Sign in

THOR Collective

@thorcollective.bsky.social
37 followers 4 following 9 posts

thorcollective.com

PostsRepliesMedia
THOR Collective @thorcollective.bsky.social · 09/12/2025
Hi thrunters! We’re on a well-earned December break. Stay tuned for an end-of-year post and a podcast episode with the OG Detection Dispatcher, Alex Hurtado!
000
Reposted by THOR Collective
LP @jotunvillur.bsky.social · 01/10/2025
We at @thorcollective.bsky.social are waking you up before September ends, because a new Ask-a-Thrunt3r episode just dropped with: 2K subscriber milestone 🎉 15 baseline examples The great data vs. data debate Plus: Is Git the future of hunting collab? 🎧: dispatch.thorcollective.com/p/ask-a-thru...
dispatch.thorcollective.com
Ask-a-Thrunt3r: September 2025 Recap 🐏
Mainly ramblings. And maybe some wisdom.
022
Reposted by THOR Collective
sydney @letswastetime.bsky.social · 18/09/2025
✨ Representation is STILL a security issue. ✨ @thorcollective.bsky.social Dispatch with @kassafras09.bsky.social from March. The message still stands. • Fix biased job reqs • Put diverse voices on panels • Mentor future hackers • Model inclusive leadership dispatch.thorcollective.com/p/why-we-nee...
dispatch.thorcollective.com
Why We Need More Women and Intersectional Diversity in Cyber (And How to Get There)
Representation matters in cybersecurity. Here’s why—and what we can do about it.
121
Reposted by THOR Collective
sydney @letswastetime.bsky.social · 05/08/2025
The Hacker Summer Camp starter pack: ⚡ Stickers ⚡ Patches ⚡ Coins ⚡ Wristbands ⚡ Temporary THRUNT tattoos Find the @thorcollective.bsky.social crew in Vegas. Say hi and get some swag 👀
111
THOR Collective @thorcollective.bsky.social · 04/08/2025
Shoutout to our fam Elipscion, who's spinning live at DEF CON 33 this Friday at 8pm on the DEF CON stage. 🎧 Listen here: open.spotify.com/artist/2tgPZ... 🔥 Join our @thorcollective.bsky.social meetup during his set. Say hi, talk hunts, and grab some free swag. See you there!
open.spotify.com
ELIPSCION
Artist · 10 monthly listeners.
133
Reposted by THOR Collective
sydney @letswastetime.bsky.social · 27/07/2025
Threat hunting is broken. We can’t out-query adversaries who automate everything. Enter the agentic threat hunter. An AI that thinks, hypothesizes, investigates, and scales. In the latest @thorcollective.bsky.social Dispatch, we explore this shift: 📌 dispatch.thorcollective.com/p/the-agenti...
133
Reposted by THOR Collective
drterdnugget.bsky.social @drterdnugget.bsky.social · 22/07/2025
🚨New post on @thorcollective.bsky.social Dispatch🚨 Tired of getting ignored after dropping a valid XSS vuln? Stop showing alert(1) pop-ups & start stealing sessions. Make it real. Bring a bit of pain. Read it here 👉 open.substack.com/pub/thorcoll...
open.substack.com
Make It Hurt (a Little): Why Showing Real Impact in Pentest Findings Matters
“Cool alert box, bro. Now what?”
011
THOR Collective @thorcollective.bsky.social · 19/07/2025
We’re giving away another THOR Collective Challenge Coin. Ask-a-Thrunter drops early August (recording July 31). Hacker Summer Camp vibes guaranteed. 🎟️ Join our paid sub for giveaways + Discord. 💬 Questions? Drop ’em. radio.thorcollective.com
radio.thorcollective.com
Redirecting…
If you’re not redirected, click here.
111
Reposted by THOR Collective
sydney @letswastetime.bsky.social · 15/07/2025
New from @thorcollective.bsky.social Dispatch: If You Like It Then You Should’ve Put a timechart on It We’re diving into why timechart is a threat hunter’s best friend. From beaconing to privilege spikes, baselines, and more. Read it here 👉 dispatch.thorcollective.com/p/if-you-lik...
dispatch.thorcollective.com
If You Like It Then You Should've Put a timechart on It
Hey thrunters, gather ’round: timechart’s up
133
THOR Collective @thorcollective.bsky.social · 08/07/2025
No @thorcollective.bsky.social Dispatch posts this week. We’re taking a breather to rest and recharge. We'll be back next week, ready to thrunt. #threathunting #thrunting #THORcollective #cybersecurity #infosec
011
Reposted by THOR Collective
sydney @letswastetime.bsky.social · 03/07/2025
THRUNTING isn’t just a buzzword. It’s a mindset. 🐑 Inspired by Tim Peters’ 19 aphorisms for Python, @thorcollective.bsky.social Dispatch introduces "The Zen of Thrunting." dispatch.thorcollective.com/p/the-zen-of... Stay curious. Happy thrunting.
dispatch.thorcollective.com
The Zen of Thrunting
Abstract
143
Reposted by THOR Collective
sydney @letswastetime.bsky.social · 26/06/2025
Dispatch Debrief: June 2025 Everything’s fine… until it isn’t. This month’s @thorcollective.bsky.social Dispatch served up a spicy mix of threat hunting, plugin paranoia, purple teaming insights, and a few thrunting curveballs to keep you sharp. 🌶️ dispatch.thorcollective.com/p/dispatch-d...
dispatch.thorcollective.com
Dispatch Debrief: June 2025
Because "Everything's Fine" is Just Another Way of Saying "I Haven't Looked Yet"
132
Reposted by THOR Collective
sydney @letswastetime.bsky.social · 19/06/2025
New guest post on thorcollective.bsky.social Dispatch from infosecsherpa.bsky.social: Don’t Let Mis(s) Information Take the Crown 👑 This post shows how to apply the Intelligence Cycle to news and help you filter bias. Read it here: dispatch.thorcollective.com/p/dont-let-m...
dispatch.thorcollective.com
Don't Let Mis(s) Information Take the Crown
Sherpa Intelligence: Your Guide Up a Mountain of Information!
144
THOR Collective @thorcollective.bsky.social · 13/06/2025
This month’s Dispatch Giveaway is live! 🔥 One lucky paid subscriber will win a thorcollective.bsky.social challenge coin! 🗓️ June 26 @ 7PM PT Streaming live in our private Discord Podcast drops for everyone the following week ➡️ Join the Collective: dispatch.thorcollective.com
dispatch.thorcollective.com
THOR Collective Dispatch | Sydney Marrone | Substack
A hub for threat hunters (thrunters) and security professionals. Explore cutting-edge ideas, practical frameworks, and community-driven insights in cybersecurity. Powered by collaboration,…
121
Reposted by THOR Collective
LP @jotunvillur.bsky.social · 10/06/2025
⚡ New @thorcollective.bsky.social Dispatch drop No hallucinations here. Just TTPs that quietly defined Q1 2025. 🔐 OAuth abuse 📦 Malicious packages 🖥️ SimpleHelp RMM exploits Stay ahead with what to hunt & where to look. 👉 dispatch.thorcollective.com/p/from-the-f... #THORCollective #threathunting
dispatch.thorcollective.com
From the Fire: Q1FY25
TTPs that sparked, spread, and still burn for those paying attention.
043
Reposted by THOR Collective
sydney @letswastetime.bsky.social · 29/05/2025
#threatintelligence #threathunting #splunk #cybersecurity #infosec #THORcollective #thrunting #AIisMyBestie
011
Reposted by THOR Collective
sydney @letswastetime.bsky.social · 29/05/2025
The May Dispatch is live. Fresh insights from @thorcollective.bsky.social and guest contributors on detection in depth, AI in the SOC, career overlaps, and making your hunts actually matter. Plus memes. Obviously. 👉 dispatch.thorcollective.com/p/dispatch-d...
dispatch.thorcollective.com
Dispatch Debrief: May 2025
Quiet logs, loud analysts, and AI besties. Just another month in the hunt.
132
THOR Collective @thorcollective.bsky.social · 22/05/2025
🐏 Ask a Thrunter AMA + Giveaway! Join @thorcollective.bsky.social live next THORsday, May 29th @ 7pm PT in Discord. We’ve got a special announcement + we’ll reveal the monthly giveaway winner (all paid Dispatch subscribers automatically entered!). Submit your questions early👇
032
Reposted by THOR Collective
sydney @letswastetime.bsky.social · 22/05/2025
Introverts rewrite detection rules repeatedly, while extroverts demo them mid-draft. In cybersecurity, you need both. Today's @thorcollective.bsky.social Dispatch features Alex Hurtado, highlighting how embracing differences strengthens SOC teams. 👉 : dispatch.thorcollective.com/p/quiet-loud...
dispatch.thorcollective.com
Quiet, Loud, and in the Logfiles: The Detection Duo You Didn’t Know You Needed
Filed under: Things your agent can’t do but Linda from SecOps does without breaking a sweat.
012
Reposted by THOR Collective
drterdnugget.bsky.social @drterdnugget.bsky.social · 15/05/2025
🚨 New guest drop on @THOR_Collective Dispatch! 🚨 "Exploring Cybersecurity Career Paths and How They Work Together" by Audra Streetman Whether you're into offense, intel, or cyber defense, there's a path for you! Read it here: dispatch.thorcollective.com/p/exploring-...
023
Reposted by THOR Collective
sydney @letswastetime.bsky.social · 13/05/2025
💥 New SPL Dispatch drop from @thorcollective.bsky.social : eventstats 💥 Want to flag weird behavior without losing raw data? eventstats lets you compare each event to the group without rolling things up. Read it here 👉 dispatch.thorcollective.com/p/every-even...
dispatch.thorcollective.com
Every Event for Itself…Until You Run eventstats
SPL Dispatch #2 - 05/13/2025
122
Reposted by THOR Collective
sydney @letswastetime.bsky.social · 08/05/2025
💡 New guest drop on @thorcollective.bsky.social Dispatch: "Detection-in-Depth" by Day Johnson. Day covers how to build resilient detection systems that handle real-world challenges, from fine-tuning rules to threat emulation and kill chain coverage. dispatch.thorcollective.com/p/detection-...
dispatch.thorcollective.com
Detection-In-Depth
Eliminating detection blind spots through a multi-layered defense approach
123
Reposted by THOR Collective
sydney @letswastetime.bsky.social · 05/05/2025
🎧 Ask-a-Thrunter: Episode 1 is live! @thorcollective.bsky.social covered everything from hunt standups to VirusTotal vs. behavioral hunting and announced our April giveaway winner! Replay: dispatch.thorcollective.com/p/ask-a-thru... Should we make this monthly? Drop a comment below.
dispatch.thorcollective.com
Ask-a-Thrunter: The Recap Is Here 🐏
Mainly ramblings. And maybe some wisdom.
111
Reposted by THOR Collective
sydney @letswastetime.bsky.social · 01/05/2025
🔥 Dispatch Debrief: April 2025 is live 🔥 Explore star sign-inspired hunting techniques, organizing your hunt squad, and the value of finding "nothing." Discover this month's insights from @thorcollective.bsky.social Dispatch - dispatch.thorcollective.com/p/april-debr...
dispatch.thorcollective.com
Dispatch Debrief: April 2025
What We Hunted, Learned, and Loved This Month
144
Reposted by THOR Collective
sydney @letswastetime.bsky.social · 30/04/2025
Ask-a-Thrunter is live this THORsday, May 1 @ 7pm PDT — paid subscribers only. Join us in the @thorcollective.bsky.social Discord for solid answers, spicy takes, and the April giveaway winner reveal. Drop your questions below. Not subscribed? Replay drops next week. Come thrunt with us 🐏
142
Reposted by THOR Collective
sydney @letswastetime.bsky.social · 29/04/2025
Normal is overrated. Hunt the outliers with Z-scores and standard deviation in the new @thorcollective.bsky.social Dispatch post. Read it here: dispatch.thorcollective.com/p/z-scoring-... #threathunting #thrunting #detectionengineering #infosec #cybersecurity #splunk #statistics
dispatch.thorcollective.com
Z-Scoring Your Way to Better Threat Detection
“Normal” is just a setting on a dryer. Let’s talk about what’s actually weird in your data.
023
Reposted by THOR Collective
sydney @letswastetime.bsky.social · 24/04/2025
🪦 D.E.A.T.H. comes in many forms, and so does thrunting. Check out the latest @thorcollective.bsky.social Dispatch covering three ways to implement these! dispatch.thorcollective.com/p/the-models... #threathunting #thrunting #detectionengineering #THORcollective #cybersecurity #DEATH #infosec
dispatch.thorcollective.com
The Model(s) of D.E.A.T.H & Thrunt
There Can Only (Not) Be One
022
Reposted by THOR Collective
sydney @letswastetime.bsky.social · 17/04/2025
When incidents hit, how you communicate shapes the outcome. This week’s @thorcollective.bsky.social Dispatch features @audrastreetman.bsky.social, former journalist turned cyber intel analyst. dispatch.thorcollective.com/p/how-commun...
dispatch.thorcollective.com
How Communication Shapes the Outcome of Cybersecurity Incidents
Why the timing and transparency of messaging can make or break your incident response
143
Reposted by THOR Collective
sydney @letswastetime.bsky.social · 03/04/2025
Hunting smarter ≠ harder. In this week's @thorcollective.bsky.social post, Sai Molige introduces the LAYER approach, turning strategy into practical threat hunting moves. dispatch.thorcollective.com/p/the-power-... #infosec #threathunting #thrunting #blueteam #threatdetection #THORcollective
dispatch.thorcollective.com
The Power of the Trio
Introducing the LAYER Approach
011
Reposted by THOR Collective
sydney @letswastetime.bsky.social · 08/04/2025
Because logs don’t hunt themselves 😤 We just kicked off a new series on @thorcollective.bsky.social Dispatch called SPL Dispatch, where we break down powerful Splunk commands through a threat hunting lens. First up: tstats dispatch.thorcollective.com/p/because-lo...
dispatch.thorcollective.com
Because Logs Don’t Hunt Themselves - A Deep Dive into tstats
SPL Dispatch #1 - 04/08/2025
011
Reposted by THOR Collective
sydney @letswastetime.bsky.social · 20/03/2025
🔥 New Dispatch 🔥 In our latest guest post, Alex Hurtado talks the 2025 State of Detection Engineering Report. tl;dr: Off-the-shelf detections won't save you. Your environment deserves better. dispatch.thorcollective.com/p/detection-... #detectionengineering #threathunting #thrunting #THORcollective
dispatch.thorcollective.com
Detection Engineering: DIY or Die Trying
There’s a rising practice becoming the critical backbone of SecOps—and surprise, it’s not CNAPP. Sorry, unicorn Wiz.
032
Reposted by THOR Collective
sydney @letswastetime.bsky.social · 13/03/2025
🔥Latest Dispatch: HEARTH🔥 HEARTH (Hunting Exchange and Research Threat Hub) is an open-source project for sharing and refining threat hunting ideas. Learn what it is and how to contribute: dispatch.thorcollective.com/p/introducin... #ThreatHunting #Thrunting #Cybersecurity #HEARTH #THORcollective
dispatch.thorcollective.com
Introducing HEARTH: A Community-Driven Threat Hunting Repository
Threat hunting is an art and a science.
023
Reposted by THOR Collective
sydney @letswastetime.bsky.social · 11/03/2025
🚨 New Dispatch Drop 🚨 Attackers will get in—just give them time. In this week's @thorcollective.bsky.social Dispatch, we talk why security teams must test their defenses: dispatch.thorcollective.com/p/why-cybers... #threathunting #thrunting #cybersecurity #infosec #purpleteam #THORcollective
dispatch.thorcollective.com
Why Cybersecurity Teams Need to Break Their Own Defenses
If you’re not testing your security, you don’t have security.
022
Reposted by THOR Collective
sydney @letswastetime.bsky.social · 27/02/2025
Excited to share our latest post from @thorcollective.bsky.social Dispatch! @ednas.bsky.social dives into Splunk DECEIVE, an AI-powered honeypot by @davidjbianco.bsky.social. Read more: dispatch.thorcollective.com/p/exploring-... #cybersecurity #infosec #AI #thrunting #THORCollective #splunk
dispatch.thorcollective.com
Exploring Splunk DECEIVE
The AI Queen bee does DECEIVE
024
Reposted by THOR Collective
sydney @letswastetime.bsky.social · 20/02/2025
Tired of getting ghosted by endless events? The five-number summary is your threat-hunting sidekick. Check out our latest @thorcollective.bsky.social Dispatch. Join us👉: dispatch.thorcollective.com/p/stop-chasi... #threathunting #thrunting #cybersecurity #mathiscool #THORCollective
dispatch.thorcollective.com
Stop Chasing Ghosts: How Five-Number Summaries Reveal Real Anomalies
Boo. No séance required.
022
Reposted by THOR Collective
sydney @letswastetime.bsky.social · 11/02/2025
🐘 Let’s address the elephant in the room — #thrunting is a thing now, and it stuck. Why? Because thrunting has that perfect blend of #hacker culture & "I dare you to question this term" energy. 🔥 Keep thrunting. 👉 dispatch.thorcollective.com/p/the-case-f... #threathunting #cybersecurity #infosec
dispatch.thorcollective.com
The Case for Thrunting
Why Thrunting Is Here to Stay
132
Reposted by THOR Collective
sydney @letswastetime.bsky.social · 06/02/2025
🚀 Attention Thrunters!🚀 Part 3 of the DEATHCon thrunting workshop is live! @jotunvillur.bsky.social and I break down a hypothesis-driven scenario step by step. Grab your hammer and sharpen your skills! 🛠️ Read now: dispatch.thorcollective.com/p/a-deathcon... #threathunting #thrunting #cybersecurity
dispatch.thorcollective.com
A DEATHCON Thrunting Workshop Overview Part 3: ⚡ Hypothesis-Driven Threat Hunting
Detecting /etc/passwd File Access and Exfiltration in HTTP Traffic
032
Reposted by THOR Collective
sydney @letswastetime.bsky.social · 30/01/2025
🚀 THOR Collective Dispatch is live! Your go to source for threat hunting insights and community-driven content. 📩 Check it out & subscribe: dispatch.thorcollective.com We appreciate any support, every spark keeps the fire burning. 🔥 #threathunting #cybersecurity #THORCollective
dispatch.thorcollective.com
THOR Collective Dispatch | Sydney Marrone | Substack
A hub for threat hunters (thrunters) and security professionals. Explore cutting-edge ideas, practical frameworks, and community-driven insights in cybersecurity. Powered by collaboration, innovation,...
011
Reposted by THOR Collective
LP @jotunvillur.bsky.social · 26/01/2025
@thorcollective.bsky.social dropped a new blog "Helloooooooo, Thrunters!" 😤 It kicks off a series from a workshop @letswastetime.bsky.social and I gave at #DEATHCon on #threathunting with the PEAK framework. Read at: thorcollective.com/helloooooooo... #cybersecurity #thrunting #THORCollective
thorcollective.com
Helloooooooo thrunters 👋
A DEATHCON Thrunting Workshop Overview
043
Reposted by THOR Collective
sydney @letswastetime.bsky.social · 26/01/2025
@thorcollective.bsky.social dropped a new blog "Helloooooooo, Thrunters!" 😤 It kicks off a series from a workshop @jotunvillur.bsky.social and I gave at #DEATHCon on #threathunting with the PEAK framework. Start reading: thorcollective.com/helloooooooo... #cybersecurity #thrunting #THORCollective
thorcollective.com
Helloooooooo thrunters 👋
A DEATHCON Thrunting Workshop Overview
032