Meet Sliver Armory BOFs. Tiny in-memory payloads you run from a beacon to test technique-based detections, not filenames. Cleaner telemetry, repeatable tests, real thrunting value. Read here: dispatch.thorcollective.com/p/sliver-bof...
Meet Sliver Armory BOFs. Tiny in-memory payloads you run from a beacon to test technique-based detections, not filenames. Cleaner telemetry, repeatable tests, real thrunting value. Read here: dispatch.thorcollective.com/p/sliver-bof...
👉 dispatch.thorcollective.com/p/hunting-be...
👉 dispatch.thorcollective.com/p/hunting-be...
This week’s @thorcollective.bsky.social SPL Dispatch breaks down how to use timechart to uncover rhythm, automation, and the a cron job masquerading as “normal.”
dispatch.thorcollective.com/p/the-shape-...
This week’s @thorcollective.bsky.social SPL Dispatch breaks down how to use timechart to uncover rhythm, automation, and the a cron job masquerading as “normal.”
dispatch.thorcollective.com/p/the-shape-...
Part 2 of the @thorcollective.bsky.social Dispatch Agentic Threat Hunting series covers the first step to scaling: put your hunts in a GitHub repo and give your AI bestie memory.
dispatch.thorcollective.com/p/agentic-th...
Part 2 of the @thorcollective.bsky.social Dispatch Agentic Threat Hunting series covers the first step to scaling: put your hunts in a GitHub repo and give your AI bestie memory.
dispatch.thorcollective.com/p/agentic-th...
🔗 dispatch.thorcollective.com/p/dispatch-d...
🔗 dispatch.thorcollective.com/p/dispatch-d...
@thorcollective.bsky.social
just dropped 10 baseline hunts you can shine in the dark parts of your env and magnify the adversaries from the noise.
Join us for all the thrunting 👉: open.substack.com/pub/thorcoll...
#threathunting #infosec
@thorcollective.bsky.social
just dropped 10 baseline hunts you can shine in the dark parts of your env and magnify the adversaries from the noise.
Join us for all the thrunting 👉: open.substack.com/pub/thorcoll...
#threathunting #infosec
In this week’s @thorcollective.bsky.social Dispatch, Courtney Shar shares how project management skills like risk alignment, process design, and team coordination directly strengthen security programs.
👉 dispatch.thorcollective.com/p/beyond-hac...
In this week’s @thorcollective.bsky.social Dispatch, Courtney Shar shares how project management skills like risk alignment, process design, and team coordination directly strengthen security programs.
👉 dispatch.thorcollective.com/p/beyond-hac...
Join @johntuckner.me for @thorcollective.bsky.social
and learn how to hunt the dangerous ones before they hunt you:
thorcollective.substack.com/p/even-if-ma...
#cybersecurity #infosec #threathunting #thrunting
Join @johntuckner.me for @thorcollective.bsky.social
and learn how to hunt the dangerous ones before they hunt you:
thorcollective.substack.com/p/even-if-ma...
#cybersecurity #infosec #threathunting #thrunting
Certis Foster didn't hunt for it.
It revealed itself.
The key? Plotting behavior in 3D space:
🕒 Time
🗺️ Terrain
🎯 Behavior
Outliers can’t hide in 3D.
dispatch.thorcollective.com/p/cant-hide-...
#threathunting #thrunting #THORcollective
Certis Foster didn't hunt for it.
It revealed itself.
The key? Plotting behavior in 3D space:
🕒 Time
🗺️ Terrain
🎯 Behavior
Outliers can’t hide in 3D.
dispatch.thorcollective.com/p/cant-hide-...
#threathunting #thrunting #THORcollective
Our latest @thorcollective.bsky.social Dispatch post breaks down 5 baselines every thrunter needs.
Map normal. Track drift. Catch threats.
Read here: dispatch.thorcollective.com/p/you-cant-f...
Our latest @thorcollective.bsky.social Dispatch post breaks down 5 baselines every thrunter needs.
Map normal. Track drift. Catch threats.
Read here: dispatch.thorcollective.com/p/you-cant-f...
But the hunts never stopped, and this month we’re back with fresh chaos, AI wisdom, and a noob’s-eye view of DEF CON.
👉 Catch the @thorcollective.bsky.social August Dispatch: dispatch.thorcollective.com/p/dispatch-d...
But the hunts never stopped, and this month we’re back with fresh chaos, AI wisdom, and a noob’s-eye view of DEF CON.
👉 Catch the @thorcollective.bsky.social August Dispatch: dispatch.thorcollective.com/p/dispatch-d...
Hunters must shift: hunt intent, not just indicators.
👉 New guest post by Damien Lewke on @thorcollective.bsky.social Dispatch: dispatch.thorcollective.com/p/the-quiet-...
Hunters must shift: hunt intent, not just indicators.
👉 New guest post by Damien Lewke on @thorcollective.bsky.social Dispatch: dispatch.thorcollective.com/p/the-quiet-...
dispatch.thorcollective.com/p/my-first-d...
dispatch.thorcollective.com/p/my-first-d...
🎧 Listen here: open.spotify.com/artist/2tgPZ...
🔥 Join our @thorcollective.bsky.social meetup during his set. Say hi, talk hunts, and grab some free swag. See you there!
🎧 Listen here: open.spotify.com/artist/2tgPZ...
🔥 Join our @thorcollective.bsky.social meetup during his set. Say hi, talk hunts, and grab some free swag. See you there!
We can’t out-query adversaries who automate everything.
Enter the agentic threat hunter. An AI that thinks, hypothesizes, investigates, and scales.
In the latest @thorcollective.bsky.social Dispatch, we explore this shift:
📌 dispatch.thorcollective.com/p/the-agenti...
We can’t out-query adversaries who automate everything.
Enter the agentic threat hunter. An AI that thinks, hypothesizes, investigates, and scales.
In the latest @thorcollective.bsky.social Dispatch, we explore this shift:
📌 dispatch.thorcollective.com/p/the-agenti...
I wrote a survival guide for DEF CON, Black Hat, etc.
- Pick your purpose
- Villages > talks
- Hallway track is real
- You belong here
👽 dispatch.thorcollective.com/p/con-101-ho...
@thorcollective.bsky.social will be out there with thrunting stickers—come say hi.
I wrote a survival guide for DEF CON, Black Hat, etc.
- Pick your purpose
- Villages > talks
- Hallway track is real
- You belong here
👽 dispatch.thorcollective.com/p/con-101-ho...
@thorcollective.bsky.social will be out there with thrunting stickers—come say hi.
Tired of getting ignored after dropping a valid XSS vuln?
Stop showing alert(1) pop-ups & start stealing sessions.
Make it real. Bring a bit of pain.
Read it here 👉 open.substack.com/pub/thorcoll...
Tired of getting ignored after dropping a valid XSS vuln?
Stop showing alert(1) pop-ups & start stealing sessions.
Make it real. Bring a bit of pain.
Read it here 👉 open.substack.com/pub/thorcoll...
We’re diving into why timechart is a threat hunter’s best friend. From beaconing to privilege spikes, baselines, and more.
Read it here 👉 dispatch.thorcollective.com/p/if-you-lik...
We’re diving into why timechart is a threat hunter’s best friend. From beaconing to privilege spikes, baselines, and more.
Read it here 👉 dispatch.thorcollective.com/p/if-you-lik...
Inspired by Tim Peters’ 19 aphorisms for Python, @thorcollective.bsky.social Dispatch introduces "The Zen of Thrunting."
dispatch.thorcollective.com/p/the-zen-of...
Stay curious. Happy thrunting.
Inspired by Tim Peters’ 19 aphorisms for Python, @thorcollective.bsky.social Dispatch introduces "The Zen of Thrunting."
dispatch.thorcollective.com/p/the-zen-of...
Stay curious. Happy thrunting.
Everything’s fine… until it isn’t.
This month’s @thorcollective.bsky.social Dispatch served up a spicy mix of threat hunting, plugin paranoia, purple teaming insights, and a few thrunting curveballs to keep you sharp.
🌶️ dispatch.thorcollective.com/p/dispatch-d...
Everything’s fine… until it isn’t.
This month’s @thorcollective.bsky.social Dispatch served up a spicy mix of threat hunting, plugin paranoia, purple teaming insights, and a few thrunting curveballs to keep you sharp.
🌶️ dispatch.thorcollective.com/p/dispatch-d...
New on @thorcollective.bsky.social Dispatch: five hunt ideas + a PEAK deep dive into sneaky plugin abuse.
Start with visibility. Hunt what blends in.
📖 dispatch.thorcollective.com/p/your-plugi...
New on @thorcollective.bsky.social Dispatch: five hunt ideas + a PEAK deep dive into sneaky plugin abuse.
Start with visibility. Hunt what blends in.
📖 dispatch.thorcollective.com/p/your-plugi...
Don’t Let Mis(s) Information Take the Crown 👑
This post shows how to apply the Intelligence Cycle to news and help you filter bias.
Read it here: dispatch.thorcollective.com/p/dont-let-m...
Don’t Let Mis(s) Information Take the Crown 👑
This post shows how to apply the Intelligence Cycle to news and help you filter bias.
Read it here: dispatch.thorcollective.com/p/dont-let-m...
No hallucinations here. Just TTPs that quietly defined Q1 2025.
🔐 OAuth abuse
📦 Malicious packages
🖥️ SimpleHelp RMM exploits
Stay ahead with what to hunt & where to look.
👉 dispatch.thorcollective.com/p/from-the-f...
#THORCollective
#threathunting
No hallucinations here. Just TTPs that quietly defined Q1 2025.
🔐 OAuth abuse
📦 Malicious packages
🖥️ SimpleHelp RMM exploits
Stay ahead with what to hunt & where to look.
👉 dispatch.thorcollective.com/p/from-the-f...
#THORCollective
#threathunting
Red with Benefits: Purple Teaming with Sliver Beacons
Sliver isn’t just for flexing during pentests, it’s your new favorite detection engineering wingman.
👇
dispatch.thorcollective.com/p/red-with-b...
Red with Benefits: Purple Teaming with Sliver Beacons
Sliver isn’t just for flexing during pentests, it’s your new favorite detection engineering wingman.
👇
dispatch.thorcollective.com/p/red-with-b...
Fresh insights from @thorcollective.bsky.social and guest contributors on detection in depth, AI in the SOC, career overlaps, and making your hunts actually matter.
Plus memes. Obviously.
👉 dispatch.thorcollective.com/p/dispatch-d...
Fresh insights from @thorcollective.bsky.social and guest contributors on detection in depth, AI in the SOC, career overlaps, and making your hunts actually matter.
Plus memes. Obviously.
👉 dispatch.thorcollective.com/p/dispatch-d...