by @drterdnugget.bsky.social
sydney @letswastetime.bsky.social · 24/06/2025
🔌 That browser extension? That IDE plugin? Might not be doing what you think. New on @thorcollective.bsky.social Dispatch: five hunt ideas + a PEAK deep dive into sneaky plugin abuse. Start with visibility. Hunt what blends in. 📖 dispatch.thorcollective.com/p/your-plugi...
dispatch.thorcollective.com
Your Plugins and Extensions Are (Probably) Fine. Hunt Them Anyway.
Five hunt ideas (and one deep dive) for abuse hiding in plain sight.
122
Reposted by @drterdnugget.bsky.social
sydney @letswastetime.bsky.social · 19/06/2025
New guest post on thorcollective.bsky.social Dispatch from infosecsherpa.bsky.social: Don’t Let Mis(s) Information Take the Crown 👑 This post shows how to apply the Intelligence Cycle to news and help you filter bias. Read it here: dispatch.thorcollective.com/p/dont-let-m...
dispatch.thorcollective.com
Don't Let Mis(s) Information Take the Crown
Sherpa Intelligence: Your Guide Up a Mountain of Information!
144
Reposted by @drterdnugget.bsky.social
LP @jotunvillur.bsky.social · 10/06/2025
⚡ New @thorcollective.bsky.social Dispatch drop No hallucinations here. Just TTPs that quietly defined Q1 2025. 🔐 OAuth abuse 📦 Malicious packages 🖥️ SimpleHelp RMM exploits Stay ahead with what to hunt & where to look. 👉 dispatch.thorcollective.com/p/from-the-f... #THORCollective #threathunting
dispatch.thorcollective.com
From the Fire: Q1FY25
TTPs that sparked, spread, and still burn for those paying attention.
043
drterdnugget.bsky.social @drterdnugget.bsky.social · 03/06/2025
🚨 New post on @thorcollective.bsky.social Dispatch🚨 Red with Benefits: Purple Teaming with Sliver Beacons Sliver isn’t just for flexing during pentests, it’s your new favorite detection engineering wingman. 👇 dispatch.thorcollective.com/p/red-with-b...
dispatch.thorcollective.com
Red with Benefits: Purple Teaming with Sliver Beacons
How to turn a modern post-exploitation tool into your next detection engineering best friend.
011
Reposted by @drterdnugget.bsky.social
sydney @letswastetime.bsky.social · 29/05/2025
The May Dispatch is live. Fresh insights from @thorcollective.bsky.social and guest contributors on detection in depth, AI in the SOC, career overlaps, and making your hunts actually matter. Plus memes. Obviously. 👉 dispatch.thorcollective.com/p/dispatch-d...
dispatch.thorcollective.com
Dispatch Debrief: May 2025
Quiet logs, loud analysts, and AI besties. Just another month in the hunt.
132
Reposted by @drterdnugget.bsky.social
LP @jotunvillur.bsky.social · 27/05/2025
✨ New THOR Collective post ✨ Introducing Threat Hunting Relevancy Factors (THRF!) These factors can help you create relevant hunts and tangible impact for your organization. Show your business that you mean bzns. 📈 Join us at 👉: dispatch.thorcollective.com/p/threat-hun... #threathunting
dispatch.thorcollective.com
Making Your Hunts Matter: Introducing Threat Hunting Relevancy Factors
Don’t just hunt, hunt with purpose.
054
drterdnugget.bsky.social @drterdnugget.bsky.social · 15/05/2025
🚨 New guest drop on @THOR_Collective Dispatch! 🚨 "Exploring Cybersecurity Career Paths and How They Work Together" by Audra Streetman Whether you're into offense, intel, or cyber defense, there's a path for you! Read it here: dispatch.thorcollective.com/p/exploring-...
023
Reposted by @drterdnugget.bsky.social
sydney @letswastetime.bsky.social · 13/05/2025
💥 New SPL Dispatch drop from @thorcollective.bsky.social : eventstats 💥 Want to flag weird behavior without losing raw data? eventstats lets you compare each event to the group without rolling things up. Read it here 👉 dispatch.thorcollective.com/p/every-even...
dispatch.thorcollective.com
Every Event for Itself…Until You Run eventstats
SPL Dispatch #2 - 05/13/2025
122
Reposted by @drterdnugget.bsky.social
sydney @letswastetime.bsky.social · 08/05/2025
💡 New guest drop on @thorcollective.bsky.social Dispatch: "Detection-in-Depth" by Day Johnson. Day covers how to build resilient detection systems that handle real-world challenges, from fine-tuning rules to threat emulation and kill chain coverage. dispatch.thorcollective.com/p/detection-...
dispatch.thorcollective.com
Detection-In-Depth
Eliminating detection blind spots through a multi-layered defense approach
123
drterdnugget.bsky.social @drterdnugget.bsky.social · 06/05/2025
🚨 New THOR Collective Dispatch 🚨 Stop the Spreadsheet Madness: Visualize Your Atomic Red Team Tests with VECTR dispatch.thorcollective.com/p/stop-the-s...
dispatch.thorcollective.com
Stop the Spreadsheet Madness: Visualize Your Atomic Red Team Tests with VECTR
A follow-up to Simulate. Detect. Tune. Repeat.
000
Reposted by @drterdnugget.bsky.social
sydney @letswastetime.bsky.social · 01/05/2025
🔥 Dispatch Debrief: April 2025 is live 🔥 Explore star sign-inspired hunting techniques, organizing your hunt squad, and the value of finding "nothing." Discover this month's insights from @thorcollective.bsky.social Dispatch - dispatch.thorcollective.com/p/april-debr...
dispatch.thorcollective.com
Dispatch Debrief: April 2025
What We Hunted, Learned, and Loved This Month
144
Reposted by @drterdnugget.bsky.social
sydney @letswastetime.bsky.social · 29/04/2025
Normal is overrated. Hunt the outliers with Z-scores and standard deviation in the new @thorcollective.bsky.social Dispatch post. Read it here: dispatch.thorcollective.com/p/z-scoring-... #threathunting #thrunting #detectionengineering #infosec #cybersecurity #splunk #statistics
dispatch.thorcollective.com
Z-Scoring Your Way to Better Threat Detection
“Normal” is just a setting on a dryer. Let’s talk about what’s actually weird in your data.
023
Reposted by @drterdnugget.bsky.social
sydney @letswastetime.bsky.social · 24/04/2025
🪦 D.E.A.T.H. comes in many forms, and so does thrunting. Check out the latest @thorcollective.bsky.social Dispatch covering three ways to implement these! dispatch.thorcollective.com/p/the-models... #threathunting #thrunting #detectionengineering #THORcollective #cybersecurity #DEATH #infosec
dispatch.thorcollective.com
The Model(s) of D.E.A.T.H & Thrunt
There Can Only (Not) Be One
022
drterdnugget.bsky.social @drterdnugget.bsky.social · 15/04/2025
Simulate. Detect. Tune. Repeat dispatch.thorcollective.com/p/simulate-d...
dispatch.thorcollective.com
Simulate. Detect. Tune. Repeat
Purple Teaming with Atomic Red Team and ATT&CK
022
Reposted by @drterdnugget.bsky.social
sydney @letswastetime.bsky.social · 11/04/2025
@thorcollective.bsky.social Dispatch time! Part 2 is live of @cyb3rhawk.bsky.social's post on the LAYER approach! This discusses using real BlackBasta leak data to guide smarter, more targeted hunts. dispatch.thorcollective.com/p/the-power-...
dispatch.thorcollective.com
The Power of Trio - Part 2
Practical Implementation of the LAYER approach
022