's Avatar

@drterdnugget

5
Followers
11
Following
9
Posts
14.03.2025
Joined
Posts Following

Latest posts by @drterdnugget

Post image

You don’t need a desk to build.

I used AI more from my phone last month than from my desk. What mattered was removing friction and building where ideas show up.

👉 New on @thorcollective.bsky.social Dispatch:
dispatch.thorcollective.com/p/you-dont-n...

27.01.2026 15:37 👍 1 🔁 1 💬 1 📌 0
Post image

“I’m not a developer” is a self-imposed limit.

If you’ve written a query, a script, or an automation to fix a problem, you’re already building.

In the latest @thorcollective.bsky.social Dispatch, we talk about why building is a core security skill.

dispatch.thorcollective.com/p/why-you-sh...

20.01.2026 16:30 👍 1 🔁 1 💬 1 📌 0
Preview
Aligning Risk Management and Threat-Informed Defense Practices (Part 2) We’re back with part two of a series analyzing how to align common GRC tasks/teams with SecOps and threat-informed defense practices.

🚨New post on @THOR_Collective Dispatch🚨

“Aligning Risk Management and Threat-Informed Defense Practices (Part 2)” by Micah VanFossen

What happens when you sync risk, controls, and threat intel to drive real-security outcomes.

dispatch.thorcollective.com/p/aligning-r...

#thrunting #grc

20.11.2025 16:17 👍 2 🔁 1 💬 0 📌 0
Preview
Purple Teaming in the Real World: When Everything Goes Off the Rails (and That’s Normal) People love the glossy version of purple teaming:

🚨New post on @THOR_Collective Dispatch🚨
Purple teaming isn’t shiny. It’s delays, blockers, tickets & pivots. And that’s okay.
open.substack.com/pub/thorcoll...
#thrunting #PurpleTeaming

18.11.2025 14:00 👍 1 🔁 1 💬 0 📌 0
Preview
Sliver BOFs in Action: Bringing Sliver Armory BOFs to Purple Teaming When I first wrote about Sliver beacons in purple teaming, the point was simple: implants aren’t just red-team toys, they’re teaching tools for defenders.

🚨New post on @THOR_Collective Dispatch🚨

Meet Sliver Armory BOFs. Tiny in-memory payloads you run from a beacon to test technique-based detections, not filenames. Cleaner telemetry, repeatable tests, real thrunting value. Read here: dispatch.thorcollective.com/p/sliver-bof...

14.10.2025 18:00 👍 0 🔁 0 💬 0 📌 0
Post image

In this week’s @thorcollective.bsky.social Dispatch, Sam Hanson lays out how to move beyond indicator-based hunting and build detection muscle that actually scales.

👉 dispatch.thorcollective.com/p/hunting-be...

09.10.2025 19:01 👍 1 🔁 1 💬 1 📌 0

If tstats gives you speed and eventstats gives you context...timechart gives you shape.

This week’s @thorcollective.bsky.social SPL Dispatch breaks down how to use timechart to uncover rhythm, automation, and the a cron job masquerading as “normal.”

dispatch.thorcollective.com/p/the-shape-...

07.10.2025 23:15 👍 1 🔁 1 💬 1 📌 0
Post image

Threat hunting falls apart when your “docs” live in Slack threads.

Part 2 of the @thorcollective.bsky.social Dispatch Agentic Threat Hunting series covers the first step to scaling: put your hunts in a GitHub repo and give your AI bestie memory.

dispatch.thorcollective.com/p/agentic-th...

02.10.2025 22:15 👍 2 🔁 2 💬 1 📌 0
Post image

From temporal to behavioral, baselines are the thrunter’s compass. September’s Dispatch from @thorcollective.bsky.social shows how to use them to sharpen the hunt and includes ten baseline hunts you should be running now.
🔗 dispatch.thorcollective.com/p/dispatch-d...

26.09.2025 15:15 👍 3 🔁 2 💬 1 📌 0

You can’t find weird if you don’t know normal.

@thorcollective.bsky.social
just dropped 10 baseline hunts you can shine in the dark parts of your env and magnify the adversaries from the noise.

Join us for all the thrunting 👉: open.substack.com/pub/thorcoll...

#threathunting #infosec

23.09.2025 20:51 👍 2 🔁 2 💬 0 📌 0

Cybersecurity needs more than hackers in hoodies.

In this week’s @thorcollective.bsky.social Dispatch, Courtney Shar shares how project management skills like risk alignment, process design, and team coordination directly strengthen security programs.

👉 dispatch.thorcollective.com/p/beyond-hac...

16.09.2025 15:15 👍 6 🔁 3 💬 1 📌 0
Preview
Even if many plugins are fine, the bad ones are BAD Sydney recently wrote a great piece about extensions and hunting for IDE plugins.

🚨 Think your browser extensions are harmless?

Join @johntuckner.me for @thorcollective.bsky.social
and learn how to hunt the dangerous ones before they hunt you:

thorcollective.substack.com/p/even-if-ma...

#cybersecurity #infosec #threathunting #thrunting

12.09.2025 20:20 👍 3 🔁 2 💬 0 📌 0
Preview
Can't Hide in 3D In a sea of millions of security events, one workstation literally stood out, floating high above all the others when I transformed flat logs into a 3D visualization.

🚨New post on @thorcollective.bsky.social Dispatch 🚨

Certis Foster didn't hunt for it.
It revealed itself.

The key? Plotting behavior in 3D space:

🕒 Time
🗺️ Terrain
🎯 Behavior

Outliers can’t hide in 3D.

dispatch.thorcollective.com/p/cant-hide-...

#threathunting #thrunting #THORcollective

05.09.2025 00:31 👍 1 🔁 1 💬 0 📌 0
Preview
You Can't Find Weird If You Don't Know Normal Five baselines with hunt queries you can run today

If you don’t know what “normal” looks like in your environment, you’re not hunting...you’re hoping.

Our latest @thorcollective.bsky.social Dispatch post breaks down 5 baselines every thrunter needs.

Map normal. Track drift. Catch threats.

Read here: dispatch.thorcollective.com/p/you-cant-f...

02.09.2025 15:15 👍 2 🔁 1 💬 1 📌 0
Post image

Summertime sadness hit the Dispatch hard: sunscreen > screen time. 🌞
But the hunts never stopped, and this month we’re back with fresh chaos, AI wisdom, and a noob’s-eye view of DEF CON.

👉 Catch the @thorcollective.bsky.social August Dispatch: dispatch.thorcollective.com/p/dispatch-d...

28.08.2025 15:15 👍 1 🔁 1 💬 1 📌 0
Post image

The Quiet War isn’t loud breaches or ransomware. It’s subtle. AI-driven adversaries are blending in and evading detection.

Hunters must shift: hunt intent, not just indicators.

👉 New guest post by Damien Lewke on @thorcollective.bsky.social Dispatch: dispatch.thorcollective.com/p/the-quiet-...

21.08.2025 15:10 👍 1 🔁 1 💬 0 📌 0
Post image

What happens when you throw yourself into DEFCON for the very first time? You get Line Con, Noob Village wisdom, hacker merch battles, Flipper Zero impulse buys, Hacker Jeopardy chaos, and the realization that DEFCON is not just a con, it is a community.

dispatch.thorcollective.com/p/my-first-d...

19.08.2025 15:40 👍 3 🔁 1 💬 1 📌 0
Preview
ELIPSCION Artist · 10 monthly listeners.

Shoutout to our fam Elipscion, who's spinning live at DEF CON 33 this Friday at 8pm on the DEF CON stage.
🎧 Listen here: open.spotify.com/artist/2tgPZ...

🔥 Join our @thorcollective.bsky.social meetup during his set. Say hi, talk hunts, and grab some free swag. See you there!

04.08.2025 17:30 👍 3 🔁 3 💬 1 📌 0
Post image

Threat hunting is broken.
We can’t out-query adversaries who automate everything.
Enter the agentic threat hunter. An AI that thinks, hypothesizes, investigates, and scales.

In the latest @thorcollective.bsky.social Dispatch, we explore this shift:

📌 dispatch.thorcollective.com/p/the-agenti...

27.07.2025 16:34 👍 3 🔁 3 💬 1 📌 0
Post image

Heading to hacker summer camp?

I wrote a survival guide for DEF CON, Black Hat, etc.

- Pick your purpose
- Villages > talks
- Hallway track is real
- You belong here

👽 dispatch.thorcollective.com/p/con-101-ho...

@thorcollective.bsky.social will be out there with thrunting stickers—come say hi.

24.07.2025 16:21 👍 2 🔁 1 💬 1 📌 0
Preview
Make It Hurt (a Little): Why Showing Real Impact in Pentest Findings Matters “Cool alert box, bro. Now what?”

🚨New post on @thorcollective.bsky.social Dispatch🚨
Tired of getting ignored after dropping a valid XSS vuln?
Stop showing alert(1) pop-ups & start stealing sessions.
Make it real. Bring a bit of pain.
Read it here 👉 open.substack.com/pub/thorcoll...

22.07.2025 14:30 👍 1 🔁 1 💬 0 📌 0
Preview
If You Like It Then You Should've Put a timechart on It Hey thrunters, gather ’round: timechart’s up

New from @thorcollective.bsky.social Dispatch: If You Like It Then You Should’ve Put a timechart on It

We’re diving into why timechart is a threat hunter’s best friend. From beaconing to privilege spikes, baselines, and more.

Read it here 👉 dispatch.thorcollective.com/p/if-you-lik...

15.07.2025 15:05 👍 3 🔁 3 💬 1 📌 0
Preview
The Zen of Thrunting Abstract

THRUNTING isn’t just a buzzword. It’s a mindset. 🐑

Inspired by Tim Peters’ 19 aphorisms for Python, @thorcollective.bsky.social Dispatch introduces "The Zen of Thrunting."

dispatch.thorcollective.com/p/the-zen-of...

Stay curious. Happy thrunting.

03.07.2025 15:11 👍 4 🔁 3 💬 1 📌 0
Preview
Dispatch Debrief: June 2025 Because "Everything's Fine" is Just Another Way of Saying "I Haven't Looked Yet"

Dispatch Debrief: June 2025

Everything’s fine… until it isn’t.

This month’s @thorcollective.bsky.social Dispatch served up a spicy mix of threat hunting, plugin paranoia, purple teaming insights, and a few thrunting curveballs to keep you sharp.

🌶️ dispatch.thorcollective.com/p/dispatch-d...

26.06.2025 15:09 👍 3 🔁 2 💬 1 📌 0
Preview
Your Plugins and Extensions Are (Probably) Fine. Hunt Them Anyway. Five hunt ideas (and one deep dive) for abuse hiding in plain sight.

🔌 That browser extension? That IDE plugin? Might not be doing what you think.

New on @thorcollective.bsky.social Dispatch: five hunt ideas + a PEAK deep dive into sneaky plugin abuse.

Start with visibility. Hunt what blends in.

📖 dispatch.thorcollective.com/p/your-plugi...

24.06.2025 15:27 👍 2 🔁 2 💬 1 📌 0
Preview
Don't Let Mis(s) Information Take the Crown Sherpa Intelligence: Your Guide Up a Mountain of Information!

New guest post on thorcollective.bsky.social Dispatch from infosecsherpa.bsky.social:

Don’t Let Mis(s) Information Take the Crown 👑

This post shows how to apply the Intelligence Cycle to news and help you filter bias.

Read it here: dispatch.thorcollective.com/p/dont-let-m...

19.06.2025 18:03 👍 4 🔁 4 💬 1 📌 0
Preview
From the Fire: Q1FY25 TTPs that sparked, spread, and still burn for those paying attention.

⚡ New @thorcollective.bsky.social Dispatch drop

No hallucinations here. Just TTPs that quietly defined Q1 2025.

🔐 OAuth abuse
📦 Malicious packages
🖥️ SimpleHelp RMM exploits

Stay ahead with what to hunt & where to look.

👉 dispatch.thorcollective.com/p/from-the-f...

#THORCollective
#threathunting

10.06.2025 16:22 👍 4 🔁 3 💬 0 📌 0
Preview
Red with Benefits: Purple Teaming with Sliver Beacons How to turn a modern post-exploitation tool into your next detection engineering best friend.

🚨 New post on @thorcollective.bsky.social Dispatch🚨
Red with Benefits: Purple Teaming with Sliver Beacons
Sliver isn’t just for flexing during pentests, it’s your new favorite detection engineering wingman.

👇
dispatch.thorcollective.com/p/red-with-b...

03.06.2025 14:05 👍 1 🔁 1 💬 0 📌 0
Preview
Dispatch Debrief: May 2025 Quiet logs, loud analysts, and AI besties. Just another month in the hunt.

The May Dispatch is live.

Fresh insights from @thorcollective.bsky.social and guest contributors on detection in depth, AI in the SOC, career overlaps, and making your hunts actually matter.

Plus memes. Obviously.

👉 dispatch.thorcollective.com/p/dispatch-d...

29.05.2025 15:15 👍 3 🔁 2 💬 1 📌 0
Preview
Making Your Hunts Matter: Introducing Threat Hunting Relevancy Factors Don’t just hunt, hunt with purpose.

✨ New THOR Collective post ✨

Introducing Threat Hunting Relevancy Factors (THRF!) These factors can help you create relevant hunts and tangible impact for your organization. Show your business that you mean bzns. 📈

Join us at 👉: dispatch.thorcollective.com/p/threat-hun...

#threathunting

27.05.2025 19:03 👍 5 🔁 4 💬 0 📌 0