Sign in

Jason Faulhefer

@hamradiohef.bsky.social
1.8K followers 1.2K following 299 posts

Formerly @crypiehef on evil site. www.threatspire.com Ham radio callsign K4HEF. youtube.com/@hamradiohef ICS/OT Security CyberSecurity Professional NOSTR: npub1lqedmrj848yutt47tklvjqjyv6plsy4tsv9v9hl2pazt4l229mlsdh305c buymeacoffee.com/hamradiohef

PostsRepliesMedia
Jason Faulhefer @hamradiohef.bsky.social · 09/10/2026
Healthcare Threat Intelligence Sharing: Turning Sector Reports into Hospital Action www.threatspire.com/blog/healthc... #CyberSecurity #ThreatIntel #HealthCare
threatspire.com
Healthcare Threat Intelligence Sharing Guide
A practical workflow for turning healthcare sector reports, indicators, advisories, and peer observations into hospital detection and risk decisions.
010
Jason Faulhefer @hamradiohef.bsky.social · 08/10/2026
Medical Device Threat Intelligence: From CVE Queue to Clinical Risk www.threatspire.com/blog/medical... #CyberSecurity #ThreatIntel #Healthcare
threatspire.com
Medical Device Threat Intelligence for Clinical Risk
Learn how hospitals can turn medical device vulnerabilities, exploitation evidence, and clinical context into safe, actionable risk decisions.
000
Jason Faulhefer @hamradiohef.bsky.social · 06/10/2026
Healthcare Supply Chain Threat Intelligence: Seeing Risk Beyond the Hospital Perimeter www.threatspire.com/blog/healthc... #CyberSecurity #ThreatIntel #Healthcare
threatspire.com
Healthcare Supply Chain Threat Intelligence
Learn how hospitals can use CTI to monitor vendors, technology providers, remote access, and supply chain dependencies that affect patient care.
000
Jason Faulhefer @hamradiohef.bsky.social · 05/10/2026
Identity Threat Intelligence for Hospitals: Following the Accounts Attackers Actually Use www.threatspire.com/blog/identit... #CyberSecurity #ThreatIntel #Healthcare #Hospital #PHI
threatspire.com
Identity Threat Intelligence for Hospitals
A practical guide to using threat intelligence to prioritize clinician, vendor, privileged, service, and cloud identity risks in hospitals.
000
Jason Faulhefer @hamradiohef.bsky.social · 24/09/2026
youtu.be/nxyfBfCrbDw?... (Please watch this and follow the link in it's description to stop this war on science).
youtu.be
The Plan To Destroy Americas Oldest Natural History Museum
YouTube video by Miniminuteman
010
Jason Faulhefer @hamradiohef.bsky.social · 22/09/2026
If a hotdog isn’t a sandwich, neither is a taco. I’ll see myself out.
010
Jason Faulhefer @hamradiohef.bsky.social · 21/09/2026
www.tiktok.com/t/ZTUoDBN5n/
tiktok.com
#curruption
TikTok video by Sania
000
Jason Faulhefer @hamradiohef.bsky.social · 19/09/2026
@hankgreen.bsky.social I’ve finished all my decorations in #focusfriends. Oh no!
000
Jason Faulhefer @hamradiohef.bsky.social · 04/09/2026
ThreatSpire's Community Edition Honeypot now includes iOT protocol sensors! #CyberSecurity #ThreatIntel #Honeypot
ThreatSpire's Community Edition Honeypot Protocols included.
010
Jason Faulhefer @hamradiohef.bsky.social · 02/09/2026
Wicked awesome.
010
Jason Faulhefer @hamradiohef.bsky.social · 01/09/2026
Why Manufacturing Plants Need Threat Intelligence for OT/SCADA Security www.threatspire.com/blog/why-man... #Manufacturing #ThreatIntel #CyberSecurity #OT #SCADA
threatspire.com
Why Manufacturing Plants Need Threat Intelligence for OT/SCADA Security | ThreatSpire
Manufacturing plants run on OT and SCADA systems that were never designed for internet exposure. Learn why threat intelligence is essential for resilient production.
000
Jason Faulhefer @hamradiohef.bsky.social · 20/08/2026
SCADA Threat Intel Part 5: Intelligence Driven Response in the Control Room www.threatspire.com/blog/scada-t... #CyberSecurity #ThreatIntel #SCADA #OT
threatspire.com
SCADA Threat Intel Part 5: Intelligence Driven Response in the Control Room
How a SCADA alert becomes an assessment, an assessment becomes a safe operator action, and every incident feeds the next intelligence cycle.
001
Jason Faulhefer @hamradiohef.bsky.social · 18/08/2026
SCADA Threat Intel Part 4: Turning Intelligence Into Protocol Aware Detections www.threatspire.com/blog/scada-t... #CyberSecurity #DetectionEngineering #ThreatIntel #SCADA #OT
threatspire.com
SCADA Threat Intel Part 4: Protocol Aware Detections for SCADA
Convert adversary profiles and control network evidence into behavior based detections using protocol semantics, baselines, and consequence tiering.
001
Jason Faulhefer @hamradiohef.bsky.social · 17/08/2026
SCADA Threat Intel Part 3: The Collection Plan for Control Networks www.threatspire.com/blog/scada-t... #CyberSecurity #ThreatIntel #SCADA #Honeypots
threatspire.com
SCADA Threat Intel Part 3: The Collection Plan for Control Networks
Build a SCADA collection plan from passive taps, engineering workstation logs, remote access records, and protocol honeypots. Part three of a five part series.
000
Jason Faulhefer @hamradiohef.bsky.social · 16/08/2026
threatspire.com/tools Just released an update to our free Cyber Intel AI announcer for MacOS 26 Tahoe+ with Apple Intelligence. Feedback welcomed. #ThreatIntel
threatspire.com
Tools — Free Security Utilities | ThreatSpire
Download Cyber Announcer for macOS and let your desk read the latest cybersecurity headlines to you.
020
Jason Faulhefer @hamradiohef.bsky.social · 13/08/2026
SCADA Threat Intel Part 2: Building Adversary Profiles That Fit Your Plant www.threatspire.com/blog/scada-t... #CyberSecurity #ThreatIntel #SCADA
threatspire.com
SCADA Threat Intel Part 2: Adversary Profiles That Fit Your Plant
Turn generic ICS threat reporting into adversary profiles anchored to your devices, protocols, and access paths. Part two of a five part SCADA series.
000
Jason Faulhefer @hamradiohef.bsky.social · 11/08/2026
SCADA Threat Intel Part 1: Knowing What You Actually Operate www.threatspire.com/blog/scada-t... #ThreatIntel #CyberSecurity #SCADA
threatspire.com
SCADA Threat Intel Part 1: Knowing What You Actually Operate
Threat intelligence for SCADA only works when you know your controllers, protocols, reachability, and consequence tiers. Part one of a five part series.
011
Jason Faulhefer @hamradiohef.bsky.social · 06/08/2026
threatspire.com/tools CyberSecurity Announcer App for MacOS. Get all CyberSecurity Headlines announced to you whenever you restart or unlock your Mac. All user configurable settings, Choose your own voice. I recommend Ava (Premium) in Voice settings under Accessibility. #CyberSecurity #InfoSec
threatspire.com
Tools — Free Security Utilities | ThreatSpire
Download Cyber Announcer for macOS and let your desk read the latest cybersecurity headlines to you.
001
Jason Faulhefer @hamradiohef.bsky.social · 06/08/2026
Introducing ThreatSpire's Honeypot Community Edition for Free. threatspire.com/honeypot Be among the first to start capturing rich IOCs and TTPs to grow our deception-grid data. #CyberSecurity #ThreatIntel
threatspire.com
ThreatSpire Honeypot Community Edition — Free Download
Deploy in minutes, watch the internet attack your sensor, and contribute to a global map of community honeypots.
000
Jason Faulhefer @hamradiohef.bsky.social · 31/07/2026
Intelligence-Driven Tabletop Exercises for Water Utilities www.threatspire.com/blog/intelli... #CyberSecurity #ThreatIntel #ICS #OT #SCADA #WaterSecurity
threatspire.com
Intelligence-Driven Tabletop Exercises for Water Utilities — ThreatSpire Blog
Most water utility tabletops rehearse a generic ransomware story. Here is how to build exercises from real intelligence about your own plant, your own vendors, and your own remote access paths.
001
Jason Faulhefer @hamradiohef.bsky.social · 30/07/2026
Water Sector Supply Chain Intelligence: Integrators, Vendors, and Chemical Suppliers www.threatspire.com/blog/water-s... #CyberSecurity #ThreatIntel #CTI #OT #ICS #SCADA #Chemicals #WaterSecurity
threatspire.com
Water Sector Supply Chain Intelligence: Integrators, Vendors, and Chemical Suppliers — ThreatSpire Blog
Water utilities are reached through the integrators, panel builders, instrument techs, and chemical suppliers who touch the plant. Here is how to inventory that network, write intelligence requirement...
001
Jason Faulhefer @hamradiohef.bsky.social · 29/07/2026
CTI for Small Water Systems: A Program Two People Can Run www.threatspire.com/blog/cti-for... #CyberSecurity #ThreatIntel #ICS #OT #SCADA #WaterSecurity
threatspire.com
CTI for Small Water Systems: A Program Two People Can Run — ThreatSpire Blog
Most water systems have no SOC and no analyst. Here is a threat intelligence practice sized for a two person shop: three requirements, five sources, two artifacts, and one rehearsed manual fallback.
001
Jason Faulhefer @hamradiohef.bsky.social · 28/07/2026
Remote Access at Water Utilities: Who Can Touch the Plant Tonight? www.threatspire.com/blog/remote-... #CyberSecurity #ThreatIntel #ICS #OT #SCADA #Water
threatspire.com
Remote Access at Water Utilities: Who Can Touch the Plant Tonight? — ThreatSpire Blog
Yesterday we looked at building intelligence around treatment and distribution. The follow up question is narrower and harder: at this exact moment, who or what can reach the plant from outside the fe...
013
Jason Faulhefer @hamradiohef.bsky.social · 27/07/2026
CTI for Water Utilities: Building Intelligence Around Treatment and Distribution www.threatspire.com/blog/cti-for... #CyberSecurity #ThreatIntel #ICS #OT #SCADA #Water
threatspire.com
CTI for Water Utilities: Building Intelligence Around Treatment and Distribution — ThreatSpire Blog
Water and wastewater systems run lean, span hundreds of unmanned sites, and lean heavily on remote access. Generic threat feeds do not help them. Here is what a working intelligence program looks like...
000
Jason Faulhefer @hamradiohef.bsky.social · 24/07/2026
What a Modbus and IEC-104 Honeypot Fleet Actually Teaches You www.threatspire.com/blog/ics-hon... #CyberSecurity #ThreatIntel #ICS #OT #Energy
threatspire.com
What a Modbus and IEC-104 Honeypot Fleet Actually Teaches You — ThreatSpire Blog
Deploying vendor-authentic Modbus/TCP and IEC 60870-5-104 decoys is only the start. The real value comes from what the traffic tells you about scanning campaigns, targeted operators, and pre-attack re...
001
Jason Faulhefer @hamradiohef.bsky.social · 23/07/2026
PIRs for OT: Writing Intelligence Requirements That Actually Fit a Plant www.threatspire.com/blog/pirs-fo... #CyberSecurity #ThreatIntel #ICS #OT #Energy
threatspire.com
PIRs for OT: Writing Intelligence Requirements That Actually Fit a Plant — ThreatSpire Blog
Most PIR templates were written for enterprise IT. When you drop them into a plant or a substation program, they either go unanswered or produce reports no operations leader will read.
021
Jason Faulhefer @hamradiohef.bsky.social · 22/07/2026
Evidence Timeline for OT Incidents: What to Capture Before You Lose It www.threatspire.com/blog/evidenc... #CyberSecurity #ThreatIntel #ICS #OT
threatspire.com
Evidence Timeline for OT Incidents: What to Capture Before You Lose It — ThreatSpire Blog
OT environments overwrite the evidence you need faster than IT ones do. A disciplined evidence timeline captured in the first hours is worth more than any post incident forensic effort.
011
Jason Faulhefer @hamradiohef.bsky.social · 22/07/2026
Refied beans is Mexican Hummus. Mushy Peas is British Hummus. Peanut butter is American Hummus.
110
Jason Faulhefer @hamradiohef.bsky.social · 21/07/2026
Grid Signal: What Cross Sensor Correlation Actually Reveals www.threatspire.com/blog/grid-si... #CyberSecurity #ThreatIntel #ICS #OT
threatspire.com
Grid Signal: What Cross Sensor Correlation Actually Reveals — ThreatSpire Blog
A single honeypot tells you what one attacker did in one place. A correlated fleet tells you which campaigns are hunting your sector, which are opportunistic, and which are quietly trying not to be se...
001
Jason Faulhefer @hamradiohef.bsky.social · 20/07/2026
Protocol Aware Detections: Practical Rules for Modbus, DNP3, IEC-104, and MMS www.threatspire.com/blog/protoco... #cybersecurity #threatintel #ICS #OT
threatspire.com
Protocol Aware Detections: Practical Rules for Modbus, DNP3, IEC-104, and MMS — ThreatSpire Blog
Generic network detections miss the behaviors that actually matter on a control network. A small set of protocol aware rules per protocol will catch more real activity than a thousand IT signatures ev...
022
Jason Faulhefer @hamradiohef.bsky.social · 19/07/2026
From back when Twitter was good.
021
Jason Faulhefer @hamradiohef.bsky.social · 19/07/2026
Launching soon. www.threatspire.com
000
Jason Faulhefer @hamradiohef.bsky.social · 17/07/2026
NERC CIP and CTI: Turning Compliance Controls Into Detection Value www.threatspire.com/blog/nerc-ci... #cybersecurity #compliance #NERC #CIP #threatintel #ICS #OT
threatspire.com
NERC CIP and CTI: Turning Compliance Controls Into Detection Value — ThreatSpire Blog
Most CIP programs treat compliance and threat intelligence as separate universes. The controls that CIP already requires are, with small additions, one of the richest detection surfaces a utility can ...
001
Jason Faulhefer @hamradiohef.bsky.social · 16/07/2026
Remote Access Is Still the Front Door to OT www.threatspire.com/blog/remote-... #cybersecurity #threatintel #OT #ICS
threatspire.com
Remote Access Is Still the Front Door to OT — ThreatSpire Blog
Nearly every publicly reported OT intrusion of the last five years touched remote access at some point. Treating that pathway as a first class collection target is one of the highest leverage moves a ...
001
Jason Faulhefer @hamradiohef.bsky.social · 15/07/2026
Actor Tracking for ICS Groups: How to Follow VOLTZITE, ELECTRUM, and Peers Without Losing the Signal www.threatspire.com/blog/actor-t... #cybersecurity #threatintel #OT #ICS #CriticalInfrastructure
threatspire.com
Actor Tracking for ICS Groups: How to Follow VOLTZITE, ELECTRUM, and Peers Without Losing the Signal — ThreatSpire Blog
ICS focused groups do not behave like ransomware crews. Tracking them requires a different cadence, different collection sources, and a different bar for attribution.
001
Jason Faulhefer @hamradiohef.bsky.social · 15/07/2026
IOCs in OT: Why Hashes and IPs Fail in the Substation www.threatspire.com/blog/iocs-in... #cybersecurity #threatintel #OT #ICS #CriticalInfrastructure
threatspire.com
IOCs in OT: Why Hashes and IPs Fail in the Substation — ThreatSpire Blog
The IT playbook of hash and IP indicators breaks down inside a substation or plant. Effective OT indicators look more like protocol behavior, engineering workstation drift, and unexpected point writes...
001
Jason Faulhefer @hamradiohef.bsky.social · 14/07/2026
www.threatspire.com/blog/iocs-in... #cybersecurity #threatintel #threatintelligence #ICS #NERC
threatspire.com
IOCs in OT: Why Hashes and IPs Fail in the Substation — ThreatSpire Blog
The IT playbook of hash and IP indicators breaks down inside a substation or plant. Effective OT indicators look more like protocol behavior, engineering workstation drift, and unexpected point writes...
011
Jason Faulhefer @hamradiohef.bsky.social · 25/06/2026
Purple Team Intelligence: Red Team Findings as a Controlled Collection Source www.threatspire.com/blog/purple-... #cybersecurity #infosec #threatintel #threatintelligence #CTI
threatspire.com
Purple Team Intelligence: Red Team Findings as a Controlled Collection Source — ThreatSpire Blog
Red team engagements are usually treated as audits. Treat them as a controlled collection source instead and your CTI program gains ground truth that no feed can match.
001
Jason Faulhefer @hamradiohef.bsky.social · 24/06/2026
Writing Intelligence Assessments That Executives Actually Read www.threatspire.com/blog/intelli... #cybersecurity #threatintel #threatintelligence #CTI
threatspire.com
Writing Intelligence Assessments That Executives Actually Read — ThreatSpire Blog
Most CTI reports lose the executive in the first paragraph. Apply the Pyramid Principle and you will get read, understood, and acted on.
000
Jason Faulhefer @hamradiohef.bsky.social · 23/06/2026
The SOC and CTI Feedback Loop: How Threat Intel Earns Its Seat in the SOC www.threatspire.com/blog/soc-cti... #cybersecurity #threatintel #threatintelligence #CTI
threatspire.com
The SOC and CTI Feedback Loop: How Threat Intel Earns Its Seat in the SOC — ThreatSpire Blog
CTI teams complain that the SOC ignores their reports. SOC teams complain that CTI is theoretical. The fix is a small set of feedback rituals.
001
Jason Faulhefer @hamradiohef.bsky.social · 22/06/2026
Dark Web Monitoring for CTI: Collection Tradecraft for Underground Markets www.threatspire.com/blog/dark-we... #cybersecurity #threatintel #threatintelligence #CTI
threatspire.com
Dark Web Monitoring for CTI: Collection Tradecraft for Underground Markets — ThreatSpire Blog
Dark web monitoring is the most oversold capability in CTI. Done right, it is also one of the most useful. Here is the collection tradecraft that separates the two.
000
Reposted by Jason Faulhefer
💙💙~Patty~💙💙 @pattyger.bsky.social · 20/06/2026
#FridayNightParties 🥳🎉🍕💃🕺🎶🍻 @hamradiohef.bsky.social @saturdaysun2009.bsky.social @bareroot.bsky.social @johnrafferty.bsky.social @warlach.bsky.social @pattyger.bsky.social @mrsdeborahlynn.bsky.social @hamkold.bsky.social @sandybsassy.bsky.social @packers1.bsky.social @trisha102466.bsky.social
54824
Jason Faulhefer @hamradiohef.bsky.social · 19/06/2026
Threat Hunting with Intelligence Requirements: Hypothesis-Driven Sweeps That Actually Find Things www.threatspire.com/blog/threat-... #CyberSecurity #ThreatIntel #CTI
threatspire.com
Threat Hunting with Intelligence Requirements: Hypothesis-Driven Sweeps That Actually Find Things — ThreatSpire Blog
Most hunts are searches for the things you already know how to detect. A PIR driven hunting program asks the questions your detections cannot answer.
001
Jason Faulhefer @hamradiohef.bsky.social · 18/06/2026
Ransomware Negotiation Leaks: Using Leak Site Data to Model the Adversary's Business www.threatspire.com/blog/ransomw... #cybersecurity #threatintel #CTI
threatspire.com
Ransomware Negotiation Leaks: Using Leak Site Data to Model the Adversary's Business — ThreatSpire Blog
Leak site posts and negotiation transcripts are public, abundant, and underused. Read them like a business analyst and you can predict pricing, dwell, and exfiltration behavior.
021
Reposted by Jason Faulhefer
Dovewoman 💙 🇺🇦 💙 @dovewoman.bsky.social · 18/06/2026
0216
Jason Faulhefer @hamradiohef.bsky.social · 17/06/2026
Privacy getting eroded right by right, soon court warrants will go the way of the dodo if we don’t stop this.
0116
Jason Faulhefer @hamradiohef.bsky.social · 17/06/2026
Supply Chain Intelligence: Vendor Risk Through an Intelligence Lens www.threatspire.com/blog/supply-...
threatspire.com
Supply Chain Intelligence: Vendor Risk Through an Intelligence Lens — ThreatSpire Blog
Vendor risk programs ask the wrong questions and get the wrong answers. Here is how to apply a CTI lens to the suppliers most likely to bring an adversary into your network.
020
Reposted by Jason Faulhefer
Jesse : 💙💙💙 @journeyled1.bsky.social · 17/06/2026
Starter pack 389 @bab102.bsky.social @lunaluvgood2020.bsky.social @yodamonkey2.bsky.social @coolsprings.bsky.social @daisyd.bsky.social @peggystuart.bsky.social @jadajones57.bsky.social @bahatitu.bsky.social @hamradiohef.bsky.social @jbst33lady.bsky.social @snoocupcakes.bsky.social
41814
Jason Faulhefer @hamradiohef.bsky.social · 16/06/2026
Nation-State Attribution: Communicating Uncertainty Without Diluting Impact www.threatspire.com/blog/nation-... #cybersecurity #threatintel #threatintelligence #CTI #nationstate
threatspire.com
Nation-State Attribution: Communicating Uncertainty Without Diluting Impact — ThreatSpire Blog
Attribution is a probabilistic claim, not a verdict. Here is how to communicate confidence honestly without producing a report that no one can act on.
000
Jason Faulhefer @hamradiohef.bsky.social · 15/06/2026
The Half-Life of an IOC: Operationalizing Decay and Confidence Scoring www.threatspire.com/blog/half-li... #cybersecurity #threatintel #CTI
threatspire.com
The Half-Life of an IOC: Operationalizing Decay and Confidence Scoring — ThreatSpire Blog
An IOC is not a fact. It is a perishable claim. Treat indicators like radioactive isotopes with a half-life and your blocklists, hunts, and reports get a lot more honest.
011