sydney's Avatar

sydney

@letswastetime.bsky.social

| search "thrunter" | eval specialty="Purple Team, Treat Hunter, Lifting Heavy Things"

138 Followers  |  42 Following  |  100 Posts  |  Joined: 15.05.2023  |  2.081

Latest posts by letswastetime.bsky.social on Bluesky

#threathunting #threatdetection #thrunting #agentai #openclaw #clawdbot #moltbot

03.02.2026 21:00 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Hunting OpenClaw and Agentic AI Through Behavior | Nebulock blog This Hunt Mode breaks down the behaviors that give away OpenClaw (formerly ClawdBot / MoltBot), regardless of how it is packaged, renamed, or delivered.

OpenClaw isn't malware. It's a legitimate tool that store credentials, retain memory, and act autonomously. That's what makes it dangerous when misused.

Full behavioral breakdown in our latest Hunt Mode post.

πŸ¦€ nebulock.io/blog/hunting...

03.02.2026 21:00 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

#building #ai #softwaredevelopment #neurodiversity #shipping #threathunting #thrunting #THORcollective

27.01.2026 15:37 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

You don’t need a desk to build.

I used AI more from my phone last month than from my desk. What mattered was removing friction and building where ideas show up.

πŸ‘‰ New on @thorcollective.bsky.social Dispatch:
dispatch.thorcollective.com/p/you-dont-n...

27.01.2026 15:37 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0

#infosec #threathunting #builders #ai #thrunting #THORcollective

20.01.2026 16:30 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

β€œI’m not a developer” is a self-imposed limit.

If you’ve written a query, a script, or an automation to fix a problem, you’re already building.

In the latest @thorcollective.bsky.social Dispatch, we talk about why building is a core security skill.

dispatch.thorcollective.com/p/why-you-sh...

20.01.2026 16:30 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0

#threathunting #macos #cybersecurity #dfir #thrunting

15.01.2026 19:59 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

DigitStealer is an excellent example of where macOS malware is heading: multi-stage, modular, and using legit macOS tools like it belongs there.

Detect the attack, not the sample.
Shoutout Jamf Threat Labs πŸ™Œ

nebulock.io/blog/hunting...

15.01.2026 19:59 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

#threathunting #infosec #cybersecurity #thrunting #THORcollective

01.01.2026 16:22 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

80 posts. @thorcollective.bsky.social kept hitting publish.
This year was about doing the work, writing it down, and sharing it anyway.
If you read, argued, bookmarked, or built alongside us, thank you.
Happy New Year. Happy thrunting.

dispatch.thorcollective.com/p/80-posts-l...

01.01.2026 16:22 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image Post image Post image

It's happening!

Meet the Agentic Threat Hunting Framework (ATHF).

Tired of copy-pasting the same hunt template over and over? Same. I built a framework designed for an AI-assisted future that adds structure, memory, and context to every hunt.

Come check it out!

nebulock.io/blog/agentic...

11.12.2025 14:01 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

#threathunting #cybersecurity #thrunting #soc #blueteam #detectionengineering #incidentresponse #cyberdefense #aiinsecurity #agenticai #scada #otsecurity #purpleteam #grc #peakframework #THORcollective #dispatchdebrief

25.11.2025 15:15 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

November’s @thorcollective.bsky.social Dispatch Debrief is live with SCADA weirdness, Taylor’s Version SOC vibes, and purple team chaos.

Come thrunt with us.

dispatch.thorcollective.com/p/dispatch-d...

25.11.2025 15:15 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Aligning Risk Management and Threat-Informed Defense Practices (Part 2) We’re back with part two of a series analyzing how to align common GRC tasks/teams with SecOps and threat-informed defense practices.

🚨New post on @THOR_Collective Dispatch🚨

β€œAligning Risk Management and Threat-Informed Defense Practices (Part 2)” by Micah VanFossen

What happens when you sync risk, controls, and threat intel to drive real-security outcomes.

dispatch.thorcollective.com/p/aligning-r...

#thrunting #grc

20.11.2025 16:17 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Purple Teaming in the Real World: When Everything Goes Off the Rails (and That’s Normal) People love the glossy version of purple teaming:

🚨New post on @THOR_Collective Dispatch🚨
Purple teaming isn’t shiny. It’s delays, blockers, tickets & pivots. And that’s okay.
open.substack.com/pub/thorcoll...
#thrunting #PurpleTeaming

18.11.2025 14:00 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

#threathunting #cybersecurity #soc #dfir #blueteam #thrunting #thrunting #THORcollective

13.11.2025 20:47 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Have you ever run the best hunt of your life and then forget how two weeks later?
Same.

Meet the PEAK Threat Hunting Template. Built to make your hunts repeatable, reviewable, and impossible to lose.

πŸ‘‰ Read on THOR Collective Dispatch - dispatch.thorcollective.com/p/the-peak-t...

13.11.2025 20:47 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

#autonomousSOC #taylorsversion #cybersecurity #threathunting #SOClife #detectionengineering #automation #THORcollective #infosec #securityoperations

11.11.2025 15:41 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
The Autonomous SOC (Taylor’s Version) Opening Act: Welcome to the SOC Show

🎀 The Autonomous SOC (Taylor’s Version)
Guest post with @kassafras09.bsky.social

AI hype is loud. Most teams are just automating chaos.
Fix the basics first. Then scale the magic.

Read it on @thorcollective.bsky.social Dispatch.

dispatch.thorcollective.com/p/the-autono...

11.11.2025 15:41 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

#threathunting #ICS #OTSecurity #THORcollective #thrunting #threatdetection #threatintel

06.11.2025 15:45 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

In the latest @thorcollective.bsky.social guest post, Sam Hanson breaks down two TTP-driven hunts β€” KurtLar_SCADA and a weird .NET Modbus binary β€” proving simple hypotheses > chasing IOCs.

IOCs show where the fire was.
TTPs show where it will be.

dispatch.thorcollective.com/p/hunting-be...

06.11.2025 15:45 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

#threathunting #cybersecurity #THORcollective #purpleteaming #baselines #grc #thrunting #ai

30.10.2025 15:15 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Dispatch Debrief: October 2025 Seven Dispatch drops that prove hunting smarter beats hunting harder.

October delivered AI agents, time mastery, and purple team curveballs. From scaling hunts like code to aligning GRC with threat-informed defense, this month’s Dispatch lineup from @thorcollective.bsky.social hit every layer of the stack.

Full recap here:
dispatch.thorcollective.com/p/dispatch-d...

30.10.2025 15:15 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
Preview
Measuring the Hunt When You Find β€œNothing” Because sometimes success looks like silence.

Finding nothing β‰  failing the hunt.
Sometimes β€œnothing” is the loudest signal that your defenses worked.

@jotunvillur.bsky.social breaks down how to measure the quiet wins in in one of my favorite @thorcollective.bsky.social Dispatch posts:

dispatch.thorcollective.com/p/measuring-...

28.10.2025 15:03 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

#threathunting #cybersecurity #TTPhunting #mitre #THORcollective #thrunting #infosec #cybersecurity

09.10.2025 19:01 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

In this week’s @thorcollective.bsky.social Dispatch, Sam Hanson lays out how to move beyond indicator-based hunting and build detection muscle that actually scales.

πŸ‘‰ dispatch.thorcollective.com/p/hunting-be...

09.10.2025 19:01 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0

#splunk #threathunting #cybersecurity #infosec #THORcollective #thrunting

07.10.2025 23:15 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

If tstats gives you speed and eventstats gives you context...timechart gives you shape.

This week’s @thorcollective.bsky.social SPL Dispatch breaks down how to use timechart to uncover rhythm, automation, and the a cron job masquerading as β€œnormal.”

dispatch.thorcollective.com/p/the-shape-...

07.10.2025 23:15 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0

#threathunting #thrunting #cybersecurity #AI #thrunting #THORcollective #AIbestie

02.10.2025 22:15 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Threat hunting falls apart when your β€œdocs” live in Slack threads.

Part 2 of the @thorcollective.bsky.social Dispatch Agentic Threat Hunting series covers the first step to scaling: put your hunts in a GitHub repo and give your AI bestie memory.

dispatch.thorcollective.com/p/agentic-th...

02.10.2025 22:15 β€” πŸ‘ 2    πŸ” 2    πŸ’¬ 1    πŸ“Œ 0

@letswastetime is following 20 prominent accounts