Hi thrunters! We’re on a well-earned December break. Stay tuned for an end-of-year post and a podcast episode with the OG Detection Dispatcher, Alex Hurtado!
We at @thorcollective.bsky.social are waking you up before September ends, because a new Ask-a-Thrunt3r episode just dropped with: 2K subscriber milestone 🎉 15 baseline examples The great data vs. data debate Plus: Is Git the future of hunting collab? 🎧: dispatch.thorcollective.com/p/ask-a-thru...
Ask-a-Thrunt3r: September 2025 Recap 🐏
Mainly ramblings. And maybe some wisdom.
dispatch.thorcollective.com
✨ Representation is STILL a security issue. ✨ @thorcollective.bsky.social Dispatch with @kassafras09.bsky.social from March. The message still stands. • Fix biased job reqs • Put diverse voices on panels • Mentor future hackers • Model inclusive leadership dispatch.thorcollective.com/p/why-we-nee...
Why We Need More Women and Intersectional Diversity in Cyber (And How to Get There)
Representation matters in cybersecurity. Here’s why—and what we can do about it.
dispatch.thorcollective.com
The Hacker Summer Camp starter pack: ⚡ Stickers ⚡ Patches ⚡ Coins ⚡ Wristbands ⚡ Temporary THRUNT tattoos Find the @thorcollective.bsky.social crew in Vegas. Say hi and get some swag 👀
Shoutout to our fam Elipscion, who's spinning live at DEF CON 33 this Friday at 8pm on the DEF CON stage. 🎧 Listen here: open.spotify.com/artist/2tgPZ... 🔥 Join our @thorcollective.bsky.social meetup during his set. Say hi, talk hunts, and grab some free swag. See you there!
ELIPSCION
Artist · 10 monthly listeners.
open.spotify.com
Threat hunting is broken. We can’t out-query adversaries who automate everything. Enter the agentic threat hunter. An AI that thinks, hypothesizes, investigates, and scales. In the latest @thorcollective.bsky.social Dispatch, we explore this shift: 📌 dispatch.thorcollective.com/p/the-agenti...
🚨New post on @thorcollective.bsky.social Dispatch🚨 Tired of getting ignored after dropping a valid XSS vuln? Stop showing alert(1) pop-ups & start stealing sessions. Make it real. Bring a bit of pain. Read it here 👉 open.substack.com/pub/thorcoll...
Make It Hurt (a Little): Why Showing Real Impact in Pentest Findings Matters
“Cool alert box, bro. Now what?”
open.substack.com
We’re giving away another THOR Collective Challenge Coin. Ask-a-Thrunter drops early August (recording July 31). Hacker Summer Camp vibes guaranteed. 🎟️ Join our paid sub for giveaways + Discord. 💬 Questions? Drop ’em. radio.thorcollective.com
Redirecting…
If you’re not redirected, click here.
radio.thorcollective.com
New from @thorcollective.bsky.social Dispatch: If You Like It Then You Should’ve Put a timechart on It We’re diving into why timechart is a threat hunter’s best friend. From beaconing to privilege spikes, baselines, and more. Read it here 👉 dispatch.thorcollective.com/p/if-you-lik...
If You Like It Then You Should've Put a timechart on It
Hey thrunters, gather ’round: timechart’s up
dispatch.thorcollective.com
No @thorcollective.bsky.social Dispatch posts this week. We’re taking a breather to rest and recharge. We'll be back next week, ready to thrunt. #threathunting #thrunting #THORcollective #cybersecurity #infosec
THRUNTING isn’t just a buzzword. It’s a mindset. 🐑 Inspired by Tim Peters’ 19 aphorisms for Python, @thorcollective.bsky.social Dispatch introduces "The Zen of Thrunting." dispatch.thorcollective.com/p/the-zen-of... Stay curious. Happy thrunting.
The Zen of Thrunting
Abstract
dispatch.thorcollective.com
Dispatch Debrief: June 2025 Everything’s fine… until it isn’t. This month’s @thorcollective.bsky.social Dispatch served up a spicy mix of threat hunting, plugin paranoia, purple teaming insights, and a few thrunting curveballs to keep you sharp. 🌶️ dispatch.thorcollective.com/p/dispatch-d...
Dispatch Debrief: June 2025
Because "Everything's Fine" is Just Another Way of Saying "I Haven't Looked Yet"
dispatch.thorcollective.com
New guest post on thorcollective.bsky.social Dispatch from infosecsherpa.bsky.social: Don’t Let Mis(s) Information Take the Crown 👑 This post shows how to apply the Intelligence Cycle to news and help you filter bias. Read it here: dispatch.thorcollective.com/p/dont-let-m...
Don't Let Mis(s) Information Take the Crown
Sherpa Intelligence: Your Guide Up a Mountain of Information!
dispatch.thorcollective.com
This month’s Dispatch Giveaway is live! 🔥 One lucky paid subscriber will win a thorcollective.bsky.social challenge coin! 🗓️ June 26 @ 7PM PT Streaming live in our private Discord Podcast drops for everyone the following week ➡️ Join the Collective: dispatch.thorcollective.com
THOR Collective Dispatch | Sydney Marrone | Substack
A hub for threat hunters (thrunters) and security professionals. Explore cutting-edge ideas, practical frameworks, and community-driven insights in cybersecurity. Powered by collaboration,…
dispatch.thorcollective.com
⚡ New @thorcollective.bsky.social Dispatch drop No hallucinations here. Just TTPs that quietly defined Q1 2025. 🔐 OAuth abuse 📦 Malicious packages 🖥️ SimpleHelp RMM exploits Stay ahead with what to hunt & where to look. 👉 dispatch.thorcollective.com/p/from-the-f... #THORCollective #threathunting
From the Fire: Q1FY25
TTPs that sparked, spread, and still burn for those paying attention.
dispatch.thorcollective.com
The May Dispatch is live. Fresh insights from @thorcollective.bsky.social and guest contributors on detection in depth, AI in the SOC, career overlaps, and making your hunts actually matter. Plus memes. Obviously. 👉 dispatch.thorcollective.com/p/dispatch-d...
Dispatch Debrief: May 2025
Quiet logs, loud analysts, and AI besties. Just another month in the hunt.
dispatch.thorcollective.com
🐏 Ask a Thrunter AMA + Giveaway! Join @thorcollective.bsky.social live next THORsday, May 29th @ 7pm PT in Discord. We’ve got a special announcement + we’ll reveal the monthly giveaway winner (all paid Dispatch subscribers automatically entered!). Submit your questions early👇
Introverts rewrite detection rules repeatedly, while extroverts demo them mid-draft. In cybersecurity, you need both. Today's @thorcollective.bsky.social Dispatch features Alex Hurtado, highlighting how embracing differences strengthens SOC teams. 👉 : dispatch.thorcollective.com/p/quiet-loud...
Quiet, Loud, and in the Logfiles: The Detection Duo You Didn’t Know You Needed
Filed under: Things your agent can’t do but Linda from SecOps does without breaking a sweat.
dispatch.thorcollective.com
🚨 New guest drop on @THOR_Collective Dispatch! 🚨 "Exploring Cybersecurity Career Paths and How They Work Together" by Audra Streetman Whether you're into offense, intel, or cyber defense, there's a path for you! Read it here: dispatch.thorcollective.com/p/exploring-...
💥 New SPL Dispatch drop from @thorcollective.bsky.social : eventstats 💥 Want to flag weird behavior without losing raw data? eventstats lets you compare each event to the group without rolling things up. Read it here 👉 dispatch.thorcollective.com/p/every-even...
Every Event for Itself…Until You Run eventstats
SPL Dispatch #2 - 05/13/2025
dispatch.thorcollective.com
💡 New guest drop on @thorcollective.bsky.social Dispatch: "Detection-in-Depth" by Day Johnson. Day covers how to build resilient detection systems that handle real-world challenges, from fine-tuning rules to threat emulation and kill chain coverage. dispatch.thorcollective.com/p/detection-...
Detection-In-Depth
Eliminating detection blind spots through a multi-layered defense approach
dispatch.thorcollective.com
🎧 Ask-a-Thrunter: Episode 1 is live! @thorcollective.bsky.social covered everything from hunt standups to VirusTotal vs. behavioral hunting and announced our April giveaway winner! Replay: dispatch.thorcollective.com/p/ask-a-thru... Should we make this monthly? Drop a comment below.
Ask-a-Thrunter: The Recap Is Here 🐏
Mainly ramblings. And maybe some wisdom.
dispatch.thorcollective.com
🔥 Dispatch Debrief: April 2025 is live 🔥 Explore star sign-inspired hunting techniques, organizing your hunt squad, and the value of finding "nothing." Discover this month's insights from @thorcollective.bsky.social Dispatch - dispatch.thorcollective.com/p/april-debr...
Dispatch Debrief: April 2025
What We Hunted, Learned, and Loved This Month
dispatch.thorcollective.com
Ask-a-Thrunter is live this THORsday, May 1 @ 7pm PDT — paid subscribers only. Join us in the @thorcollective.bsky.social Discord for solid answers, spicy takes, and the April giveaway winner reveal. Drop your questions below. Not subscribed? Replay drops next week. Come thrunt with us 🐏
Normal is overrated. Hunt the outliers with Z-scores and standard deviation in the new @thorcollective.bsky.social Dispatch post. Read it here: dispatch.thorcollective.com/p/z-scoring-... #threathunting #thrunting #detectionengineering #infosec #cybersecurity #splunk #statistics
Z-Scoring Your Way to Better Threat Detection
“Normal” is just a setting on a dryer. Let’s talk about what’s actually weird in your data.
dispatch.thorcollective.com
🪦 D.E.A.T.H. comes in many forms, and so does thrunting. Check out the latest @thorcollective.bsky.social Dispatch covering three ways to implement these! dispatch.thorcollective.com/p/the-models... #threathunting #thrunting #detectionengineering #THORcollective #cybersecurity #DEATH #infosec
The Model(s) of D.E.A.T.H & Thrunt
There Can Only (Not) Be One
dispatch.thorcollective.com
When incidents hit, how you communicate shapes the outcome. This week’s @thorcollective.bsky.social Dispatch features @audrastreetman.bsky.social, former journalist turned cyber intel analyst. dispatch.thorcollective.com/p/how-commun...
How Communication Shapes the Outcome of Cybersecurity Incidents
Why the timing and transparency of messaging can make or break your incident response
dispatch.thorcollective.com
Hunting smarter ≠ harder. In this week's @thorcollective.bsky.social post, Sai Molige introduces the LAYER approach, turning strategy into practical threat hunting moves. dispatch.thorcollective.com/p/the-power-... #infosec #threathunting #thrunting #blueteam #threatdetection #THORcollective
The Power of the Trio
Introducing the LAYER Approach
dispatch.thorcollective.com
Because logs don’t hunt themselves 😤 We just kicked off a new series on @thorcollective.bsky.social Dispatch called SPL Dispatch, where we break down powerful Splunk commands through a threat hunting lens. First up: tstats dispatch.thorcollective.com/p/because-lo...
Because Logs Don’t Hunt Themselves - A Deep Dive into tstats
SPL Dispatch #1 - 04/08/2025
dispatch.thorcollective.com