Sign in

sydney

@letswastetime.bsky.social
149 followers 42 following 119 posts

| search "thrunter" | eval specialty="Purple Team, Treat Hunter, Lifting Heavy Things"

PostsRepliesMedia
sydney @letswastetime.bsky.social · 29/09/2026
Agents are completion machines. They want to answer and they want to be done. That's not curiosity. New on @thorcollective.bsky.social Dispatch: dispatch.thorcollective.com/p/teaching-m...
120
sydney @letswastetime.bsky.social · 13/07/2026
I'll be running a workshop at DEF CON 34! Agentic Threat Hunting: Building AI That Remembers What You Hunted This isn't a walkthrough or an AI demo. It's a real threat hunt. Workshop registration opens Tuesday, July 14 at 12:00 PM PT. Hope to see you there. 🖤 events.humanitix.com/fri_am_ws4_4...
events.humanitix.com
WS4 - Agentic Threat Hunting: Building AI That Remembers What You Hunted
Instructed by: Sydney “letswastetime” Marrone Level of Difficulty: Intermediate, Advanced
000
sydney @letswastetime.bsky.social · 23/06/2026
I GOT A TEXT!!!!! Anthropic analyzed 832 malicious cyber actors using AI. The takeaway: your detections probably aren't broken. Assumptions about attacker speed might be. New @thorcollective.bsky.social Dispatch from guest author Kassandra Murphy👇 dispatch.thorcollective.com/p/ai-has-ent...
120
sydney @letswastetime.bsky.social · 04/06/2026
Ideas are easy. Following through is the hard part. I'll be joining Women's Society of Cyberjutsu for "You've Got This: Just Hit Submit on That Brilliant Idea!" to talk about turning ideas into action. Hope to see you there. womenscyberjutsu.org/event/youveg...
100
sydney @letswastetime.bsky.social · 02/06/2026
That CFP. That blog post. That workshop. That idea. Hit submit. Some of the best opportunities in my career started with putting myself out there before I felt ready. 🔥 New @thorcollective.bsky.social Dispatch: You've Got This. Just Hit Submit. dispatch.thorcollective.com/p/youve-got-...
112
sydney @letswastetime.bsky.social · 26/05/2026
I’ll be speaking at the Threat Hunting Summit on June 17 about hunt memory and building lightweight repos your AI assistant can actually use during investigations. Because most hunts still end up in “wait… have we seen this before?” Come hang 👀 www.antisyphontraining.com/event/threat...
100
sydney @letswastetime.bsky.social · 22/04/2026
HEARTH just got operational. 160+ hunts, now with: What can I hunt? → based on your telemetry Coverage map → see your gaps Context graph → prioritize what matters now Same library. Way more usable. dispatch.thorcollective.com/p/three-new-...
020
sydney @letswastetime.bsky.social · 10/03/2026
Breaking into cybersecurity can feel like opening 23 tabs and learning nothing. In this @THOR_Collective Dispatch guest post, Bella San Lorenzo shares practical ways to break the cycle and start making real progress. Part II is live! dispatch.thorcollective.com/p/all-roads-...
100
sydney @letswastetime.bsky.social · 03/03/2026
We teach people how to start a threat hunt. Nobody teaches them when to stop. New post on @thorcollective.bsky.social Dispatch on closing hunts with actual criteria instead of gut feelings 👇 👉 dispatch.thorcollective.com/p/when-to-st...
201
sydney @letswastetime.bsky.social · 24/02/2026
New on the @thorcollective.bsky.social Dispatch - Bella San Lorenzo on the paralysis of trying to find your place in cybersecurity. 47 browser tabs. A perfectly organized Notion page. Zero actual progress. Sound familiar? 👉 dispatch.thorcollective.com/p/the-more-i...
100
sydney @letswastetime.bsky.social · 03/02/2026
OpenClaw isn't malware. It's a legitimate tool that store credentials, retain memory, and act autonomously. That's what makes it dangerous when misused. Full behavioral breakdown in our latest Hunt Mode post. 🦀 nebulock.io/blog/hunting...
nebulock.io
Hunting OpenClaw and Agentic AI Through Behavior | Nebulock blog
This Hunt Mode breaks down the behaviors that give away OpenClaw (formerly ClawdBot / MoltBot), regardless of how it is packaged, renamed, or delivered.
100
sydney @letswastetime.bsky.social · 27/01/2026
You don’t need a desk to build. I used AI more from my phone last month than from my desk. What mattered was removing friction and building where ideas show up. 👉 New on @thorcollective.bsky.social Dispatch: dispatch.thorcollective.com/p/you-dont-n...
111
sydney @letswastetime.bsky.social · 20/01/2026
“I’m not a developer” is a self-imposed limit. If you’ve written a query, a script, or an automation to fix a problem, you’re already building. In the latest @thorcollective.bsky.social Dispatch, we talk about why building is a core security skill. dispatch.thorcollective.com/p/why-you-sh...
111
sydney @letswastetime.bsky.social · 15/01/2026
DigitStealer is an excellent example of where macOS malware is heading: multi-stage, modular, and using legit macOS tools like it belongs there. Detect the attack, not the sample. Shoutout Jamf Threat Labs 🙌 nebulock.io/blog/hunting...
100
sydney @letswastetime.bsky.social · 01/01/2026
80 posts. @thorcollective.bsky.social kept hitting publish. This year was about doing the work, writing it down, and sharing it anyway. If you read, argued, bookmarked, or built alongside us, thank you. Happy New Year. Happy thrunting. dispatch.thorcollective.com/p/80-posts-l...
100
sydney @letswastetime.bsky.social · 11/12/2025
It's happening! Meet the Agentic Threat Hunting Framework (ATHF). Tired of copy-pasting the same hunt template over and over? Same. I built a framework designed for an AI-assisted future that adds structure, memory, and context to every hunt. Come check it out! nebulock.io/blog/agentic...
010
sydney @letswastetime.bsky.social · 25/11/2025
November’s @thorcollective.bsky.social Dispatch Debrief is live with SCADA weirdness, Taylor’s Version SOC vibes, and purple team chaos. Come thrunt with us. dispatch.thorcollective.com/p/dispatch-d...
100
Reposted by sydney
drterdnugget.bsky.social @drterdnugget.bsky.social · 20/11/2025
🚨New post on @THOR_Collective Dispatch🚨 “Aligning Risk Management and Threat-Informed Defense Practices (Part 2)” by Micah VanFossen What happens when you sync risk, controls, and threat intel to drive real-security outcomes. dispatch.thorcollective.com/p/aligning-r... #thrunting #grc
dispatch.thorcollective.com
Aligning Risk Management and Threat-Informed Defense Practices (Part 2)
We’re back with part two of a series analyzing how to align common GRC tasks/teams with SecOps and threat-informed defense practices.
021
Reposted by sydney
drterdnugget.bsky.social @drterdnugget.bsky.social · 18/11/2025
🚨New post on @THOR_Collective Dispatch🚨 Purple teaming isn’t shiny. It’s delays, blockers, tickets & pivots. And that’s okay. open.substack.com/pub/thorcoll... #thrunting #PurpleTeaming
open.substack.com
Purple Teaming in the Real World: When Everything Goes Off the Rails (and That’s Normal)
People love the glossy version of purple teaming:
011
sydney @letswastetime.bsky.social · 13/11/2025
Have you ever run the best hunt of your life and then forget how two weeks later? Same. Meet the PEAK Threat Hunting Template. Built to make your hunts repeatable, reviewable, and impossible to lose. 👉 Read on THOR Collective Dispatch - dispatch.thorcollective.com/p/the-peak-t...
110
sydney @letswastetime.bsky.social · 11/11/2025
🎤 The Autonomous SOC (Taylor’s Version) Guest post with @kassafras09.bsky.social AI hype is loud. Most teams are just automating chaos. Fix the basics first. Then scale the magic. Read it on @thorcollective.bsky.social Dispatch. dispatch.thorcollective.com/p/the-autono...
dispatch.thorcollective.com
The Autonomous SOC (Taylor’s Version)
Opening Act: Welcome to the SOC Show
110
sydney @letswastetime.bsky.social · 06/11/2025
In the latest @thorcollective.bsky.social guest post, Sam Hanson breaks down two TTP-driven hunts — KurtLar_SCADA and a weird .NET Modbus binary — proving simple hypotheses > chasing IOCs. IOCs show where the fire was. TTPs show where it will be. dispatch.thorcollective.com/p/hunting-be...
dispatch.thorcollective.com
110
sydney @letswastetime.bsky.social · 30/10/2025
October delivered AI agents, time mastery, and purple team curveballs. From scaling hunts like code to aligning GRC with threat-informed defense, this month’s Dispatch lineup from @thorcollective.bsky.social hit every layer of the stack. Full recap here: dispatch.thorcollective.com/p/dispatch-d...
dispatch.thorcollective.com
Dispatch Debrief: October 2025
Seven Dispatch drops that prove hunting smarter beats hunting harder.
121
sydney @letswastetime.bsky.social · 28/10/2025
Finding nothing ≠ failing the hunt. Sometimes “nothing” is the loudest signal that your defenses worked. @jotunvillur.bsky.social breaks down how to measure the quiet wins in in one of my favorite @thorcollective.bsky.social Dispatch posts: dispatch.thorcollective.com/p/measuring-...
dispatch.thorcollective.com
Measuring the Hunt When You Find “Nothing”
Because sometimes success looks like silence.
000
sydney @letswastetime.bsky.social · 09/10/2025
In this week’s @thorcollective.bsky.social Dispatch, Sam Hanson lays out how to move beyond indicator-based hunting and build detection muscle that actually scales. 👉 dispatch.thorcollective.com/p/hunting-be...
111
sydney @letswastetime.bsky.social · 08/10/2025
If tstats gives you speed and eventstats gives you context...timechart gives you shape. This week’s @thorcollective.bsky.social SPL Dispatch breaks down how to use timechart to uncover rhythm, automation, and the a cron job masquerading as “normal.” dispatch.thorcollective.com/p/the-shape-...
dispatch.thorcollective.com
111
sydney @letswastetime.bsky.social · 02/10/2025
Threat hunting falls apart when your “docs” live in Slack threads. Part 2 of the @thorcollective.bsky.social Dispatch Agentic Threat Hunting series covers the first step to scaling: put your hunts in a GitHub repo and give your AI bestie memory. dispatch.thorcollective.com/p/agentic-th...
122
sydney @letswastetime.bsky.social · 01/10/2025
✨ To get you ready for Taylor Swift’s latest album… ✨ 🎶 Check out Life of a Detection Girl - a playlist I created inspired by Taylor Swift and Alex Hurtado, with a touch of cyber woven in. Give it a listen and let me know your favorite track! suno.com/playlist/5cf...
suno.com
Life of a Detection Girl by @letswastetime | Suno
✨ inspo by alex hurtado & taylor swift ✨
000
Reposted by sydney
LP @jotunvillur.bsky.social · 01/10/2025
We at @thorcollective.bsky.social are waking you up before September ends, because a new Ask-a-Thrunt3r episode just dropped with: 2K subscriber milestone 🎉 15 baseline examples The great data vs. data debate Plus: Is Git the future of hunting collab? 🎧: dispatch.thorcollective.com/p/ask-a-thru...
dispatch.thorcollective.com
Ask-a-Thrunt3r: September 2025 Recap 🐏
Mainly ramblings. And maybe some wisdom.
022
sydney @letswastetime.bsky.social · 26/09/2025
From temporal to behavioral, baselines are the thrunter’s compass. September’s Dispatch from @thorcollective.bsky.social shows how to use them to sharpen the hunt and includes ten baseline hunts you should be running now. 🔗 dispatch.thorcollective.com/p/dispatch-d...
132
Reposted by sydney
LP @jotunvillur.bsky.social · 23/09/2025
You can’t find weird if you don’t know normal. @thorcollective.bsky.social just dropped 10 baseline hunts you can shine in the dark parts of your env and magnify the adversaries from the noise. Join us for all the thrunting 👉: open.substack.com/pub/thorcoll... #threathunting #infosec
022
sydney @letswastetime.bsky.social · 18/09/2025
✨ Representation is STILL a security issue. ✨ @thorcollective.bsky.social Dispatch with @kassafras09.bsky.social from March. The message still stands. • Fix biased job reqs • Put diverse voices on panels • Mentor future hackers • Model inclusive leadership dispatch.thorcollective.com/p/why-we-nee...
dispatch.thorcollective.com
Why We Need More Women and Intersectional Diversity in Cyber (And How to Get There)
Representation matters in cybersecurity. Here’s why—and what we can do about it.
121
sydney @letswastetime.bsky.social · 16/09/2025
Cybersecurity needs more than hackers in hoodies. In this week’s @thorcollective.bsky.social Dispatch, Courtney Shar shares how project management skills like risk alignment, process design, and team coordination directly strengthen security programs. 👉 dispatch.thorcollective.com/p/beyond-hac...
dispatch.thorcollective.com
163
Reposted by sydney
drterdnugget.bsky.social @drterdnugget.bsky.social · 05/09/2025
🚨New post on @thorcollective.bsky.social Dispatch 🚨 Certis Foster didn't hunt for it. It revealed itself. The key? Plotting behavior in 3D space: 🕒 Time 🗺️ Terrain 🎯 Behavior Outliers can’t hide in 3D. dispatch.thorcollective.com/p/cant-hide-... #threathunting #thrunting #THORcollective
dispatch.thorcollective.com
Can't Hide in 3D
In a sea of millions of security events, one workstation literally stood out, floating high above all the others when I transformed flat logs into a 3D visualization.
011
sydney @letswastetime.bsky.social · 02/09/2025
If you don’t know what “normal” looks like in your environment, you’re not hunting...you’re hoping. Our latest @thorcollective.bsky.social Dispatch post breaks down 5 baselines every thrunter needs. Map normal. Track drift. Catch threats. Read here: dispatch.thorcollective.com/p/you-cant-f...
dispatch.thorcollective.com
You Can't Find Weird If You Don't Know Normal
Five baselines with hunt queries you can run today
121
sydney @letswastetime.bsky.social · 28/08/2025
Summertime sadness hit the Dispatch hard: sunscreen > screen time. 🌞 But the hunts never stopped, and this month we’re back with fresh chaos, AI wisdom, and a noob’s-eye view of DEF CON. 👉 Catch the @thorcollective.bsky.social August Dispatch: dispatch.thorcollective.com/p/dispatch-d...
111
sydney @letswastetime.bsky.social · 21/08/2025
The Quiet War isn’t loud breaches or ransomware. It’s subtle. AI-driven adversaries are blending in and evading detection. Hunters must shift: hunt intent, not just indicators. 👉 New guest post by Damien Lewke on @thorcollective.bsky.social Dispatch: dispatch.thorcollective.com/p/the-quiet-...
011
sydney @letswastetime.bsky.social · 19/08/2025
What happens when you throw yourself into DEFCON for the very first time? You get Line Con, Noob Village wisdom, hacker merch battles, Flipper Zero impulse buys, Hacker Jeopardy chaos, and the realization that DEFCON is not just a con, it is a community. dispatch.thorcollective.com/p/my-first-d...
131
sydney @letswastetime.bsky.social · 06/08/2025
It’s here! 🎉 @dr-fett.bsky.social and I coauthored The Threat Hunter’s Cookbook and we’re thrilled to finally share it. Built for defenders at every level with hunting methods from simple filtering to advanced clustering. 👉 Get the eBook: www.splunk.com/en_us/form/t...
splunk.com
Introducing… The Threat Hunter’s Cookbook! | Splunk
The security experts on the SURGe team have released The Threat Hunter’s Cookbook, a hands-on guide for security practitioners that features actionable insights into threat hunting methods,…
110
sydney @letswastetime.bsky.social · 05/08/2025
The Hacker Summer Camp starter pack: ⚡ Stickers ⚡ Patches ⚡ Coins ⚡ Wristbands ⚡ Temporary THRUNT tattoos Find the @thorcollective.bsky.social crew in Vegas. Say hi and get some swag 👀
111
Reposted by sydney
THOR Collective @thorcollective.bsky.social · 04/08/2025
Shoutout to our fam Elipscion, who's spinning live at DEF CON 33 this Friday at 8pm on the DEF CON stage. 🎧 Listen here: open.spotify.com/artist/2tgPZ... 🔥 Join our @thorcollective.bsky.social meetup during his set. Say hi, talk hunts, and grab some free swag. See you there!
open.spotify.com
ELIPSCION
Artist · 10 monthly listeners.
133
sydney @letswastetime.bsky.social · 31/07/2025
🌵 Calm before the Hacker Summer Camp storm. July’s Dispatch Debrief is light on posts, heavy on hot takes — from agentic AI to making pentest findings sting. Catch up before Vegas 👉 dispatch.thorcollective.com/p/dispatch-d...
dispatch.thorcollective.com
Dispatch Debrief: July 2025
Consider this the calm before the Hacker Summer Camp storm.
111
sydney @letswastetime.bsky.social · 27/07/2025
Threat hunting is broken. We can’t out-query adversaries who automate everything. Enter the agentic threat hunter. An AI that thinks, hypothesizes, investigates, and scales. In the latest @thorcollective.bsky.social Dispatch, we explore this shift: 📌 dispatch.thorcollective.com/p/the-agenti...
133
sydney @letswastetime.bsky.social · 24/07/2025
Heading to hacker summer camp? I wrote a survival guide for DEF CON, Black Hat, etc. - Pick your purpose - Villages > talks - Hallway track is real - You belong here 👽 dispatch.thorcollective.com/p/con-101-ho... @thorcollective.bsky.social will be out there with thrunting stickers—come say hi.
121
Reposted by sydney
THOR Collective @thorcollective.bsky.social · 19/07/2025
We’re giving away another THOR Collective Challenge Coin. Ask-a-Thrunter drops early August (recording July 31). Hacker Summer Camp vibes guaranteed. 🎟️ Join our paid sub for giveaways + Discord. 💬 Questions? Drop ’em. radio.thorcollective.com
radio.thorcollective.com
Redirecting…
If you’re not redirected, click here.
111
sydney @letswastetime.bsky.social · 15/07/2025
New from @thorcollective.bsky.social Dispatch: If You Like It Then You Should’ve Put a timechart on It We’re diving into why timechart is a threat hunter’s best friend. From beaconing to privilege spikes, baselines, and more. Read it here 👉 dispatch.thorcollective.com/p/if-you-lik...
dispatch.thorcollective.com
If You Like It Then You Should've Put a timechart on It
Hey thrunters, gather ’round: timechart’s up
133
sydney @letswastetime.bsky.social · 11/07/2025
The Threat Hunter’s Cookbook drops at #BlackHat! Huge thanks to my co-author @dr-fett.bsky.social for bringing this project to life and @meansec.bsky.social for the forward. Come celebrate with #SURGe and grab a signed copy at #Splunk’s After Party! 🖤 splunk.swoogo.com/splunkafterp...
splunk.swoogo.com
Home
Splunk AfterParty and Book Signing with Co-Sponsors Cisco and Contrast Security
152
Reposted by sydney
THOR Collective @thorcollective.bsky.social · 08/07/2025
No @thorcollective.bsky.social Dispatch posts this week. We’re taking a breather to rest and recharge. We'll be back next week, ready to thrunt. #threathunting #thrunting #THORcollective #cybersecurity #infosec
011
sydney @letswastetime.bsky.social · 03/07/2025
THRUNTING isn’t just a buzzword. It’s a mindset. 🐑 Inspired by Tim Peters’ 19 aphorisms for Python, @thorcollective.bsky.social Dispatch introduces "The Zen of Thrunting." dispatch.thorcollective.com/p/the-zen-of... Stay curious. Happy thrunting.
dispatch.thorcollective.com
The Zen of Thrunting
Abstract
143
sydney @letswastetime.bsky.social · 26/06/2025
Dispatch Debrief: June 2025 Everything’s fine… until it isn’t. This month’s @thorcollective.bsky.social Dispatch served up a spicy mix of threat hunting, plugin paranoia, purple teaming insights, and a few thrunting curveballs to keep you sharp. 🌶️ dispatch.thorcollective.com/p/dispatch-d...
dispatch.thorcollective.com
Dispatch Debrief: June 2025
Because "Everything's Fine" is Just Another Way of Saying "I Haven't Looked Yet"
132