<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[THOR Collective Dispatch]]></title><description><![CDATA[A hub for threat hunters (thrunters) and security professionals. Explore cutting-edge ideas, practical frameworks, and community-driven insights in cybersecurity. Powered by collaboration, innovation, and a relentless pursuit of a safer digital world.]]></description><link>https://dispatch.thorcollective.com</link><image><url>https://substackcdn.com/image/fetch/$s_!8mB0!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f0d0d66-07ae-4f5b-a26a-b6d91cfc488e_1280x1280.png</url><title>THOR Collective Dispatch</title><link>https://dispatch.thorcollective.com</link></image><generator>Substack</generator><lastBuildDate>Fri, 11 Sep 2026 10:31:49 GMT</lastBuildDate><atom:link href="https://dispatch.thorcollective.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[THOR Collective]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[dispatch@thorcollective.com]]></webMaster><itunes:owner><itunes:email><![CDATA[dispatch@thorcollective.com]]></itunes:email><itunes:name><![CDATA[Sydney Marrone]]></itunes:name></itunes:owner><itunes:author><![CDATA[Sydney Marrone]]></itunes:author><googleplay:owner><![CDATA[dispatch@thorcollective.com]]></googleplay:owner><googleplay:email><![CDATA[dispatch@thorcollective.com]]></googleplay:email><googleplay:author><![CDATA[Sydney Marrone]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Open Season: Passive DNS]]></title><description><![CDATA[Part 2 of the Open Season series from the THOR Collective. All free tools, no vendor gatekeeping]]></description><link>https://dispatch.thorcollective.com/p/open-season-passive-dns</link><guid isPermaLink="false">https://dispatch.thorcollective.com/p/open-season-passive-dns</guid><dc:creator><![CDATA[Lauren Proehl]]></dc:creator><pubDate>Tue, 08 Sep 2026 21:00:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!0D1q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87de2286-fa81-45b5-ae6f-f8b673ab326b_430x398.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Part 2 of the <a href="https://dispatch.thorcollective.com/p/open-season-hunting-adversary-infrastructure">Open Season series</a> from the THOR Collective. All free tools, no vendor gatekeeping</em></p><p>Part 1 left us holding <code>fifa[.]house</code>: twenty-one certificates, a first-to-last window from January to April, and about twenty sibling domains riding its SANs. Precise names, precise minutes, and not one address. The domain is NXDOMAIN today, so there is nothing left to resolve and nothing left to scan.</p><p>That is the shape of what Certificate Transparency hands you. A domain exists, its cert was issued at this minute, these names rode along on the SAN. A single point in time, the instant a piece of infrastructure announces itself.</p><p>Passive DNS gives you the rest of it.</p><p>It records the answers recursive resolvers actually returned, captured by sensors and stitched into a searchable history. Where CT shows the intent to stand something up, passive DNS shows the operational life: where a name pointed, when it moved, what it shared an address with, and what went dark the day the campaign got burned.</p><p>Passive DNS is also the source in this series where free access has narrowed the most. The two names everyone reaches for first, Farsight DNSDB and PassiveTotal, now sit inside larger platforms: DNSDB moved to DomainTools at enterprise pricing, and PassiveTotal became part of Microsoft Defender Threat Intelligence, where the free community tier did not survive the move. Both are strong products and the consolidation is ordinary. The practical problem is downstream of it: a generation of analysts learned pDNS through those tools, so a lot of intro writeups still assume a license you may not have. Everything below runs on data you can query today, for free, starting with infrastructure the community owns.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0D1q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87de2286-fa81-45b5-ae6f-f8b673ab326b_430x398.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0D1q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87de2286-fa81-45b5-ae6f-f8b673ab326b_430x398.png 424w, https://substackcdn.com/image/fetch/$s_!0D1q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87de2286-fa81-45b5-ae6f-f8b673ab326b_430x398.png 848w, https://substackcdn.com/image/fetch/$s_!0D1q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87de2286-fa81-45b5-ae6f-f8b673ab326b_430x398.png 1272w, https://substackcdn.com/image/fetch/$s_!0D1q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87de2286-fa81-45b5-ae6f-f8b673ab326b_430x398.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0D1q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87de2286-fa81-45b5-ae6f-f8b673ab326b_430x398.png" width="430" height="398" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/87de2286-fa81-45b5-ae6f-f8b673ab326b_430x398.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:398,&quot;width&quot;:430,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Megan Thee Stallion Hot Girl Meme - Megan thee stallion Hot girl Bite lip -  Discover &amp; Share GIFs&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Megan Thee Stallion Hot Girl Meme - Megan thee stallion Hot girl Bite lip -  Discover &amp; Share GIFs" title="Megan Thee Stallion Hot Girl Meme - Megan thee stallion Hot girl Bite lip -  Discover &amp; Share GIFs" srcset="https://substackcdn.com/image/fetch/$s_!0D1q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87de2286-fa81-45b5-ae6f-f8b673ab326b_430x398.png 424w, https://substackcdn.com/image/fetch/$s_!0D1q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87de2286-fa81-45b5-ae6f-f8b673ab326b_430x398.png 848w, https://substackcdn.com/image/fetch/$s_!0D1q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87de2286-fa81-45b5-ae6f-f8b673ab326b_430x398.png 1272w, https://substackcdn.com/image/fetch/$s_!0D1q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87de2286-fa81-45b5-ae6f-f8b673ab326b_430x398.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">when the free passive DNS logs hit</figcaption></figure></div><h2>What the data tells you</h2><p>A passive DNS record is boring on its own and devastating in aggregate. Each entry is roughly: a query name, a record type, the response data, a first-seen timestamp, a last-seen timestamp, and a count of how many times the sensor network observed it.</p><p>Those last two fields are what matter. A current DNS lookup answers where a name points right now. Passive DNS answers where it has pointed, and for how long, across years, which turns three otherwise impossible questions into routine ones:</p><p>What IPs did this domain use before takedown? Active DNS gives you nothing once a domain is parked or sinkholed; pDNS still has the body. What else resolved to this IP while the badness I already know about was live? That is reverse passive DNS, how you turn one indicator into a cluster. And when did the infrastructure turn on? First-seen timestamps date an operation and catch the staging nobody noticed.</p><p>You are reconstructing infrastructure that the operator thought was gone. They rotated the IP, they let the domain lapse, they moved to a new host. The resolver network already wrote it down.</p><h2>Why adversaries leave traces in it</h2><p>They cannot opt out. That is the short version.</p><p>DNS is not optional for an attacker; everything else they run rides on it. The moment a victim, a sandbox, a scanner, or the operator&#8217;s own implant resolves a domain near a sensor-instrumented resolver, that resolution gets recorded on infrastructure the adversary does not control. There is no setting to turn it off.</p><p>And operators are lazy in patterned ways. They reuse hosting, nameservers, a registrar, a mail setup, a TLS config, because standing up new ones is effort. Every reuse is a thread you can pull, and passive DNS keeps a lot of them visible over time. That is what lets you tell a coincidence, one shared IP ever, from a pattern, four domains on the same obscure VPS during the same two weeks.</p><p>The behaviors that show up loudest: fast flux and rapid IP rotation, a domain churning dozens of A records in a short window, which is not a normal CDN; DGA traffic, mostly-NXDOMAIN noise with occasional registered hits that cluster on shared infrastructure; and staging gaps, infrastructure that first-seen dates two weeks before an intrusion and goes dark right after, tempo you read off the timestamps.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">THOR Collective Dispatch is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>How to query and pivot</h2><p>Start with the data the community runs, because it is the most durable and the least likely to disappear behind a sales call.</p><p><strong>CIRCL Passive DNS</strong> is run by the Luxembourg CERT for exactly this audience: incident handlers and researchers. Access is free but vetted: request an account, get credentials. It speaks the Passive DNS Common Output Format, which matters more than it sounds, and we come back to that. The REST query is about as simple as it gets:</p><pre><code><code># Forward lookup: where has this name lived
curl --user 'user:pass' \
  'https://www.circl.lu/pdns/query/badexample.com'

# Returns newline-delimited JSON (COF), one record per line:
# {"rrname":"badexample.com","rrtype":"A","rdata":"203.0.113.40",
#  "time_first":1708300000,"time_last":1709900000,"count":412}
</code></code></pre><p><strong>Mnemonic Passive DNS</strong> is the other community workhorse, run by the Norwegian security firm mnemonic and exposed through an open API. Low-volume use needs no key, which makes it the fastest thing to script against when you are triaging:</p><pre><code><code># Forward lookup
curl 'https://api.mnemonic.no/pdns/v3/badexample.com'

# Reverse lookup: every name seen resolving to this IP
curl 'https://api.mnemonic.no/pdns/v3/203.0.113.40'
</code></code></pre><p>Notice the second call. That is the pivot that does the work: hand it an IP, get back every domain the sensor network saw pointing there, each with its own first-seen and last-seen. One known-bad IP becomes a candidate list in a single request.</p><p>One caveat before you conclude a source is broken. Sensor coverage is geographic, and the community networks are Europe-weighted. Running the Ghost Stadium origins below through Mnemonic returns almost nothing, while VirusTotal&#8217;s free tier returns the full cluster for the same addresses. That is not you querying wrong, it is a resolver network that never saw the traffic. Check a second source before you accept an empty answer, and expect community pDNS to be thinnest exactly where the campaign targets somewhere else.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KMaW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad9c91a1-43d3-4469-8a2a-0102c3841184_970x468.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KMaW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad9c91a1-43d3-4469-8a2a-0102c3841184_970x468.png 424w, https://substackcdn.com/image/fetch/$s_!KMaW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad9c91a1-43d3-4469-8a2a-0102c3841184_970x468.png 848w, https://substackcdn.com/image/fetch/$s_!KMaW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad9c91a1-43d3-4469-8a2a-0102c3841184_970x468.png 1272w, https://substackcdn.com/image/fetch/$s_!KMaW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad9c91a1-43d3-4469-8a2a-0102c3841184_970x468.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KMaW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad9c91a1-43d3-4469-8a2a-0102c3841184_970x468.png" width="970" height="468" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ad9c91a1-43d3-4469-8a2a-0102c3841184_970x468.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:468,&quot;width&quot;:970,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:549349,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dispatch.thorcollective.com/i/212047670?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad9c91a1-43d3-4469-8a2a-0102c3841184_970x468.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KMaW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad9c91a1-43d3-4469-8a2a-0102c3841184_970x468.png 424w, https://substackcdn.com/image/fetch/$s_!KMaW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad9c91a1-43d3-4469-8a2a-0102c3841184_970x468.png 848w, https://substackcdn.com/image/fetch/$s_!KMaW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad9c91a1-43d3-4469-8a2a-0102c3841184_970x468.png 1272w, https://substackcdn.com/image/fetch/$s_!KMaW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad9c91a1-43d3-4469-8a2a-0102c3841184_970x468.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Now the discipline that keeps you from drowning. <strong>Time-window everything.</strong> An IP that hosted fifty thousand domains over five years is shared hosting, a CDN edge, or parking, so pivoting on it will bury you. An IP that hosted four domains during the exact fourteen days your incident was live is a cluster. Treat first-seen and last-seen as your filter, not trivia: high count, long span, many unrelated names means shared infrastructure, so drop it; low count, tight window, and a name you already distrust means signal, so chase it.</p><p>The pivot fields, in rough order of how often they pay off:</p><p>A and AAAA records, forward and reverse, are your primary loop. Domain to historical IPs, each IP back to co-resident domains, filtered by overlapping time windows.</p><p>NS records cluster operations by shared nameserver. Self-hosted or bulletproof ones are especially telling: legitimate operators rarely run their own, and adversaries who do reuse them across campaigns.</p><p>MX records expose reused mail infrastructure, which is gold for phishing and business email compromise clusters.</p><p>TXT records leak verification tokens. A reused <code>google-site-verification</code> value or a distinctive SPF include string can tie together domains that share nothing else visible.</p><p>CNAME chains reveal shared redirectors and CDN fronting setups.</p><p>Once you have a candidate cluster from the community sources, widen the aperture with the free SaaS-style platforms, which give you a pivoting interface and deeper history than a raw API:</p><p><strong>Validin Community Edition</strong> is the strongest free pivot environment right now: free account, web UI plus API, several years of history, and pivoting across DNS, certs, and host behaviors in one place. When you want to chase a cluster visually instead of by curl, go here.</p><p><strong>Silent Push Community Edition</strong> is a free account with passive DNS lookups and infrastructure scanning, useful as a second opinion when your other sources come up thin.</p><p><strong>VirusTotal</strong> gives passive DNS relations on the free API (<code>/domains/{domain}/resolutions</code>, <code>/ip_addresses/{ip}/resolutions</code>), rate-limited to about four requests a minute, so use it for confirmation and enrichment, not bulk sweeping.</p><p><strong>SecurityTrails</strong> is worth knowing about and no longer worth planning around. It had a small free tier with historical DNS and subdomain data, and a lot of writeups still list it as a free option. Check what it costs before you build a workflow on it. This is the failure mode this installment opened with, and it happens to sources faster than the writeups get updated.</p><p>One more thing about the Common Output Format. COF is the shape CIRCL returns, one JSON record per line with <code>rrname</code>, <code>rrtype</code>, <code>rdata</code>, <code>time_first</code>, <code>time_last</code>, and <code>count</code>, and PyPDNS is a COF client you can point at any server that speaks it. Mnemonic is not one of them: it wraps its answers in a <code>responseCode</code>/<code>data</code> envelope, calls the fields <code>query</code>, <code>answer</code>, and <code>times</code>, and stamps its timestamps in epoch milliseconds. Normalize whatever you pull into COF at the edge of your tooling and the rest of your pipeline stops caring which source it came from.</p><pre><code><code># CIRCL, or any COF-speaking server, via pypdns
from pypdns import PyPDNS

pdns = PyPDNS(basic_auth=('user', 'pass'))
# rfc_query returns PDNSRecord objects; the older query() is deprecated
# and hands back plain dicts
for record in pdns.rfc_query('badexample.com'):
    # record.rdata, record.time_first, record.time_last, record.count
    if record.count and record.count &lt; 50 and record.rrtype in ('A', 'AAAA'):
        print(record.rdata, record.time_first, record.time_last)
</code></code></pre><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/p/open-season-passive-dns?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading THOR Collective Dispatch! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/p/open-season-passive-dns?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://dispatch.thorcollective.com/p/open-season-passive-dns?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><h2>Enrich and correlate</h2><p>Passive DNS feeds everything else. Every pivot above produces indicators that get sharper when you cross them against the other sources in this series.</p><p>Run the resolved IPs and co-resident domains back through Certificate Transparency (Part 1). A shared cert across two domains you connected by IP is independent confirmation they are the same operator, and its SAN list often hands you names the pDNS sweep missed. That is not theoretical here: three Ghost Stadium seed domains expanded to twenty-five registrable domains through SAN expansion alone, and one certificate carried forty-five names.</p><p>Take the live IPs into internet scan data, the next installment. Open ports, banners, and fingerprints tell you what the infrastructure was for. A box that hosted three of your cluster domains and also exposed a known C2 panel is no longer a maybe.</p><p>Pull WHOIS and registration data on the clustered domains (Part 4). Even post-GDPR, registration timing, registrar choice, and nameserver assignment cluster actor infrastructure in ways the privacy proxy does not hide.</p><p>Add ASN and hosting context: which network owns the IP, its abuse history, whether it is a known bulletproof provider. A cluster sitting inside one obscure autonomous system is a far stronger signal than the same domains spread across AWS, Cloudflare, and a shared reseller.</p><p>And aggressively discard. Sinkholes pull thousands of dead malicious domains onto one IP, a massive-looking cluster that is really a researcher&#8217;s trap; parking and CDN edges do the same with benign domains. Learn the sinkhole and parking ranges, recognize the major CDNs on sight, and filter them before they waste an afternoon.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VZ5B!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c056761-5d5c-4956-9a28-44c233b5a424_640x355.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VZ5B!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c056761-5d5c-4956-9a28-44c233b5a424_640x355.png 424w, https://substackcdn.com/image/fetch/$s_!VZ5B!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c056761-5d5c-4956-9a28-44c233b5a424_640x355.png 848w, https://substackcdn.com/image/fetch/$s_!VZ5B!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c056761-5d5c-4956-9a28-44c233b5a424_640x355.png 1272w, https://substackcdn.com/image/fetch/$s_!VZ5B!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c056761-5d5c-4956-9a28-44c233b5a424_640x355.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VZ5B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c056761-5d5c-4956-9a28-44c233b5a424_640x355.png" width="640" height="355" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0c056761-5d5c-4956-9a28-44c233b5a424_640x355.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:355,&quot;width&quot;:640,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;r/ProgrammerHumor - It was always DNS&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="r/ProgrammerHumor - It was always DNS" title="r/ProgrammerHumor - It was always DNS" srcset="https://substackcdn.com/image/fetch/$s_!VZ5B!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c056761-5d5c-4956-9a28-44c233b5a424_640x355.png 424w, https://substackcdn.com/image/fetch/$s_!VZ5B!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c056761-5d5c-4956-9a28-44c233b5a424_640x355.png 848w, https://substackcdn.com/image/fetch/$s_!VZ5B!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c056761-5d5c-4956-9a28-44c233b5a424_640x355.png 1272w, https://substackcdn.com/image/fetch/$s_!VZ5B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c056761-5d5c-4956-9a28-44c233b5a424_640x355.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>In practice: Ghost Stadium</h2><p>The question going in: where does this operation actually host behind the CDN, and can we recover an origin to hunt from?</p><p>Forward-resolve the confirmed kit domains and the active core resists you. Nearly every record is Cloudflare (AS13335), and reversing any of those addresses returns the shared edge: tens of thousands of unrelated domains, first-seen dates scattered across years, the textbook high-count, long-span noise you time-window and throw away. For that slice, the origin this lens exists to recover is simply not in the record.</p><p>So go back to the one name Part 1 actually handed over. <code>fifa[.]house</code> is dead, and every active tool you own returns nothing on it. Its resolution history returns six addresses across five networks, every handoff inside ten weeks: NetLab Global (AS979) on 2026-01-03, a second NetLab address on 02-06, ArossCloud on 02-16, CogNetCloud on 02-24, then Zillion Network and IT7 Networks together on 03-10. The handoffs are contiguous. You can read the operator&#8217;s moving schedule straight off the first-seen column.</p><p>Then run the same filter on the last hop, because your own lead is where you are least likely to apply it. On 04-16 the domain answers from two Amazon addresses, and it is tempting to call that a seventh host and a move to legitimate cloud. Both reverse to the same name, <code>a2aa9ff50de748dbe.awsglobalaccelerator[.]com</code>, and each carries hundreds of unrelated tenants, dental practices and consultancies and half-built startups. That is parking. The domain was registered through GoDaddy and kept GoDaddy nameservers to the last day, so what the record shows on 04-16 is the registration lapsing, not the operator relocating. High count, many unrelated names, discard. The rule does not stop applying because the address is yours.</p><p>It also overturns the assumption we carried in with. This domain never sat behind Cloudflare. Its nameservers were GoDaddy&#8217;s <code>domaincontrol[.]com</code> from the first day to the last, matching the GoDaddy registration and the GoDaddy certificate that Part 1 documented, and it answered from origin hosts the entire time. The domain we assumed was the most hidden of the set turns out to be the least.</p><p>You will still find Cloudflare all over those captures, and it is worth knowing why before it misleads you. urlscan lists every ASN a scan touched, and AS13335 is in that list for all eleven <code>fifa[.]house</code> captures. None of it is the site. It is <code>cdnjs.cloudflare[.]com</code> serving the kit&#8217;s copied jQuery, plus a pair of Flourish embeds that happen to be Cloudflare-fronted themselves. The page&#8217;s own address, the <code>page.ip</code> field, is NetLab or CogNetCloud in every one of those captures. This is the shared-library trap from earlier wearing an ASN instead of a resource hash, and it is the single easiest way to talk yourself into a wrong answer here. A scan summary tells you who the page talked to. One field in it tells you where the page lived.</p><p>Better still, the two lenses explain each other. Twenty-one certificates between January and April read like reissuance for its own sake when CT was all we had. It was not. The domain sat on six addresses across five networks in that window, and the certificate churn is the shadow of the hosting churn. Neither source shows that behavior alone.</p><p>Two of those addresses reach past this domain. <code>65.49.223[.]138</code> is IT7 Networks (AS25820), the same network as the kit cluster below, and <code>148.178.16[.]5</code> sits in <code>148.178.16.0/23</code>, the same Zillion Network /23 as the kit-cluster address <code>148.178.16[.]48</code>. <code>fifa[.]house</code> is not merely adjacent to the directly-hosted slice. It is inside it.</p><p>Which is the wider correction. Part 1 closed on Validin&#8217;s framing, every active domain in the set sitting behind Cloudflare, and treated it as the wall this installment had to get over. The wall has holes. urlscan records the IP each capture actually resolved to, so bucket the kit-serving captures by address and a directly-hosted slice falls out, dozens of kit lookalikes answering straight from hosting IPs with no CDN in front. They cluster hard. <code>89.208.250[.]38</code> at IT7 Networks (AS25820) served eight of them (<code>fifa[.]blue</code>, <code>fifa[.]cab</code>, <code>fifa[.]cash</code> and more); a Zillion Network block (AS54801) carried another handful; a Hong Kong host (AS140227) carried the <code>flfa</code> typosquats. Reverse one of those IPs and the co-resident cluster comes back in a single pivot, which is exactly what reverse passive DNS is for.</p><p>Two disciplines make or break this. First, filter to the kit-unique bundle. Bucket on the kit&#8217;s shared library instead, a jQuery-style helper it copied wholesale, and you drag in unrelated GitHub Pages and Squarespace sites on Fastly, the same shared-infrastructure trap this installment keeps warning about, wearing a resource hash instead of an IP. Second, confirm before you attribute. One FIFA node in the favicon cluster, <code>stadiumrushes[.]com</code>, answered from a real origin, <code>198.54.115[.]155</code> on a LiteSpeed box, and looked like a find until checking the kit ticket path returned a 404. It serves a different FIFA clone, so it is a separate lead, not a Ghost Stadium origin.</p><p>Now the two names Part 1 surfaced that were absent from every published set. Mnemonic returns nothing for either one, which is precisely the empty answer this installment warned you not to accept. Check a second source and the history is sitting right there.</p><p>Validin has <code>fifa-sg[.]shop</code> resolving on 2026-05-17 and on no other day: two Cloudflare A records, the same two hosts again as AAAA, four Cloudflare nameservers, then NXDOMAIN from the eighteenth through today. VirusTotal returns the same two addresses on the same date, which is the corroboration you want before you build anything on one vendor&#8217;s history. That is also the date of Part 1&#8217;s four-certificate burst, which makes the domain&#8217;s entire operational life about one day wide. <code>shop-26fifa[.]com</code> never resolved at all. Cloudflare nameservers from 2026-05-20 to now, no A record anywhere in the history, and a registry record still marked active and paid through May 2027.</p><p>So passive DNS has plenty to say about both and still cannot hand you an origin, because every address either of them ever carried belonged to Cloudflare. That is the honest boundary of this lens. It recovers history, not hosting, and when an operator fronts a name from its first minute there is no origin in the record to recover. One of these ran for a day and was abandoned. The other was never switched on and is still being paid for. Write both down.</p><p>None of the origin-recovered domains are new; they were all in Validin&#8217;s set. What is new is the hosting. Validin&#8217;s view stopped at Cloudflare, and the per-capture IP fills that gap for the slice that never used it. <code>89.208.250[.]38</code> is a real host with ports and services you can point a scanner at, and eight of the domains it served are kit-confirmed. Reverse it and the FIFA footprint is wider than the kit filter alone shows: VirusTotal returns ten registrable <code>fifa[.]*</code> names there between 2026-01-10 and 03-18, and Validin adds <code>fifa[.]work</code> and <code>wwww-fifa[.]com</code> for twelve. Three counts, three filters, all of them honest as long as you say which one you used.</p><p>Then ask who else has lived there, because this is the discipline turned back on your own best lead. The same address answered for a Synology dynamic-DNS host in 2020 and an unrelated personal domain in 2019, and since 2026-05-08 it has resolved <code>bwg-la9.ameredu[.]com</code>, which is BandwagonHost naming. The FIFA tenancy is a ten-week window on a recycled reseller IP, not an operator-owned box. Time-windowing is not only how you filter a reverse lookup. It is how you decide what a recovered origin actually entitles you to say.</p><p>Assessment, high confidence: this operation is only partly Cloudflare-fronted. The active core hides its origin, but a substantial directly-hosted slice exposes it on a small set of reused IPs at IT7 Networks and Zillion Network. Recover origins from urlscan&#8217;s capture history rather than live resolution, filter to the kit-unique resource so shared-library noise does not fold in unrelated hosts, and treat every recovered IP as a reverse pivot into more of the cluster. Every address above is a capture-time observation from early to mid 2026. None of it is a claim about what is still listening today, which is the next installment&#8217;s job.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">THOR Collective Dispatch is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h3>Auditing the list you were handed</h3><p>Validin publishes their set as suspected, not confirmed, and that word earns its place. Two entries look nothing like the campaign: <code>808140[.]pro</code> and <code>808150[.]pro</code>, carrying forty-eight <code>bbs*</code> subdomains between them, with no FIFA string anywhere in sight. Worth asking what they are doing on a FIFA list. Passive DNS answers it, and the answer is not the one the list implies.</p><p>All fifty-one are NXDOMAIN today, so live DNS gives you nothing and pDNS is the only way in. Resolution history returns three addresses, and the first job is throwing one away. <code>91.195.240[.]94</code> reads as the most recent hosting until you check the owner: SEDO GmbH. That is parking, and the 2026 dates read as the domains expiring rather than the operator moving. The two real origins are <code>156.235.100[.]101</code> (USCLOUD, Seychelles) in February 2025 and <code>154.40.50[.]41</code> (NetLab Global) that April.</p><p>Reverse them and the sprawl comes back whole: the entire <code>bbs*.808140[.]pro</code> run on 2025-02-23, the <code>808150[.]pro</code> half that April. Time-window as you go, because the Seychelles box also carried unrelated tenants that June, months after the operator left.</p><p>Now cross into Part 1&#8217;s lens. Let&#8217;s Encrypt issued four certificates for these names on 2025-02-23: a thirty-two name cert covering <code>808140[.]pro</code>, its <code>www.</code> variant, and thirty <code>bbs*</code> hosts, reissued identically eight minutes later, plus two-name certs for <code>808140[.]com</code> and <code>808150[.]com</code>. Same day, same issuer, and that is the thread tying an unlisted <code>.com</code> side to the listed <code>.pro</code> side. Search those <code>.com</code> names in CT and a numbered series falls out, <code>808110</code> through <code>808190</code> on the tens plus a stray <code>808122</code>, with <code>m.</code>, <code>admin.</code>, <code>blog.</code>, and <code>dev.</code> subdomains. <code>808150[.]com</code> has certificates going back to 2021 and a <code>kefu.</code> subdomain, Chinese for customer service, in 2023.</p><p>CT has one more thing to say, and it complicates the parking read rather than confirming it. Twenty-six single-name certificates land on these hosts between 2026-02-24 and 04-05, all from DigiCert&#8217;s Encryption Everywhere program, and they cover names Validin never listed: <code>sitemap.</code>, <code>sitemaps.</code>, and <code>www.</code> variants of individual <code>bbs</code> hosts. That window sits on top of the SEDO dates. Per-host DV issuance is also what a parking service does when it wants HTTPS on every name it is holding, so the parking read survives, but it is now a read rather than a fact. Note which one you took.</p><p>That is not World Cup infrastructure. It is a long-running numbered operation with a mobile site and a support desk, four years older than the tournament, and not one of its <code>.com</code> names made the published set at all. urlscan agrees: all fourteen captures of the <code>bbs*</code> hosts show the same control panel default page, <code>&#24685;&#21916;&#65292;&#31449;&#28857;&#21019;&#24314;&#25104;&#21151;&#65281;</code>, and no capture anywhere shows kit content.</p><p>One thread keeps it open rather than closing it. <code>154.40.50[.]41</code> also served <code>fifa[.]house</code> and <code>fifa[.]bio</code> in February 2026, nine months after the <code>808150[.]pro</code> sprawl. That shared address is the only bridge between the two, and it is a thin one. Nine months apart on a hosting provider&#8217;s IP is reuse as easily as tenancy, and that address was a ten-day stop in a six-address rotation rather than anybody&#8217;s home. It is probably why these names are on the list. It is not enough to keep them there.</p><p>Assessment, moderate confidence: <code>808140[.]pro</code> and <code>808150[.]pro</code> belong to a separate Chinese operation that predates the World Cup campaign and once shared an IP with it. Not one name in that numbered <code>.com</code> series is in the published set. Four have a tie to the listed pair beyond the numbering: <code>808140[.]com</code> and <code>808150[.]com</code>, certified the same day as the <code>.pro</code> names, and <code>808160[.]pro</code> with its <code>.com</code> twin, which shared the Seychelles box in the same window. Those four are net-new to somebody else&#8217;s problem.</p><p>The transferable part is not the four names. A published indicator set is a starting point, not an answer, and the entries that look wrong to you are worth ten minutes before you block on them or build a detection from them. Every lens used above was free.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XIx8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78e960c8-02f9-4117-b5aa-530b1e8e93c0_980x650.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XIx8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78e960c8-02f9-4117-b5aa-530b1e8e93c0_980x650.png 424w, https://substackcdn.com/image/fetch/$s_!XIx8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78e960c8-02f9-4117-b5aa-530b1e8e93c0_980x650.png 848w, https://substackcdn.com/image/fetch/$s_!XIx8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78e960c8-02f9-4117-b5aa-530b1e8e93c0_980x650.png 1272w, https://substackcdn.com/image/fetch/$s_!XIx8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78e960c8-02f9-4117-b5aa-530b1e8e93c0_980x650.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XIx8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78e960c8-02f9-4117-b5aa-530b1e8e93c0_980x650.png" width="980" height="650" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/78e960c8-02f9-4117-b5aa-530b1e8e93c0_980x650.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:650,&quot;width&quot;:980,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:611819,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dispatch.thorcollective.com/i/212047670?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78e960c8-02f9-4117-b5aa-530b1e8e93c0_980x650.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XIx8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78e960c8-02f9-4117-b5aa-530b1e8e93c0_980x650.png 424w, https://substackcdn.com/image/fetch/$s_!XIx8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78e960c8-02f9-4117-b5aa-530b1e8e93c0_980x650.png 848w, https://substackcdn.com/image/fetch/$s_!XIx8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78e960c8-02f9-4117-b5aa-530b1e8e93c0_980x650.png 1272w, https://substackcdn.com/image/fetch/$s_!XIx8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78e960c8-02f9-4117-b5aa-530b1e8e93c0_980x650.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h2>Hunt hypothesis template</h2><pre><code><code>HYPOTHESIS
  An adversary operating against us reuses hosting and nameserver
  infrastructure across domains. Starting from one known-bad
  indicator, related infrastructure is discoverable in passive DNS
  and was active during the incident window.

DATA SOURCES
  Primary:   CIRCL pDNS (COF), Mnemonic pDNS (own schema)
  Pivot UI:  Validin Community, Silent Push Community
  Enrich:    VirusTotal free, CT logs (Part 1)
  Context:   ASN / hosting reputation, self-run passivedns sensor

PIVOT STEPS
  1. Forward-resolve the known-bad domain. Record A/AAAA history
     with first/last seen.
  2. Constrain to IPs active during the incident window. Drop
     long-lived, high-count, shared-hosting addresses.
  3. Reverse-resolve each surviving IP. List co-resident domains.
  4. Keep only co-residents whose active window overlaps the
     incident. This is the candidate cluster.
  5. Pivot on shared NS, MX, and reused TXT tokens to extend the
     cluster beyond IP co-residence.
  6. Confirm cluster members against CT (shared certs) and scan
     data (matching service fingerprints).

EXPECTED SIGNAL
  A tight set of domains sharing IPs, nameservers, or verification
  tokens, with first-seen dates clustered around the staging
  period and last-seen dates clustered around takedown.

VALIDATION / TRIAGE
  Discard sinkholes, parking, CDNs, and shared resellers. Require
  at least two independent links (e.g. shared IP in-window AND
  shared NS) before promoting a domain to confirmed cluster member.

ATT&amp;CK MAPPING
  T1583  Acquire Infrastructure (.001 Domains, .002 DNS Server)
  T1584  Compromise Infrastructure (.001 Domains, .002 DNS Server)
  T1568  Dynamic Resolution (.001 Fast Flux, .002 DGA)
  T1071.004  Application Layer Protocol: DNS
</code></code></pre><h2>Tooling quick reference</h2><pre><code><code>COMMUNITY-RUN (start here, free, durable)
  CIRCL Passive DNS    circl.lu/services/passive-dns
                       Free, vetted account. COF output. CSIRT-built.
  Mnemonic pDNS        api.mnemonic.no/pdns/v3/{query}
                       Open API, no key for low volume. Own JSON schema.
  PyPDNS               pypi.org/project/pypdns
                       Python COF client. Any COF server via url=.

FREE SAAS PIVOT INTERFACES
  Validin Community    app.validin.com
                       Best free pivoting. Web + API. Multi-year history.
  Silent Push CE       silentpush.com (Community Edition)
                       Free pDNS + infra scanning. Daily credits, and
                       the CE number is not published. Check first.
  VirusTotal           /domains/{d}/resolutions, /ip_addresses/{ip}/resolutions
                       Free API key. ~4 req/min, ~500/day.

RUN YOUR OWN
  passivedns           github.com/gamelinux/passivedns
                       Sniff and log resolutions off your own tap.

OPTIONAL COMMERCIAL UPGRADES (not required for any of the above)
  DomainTools DNSDB (formerly Farsight), Microsoft Defender TI
  (formerly PassiveTotal), SecurityTrails (Recorded Future),
  Spamhaus pDNS, WhoisXML / DNSlytics.
</code></code></pre><p>The methodology does not change when you pay. Paid tools give you more coverage and faster queries, not a different technique. Run the loop above on the free sources and you already know how to use the expensive ones, and you are not stuck the day a trial expires.</p><h2>Up Next</h2><p><strong>Open Season: Internet Scan Data.</strong> Take <code>89.208.250[.]38</code> with you, and take its dates with it. It is a real host at IT7 Networks that carried the kit from January to March 2026 and has belonged to somebody else since May, so a scan run today profiles the current tenant and tells you nothing about the campaign. Passive DNS got us the address and the window. It cannot tell us what was listening inside that window, and that is exactly the gap the next source closes. Censys and Shodan and what their free tiers actually give you, why a historical view beats a live probe on a recycled IP, the favicon hash everyone reaches for on a target like this and why it is the wrong primitive, and the one the kit cannot help serving.</p><p><em>Open Season is a recurring series from the THOR Collective exploring how practitioners can use open-source data to hunt adversary infrastructure. Each installment covers a single data source, soup to nuts. Want to contribute an installment or suggest a data source? Reach out.</em></p>]]></content:encoded></item><item><title><![CDATA[Open Season: CZDS]]></title><description><![CDATA[What up nerds?]]></description><link>https://dispatch.thorcollective.com/p/open-season-czds</link><guid isPermaLink="false">https://dispatch.thorcollective.com/p/open-season-czds</guid><dc:creator><![CDATA[Josh Rickard]]></dc:creator><pubDate>Thu, 13 Aug 2026 21:00:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!iN9k!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fc87962-e778-4754-a3ac-b2d1e39ff62a_1536x933.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>What up nerds? I was reading this awesome post from LP titled&#8239;<a href="https://dispatch.thorcollective.com/p/open-season-certificate-transparency">Open Season: Certificate Transparency</a> (I highly recommend you read this too) and it forced me to write this blog about a free and open (mostly) service which can add another layer of context / enrichment to your threat intelligence toolbelt.</p><p>Before I get into <a href="https://czds.icann.org/home">CZDS</a>, first I want to set the stage of how we can view this data along with the other sources (mentioned in LPs blog and many others).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iN9k!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fc87962-e778-4754-a3ac-b2d1e39ff62a_1536x933.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iN9k!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fc87962-e778-4754-a3ac-b2d1e39ff62a_1536x933.png 424w, https://substackcdn.com/image/fetch/$s_!iN9k!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fc87962-e778-4754-a3ac-b2d1e39ff62a_1536x933.png 848w, https://substackcdn.com/image/fetch/$s_!iN9k!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fc87962-e778-4754-a3ac-b2d1e39ff62a_1536x933.png 1272w, https://substackcdn.com/image/fetch/$s_!iN9k!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fc87962-e778-4754-a3ac-b2d1e39ff62a_1536x933.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iN9k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fc87962-e778-4754-a3ac-b2d1e39ff62a_1536x933.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1fc87962-e778-4754-a3ac-b2d1e39ff62a_1536x933.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Open Season: Phishing Attack Lifecycle &#8212; a proactive framework for mapping, detecting, and disrupting phishing operations before they reach victims.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Open Season: Phishing Attack Lifecycle &#8212; a proactive framework for mapping, detecting, and disrupting phishing operations before they reach victims." title="Open Season: Phishing Attack Lifecycle &#8212; a proactive framework for mapping, detecting, and disrupting phishing operations before they reach victims." srcset="https://substackcdn.com/image/fetch/$s_!iN9k!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fc87962-e778-4754-a3ac-b2d1e39ff62a_1536x933.png 424w, https://substackcdn.com/image/fetch/$s_!iN9k!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fc87962-e778-4754-a3ac-b2d1e39ff62a_1536x933.png 848w, https://substackcdn.com/image/fetch/$s_!iN9k!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fc87962-e778-4754-a3ac-b2d1e39ff62a_1536x933.png 1272w, https://substackcdn.com/image/fetch/$s_!iN9k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fc87962-e778-4754-a3ac-b2d1e39ff62a_1536x933.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>When a threat actor, let&#8217;s call them BOB, is going to setup a phishing campaign they will typically:</p><ul><li><p>Register a domain (or compromise one)</p></li><li><p>Deploy their infrastructure (this one is more difficult to identify at this stage)</p></li><li><p>Configure DNS</p></li><li><p>(Nowadays) Obtain a SSL/TLS certificate</p></li><li><p>Kick off the campaign</p></li></ul><p>There are also operational steps that are highly dependent on infrastructure:</p><ul><li><p>General reconnaissance</p></li><li><p>Brand impersonation/cloning/etc.</p></li><li><p>Testing and verification</p></li><li><p>Lure infrastructure may be different</p></li></ul><p>All of these are different sources of data.</p><p>The important thing to understand is that each phase leaves behind a different type of telemetry:</p><ul><li><p>Certificate Transparency logs tell us when certificates are issued.</p></li><li><p>Passive DNS tells us how infrastructure resolves over time.</p></li><li><p>Hosting and network intelligence tells us where infrastructure lives.</p></li><li><p>Registrar data gives us ownership and registration context.</p></li></ul><p>CZDS gives us visibility into one of the earliest events in this lifecycle: domain delegation.</p><p>Today, though, we are going to talk more about the first phase: domain registration.</p><p>DNS (Domain Name System) is a globally distributed, hierarchical naming system. The age-old question of how the internet works is how&#8239;domain.com&#8239;eventually resolves to an IP address. When a new domain is delegated, the appropriate TLD registry publishes that delegation, so recursive resolvers can eventually discover it.</p><p>Before a phishing page exists, before a certificate is issued, before a victim receives an email, there is usually a domain registration and DNS delegation event.</p><p>That small window is where CZDS becomes interesting.</p><p>Because of this, ICANN has a service called CZDS (Centralized Zone Data Service) which provides daily zone files for participating gTLD registries. These zone files map delegated domains to their authoritative name servers and, when necessary, include glue records containing the IP addresses of those name servers.</p><p>In other words, CZDS gives defenders a view into the DNS delegation layer of the internet.</p><p>It does not tell you what a domain is currently hosting, what IP address a website resolves to, or what content exists behind the domain. Instead, it tells you that a domain exists and where its authoritative DNS infrastructure lives.</p><p>By collecting this data over time, you can begin to see how certain authoritative name servers repeatedly appear alongside fuzzy domain registrations, how domain name re-use/re-registration occurs over extended periods of time, or view outliers/clusters in relation to your own threat intelligence feed.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">THOR Collective Dispatch is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>What is CZDS?</h2><p>One reason CZDS tends to be overlooked is that the raw data isn&#8217;t immediately exciting. A zone file is just text, and most of the records you&#8217;ll encounter are completely benign.</p><p>Unlike Certificate Transparency, where suspicious certificate requests can sometimes stand out on their own, the value in CZDS rarely comes from an individual record. It emerges when you collect snapshots over time, enrich them with other datasets, and start asking relationship-based questions instead of record-based ones.</p><p>To use <a href="https://czds.icann.org/home">CZDS</a>&#8239;you do have to register an account and get an API key to download the compressed files. Each&#8239;.zone&#8239;file contains DNS delegation information for a gTLD, including delegated domains, authoritative name servers, and glue records where required.</p><p>I&#8217;m not going to go into details about name servers here, but the basics are that authoritative name servers publish the DNS records that allow resolvers to translate domain names into IP addresses and other resource records.</p><p>The IP addresses you see in a CZDS TLD zone file are glue records. They are not the IP addresses of the domain itself but rather the IP addresses of authoritative name servers when those addresses are needed to complete DNS delegation.</p><p>This distinction is important because CZDS is not passive DNS.</p><p>CZDS will not tell you:</p><ul><li><p>Where a domain currently resolves</p></li><li><p>Historical A/AAAA resolutions</p></li><li><p>HTTP behavior</p></li><li><p>Malware delivery infrastructure</p></li><li><p>Certificate history</p></li></ul><p>For that, you still need additional data sources.</p><p>What CZDS does provide is the earliest DNS-level visibility into domain existence and delegation relationships.</p><p>There is an important tradeoff, though. Certificate Transparency can often provide visibility close to the moment a certificate is issued, whereas CZDS is distributed as periodic snapshots by participating registries. Rather than observing individual delegation events in real time, you&#8217;re observing how the delegation layer changes over time. Those are different datasets with different strengths, and together they provide a more complete picture of infrastructure evolution.</p><h2>Data Relationships</h2><p>This is where the data becomes much more interesting.</p><p>A single domain registration by itself is usually just noise.</p><p>A domain that shares authoritative infrastructure with hundreds of other suspicious domains is a different story.</p><p>The value is not necessarily in the individual record. The value comes from the relationships.</p><p>Imagine ingesting daily zone files for a handful of popular gTLDs. One morning, a newly delegated domain catches your attention. On its own, it isn&#8217;t particularly interesting. But when you pivot to its authoritative name servers, you discover they&#8217;re also responsible for hundreds of other recently delegated domains.</p><p>Those name servers resolve through the same glue IPs, which belong to infrastructure you&#8217;ve previously associated with phishing activity. None of the domains have active websites yet, and none have appeared in Certificate Transparency logs. Nevertheless, you&#8217;ve already identified what appears to be a coordinated infrastructure cluster before most defenders would even know it exists.</p><p>That&#8217;s the advantage of treating CZDS as relationship data instead of a list of domain names. You&#8217;re not waiting for malicious content to appear; you&#8217;re looking for infrastructure patterns that suggest future activity.</p><p>For example:</p><pre><code><code>domain
  |
  +-- authoritative nameserver
          |
          +-- glue IP
                  |
                  +-- ASN
                  |
                  +-- other domains
</code></code></pre><p>Once you start looking at CZDS data as relationship data instead of just DNS records, you can begin building infrastructure graphs.</p><p>There are dozens of ways that this data can be useful for your organization:</p><ul><li><p>Shared authoritative name servers</p></li><li><p>Shared glue IPs</p></li><li><p>Newly delegated domains</p></li><li><p>Registrar patterns (with additional data)</p></li><li><p>DNS hosting providers</p></li><li><p>Infrastructure reuse</p></li><li><p>Identifying clusters of related registrations</p></li></ul><p>The problem though is size because of exponential growth over time (which has limited my research) unless you engineer it.</p><blockquote><p>NOTE: If anyone has petabyte(s) storage for free and forever then holla at me</p></blockquote><p>The interesting engineering problem is not necessarily storing every record forever. It is deciding what relationships and attributes actually matter.</p><p>For example, instead of storing:</p><pre><code><code>domain -&gt; every historical DNS record
</code></code></pre><p>you may get more value from storing:</p><pre><code><code>nameserver -&gt; domains
IP -&gt; nameservers
ASN -&gt; infrastructure
registrar -&gt; domains
first_seen
last_seen
</code></code></pre><p>The intelligence questions you want to answer should drive the data model.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/p/open-season-czds?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading THOR Collective Dispatch! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/p/open-season-czds?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://dispatch.thorcollective.com/p/open-season-czds?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><h2>Understanding CZDS Zone Files</h2><p>Each&#8239;.zone&#8239;file contains DNS delegation information for a gTLD, including delegated domains, authoritative name servers, and glue records where required.</p><p>For example, a simplified delegation may look something like:</p><pre><code><code>example.com. 172800 IN NS ns1.example.net.
ns1.example.net. 172800 IN A 192.0.2.10
</code></code></pre><p>The first record tells resolvers which authoritative name server is responsible for the domain.</p><p>The second record exists because&#8239;ns1.example.net&#8239;is within the namespace being delegated, and the resolver needs the IP address to find that server.</p><p>This is why CZDS is useful, but also why it is commonly misunderstood.</p><p>These zone files will give you the authoritative information for a gTLD but not details about the domain itself (the domain&#8217;s A, AAAA, CNAME, MX, etc. records); that you must still do if needed/warranted/etc.</p><p>The intelligence comes from combining CZDS with other sources.</p><p>For example:</p><pre><code><code>CZDS
&#8239;|
&#8239;+-- Domain delegation
&#8239; &#8239; &#8239; &#8239;&#8239;|
&#8239; &#8239; &#8239; &#8239;&#8239;+-- Nameserver
&#8239; &#8239; &#8239; &#8239; &#8239; &#8239; &#8239;&#8239;|
&#8239; &#8239; &#8239; &#8239; &#8239; &#8239; &#8239;&#8239;+-- Glue IP
&#8239; &#8239; &#8239; &#8239; &#8239; &#8239; &#8239; &#8239; &#8239; &#8239;&#8239;|
&#8239; &#8239; &#8239; &#8239; &#8239; &#8239; &#8239; &#8239; &#8239; &#8239;&#8239;+-- ASN
&#8239; &#8239; &#8239; &#8239; &#8239; &#8239; &#8239; &#8239; &#8239; &#8239;&#8239;|
&#8239; &#8239; &#8239; &#8239; &#8239; &#8239; &#8239; &#8239; &#8239; &#8239;&#8239;+-- Other observed domains
</code></code></pre><p>That relationship can then be enriched with:</p><ul><li><p>Certificate Transparency</p></li><li><p>WHOIS/RDAP</p></li><li><p>Passive DNS</p></li><li><p>Hosting intelligence</p></li><li><p>Reputation feeds</p></li><li><p>Internal telemetry</p></li></ul><p>The goal is not to answer:</p><pre><code><code>&#8220;Is this domain malicious?&#8221;
</code></code></pre><p>The goal is to answer:</p><pre><code><code>&#8220;What infrastructure relationships does this domain have, and have we seen similar behavior before?&#8221;
</code></code></pre><h2>Parsing Zone Files</h2><p>Here&#8217;s a general layout of the field data in these zone files:</p><pre><code><code>www.example.com. 3600 IN A 192.168.1.10
</code></code></pre><p>which produces the following in a JSON format:</p><pre><code><code>{
    "dns_record": "www.example.com",
    "ttl": "3600",
    "record_class": "IN",
    "record_type": "A",
    "record_data": "192.168.1.10"
}
</code></code></pre><p>For CZDS specifically, the records you will most commonly care about are delegation-related records:</p><ul><li><p>NS records</p></li><li><p>Glue A records</p></li><li><p>Glue AAAA records</p></li></ul><p>The challenge with CZDS is not parsing a single file.</p><p>The challenge is scale.</p><p>Zone files can be large, and storing every record from every zone forever, quickly becomes impractical unless you have a very specific reason for doing so.</p><p>This is why streaming is important.</p><p>Instead of:</p><pre><code><code>records = load_entire_zone_file() 
</code></code></pre><p>you generally want:</p><pre><code><code>for record in stream_zone_file(): 

    process(record) 
</code></code></pre><p>This allows you to:</p><ul><li><p>Process large zones with constant memory usage</p></li><li><p>Build enrichment indexes incrementally</p></li><li><p>Extract only relationships you care about</p></li><li><p>Avoid loading multi-gigabyte files into memory</p></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">THOR Collective Dispatch is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>Implementation Examples</h2><p>I have had a few implementations of using CZDS over the years. The most recent is embedded as a source within a project called&#8239;go-member-extender. This takes a MMDB database (binary search tree over IP addresses; fast lookups possible) and can extend or upsert it with data from different sources.</p><p>This one happens to be CZDS and written in Golang:</p><p><a href="https://github.com/MSAdministrator/go-mmdb-extender/blob/main/internal/source/czds/czds.go">https://github.com/MSAdministrator/go-mmdb-extender/blob/main/internal/source/czds/czds.go</a></p><p>The general idea is:</p><pre><code><code>CZDS Zone File 
&#8239; &#8239; &#8239; &#8239;&#8239;| 
&#8239; &#8239; &#8239; &#8239;&#8239;v 
Parse delegation data
&#8239; &#8239; &#8239; &#8239;&#8239;|
&#8239; &#8239; &#8239; &#8239;&#8239;v
Extract relationships
&#8239; &#8239; &#8239; &#8239;&#8239;|
&#8239; &#8239; &#8239; &#8239;&#8239;v
Enrich IP intelligence database
</code></code></pre><p>The advantage of this approach is that you can combine CZDS-derived information with other enrichment sources without needing to query massive raw datasets during investigations.</p><p>If Python is more your thing, then check out my Python package/CLI tool for CZDS below.</p><p>This one doesn&#8217;t touch a MMDB at all and just retrieves the zone files as requested.</p><p><a href="https://github.com/MSAdministrator/czds">https://github.com/MSAdministrator/czds</a></p><p>With either tool, remember you must have API access and have been granted access to more than one zone files.</p><h2>Python Streaming Parser (example)</h2><p>The first implementation uses&#8239;dnspython&#8239;and provides behavior similar to Go&#8217;s DNS parsing libraries.</p><p>The goal is:</p><ul><li><p>Stream records</p></li><li><p>Avoid loading entire zones</p></li><li><p>Support compressed zone files</p></li><li><p>Process records as they arrive</p></li></ul><pre><code><code>from __future__ import annotations

import gzip
from pathlib import Path
from typing import Iterator

import dns.exception
import dns.name
import dns.rdata
import dns.rdataclass
import dns.rdatatype
import dns.tokenizer
import dns.zonefile


def stream_zone_records(
    filename: str | Path,
    origin: str,
) -&gt; Iterator[dns.rdata.Rdata]:
    """
    Stream records from a zone file without loading the entire zone.

    Yields ResourceRecord objects one at a time, similar to Go's
    dns.NewZoneParser().
    """
    opener = gzip.open if str(filename).endswith(".gz") else open

    with opener(filename, "rt", encoding="utf-8", errors="replace") as f:
        tok = dns.tokenizer.Tokenizer(f)

        reader = dns.zonefile.Reader(
            tok,
            dns.name.from_text(origin),
            rdclass=dns.rdataclass.IN,
            relativize=False,
        )

        while True:
            try:
                rr = reader.read_rr()
            except EOFError:
                break
            except dns.exception.DNSException as e:
                raise RuntimeError(f"Zone parse error: {e}") from e

            if rr is None:
                continue

            yield rr
</code></code></pre><p>The important part here is not the dictionary itself. The important part is that we are transforming raw DNS data into relationships that can later be queried.</p><p>A raw zone file is just text.</p><p>A relationship database built from those records becomes intelligence.</p><h2>Lightweight CZDS Parser</h2><p>The second implementation is a lightweight parser written specifically around the CZDS workflow.</p><p>The goal was not to replace full DNS parsing libraries.</p><p>The goal was a small streaming parser that handles the features needed for large-scale zone processing:</p><ul><li><p>Streaming iteration (for rr in ZoneParser(path):)</p></li><li><p>Constant memory usage</p></li><li><p>.gz and plain text support</p></li><li><p>$ORIGIN</p></li><li><p>$TTL</p></li><li><p>Owner inheritance</p></li><li><p>Multiline records with parentheses</p></li><li><p>Comment stripping</p></li><li><p>Quoted-string preservation</p></li><li><p>RFC 3597 TYPE#### support</p></li><li><p>Lightweight ResourceRecord dataclass</p></li></ul><p>This version is intentionally focused on CZDS-style processing rather than being a complete replacement for every possible BIND zone feature.</p><blockquote><p>NOTE: This bottom one was written by Claude so take it with a grain of salt but it looks like to would work.</p></blockquote><pre><code><code>from __future__ import annotations

from dataclasses import dataclass
from pathlib import Path
import gzip
import re
import shlex
from typing import Iterator, TextIO

RFC3597_TYPE = re.compile(r"^TYPE\d+$", re.IGNORECASE)
_CLASSES = {"IN", "CH", "HS"}


@dataclass(slots=True)
class ResourceRecord:
    name: str
    ttl: int | None
    rdclass: str
    rdtype: str
    rdata: tuple[str, ...]


class ZoneParser:
    """Streaming BIND zone parser suitable for CZDS."""

    def __init__(self, path: str | Path):
        self.path = Path(path)
        self.origin = ""
        self.default_ttl: int | None = None
        self.current_owner: str | None = None

    def __iter__(self) -&gt; Iterator[ResourceRecord]:
        opener = gzip.open if self.path.suffix == ".gz" else open
        with opener(self.path, "rt", encoding="utf-8", errors="replace") as f:
            yield from self._parse(f)

    @staticmethod
    def _strip_comment(line: str) -&gt; str:
        out = []
        quoted = False
        escaped = False
        for ch in line:
            if escaped:
                out.append(ch)
                escaped = False
                continue
            if ch == "\\":
                escaped = True
                out.append(ch)
                continue
            if ch == '"':
                quoted = not quoted
                out.append(ch)
                continue
            if ch == ";" and not quoted:
                break
            out.append(ch)
        return "".join(out)

    def _fqdn(self, owner: str) -&gt; str:
        if owner == "@":
            return self.origin
        if owner.endswith("."):
            return owner[:-1]
        return f"{owner}.{self.origin}" if self.origin else owner

    def _parse(self, fh: TextIO) -&gt; Iterator[ResourceRecord]:
        buf = []
        depth = 0
        for raw in fh:
            line = self._strip_comment(raw).strip()
            if not line:
                continue
            depth += line.count("(")
            depth -= line.count(")")
            buf.append(line.replace("(", " ").replace(")", " "))
            if depth &gt; 0:
                continue
            record = " ".join(buf)
            buf.clear()

            if record.startswith("$ORIGIN"):
                parts = record.split(None, 1)
                if len(parts) &gt; 1:
                    self.origin = parts[1].rstrip(".")
                continue
            if record.startswith("$TTL"):
                parts = record.split(None, 1)
                if len(parts) &gt; 1:
                    self.default_ttl = int(parts[1])
                continue

            lex = shlex.shlex(record, posix=True)
            lex.whitespace_split = True
            tokens = list(lex)
            if not tokens:
                continue

            idx = 0
            owner = None
            first = tokens[0]
            up = first.upper()
            if not first.isdigit() and up not in _CLASSES:
                owner = first
                self.current_owner = owner
                idx = 1
            else:
                owner = self.current_owner
                if owner is None:
                    continue

            ttl = None
            rdclass = "IN"

            while idx &lt; len(tokens):
                t = tokens[idx]
                u = t.upper()
                if t.isdigit():
                    ttl = int(t)
                    idx += 1
                elif u in _CLASSES:
                    rdclass = u
                    idx += 1
                else:
                    break

            ttl = self.default_ttl if ttl is None else ttl
            if idx &gt;= len(tokens):
                continue

            rdtype = tokens[idx].upper()
            idx += 1

            if not (rdtype.isalpha() or RFC3597_TYPE.fullmatch(rdtype)):
                continue

            yield ResourceRecord(
                name=self._fqdn(owner),
                ttl=ttl,
                rdclass=rdclass,
                rdtype=rdtype,
                rdata=tuple(tokens[idx:]),
            )


if __name__ == "__main__":
    import sys
    for rr in ZoneParser(sys.argv[1]):
        print(rr)
</code></code></pre><p>Like Certificate Transparency, CZDS isn&#8217;t valuable because it magically identifies malicious domains. Its value comes from exposing another layer of attacker infrastructure that would otherwise remain difficult to observe.</p><p>By itself, a zone file is little more than a collection of DNS delegation records. Combined with Certificate Transparency, Passive DNS, registrar information, hosting intelligence, and your own internal telemetry, those records become edges in an infrastructure graph that can reveal relationships long before a phishing campaign reaches a victim.</p><p>That&#8217;s ultimately the lesson I took away after reading LP&#8217;s post. Modern threat intelligence isn&#8217;t about finding one perfect dataset, it&#8217;s more about understanding what each dataset can tell you, what it can&#8217;t, and how combining them creates something far more valuable than any individual source alone.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/p/open-season-czds/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://dispatch.thorcollective.com/p/open-season-czds/comments"><span>Leave a comment</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Open Season: Certificate Transparency]]></title><description><![CDATA[Part 1 of the Open Season series from the THOR Collective.]]></description><link>https://dispatch.thorcollective.com/p/open-season-certificate-transparency</link><guid isPermaLink="false">https://dispatch.thorcollective.com/p/open-season-certificate-transparency</guid><dc:creator><![CDATA[Lauren Proehl]]></dc:creator><pubDate>Thu, 30 Jul 2026 20:00:56 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!pD0z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6c4974-0ea0-4970-a6bb-7fdca938aeea_1920x2196.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Part 1 of the <a href="https://dispatch.thorcollective.com/p/open-season-hunting-adversary-infrastructure">Open Season series</a> from the THOR Collective. All free tools, no vendor gatekeeping.</em></p><p>Most data sources catch an adversary after they act. Certificate Transparency catches them before.</p><p>When an operator stands up new infrastructure, say a phishing page or a C2 redirector, they almost always want TLS on it. A padlock makes a fake login look real, and browsers punish plain HTTP, so they request a certificate. The moment a publicly trusted CA issues it, that certificate is written into the Certificate Transparency logs, public append-only ledgers built so anyone can audit what CAs hand out.</p><p>The operator never chose to publish the domain. The CA did it for them, automatically, often before the service is even reachable. That gap is what you hunt in: the window between cert issued and attack launched, sometimes hours, sometimes days.</p><p>And it is completely free. CT was built as a public good and it remains one, no matter how many vendors wrap it in a dashboard and charge for the view.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!A3Hq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce9a2765-084c-42a8-b716-f00b6081a940_165x299.gif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!A3Hq!,w_424,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce9a2765-084c-42a8-b716-f00b6081a940_165x299.gif 424w, https://substackcdn.com/image/fetch/$s_!A3Hq!,w_848,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce9a2765-084c-42a8-b716-f00b6081a940_165x299.gif 848w, https://substackcdn.com/image/fetch/$s_!A3Hq!,w_1272,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce9a2765-084c-42a8-b716-f00b6081a940_165x299.gif 1272w, https://substackcdn.com/image/fetch/$s_!A3Hq!,w_1456,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce9a2765-084c-42a8-b716-f00b6081a940_165x299.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!A3Hq!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce9a2765-084c-42a8-b716-f00b6081a940_165x299.gif" width="320" height="579.8787878787879" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ce9a2765-084c-42a8-b716-f00b6081a940_165x299.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:299,&quot;width&quot;:165,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Security Guard Meme GIFs | Tenor&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Security Guard Meme GIFs | Tenor" title="Security Guard Meme GIFs | Tenor" srcset="https://substackcdn.com/image/fetch/$s_!A3Hq!,w_424,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce9a2765-084c-42a8-b716-f00b6081a940_165x299.gif 424w, https://substackcdn.com/image/fetch/$s_!A3Hq!,w_848,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce9a2765-084c-42a8-b716-f00b6081a940_165x299.gif 848w, https://substackcdn.com/image/fetch/$s_!A3Hq!,w_1272,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce9a2765-084c-42a8-b716-f00b6081a940_165x299.gif 1272w, https://substackcdn.com/image/fetch/$s_!A3Hq!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce9a2765-084c-42a8-b716-f00b6081a940_165x299.gif 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">padlock on a fake O365 login? good to go.</figcaption></figure></div><h2><strong>What the data tells you</strong></h2><p>A CT log entry is a certificate plus metadata. For hunting, the fields that matter are the common name and the Subject Alternative Names (the domains the cert is valid for), the issuer (which CA signed it), the validity window (not_before and not_after), and the log entry timestamp, which is when the certificate actually reached the log.</p><p>The single most useful field is the SAN list. A certificate is frequently valid for more than one name, and operators bundle related infrastructure onto one cert all the time: the phishing domain, its www variant, a staging subdomain, sometimes a second unrelated campaign domain they were too lazy to separate. One cert, read carefully, hands you the operator&#8217;s other names for free.</p><p>The second useful field is the log entry timestamp. Certificates hitting the logs in a tight cluster for similar-looking names are a batch of infrastructure going up at once, and that rhythm is something you can cluster on. Use that one rather than not_before, for reasons in the traps below.</p><p>As of early 2026 there are roughly thirty to forty active CT log shards, operated by Google, Cloudflare, Let&#8217;s Encrypt, Sectigo, and a few others. Chrome and Apple each maintain their own list of trusted logs, and the two do not overlap perfectly. Chrome&#8217;s is the one most tooling tracks. To be trusted in a modern browser a cert needs proof that it was logged, and that proof is a Signed Certificate Timestamp, or SCT, a log&#8217;s signed promise that it accepted the certificate. You do not have to talk to the logs directly. Aggregators do that for you.</p><h2><strong>Why adversaries leave traces in it</strong></h2><p>Because the alternative is worse for them. Skip CT and the cert is untrusted, which means browser warnings, which means victims bounce before they type their password. The whole point of the fake login page is that it looks legitimate, and looking legitimate now requires a logged certificate. CT compliance is load-bearing for the attack.</p><p>They can use self-signed certs on non-browser infrastructure like C2, and some do. But anything a human opens in a browser needs a real cert, and a real cert gets logged. The economics of phishing leave no way around it.</p><p>Know what this lens cannot see, though. CT only covers publicly trusted CAs, so a private CA leaves no entry, and neither does IP-only infrastructure that never gets a name. Anything behind a provider that terminates TLS on a shared certificate (Cloudflare universal certs, Vercel, most phishing-as-a-service platforms) may never produce an entry you can tie to the operator. Absence from CT is not absence of infrastructure.</p><h3>The behaviors that show up:</h3><h4>Batch issuance. </h4><p>An actor registering and certing ten lookalike domains in an afternoon produces ten certs that hit the logs within minutes of each other. Cluster on the timing.</p><h4>Naming conventions. </h4><p>Operators reuse patterns. Once you see <code>login-acme-support.com</code>, you go looking for <code>login-acme-secure.com</code> and <code>acme-support-login.com</code>, because the same person tends to name things the same way.</p><h4>CA preference. </h4><p>Throwaway phishing infrastructure leans on free, automated CAs because cost and speed matter at volume. That is a weak signal on its own, but it stacks with the others.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">THOR Collective Dispatch is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2><strong>How to query and pivot</strong></h2><p>The free workhorse is <strong><a href="http://crt.sh">crt.sh</a></strong>, Sectigo&#8217;s CT search engine. It indexes the major logs into a Postgres database and exposes both a web UI and a JSON API. Start simple:</p><pre><code><code># every name ever seen in a cert under a domain
curl -s 'https://crt.sh/?q=%25.example.com&amp;output=json' \
  | jq -r '.[].name_value' | sed 's/^\*\.//' | sort -u
</code></code></pre><p>The <code>%</code> is a SQL wildcard, so <code>%.example.com</code> pulls every subdomain that has ever appeared in a logged certificate. Write it as <code>%25</code> in the URL, which is how <code>%</code> is percent-encoded. The bare version usually works but is not valid encoding, and it will fail behind some proxies. This alone surfaces dev, staging, and internal-looking hosts that were never meant to be public. For an adversary domain, it surfaces their other names.</p><p>Point it at your own domain while you are here. Every name in a publicly trusted cert is public the moment the CA issues it, so an internal hostname in one is a hostname you have published. If it should not be, it belongs on a private CA or behind a wildcard.</p><p>When you need real power, crt.sh exposes its Postgres directly, no account, read-only guest access:</p><pre><code><code>psql -h crt.sh -p 5432 -U guest certwatch
</code></code></pre><p>From there you can run actual SQL against the certificate data, which is how you do timing clustering and pattern hunting that the web UI cannot:</p><pre><code><code>-- one row per certificate, ordered by when it actually hit the logs
SELECT min(le.entry_timestamp) AS logged,
       x509_notBefore(c.certificate) AS not_before,
       x509_issuerName(c.certificate) AS ca
FROM certificate c
JOIN ct_log_entry le ON le.certificate_id = c.id
WHERE to_tsquery('certwatch', 'login-acme-support.com') @@ identities(c.certificate)
GROUP BY c.id, c.certificate
ORDER BY logged;
</code></code></pre><p>Grouping on <code>c.id</code> collapses a cert logged to several logs into one row, and <code>min(entry_timestamp)</code> gives you the moment it first appeared. Ordering on that rather than <code>not_before</code> is deliberate, for reasons in the traps below. The <code>to_tsquery</code> match is the current way in: as of July 2026 crt.sh has retired the old certificate_identity table for a full-text index, so queries against it now error, and the tsquery goes on the left.</p><p>That index does prefix and suffix matching, not substring, so you cannot ask crt.sh for every name containing a string. You have to arrive with names. The public Postgres is slow and kills anything running over about a minute, so be specific.</p><h3>The pivots, in the order they tend to pay off:</h3><h4>SAN expansion. </h4><p>Pull a suspicious cert. Read every name on it. Each new name is a new lead, and you feed each one back into crt.sh to find its certs and its SANs in turn. This is the core loop.</p><h4>Timing clustering. </h4><p>Sort candidate certs by log entry time. Names that cluster within minutes or hours of each other are very likely the same operator&#8217;s batch. The tighter the cluster and the more the names rhyme, the stronger the signal.</p><h4>Naming-convention sweeps. </h4><p>Take the pattern from one confirmed domain and go looking for its siblings. Operators are creatures of habit, and the database remembers every cert. crt.sh will not do this as a free-text substring search, so generate the candidate names yourself and check them in batches. A few hundred generated names cost nothing but patience. The indexes that do offer substring matching over CT gate it behind a paid tier or a browser session, so treat those as a manual spot-check.</p><h3>Mind the traps though.</h3><p>Wildcard certs (<code>*.example.com</code>) are candidates, not confirmed hosts, so always resolve before you trust them. Every certificate appears in the logs at least twice, once as a precertificate and once as the final cert, so deduplicate before you count.</p><p>And do not build timing analysis on <code>not_before</code>. The issuing CA sets it and every CA does it differently: Let&#8217;s Encrypt backdates about an hour, some a full day, some pin to midnight UTC. Compare certs from two CAs on that field and you are reading two clocks with two offsets, which invents bursts that never happened and flattens ones that did. Use the log entry timestamp. <code>not_before</code> is a CA&#8217;s opinion; the log entry is a fact.</p><p>For watching issuance live, <strong>certstream</strong> gives you a real-time firehose of every cert hitting the logs:</p><pre><code><code># wss://certstream.calidog.io  (filter for your patterns in real time)
pip install certstream
</code></code></pre><p>Point a small script at the stream, match on your target&#8217;s naming patterns or brand strings, and you get alerted within minutes of a new lookalike cert being minted. For a handful of domains without writing code, <strong>Certspotter</strong> from SSLMate offers free monitoring for up to five domains with email alerts.</p><p>One warning before you build on it. The public <code>certstream.calidog.io</code> endpoint fails in the worst possible way: the socket opens, stays up, and no certificates arrive. Nothing errors, so your watcher looks healthy and is deaf. Tested while writing this with the official client and with raw websockets, both endpoints, zero certificates.</p><p>The website will not tell you either. On connect the page replays a cached <code>/latest.json</code> into the live pane at a randomized, human-looking pace, and that cache has not moved since October 2025, so a dead feed still scrolls convincingly. Treat the public firehose as a demo. If the alert matters, self-host <code>certstream-server-go</code>, or <code>certstream-server-rust</code> at certstream.dev if you want the stream over SSE instead. And alert on silence as well as on matches, because here silence is ambiguous.</p><p>One note if you build your own tooling. CT is migrating from the original RFC 6962 dynamic logs to the tile-based <strong>Static CT API</strong> (Sunlight), and Chrome&#8217;s trusted list already mixes both. Query through crt.sh, certstream, or Certspotter and this is handled for you. Write your own log reader and you need to speak both during the changeover.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/p/open-season-certificate-transparency?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading THOR Collective Dispatch! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/p/open-season-certificate-transparency?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://dispatch.thorcollective.com/p/open-season-certificate-transparency?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><h2><strong>In practice: Ghost Stadium</strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Vbps!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefadc0a8-65f8-4728-aae4-b113d84fd535_1092x770.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Vbps!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefadc0a8-65f8-4728-aae4-b113d84fd535_1092x770.png 424w, https://substackcdn.com/image/fetch/$s_!Vbps!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefadc0a8-65f8-4728-aae4-b113d84fd535_1092x770.png 848w, https://substackcdn.com/image/fetch/$s_!Vbps!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefadc0a8-65f8-4728-aae4-b113d84fd535_1092x770.png 1272w, https://substackcdn.com/image/fetch/$s_!Vbps!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefadc0a8-65f8-4728-aae4-b113d84fd535_1092x770.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Vbps!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefadc0a8-65f8-4728-aae4-b113d84fd535_1092x770.png" width="1092" height="770" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/efadc0a8-65f8-4728-aae4-b113d84fd535_1092x770.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:770,&quot;width&quot;:1092,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1162370,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dispatch.thorcollective.com/i/209155639?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefadc0a8-65f8-4728-aae4-b113d84fd535_1092x770.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Vbps!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefadc0a8-65f8-4728-aae4-b113d84fd535_1092x770.png 424w, https://substackcdn.com/image/fetch/$s_!Vbps!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefadc0a8-65f8-4728-aae4-b113d84fd535_1092x770.png 848w, https://substackcdn.com/image/fetch/$s_!Vbps!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefadc0a8-65f8-4728-aae4-b113d84fd535_1092x770.png 1272w, https://substackcdn.com/image/fetch/$s_!Vbps!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefadc0a8-65f8-4728-aae4-b113d84fd535_1092x770.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The question going in: can certificate data surface campaign infrastructure the published sets have missed, and can it at least date the operation?</p><p>Point the CT loop at Ghost Stadium and the operator turns out to live by the same economics as everyone else. The kit is a fake FIFA World Cup 2026 ticket storefront meant to be opened in a browser, so every live node needs a trusted cert, and every cert lands in the logs. Pull the certs for fifa-sg[.]shop, a confirmed net-new node that has since been deleted, and the issuance pattern is louder than any SAN. On 2026-05-17 it drew four certificates in twenty-one minutes from three different CAs, Google Trust Services, then Let&#8217;s Encrypt, then SSL Corporation, back to back. That is automated standup, an operator spraying certificate requests the moment the domain goes live. Measure the same burst on not_before and it stretches to seventy minutes, because the three CAs backdate by different amounts. The tight number is the real one.</p><p>shop-26fifa[.]com shows the same shape three days later, four certs across two CAs inside fourteen minutes on 2026-05-20. The domain was registered at 18:30:41 UTC and its first certificate hit the logs under three minutes later. Cert issuance and registration are not just the same day, they are the same event, which is why this lens and Part 4 corroborate each other. It is also the cleanest argument for reading log entries: that first certificate carries a not_before of 17:34:45, fifty-six minutes before the domain it covers existed.</p><p>Check one thing before you call that automation. The registrar was NameSilo and the certificates came from Let&#8217;s Encrypt and SSL Corporation, unrelated vendors, so somebody&#8217;s own tooling drove it. fifa[.]house is the counterexample: registered through GoDaddy, certified by GoDaddy thirty-seven seconds later. That interval says something about GoDaddy&#8217;s provisioning and nothing at all about the operator. When registrar and CA are the same company, a fast cert is a checkout bundle, not tradecraft.</p><p>The reissuance rhythm then just keeps going: fifa[.]house cycled through twenty-one certs from January to April across GoDaddy, Let&#8217;s Encrypt, and TrustAsia, tempo you read straight off the log entries.</p><p>SAN co-tenancy is where this gets interesting, because the same campaign does it both ways. fifa-sg[.]shop and shop-26fifa[.]com are disciplined: apex, wildcard, nothing else. Read those two and you would conclude the operator certs one name at a time.</p><p>fifa[.]house is the opposite. One of its certificates carries forty-five names spanning about twenty registrable domains: fifa[.]bio, fifa[.]cafe, fifa[.]college, fifa[.]tax, the whole fifa-com[.]* run across seven TLDs, then www-fifaworldcup[.]* across seven more. Feed three seed domains into the SAN loop and twenty-five come back out.</p><p>Widen that to a sample of six hundred domains from the published set and the split holds: ninety-one percent of their certificates cover a single registrable domain, nine percent bundle more, and a hundred and sixty-two certs carry exactly one hundred names, which is Let's Encrypt's SAN limit. Somebody is filling certificates to the limit and somebody else is provisioning one at a time. The certificates are where that seam shows.</p><p>Expanding on shared certs drags in infrastructure that is merely adjacent. One of those hundred-name certs mixes FIFA lookalikes with Chinese gambling brands that may be a different operation entirely, and six more turned out to be a bulk-cert service carrying unrelated tenants that have nothing to do with this campaign at all. The highest-yield pivot here is also the one most likely to hand you somebody else's estate. Confirm before you count.</p><p>Ghost Stadium is also heavily reported, and that shapes what CT is good for. <a href="https://www.group-ib.com/blog/ghost-stadium-football-fraud/">Group-IB</a> mapped more than 4,300 fraudulent FIFA domains registered since August 2025, but that total spans six fraud schemes and four independent threat actors; Ghost Stadium itself is the 300-plus domains actively serving the kit. Group-IB describes the operator as Chinese-speaking and financially motivated, and that is as far as attribution goes here. <a href="https://www.validin.com/blog/ghost_stadium/">Validin</a> went further on infrastructure and published a suspected set of 6,113 domains, about half still resolving, with the full list on GitHub where anyone can diff against it.</p><p>So check rather than assert. The SAN loop turned three seed domains into twenty-five registrable domains, forty-nine DNS names once you count www variants. Diff those against Validin&#8217;s set and forty-six of the forty-nine were already on it. Two of the three misses were seeds rather than discoveries &#8212; fifa-sg[.]shop and shop-26fifa[.]com went into the loop, they did not come out of it &#8212; and the third is a www variant of a listed domain. SAN expansion produced exactly one name nobody had.</p><p>Read that before you take it as a verdict. Most of Validin&#8217;s set came from a lookalike regex that matches any fifa-shaped domain, so fifa[.]cafe was going to be on that list whether or not a human ever looked at it. Against a regex superset, &#8220;already published&#8221; means the name matched a pattern. Against Group-IB&#8217;s 300 active domains it would mean someone investigated it. Those are different bars, and CT grades worse against the first one than it deserves.</p><p>Corroboration with timestamps is still worth having when you are deciding whether to act on someone else&#8217;s list. But the net-new nodes in this series came from <strong>pairing the cert view with a kit-specific fingerprint</strong> in a later installment, not from certificates alone. One more thing from Validin that matters for what comes next: every active domain in their set sits behind Cloudflare, which is exactly the wall Part 2 has to get over.</p><p>Then take one confirmed node and resolve it. These answered from 104.21, 172.64, and 172.67 space while they were live, all Cloudflare, AS13335. CT told you the name exists and the minute its cert was minted. It cannot tell you where the box actually sits, because the operator parked Cloudflare in front of it. That gap is exactly what the next source exists to close.</p><p>Assessment, high confidence: against an actor this heavily reported, Certificate Transparency expands a name list fast but rarely past what someone has already published. Use it to confirm cluster membership, read the batch rhythm, and date the standup. Expect a thin net-new edge, not a new cluster.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pD0z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6c4974-0ea0-4970-a6bb-7fdca938aeea_1920x2196.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pD0z!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6c4974-0ea0-4970-a6bb-7fdca938aeea_1920x2196.png 424w, https://substackcdn.com/image/fetch/$s_!pD0z!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6c4974-0ea0-4970-a6bb-7fdca938aeea_1920x2196.png 848w, https://substackcdn.com/image/fetch/$s_!pD0z!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6c4974-0ea0-4970-a6bb-7fdca938aeea_1920x2196.png 1272w, https://substackcdn.com/image/fetch/$s_!pD0z!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6c4974-0ea0-4970-a6bb-7fdca938aeea_1920x2196.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pD0z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6c4974-0ea0-4970-a6bb-7fdca938aeea_1920x2196.png" width="1456" height="1665" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/db6c4974-0ea0-4970-a6bb-7fdca938aeea_1920x2196.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1665,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:6318995,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dispatch.thorcollective.com/i/209155639?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6c4974-0ea0-4970-a6bb-7fdca938aeea_1920x2196.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pD0z!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6c4974-0ea0-4970-a6bb-7fdca938aeea_1920x2196.png 424w, https://substackcdn.com/image/fetch/$s_!pD0z!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6c4974-0ea0-4970-a6bb-7fdca938aeea_1920x2196.png 848w, https://substackcdn.com/image/fetch/$s_!pD0z!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6c4974-0ea0-4970-a6bb-7fdca938aeea_1920x2196.png 1272w, https://substackcdn.com/image/fetch/$s_!pD0z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6c4974-0ea0-4970-a6bb-7fdca938aeea_1920x2196.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">adversaries be like</figcaption></figure></div><p></p><h2><strong>Hunt hypothesis template</strong></h2><pre><code><code>HYPOTHESIS
  An adversary targeting our brand stages lookalike infrastructure
  and certs it before launch. New certificates matching our brand
  patterns appear in CT logs ahead of the attack and cluster by
  issuance time and naming convention.

DATA SOURCES
  Primary:  crt.sh (web, JSON API, direct Postgres)
  Live:     certstream (wss://certstream.calidog.io), Certspotter
  Backup:   Censys/Shodan cert search (free), MerkleMap, Merkle Town
  Cross-ref: passive DNS (Part 2), scan data (Part 3),
             registration data (Part 4)

PIVOT STEPS
  1. Start from known domains and pull their certs. crt.sh
     matches names, not substrings.
  2. For each hit, expand the SAN list. Every name is a new lead.
  3. Sort candidates by log entry time, not not_before. Flag
     tight issuance clusters.
  4. Generate names from the convention and check them in
     batches. crt.sh has no substring search.
  5. Resolve survivors; confirm via pDNS co-residence and scan-time
     cert match before promoting to confirmed.
  6. Add matched patterns to a certstream watch for live alerting.

EXPECTED SIGNAL
  A cluster of lookalike domains sharing a naming convention, with
  certs hitting the logs in a tight window, from one CA or
  sprayed across several, resolving to shared or adjacent hosting.

VALIDATION / TRIAGE
  Deduplicate precert/leaf pairs. Treat wildcards as candidates,
  not hosts. Resolve before trusting. Require a second independent
  link (shared IP, shared registrant) before confirming.

ATT&amp;CK MAPPING
  T1583.001  Acquire Infrastructure: Domains
  T1588.004  Obtain Capabilities: Digital Certificates
  T1587.003  Develop Capabilities: Digital Certificates
  T1608.003  Stage Capabilities: Install Digital Certificate
  T1596.003  Search Open Technical Databases: Digital Certificates
</code></code></pre><h2><strong>Tooling quick reference</strong></h2><pre><code><code>FREE, NO ACCOUNT (start here)
  crt.sh              crt.sh/?q=%25.domain&amp;output=json
                      Web UI, JSON API, and direct Postgres:
                      psql -h crt.sh -p 5432 -U guest certwatch
  certstream          wss://certstream.calidog.io
                      Real-time firehose of all new certs.
                      Public server accepts the connection then
                      delivers nothing, which looks like a quiet
                      day. Self-host certstream-server-go for
                      anything load-bearing.

FREE MONITORING / BACKUP INDEXES
  Certspotter         api.certspotter.com/v1/issuances
                      Free alerts for up to 5 domains. Works
                      without an account for lookups.
  Merkle Town         Cloudflare CT dashboard/search
  MerkleMap           merklemap.com  (alternate CT search)
  Censys / Shodan     cert search. Substring search exists here
                      but free tiers restrict it to the browser;
                      the search APIs want a paid plan.

PASSIVE SUBDOMAIN TOOLS THAT USE CT
  subfinder, amass    use CT logs as a primary passive source

OPTIONAL COMMERCIAL UPGRADES (not required)
  Censys/Shodan paid cert data, SSLMate paid monitoring,
  vendor CT feeds. None needed for anything above.
</code></code></pre><p>Two things are true about the hunt above. The SAN loop worked exactly as advertised and turned three domains into twenty-five. And all but one were already on a list somebody published months ago. CT did not fail there. It walked ground that had already been mapped, and told us when each stone was laid.</p><p>That is the shape of this source. What you get out of CT scales with how early you are and how few people have looked before you. Arrive after the reporting lands and it corroborates and dates. Arrive first and it is the only place the infrastructure exists yet, because the certificate is minted before the site serves a page, before the mail goes out, before there is anything else to detect.</p><p>Which is the argument for pointing it at yourself. Nobody has published the list of domains that will impersonate your brand next quarter. On that hunt you are not late, you are first, and you already know the brand strings worth watching. The limitation that blunts CT against a well-reported actor does not apply when the target is you.</p><p>CT is the rare source where you are not chasing the adversary, you are waiting at the door they have to walk through. They need a trusted cert, that cert gets logged the moment a CA issues it, and the log is public and free for anyone to read. No vendor owns that.</p><p>Catch the cert before the campaign starts, and you are hunting the attack while it is still being built.</p><h2><strong>Up Next</strong></h2><p> Take fifa[.]house with you. CT handed us twenty-one certificates on it, a first-to-last window from January to April, and roughly twenty sibling domains riding its SANs. What CT cannot tell us is where any of it was hosted. The name is NXDOMAIN today, so there is nothing left to resolve. Same for fifa-sg[.]shop, dead since May. We have precise names and precise minutes, and no addresses.</p><p><strong>Open Season: Passive DNS.</strong> That gap is what the next source closes. Passive DNS is the historical record of what resolved where and when, the one place a dead name still has an address, and the way behind a CDN to an origin the operator forgot to firewall. It reverses an IP into every domain that shared it, and clusters campaigns by the hosting and nameservers they reuse. We anchor it on community-run data, no vendor gates.</p><p><em>Open Season is a recurring series from the THOR Collective exploring how practitioners can use open-source data to hunt adversary infrastructure. Each installment covers a single data source, soup to nuts. Want to contribute an installment or suggest a data source? Reach out.</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/p/open-season-certificate-transparency/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://dispatch.thorcollective.com/p/open-season-certificate-transparency/comments"><span>Leave a comment</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Open Season: Hunting Adversary Infrastructure With Free Data]]></title><description><![CDATA[Introducing a recurring series from the THOR Collective. All free tools, no vendor gatekeeping]]></description><link>https://dispatch.thorcollective.com/p/open-season-hunting-adversary-infrastructure</link><guid isPermaLink="false">https://dispatch.thorcollective.com/p/open-season-hunting-adversary-infrastructure</guid><dc:creator><![CDATA[Lauren Proehl]]></dc:creator><pubDate>Tue, 28 Jul 2026 17:22:55 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!3cVm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F317b38aa-e2f1-46f8-bee8-b9a90f201868_2510x1664.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3cVm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F317b38aa-e2f1-46f8-bee8-b9a90f201868_2510x1664.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3cVm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F317b38aa-e2f1-46f8-bee8-b9a90f201868_2510x1664.png 424w, https://substackcdn.com/image/fetch/$s_!3cVm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F317b38aa-e2f1-46f8-bee8-b9a90f201868_2510x1664.png 848w, https://substackcdn.com/image/fetch/$s_!3cVm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F317b38aa-e2f1-46f8-bee8-b9a90f201868_2510x1664.png 1272w, https://substackcdn.com/image/fetch/$s_!3cVm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F317b38aa-e2f1-46f8-bee8-b9a90f201868_2510x1664.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3cVm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F317b38aa-e2f1-46f8-bee8-b9a90f201868_2510x1664.png" width="1456" height="965" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/317b38aa-e2f1-46f8-bee8-b9a90f201868_2510x1664.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:965,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:6229725,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://dispatch.thorcollective.com/i/208711290?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F317b38aa-e2f1-46f8-bee8-b9a90f201868_2510x1664.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3cVm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F317b38aa-e2f1-46f8-bee8-b9a90f201868_2510x1664.png 424w, https://substackcdn.com/image/fetch/$s_!3cVm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F317b38aa-e2f1-46f8-bee8-b9a90f201868_2510x1664.png 848w, https://substackcdn.com/image/fetch/$s_!3cVm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F317b38aa-e2f1-46f8-bee8-b9a90f201868_2510x1664.png 1272w, https://substackcdn.com/image/fetch/$s_!3cVm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F317b38aa-e2f1-46f8-bee8-b9a90f201868_2510x1664.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The threat intelligence industry has spent years selling practitioners a lie: that hunting takes a budget.</p><p>You have heard the pitch on every sales call. The good data is gated, the real pivots need an enterprise license, and mapping an adversary&#8217;s infrastructure runs six figures before you start. Everything cheaper is for hobbyists.</p><p>It was never true, and this series is the proof.</p><p>The internet already records adversary infrastructure constantly, in public and for free, if you know where to look. Every certificate an operator mints gets logged by the CA that issued it. Passive sensors keep the domains they resolve long after those domains go dark. Scanners banner-grab exposed services within hours, registration paperwork carries a timestamp, and anything leaked to a public repo sits there until someone finds it. None of this needs permission, and most of it predates the vendors now reselling it to you at a markup.</p><p>That is the first ground rule, and it does not bend. Every source in this series is free to reach, no enterprise license, no &#8220;contact sales.&#8221; Where a paid tool genuinely helps, it shows up as an optional upgrade and the core method still runs without it. A technique that only works with a paid key is not in here. A practitioner with a terminal and no budget can run everything that follows.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">THOR Collective Dispatch is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>Reading defensive data offensively</h2><p>Most analysts meet these sources from the defensive side, watching their own walls. You monitor Certificate Transparency in case someone mis-issues a cert for your domain, check passive DNS to see where your own infrastructure resolved, scan your external surface, and grep public repos for your leaked secrets. Useful work, all of it, and all of it reactive.</p><p>This series is about turning the telescope around.</p><p>Point the same tools the other way and they do offensive work without complaint. The Certificate Transparency log that warns you about a phished brand will also surface the staging domains an actor certed last night, before the first email goes out. Passive DNS that maps your own footprint reverses an adversary&#8217;s IP into every domain that shared it. The scanners inventorying your attack surface will flag a Cobalt Strike team server hiding behind a redirector. The queries are identical; only who you aim them at changes.</p><p>That shift is the whole discipline: you stop waiting for an alert and start finding the campaign while it is still being built. It costs nothing but the time to learn the queries.</p><h2>What this is, and what it is not</h2><p>Open Season is a methodology series. Each installment takes a single freely accessible data source and walks it end to end: what the source actually tells you, why adversaries leave traces in it whether they want to or not, how to query and pivot through it, how to enrich and correlate it against the other sources, a hunt hypothesis you can lift and run, and a tooling quick reference. Soup to nuts, one source at a time.</p><p>It is written for practitioners. Threat hunters, detection engineers, CTI analysts, IR leads. People who will actually open the terminal. There is no executive summary energy here, no &#8220;in today&#8217;s evolving threat environment.&#8221; If you want a vendor whitepaper, there are a thousand of those and they are easy to find. This is the other thing.</p><p>It is also not a story series. The THOR Collective does narrative threat intelligence elsewhere, the &#8220;From the Fire&#8221; kind, behavioral and contextual. Open Season is the opposite register. Straight hunt methodology, structured, repeatable, the kind of thing you keep open in a second tab while you work.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/p/open-season-hunting-adversary-infrastructure?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading THOR Collective Dispatch! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/p/open-season-hunting-adversary-infrastructure?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://dispatch.thorcollective.com/p/open-season-hunting-adversary-infrastructure?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p></p><h2>The map</h2><p>Each installment stands on its own, but they compound, because real hunting is never one source. You pivot from a cert to an IP to a domain to a registrant to a repo, and the picture assembles across all of them.</p><p><strong>Certificate Transparency.</strong> Every public cert, logged forever, queryable for free through crt.sh. Issuance timing, SAN analysis, naming conventions, real-time monitoring of new certs as they are minted. The fastest way to catch infrastructure before it goes live.</p><p><strong>Passive DNS.</strong> The historical record of what resolved where, and when. Reverse an IP into its co-resident domains, time-window the noise out, cluster operations by shared hosting and nameservers. Anchored on community-run data, not vendor gates.</p><p><strong>Internet Scan Data.</strong> What a box is actually running. Open ports, banners, TLS fingerprints. JARM and JA4 to identify C2 frameworks even behind a redirector, with tools you run yourself for nothing.</p><p><strong>WHOIS and Registration Intelligence.</strong> The paperwork, in the post-GDPR, RDAP era. What still leaks after redaction: registration timing, nameserver patterns, registrar choices, and the historical records that predate privacy.</p><p><strong>Code and Paste Repositories.</strong> Where operators leak their own tooling, configs, and credentials. GitHub, GitLab, paste sites. Reading the adversary&#8217;s OPSEC failures off the public record.</p><p><strong>Front Companies and Fraudulent Employment.</strong> The capstone, where every prior source converges on a single live problem: hunting DPRK IT worker operations and the shell infrastructure that supports them.</p><p>To keep the methodology concrete, the series hunts one live operation the whole way down. Ghost Stadium is the FIFA World Cup 2026 ticket-phishing kit that <a href="https://www.group-ib.com/blog/ghost-stadium-football-fraud/">Group-IB</a> and <a href="https://cybelangel.com/blog/our-investigation-of-fifa-world-cup-2026-fraud-threat-report/">CybelAngel</a> attribute to a Chinese-speaking, financially motivated operator, and it has stood up thousands of lookalike domains ahead of the tournament. Each installment works it with that installment&#8217;s lens, then hands the next one a live node to carry forward. The capstone deliberately flips to a different adversary, to show the pivots do not care who they are aimed at.</p><h2>Why free matters</h2><p>A last word on the free rule, because it holds up everything else.</p><p>Paywalls do two kinds of damage. The obvious one is exclusion: small teams, students, nonprofits, and underfunded defenders get locked out. The quieter one is rot. Techniques only a handful of licensed analysts can run never get taught or pressure-tested, the community loses its ability to check the vendors&#8217; work, and the shared skill base shrinks.</p><p>Free, community-run data behaves the opposite way. People share it, fork it, script against it, improve it. A couple of classic sources went commercial while this series was being written, and each time the community routed around the paywall and built something open. The way to protect that is to keep using it and teaching it, and to stop treating a purchase order as the price of entry.</p><p>So: pick up the queries and point the telescope the other way. The adversary&#8217;s infrastructure is already on the public record, and you already have what you need to find it.</p><p>Part 1 starts with the source that catches infrastructure before it is even live: Certificate Transparency.</p><p><em>Open Season is a recurring series from the THOR Collective exploring how practitioners can use open-source data to hunt adversary infrastructure. Each installment covers a single data source, soup to nuts. Want to contribute an installment or suggest a data source? Reach out.</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/p/open-season-hunting-adversary-infrastructure/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://dispatch.thorcollective.com/p/open-season-hunting-adversary-infrastructure/comments"><span>Leave a comment</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Keep the Tension That Builds You]]></title><description><![CDATA[In the age of AI, the work worth keeping is the work that lets you catch the machine when it's wrong.]]></description><link>https://dispatch.thorcollective.com/p/keep-the-tension-that-builds-you</link><guid isPermaLink="false">https://dispatch.thorcollective.com/p/keep-the-tension-that-builds-you</guid><dc:creator><![CDATA[Lauren Proehl]]></dc:creator><pubDate>Thu, 02 Jul 2026 16:03:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!zeGb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb08d27dd-8500-49cc-b30e-d2efc3be1bbc_1500x1000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Every forecast about AI focuses on its impact on jobs. But what&#8217;s it doing to you right now, while you still have a job and things seem fine? <br></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zeGb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb08d27dd-8500-49cc-b30e-d2efc3be1bbc_1500x1000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zeGb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb08d27dd-8500-49cc-b30e-d2efc3be1bbc_1500x1000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!zeGb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb08d27dd-8500-49cc-b30e-d2efc3be1bbc_1500x1000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!zeGb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb08d27dd-8500-49cc-b30e-d2efc3be1bbc_1500x1000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!zeGb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb08d27dd-8500-49cc-b30e-d2efc3be1bbc_1500x1000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zeGb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb08d27dd-8500-49cc-b30e-d2efc3be1bbc_1500x1000.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b08d27dd-8500-49cc-b30e-d2efc3be1bbc_1500x1000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Sophie Cunningham's Finger-Pointing Clip Lasted Approximately 22 Seconds,  but the Memes Will Live Forever&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Sophie Cunningham's Finger-Pointing Clip Lasted Approximately 22 Seconds,  but the Memes Will Live Forever" title="Sophie Cunningham's Finger-Pointing Clip Lasted Approximately 22 Seconds,  but the Memes Will Live Forever" srcset="https://substackcdn.com/image/fetch/$s_!zeGb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb08d27dd-8500-49cc-b30e-d2efc3be1bbc_1500x1000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!zeGb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb08d27dd-8500-49cc-b30e-d2efc3be1bbc_1500x1000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!zeGb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb08d27dd-8500-49cc-b30e-d2efc3be1bbc_1500x1000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!zeGb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb08d27dd-8500-49cc-b30e-d2efc3be1bbc_1500x1000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>I&#8217;m training for a powerlifting meet. A phrase I keep thinking about? </span><em><strong><span>Time under tension.</span></strong></em><span> </span>It&#8217;s simple: muscles grow when they&#8217;re under load. Take the load off, and they start to degrade, slowly, without warning. It isn&#8217;t instant, but the minute you stop pushing, it begins.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">THOR Collective Dispatch is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p><span>You got good at your work the same way, even if no one called it training. The bad first drafts. The ticket you wrestled with for two days before it finally gave. Sitting with a problem long enough that you stopped being scared of it. Those hours made you who you are today. Growth was the tax we paid for having no shortcut.</span></p><p><span>When the shortcut arrived, the work didn&#8217;t go away, but much of it became optional. Everything that used to be forced on you must now be opted into. But we are seeing a lot of people don&#8217;t opt in because there&#8217;s no ache from a rep you never did. You just feel faster. And faster feels like progress.</span></p><p><span>Maybe, for a while, you can&#8217;t tell the difference. And maybe, neither can anyone else. The output stops telling you who did the thinking. The person still does the hard reasoning, and the person who quietly handed it over turns in work that reads the same on the page. So the signal you used to take off someone&#8217;s output, the one that told you who was actually sharp, stops working. Everyone looks capable.</span></p><p><span>But that doesn&#8217;t last.</span></p><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Us2V!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57113610-31b3-4dd8-8ece-14a3a1a7d533_399x498.gif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Us2V!,w_424,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57113610-31b3-4dd8-8ece-14a3a1a7d533_399x498.gif 424w, https://substackcdn.com/image/fetch/$s_!Us2V!,w_848,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57113610-31b3-4dd8-8ece-14a3a1a7d533_399x498.gif 848w, https://substackcdn.com/image/fetch/$s_!Us2V!,w_1272,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57113610-31b3-4dd8-8ece-14a3a1a7d533_399x498.gif 1272w, https://substackcdn.com/image/fetch/$s_!Us2V!,w_1456,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57113610-31b3-4dd8-8ece-14a3a1a7d533_399x498.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Us2V!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57113610-31b3-4dd8-8ece-14a3a1a7d533_399x498.gif" width="399" height="498" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/57113610-31b3-4dd8-8ece-14a3a1a7d533_399x498.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:498,&quot;width&quot;:399,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;a man in a brown jacket and plaid shirt stands in front of a swimming pool&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="a man in a brown jacket and plaid shirt stands in front of a swimming pool" title="a man in a brown jacket and plaid shirt stands in front of a swimming pool" srcset="https://substackcdn.com/image/fetch/$s_!Us2V!,w_424,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57113610-31b3-4dd8-8ece-14a3a1a7d533_399x498.gif 424w, https://substackcdn.com/image/fetch/$s_!Us2V!,w_848,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57113610-31b3-4dd8-8ece-14a3a1a7d533_399x498.gif 848w, https://substackcdn.com/image/fetch/$s_!Us2V!,w_1272,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57113610-31b3-4dd8-8ece-14a3a1a7d533_399x498.gif 1272w, https://substackcdn.com/image/fetch/$s_!Us2V!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57113610-31b3-4dd8-8ece-14a3a1a7d533_399x498.gif 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>What&#8217;s come apart underneath is capability and output, and your job only measures one of them. The person who kept the load can still work when the machine is wrong. They can catch it in the moments it&#8217;s confidently and sometimes fluently wrong. The person who let the load go can only supervise. And supervising a system you can no longer out-think isn&#8217;t oversight. It&#8217;s trust with a manager&#8217;s title. One side keeps compounding. The other plateaus and calls it seniority.</span></p><p><span>You won&#8217;t know which one you became until the day it matters, and by then it&#8217;s already set. There&#8217;s no cramming years of skipped reps when the gap finally surfaces. The choice is being made now, in a hundred forgettable moments where you let the machine take the tension off, and the bill for those moments doesn&#8217;t arrive for years.</span></p><p><span>None of this is nostalgia, and I&#8217;m not afraid of the tools. In fact, I have embraced them wholeheartedly. Handing work to machines is the whole story of how work has ever moved: the calculator, the compiler, the search bar. Nobody is a better thinker for only doing long division by hand. The question has never been whether to use the machine. It was which work to keep, now that keeping any of it is finally up to you.</span></p><p><span>And there is a test for that. </span><strong><span>The weight worth keeping is the weight that builds the judgment you&#8217;ll need to supervise the machine you&#8217;re handing the work to.</span></strong><span> That&#8217;s the whole filter. Some of what you do all day is hauling, and you should automate it without a flicker of guilt. But some of it is the exact rep that lets you catch the machine when it&#8217;s wrong &#8212; usually the slow, irritating, judgment-shaped part. Keep that one. Let the rest go.</span></p><p><span>I came up in threat hunting, and the discipline is almost a proof of this. Hunting only exists because the automated layer isn&#8217;t enough, because the confident alert and the confident silence are both, sometimes, wrong. What makes a hunter is years of reps that don&#8217;t obviously pay off: staring at ordinary logs until the one thing that doesn&#8217;t belong finally lifts off the page. That instinct can&#8217;t be handed to you. It&#8217;s the judgment that lets you stand over an automated system and say, quietly, </span><em><span>that&#8217;s wrong</span></em><span>. Which is exactly the weight worth keeping. Everything that builds it, you protect. Everything that doesn&#8217;t, the machine can have.</span></p><p><span>In practice, this comes down to smaller things than it sounds. Mostly it&#8217;s about order. </span></p><p><span>Do the rep before you ask the machine: write your own version first, even a rough one, then hand it over and tell it to tear the thing apart. Go to the machine first, and you spend the day editing its thinking instead of building your own; go to yourself first, and it becomes the thing that checks your work, which is a completely different job for your brain and a completely different you a year out. And set the tool up to put strain on you rather than take it off. Ask it to hold its answer and quiz you instead. Tell it to argue the other side and go hunting for the weak joint in your reasoning. Guess what it&#8217;s going to say before you let it speak, and pay attention to the gap. Same tool either way. Whether it ends up a coach or a crutch is entirely a function of what you asked it for.</span></p><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qA8k!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b1303cd-690c-40a1-883c-8c5d5844205a_439x532.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qA8k!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b1303cd-690c-40a1-883c-8c5d5844205a_439x532.jpeg 424w, https://substackcdn.com/image/fetch/$s_!qA8k!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b1303cd-690c-40a1-883c-8c5d5844205a_439x532.jpeg 848w, https://substackcdn.com/image/fetch/$s_!qA8k!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b1303cd-690c-40a1-883c-8c5d5844205a_439x532.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!qA8k!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b1303cd-690c-40a1-883c-8c5d5844205a_439x532.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qA8k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b1303cd-690c-40a1-883c-8c5d5844205a_439x532.jpeg" width="439" height="532" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7b1303cd-690c-40a1-883c-8c5d5844205a_439x532.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:532,&quot;width&quot;:439,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;The Use of RPE in Team Sports - SimpliFaster&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="The Use of RPE in Team Sports - SimpliFaster" title="The Use of RPE in Team Sports - SimpliFaster" srcset="https://substackcdn.com/image/fetch/$s_!qA8k!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b1303cd-690c-40a1-883c-8c5d5844205a_439x532.jpeg 424w, https://substackcdn.com/image/fetch/$s_!qA8k!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b1303cd-690c-40a1-883c-8c5d5844205a_439x532.jpeg 848w, https://substackcdn.com/image/fetch/$s_!qA8k!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b1303cd-690c-40a1-883c-8c5d5844205a_439x532.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!qA8k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b1303cd-690c-40a1-883c-8c5d5844205a_439x532.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>But the individual version of this is the small version, and I&#8217;ve come to think it isn&#8217;t even the one that matters most. Because the same thing is happening to organizations, and almost nobody is pricing it in.</span></p><p><span>Every company automating its grunt work is also switching off the machine that produced its own experts. The senior people it leans on, the ones whose judgment everyone trusts, were built by exactly the kind of work the next round of hires will never touch. The on-ramp and the drudgery were one and the same. Automate the drudgery, and you don&#8217;t just lose the busywork. You quietly remove the bottom two rungs of the ladder that turned juniors into the people you can&#8217;t operate without.</span></p><p><span>The entry-level work that used to forge an analyst, the slow reps that built the instinct, is the most automatable work we own. Every efficiency we take, seen from the other side, is a rep we are removing from someone who still needs it. That&#8217;s not an argument against the efficiency. It&#8217;s an argument that the reps now have to be put back on purpose, because the work will no longer install them by accident.</span></p><p><span>So the principle scales without changing shape. The weight worth keeping for a person or an organization is the one that builds the judgment you&#8217;ll need to supervise the machine you&#8217;re handing the work to. For you, that&#8217;s staying sharp enough to catch confident wrongness. For the org, it&#8217;s deliberately manufacturing the reps that used to happen on their own, so that ten years from now, the bottleneck won&#8217;t be the machines. It&#8217;ll be finding anyone who can still do the building. The companies that come through this are the ones treating it like a training program right now, while the old one is still warm, instead of assuming the work will keep forging people the way it always has.</span></p><p><span>Time under tension didn&#8217;t die with the old workflow. The load still builds you, exactly the way it built everyone who came before you. The only thing that changed is that staying under it is now a decision, and most people are making that decision every day without realizing there was one to make.</span></p><p><span>So choose your weights and reps on purpose. The ones who don&#8217;t will never feel the moment they stopped growing. They&#8217;ll glance up one ordinary afternoon and find the work has moved somewhere they can&#8217;t follow. And they&#8217;ve been standing in the same place the whole time it left.</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">THOR Collective Dispatch is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/p/keep-the-tension-that-builds-you/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://dispatch.thorcollective.com/p/keep-the-tension-that-builds-you/comments"><span>Leave a comment</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[AI Has Entered the Villa.]]></title><description><![CDATA[Skill stopped predicting risk this year. Here&#8217;s what that does to your detections and where your playbook quietly breaks.]]></description><link>https://dispatch.thorcollective.com/p/ai-has-entered-the-villa</link><guid isPermaLink="false">https://dispatch.thorcollective.com/p/ai-has-entered-the-villa</guid><dc:creator><![CDATA[Kassandra Murphy]]></dc:creator><pubDate>Tue, 23 Jun 2026 13:03:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-su9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe3c17c5-d08f-4ac4-aa43-9c5c2b852f04_827x500.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">I GOT A TEXT!!! And unlike Love Island, this one actually made me nervous. Anthropic just dropped a</span><a href="https://red.anthropic.com/2026/attack-navigator/"><span> breakdown of 832 accounts they banned for malicious cyber activity</span></a><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);"> in a single year mapping what those actors </span><em><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">actually</span></em><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);"> did with AI onto MITRE ATT&amp;CK. It&#8217;s a real dataset, not a fear pitch, but one number stopped me mid-scroll.</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">THOR Collective Dispatch is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">The share of actors scoring medium-risk or higher on Anthropic&#8217;s enablement scale climbed from roughly 33% to 56% in under a year. A 1.7x jump. The most bothersome part? It happened without the actors getting any more skilled. Technical sophistication was your type on paper; looks great, predicts almost nothing about the actual connection (r = 0.28), as did the breadth of techniques an actor used (r = 0.27). So did which interface they came through. The thing that used to tell you how worried to be, &#8220;Is this a sophisticated adversary?&#8221;, doesn&#8217;t really apply anymore.</span></p><p><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">That&#8217;s the real story and I don&#8217;t say it to be inflammatory. It&#8217;s a tooling problem. The mental model most of us use to triage threats assumes risk tracks skill. When skill stops tracking risk, the model breaks and a lot of our playbooks were built on top of that model.</span></p><p><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">So let&#8217;s start with something productive: mapping your existing detections to what these actors are actually doing (most of it you likely already cover) and then we&#8217;ll talk about the part you don&#8217;t.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-su9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe3c17c5-d08f-4ac4-aa43-9c5c2b852f04_827x500.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-su9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe3c17c5-d08f-4ac4-aa43-9c5c2b852f04_827x500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-su9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe3c17c5-d08f-4ac4-aa43-9c5c2b852f04_827x500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-su9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe3c17c5-d08f-4ac4-aa43-9c5c2b852f04_827x500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-su9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe3c17c5-d08f-4ac4-aa43-9c5c2b852f04_827x500.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-su9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe3c17c5-d08f-4ac4-aa43-9c5c2b852f04_827x500.jpeg" width="827" height="500" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/be3c17c5-d08f-4ac4-aa43-9c5c2b852f04_827x500.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:500,&quot;width&quot;:827,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-su9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe3c17c5-d08f-4ac4-aa43-9c5c2b852f04_827x500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-su9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe3c17c5-d08f-4ac4-aa43-9c5c2b852f04_827x500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-su9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe3c17c5-d08f-4ac4-aa43-9c5c2b852f04_827x500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-su9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe3c17c5-d08f-4ac4-aa43-9c5c2b852f04_827x500.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong><span data-color="rgb(31, 78, 121)" style="color: rgb(31, 78, 121);">What&#8217;s mappable</span></strong></h2><p><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">A web shell is still a web shell. None of these techniques are new. Your existing ATT&amp;CK-aligned detections fire on the artifact and the action regardless of whether a human or a model produced them. The report logged 13,873 observations across 482 sub-techniques within14 tactics, each having a MITRE ID and likely a rule in your library.</span></p><p><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">I&#8217;ve split the coverage into two tiers because that split is the argument. Tier 1 is the high-prevalence preparatory work that dominates the dataset and Tier 2 is the smaller, post-compromise cluster where the highest-risk actors actually start to separate themselves.</span></p><h3><strong><span data-color="rgb(46, 117, 182)" style="color: rgb(46, 117, 182);">Tier 1 &#8212; Preparatory and pre-intrusion</span></strong></h3><p><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">Can you say volume? The single most common technique family was T1587.001 (Malware Development), used by 560 of 832 actors. Most AI-enabled activity today is actors building offensive tooling</span><em><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);"> </span></em><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">before</span><em><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);"> </span></em><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">they engage, then making it harder to detect.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WeTr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F463998a3-2c83-4432-8e47-8bdb04825d9e_1970x550.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WeTr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F463998a3-2c83-4432-8e47-8bdb04825d9e_1970x550.png 424w, https://substackcdn.com/image/fetch/$s_!WeTr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F463998a3-2c83-4432-8e47-8bdb04825d9e_1970x550.png 848w, https://substackcdn.com/image/fetch/$s_!WeTr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F463998a3-2c83-4432-8e47-8bdb04825d9e_1970x550.png 1272w, https://substackcdn.com/image/fetch/$s_!WeTr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F463998a3-2c83-4432-8e47-8bdb04825d9e_1970x550.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WeTr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F463998a3-2c83-4432-8e47-8bdb04825d9e_1970x550.png" width="1456" height="406" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/463998a3-2c83-4432-8e47-8bdb04825d9e_1970x550.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:406,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:196884,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dispatch.thorcollective.com/i/202638049?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F463998a3-2c83-4432-8e47-8bdb04825d9e_1970x550.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WeTr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F463998a3-2c83-4432-8e47-8bdb04825d9e_1970x550.png 424w, https://substackcdn.com/image/fetch/$s_!WeTr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F463998a3-2c83-4432-8e47-8bdb04825d9e_1970x550.png 848w, https://substackcdn.com/image/fetch/$s_!WeTr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F463998a3-2c83-4432-8e47-8bdb04825d9e_1970x550.png 1272w, https://substackcdn.com/image/fetch/$s_!WeTr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F463998a3-2c83-4432-8e47-8bdb04825d9e_1970x550.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">What AI changes in Tier 1:</span></strong><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);"> mostly volume and variety. One actor can now generate dozens of obfuscation variants for the cost of a few prompts, so signature coverage decays faster than it used to. But your behavioral detections hold and so do your runbooks. If you cover this tier well, you&#8217;re in good shape against the majority of the population in the dataset.</span></p><h3><strong><span data-color="rgb(46, 117, 182)" style="color: rgb(46, 117, 182);">Tier 2 &#8212; Post-compromise and hands-on-keyboard (or: After Casa Amor)</span></strong></h3><p><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">This tier is a little rarer; lateral movement showed up in just 0.7% of all observations, but the risk is more concentrated. The 54 actors who used AI for lateral movement averaged a risk score about 10 points above the mean, the strongest single predictor of a high-risk actor in the entire study. The techniques below were three to five times more common among the highest-risk cohort than the general population.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0Wfd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03e0c688-58bb-414c-9f28-45af82a05942_1968x764.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0Wfd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03e0c688-58bb-414c-9f28-45af82a05942_1968x764.png 424w, https://substackcdn.com/image/fetch/$s_!0Wfd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03e0c688-58bb-414c-9f28-45af82a05942_1968x764.png 848w, https://substackcdn.com/image/fetch/$s_!0Wfd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03e0c688-58bb-414c-9f28-45af82a05942_1968x764.png 1272w, https://substackcdn.com/image/fetch/$s_!0Wfd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03e0c688-58bb-414c-9f28-45af82a05942_1968x764.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0Wfd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03e0c688-58bb-414c-9f28-45af82a05942_1968x764.png" width="1456" height="565" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/03e0c688-58bb-414c-9f28-45af82a05942_1968x764.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:565,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:281234,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dispatch.thorcollective.com/i/202638049?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03e0c688-58bb-414c-9f28-45af82a05942_1968x764.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0Wfd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03e0c688-58bb-414c-9f28-45af82a05942_1968x764.png 424w, https://substackcdn.com/image/fetch/$s_!0Wfd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03e0c688-58bb-414c-9f28-45af82a05942_1968x764.png 848w, https://substackcdn.com/image/fetch/$s_!0Wfd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03e0c688-58bb-414c-9f28-45af82a05942_1968x764.png 1272w, https://substackcdn.com/image/fetch/$s_!0Wfd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03e0c688-58bb-414c-9f28-45af82a05942_1968x764.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">Notice the two techniques flagged with year-over-year growth. T1087 and T1020 both presuppose that the actor is already inside the network. The activity that grew over the study window wasn&#8217;t more tool-building, it was actually more in-network work. What that really means to me: the population isn&#8217;t just getting bigger, it&#8217;s actually drifting toward the riskier end of the kill chain.</span></p><p><strong><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">What AI changes in Tier 2:</span></strong><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);"> this is where your runbook&#8217;s hidden assumption breaks. It&#8217;s worth being precise about what breaks, too, because it isn&#8217;t the detections.</span></p><p><strong><span data-color="rgb(31, 78, 121)" style="color: rgb(31, 78, 121);">The cadence is what fails. Now, you&#8217;re sending three home.</span></strong></p><p><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">Can I pull your playbooks for a chat? Every response playbook you&#8217;ve ever written silently assumes a human operator&#8217;s tempo between these steps. Recon takes a while. There&#8217;s dwell time before lateral movement. Discovery, credential access, and the pivot are separate phases with gaps between them. THOSE gaps are what your alert triage, analyst SOPs, and SOAR playbooks were designed around.</span></p><p><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">Now picture those phases collapsed into one uninterrupted sequence, executed at machine speed, by something that doesn&#8217;t get tired, doesn&#8217;t context-switch, doesn&#8217;t wait for a second analyst to confirm before moving, and doesn&#8217;t need to recouple between phases. The individual detections still fire. T1003 fires, T1021 fires, T1087 fires, but they fire concurrently or out of the order your triage expects. Now your mean-time-to-respond is suddenly racing an adversary that doesn&#8217;t need to stand up and stretch their legs.</span></p><p><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">That&#8217;s the honest version of what changes. Not &#8220;AI invents undetectable attacks&#8221; (at least not yet) it&#8217;s that the spacing between known techniques is no longer guaranteed. I want to be careful with that &#8220;yet,&#8221; though. I&#8217;m describing what the dataset shows </span><em><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">today</span></em><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">: known TTPs, executed faster and I genuinely don&#8217;t know if that holds. If a model crosses some capability threshold we haven&#8217;t hit, call it AGI, call it whatever, there&#8217;s no law of nature that says it stays inside the existing technique map or even inside human-plausible speed. The honest position is that I&#8217;m bounding a present-tense problem, not predicting the ceiling.</span></p><h2><strong><span data-color="rgb(31, 78, 121)" style="color: rgb(31, 78, 121);">Soul Ties Is Crazy&#8230;So is Lateral Movement at Machine Speed: Where the map runs out.</span></strong></h2><p><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">Something else the report is very transparent about: you can map every individual action one of these actors takes (Anthropic did exactly that, with 13,873 observations, every one with a MITRE ID) and mapping all of it still doesn&#8217;t capture what made the highest-risk actor in the dataset dangerous.</span></p><p><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">Consider the espionage campaign Anthropic </span><a href="https://www.anthropic.com/news/disrupting-AI-espionage"><span>disrupted in November 2025</span></a><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">, labeled GTG-1002. Maximum possible risk score: 100. Number of techniques: about 30 across 13 tactics which is comparable to plenty of medium-risk actors. The median actor in the whole study used 16 techniques, and some low-risk actors used more than 30. By every metric we normally reach for, things like technique count, tactic breadth, interface, assessed skill, GTG-1002 actually looks like Rob standing at the firepit in his overalls, unremarkable.</span></p><p><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">But what made it the most dangerous actor observed wasn&#8217;t any technique, it was the scaffolding. The actor wired an AI agent into a Kali box with offensive tooling exposed as MCP servers and it wasn&#8217;t asking for advice, it was standing on business; scanning, pivoting, deciding what to probe next all on its own. The AI scanned, found internal services, exploited an SSRF flaw to pivot inward, harvested SSH keys and cloud credentials and moved laterally. All the while it was making its own tactical calls about what to probe next, with the human only stepping in for the consequential decisions.</span></p><p><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">Autonomous chaining of the kill chain. Real-time pivot decisions. AI-directed execution with no human in the loop between steps. None of these has an MITRE ATT&amp;CK ID. There&#8217;s no technique to map a detection to because the dangerous thing isn&#8217;t a technique, it&#8217;s the orchestration between techniques. The taxonomy our entire shared threat vocabulary is built on describes the moves but it essentially has no vocabulary for the player.</span></p><p><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">This is why it can feel unwinnable. You can have perfect coverage of all 482 techniques and still be blind to the one variable that best predicts catastrophic risk because that variable doesn&#8217;t exist in your framework yet.</span></p><p><strong><span data-color="rgb(31, 78, 121)" style="color: rgb(31, 78, 121);">Is all this really unwinnable? Are we defenders doomed? Are we Kordell standing at an empty door?</span></strong></p><p><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">It feels that way some days, and I&#8217;d rather say that out loud than pretend otherwise. But &#8220;unwinnable&#8221; is the wrong frame, IMO.</span></p><p><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">The wrong work is mapping more rules to a frozen taxonomy. If the differentiator has moved to the orchestration layer, adding the 483rd technique mapping doesn&#8217;t help you. The math only changes if your detection thinking moves up a level too:</span></p><ul><li><p><strong><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">Detect tempo, not just technique. </span></strong><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">A sequence of individually-benign-looking actions executing faster than a human plausibly could is itself the signal. Machine-speed sequencing across discovery &#8594; cred access &#8594; lateral movement is a behavioral fingerprint even when each step looks normal in isolation. This is where UEBA and sequence-aware detection come in clutch.</span></p></li><li><p><strong><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">Watch the orchestration interfaces. </span></strong><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">Tool-augmented operations through MCP-style servers and agentic harnesses are a new and observable surface. They don&#8217;t map to MITRE today but they leave traces.</span></p></li><li><p><strong><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">Compress vuln-to-patch. </span></strong><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">If attackers can autonomously find and chain exploitation at speed, your tolerance for known-unpatched systems has to drop accordingly. The transitional period rewards whoever shrinks that window fastest.</span></p></li><li><p><strong><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">Push on the framework. </span></strong><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">Anthropic is in active conversations with MITRE about adding cross-cutting categories for agentic, autonomous, decision-making behaviors. That vocabulary is coming. The teams that have already started detecting at the behavioral layer will adopt it fastest.</span></p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!y6su!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd334a7-8638-4e0f-b4d4-c1dde5b12447_500x631.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!y6su!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd334a7-8638-4e0f-b4d4-c1dde5b12447_500x631.jpeg 424w, https://substackcdn.com/image/fetch/$s_!y6su!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd334a7-8638-4e0f-b4d4-c1dde5b12447_500x631.jpeg 848w, https://substackcdn.com/image/fetch/$s_!y6su!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd334a7-8638-4e0f-b4d4-c1dde5b12447_500x631.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!y6su!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd334a7-8638-4e0f-b4d4-c1dde5b12447_500x631.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!y6su!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd334a7-8638-4e0f-b4d4-c1dde5b12447_500x631.jpeg" width="500" height="631" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bdd334a7-8638-4e0f-b4d4-c1dde5b12447_500x631.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:631,&quot;width&quot;:500,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!y6su!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd334a7-8638-4e0f-b4d4-c1dde5b12447_500x631.jpeg 424w, https://substackcdn.com/image/fetch/$s_!y6su!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd334a7-8638-4e0f-b4d4-c1dde5b12447_500x631.jpeg 848w, https://substackcdn.com/image/fetch/$s_!y6su!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd334a7-8638-4e0f-b4d4-c1dde5b12447_500x631.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!y6su!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd334a7-8638-4e0f-b4d4-c1dde5b12447_500x631.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">Now, I also have to mention that there&#8217;s a genuinely defensible reason for optimism about this new bombshell. The same capabilities that let a low-skill actor command an expert-level harness also let defenders find bugs before code ships, triage at machine speed, and close the patch gap. The asymmetry that&#8217;s hurting us right now isn&#8217;t permanent, it&#8217;s a function of attackers adopting the tooling faster than defenders have and that gap is one we control.</span></p><p><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">But I want to keep the same honesty I used a few paragraphs up. That optimism is scoped to the problem I&#8217;ve actually described: known techniques, executed faster by a population drifting up the kill chain. It&#8217;s a real edge against a real, present-tense threat and we should take it. What it isn&#8217;t is a guarantee about the thing I admitted I can&#8217;t see. If capability jumps somewhere we&#8217;re not expecting, &#8220;defenders have the same tools&#8221; stops being reassurance, because both sides would be improvising against a map that no longer describes the territory. I&#8217;d rather hand you a defensible reason for optimism about today than a fragile promise about a future none of us can map yet.</span></p><p><span data-color="rgb(26, 26, 26)" style="color: rgb(26, 26, 26);">So here&#8217;s where I land. The battle isn&#8217;t unwinnable but the old way of fighting it is. Map your detections to the techniques (yes, genuinely, all of them, it&#8217;s worth doing), then accept that the map ends where the orchestration begins, and start building for the territory past the edge. And hold that posture loosely, because the edge moves. The teams that win the next few years won&#8217;t be the ones with the most complete rule library; they&#8217;ll be the ones who stayed honest about what their map couldn&#8217;t see yet, and built the muscle to notice when it changed.</span></p><p><em><span data-color="rgb(90, 90, 90)" style="color: rgb(90, 90, 90);">Source: Anthropic, </span><a href="https://red.anthropic.com/2026/attack-navigator/"><span>&#8220;Mapping AI-enabled cyber threats: Insights from the LLM ATT&amp;CK Navigator,&#8221;</span></a><span data-color="rgb(90, 90, 90)" style="color: rgb(90, 90, 90);"> June 2026</span></em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">THOR Collective Dispatch is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Ask-a-Thrunt3r: May 2026 — Ask Me About the War of 1812 🐏]]></title><description><![CDATA[&#128221; Episode Summary]]></description><link>https://dispatch.thorcollective.com/p/ask-a-thrunt3r-may-2026-ask-me-about</link><guid isPermaLink="false">https://dispatch.thorcollective.com/p/ask-a-thrunt3r-may-2026-ask-me-about</guid><dc:creator><![CDATA[Lauren Proehl]]></dc:creator><pubDate>Tue, 16 Jun 2026 15:03:09 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/202240344/57a54a73c772158015b789fd41a3457d.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<h3>&#128221; Episode Summary</h3><p>We took a detour this month. No thrunting, no hunt repos, just a long honest look at social engineering in the age of AI, with the person who scares Lauren the most in the entire SE community: <strong>Matt Bangert (aka @bngrsec)</strong>, DEF CON 30 black badge winner and the guy whose AI bots now do his social engineering for him. If you have spent a decade training users to spot bad grammar, robotic voices, and the Nigerian prince in your inbox, this is the episode that tells you those red flags are already gone.</p><p>The throughline is uncomfortable and simple: the cost of a convincing lure has cratered. Matt walks through the actual math, roughly 500 vishing calls for a hundred bucks, no doomer hand-waving required, and you only need one person to pick up. The old tells are dead, the perfect phish is here, and the gut check (&#8221;am I actually expecting this, and what is being asked of me right now?&#8221;) is most of what users have left. We get into device code phishing as an initial access path, why the help desk is the single highest-value vector going (ask Scattered Spider), and the part that genuinely kept Lauren up that night: attackers turning your own AI against you. Matt&#8217;s go-to move after initial access is opening Copilot and asking it to find the passwords in SharePoint. It works. One of his engagements turned up a password hidden as white text in a spreadsheet, invisible to a human eye, trivially readable to a machine.</p><p>But this is THOR Collective, so the answer is not &#8220;we are all going to die&#8221; (even if Matt says it twice). The defenses that actually hold are boring and process-driven: callback and manager verification, out-of-band notification for any sensitive help desk event, and real defense in depth that does not put the entire load on a tired human at 2 AM. Sydney brings the defensive read throughout, Lauren brings the CISO-adjacent reality of user fatigue and finite resources, and we close with a lightning round and a running joke about the War of 1812 that may or may not become your team&#8217;s new safe word. Stick around for the credits. There is a surprise.</p><h3>&#9201;&#65039; Episode Breakdown</h3><ul><li><p>00:23 &#8211; Intro and the May detour into social engineering</p></li><li><p>02:39 &#8211; Guest intro: Matt Bangert, and the Plenty of Fish AI bot research</p></li><li><p>07:21 &#8211; What AI is doing to social engineering, and the new economics of a lure</p></li><li><p>13:08 &#8211; Battle of the Bots, and how defenders actually respond</p></li><li><p>15:49 &#8211; Phishing at scale, device code abuse, and the help desk problem</p></li><li><p>24:57 &#8211; Turning their own AI against them: Copilot abuse and the persistent insider</p></li><li><p>33:56 &#8211; &#9889; Lightning Round</p></li><li><p>40:14 &#8211; Closing, DEF CON plans, and a credits Easter egg</p></li></ul><h3>&#127908; Hosts &amp; Guest</h3><p><strong>Lauren Proehl (Host)</strong> &#8212; Manager of the group, cautious AI optimist, and the one steering this conversation toward the parts that should actually scare you. </p><p><strong>Sydney Marrone (Host)</strong> &#8212; Now officially a manager too (the elder thrunter holds the belt). Co-founder, builder of ATHF and HEARTH, and the defensive voice keeping this episode grounded in what teams can actually do.</p><p><strong>Matt Bangert / @bngrsec (Guest)</strong> &#8212; DEF CON 30 black badge winner as part of team Spilt Beans in the Social Engineering CTF, nine-ish years deep in offensive security since his OSCP, and now hands his social engineering off to AI agents. Took first in the Social Engineering Community&#8217;s Battle of the Bots vishing competition. Currently between affiliations. Catch him at DEF CON this year running the GIFs during the live vishing calls at the Social Engineering Community Village (yes, he is taking your not-safe-for-work suggestions).</p><ul><li><p>X: <a href="https://x.com/bngrsec">@bngrsec</a></p></li><li><p>LinkedIn: <a href="https://www.linkedin.com/in/mattbangert1/">mattbangert1</a></p></li></ul><h3>&#128279; Resources &amp; Mentions</h3><h4>On the Dispatch</h4><ul><li><p><strong><a href="https://dispatch.thorcollective.com/p/ask-a-thrunt3r-april-2026-signal">Ask-a-Thrunt3r: April 2026 &#8212; Signal vs Myth</a></strong> &#8212; last month&#8217;s episode, cutting through the Mythos hype with Trent Lo. Catch up if you missed it.</p></li></ul><h4>Featured in This Episode</h4><ul><li><p><strong><a href="https://www.youtube.com/watch?v=NhMpw3eaM_w">Matt&#8217;s SecKC Talk on AI Bots and Dating App Honeypots</a></strong> &#8212; Matt and Snow&#8217;s research using AI agents to detect bots and scammers on Plenty of Fish, presented at SecKC in March</p></li><li><p><strong><a href="https://www.se.community/">Social Engineering Community Village</a></strong> &#8212; the DEF CON village where Matt volunteers, led by Snow. Home of the vishing competition and Battle of the Bots.</p></li><li><p><strong>Battle of the Bots (Vishing Edition)</strong> &#8212; the autonomous AI vishing competition that debuted at DEF CON 33. Five teams build agents that call companies and extract flags, fully hands-off. Returning this year.</p></li></ul><h3>&#128226; Call to Action</h3><ul><li><p><strong>Audit your help desk</strong> &#8212; map your own verification flow before an attacker does it for you, and add out-of-band manager notification for MFA, phone, and password changes</p></li><li><p><strong>Stop training users on grammar and spelling</strong> &#8212; the perfect phish is here; shift to &#8220;am I expecting this, and what is being asked of me right now?&#8221;</p></li><li><p><strong>Look at what your own AI can reach</strong> &#8212; if a Copilot or assistant has a license in your environment, find out what it will hand over before someone else does</p></li><li><p><strong>Pick a safe word</strong> &#8212; yes, really, ask people about the War of 1812</p></li><li><p><strong>Come find Matt at DEF CON</strong> &#8212; Social Engineering Community Village, running the GIFs during the live vishing calls</p></li><li><p><strong>Catch us at the <a href="https://www.antisyphontraining.com/event/threat-hunting-summit/">Antisyphon Threat Hunting Summit</a></strong> &#8212; virtual and free, June 17, 2026, the day after this drops:</p><ul><li><p>Sydney: <em><a href="https://www.antisyphontraining.com/event/threat-hunting-summit-talk-avoiding-hunt-amnesia-building-a-memory-your-ai-can-use/">Avoiding Hunt Amnesia: Building a Memory Your AI Can Use</a></em> &#8212; 12:00 PM ET</p></li><li><p>Lauren: <em><a href="https://www.antisyphontraining.com/event/threat-hunting-summit-talk-fast-track-reports-into-ready-made-hypotheses-with-ai/">Fast-track Reports into Ready-Made Hypotheses with AI</a></em> &#8212; 3:00 PM ET</p></li></ul></li><li><p><strong>Write for THOR Collective</strong> &#8212; first-time publishers, up-and-coming voices, builders with something to share: come find us</p></li></ul><h3>&#128236; Connect with THOR Collective</h3><h4>&#128483;&#65039; Social Media</h4><ul><li><p>Twitter/X: <a href="https://x.com/THOR_Collective">@THOR_Collective</a></p></li><li><p>LinkedIn: <a href="https://www.linkedin.com/company/thorcollective">THOR Collective</a></p></li><li><p>BlueSky: <a href="https://bsky.app/profile/thorcollective.bsky.social">@thorcollective</a></p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QK_j!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2d1893b-b831-4ff9-97a2-df19d8880276_1024x962.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QK_j!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2d1893b-b831-4ff9-97a2-df19d8880276_1024x962.png 424w, https://substackcdn.com/image/fetch/$s_!QK_j!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2d1893b-b831-4ff9-97a2-df19d8880276_1024x962.png 848w, https://substackcdn.com/image/fetch/$s_!QK_j!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2d1893b-b831-4ff9-97a2-df19d8880276_1024x962.png 1272w, https://substackcdn.com/image/fetch/$s_!QK_j!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2d1893b-b831-4ff9-97a2-df19d8880276_1024x962.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QK_j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2d1893b-b831-4ff9-97a2-df19d8880276_1024x962.png" width="1024" height="962" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a2d1893b-b831-4ff9-97a2-df19d8880276_1024x962.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:962,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:403496,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dispatch.thorcollective.com/i/202240344?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2d1893b-b831-4ff9-97a2-df19d8880276_1024x962.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QK_j!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2d1893b-b831-4ff9-97a2-df19d8880276_1024x962.png 424w, https://substackcdn.com/image/fetch/$s_!QK_j!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2d1893b-b831-4ff9-97a2-df19d8880276_1024x962.png 848w, https://substackcdn.com/image/fetch/$s_!QK_j!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2d1893b-b831-4ff9-97a2-df19d8880276_1024x962.png 1272w, https://substackcdn.com/image/fetch/$s_!QK_j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2d1893b-b831-4ff9-97a2-df19d8880276_1024x962.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4>&#128231; Contact</h4><p>Reach out through any social channel for guest post opportunities, collaborations, or to tell us what you&#8217;re building.</p>]]></content:encoded></item><item><title><![CDATA[You’ve Got This: Just Hit Submit on That Brilliant Idea]]></title><description><![CDATA[The Problem We&#8217;re Not Pretending Isn&#8217;t There]]></description><link>https://dispatch.thorcollective.com/p/youve-got-this-just-hit-submit-on</link><guid isPermaLink="false">https://dispatch.thorcollective.com/p/youve-got-this-just-hit-submit-on</guid><dc:creator><![CDATA[Sydney Marrone]]></dc:creator><pubDate>Tue, 02 Jun 2026 15:01:48 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!bht-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddbba46c-7114-48dd-8e0c-8f6f940acea3_760x500.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>You don&#8217;t need permission to teach the thing you know. You need a scope, a plan, and the courage to hit submit.</p><p>You&#8217;ve had the idea. Maybe for a while now.</p><p>You&#8217;ve thought about it, talked yourself out of it, told yourself next year, or decided that someone more qualified should be the one to do it.</p><p>They shouldn&#8217;t. You should.</p><p>This post exists because the gap between knowing something and believing you&#8217;re allowed to teach it is real, and it stops good proposals from ever getting written. We want to help you write yours.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bht-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddbba46c-7114-48dd-8e0c-8f6f940acea3_760x500.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bht-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddbba46c-7114-48dd-8e0c-8f6f940acea3_760x500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!bht-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddbba46c-7114-48dd-8e0c-8f6f940acea3_760x500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!bht-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddbba46c-7114-48dd-8e0c-8f6f940acea3_760x500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!bht-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddbba46c-7114-48dd-8e0c-8f6f940acea3_760x500.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bht-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddbba46c-7114-48dd-8e0c-8f6f940acea3_760x500.jpeg" width="760" height="500" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ddbba46c-7114-48dd-8e0c-8f6f940acea3_760x500.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:500,&quot;width&quot;:760,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!bht-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddbba46c-7114-48dd-8e0c-8f6f940acea3_760x500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!bht-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddbba46c-7114-48dd-8e0c-8f6f940acea3_760x500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!bht-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddbba46c-7114-48dd-8e0c-8f6f940acea3_760x500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!bht-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddbba46c-7114-48dd-8e0c-8f6f940acea3_760x500.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">THOR Collective Dispatch is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>The Imposter Syndrome Trap Is a Specific Lie</h2><p>The thought sounds like: &#8220;Someone else knows this better than I do. Someone more qualified should be the one teaching it.&#8221;</p><p>Here&#8217;s what makes that thought dangerous: it&#8217;s technically unfalsifiable and practically infinite. There will always be someone who has been doing this longer. That doesn&#8217;t make your knowledge less real or less useful. It just means you have more to learn, same as everyone in the room, including the person you think is more qualified.</p><p>The bar for teaching a workshop is not &#8220;know everything.&#8221; The bar is &#8220;know enough more than your attendees to take them somewhere they couldn&#8217;t get to on their own.&#8221; That bar is almost certainly lower than imposter syndrome is telling you it is.</p><p>A simple test: think about the last time a colleague asked you to explain something. Think about the workaround you figured out that nobody else on your team knew existed. Think about the presentation where you thought &#8220;they skipped the part that actually matters.&#8221;</p><p>That&#8217;s your workshop.</p><p>Some of the best workshops start as &#8220;here&#8217;s the weird thing I had to figure out at work.&#8221;</p><p>That moment of &#8220;wait, I actually know this&#8221; is the seed of a proposal.</p><p>If you&#8217;re still not sure, ask three people in your network what they&#8217;d most want to learn from you. The answers will probably surprise you.</p><h2>How to Scope a Workshop Topic</h2><p>Most proposals collapse at this step, not because the idea is bad, but because it&#8217;s too wide.</p><p>The talk version of your idea tries to cover everything. The workshop version picks one thing and goes deep.</p><p>A talk might be &#8220;Introduction to Memory Forensics.&#8221; A workshop is &#8220;Analyzing LSASS Dumps to Identify Credential Theft: A Hands-On Lab.&#8221; See the difference? The workshop has a specific destination. Attendees know exactly what they&#8217;re walking out able to do.</p><p>Scoping test:</p><ul><li><p>Write down what you want attendees to be able to do by the end. Not &#8220;understand X,&#8221; do Y.</p></li><li><p>Draw a box around it. Smaller than you think. Now smaller again.</p></li><li><p>Ask: can someone complete this in 90 minutes to three hours with a laptop and a pre-built environment?</p></li><li><p>If yes, you have a workshop scope. If no, cut it.</p></li></ul><p>Tight scope delivered well beats ambitious scope delivered poorly every time. Attendees leave a focused workshop feeling like they actually got something. They leave an over-scoped one feeling like they missed most of it, and they&#8217;ll be right.</p><p>The other scope question is logistics. Does your attendee need a VM? A cloud sandbox? A pre-loaded dataset? A browser? Nothing? Work that out early. A lab environment that 40% of the room can&#8217;t access will derail an otherwise excellent workshop faster than anything.</p><h2>The Format Is More Forgiving Than It Looks</h2><p>The proposal is not a thesis defense.</p><p>You need to describe the topic, the target skill level, what attendees will leave able to do, and what environment or materials they&#8217;ll need. That&#8217;s it. Reviewers are looking for clarity of intent, not polish.</p><p>What is this workshop?<br>Who is it for?<br>Will people walk out with a concrete skill or artifact?</p><p>If you can answer those three questions in plain sentences, you can write a proposal.</p><p>You also don&#8217;t need a fully built-out lab to submit. You need a plan. The lab gets built after acceptance. The proposal is the idea.</p><p>And nerves are normal. They don&#8217;t go away with preparation, but preparation changes what they feel like. Instead of &#8220;I don&#8217;t know if I can do this,&#8221; they become &#8220;I really want this to land.&#8221; That is a useful kind of nervous.</p><p>The first five minutes on stage are the hardest. After that, once the first question comes in and someone runs the first command and gets a result, it stops being a performance and starts being a conversation. That&#8217;s when the room becomes yours.</p><p>The audience wants you to succeed. They chose your workshop over every other option in the schedule. They showed up because they already believe what you&#8217;re offering is worth their time.</p><h2>The Community Is Better When More of Us Teach</h2><p>When the people teaching are a narrow slice of the people doing the work, the content reflects that. Knowledge that lives in different parts of the community, different environments, different tooling constraints, different perspectives, doesn&#8217;t make it into workshops because the people who could teach it never submit.</p><p>That&#8217;s a loss for everyone in the room.</p><p>The downside of submitting and not getting accepted is a rejection email.</p><p>The downside of not submitting is that your workshop doesn&#8217;t exist, and neither does the community that would have formed around it.</p><h2>Before You Close This Tab</h2><p>Open the CFP. Not to submit today. Just to open it.</p><p>Quick-start checklist:</p><ul><li><p>Name the thing you&#8217;d most want to teach. One topic, two sentences.</p></li><li><p>Identify the specific skill attendees will leave with. Not &#8220;they&#8217;ll understand X,&#8221; &#8220;they&#8217;ll be able to do Y.&#8221;</p></li><li><p>Write down what environment they&#8217;ll need (VM, browser, dataset, nothing).</p></li><li><p>Draft a title. It doesn&#8217;t have to be good. It has to exist.</p></li><li><p>Open the CFP form and put your two sentences in it.</p></li></ul><p>That&#8217;s the first step. Everything else you can figure out after you&#8217;ve decided to do it.</p><p>Your idea deserves a room. Give it one.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QhP2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde1a7add-c3e2-402a-a7c9-02595b901eab_513x500.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QhP2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde1a7add-c3e2-402a-a7c9-02595b901eab_513x500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!QhP2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde1a7add-c3e2-402a-a7c9-02595b901eab_513x500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!QhP2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde1a7add-c3e2-402a-a7c9-02595b901eab_513x500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!QhP2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde1a7add-c3e2-402a-a7c9-02595b901eab_513x500.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QhP2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde1a7add-c3e2-402a-a7c9-02595b901eab_513x500.jpeg" width="513" height="500" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/de1a7add-c3e2-402a-a7c9-02595b901eab_513x500.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:500,&quot;width&quot;:513,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QhP2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde1a7add-c3e2-402a-a7c9-02595b901eab_513x500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!QhP2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde1a7add-c3e2-402a-a7c9-02595b901eab_513x500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!QhP2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde1a7add-c3e2-402a-a7c9-02595b901eab_513x500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!QhP2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde1a7add-c3e2-402a-a7c9-02595b901eab_513x500.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>And if you happen to be looking for a place to start, <a href="https://deathcon.io/cfp.html">DEATHCon&#8217;s CFP</a> is currently open.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">THOR Collective Dispatch is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Ask-a-Thrunt3r: April 2026 — Signal vs Myth 🐏]]></title><description><![CDATA[&#128221; Episode Summary]]></description><link>https://dispatch.thorcollective.com/p/ask-a-thrunt3r-april-2026-signal</link><guid isPermaLink="false">https://dispatch.thorcollective.com/p/ask-a-thrunt3r-april-2026-signal</guid><dc:creator><![CDATA[Lauren Proehl]]></dc:creator><pubDate>Tue, 12 May 2026 17:45:40 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/197379176/1f92b0f6d073f77d8065af52e486674e.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<h3>&#128221; Episode Summary</h3><p>Mythos pulled us out of sabbatical. After a few months heads-down on conferences, work, and shipping, the THOR Collective is back with a special episode dedicated to cutting through the Mythos hype cycle. Lauren and Sydney are joined by <strong>Trent Lo (aka Surbo)</strong>, Principal Security Researcher at Marsh and longtime adversary-in-chief from the CenturyLink days. Trent lives on both sides of the fence &#8212; offense and defense &#8212; which makes him exactly the right person to help us answer the question the whole industry has been screaming about since Anthropic&#8217;s announcement: is this real, or is this marketing?</p><p>The crew walks through what Mythos and Glasswing actually were (versus the cyber-nuclear-war headlines), where AI genuinely changes the game for attackers, and where defenders still hold the line. The throughline: behaviors still win. AI changes tempo, not fundamentals. There is still a human pointing the tool, and that intent &#8212; not the model &#8212; is what matters. Trent&#8217;s take is measured, grounded, and refreshingly free of doom: nation-states already have this capability and have for a while, the have-and-have-nots gap is going to widen, and the smartest move right now is to get your patching program in order before the wave of AI-found vulnerabilities crests.</p><p>Sydney walks through three new HEARTH features &#8212; <em>What Can I Hunt</em>, the Coverage Map, and the Context Graph &#8212; and recaps ATHF for anyone who missed her SANS AI Summit talk. Lauren teases her Vercel/Context.ai infostealer-to-SaaS hunt guide. Then the conversation pivots to defense at machine scale: how the well-resourced orgs should be thinking, what the under-resourced shops can actually do with Gemma 4 running locally and Copilot bundled in their E5 license, and why vulnerability programs are about to become the most important muscle on the team. We close with a Myth or Signal rapid round (AI SOC replacing analysts? threat hunting copilots? baselining? autonomous pentest? AI-generated malware?) and conference plans for the rest of the year.</p><h3>&#9201;&#65039; Episode Breakdown</h3><ul><li><p>00:23 &#8211; Intro and welcome back from sabbatical</p></li><li><p>02:06 &#8211; Guest intro: Trent Lo (Surbo), Principal Security Researcher at Marsh</p></li><li><p>04:24 &#8211; THOR updates: new HEARTH features and ATHF recap</p></li><li><p>07:41 &#8211; April Dispatch posts: Vercel infostealer-to-SaaS hunt + Mythos Won&#8217;t Kill Threat Hunting</p></li><li><p>10:17 &#8211; What Mythos and Glasswing actually were vs. the marketing hype</p></li><li><p>15:37 &#8211; Where humans still win: judgment, intent, and what &#8220;agentic&#8221; really means</p></li><li><p>21:43 &#8211; What actually worries us about Mythos (hint: it&#8217;s the keyboard, not the model)</p></li><li><p>25:14 &#8211; Defense in the open and the widening have-and-have-nots gap</p></li><li><p>27:52 &#8211; Closed source vs. open source post-Mythos, and the CVE explosion problem</p></li><li><p>34:25 &#8211; How defenders can actually use AI: imposter syndrome, IR, and machine-scale hunting</p></li><li><p>39:56 &#8211; Defense at machine scale: resourced vs. under-resourced playbooks</p></li><li><p>46:46 &#8211; What a two-person team should prioritize (spoiler: patch your shit)</p></li><li><p>51:13 &#8211; &#9889; Myth or Signal rapid round</p></li><li><p>53:41 &#8211; Plugs, conferences, and Allbirds becoming an AI company</p></li><li><p>56:32 &#8211; Happy thrunting</p></li></ul><h3>&#127908; Hosts &amp; Guest</h3><p><strong>Lauren Proehl (Host)</strong> &#8212; Manager of the group, cautious optimist, and the person who still has receipts on Trent from CenturyLink days.</p><p><strong>Sydney Marrone (Host)</strong> &#8212; Now officially a manager (welcome to the dark side). Built ATHF, shipped three new HEARTH features this cycle, and is the reason 90% of you have a starting point for agentic threat hunting.</p><p><strong>Trent Lo / Surbo (Guest)</strong> &#8212; Principal Security Researcher at Marsh. Self-described professional hand grenade thrower who also jumps on the grenades. </p><ul><li><p>LinkedIn: <a href="https://www.linkedin.com/in/trentlo/">trentlo</a></p></li><li><p>X: <a href="https://x.com/surbo">@surbo</a></p></li></ul><h3>&#128279; Resources &amp; Mentions</h3><h4>April Dispatch Posts</h4><ul><li><p><strong><a href="https://dispatch.thorcollective.com/p/mythos-wont-kill-threat-hunting">Mythos Won&#8217;t Kill Threat Hunting. It&#8217;ll Prove We Were Right.</a></strong> by Lauren Proehl &amp; Sydney Marrone &#8212; the editorial thesis driving this episode</p></li><li><p><strong><a href="https://dispatch.thorcollective.com/p/hunting-the-infostealer-to-saas-pipeline">Hunting the Infostealer-to-SaaS Pipeline</a></strong> by Lauren Proehl &#8212; practitioner hunt guide on OAuth abuse and lateral movement via over-permissioned SaaS apps, using the Vercel/Context.ai breach as a case study</p></li></ul><h4>Mythos &amp; Glasswing &#8212; Primary Sources</h4><ul><li><p><strong><a href="https://red.anthropic.com/2026/mythos-preview/">Claude Mythos Preview</a></strong> &#8212; Anthropic&#8217;s technical writeup of the model&#8217;s vulnerability discovery capabilities</p></li><li><p><strong><a href="https://www.anthropic.com/project/glasswing">Project Glasswing</a></strong> &#8212; the coordinated disclosure consortium (AWS, Cisco, Google, and others)</p></li><li><p><strong><a href="https://www.schneier.com/blog/archives/2026/04/on-anthropics-mythos-preview-and-project-glasswing.html">Bruce Schneier: On Mythos Preview and Project Glasswing</a></strong> &#8212; a healthy counterweight to the breathless coverage</p></li></ul><h4>THOR Collective Tools &amp; Frameworks</h4><ul><li><p><strong><a href="https://hearth.thorcollective.com/">HEARTH</a></strong> &#8212; the community hypothesis library. Three new features: <em>What Can I Hunt</em> (pick your data sources, get matched hypotheses), <em>Coverage Map</em> (HEARTH hypotheses linked to MITRE ATT&amp;CK), and <em>Context Graph</em> (adds threat actors and campaigns to the coverage map to surface gaps). <a href="https://github.com/THORCollective/HEARTH">Source on GitHub</a>.</p></li><li><p><strong><a href="https://github.com/Nebulock-Inc/agentic-threat-hunting-framework">ATHF (Agentic Threat Hunting Framework)</a></strong> &#8212; Sydney&#8217;s open-source framework. Maturity model from manual to multi-agent, LOCK pattern, MCP server, AI assistant. Drop it into Cursor or Claude Code. Watch <a href="https://www.sans.org/cyber-security-training-events/ai-summit-2026">Sydney&#8217;s SANS AI Summit talk </a><em><a href="https://www.sans.org/cyber-security-training-events/ai-summit-2026">&#8220;Designing AI-Assisted Threat Hunting That Remembers&#8221;</a></em> for the walkthrough.</p></li></ul><h4>Other Mentions</h4><ul><li><p><strong><a href="https://aisle.com/">AISLE</a></strong> &#8212; the autonomous vulnerability research team that found <a href="https://aisle.com/blog/aisle-discovered-12-out-of-12-openssl-vulnerabilities">12 of 12 OpenSSL CVEs</a> in January (covered in our January episode), and <a href="https://aisle.com/blog/aisle-uncovered-5-of-7-openssl-vulnerabilities-in-the-april-2026-release">5 of 7 in the April release</a>. Their post-Mythos analysis, <em><a href="https://aisle.com/blog/ai-cybersecurity-after-mythos-the-jagged-frontier">AI Cybersecurity After Mythos: The Jagged Frontier</a></em>, is directly relevant to Trent&#8217;s point about another company quietly doing this work for less money. Give credit for what AISLE actually did without conflating it with Mythos.</p></li><li><p><strong><a href="https://deepmind.google/models/gemma/gemma-4/">Gemma 4</a></strong> &#8212; Google&#8217;s most capable open model, <a href="https://blog.google/innovation-and-ai/technology/developers-tools/gemma-4/">released April 2 under Apache 2.0</a>. Lauren is running it locally. Trent&#8217;s tip: jumpstart prompts here before burning real API tokens.</p></li><li><p><strong><a href="https://techcrunch.com/2026/04/15/after-sale-of-its-shoe-business-allbirds-pivots-to-ai/">Allbirds &#8594; NewBird AI</a></strong> &#8212; yes, the shoe company. Sold its footwear assets for $39M and pivoted to GPU-as-a-Service. We&#8217;re as confused as you are.</p></li></ul><h3>&#128226; Call to Action</h3><ul><li><p><strong>Read the April Mythos post</strong> &#8212; and pass it to anyone in your org panicking about cyber-nuclear war</p></li><li><p><strong>Check out the new HEARTH features</strong> at <a href="https://hearth.thorcollective.com/">hearth.thorcollective.com</a> &#8212; start with <em>What Can I Hunt</em></p></li><li><p><strong><a href="https://github.com/Nebulock-Inc/agentic-threat-hunting-framework">Fork ATHF on GitHub</a></strong> &#8212; start at Level 1 (one hunt in LOCK format) and grow from there</p></li><li><p><strong>Fix your patching program</strong> &#8212; the most boring, most important investment you&#8217;ll make this year</p></li><li><p><strong><a href="https://deepmind.google/models/gemma/gemma-4/">Run Gemma 4 locally</a></strong> &#8212; get your reps in before you burn real API tokens</p></li><li><p><strong>Catch us on the conference circuit:</strong></p><ul><li><p>Lauren at the CrowdTour in New York</p></li><li><p>Trent at NCFTA Pittsburgh and Zenith</p></li><li><p><strong><a href="https://www.antisyphontraining.com/event/threat-hunting-summit/">Antisyphon Threat Hunting Summit</a></strong> &#8212; virtual and free, June 17, 2026</p><ul><li><p>Sydney: <em><a href="https://www.antisyphontraining.com/event/threat-hunting-summit-talk-avoiding-hunt-amnesia-building-a-memory-your-ai-can-use/">Avoiding Hunt Amnesia: Building a Memory Your AI Can Use</a></em> &#8212; 12:00 PM ET</p></li><li><p>Lauren: <em><a href="https://www.antisyphontraining.com/event/threat-hunting-summit-talk-fast-track-reports-into-ready-made-hypotheses-with-ai/">Fast-track Reports into Ready-Made Hypotheses with AI</a></em> &#8212; 3:00 PM ET</p></li></ul></li><li><p>Everyone at Black Hat and DEF CON</p></li></ul></li><li><p><strong>Write for THOR Collective</strong> &#8212; first-time publishers, up-and-coming voices, builders with something to share: come find us</p></li></ul><h3>&#128236; Connect with THOR Collective</h3><h4>&#128483;&#65039; Social Media</h4><ul><li><p>Twitter/X: <a href="https://x.com/THOR_Collective">@THOR_Collective</a></p></li><li><p>LinkedIn: <a href="https://www.linkedin.com/company/thorcollective">THOR Collective</a></p></li><li><p>BlueSky: <a href="https://bsky.app/profile/thorcollective.bsky.social">@thorcollective</a></p></li></ul><h4>&#128231; Contact</h4><p>Reach out through any social channel for guest post opportunities, collaborations, or to tell us what you&#8217;re building.</p>]]></content:encoded></item><item><title><![CDATA[Hunting the Infostealer-to-SaaS Pipeline: When Third-Party Trust Becomes Lateral Movement]]></title><description><![CDATA[Your vendors have OAuth tokens to your environment. Do you know who else does?]]></description><link>https://dispatch.thorcollective.com/p/hunting-the-infostealer-to-saas-pipeline</link><guid isPermaLink="false">https://dispatch.thorcollective.com/p/hunting-the-infostealer-to-saas-pipeline</guid><dc:creator><![CDATA[Lauren Proehl]]></dc:creator><pubDate>Tue, 28 Apr 2026 15:29:04 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!FiuY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1819bfe3-9ee0-44a5-a794-0530a9d200a1_2506x1664.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FiuY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1819bfe3-9ee0-44a5-a794-0530a9d200a1_2506x1664.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FiuY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1819bfe3-9ee0-44a5-a794-0530a9d200a1_2506x1664.png 424w, https://substackcdn.com/image/fetch/$s_!FiuY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1819bfe3-9ee0-44a5-a794-0530a9d200a1_2506x1664.png 848w, https://substackcdn.com/image/fetch/$s_!FiuY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1819bfe3-9ee0-44a5-a794-0530a9d200a1_2506x1664.png 1272w, https://substackcdn.com/image/fetch/$s_!FiuY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1819bfe3-9ee0-44a5-a794-0530a9d200a1_2506x1664.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FiuY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1819bfe3-9ee0-44a5-a794-0530a9d200a1_2506x1664.png" width="1456" height="967" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1819bfe3-9ee0-44a5-a794-0530a9d200a1_2506x1664.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:967,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:8900948,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://dispatch.thorcollective.com/i/195757921?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1819bfe3-9ee0-44a5-a794-0530a9d200a1_2506x1664.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FiuY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1819bfe3-9ee0-44a5-a794-0530a9d200a1_2506x1664.png 424w, https://substackcdn.com/image/fetch/$s_!FiuY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1819bfe3-9ee0-44a5-a794-0530a9d200a1_2506x1664.png 848w, https://substackcdn.com/image/fetch/$s_!FiuY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1819bfe3-9ee0-44a5-a794-0530a9d200a1_2506x1664.png 1272w, https://substackcdn.com/image/fetch/$s_!FiuY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1819bfe3-9ee0-44a5-a794-0530a9d200a1_2506x1664.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h2>The Pattern</h2><p>In April 2026, Vercel disclosed a breach that followed an attack chain worth studying. Not because the techniques were novel, but because the pattern is universal and almost nobody is hunting for it.</p><p>The short version: an infostealer infection on a third-party vendor&#8217;s employee machine harvested OAuth tokens. One of those tokens belonged to a trust relationship between the vendor&#8217;s application and a Vercel employee&#8217;s corporate Google Workspace account. The attacker inherited that access, pivoted into Vercel&#8217;s internal environments, and exfiltrated data. The attacker never phished the Vercel employee, bypassing their MFA, or touching their endpoint.</p><p>The breach wasn&#8217;t about Vercel specifically. It was about a pattern that exists in every organization: employees grant third-party applications OAuth access to corporate identity providers, creating persistent trust relationships that can be weaponized if the third party is compromised. The attacker doesn&#8217;t need to compromise <em>you</em>. They need to compromise anyone you trust.</p><p>This post breaks that pattern into four huntable behaviors. The Vercel/Context.ai incident is used as an illustrative case, but the hunts are designed to detect this pattern regardless of which vendor, which identity provider, or which attacker is involved.</p><div><hr></div><h2>Understanding the Attack Chain</h2><p>The pattern decomposes into four phases. Each phase has distinct observable behaviors that can be hunted independently:</p><p><strong>Phase 1 &#8212; Initial Compromise (Third-Party Endpoint)</strong><br>An employee at a third-party vendor has their endpoint compromised by infostealer malware. The malware harvests credentials, session cookies, and OAuth tokens from the machine. In the Vercel case, this was Lumma Stealer delivered via a trojanized game cheat download on a Context.ai employee&#8217;s machine.</p><p><strong>Phase 2 &#8212; Token Harvesting and Abuse</strong><br>The stolen OAuth tokens include grants that the vendor&#8217;s application holds against <em>your</em> enterprise identity provider. These are legitimate tokens issued through a legitimate consent flow. The only thing illegitimate is who&#8217;s using them. In the Vercel case, Context.ai&#8217;s OAuth app had been granted <code>Allow All</code> permissions on a Vercel employee&#8217;s Google Workspace.</p><p><strong>Phase 3 &#8212; Lateral Movement via Trust Relationship</strong><br>The attacker uses the harvested tokens to authenticate as the trusted third-party application and access your environment. From your identity provider&#8217;s perspective, this looks like a normal API call from an authorized application. In the Vercel case, the attacker used Context.ai&#8217;s token to access the employee&#8217;s Google Workspace, then pivoted into Vercel&#8217;s platform environments.</p><p><strong>Phase 4 &#8212; Objective Completion</strong><br>With access to your environment through the trusted application, the attacker pursues their objective: data exfiltration, secrets harvesting, persistence establishment. In the Vercel case, the attacker enumerated and decrypted environment variables.</p><p>Each phase maps to a hunt below.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/p/hunting-the-infostealer-to-saas-pipeline?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading THOR Collective Dispatch! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/p/hunting-the-infostealer-to-saas-pipeline?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://dispatch.thorcollective.com/p/hunting-the-infostealer-to-saas-pipeline?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p></p><div><hr></div><h2>Hunt 1: Uncontrolled Third-Party OAuth Grants</h2><p><strong>Behavior you&#8217;re hunting</strong>: Employees granting OAuth consent to third-party applications (especially AI and productivity tools) that hold persistent, over-permissioned access to your identity provider.</p><p><strong>Why this matters</strong>: This is the precondition that makes the entire attack chain possible. Without an existing OAuth trust relationship, a compromised third party can&#8217;t pivot into your environment. Every unmanaged OAuth grant is a lateral movement path waiting to be activated.</p><h3>What to Look For</h3><p>The specific indicators are consistent regardless of which identity provider you&#8217;re running:</p><ul><li><p><strong>Over-permissioned scopes</strong>: Applications with broad access like full Drive/OneDrive read-write, full Mail access, directory administration, or blanket <code>Allow All</code> grants. Any scope that gives the application access beyond what its stated function requires.</p></li><li><p><strong>Shadow applications</strong>: Apps that aren&#8217;t on your approved SaaS inventory. Single-user signups are the highest risk. One employee tried a tool, clicked through a consent screen, and created a trust relationship your security team doesn&#8217;t know about.</p></li><li><p><strong>AI and productivity tools</strong>: The explosion of AI-powered SaaS means employees are self-provisioning tools at a rate that outpaces any approval process. These tools typically request broad data access (Drive, email, calendar) to function, creating exactly the kind of over-permissioned grants this pattern exploits.</p></li><li><p><strong>Stale grants</strong>: Applications the employee no longer uses but the OAuth grant persists. The vendor may have been acquired, shut down, or deprioritized security, but the token is still live.</p></li></ul><h3>Google Workspace</h3><p>Navigate to <code>Admin Console &#8594; Security &#8594; API Controls &#8594; Third-party app access</code>. This shows every third-party application with OAuth access across your domain, the scopes granted, and which users consented.</p><p>For audit log hunting, filter OAuth Token events for <code>authorize</code> actions:</p><pre><code><code>Event: authorize
Scope contains: drive OR gmail OR admin.directory OR calendar
Time: Last 180 days
</code></code></pre><p>Prioritize any grant where the scope includes broad permissions and the application isn&#8217;t in your approved inventory.</p><h3>Microsoft Entra ID</h3><p>Navigate to <code>Entra Admin Center &#8594; Enterprise Applications &#8594; All Applications</code>. Review permissions granted, focusing on:</p><ul><li><p>Applications with delegated permissions consented by individual users (not admin-granted)</p></li><li><p><code>Directory.ReadWrite.All</code>, <code>Mail.ReadWrite</code>, <code>Files.ReadWrite.All</code>, or <code>User.ReadWrite.All</code> scopes</p></li><li><p>Service principals with owners who are standard users. This is the service principal ownership abuse vector where compromising a regular user gives the attacker the ability to add credentials to a privileged app registration</p></li></ul><pre><code><code>AuditLogs
| where OperationName == "Consent to application"
| extend AppName = tostring(TargetResources[0].displayName)
| extend Scopes = tostring(TargetResources[0].modifiedProperties[0].newValue)
| extend User = tostring(InitiatedBy.user.userPrincipalName)
| where Scopes has_any ("Directory.ReadWrite", "Mail.ReadWrite", "Files.ReadWrite")
| project TimeGenerated, User, AppName, Scopes
| sort by TimeGenerated desc
</code></code></pre><h3>The Deliverable</h3><p>A complete inventory of third-party OAuth grants with: application name and client ID, scopes granted, consenting users, whether the application is on your approved SaaS inventory, and a risk assessment. Any application that is (a) not approved and (b) holds broad permissions should be reviewed for immediate revocation.</p><h3>Vercel Case Reference</h3><p>The specific indicators from the Vercel breach to check for in your environment:</p><pre><code><code>OAuth Client ID (app):        110671459871-30f1spbu0hptbs60cb4vsmv79i7bbvqj.apps.googleusercontent.com
OAuth Client ID (extension):  110671459871-f3cq3okebd3jcg1lllmroqejdbka8cqq.apps.googleusercontent.com
Chrome Extension ID:          omddlmnhcofjbnbflmjginpjjblphbgk
</code></code></pre><p>Check for these specifically, but the hunt is about finding <em>all</em> uncontrolled grants. These are just today&#8217;s IOCs.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!b9pZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F049c1939-bf94-4831-9566-487295292479_1280x720.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!b9pZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F049c1939-bf94-4831-9566-487295292479_1280x720.jpeg 424w, https://substackcdn.com/image/fetch/$s_!b9pZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F049c1939-bf94-4831-9566-487295292479_1280x720.jpeg 848w, https://substackcdn.com/image/fetch/$s_!b9pZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F049c1939-bf94-4831-9566-487295292479_1280x720.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!b9pZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F049c1939-bf94-4831-9566-487295292479_1280x720.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!b9pZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F049c1939-bf94-4831-9566-487295292479_1280x720.jpeg" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/049c1939-bf94-4831-9566-487295292479_1280x720.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Reginald Skulinski Eating / Disappointed (Monster House) | Know Your Meme&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Reginald Skulinski Eating / Disappointed (Monster House) | Know Your Meme" title="Reginald Skulinski Eating / Disappointed (Monster House) | Know Your Meme" srcset="https://substackcdn.com/image/fetch/$s_!b9pZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F049c1939-bf94-4831-9566-487295292479_1280x720.jpeg 424w, https://substackcdn.com/image/fetch/$s_!b9pZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F049c1939-bf94-4831-9566-487295292479_1280x720.jpeg 848w, https://substackcdn.com/image/fetch/$s_!b9pZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F049c1939-bf94-4831-9566-487295292479_1280x720.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!b9pZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F049c1939-bf94-4831-9566-487295292479_1280x720.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">finding 20 apps with overly permissive read/write perms in your admin portal like</figcaption></figure></div><div><hr></div><h2>Hunt 2: Infostealer Exposure in Your Trust Chain</h2><p><strong>Behavior you&#8217;re hunting</strong>: Evidence that credentials, tokens, or session data from your employees, or from employees at vendors who hold OAuth grants against your environment, have been harvested by infostealer malware.</p><p><strong>Why this matters</strong>: Infostealers are the initial access vector that feeds this entire pattern. But here&#8217;s the uncomfortable part: the Vercel breach didn&#8217;t start because a <em>Vercel</em> employee got hit. It started because a <em>vendor&#8217;s</em> employee got hit. You can run flawless endpoint hygiene internally and still be exposed through a third party&#8217;s compromised machine.</p><p>This hunt has two prongs: checking your own exposure and assessing your trust chain.</p><h3>Your Own Exposure</h3><p><strong>Threat intelligence feed checks</strong>: Several services aggregate infostealer logs and index them by corporate domain.</p><ul><li><p><strong>Hudson Rock</strong> (hudsonrock.com): large infostealer log database, searchable by domain. They first attributed the Context.ai compromise to Lumma Stealer.</p></li><li><p><strong>Flare</strong> (flare.io): dark web and infostealer market monitoring.</p></li><li><p><strong>SpyCloud</strong> (spycloud.com): specializes in infostealer-derived credential exposure.</p></li><li><p><strong>Have I Been Pwned</strong> (haveibeenpwned.com): more breach-focused than infostealer-focused, but a baseline check.</p></li></ul><p>Query for your corporate domain(s). Any hits should be treated as active compromise indicators, not historical data points. If an employee&#8217;s tokens appear in an infostealer log, assume the tokens are in adversary hands until proven otherwise.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yhHo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F708f8b83-3092-4592-991d-56e3487bfd97_494x263.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yhHo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F708f8b83-3092-4592-991d-56e3487bfd97_494x263.png 424w, https://substackcdn.com/image/fetch/$s_!yhHo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F708f8b83-3092-4592-991d-56e3487bfd97_494x263.png 848w, https://substackcdn.com/image/fetch/$s_!yhHo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F708f8b83-3092-4592-991d-56e3487bfd97_494x263.png 1272w, https://substackcdn.com/image/fetch/$s_!yhHo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F708f8b83-3092-4592-991d-56e3487bfd97_494x263.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yhHo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F708f8b83-3092-4592-991d-56e3487bfd97_494x263.png" width="494" height="263" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/708f8b83-3092-4592-991d-56e3487bfd97_494x263.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:263,&quot;width&quot;:494,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:225955,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dispatch.thorcollective.com/i/195757921?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F708f8b83-3092-4592-991d-56e3487bfd97_494x263.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yhHo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F708f8b83-3092-4592-991d-56e3487bfd97_494x263.png 424w, https://substackcdn.com/image/fetch/$s_!yhHo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F708f8b83-3092-4592-991d-56e3487bfd97_494x263.png 848w, https://substackcdn.com/image/fetch/$s_!yhHo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F708f8b83-3092-4592-991d-56e3487bfd97_494x263.png 1272w, https://substackcdn.com/image/fetch/$s_!yhHo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F708f8b83-3092-4592-991d-56e3487bfd97_494x263.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p><strong>Endpoint behavioral hunting</strong> (if you have EDR):</p><p>Key file paths to monitor for unauthorized access:</p><pre><code><code># Browser credential stores (Chrome/Edge)
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Login Data
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Cookies
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Web Data
%LOCALAPPDATA%\Microsoft\Edge\User Data\Default\Login Data

# Token caches
~/.config/gcloud/credentials.db
~/.config/gcloud/access_tokens.db
~/.aws/credentials
~/.azure/msal_token_cache.json
</code></code></pre><p>Hunt for:</p><ul><li><p>Processes accessing these files that aren&#8217;t the browser itself or an approved password manager</p></li><li><p>Processes reading from multiple browser profile directories in sequence (the signature &#8220;harvest everything&#8221; behavior of infostealers)</p></li><li><p>Outbound connections shortly after credential store access, especially to unfamiliar infrastructure</p></li></ul><h3>Your Trust Chain Exposure</h3><p>This is harder and less comfortable. The vendors who hold OAuth grants against your identity provider have employees with endpoints. Those endpoints can be compromised. When they are, the tokens those vendors hold <em>for your environment</em> may be in the exfiltrated data.</p><p>What you can do:</p><ul><li><p>Cross-reference your OAuth grant inventory (from Hunt 1) with infostealer exposure feeds. If a vendor&#8217;s domain appears in Hudson Rock or similar, and that vendor holds OAuth grants against your IdP, that&#8217;s a high-priority risk.</p></li><li><p>For critical vendors (those with broad OAuth scopes), ask directly about their endpoint security posture and infostealer monitoring during your next vendor security review.</p></li><li><p>Monitor for public disclosure of vendor compromises. The window between a vendor&#8217;s compromise and their disclosure is exactly when you&#8217;re most exposed.</p></li></ul><h3>The Uncomfortable Truth</h3><p>There&#8217;s a gap in this hunt that&#8217;s worth acknowledging: you can check if <em>your</em> employees are compromised, and you can reactively learn about <em>vendor</em> compromises through intelligence feeds or disclosure. But you can&#8217;t continuously monitor whether every vendor employee with access to tokens that touch your environment has a clean endpoint. This is a structural limitation of the OAuth trust model, and it&#8217;s why Hunt 1 (reducing the attack surface by controlling OAuth grants) is ultimately more impactful than Hunt 2 (detecting after the fact).</p><div><hr></div><h2>Hunt 3: Anomalous Third-Party Application Behavior</h2><p><strong>Behavior you&#8217;re hunting</strong>: OAuth-authenticated API access from a trusted third-party application that deviates from the application&#8217;s established behavioral baseline, indicating that someone other than the vendor is driving the API calls.</p><p><strong>Why this matters</strong>: When an attacker uses a stolen OAuth token, the access appears to come from the legitimate application. Your IdP logs will show the app&#8217;s client ID making authorized API calls within its granted scopes. The access is technically legitimate. The only detectable anomaly is in <em>how</em> the token is being used: the behavioral pattern, not the authentication event.</p><h3>Behavioral Indicators</h3><p>These indicators apply regardless of identity provider or which third-party application is involved:</p><p><strong>Geographic anomalies</strong>: An OAuth app that normally makes API calls from a cloud provider&#8217;s IP range (the vendor&#8217;s infrastructure) suddenly making calls from a different geographic region, a residential ISP, a VPN provider, or a hosting provider not associated with the vendor. This is the strongest signal. It means someone other than the vendor is using the token.</p><p><strong>Temporal anomalies</strong>: API access outside the application&#8217;s normal operating pattern. A productivity tool that typically makes requests during business hours suddenly making calls at 3 AM. A synchronization service that normally runs on a schedule suddenly making ad-hoc requests.</p><p><strong>Volume anomalies</strong>: A sudden spike in API calls. An app that normally makes a handful of requests per day suddenly enumerating entire Drive contents or pulling large volumes of email. The &#8220;smash and grab&#8221; pattern is distinctive: rapid, sequential access to resources the application previously accessed infrequently or not at all.</p><p><strong>Access pattern changes</strong>: An application accessing resources or API endpoints it has scopes for but hasn&#8217;t historically used. The OAuth grant may allow broad access, but the legitimate application&#8217;s normal behavior only touches a subset. An attacker with the same token will use it differently.</p><h3>Google Workspace</h3><p>Use the Workspace audit logs to profile OAuth application behavior. The key log sources are Drive log events, Gmail log events, and OAuth Token log events under <code>Admin Console &#8594; Reporting &#8594; Audit and Investigation</code>.</p><p>Look for:</p><pre><code><code>Drive Audit Log:
Event: view OR download
Actor: [OAuth app client ID]
Volume: &gt; 50 events in 1 hour (adjust based on baseline)
</code></code></pre><p>And via the Reports API:</p><pre><code><code>GET https://admin.googleapis.com/admin/reports/v1/activity/users/all/applications/token
</code></code></pre><p>Filter for token activity events associated with applications identified as high-risk in Hunt 1. Correlate IP addresses against the vendor&#8217;s known infrastructure ranges.</p><h3>Microsoft Entra ID</h3><p>Service principal sign-in logs are the primary data source:</p><pre><code><code>AADServicePrincipalSignInLogs
| where TimeGenerated &gt; ago(30d)
| extend AppName = tostring(ServicePrincipalName)
| summarize
    DistinctIPs = dcount(IPAddress),
    IPs = make_set(IPAddress),
    Locations = make_set(LocationDetails.city),
    CallCount = count()
    by AppName, AppId
| where DistinctIPs &gt; 3
| sort by DistinctIPs desc
</code></code></pre><p>This surfaces service principals authenticating from an unusual number of distinct IPs, a potential indicator of credential misuse. Also hunt for new credentials being added to service principals, which is a persistence technique:</p><pre><code><code>AuditLogs
| where OperationName has "Add service principal credentials"
| extend AppName = tostring(TargetResources[0].displayName)
| extend Actor = tostring(InitiatedBy.user.userPrincipalName)
| project TimeGenerated, Actor, AppName, OperationName
</code></code></pre><h3>Building a Baseline</h3><p>This hunt is only as good as your behavioral baseline. If you don&#8217;t know what normal looks like for an OAuth application, you can&#8217;t detect abnormal. Start by profiling the high-risk applications from Hunt 1:</p><ul><li><p>What IP ranges do they normally authenticate from?</p></li><li><p>What times of day do they make API calls?</p></li><li><p>What resources do they typically access?</p></li><li><p>What&#8217;s their normal API call volume?</p></li></ul><p>Document the baseline. Then alert on deviation. This doesn&#8217;t have to be sophisticated. Even a weekly manual review of OAuth app activity for your top-risk applications is better than nothing.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">THOR Collective Dispatch is a reader-supported publication. To receive new posts and support our work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><div><hr></div><h2>Hunt 4: Trust Boundary Lateral Movement</h2><p><strong>Behavior you&#8217;re hunting</strong>: Compromise of an identity provider account (via OAuth token abuse or any other means) being leveraged to access downstream platforms: CI/CD systems, cloud infrastructure, code repositories, PaaS environments, secrets managers.</p><p><strong>Why this matters</strong>: Owning a Workspace or M365 identity is rarely the objective. It&#8217;s a waypoint. The attacker wants what that identity can reach. In modern environments, a single identity is often federated across dozens of platforms via SSO, linked credentials, and stored secrets. In the Vercel case, Workspace access led to platform environment access and secrets exfiltration. In your environment, the blast radius may be different, but the movement pattern is the same.</p><h3>Map the Blast Radius First</h3><p>Before you can hunt for this movement, you need to understand what&#8217;s reachable from a compromised identity. For each user with high-risk third-party OAuth grants:</p><ul><li><p><strong>SSO-connected applications</strong>: What can this identity access via Google/Microsoft SSO? Each is a pivot target if that identity is compromised. Most organizations underestimate how many platforms are SSO-connected.</p></li><li><p><strong>Stored secrets in email and cloud storage</strong>: API keys, connection strings, passwords, tokens sitting in email threads, shared Drive folders, or OneNote notebooks. Attackers search for these immediately upon gaining email/Drive access.</p></li><li><p><strong>CI/CD and PaaS integrations</strong>: Does this user have access to deployment platforms, build systems, or cloud consoles? Are there environment variables or secrets in those platforms stored in plaintext or not marked as <code>sensitive</code>?</p></li><li><p><strong>Browser-synced credentials</strong>: If the user syncs their browser profile with their corporate identity, a Workspace/M365 compromise may expose their entire browser password store.</p></li></ul><h3>Detection Queries</h3><p><strong>SSO session correlation:</strong></p><p>Look for SSO-initiated sessions in downstream platforms that correlate temporally with suspicious activity in your identity provider:</p><pre><code><code>SignInLogs (downstream platform):
Authentication method: SSO
User: [users with high-risk OAuth grants]
Correlate with: unusual OAuth app activity from Hunt 3
</code></code></pre><p>The specific log sources depend on your platform stack, but the logic is consistent: if you see anomalous OAuth token usage in your IdP, check whether the affected identity subsequently created sessions in connected platforms.</p><p><strong>Secrets and environment variable access:</strong></p><pre><code><code>GitHub:   org.update_actions_secret, repo.update_actions_secret
AWS:      CloudTrail GetSecretValue, GetParameter (SSM)
GCP:      Secret Manager AccessSecretVersion
Azure:    Key Vault SecretGet
PaaS:     Environment variable access events (check audit logs)
</code></code></pre><p>On Vercel, Netlify, and similar platforms, pay special attention to variables not configured as <code>sensitive</code> or <code>encrypted</code>, which may be readable to any authenticated user with project access.</p><p><strong>Email and cloud storage enumeration:</strong></p><p>The rapid-fire pattern of an attacker enumerating everything they can reach through a compromised identity:</p><ul><li><p>Drive/OneDrive: high-volume <code>view</code>, <code>download</code>, or <code>copy</code> events in a short window, especially against files the user doesn&#8217;t typically access</p></li><li><p>Email: API-based access to mailbox contents (as opposed to normal interactive use), particularly bulk read patterns</p></li><li><p>Across both: access from the same anomalous IP/geo identified in Hunt 3</p></li></ul><div><hr></div><h2>Hardening Against the Pattern</h2><p>Hunting finds current exposure. Hardening reduces future attack surface. These recommendations map to the four phases of the attack chain:</p><p><strong>Reduce the trust surface (Phase 2 prevention):</strong></p><ul><li><p>Implement an OAuth app allowlist in your identity provider. Block user consent for unapproved applications.</p></li><li><p>Restrict broad scopes by default. No third-party app gets <code>Allow All</code> or equivalent without explicit security review.</p></li><li><p>Alert on new OAuth consent events, especially for high-privilege scopes.</p></li><li><p>Conduct quarterly reviews of active OAuth grants and revoke stale or unnecessary ones.</p></li><li><p>Establish a lightweight process for employees to request approval for new SaaS tools rather than self-provisioning with corporate credentials.</p></li></ul><p><strong>Limit the blast radius (Phase 3/4 prevention):</strong></p><ul><li><p>Default all secrets, environment variables, and API keys to encrypted/sensitive storage in every platform. The Vercel breach specifically exploited variables that weren&#8217;t marked sensitive.</p></li><li><p>Audit CI/CD and PaaS platforms for secrets stored in plaintext.</p></li><li><p>Enforce short-lived access tokens (5-15 minutes) with appropriately scoped refresh tokens where your IdP supports it.</p></li><li><p>Implement token binding or sender-constrained tokens to make stolen tokens unusable from unauthorized devices.</p></li><li><p>Segment SSO access. Not every identity needs access to every connected platform.</p></li></ul><p><strong>Build resilience (detection and response):</strong></p><ul><li><p>Monitor infostealer exposure feeds for your corporate domains and critical vendor domains.</p></li><li><p>Baseline OAuth application behavior and alert on deviation.</p></li><li><p>Rotate tokens and secrets immediately upon any suspected identity compromise, including when a <em>vendor</em> discloses a compromise.</p></li><li><p>Maintain a runbook for &#8220;third-party vendor compromise&#8221; that includes identifying all OAuth grants from that vendor, revoking them, auditing access logs for the affected period, and rotating any secrets the affected identities could reach.</p></li></ul><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pUS2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e902dbc-e34e-4273-b63d-c9dd706e5f4a_1200x655.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pUS2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e902dbc-e34e-4273-b63d-c9dd706e5f4a_1200x655.png 424w, https://substackcdn.com/image/fetch/$s_!pUS2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e902dbc-e34e-4273-b63d-c9dd706e5f4a_1200x655.png 848w, https://substackcdn.com/image/fetch/$s_!pUS2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e902dbc-e34e-4273-b63d-c9dd706e5f4a_1200x655.png 1272w, https://substackcdn.com/image/fetch/$s_!pUS2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e902dbc-e34e-4273-b63d-c9dd706e5f4a_1200x655.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pUS2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e902dbc-e34e-4273-b63d-c9dd706e5f4a_1200x655.png" width="1200" height="655" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1e902dbc-e34e-4273-b63d-c9dd706e5f4a_1200x655.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:655,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;The Vercel Hack: How One AI Tool Cracked Open the Internet's Deployment  Stack | by Faisal haque | Apr, 2026 | Artificial Intelligence in Plain  English&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="The Vercel Hack: How One AI Tool Cracked Open the Internet's Deployment  Stack | by Faisal haque | Apr, 2026 | Artificial Intelligence in Plain  English" title="The Vercel Hack: How One AI Tool Cracked Open the Internet's Deployment  Stack | by Faisal haque | Apr, 2026 | Artificial Intelligence in Plain  English" srcset="https://substackcdn.com/image/fetch/$s_!pUS2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e902dbc-e34e-4273-b63d-c9dd706e5f4a_1200x655.png 424w, https://substackcdn.com/image/fetch/$s_!pUS2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e902dbc-e34e-4273-b63d-c9dd706e5f4a_1200x655.png 848w, https://substackcdn.com/image/fetch/$s_!pUS2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e902dbc-e34e-4273-b63d-c9dd706e5f4a_1200x655.png 1272w, https://substackcdn.com/image/fetch/$s_!pUS2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e902dbc-e34e-4273-b63d-c9dd706e5f4a_1200x655.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">credit Faisal Haque - https://ai.plainenglish.io/the-vercel-hack-how-one-ai-tool-cracked-open-the-internets-deployment-stack-562303c026f0...</figcaption></figure></div><h2>Vercel/Context.ai IOCs</h2><p>For immediate operational use. These are specific to the April 2026 Vercel incident and should be checked alongside the broader hunts above:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nBI2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94b659e1-02bb-4e31-9bfd-d04539faa4fe_1760x808.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nBI2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94b659e1-02bb-4e31-9bfd-d04539faa4fe_1760x808.png 424w, https://substackcdn.com/image/fetch/$s_!nBI2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94b659e1-02bb-4e31-9bfd-d04539faa4fe_1760x808.png 848w, https://substackcdn.com/image/fetch/$s_!nBI2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94b659e1-02bb-4e31-9bfd-d04539faa4fe_1760x808.png 1272w, https://substackcdn.com/image/fetch/$s_!nBI2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94b659e1-02bb-4e31-9bfd-d04539faa4fe_1760x808.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nBI2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94b659e1-02bb-4e31-9bfd-d04539faa4fe_1760x808.png" width="1456" height="668" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/94b659e1-02bb-4e31-9bfd-d04539faa4fe_1760x808.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:668,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:142115,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dispatch.thorcollective.com/i/195757921?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94b659e1-02bb-4e31-9bfd-d04539faa4fe_1760x808.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nBI2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94b659e1-02bb-4e31-9bfd-d04539faa4fe_1760x808.png 424w, https://substackcdn.com/image/fetch/$s_!nBI2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94b659e1-02bb-4e31-9bfd-d04539faa4fe_1760x808.png 848w, https://substackcdn.com/image/fetch/$s_!nBI2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94b659e1-02bb-4e31-9bfd-d04539faa4fe_1760x808.png 1272w, https://substackcdn.com/image/fetch/$s_!nBI2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94b659e1-02bb-4e31-9bfd-d04539faa4fe_1760x808.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>and because I spent too many years hand keying IOCs from photos and PDFs:<br><br><code>110671459871-30f1spbu0hptbs60cb4vsmv79i7bbvqj.apps.googleusercontent.com
110671459871-f3cq3okebd3jcg1lllmroqejdbka8cqq.apps.googleusercontent.com
omddlmnhcofjbnbflmjginpjjblphbgk
beta.context.ai
</code></p><div><hr></div><h2>The Bigger Picture</h2><p>The Vercel/Context.ai breach is a clean example of a pattern that&#8217;s been building for years: as organizations adopt more SaaS tools, they create more trust relationships, and each trust relationship is a lateral movement path that bypasses traditional perimeter and endpoint controls. The attacker doesn&#8217;t need to beat your security. They need to beat the security of anyone you&#8217;ve granted trust to.</p><p>That&#8217;s not a problem you solve once. It&#8217;s a behavior you hunt for continuously.</p><p>Happy thrunting!</p><div><hr></div><p><em>The THOR Collective is a practitioner-driven cybersecurity collective focused on detection, hunting, and response tradecraft. Want to contribute? Reach out.</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/p/hunting-the-infostealer-to-saas-pipeline/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://dispatch.thorcollective.com/p/hunting-the-infostealer-to-saas-pipeline/comments"><span>Leave a comment</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Three New Ways to Use HEARTH ]]></title><description><![CDATA[What Can I Hunt?, Coverage Map, and Context Graph]]></description><link>https://dispatch.thorcollective.com/p/three-new-ways-to-use-hearth</link><guid isPermaLink="false">https://dispatch.thorcollective.com/p/three-new-ways-to-use-hearth</guid><dc:creator><![CDATA[Sydney Marrone]]></dc:creator><pubDate>Wed, 22 Apr 2026 12:04:11 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!WAAN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61d2e08d-68c8-4e36-91b9-1338aa2f388d_500x500.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>HEARTH now has 160+ community-curated hunting hypotheses structured around the <a href="https://www.splunk.com/en_us/blog/security/peak-threat-hunting-framework.html">PEAK threat hunting framework:</a>&nbsp;Flames for hypothesis-driven hunts, Embers for baselining and exploration, and&nbsp;Alchemy for model-assisted work. That&#8217;s a lot of ground to cover, and the flat list view we shipped with was fine for browsing but not for answering the questions analysts actually ask at their desks: <em>What can I run with the logs I already have? Where are my coverage holes? Why does this hunt matter this week?</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">THOR Collective Dispatch is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>This release adds three new tabs that each answer one of those questions. None of them change the underlying hunt library &#8212; hunts still live as markdown in the repo and flow into <code>hunts-data.json</code> on build. The tabs are different lenses on the same data, plus a context graph layer that ties hunts back to the actors and campaigns driving them.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WAAN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61d2e08d-68c8-4e36-91b9-1338aa2f388d_500x500.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WAAN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61d2e08d-68c8-4e36-91b9-1338aa2f388d_500x500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!WAAN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61d2e08d-68c8-4e36-91b9-1338aa2f388d_500x500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!WAAN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61d2e08d-68c8-4e36-91b9-1338aa2f388d_500x500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!WAAN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61d2e08d-68c8-4e36-91b9-1338aa2f388d_500x500.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WAAN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61d2e08d-68c8-4e36-91b9-1338aa2f388d_500x500.jpeg" width="500" height="500" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/61d2e08d-68c8-4e36-91b9-1338aa2f388d_500x500.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:500,&quot;width&quot;:500,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WAAN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61d2e08d-68c8-4e36-91b9-1338aa2f388d_500x500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!WAAN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61d2e08d-68c8-4e36-91b9-1338aa2f388d_500x500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!WAAN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61d2e08d-68c8-4e36-91b9-1338aa2f388d_500x500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!WAAN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61d2e08d-68c8-4e36-91b9-1338aa2f388d_500x500.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Here&#8217;s what shipped.</p><h2><strong>What Can I Hunt?</strong></h2><p><strong>The problem.</strong> You have an EDR, Zeek, Okta, and Microsoft 365 logs. You do not have a cloud trail from every CSP, you do not have full packet capture, and you are not going to read 130 markdown files to figure out which hunts are runnable tonight. The default question for any new hunter onboarding to an environment is &#8220;given my telemetry, what should I work on first?&#8221; &#8212; and until now HEARTH made you answer that by hand.</p><p><strong>How it works.</strong> The left sidebar lists data source categories pulled from a curated <code>datasource-mapping.json</code> &#8212; EDR, Network, Identity, Cloud, Email, and so on. Check the boxes for what you actually have. The right pane filters in real time to only hunts whose required data sources you can satisfy, then ranks them with a HuntRanker score that blends three signals:</p><ul><li><p><strong>Prevalence</strong> &#8212; how many active threat campaigns are currently leveraging the underlying techniques, shown as &#128293; hot, &#127777;&#65039; warm, or &#10052;&#65039; cold.</p></li><li><p><strong>Actor count</strong> &#8212; how many tracked threat actors are known to use the technique.</p></li><li><p><strong>Active campaigns</strong> &#8212; the live campaign count touching the technique right now.</p></li></ul><p>The top 5 cards float to the top as &#8220;highest-impact given current threat activity.&#8221; If you have a data source but the techniques under it have zero HEARTH hypotheses, a coverage gap alert fires with a CTA to submit one &#8212; this is how the library grows in the places it&#8217;s needed. Every card has a &#8220;View hypothesis&#8221; link that opens the rendered markdown straight from GitHub, so you can go from &#8220;what should I hunt?&#8221; to reading the full hypothesis, data requirements, and detection logic in one click.</p><p><strong>Who it&#8217;s for.</strong> SOC analysts and detection engineers onboarding to a new environment, hunt team leads building a sprint backlog, and anyone who wants to stop triaging a 130-row spreadsheet. The pitch is simple: tell us what telemetry you have, and we&#8217;ll tell you what&#8217;s worth hunting right now.</p><h2><strong>Coverage Map</strong></h2><p><strong>The problem.</strong> Leadership asks where your hunting program covers ATT&amp;CK and where it doesn&#8217;t. You want a single view that shows hunts mapped to techniques, color-coded by hunt type, with gaps called out &#8212; not a spreadsheet you have to re-render every quarter.</p><p><strong>How it works.</strong> The Coverage Map is an interactive data visualization graph placing hunts against ATT&amp;CK techniques. Nodes are color-coded by type so you can read the map at a glance:</p><ul><li><p>Orange &#8212; ATT&amp;CK technique</p></li><li><p>Purple &#8212; Flame hunt (hypothesis-driven)</p></li><li><p>Blue &#8212; Ember hunt (baselining/exploration)</p></li><li><p>Amber &#8212; Alchemy hunt (model-assisted)</p></li><li><p>Green &#8212; Data source</p></li><li><p>Red (glowing) &#8212; Coverage gap</p></li></ul><p>Tactic filter buttons across the top let you narrow to a single kill-chain phase &#8212; Credential Access, Persistence, Exfiltration, whatever you&#8217;re scoping. Click any node and a sidebar slides out with the full details: linked techniques, required data sources, hunt IDs, description.</p><p>The coverage gap nodes are the interesting ones. They surface techniques that public reporting has tied to active campaigns but that HEARTH does not yet have a hypothesis for. That&#8217;s your contribution backlog, sorted by relevance instead of by whim.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vX8J!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1186e0a0-d60b-4ecb-9749-d19c561a6cb9_667x375.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vX8J!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1186e0a0-d60b-4ecb-9749-d19c561a6cb9_667x375.jpeg 424w, https://substackcdn.com/image/fetch/$s_!vX8J!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1186e0a0-d60b-4ecb-9749-d19c561a6cb9_667x375.jpeg 848w, https://substackcdn.com/image/fetch/$s_!vX8J!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1186e0a0-d60b-4ecb-9749-d19c561a6cb9_667x375.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!vX8J!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1186e0a0-d60b-4ecb-9749-d19c561a6cb9_667x375.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vX8J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1186e0a0-d60b-4ecb-9749-d19c561a6cb9_667x375.jpeg" width="667" height="375" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1186e0a0-d60b-4ecb-9749-d19c561a6cb9_667x375.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:375,&quot;width&quot;:667,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vX8J!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1186e0a0-d60b-4ecb-9749-d19c561a6cb9_667x375.jpeg 424w, https://substackcdn.com/image/fetch/$s_!vX8J!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1186e0a0-d60b-4ecb-9749-d19c561a6cb9_667x375.jpeg 848w, https://substackcdn.com/image/fetch/$s_!vX8J!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1186e0a0-d60b-4ecb-9749-d19c561a6cb9_667x375.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!vX8J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1186e0a0-d60b-4ecb-9749-d19c561a6cb9_667x375.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Who it&#8217;s for.</strong> Detection engineering leads building a coverage strategy, program leads pitching hunting maturity to stakeholders, and contributors looking for the highest-value gap to fill instead of writing yet another Mimikatz hunt.</p><h2><strong>Context Graph</strong></h2><p><strong>The problem.</strong> A hunt hypothesis on its own tells you what to look for, not why it matters this week. To prioritize, you need the full chain: which actor ran which campaign, which techniques did that campaign use, and which HEARTH hunts land on those techniques. That&#8217;s four entity types and a lot of edges, and it does not fit in a flat list.</p><p><strong>How it works.</strong> The Context Graph is a data visualization force-directed graph with four node types and real edges between them:</p><ul><li><p>Threat actors (red)</p></li><li><p>Campaigns (amber)</p></li><li><p>ATT&amp;CK techniques (orange)</p></li><li><p>HEARTH hunts (Flames, Embers, Alchemy in their respective colors)</p></li></ul><p>Edges reflect real relationships derived from public threat intel: actor X ran campaign Y, which used T1071.001, which HEARTH hunt H002 can detect. Hover any node for a tooltip with the metadata that matters &#8212; campaign dates, actor aliases, technique ID, hunt description. Click to expand the full sidebar.</p><p>The graph is kept up to date by enrichment scripts that pull data from public threat intelligence sources. You&#8217;re not looking at a snapshot someone committed last quarter; you&#8217;re looking at a live picture of what&#8217;s being reported on.</p><p><strong>Who it&#8217;s for.</strong> Threat intel analysts who need to connect reports to action, hunt program leads justifying prioritization to stakeholders, and researchers exploring what a given actor has actually been doing lately.</p><h2><strong>Putting it together</strong></h2><p>These tabs are designed to chain. A realistic workflow looks like this:</p><p>You read an advisory about an actor getting louder &#8212; pick your favorite. You jump into the <strong>Context Graph</strong>, find the actor node, and expand out to the campaigns and techniques they&#8217;ve been using. Two of those techniques look new and relevant to your environment.</p><p>From there you switch to the <strong>Coverage Map</strong> and filter by the tactics those techniques belong to. Three are covered by existing hunts; one is a red gap node. You note the gap as a contribution candidate and move on.</p><p>Finally you open <strong>&#127919; What Can I Hunt?</strong>, confirm your data source boxes are checked, and the three covered hunts sort into your top 5 based on current prevalence and actor count. You click through to the markdown, paste the detection logic into your platform of choice, and you&#8217;re running something meaningful by lunch.</p><p>That&#8217;s the whole point. Context Graph tells you what matters, Coverage Map tells you where you stand, and What Can I Hunt? tells you what to run. Same library, three different questions, one workflow.</p><h2><strong>Try it</strong></h2><p>All three tabs are live now at <strong><a href="https://hearth.thorcollective.com/">hearth.thorcollective.com</a></strong>. If you find a coverage gap worth filling, the contribution workflow is linked directly from the gap alerts &#8212; submit a hypothesis and it&#8217;ll flow through the normal PEAK review into the next build.</p><p>Feedback, bug reports, and new hunts all welcome. HEARTH is only as useful as the community makes it, and these tabs are meant to make that contribution loop tighter.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">THOR Collective Dispatch is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Mythos Won’t Kill Threat Hunting]]></title><description><![CDATA[It&#8217;ll Prove We Were Right]]></description><link>https://dispatch.thorcollective.com/p/mythos-wont-kill-threat-hunting</link><guid isPermaLink="false">https://dispatch.thorcollective.com/p/mythos-wont-kill-threat-hunting</guid><dc:creator><![CDATA[Sydney Marrone]]></dc:creator><pubDate>Mon, 13 Apr 2026 17:02:35 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!65p5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32680bf5-5458-46ca-a36c-aa9764ff45a4_567x500.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Last week, a coalition of CISOs, SANS, OWASP, and the Cloud Security Alliance published a strategy briefing called <a href="https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/04/mythosready.pdf">&#8220;The AI Vulnerability Storm: Building a &#8216;Mythos-ready&#8217; Security Program.&#8221;</a> If you haven&#8217;t read it yet, you should. The author list alone is stacked: Gadi Evron, Rob T. Lee, Jen Easterly, Bruce Schneier, Chris Inglis, Heather Adkins, Rob Joyce. It&#8217;s the kind of document that doesn&#8217;t happen unless people are genuinely worried.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">THOR Collective Dispatch is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The headline is hard to ignore. Anthropic&#8217;s Claude Mythos can autonomously <a href="https://www.anthropic.com/glasswing">discover thousands of zero-day vulnerabilities</a> across major operating systems and browsers. A 72% exploit success rate. It found a 27-year-old OpenBSD bug nobody caught. Where Opus 4.6 generated two working Firefox exploits, Mythos generated 181 under identical conditions. The time between vulnerability discovery and a working exploit now looks like hours, not weeks.</p><p>The briefing lays out a 90-day plan for CISOs. It&#8217;s solid. But it&#8217;s written for people managing budgets and setting strategy.</p><p>We want to talk about what this means for the people actually doing the work.</p><p>This is a genuine inflection point. So naturally, the hot takes started rolling in: <em>AI will replace security analysts. Threat hunting is dead. Humans can&#8217;t keep up.</em></p><p>They&#8217;re wrong. And they&#8217;re wrong for the same reason they&#8217;ve always been wrong. They keep confusing finding bugs with finding adversaries.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!65p5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32680bf5-5458-46ca-a36c-aa9764ff45a4_567x500.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!65p5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32680bf5-5458-46ca-a36c-aa9764ff45a4_567x500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!65p5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32680bf5-5458-46ca-a36c-aa9764ff45a4_567x500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!65p5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32680bf5-5458-46ca-a36c-aa9764ff45a4_567x500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!65p5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32680bf5-5458-46ca-a36c-aa9764ff45a4_567x500.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!65p5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32680bf5-5458-46ca-a36c-aa9764ff45a4_567x500.jpeg" width="567" height="500" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/32680bf5-5458-46ca-a36c-aa9764ff45a4_567x500.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:500,&quot;width&quot;:567,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!65p5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32680bf5-5458-46ca-a36c-aa9764ff45a4_567x500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!65p5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32680bf5-5458-46ca-a36c-aa9764ff45a4_567x500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!65p5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32680bf5-5458-46ca-a36c-aa9764ff45a4_567x500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!65p5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32680bf5-5458-46ca-a36c-aa9764ff45a4_567x500.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>The Category Error That Won&#8217;t Die</strong></h2><p>Finding a bug in source code and finding an adversary living in your environment are fundamentally different problems. One is a code analysis challenge. The other is a behavioral detection problem. One looks at what software <em>could</em> do wrong. The other looks at what humans <em>are</em> doing wrong, inside your network, right now, with intent.</p><p>Could Mythos-class models eventually correlate authentication anomalies with lateral movement at 2 AM? Probably. Could they ask why a legitimate admin tool is running on a finance workstation outside a change window? Maybe. But that&#8217;s not a threat to hunting. That&#8217;s hunting getting faster. The methodology doesn&#8217;t go away because the tools got better. It gets more important because the volume and speed of what we&#8217;re up against just changed overnight.</p><h2><strong>The Model Isn&#8217;t the Moat (But It&#8217;s Not Nothing)</strong></h2><p>After Glasswing dropped, <a href="https://aisle.com/blog/ai-cybersecurity-after-mythos-the-jagged-frontier">AISLE ran Mythos&#8217;s showcase vulnerabilities</a> through small, cheap, open-weights models. Eight out of eight detected the flagship FreeBSD exploit. A 3.6 billion parameter model found it. Headlines followed: Mythos isn&#8217;t special, smaller models can do this too.</p><p>Not so fast.</p><p>AISLE isolated the vulnerable functions and pointed their models directly at them. That&#8217;s a very different problem than what Mythos did. Anthropic pointed Mythos at entire codebases with no guidance and told it to find something. It scoured millions of lines of code, identified the weak points, chained vulnerabilities together, and built working exploits. The targeting is the hard part, and AISLE skipped it.</p><p>But here&#8217;s what AISLE got right, and it matters for us: even with a frontier model, the value isn&#8217;t the model alone. It&#8217;s the system around it. The targeting. The methodology. The expertise that knows where to look and what to do with what you find.</p><p>That&#8217;s the threat hunting argument we&#8217;ve been making for a decade. The tool doesn&#8217;t matter. The SIEM doesn&#8217;t matter. What matters is the hypothesis, the iterative refinement, the human who understands the terrain. Every agentic security framework being built right now runs the same loop hunters have been running manually. Form hypothesis, collect data, analyze, iterate, improve the posture. We didn&#8217;t copy that from AI. AI copied that from us.</p><h2><strong>What Mythos Actually Changes</strong></h2><p>Mythos increases volume and speed. It does not change attacker behavior.</p><p>The biggest breaches we see today still come from the basics:</p><ul><li><p>credential abuse</p></li><li><p>phishing</p></li><li><p>supply chain compromise</p></li><li><p>misconfigurations</p></li></ul><p>Not zero-days.</p><p>Attackers still have to operate in your environment. And that shows up as behavior.</p><p>That&#8217;s what we hunt.</p><h2><strong>Detection Was Already Losing</strong></h2><p>Signature-based detection was already losing.</p><p>When exploitation happens faster than your patch cycle, detection tied to known CVEs is always late. You&#8217;re reacting after the exploit exists.</p><p>Threat hunting exists because of that gap.</p><p>Mythos doesn&#8217;t break the model.</p><p>It validates it.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!03XJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4f7430f-633d-40e1-ac76-a444794dd3af_524x500.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!03XJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4f7430f-633d-40e1-ac76-a444794dd3af_524x500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!03XJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4f7430f-633d-40e1-ac76-a444794dd3af_524x500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!03XJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4f7430f-633d-40e1-ac76-a444794dd3af_524x500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!03XJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4f7430f-633d-40e1-ac76-a444794dd3af_524x500.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!03XJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4f7430f-633d-40e1-ac76-a444794dd3af_524x500.jpeg" width="524" height="500" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d4f7430f-633d-40e1-ac76-a444794dd3af_524x500.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:500,&quot;width&quot;:524,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!03XJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4f7430f-633d-40e1-ac76-a444794dd3af_524x500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!03XJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4f7430f-633d-40e1-ac76-a444794dd3af_524x500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!03XJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4f7430f-633d-40e1-ac76-a444794dd3af_524x500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!03XJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4f7430f-633d-40e1-ac76-a444794dd3af_524x500.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>What Actually Scales</h2><p>When exploits can be generated at machine speed, the only thing that scales is behavioral hunting.</p><p>You&#8217;re not asking &#8220;was this CVE exploited.&#8221;</p><p>You&#8217;re asking:</p><ul><li><p>does this process tree make sense?</p></li><li><p>does this auth pattern match baseline?</p></li><li><p>why is this system talking to something new?</p></li><li><p>who wrote to this directory?</p></li></ul><p>None of that changes.</p><p>It just matters more.</p><h2><strong>The Real Problem: Memory</strong></h2><p>Most hunting programs don&#8217;t have memory.</p><p>Hunts get run, closed, and forgotten. Insights live in Slack. Knowledge walks out the door.</p><p>That was already inefficient.</p><p>At Mythos scale, it&#8217;s a failure mode.</p><p>If you can&#8217;t recall what you&#8217;ve already investigated, you can&#8217;t keep up.</p><h2><strong>What Needs to Change</strong></h2><p>The CSA briefing&#8217;s 90-day plan is good for CISOs. Here&#8217;s what it looks like translated to hunting operations:</p><p><strong>This week:</strong></p><ul><li><p>Assess behavior coverage, not just data</p></li><li><p>Baseline auth, DNS, service accounts</p></li><li><p>Write your hunts down</p></li></ul><p><strong>This month:</strong></p><ul><li><p>Use AI to accelerate, not replace</p></li><li><p>Generate hypotheses and draft queries faster</p></li><li><p>Add quality gates</p></li></ul><p><strong>This quarter:</strong></p><ul><li><p>Start building agents for repeatable work</p></li><li><p>CVE &#8594; hypothesis generation</p></li><li><p>baseline &#8594; drift detection</p></li><li><p>recommendations &#8594; tracking</p></li></ul><p>Humans decide.</p><p>Agents scale.</p><h2><strong>HEARTH: The Receipts</strong></h2><p>We keep saying &#8220;we hunt behavior.&#8221; Here&#8217;s what that looks like in practice.</p><p><a href="https://hearth.thorcollective.com/">HEARTH</a> is the community hypothesis library we built at THOR Collective. It currently has 133 hypotheses, 19 baselines, and 15 analytical models, all structured using the PEAK framework. Every hypothesis targets a specific adversary behavior, not a CVE.</p><p>When we mapped the Mythos briefing&#8217;s threat categories to HEARTH, the coverage held up better than we expected.</p><ul><li><p><strong>Supply chain attacks:</strong> npm compromise, VS Code extensions, PyPI poisoning, GitHub Actions abuse</p></li><li><p><strong>AI/agentic attack surface:</strong> MCP server abuse, prompt injection chains, LLM credential theft, autonomous recon</p></li><li><p><strong>Social engineering at scale:</strong> ClickFix variants, AI tool impersonation, fake VPN clients</p></li><li><p><strong>Baselines:</strong> non-human identities, DNS patterns, scheduled tasks, service account auth, PowerShell usage</p></li></ul><p>It&#8217;s not complete. We don&#8217;t yet cover things like detecting exploitation of newly discovered kernel-level bugs or tracking patch velocity against disclosure rates.</p><p>But the model holds.</p><p>A shared library of behavioral hypotheses is exactly the kind of infrastructure the CSA briefing points to when it says coalitions win. HEARTH is open source. Every hypothesis is a pull request away from better coverage.</p><h2><strong>The Five Levels</strong></h2><p>The briefing calls for &#8220;Mythos-ready&#8221; programs but doesn&#8217;t define what that means. This is exactly the problem the <a href="https://agenticthreathuntingframework.com/">Agentic Threat Hunting Framework (ATHF)</a> was designed to solve.</p><ul><li><p><strong>Level 0: Ad hoc</strong> - Hunts live in Slack. No structure, no memory.</p></li><li><p><strong>Level 1: Documented</strong> - Hunts are written and stored.</p></li><li><p><strong>Level 2: Searchable</strong> - Hunt history can be queried and recalled, including by AI.</p></li><li><p><strong>Level 3: Generative</strong> - AI assists with hypotheses and execution.</p></li><li><p><strong>Level 4: Agentic</strong> - Agents handle monitoring, triage, and workflow execution.</p></li></ul><p>Most teams should be targeting Level 2 right now.</p><p>That&#8217;s the minimum viable response to this shift. Because at Mythos scale, memory isn&#8217;t optional.</p><p>It&#8217;s the difference between scaling and sinking.</p><h3><strong>The Bottom Line</strong></h3><p>Mythos didn&#8217;t change what threat hunting is.</p><p>It changed how fast we need to do it.</p><p><a href="https://www.splunk.com/en_us/blog/security/peak-threat-hunting-framework.html">PEAK</a> still works. Behavioral hunting still works.</p><p>You just need to move faster, remember more, and cover more ground.</p><p>The hunters who figure that out won&#8217;t just be fine. They&#8217;ll be the ones everyone else is depending on.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!u92u!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F326db02b-8dd9-4607-ac59-1aec2ea1a162_800x450.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!u92u!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F326db02b-8dd9-4607-ac59-1aec2ea1a162_800x450.jpeg 424w, https://substackcdn.com/image/fetch/$s_!u92u!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F326db02b-8dd9-4607-ac59-1aec2ea1a162_800x450.jpeg 848w, https://substackcdn.com/image/fetch/$s_!u92u!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F326db02b-8dd9-4607-ac59-1aec2ea1a162_800x450.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!u92u!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F326db02b-8dd9-4607-ac59-1aec2ea1a162_800x450.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!u92u!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F326db02b-8dd9-4607-ac59-1aec2ea1a162_800x450.jpeg" width="800" height="450" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/326db02b-8dd9-4607-ac59-1aec2ea1a162_800x450.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:450,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!u92u!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F326db02b-8dd9-4607-ac59-1aec2ea1a162_800x450.jpeg 424w, https://substackcdn.com/image/fetch/$s_!u92u!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F326db02b-8dd9-4607-ac59-1aec2ea1a162_800x450.jpeg 848w, https://substackcdn.com/image/fetch/$s_!u92u!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F326db02b-8dd9-4607-ac59-1aec2ea1a162_800x450.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!u92u!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F326db02b-8dd9-4607-ac59-1aec2ea1a162_800x450.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Mythos didn&#8217;t change what threat hunting is.</p><p>It changed how fast we need to do it.</p><p>Happy thrunting!</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">THOR Collective Dispatch is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/p/mythos-wont-kill-threat-hunting/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://dispatch.thorcollective.com/p/mythos-wont-kill-threat-hunting/comments"><span>Leave a comment</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Vibe Coding The Holidays Away]]></title><description><![CDATA[A data-driven breakdown of what attackers are actually hunting for on the open internet &#8212; and what defenders should be watching.]]></description><link>https://dispatch.thorcollective.com/p/vibe-coding-the-holidays-away</link><guid isPermaLink="false">https://dispatch.thorcollective.com/p/vibe-coding-the-holidays-away</guid><pubDate>Tue, 31 Mar 2026 14:33:44 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dXos!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18dceb4a-4220-403c-9c11-592ae2b489bc_2000x1090.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dXos!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18dceb4a-4220-403c-9c11-592ae2b489bc_2000x1090.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dXos!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18dceb4a-4220-403c-9c11-592ae2b489bc_2000x1090.jpeg 424w, https://substackcdn.com/image/fetch/$s_!dXos!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18dceb4a-4220-403c-9c11-592ae2b489bc_2000x1090.jpeg 848w, https://substackcdn.com/image/fetch/$s_!dXos!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18dceb4a-4220-403c-9c11-592ae2b489bc_2000x1090.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!dXos!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18dceb4a-4220-403c-9c11-592ae2b489bc_2000x1090.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dXos!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18dceb4a-4220-403c-9c11-592ae2b489bc_2000x1090.jpeg" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/18dceb4a-4220-403c-9c11-592ae2b489bc_2000x1090.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:435086,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://dispatch.thorcollective.com/i/192687506?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18dceb4a-4220-403c-9c11-592ae2b489bc_2000x1090.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dXos!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18dceb4a-4220-403c-9c11-592ae2b489bc_2000x1090.jpeg 424w, https://substackcdn.com/image/fetch/$s_!dXos!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18dceb4a-4220-403c-9c11-592ae2b489bc_2000x1090.jpeg 848w, https://substackcdn.com/image/fetch/$s_!dXos!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18dceb4a-4220-403c-9c11-592ae2b489bc_2000x1090.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!dXos!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18dceb4a-4220-403c-9c11-592ae2b489bc_2000x1090.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><br>Over the holiday break, I deployed a set of web honeypots on Digital Ocean and let them soak. No fancy banners, no fake login portals &#8212; just nginx instances logging every request to Loki, with a daily analysis pipeline crunching the data into structured threat models. The honeypots ran from January 1&#8211;16, 2026, collecting <strong>71,768 total requests</strong> from <strong>~400+ unique IPs per day</strong> across <strong>tens of thousands of unique URI paths</strong>.</p><p>Over the holidays I had some free time and decided to sit down and build out a project I had been kicking around for quite some time. I wanted to see if I couldn&#8217;t build a honeypot network across global AWS infrastructure, forward the goals to a single destination (my aggregator), and then analyze those logs to see if there were any noteworthy trends.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">THOR Collective Dispatch is a reader-supported publication. To receive new posts and support our work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>What came back isn&#8217;t groundbreaking in the &#8220;zero-day&#8221; sense. But it paints one of the clearest pictures I&#8217;ve seen of what the automated internet actually looks like when it hits your infrastructure &#8212; and more importantly, what it&#8217;s looking for. If you&#8217;re building hunt hypotheses, tuning detections, or trying to prioritize hardening, this is the kind of ground truth that matters.</p><p>Here&#8217;s what the data said.</p><div><hr></div><h2><strong>The Shape of the Noise</strong></h2><p>Before diving into what was targeted, let&#8217;s look at the volume and rhythm.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jDFu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86c7af79-ccc7-4124-af32-4c6b57c9d208_872x697.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jDFu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86c7af79-ccc7-4124-af32-4c6b57c9d208_872x697.png 424w, https://substackcdn.com/image/fetch/$s_!jDFu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86c7af79-ccc7-4124-af32-4c6b57c9d208_872x697.png 848w, https://substackcdn.com/image/fetch/$s_!jDFu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86c7af79-ccc7-4124-af32-4c6b57c9d208_872x697.png 1272w, https://substackcdn.com/image/fetch/$s_!jDFu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86c7af79-ccc7-4124-af32-4c6b57c9d208_872x697.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jDFu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86c7af79-ccc7-4124-af32-4c6b57c9d208_872x697.png" width="872" height="697" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/86c7af79-ccc7-4124-af32-4c6b57c9d208_872x697.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:697,&quot;width&quot;:872,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:92132,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dispatch.thorcollective.com/i/192687506?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86c7af79-ccc7-4124-af32-4c6b57c9d208_872x697.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jDFu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86c7af79-ccc7-4124-af32-4c6b57c9d208_872x697.png 424w, https://substackcdn.com/image/fetch/$s_!jDFu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86c7af79-ccc7-4124-af32-4c6b57c9d208_872x697.png 848w, https://substackcdn.com/image/fetch/$s_!jDFu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86c7af79-ccc7-4124-af32-4c6b57c9d208_872x697.png 1272w, https://substackcdn.com/image/fetch/$s_!jDFu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86c7af79-ccc7-4124-af32-4c6b57c9d208_872x697.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Two things jump out immediately:</p><p><strong>The baseline is remarkably consistent.</strong> On quiet days, you&#8217;re looking at ~2,500 requests from 300&#8211;400 unique IPs. This is the internet&#8217;s ambient scanning noise, distributed across many sources running standard checklists. Your average exposed service gets probed roughly this much every single day whether you notice or not.</p><p><strong>The spikes tell a different story.</strong> January 5th saw a 6x volume surge driven by just three AWS-based /24 networks (13.59.55.0/24, 54.234.91.0/24, 54.175.183.0/24) running what appears to be coordinated broad enumeration. January 7th was even more dramatic &#8212; a single /24 (144.91.101.0/24) fired off 19,873 requests in 24 hours, cycling through nearly 20,000 unique URI paths. That&#8217;s one scanner working through a massive filename permutation list of backup files, config artifacts, and secret files across /api, /admin, /core, and /backup prefixes.</p><p>The contrast matters: Jan 7 had only 44 unique IPs but 20,000 unique URIs. A typical day has 350+ IPs but only 500&#8211;700 URIs. The spike wasn&#8217;t a DDoS &#8212; it was a single, methodical scanner running a very large dictionary. And honestly that&#8217;s just what the data showed because I hadn&#8217;t expected to get that many hits and logs were truncated to 20,000 lines.</p><div><hr></div><h2><strong>What They&#8217;re Actually Hunting For</strong></h2><p>Here&#8217;s where it gets actionable. Across 16 days, I classified every URI into families based on what technology or misconfiguration it targets. The top 10 families by total volume:</p><h3><strong>1. Environment Files &amp; Secrets &#8212; 12,365 hits (every single day)</strong></h3><p><strong>Paths:</strong> <code>/.env</code>, <code>/config.zip</code>, <code>/app/.env</code>, <code>/.env.ts</code>, <code>/api/env.zip</code>, <code>/.aws/credentials</code>, <code>/assets/credentials.json</code></p><p>This was the single most persistent category across the entire observation window. Every single day, scanners checked for exposed dotenv files, config archives, and cloud credential artifacts. The Jan 7 spike included 8,438 env-family requests alone &#8212; a massive run through <code>.env</code> path permutations.</p><p>The scanner toolkits aren&#8217;t just checking <code>/.env</code> anymore. Isaw probes for <code>.env.ts</code>, <code>.env.production</code>, <code>env.zip</code>, and even <code>/.aws/credentials</code> and <code>/.aws/config</code>. They&#8217;re adapting to modern deployment patterns.</p><p><strong>Hunt angle:</strong> If your org deploys to cloud infrastructure, check your external attack surface for any 200 responses to dotenv paths. One exposed <code>.env</code> file is a full credential compromise. Also worth hunting for any CI/CD pipelines that might accidentally publish these to web roots.</p><h3><strong>2. Application Files &amp; PHP Supply Chain &#8212; 10,903 hits (15 of 16 days)</strong></h3><p><strong>Paths:</strong> <code>/vendor/phpunit/phpunit/src/util/php/eval-stdin.php</code>, <code>/vendor/phpunit/phpunit/util/php/eval-stdin.php</code></p><p>Legacy PHP supply chain exploitation is alive and well. The phpunit <code>eval-stdin.php</code> path &#8212; a file that shouldn&#8217;t exist in production but does when vendor directories are accidentally web-accessible &#8212; was one of the most consistently probed targets. Multiple path variants are checked simultaneously, suggesting scanner dictionaries include known path permutations across different phpunit versions.</p><p>Beyond phpunit, this family includes broad <code>.php</code>, <code>.asp</code>, <code>.aspx</code>, <code>.jsp</code> probing, effectively fingerprinting what server-side technologies are present.</p><p><strong>Hunt angle:</strong> Check for web-accessible <code>/vendor/</code> directories in any PHP deployments. If phpunit eval-stdin is reachable, you have RCE. Also audit your build pipelines &#8212; do they strip vendor/test directories from production artifacts?</p><h3><strong>3. Backup File &amp; Config Artifact Enumeration &#8212; 6,500+ hits (concentrated spikes)</strong></h3><p><strong>Paths:</strong> <code>/api/error.bak</code>, <code>/admin/backup/database.bak</code>, <code>/core/backup/database.conf</code>, <code>/backup/database.cfg</code></p><p>The January 7th scanner drove this almost entirely. It systematically checked <code>/api</code>, <code>/admin</code>, <code>/core</code>, and <code>/backup</code> prefixes combined with backup extensions (<code>.bak</code>, <code>.cfg</code>, <code>.conf</code>, <code>.old</code>, <code>.save</code>, <code>.sql</code>). The approach was pure permutation &#8212; take common directory prefixes, combine with common sensitive filenames, append every backup extension in the book.</p><p>This is a numbers game. Across thousands of targets, even a tiny percentage of accidentally published database backups or config files yields immediate credential access.</p><p><strong>Hunt angle:</strong> Scan your own web roots for backup extension files. Any <code>.bak</code>, <code>.sql</code>, <code>.old</code>, <code>.cfg</code> file accessible via HTTP is a finding. Add deny rules at your web server/WAF layer for these extensions globally.</p><h3><strong>4. Login &amp; Authentication Surface Discovery &#8212; 2,262 hits (10 days)</strong></h3><p><strong>Paths:</strong> <code>/login</code>, <code>/api/login</code>, <code>/signin</code>, <code>/auth</code>, <code>/core/skin/login.aspx</code>, <code>/owa/auth/logon.aspx</code></p><p>Scanners are cataloging what authentication endpoints exist &#8212; not (yet) brute-forcing them, but mapping the surface. Isaw probes for generic login paths alongside specific product surfaces: ASP.NET login forms, Outlook Web Access, and API authentication endpoints.</p><p><strong>Hunt angle:</strong> This is reconnaissance. If these endpoints exist in your environment, ensure MFA is enforced, rate limiting is in place, and you&#8217;re monitoring for the credential stuffing that follows discovery.</p><h3><strong>5. Git Repository Exposure &#8212; 686 hits (13 of 16 days)</strong></h3><p><strong>Paths:</strong> <code>/.git/config</code>, <code>/.git/index</code>, <code>/.git/info/refs</code></p><p>Persistent, steady, and high-impact. Git exposure was checked almost every day with above-baseline emphasis. If <code>/.git/config</code> returns 200, an attacker can reconstruct your entire source code repository, including hardcoded secrets, internal API endpoints, and deployment configurations.</p><p><strong>Hunt angle:</strong> This is one of the easiest wins for external attack surface validation. Test your own internet-facing services for <code>/.git/config</code> access. Block all dotfile directories at the web server level.</p><h3><strong>6. WordPress &#8212; 551 hits (7 days)</strong></h3><p><strong>Paths:</strong> <code>/wp-config.php.bak</code>, <code>/wp-content/w3tc-config/master-preview.php</code>, <code>/xmlrpc.php</code>, <code>/wp-admin</code>, <code>/wp-login.php</code></p><p>WordPress scanning came in waves, not constantly. When it appeared, it focused on configuration file backups (<code>wp-config.php.bak</code>, <code>wp-config.php.old</code>) and known vulnerable plugin paths rather than just login brute-forcing.</p><h3><strong>7. Dev-Server / Vite File Read (</strong><code>/@fs/</code><strong>) &#8212; 350 hits (3 days, sharp spikes)</strong></h3><p><strong>Paths:</strong> <code>/@fs/etc/passwd?import=</code>, <code>/@fs/.docker.env?import=</code>, <code>/@fs/proc/self/environ?raw??=</code></p><p>This was one of the more interesting findings. The <code>/@fs/</code> pattern targets <strong>Vite dev server</strong> file-read vulnerabilities (CVE-2023-34092 and related). When a Vite dev server is accidentally exposed to the internet, the <code>/@fs/</code> prefix can read arbitrary files from the host filesystem.</p><p>The scanners were specifically targeting <code>/etc/passwd</code>, <code>.docker.env</code>, and <code>/proc/self/environ</code> through this path &#8212; all high-value for credential harvesting or container escape.</p><p><strong>Hunt angle:</strong> This is a great detection engineering target. Any production system responding to <code>/@fs/</code> requests has a dev server exposed. Hunt for Vite or similar dev servers bound to 0.0.0.0 in production environments. The <code>?import=</code> query parameter is highly specific and makes a clean detection signature.</p><h3><strong>8. Citrix Gateway (</strong><code>/+cscoe+/</code><strong>, </strong><code>/+cscol+/</code><strong>) &#8212; 201 hits (6 days)</strong></h3><p><strong>Paths:</strong> <code>/+cscoe+/logon.html</code>, <code>/+cscoe+/logon_forms.js</code>, <code>/+cscol+/java.jar</code></p><p>Perimeter device fingerprinting for Cisco/Citrix gateways. Consistent low-volume probing to identify if these appliances exist and are reachable. Once fingerprinted, follow-on exploitation of known CVEs is the playbook.</p><h3><strong>9. AI/LLM API Endpoint Discovery &#8212; 140 hits (appeared Jan 8)</strong></h3><p><strong>Paths:</strong> <code>/v1/messages</code>, <code>/v1/chat/completions</code>, <code>/openai/v1/chat/completions</code>, <code>/openai/deployments/gpt-4/chat/completions?api-version=2024-02-15-preview</code></p><p>This one caught my attention. Starting January 8th, Iobserved scanners probing for <strong>exposed LLM API endpoints</strong> &#8212; checking for OpenAI-compatible and Anthropic-style API paths. The requests targeted both generic paths (<code>/v1/chat/completions</code>) and Azure OpenAI deployment-specific paths with version parameters.</p><p>This is a relatively new addition to scanner dictionaries. Exposed LLM API proxies represent a direct financial risk (token theft/abuse) and a potential data exfiltration vector if the API has access to internal knowledge bases or RAG systems.</p><p><strong>Hunt angle:</strong> Search your environment for any services exposing <code>/v1/chat/completions</code> or <code>/v1/messages</code> to the internet without authentication. If you run LLM inference proxies, API gateways, or development endpoints, confirm they&#8217;re not accidentally internet-facing. This is a fresh hunting target that most orgs probably aren&#8217;t monitoring for yet.</p><h3><strong>10. Management Surfaces &#8212; Steady Background</strong></h3><p>Across the 16 days, Ialso saw consistent probing for:</p><ul><li><p><strong>Spring Boot Actuator</strong> (<code>/actuator</code>, <code>/actuator/gateway/routes</code>, <code>/env</code>, <code>/health</code>) &#8212; 118 hits across 6 days</p></li><li><p><strong>Docker Remote API</strong> (<code>/containers/json</code>) &#8212; 57 hits across 5 days</p></li><li><p><strong>Tomcat Manager</strong> (<code>/manager/text/list</code>, <code>/manager/html</code>) &#8212; 45 hits across 5 days</p></li><li><p><strong>GeoServer</strong> (<code>/geoserver/web</code>) &#8212; 29 hits across 2 days</p></li><li><p><strong>Trend Micro OfficeScan</strong> (<code>/officescan/console/cgi/cgichkmasterpwd.exe</code>) &#8212; appeared once</p></li></ul><p>Each of these individually is low volume. Collectively, they represent scanners maintaining checklists of management interfaces that, when exposed, provide immediate administrative access or sensitive configuration disclosure.</p><div><hr></div><h2></h2><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/p/vibe-coding-the-holidays-away?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading THOR Collective Dispatch! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/p/vibe-coding-the-holidays-away?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://dispatch.thorcollective.com/p/vibe-coding-the-holidays-away?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><h2><strong><br><br>The Scanner Ecosystem</strong></h2><h3><strong>Source Concentration</strong></h3><p>One of the clearest patterns was how <strong>source-concentrated</strong> the traffic was. The top 5 source networks accounted for the vast majority of requests:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Gtp5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29a19f4f-a27f-40e9-ad49-d138c22cec0f_813x338.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Gtp5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29a19f4f-a27f-40e9-ad49-d138c22cec0f_813x338.png 424w, https://substackcdn.com/image/fetch/$s_!Gtp5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29a19f4f-a27f-40e9-ad49-d138c22cec0f_813x338.png 848w, https://substackcdn.com/image/fetch/$s_!Gtp5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29a19f4f-a27f-40e9-ad49-d138c22cec0f_813x338.png 1272w, https://substackcdn.com/image/fetch/$s_!Gtp5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29a19f4f-a27f-40e9-ad49-d138c22cec0f_813x338.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Gtp5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29a19f4f-a27f-40e9-ad49-d138c22cec0f_813x338.png" width="813" height="338" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/29a19f4f-a27f-40e9-ad49-d138c22cec0f_813x338.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:338,&quot;width&quot;:813,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:39134,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dispatch.thorcollective.com/i/192687506?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29a19f4f-a27f-40e9-ad49-d138c22cec0f_813x338.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Gtp5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29a19f4f-a27f-40e9-ad49-d138c22cec0f_813x338.png 424w, https://substackcdn.com/image/fetch/$s_!Gtp5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29a19f4f-a27f-40e9-ad49-d138c22cec0f_813x338.png 848w, https://substackcdn.com/image/fetch/$s_!Gtp5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29a19f4f-a27f-40e9-ad49-d138c22cec0f_813x338.png 1272w, https://substackcdn.com/image/fetch/$s_!Gtp5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29a19f4f-a27f-40e9-ad49-d138c22cec0f_813x338.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The Jan 5 spike was three AWS /24s working together &#8212; likely a single operator using EC2 instances for distributed scanning. The Jan 7 spike was a single Contabo-hosted /24 running a much larger, more comprehensive dictionary against fewer targets.</p><p>Background noise comes from a rotating cast of 300&#8211;400 IPs per day, mostly running shorter, more focused checklists. The heavy hitters are episodic and concentrated.</p><h3><strong>Scanner Dictionary Evolution</strong></h3><p>Day-over-day, Itracked which URI families appeared as &#8220;new&#8221; &#8212; never seen before in the observation window. The pattern suggests scanner operators are <strong>actively refreshing their dictionaries</strong>:</p><ul><li><p><strong>Jan 1:</strong> Tomcat Manager, <code>.well-known/security.txt</code></p></li><li><p><strong>Jan 4:</strong> WordPress probing increase, <code>/@fs/</code> dev-server pattern appears</p></li><li><p><strong>Jan 5:</strong> Broad enumeration surge with <code>/@fs/</code> and secrets emphasis</p></li><li><p><strong>Jan 7:</strong> Massive backup/config permutation sweep (<code>/api</code>, <code>/admin</code>, <code>/core</code>, <code>/backup</code>)</p></li><li><p><strong>Jan 8:</strong> AI/LLM API endpoints (<code>/v1/messages</code>, <code>/openai/*</code>) appear for the first time</p></li><li><p><strong>Jan 11:</strong> GeoServer, OfficeScan fingerprinting</p></li><li><p><strong>Jan 12:</strong> Docker API, Exchange ECP export tool, AWS credential files</p></li><li><p><strong>Jan 14:</strong> VoIP/Polycom provisioning config fetches, embedded device login forms (<code>/boaform/admin/formlogin</code>)</p></li><li><p><strong>Jan 16:</strong> Increased Spring Actuator and embedded admin path checks</p></li></ul><p>The LLM endpoint probing starting Jan 8 is particularly notable &#8212; it suggests these scanning tools are being updated to reflect the current technology landscape, not just running stale lists from 2020.</p><div><hr></div><h2><strong>Defensive Takeaways</strong></h2><p>If you&#8217;re building hunts or hardening your environment based on this data, here&#8217;s where to start:</p><p><strong>Quick wins (external attack surface):</strong></p><ul><li><p>Block dotfile access (<code>/.env</code>, <code>/.git/*</code>, <code>/.aws/*</code>) at the edge. If any of these return 200 from your infrastructure, treat it as a confirmed finding.</p></li><li><p>Deny backup extensions (<code>.bak</code>, <code>.old</code>, <code>.cfg</code>, <code>.conf</code>, <code>.save</code>, <code>.sql</code>) across all web-accessible paths.</p></li><li><p>Validate that <code>/vendor/</code> directories are not web-accessible in PHP deployments.</p></li></ul><p><strong>Detection engineering targets:</strong></p><ul><li><p><code>/@fs/</code> requests with <code>?import=</code> parameter &#8212; highly specific Vite dev-server file read indicator.</p></li><li><p><code>/v1/chat/completions</code> or <code>/v1/messages</code> on unexpected hosts &#8212; exposed LLM infrastructure.</p></li><li><p><code>/containers/json</code> &#8212; Docker Remote API exposure check.</p></li><li><p><code>/actuator/gateway/routes</code> &#8212; Spring Cloud Gateway route disclosure.</p></li><li><p><code>/proc/self/environ</code> &#8212; local file read validation attempt.</p></li></ul><p><strong>Hunt hypotheses:</strong></p><ul><li><p>Are any internal dev servers (Vite, webpack-dev-server, Next.js dev mode) accidentally bound to external interfaces?</p></li><li><p>Do any CI/CD pipelines publish <code>.env</code>, <code>.git</code>, or vendor test directories to production web roots?</p></li><li><p>Are LLM API proxies, inference endpoints, or development servers exposed without authentication?</p></li><li><p>Are any Spring Boot services running with Actuator endpoints exposed and unauthenticated?</p></li></ul><div><hr></div><h2><strong>Methodology Notes</strong></h2><p>The honeypots were nginx instances forwarding all access logs to a centralized Loki instance via Grafana&#8217;s log aggregation stack. A daily Python analysis pipeline pulled the raw logs, classified URIs into technology families using regex-based rules, tracked source IP concentrations at the /24 level (to capture infrastructure patterns), and generated structured threat models with day-over-day delta analysis.</p><p>Request counts were capped at 20,000 per 24-hour window and 40,000 per 7-day window in the collection pipeline, meaning actual volumes on spike days (particularly Jan 5 and Jan 7) may have been higher than reported. The 16-day observation window provides a useful snapshot but shouldn&#8217;t be treated as a comprehensive survey &#8212; regional and temporal variation in scanning patterns is expected.</p><p>The raw data and analysis pipeline are available for anyone interested in replicating or extending this work. Reach out if you want to compare notes. Attached is also my github projects with the code so you can deploy this yourself!</p><p><a href="https://github.com/eliwoodward/Holiday-Honeypot-Vibecoded/tree/main">https://github.com/eliwoodward/Holiday-Honeypot-Vibecoded/tree/main</a></p><div><hr></div><p><em>Happy thrunting.</em> &#128293;<br><br></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/p/vibe-coding-the-holidays-away/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://dispatch.thorcollective.com/p/vibe-coding-the-holidays-away/comments"><span>Leave a comment</span></a></p>]]></content:encoded></item><item><title><![CDATA[All Roads Lead to Where You Already Are]]></title><description><![CDATA[The Unofficial Declassified Cybersecurity Beginner&#8217;s Guide]]></description><link>https://dispatch.thorcollective.com/p/all-roads-lead-to-where-you-already-are</link><guid isPermaLink="false">https://dispatch.thorcollective.com/p/all-roads-lead-to-where-you-already-are</guid><dc:creator><![CDATA[Isabella Sparks]]></dc:creator><pubDate>Tue, 10 Mar 2026 17:44:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ruqP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74819ddb-49b3-4539-984f-3c537123f9bf_500x500.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h3><strong>print(&#8220;Welcome to Part II&#8221;)</strong></h3><p>Annnnnnnddddd, we&#8217;re back. If you&#8217;ve been following along, you may be a career existentialist! Congratulations, you&#8217;re in good company.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ejkb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1df44150-5c95-4908-9255-e8d18c1bb853_1138x1114.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ejkb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1df44150-5c95-4908-9255-e8d18c1bb853_1138x1114.png 424w, https://substackcdn.com/image/fetch/$s_!Ejkb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1df44150-5c95-4908-9255-e8d18c1bb853_1138x1114.png 848w, https://substackcdn.com/image/fetch/$s_!Ejkb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1df44150-5c95-4908-9255-e8d18c1bb853_1138x1114.png 1272w, https://substackcdn.com/image/fetch/$s_!Ejkb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1df44150-5c95-4908-9255-e8d18c1bb853_1138x1114.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ejkb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1df44150-5c95-4908-9255-e8d18c1bb853_1138x1114.png" width="576" height="563.8523725834798" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1df44150-5c95-4908-9255-e8d18c1bb853_1138x1114.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1114,&quot;width&quot;:1138,&quot;resizeWidth&quot;:576,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ejkb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1df44150-5c95-4908-9255-e8d18c1bb853_1138x1114.png 424w, https://substackcdn.com/image/fetch/$s_!Ejkb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1df44150-5c95-4908-9255-e8d18c1bb853_1138x1114.png 848w, https://substackcdn.com/image/fetch/$s_!Ejkb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1df44150-5c95-4908-9255-e8d18c1bb853_1138x1114.png 1272w, https://substackcdn.com/image/fetch/$s_!Ejkb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1df44150-5c95-4908-9255-e8d18c1bb853_1138x1114.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In <a href="https://dispatch.thorcollective.com/p/the-more-i-learn-the-less-i-know">Part I</a> of this guide, we talked about recognizing the cycle we find ourselves in when first considering a career in cybersecurity. Forcing ourselves to answer questions we don&#8217;t have enough context to ask, shaming ourselves for not knowing everything immediately, being fatigued by a surplus of varying resources&#8230;</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">THOR Collective Dispatch is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>You&#8217;re here because you found security and you have an itch to scratch. Perhaps you met a security engineer, were inspired by research that you happened upon, felt that it was time for a change, or always wanted to enter the industry but never knew how. Or, perhaps, it is what the legends foretold and this field was always going to find you :)</p><p>Regardless of how you got here - the questions running through your head are indeed universal, and the most common answers are isolating. Let&#8217;s dive into how you can take control of this journey and break the cycle that has been holding you back from being the badass security engineer you are meant to be.</p><h3><strong>^Ctrl + C: Breaking the Loop</strong></h3><p><em>Stopping the Spiral Before It Stops You</em></p><ul><li><p><strong>Recognize the Pattern: </strong>The 7-step cycle from Part I isn&#8217;t productive learning - it&#8217;s anxiety masquerading as research. As soon as you recognize the existential loop starting, take a step away, get some fresh air, and give your mind a moment to breathe.</p></li><li><p><strong>Set a Timer:</strong> Literally. Give yourself 30 minutes and the grace to explore a rabbit hole, then force yourself to kill the process, realign, and refocus on the original task at hand.</p></li><li><p><strong>Ask Different Questions:</strong> Not &#8220;where do I fit in all of cybersecurity?&#8221; but &#8220;what problem do I want to solve right now?&#8221;</p></li></ul><h3><strong>chmod +x: Anticipating the Paralysis and Executing Accordingly</strong></h3><p><strong>When You Don&#8217;t Know Where to Start:</strong></p><ul><li><p><strong>Listen to Yourself: </strong>Pick the topic that made you feel something (curiosity, anger, excitement) most recently. I probably spent too much time trying to perfect the right topic for me &#8211; there is no correct answer; even seasoned security professionals take different paths before finding the thing that sticks.</p></li><li><p><strong>Do the Boring Stuff First:</strong> Can&#8217;t decide between malware research or threat hunting? Start with a basic tutorial; memorizing the advanced framework will do you no good, yet.</p></li><li><p><strong>Start a 2-Week Experiment:</strong> &#8220;I&#8217;m trying X for two weeks&#8221; is far less intimidating than &#8220;I&#8217;m committing to Y forever.&#8221;</p></li></ul><p><strong>When Imposter Syndrome Hits:</strong></p><ul><li><p><strong>Take Notes:</strong> Document what you <em>did</em> learn, <strong>not</strong> what you think you <em>should</em> know.</p></li><li><p><strong>Don&#8217;t Be Afraid to Ask Questions:</strong> Remember when not knowing something was fine? When you could just... ask? Somewhere between elementary school and now, we convinced ourselves that curiosity makes us look stupid. Of course you don&#8217;t know the latest IOC from last week&#8217;s attack. That&#8217;s okay! Understanding what IOCs are and why they matter will take you further than memorizing specific indicators that&#8217;ll be irrelevant in a month anyway.</p></li><li><p><strong>Network:</strong> This may be one of the strongest ways to challenge your imposter syndrome. Find one person who&#8217;s one (or a few) steps ahead of you and ask them a specific question. Have an industry leader you&#8217;re inspired by? Send them a message &#8211; I promise it&#8217;s worth pushing past the fear.</p></li><li><p><strong>Trust Yourself:</strong> You don&#8217;t need to be an expert to contribute. Curiosity and a passion for sharing knowledge are essential. The industry desperately needs new perspectives - yours included.</p></li></ul><p><strong>When Self-Doubt Creeps In:</strong></p><ul><li><p><strong>Reframe:</strong> &#8220;I don&#8217;t understand this yet&#8221; vs. &#8220;I&#8217;ll never understand this.&#8221; Every senior threat researcher was once someone staring at their first PCAP file with no idea what they were looking at. The difference isn&#8217;t talent &#8211; it&#8217;s persistence&#8230; the good kind ;)</p></li><li><p><strong>Build in Public:</strong> Leverage GitHub, Notion, CTF Time, TryHackMe, Hack The Box, and other platforms to record and share what you&#8217;ve learned, including projects or even an all-encompassing (and maybe slightly wordy) README.md, keeping track of the way you&#8217;ve managed your minutes. Not only will this help you show others what you&#8217;ve been up to, but it will also <em>keep you organized.</em></p></li><li><p><strong>Record Your Wins:</strong> Every small breakthrough, every solved challenge, every lightbulb moment deserves to be celebrated. Don&#8217;t let your instinct force you to finish one thing and barely breathe into the next &#8211; slow down and celebrate progress.</p></li></ul><h3><strong>The Moving Target Mindset</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AGNi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe80f75d-87f2-48d0-96b3-8618fa0e9a7c_250x263.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AGNi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe80f75d-87f2-48d0-96b3-8618fa0e9a7c_250x263.jpeg 424w, https://substackcdn.com/image/fetch/$s_!AGNi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe80f75d-87f2-48d0-96b3-8618fa0e9a7c_250x263.jpeg 848w, https://substackcdn.com/image/fetch/$s_!AGNi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe80f75d-87f2-48d0-96b3-8618fa0e9a7c_250x263.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!AGNi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe80f75d-87f2-48d0-96b3-8618fa0e9a7c_250x263.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AGNi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe80f75d-87f2-48d0-96b3-8618fa0e9a7c_250x263.jpeg" width="250" height="263" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fe80f75d-87f2-48d0-96b3-8618fa0e9a7c_250x263.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:263,&quot;width&quot;:250,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AGNi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe80f75d-87f2-48d0-96b3-8618fa0e9a7c_250x263.jpeg 424w, https://substackcdn.com/image/fetch/$s_!AGNi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe80f75d-87f2-48d0-96b3-8618fa0e9a7c_250x263.jpeg 848w, https://substackcdn.com/image/fetch/$s_!AGNi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe80f75d-87f2-48d0-96b3-8618fa0e9a7c_250x263.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!AGNi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe80f75d-87f2-48d0-96b3-8618fa0e9a7c_250x263.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Remember the knowledge depreciation problem?</em></p><p>Here&#8217;s the reality: fundamentals outlive tools every single time.</p><p>Python syntax changes. SIEM platforms get replaced. Specific CVEs become irrelevant. But understanding how to think like an attacker, how to correlate disparate data points, how to ask better questions &#8211; these don&#8217;t expire.</p><p>The mechanics of social engineering remain consistent even as delivery methods evolve. Network protocols evolve, sure, but how systems fundamentally communicate? That&#8217;s not going anywhere.</p><p>When you&#8217;re choosing what to learn, <em>prioritize concepts over implementations</em>. Learn <em>why</em> security engineering works, not just <em>how</em> different platforms approach a problem. Understand <em>what</em> makes OSINT effective, not just <em>which</em> tools are popular this year. The tools will change. Your ability to adapt is what will set you apart and help you grow alongside the field.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NwKu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F365b9d54-f672-4956-8aef-984255a79fe5_882x578.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NwKu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F365b9d54-f672-4956-8aef-984255a79fe5_882x578.jpeg 424w, https://substackcdn.com/image/fetch/$s_!NwKu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F365b9d54-f672-4956-8aef-984255a79fe5_882x578.jpeg 848w, https://substackcdn.com/image/fetch/$s_!NwKu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F365b9d54-f672-4956-8aef-984255a79fe5_882x578.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!NwKu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F365b9d54-f672-4956-8aef-984255a79fe5_882x578.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NwKu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F365b9d54-f672-4956-8aef-984255a79fe5_882x578.jpeg" width="882" height="578" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/365b9d54-f672-4956-8aef-984255a79fe5_882x578.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:578,&quot;width&quot;:882,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;A person in a suit and tie\n\nAI-generated content may be incorrect.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="A person in a suit and tie

AI-generated content may be incorrect." title="A person in a suit and tie

AI-generated content may be incorrect." srcset="https://substackcdn.com/image/fetch/$s_!NwKu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F365b9d54-f672-4956-8aef-984255a79fe5_882x578.jpeg 424w, https://substackcdn.com/image/fetch/$s_!NwKu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F365b9d54-f672-4956-8aef-984255a79fe5_882x578.jpeg 848w, https://substackcdn.com/image/fetch/$s_!NwKu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F365b9d54-f672-4956-8aef-984255a79fe5_882x578.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!NwKu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F365b9d54-f672-4956-8aef-984255a79fe5_882x578.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>Spiral vs. Progress: Knowing the Difference</strong></h3><p>Not all rabbit holes are bad. Some lead to breakthroughs. Here&#8217;s how to tell the difference:</p><p><strong>You&#8217;re in a productive learning spiral if:</strong></p><ul><li><p>You&#8217;re actively doing something (writing code, solving a challenge, building a project).</p></li><li><p>Each new question brings you closer to answering your original one.</p></li><li><p>You&#8217;re uncomfortable but engaged, not existential.</p></li></ul><p><strong>You&#8217;re in a paralysis spiral if:</strong></p><ul><li><p>You&#8217;re reading <em>about</em> learning more than actually learning.</p></li><li><p>You&#8217;ve opened 23 tabs but haven&#8217;t finished any of them.</p></li><li><p>The overwhelm is growing, not shrinking.</p></li><li><p>You feel more confused than when you started.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ruqP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74819ddb-49b3-4539-984f-3c537123f9bf_500x500.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ruqP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74819ddb-49b3-4539-984f-3c537123f9bf_500x500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ruqP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74819ddb-49b3-4539-984f-3c537123f9bf_500x500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ruqP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74819ddb-49b3-4539-984f-3c537123f9bf_500x500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ruqP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74819ddb-49b3-4539-984f-3c537123f9bf_500x500.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ruqP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74819ddb-49b3-4539-984f-3c537123f9bf_500x500.jpeg" width="500" height="500" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/74819ddb-49b3-4539-984f-3c537123f9bf_500x500.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:500,&quot;width&quot;:500,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ruqP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74819ddb-49b3-4539-984f-3c537123f9bf_500x500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ruqP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74819ddb-49b3-4539-984f-3c537123f9bf_500x500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ruqP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74819ddb-49b3-4539-984f-3c537123f9bf_500x500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ruqP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74819ddb-49b3-4539-984f-3c537123f9bf_500x500.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The spiral doesn&#8217;t make you a failure. It makes you human. Curiosity is an essential trait for a threat intelligence; but, there&#8217;s a difference between structured investigations and unproductive rabbit holes. The former solves problems; the latter just feels like work and often leads to burn out. So, reader, if you have 23 tabs open, ask yourself &#8220;am I getting closer to an answer, or am I just scrolling?&#8221; - let the answer redirect you accordingly.</p><h3><strong>Exit 0</strong></h3><p>You will always feel behind, and at first, you&#8217;ll feel uncertain too. The goal isn&#8217;t to eliminate that uncertainty &#8211; it&#8217;s to function despite it. The field will always move faster than anyone can keep up. Tools will become obsolete. Frameworks will evolve. Threat actors will pivot.</p><p>And you&#8217;ll keep learning anyway.</p><p>Not because you&#8217;ve found the perfect path or the right specialization or finally feel qualified. But because you chose to start somewhere and then keep going. The geolocation CTF at 2 AM. The MITRE technique you finally understood. The first time a detection rule you wrote actually caught something. The GitHub project gaining traction, stars &amp; contributions&#8230;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PlXD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd951ee1-0ab4-4b0f-8654-506a512b7adb_562x446.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PlXD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd951ee1-0ab4-4b0f-8654-506a512b7adb_562x446.png 424w, https://substackcdn.com/image/fetch/$s_!PlXD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd951ee1-0ab4-4b0f-8654-506a512b7adb_562x446.png 848w, https://substackcdn.com/image/fetch/$s_!PlXD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd951ee1-0ab4-4b0f-8654-506a512b7adb_562x446.png 1272w, https://substackcdn.com/image/fetch/$s_!PlXD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd951ee1-0ab4-4b0f-8654-506a512b7adb_562x446.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PlXD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd951ee1-0ab4-4b0f-8654-506a512b7adb_562x446.png" width="562" height="446" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cd951ee1-0ab4-4b0f-8654-506a512b7adb_562x446.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:446,&quot;width&quot;:562,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;A yellow star with black text\n\nAI-generated content may be incorrect.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="A yellow star with black text

AI-generated content may be incorrect." title="A yellow star with black text

AI-generated content may be incorrect." srcset="https://substackcdn.com/image/fetch/$s_!PlXD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd951ee1-0ab4-4b0f-8654-506a512b7adb_562x446.png 424w, https://substackcdn.com/image/fetch/$s_!PlXD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd951ee1-0ab4-4b0f-8654-506a512b7adb_562x446.png 848w, https://substackcdn.com/image/fetch/$s_!PlXD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd951ee1-0ab4-4b0f-8654-506a512b7adb_562x446.png 1272w, https://substackcdn.com/image/fetch/$s_!PlXD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd951ee1-0ab4-4b0f-8654-506a512b7adb_562x446.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>These wins prove you can move forward even on a day when it feels like you&#8217;ve taken 10 steps back.</p><p>So, pick something. Anything. Give yourself two weeks. Then pick something else if you need to. The paralysis wants you to believe that choosing wrong is worse than not choosing at all. It&#8217;s lying.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">THOR Collective Dispatch is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[How I use LLMs For Security Work: Part 2]]></title><description><![CDATA[I previously wrote a blog for THOR Collective Dispatch about some basic examples of different approaches when it comes to LLMs.]]></description><link>https://dispatch.thorcollective.com/p/how-i-use-llms-for-security-work-e7f</link><guid isPermaLink="false">https://dispatch.thorcollective.com/p/how-i-use-llms-for-security-work-e7f</guid><dc:creator><![CDATA[Josh Rickard]]></dc:creator><pubDate>Thu, 05 Mar 2026 15:03:21 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!s-ZJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af5dc56-8746-4b91-ac53-7779eaeaad7b_2816x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!s-ZJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af5dc56-8746-4b91-ac53-7779eaeaad7b_2816x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!s-ZJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af5dc56-8746-4b91-ac53-7779eaeaad7b_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!s-ZJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af5dc56-8746-4b91-ac53-7779eaeaad7b_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!s-ZJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af5dc56-8746-4b91-ac53-7779eaeaad7b_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!s-ZJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af5dc56-8746-4b91-ac53-7779eaeaad7b_2816x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!s-ZJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af5dc56-8746-4b91-ac53-7779eaeaad7b_2816x1536.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5af5dc56-8746-4b91-ac53-7779eaeaad7b_2816x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:9336181,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://dispatch.thorcollective.com/i/189795560?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af5dc56-8746-4b91-ac53-7779eaeaad7b_2816x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!s-ZJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af5dc56-8746-4b91-ac53-7779eaeaad7b_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!s-ZJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af5dc56-8746-4b91-ac53-7779eaeaad7b_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!s-ZJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af5dc56-8746-4b91-ac53-7779eaeaad7b_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!s-ZJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af5dc56-8746-4b91-ac53-7779eaeaad7b_2816x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>I previously wrote a blog for THOR Collective Dispatch about some basic examples of different approaches when it comes to LLMs. It was cool and I hope it truly helps those starting out but I wanted to follow up and share some other more specific examples, including more &#8220;advanced&#8221; patterns that have worked for me over the past year or so.</p><p>We&#8217;ve all seen the scope, complexity and rise of usage of LLMs from products which integrate them, to all new product categories to ClawdBot. If you&#8217;re not familiar with all the facets of LLMs that&#8217;s okay but before I dive into these more advanced use cases, I think it&#8217;s advantageous to understand some terminology (at a high-level) when it comes to LLMs.</p><p>Once we have a firm grasp on these different concepts, I will provide some more concrete examples of how I have used LLMs in the past.</p><h2>Terminology</h2><p>This section defines some common (current) concepts related to LLMs but really, they are just Markdown with the exception that Assistants also may include code.</p><h3>Prompting</h3><p>Really this is exactly what I wrote about in my previous blog. In this approach/use you provide statement(s), with some minimal context, maybe some general requirements and either a question or a problem statement.</p><p>I&#8217;ve seen vibe coding thrown around but never cared to look it up but my understanding is that it&#8217;s either using speech to text and just describing your problems or just typing it out listening to some JL or Joey Cool (my current vibe). Often, I believe this approach of question, answer, fix, validate, test, fix, etc. is painful and can go awry pretty quick depending on the client used.</p><p>Vibe coding maybe useful for some but where the real work will happen in our industry will be in the trenches. You must know how to describe the problem you are trying to solve, which requires you to intimately know the problem.</p><h3>Agents</h3><p>Agents are the next &#8220;level&#8221; where there is very precise context given to an LLM. This context (which is really what this post is about) is about providing the guardrails for a request. Some provide this context in form of documentation, use cases, hard and loose requirements, gotchas, what not to do, perspectives including situational awareness statements and more. This can be 1,000-word document referencing 1 or 500 other documents to a single 50K (or more) prompt and typically includes extremely detailed descriptions, when to consider alternative options and especially negations of decisions.</p><h4>SKILLS.md</h4><p>Skills (e.g. SKILLS.md) are markdown files that essentially take everything a team knows about how to perform an action and writes a document that then feeds into an agent for absolute context, decision making, etc. These are almost identical to <code>agents</code> but I&#8217;ll let others decide where the naming concepts go.</p><h4>Workflows</h4><p>Workflows are like skills, but these are supposed to be directions for an LLM on how they should &#8220;analyze&#8221; or &#8220;examine&#8221; or &#8220;perform&#8221; the task being asked. For example, how to investigate an alert may have 1 or 15 steps defined including which tools (MCPs), how to interrupt results and how to make decisions before moving on to the next phase of the workflow.</p><p>I like to think of workflows in the same way we define/document playbooks but in markdown. I think a good starting place for more mature organizations would be to embed their existing incident response documentation and response playbooks into their Agents and/or Assistants. Iterate and go wild from there.</p><h3>Assistants</h3><p>This is the &#8220;newest&#8221; evolution (that I&#8217;m aware of) and I believe is where we are headed as an industry. Assitants are multi-faceted, customized and curated to tackle problems both big and small. These are the combination of multiple Workflows which trigger defined SKILLS.md and tools (MCP servers) and use multiple discrete agents to perform tasks along the way.</p><p>These are larger projects that allow someone to hook into how an LLM is called (via it&#8217;s API) - for example, this is how one such project called PAI works (btw, Daniel is definitely onto something here). These hooks are used to control the flow of operations all described in text and past decisions. It&#8217;s quite interesting but nuanced.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">THOR Collective Dispatch is a reader-supported publication. To receive new posts and support our work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>Context Is Key</h2><p>I know that&#8217;s a lot, but really the first thing you need to understand is that this is really just all text/Markdown files. Instead of designing and defining how to communicate with a services APIs using some abstraction integration pattern, you can provide the docs and in plain English define what the inputs and outputs should be along with when to use it and how to perceive the results.</p><p>With everything said so far, I&#8217;d like to switch gears to provide some examples of why context maters and describing your problem succinctly will provide more value than &#8220;vibing&#8221; (I&#8217;m old) your way through it.<br>Let&#8217;s take this simple example I ran across the other week. Let&#8217;s say that you want to automate logging into multiple Google Chrome Profiles (you MSSP &amp; thrunters know what I mean) and kick-off a simple hunt (search) in each. Why you may ask, because it&#8217;s tedious and you have to do what you have to do with the tools you have and really this is a silly example (and don&#8217;t really do this please).</p><p>Using this example, you may start up Claude Desktop/Code or Cursor and say:</p><pre><code><code>As a threat hunter, I want to create a python package and CLI utility which accepts a list of Google Chrome Profiles to open. I want this package to ensure the latest ChromeDriver is installed. For each provided Google Chrome Profile provided as input, I want this tool to only accept Chrome Profiles that exist on the system and do not create one if it doesn&#8217;t exist. Once validated, it should create a new browser instance that opens in the provided profile display name and the first tab is X url.
</code></code></pre><p>Doing this may result in some success (again this is a simple example) but more than likely it will never get it right because it will guess at which Profile and only if that name exists will it try and open that profile. It may also take a completely different approach and may solve, it but I&#8217;d honestly be surprised.</p><p>If I change this prompt by adding the following, giving it context, it will understand and find the correct answer because it has been given explicit instructions and a determined example output.</p><pre><code><code>&#8230; Ensure that the provided Google Chrome Profile name represents the display name shown within Google Chrome. For example, I have a profile named &#8220;Thrunting - X organization name&#8221; and it should match the input value&#8221;
</code></code></pre><p>This simple addition, of providing actual context and an expected result aligns the context/data inputs with your expected outputs; again guardrails.</p><p>This was a silly example, but I hope it provides some clarification that the more concrete outputs, decision points, paths to follow, descriptions of key terms, specifications, requirements and more in the context you provide to an LLM the better inference results.</p><p>p.s. The reason why LLMS do not understand that the values you are wanting to match reside in <code>./LocalState</code> instead of its parent directory is beyond me but that is where those display names are located (FYI).</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/p/how-i-use-llms-for-security-work-e7f?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading THOR Collective Dispatch! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/p/how-i-use-llms-for-security-work-e7f?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://dispatch.thorcollective.com/p/how-i-use-llms-for-security-work-e7f?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p></p><h2>Back to the Basics</h2><p>First, I want to reiterate that in order to build something meaningful using an LLM, you must NO MATTER WHAT first understand the problem you are trying to solve. If you don&#8217;t intimately know the problem, then start by writing what you do know and ask questions until you know what the problem is.</p><p>I&#8217;ve talked a lot about context but that&#8217;s a vague statement. In this section I wanted to provide some examples of context that I&#8217;ve found to be extremely beneficial when it comes to LLM output. Here is a non-inclusive list of context examples (in no particular order):</p><h3>Personas -&gt; Identities -&gt; Personalities</h3><p>When starting, this is less of a concern but as your knowledge base on how you prefer to use LLMs grows you probably want to repeat a process, especially investigations, analysis, research, and/or tooling. This is where you can describe the experience, technologies, frameworks, etc. to skew results towards your current knowledge.</p><p>For example, you can describe your preferred Python package layout, templates, etc. You can define a persona for different projects or code bases. The point is to use the tools you are familiar with already when starting out. Don&#8217;t just let the LLM use TypeScript if you have never use it previously.<br>Over time your design patterns, thinking logic and more can be recorded and use as persona or identity for repeatable work from a specific perspective and experience.</p><p>There are some projects, like PAI, which are experimenting on building personalities from defining your background, failures, successes, etc. Pretty weird to think about but also pretty cool.</p><h3>Perspectives &amp; Goals</h3><p>Describe the perspective you want this problem to be researched or reviewed from. Whether that is QA as a staff level SDET or an elite red team ninja warrior. Defining these perspectives as well as the overall goals of the project will help keep scope within the problem space.</p><p>Here you can also define the overall skills (threat hunting, phishing defense, detection rule guru, etc.). You should also define the goals of the ask in general (e.g. find new and novel threats).</p><h3>Tools</h3><p>This is pretty straight forward but provide a list of different external tools which can be used within this project. Most of these will be MCP servers and their exposed methods. But it can also be things like:</p><ul><li><p>A local runner docker compose stack</p></li><li><p>Guidelines on which tools to use:</p><ul><li><p>use python not golang or js</p></li><li><p>Use python-fire for CLI, attrs models</p></li><li><p>Class and inheritance over utility functions, etc.</p></li><li><p>Use uv over poetry</p></li><li><p>Etc.</p></li></ul></li><li><p>Specific APIs with examples (Schema docs is preferred)</p></li></ul><p>For all of these, provide context as to when to use the tool, how to use it and how to interpret the results. This will definitely improve your results.</p><h3>Documentation</h3><p>As much reference documentation you can provide will always be helpful but ensure that you are not bloating your token usage or extending beyond the context windows of these models; size of your prompt matters both on costs and the ability for the model to provide correct inference results.</p><p>Provide things like:</p><ul><li><p>API specifications</p></li><li><p>JSONSchemas</p></li><li><p>Repositories</p></li><li><p>Internal &amp; external docs to terms/keywords specific to your org/worldview</p></li><li><p>Provide examples of similar problems</p><ul><li><p>It is also advantageous to provide examples that you already have documented on solving a problem or of a previous investigation decision</p></li></ul></li></ul><p>In addition to these standard pieces of documentation, you should also provide what NOT to do. For example:</p><ul><li><p>Provide scenarios that will / may occur and describe what not to do and why</p></li><li><p>Document when to not use a tool (defined above)</p></li><li><p>Document what to do if a situation does occur that&#8217;s critical</p></li></ul><h3>Requirements</h3><p>Like I have mentioned a few times, you must understand the problem to fully get the benefits of LLMs. Another great way to improve your research, discovery, analysis, etc. uses of LLMs is to ensure you provide all the business and technical requirements.</p><p>When defining technical requirements, provide things around when to use tools, different tools or frameworks to avoid using, and other specifics. For example:</p><ul><li><p>Defining the requirements can be as simple as &#8220;use caching of results&#8221; or specific enough to warrant something like &#8220;use Redis caching, using the rueidis go package&#8221;</p></li><li><p>Document what not to use including languages, frameworks, etc.</p></li><li><p>Define business requirements</p><ul><li><p>This should likely be the largest section, but it depends on the end goal of the prompt.</p></li></ul></li><li><p>Define gotchas</p></li></ul><p>There are lots of opportunities to write here. As a side note, I believe the ones that will prevail in the future of the &#8220;tech&#8221; industry are the ones that can describe a problem in detail effectively and efficiently as possible.</p><p>In addition to all of the above, I recommend checking out frameworks like Skills <a href="https://platform.claude.com/docs/en/agents-and-tools/agent-skills/overview">https://platform.claude.com/docs/en/agents-and-tools/agent-skills/overview</a> and review projects which have implemented <code>SKILLS.md</code> to get a different perspective. We are in a new frontier and the frameworks, schemas, etc. are constantly evolving. Just look at MCP (plug for a MCP I wrote about a year ago <a href="https://github.com/MSAdministrator/enrichment-mcp">https://github.com/MSAdministrator/enrichment-mcp</a>) and its evolution (I still think they should have used gRPC <a href="https://github.com/modelcontextprotocol/modelcontextprotocol/discussions/1144">https://github.com/modelcontextprotocol/modelcontextprotocol/discussions/1144</a>).</p><h2>Advanced Example</h2><p>Now let&#8217;s get into an example. This is purely hypothetical and for posterity I&#8217;m actually not going to put this prompt into any LLMs and just let you try it for yourself (mostly because I don&#8217;t want to waste the energy &#8212; LLMs have Externalities that reach further than most other technology known to humans &#8212; what you input has an external cost that you may not realize).</p><p>Note: I wrote this in example below in like 30 minutes. Your mileage will vary depending on the number of details provided.</p><h2>Description</h2><p>As a senior security research engineer focused on building highly scalable threat detection systems. As a senior software engineer proficient in Golang, gRPC, Protobuf, unary and bi-directional streaming, ingestion processing using Kafka or google pub/sub, caching using Redis pipelining, Postgres (and ip4r) scaling using pgbouncer(s), kubernetes, monitoring and metrics using Prometheus.Your goal is to build highly scalable threat enrichment pipeline that can ingest logs of different services, extract the necessary IPv4/IPv6 addresses (as well as their context e.g. source ips vs destination ips, etc.) and perform enrichment providing precise geolocation information (for now you can use ipinfo sample databases).</p><p>This service can process anywhere from 100 to 1 billion IPs per day to enrich but performance throughput and low latency (10ms~) are REQUIRED.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Irx1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a92b9ba-d830-4295-a089-0e71ae2be20a_1024x559.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Irx1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a92b9ba-d830-4295-a089-0e71ae2be20a_1024x559.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Irx1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a92b9ba-d830-4295-a089-0e71ae2be20a_1024x559.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Irx1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a92b9ba-d830-4295-a089-0e71ae2be20a_1024x559.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Irx1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a92b9ba-d830-4295-a089-0e71ae2be20a_1024x559.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Irx1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a92b9ba-d830-4295-a089-0e71ae2be20a_1024x559.jpeg" width="1024" height="559" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8a92b9ba-d830-4295-a089-0e71ae2be20a_1024x559.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:559,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:214420,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dispatch.thorcollective.com/i/189795560?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a92b9ba-d830-4295-a089-0e71ae2be20a_1024x559.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Irx1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a92b9ba-d830-4295-a089-0e71ae2be20a_1024x559.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Irx1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a92b9ba-d830-4295-a089-0e71ae2be20a_1024x559.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Irx1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a92b9ba-d830-4295-a089-0e71ae2be20a_1024x559.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Irx1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a92b9ba-d830-4295-a089-0e71ae2be20a_1024x559.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h2>Tools</h2><p>You have the following tools available to you:</p><ul><li><p>Golang</p></li><li><p>gRPC &amp; protobuf for inner service communications</p></li><li><p>Use Postgres (using the ip4r extension)</p><ul><li><p>Use pgbouncer for scalable queries</p></li><li><p>Ensure proper indexes are in place</p></li></ul></li><li><p>Cache results using Redis (rueidis client library)</p></li><li><p>Use kubernetes and light weight images</p></li><li><p>Setup monitoring and metrics throughout the pipeline using Prometheus</p></li></ul><h2>Documentation</h2><p>The following are references to use:</p><ul><li><p>Use the ipinfo sample databases <a href="https://github.com/ipinfo/sample-database">https://github.com/ipinfo/sample-database</a> as the core database structure</p></li><li><p>Expect that the incoming logs are in this schemas format (link to schema or samples)</p></li><li><p>It is expected that every log ingested will be enriched, but this does not mean every log will have values. Indicate in the log if enrichment occurred no matter if successful or not</p></li><li><p>Ensure you are creating the appropriate views or queries utilize the correct ip4r data types <a href="https://github.com/RhodiumToad/ip4r">https://github.com/RhodiumToad/ip4r</a></p></li></ul><h2>What Not to do</h2><ul><li><p>Do not create two separate paths for ipv4 and ipv6 addresses</p></li></ul><h2>Requirements</h2><ul><li><p>Ensure the pipeline can handle 1 billion events per day</p></li><li><p>Ensure that you are extracting all IPs found and that each IP addresses found is enriched in the correct context (source vs. destination, etc.)</p></li><li><p>Ensure that extract can be changed easily, you never know when new formats are going to be supported in the future</p></li><li><p>Keep cached results for up to 18 hours (at a minimum) but provide a way to invalidate cache</p></li><li><p>Ensure all communications are encrypted and have proper (and secure) authorization between services</p></li><li><p>Create indexes that use the ip4r data types for IPs</p></li><li><p>Data will be updated from a remote location at any time so upgrading of IP geolocation must be straight forward</p></li></ul><p>I hope this more advanced example helps you understand that the more context you can provide the better results you will receive. Vibe coding is cool and all but just like how a Product/Project Manager will provide guidance for a project, you too must do the same in order to get the best results.</p><p>As I have stated previously, I believe that those who understand a problem fully and can describe it in detail, are the ones that will prevail as we move into this new era of technology advancement. Time will tell if I&#8217;m right or wrong.</p><p>Peace</p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/p/how-i-use-llms-for-security-work-e7f/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://dispatch.thorcollective.com/p/how-i-use-llms-for-security-work-e7f/comments"><span>Leave a comment</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[When to Stop Hunting]]></title><description><![CDATA[The Art of Knowing You&#8217;ve Looked Hard Enough]]></description><link>https://dispatch.thorcollective.com/p/when-to-stop-hunting</link><guid isPermaLink="false">https://dispatch.thorcollective.com/p/when-to-stop-hunting</guid><dc:creator><![CDATA[Sydney Marrone]]></dc:creator><pubDate>Tue, 03 Mar 2026 15:02:12 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!j1nh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fec10f6-f671-4ab2-9da2-223a08f69791_749x500.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;ve been doing this long enough to know that starting a hunt is the easy part. You&#8217;ve got a hypothesis, you&#8217;ve got your data sources queued up, you&#8217;ve got that first-cup-of-coffee energy. The hard part? Knowing when you&#8217;re done.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">THOR Collective Dispatch is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Nobody teaches this. I&#8217;ve read dozens of hunting guides, sat through countless conference talks, and co-authored an entire framework. We spend so much effort on how to start a hunt, how to form a hypothesis, how to pick your data sources. But the question of <em>when to stop</em> gets a hand wave at best.</p><p>And that&#8217;s a problem. Because right now, most of us are stopping hunts based on vibes.</p><h2><strong>The Vibes Problem</strong></h2><p>Be honest. How do you currently decide a hunt is over?</p><p>&#8220;It feels like I&#8217;ve looked at enough.&#8221; &#8220;We ran out of time.&#8221; &#8220;I didn&#8217;t find anything, so I guess we&#8217;re good?&#8221; &#8220;My boss asked for the report.&#8221;</p><p>None of those are termination criteria. Those are circumstances. There&#8217;s a difference between <em>stopping</em> a hunt and a hunt being <em>done</em>.</p><p>I&#8217;ve watched hunters burn through a full week chasing phantom lateral movement because they couldn&#8217;t articulate what &#8220;done&#8221; looked like. I&#8217;ve also watched hunters close a hunt in four hours because they ran a few queries, got no hits, and called it. Both are failure modes. One wastes resources. The other creates false confidence.</p><p>We need something better than vibes.</p><h2><strong>Coverage Criteria: Did You Actually Look?</strong></h2><p>The first question to ask yourself before closing a hunt: did I actually examine all the data sources that matter for this hypothesis?</p><p>This sounds obvious but it really isn&#8217;t.</p><p>One of my first hunts ever, I was hunting PowerShell and I totally missed looking at the Windows script logging events. Partly because I was new, but also because I didn&#8217;t document my data sources. There was no list of &#8220;here&#8217;s what I need to look at.&#8221; So I looked at what I knew about and moved on, thinking I&#8217;d covered it.</p><p>I hadn&#8217;t. And I didn&#8217;t realize it until way later.</p><p>Here&#8217;s what you could do. At the start of every hunt, write down every data source that&#8217;s relevant to your hypothesis. Not &#8220;everything we have,&#8221; but the specific sources that could contain evidence of the behavior you&#8217;re looking for. Then track which ones you&#8217;ve actually queried. Simple as a table in a notebook:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uFOS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00cff389-87af-47d6-847e-6a6e9b80bf28_1497x544.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uFOS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00cff389-87af-47d6-847e-6a6e9b80bf28_1497x544.png 424w, https://substackcdn.com/image/fetch/$s_!uFOS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00cff389-87af-47d6-847e-6a6e9b80bf28_1497x544.png 848w, https://substackcdn.com/image/fetch/$s_!uFOS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00cff389-87af-47d6-847e-6a6e9b80bf28_1497x544.png 1272w, https://substackcdn.com/image/fetch/$s_!uFOS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00cff389-87af-47d6-847e-6a6e9b80bf28_1497x544.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uFOS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00cff389-87af-47d6-847e-6a6e9b80bf28_1497x544.png" width="1456" height="529" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/00cff389-87af-47d6-847e-6a6e9b80bf28_1497x544.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:529,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:122769,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dispatch.thorcollective.com/i/188681827?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00cff389-87af-47d6-847e-6a6e9b80bf28_1497x544.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uFOS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00cff389-87af-47d6-847e-6a6e9b80bf28_1497x544.png 424w, https://substackcdn.com/image/fetch/$s_!uFOS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00cff389-87af-47d6-847e-6a6e9b80bf28_1497x544.png 848w, https://substackcdn.com/image/fetch/$s_!uFOS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00cff389-87af-47d6-847e-6a6e9b80bf28_1497x544.png 1272w, https://substackcdn.com/image/fetch/$s_!uFOS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00cff389-87af-47d6-847e-6a6e9b80bf28_1497x544.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>If there&#8217;s a &#8220;No&#8221; in that queried column when I&#8217;m thinking about closing the hunt, I&#8217;m not done. I either need to go look at it or explicitly document why I couldn&#8217;t (access issues, data not available, retention gap) and flag that as a coverage gap in my findings.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3aVX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e8a3020-9fc9-4dd8-b219-33f2da06c0c7_501x498.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3aVX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e8a3020-9fc9-4dd8-b219-33f2da06c0c7_501x498.jpeg 424w, https://substackcdn.com/image/fetch/$s_!3aVX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e8a3020-9fc9-4dd8-b219-33f2da06c0c7_501x498.jpeg 848w, https://substackcdn.com/image/fetch/$s_!3aVX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e8a3020-9fc9-4dd8-b219-33f2da06c0c7_501x498.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!3aVX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e8a3020-9fc9-4dd8-b219-33f2da06c0c7_501x498.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3aVX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e8a3020-9fc9-4dd8-b219-33f2da06c0c7_501x498.jpeg" width="501" height="498" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5e8a3020-9fc9-4dd8-b219-33f2da06c0c7_501x498.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:498,&quot;width&quot;:501,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3aVX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e8a3020-9fc9-4dd8-b219-33f2da06c0c7_501x498.jpeg 424w, https://substackcdn.com/image/fetch/$s_!3aVX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e8a3020-9fc9-4dd8-b219-33f2da06c0c7_501x498.jpeg 848w, https://substackcdn.com/image/fetch/$s_!3aVX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e8a3020-9fc9-4dd8-b219-33f2da06c0c7_501x498.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!3aVX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e8a3020-9fc9-4dd8-b219-33f2da06c0c7_501x498.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Coverage isn&#8217;t just data sources either. It&#8217;s time windows. If your hypothesis is about an intrusion that could have happened anytime in the last 90 days but your logs only go back 30, that&#8217;s a coverage gap. Write it down.</p><h2><strong>Diminishing Returns: The Same False Positive Three Times</strong></h2><p>There&#8217;s a pattern I see in every hunt that&#8217;s gone on too long. You start finding the same things over and over.</p><p>The same service account triggering the same alert. The same legacy application doing weird DNS stuff. The same admin using RDP at odd hours because they&#8217;re in a different time zone. You&#8217;ve already investigated these. You&#8217;ve already ruled them out. But you keep bumping into them because your queries are broad enough to catch them.</p><p>When this starts happening, pay attention. It&#8217;s a signal.</p><p>Not a signal that there&#8217;s nothing to find. A signal that your current approach has extracted all the value it&#8217;s going to. You&#8217;ve saturated your search space at this level of granularity.</p><p>At this point you have three choices:</p><ol><li><p><strong>Refine your queries</strong> to filter out the known noise and look deeper</p></li><li><p><strong>Shift your approach</strong> entirely (different data source, different technique, pivot to a related hypothesis)</p></li><li><p><strong>Acknowledge you&#8217;ve hit the floor</strong> and document what you found (including the noise)</p></li></ol><p>Option 3 is valid. I know it feels like quitting. It&#8217;s not. It&#8217;s recognizing that more time in this direction won&#8217;t change the outcome. That&#8217;s professional judgment, not laziness.</p><h2><strong>Time-Boxing vs. Completeness</strong></h2><p>Every hunting team I&#8217;ve worked with has some version of this tension. Leadership wants hunts scoped to a sprint. Two days, a week, whatever fits the roadmap. Meanwhile, the hunter is sitting there thinking &#8220;but I haven&#8217;t checked the cloud logs yet.&#8221;</p><p>Here&#8217;s my take: time-boxing is necessary but not sufficient.</p><p>You need time constraints. Without them, hunts expand forever. I&#8217;ve seen it. A two-week hunt becomes a month because the hunter keeps pulling threads. Some of those threads matter. Most don&#8217;t. Without a boundary, there&#8217;s no forcing function to prioritize.</p><p>But a time box alone doesn&#8217;t tell you whether you&#8217;re done. It tells you when you have to stop. Those aren&#8217;t the same thing.</p><p>What I recommend: set your time box upfront, but also define your minimum coverage criteria upfront. If you hit the time box before you hit your coverage criteria, you have a decision to make. And that decision should be documented, not just made silently.</p><p>&#8220;Hunt time-boxed to 3 days. Completed analysis of Windows event logs, Sysmon, and EDR telemetry. Did NOT complete review of cloud audit logs or email gateway logs due to time constraints. Recommend follow-up hunt or including these sources in next cycle.&#8221;</p><p>That&#8217;s a responsible close. Compare that to: &#8220;Hunt complete. No findings.&#8221; Same outcome, completely different level of honesty about what you actually did.</p><h2><strong>The Confidence Spectrum</strong></h2><p>This is the thing I wish every hunter would internalize: &#8220;I found nothing&#8221; and &#8220;I am confident nothing is there&#8221; are wildly different statements.</p><p>&#8220;Found nothing&#8221; means your queries didn&#8217;t return hits. That&#8217;s a fact about your queries, not a fact about your environment.</p><p>&#8220;Confident nothing is there&#8221; means you examined the right data, with sufficient coverage, over the right time period, using techniques appropriate to the threat, and you can explain why the absence of evidence is meaningful.</p><p>Most hunts end with the first statement pretending to be the second.</p><p>I think about this as a spectrum:</p><ul><li><p><strong>Low confidence:</strong> &#8220;Ran some queries, no hits.&#8221; You looked, but not deeply.</p></li><li><p><strong>Medium confidence:</strong> &#8220;Examined primary data sources for indicators consistent with hypothesis. No evidence found, but coverage gaps exist in X and Y.&#8221;</p></li><li><p><strong>High confidence:</strong> &#8220;Examined all relevant data sources across the full time window. Validated detection logic against known-good simulations. No evidence of the hypothesized behavior. Coverage gaps: none identified.&#8221;</p></li></ul><p>Most hunts land somewhere in the medium range. That&#8217;s fine. But say so. Don&#8217;t let a medium-confidence hunt get reported as high-confidence just because it sounds better in a slide deck.</p><h2><strong>Documentation as Closure</strong></h2><p>A hunt is not done until it&#8217;s written down.</p><p>I don&#8217;t care if you found something or not. Null findings are findings. They&#8217;re data points that inform future hunts, justify detection investments, and build institutional knowledge about what you&#8217;ve looked at and when.</p><p>If you close a hunt with no documentation, it&#8217;s like it never happened. Six months from now, someone will hunt for the exact same thing because nobody recorded that you already did.</p><p>At minimum, your hunt closure document should include:</p><ul><li><p><strong>Hypothesis:</strong> What were you looking for and why?</p></li><li><p><strong>Scope:</strong> What environment, data sources, and time window?</p></li><li><p><strong>Coverage:</strong> What did you actually examine? What didn&#8217;t you get to?</p></li><li><p><strong>Findings:</strong> What did you find? Include false positives worth noting.</p></li><li><p><strong>Confidence level:</strong> How confident are you in the result?</p></li><li><p><strong>Recommendations:</strong> Detections to build, data gaps to fix, follow-up hunts to schedule.</p></li><li><p><strong>Time spent:</strong> How long did this actually take?</p></li></ul><p>That last one matters more than people think. If you&#8217;re tracking time spent per hunt, you start to build a picture of what types of hunts are expensive versus cheap. That data helps you plan better.</p><p>I know documentation isn&#8217;t sexy. Nobody got into threat hunting to write reports. But documentation is what turns a hunt from an activity into an artifact. Artifacts compound over time in ways that individual hunts don&#8217;t.</p><h2><strong>Where This Fits in PEAK</strong></h2><p>If you use PEAK (and if you don&#8217;t, <a href="https://dispatch.thorcollective.com/p/the-peak-threat-hunting-template">here&#8217;s a template to get started</a>), hunt termination should be baked into the Prepare phase.</p><p>PEAK has four phases: Prepare, Execute, Act, and Knowledge. Most people pour their energy into Execute because that&#8217;s where the actual hunting happens. But Prepare is where you define what success looks like, and that includes defining what &#8220;done&#8221; looks like.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ESld!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F227aceae-1752-407f-b5e1-93646e23011e_500x500.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ESld!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F227aceae-1752-407f-b5e1-93646e23011e_500x500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ESld!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F227aceae-1752-407f-b5e1-93646e23011e_500x500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ESld!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F227aceae-1752-407f-b5e1-93646e23011e_500x500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ESld!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F227aceae-1752-407f-b5e1-93646e23011e_500x500.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ESld!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F227aceae-1752-407f-b5e1-93646e23011e_500x500.jpeg" width="500" height="500" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/227aceae-1752-407f-b5e1-93646e23011e_500x500.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:500,&quot;width&quot;:500,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ESld!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F227aceae-1752-407f-b5e1-93646e23011e_500x500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ESld!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F227aceae-1752-407f-b5e1-93646e23011e_500x500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ESld!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F227aceae-1752-407f-b5e1-93646e23011e_500x500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ESld!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F227aceae-1752-407f-b5e1-93646e23011e_500x500.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>When you&#8217;re building your hypothesis in Prepare, add termination criteria right next to it:</p><ul><li><p>What data sources must I examine before I can call this complete?</p></li><li><p>What&#8217;s my time box?</p></li><li><p>What confidence level am I targeting?</p></li><li><p>What would &#8220;good enough&#8221; look like if I can&#8217;t hit full coverage?</p></li></ul><p>Then, in the Act phase, your closure documentation naturally includes an assessment against those criteria. Did you meet them? If not, why not?</p><p>The Knowledge phase is where this really pays off. When you capture termination criteria and coverage assessments alongside your findings, you&#8217;re building a body of knowledge about your hunting capability, not just your hunting results. Over time, you can answer questions like &#8220;how often do we hit our coverage targets?&#8221; and &#8220;where are our persistent blind spots?&#8221;</p><p>That&#8217;s the kind of thing that separates hunting programs that stick around from ones that fizzle out after a year.</p><h2><strong>The Hunt Closure Checklist</strong></h2><p>OK, I promised something practical. Here&#8217;s a checklist your team can steal and adapt.</p><h3><strong>Before You Close the Hunt</strong></h3><ul><li><p>[ ] All scoped data sources have been queried (or gaps documented)</p></li><li><p>[ ] Queries reviewed for correctness, not just &#8220;no hits&#8221;</p></li><li><p>[ ] If nothing found, you can explain why the absence is meaningful</p></li><li><p>[ ] Findings documented (including null findings)</p></li><li><p>[ ] Confidence level stated (low / medium / high)</p></li><li><p>[ ] Follow-up recommendations and detection opportunities logged</p></li><li><p>[ ] Hunt artifacts (queries, scripts) saved somewhere retrievable</p></li></ul><h3><strong>Red Flags That You&#8217;re Stopping Too Early</strong></h3><ul><li><p>You haven&#8217;t looked at all the data sources you scoped</p></li><li><p>Your queries are too narrow (you&#8217;d miss variants of the behavior)</p></li><li><p>You found something interesting but didn&#8217;t follow up because time ran out</p></li><li><p>You&#8217;re closing the hunt to hit a metric, not because you&#8217;re done</p></li></ul><h3><strong>Red Flags That You&#8217;ve Gone Too Long</strong></h3><ul><li><p>You keep finding the same false positives and re-investigating them</p></li><li><p>You&#8217;re expanding scope beyond the original hypothesis without a clear reason</p></li><li><p>You&#8217;ve shifted from &#8220;hunting&#8221; to &#8220;exploring&#8221; with no specific goal</p></li><li><p>The hunt has consumed more than 2x its original time box</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!j1nh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fec10f6-f671-4ab2-9da2-223a08f69791_749x500.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!j1nh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fec10f6-f671-4ab2-9da2-223a08f69791_749x500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!j1nh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fec10f6-f671-4ab2-9da2-223a08f69791_749x500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!j1nh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fec10f6-f671-4ab2-9da2-223a08f69791_749x500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!j1nh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fec10f6-f671-4ab2-9da2-223a08f69791_749x500.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!j1nh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fec10f6-f671-4ab2-9da2-223a08f69791_749x500.jpeg" width="749" height="500" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2fec10f6-f671-4ab2-9da2-223a08f69791_749x500.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:500,&quot;width&quot;:749,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!j1nh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fec10f6-f671-4ab2-9da2-223a08f69791_749x500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!j1nh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fec10f6-f671-4ab2-9da2-223a08f69791_749x500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!j1nh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fec10f6-f671-4ab2-9da2-223a08f69791_749x500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!j1nh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fec10f6-f671-4ab2-9da2-223a08f69791_749x500.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li></ul><h2><strong>Closing Thoughts</strong></h2><p>Knowing when to stop is a skill. It gets better with practice and worse with neglect. The checklist above is a starting point, not a religion. Adapt it. Argue about it with your team. Throw out the parts that don&#8217;t work.</p><p>Even imperfect criteria are better than none. You can always refine them. You can&#8217;t refine a gut feeling.</p><p>Now go finish that hunt you&#8217;ve been sitting on. You know the one.</p><p>Happy thrunting!</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">THOR Collective Dispatch is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The More I Learn, The Less I Know]]></title><description><![CDATA[The Not-So-Straightforward Journey of Finding Your Place in Cybersecurity]]></description><link>https://dispatch.thorcollective.com/p/the-more-i-learn-the-less-i-know</link><guid isPermaLink="false">https://dispatch.thorcollective.com/p/the-more-i-learn-the-less-i-know</guid><dc:creator><![CDATA[Isabella Sparks]]></dc:creator><pubDate>Tue, 24 Feb 2026 15:02:55 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!DQQQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e03975-b3b6-403b-8681-5f217abc785d_643x406.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h3><strong>SELECT * FROM Introduction;</strong></h3><p>Just before I sat down to write this, I had been analyzing different types of maps, thousands of photos of train tracks in British Columbia, cross-referencing transmission corridors with hiking trails to identify the real-world location of a nano banana-generated Ghibli-style scene&#8230; and falling in love with the process of finding a needle in a haystack. And yes, it was to find the first flag of a CTF.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">THOR Collective Dispatch is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>My first exposure to cyberspace came from watching Garcia &#8211; the original OSINT queen &#8211; on Criminal Minds locate an assailant in under a minute, pinging cell towers and surfacing information about virtually anyone with a few keystrokes. I remember being 8 years old, thinking less about the theatrics and more about the mechanics, how she took barely tangential pieces of information and correlated them into something coherent enough to identify, locate, and stop a suspect. In hindsight, the earliest sign that I was a nerd was that I found the data more compelling than Shemar Moore.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VgQ0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24ab3240-0087-476a-ba05-b1abdeaf2e79_540x400.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VgQ0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24ab3240-0087-476a-ba05-b1abdeaf2e79_540x400.jpeg 424w, https://substackcdn.com/image/fetch/$s_!VgQ0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24ab3240-0087-476a-ba05-b1abdeaf2e79_540x400.jpeg 848w, https://substackcdn.com/image/fetch/$s_!VgQ0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24ab3240-0087-476a-ba05-b1abdeaf2e79_540x400.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!VgQ0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24ab3240-0087-476a-ba05-b1abdeaf2e79_540x400.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VgQ0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24ab3240-0087-476a-ba05-b1abdeaf2e79_540x400.jpeg" width="540" height="400" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/24ab3240-0087-476a-ba05-b1abdeaf2e79_540x400.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:400,&quot;width&quot;:540,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!VgQ0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24ab3240-0087-476a-ba05-b1abdeaf2e79_540x400.jpeg 424w, https://substackcdn.com/image/fetch/$s_!VgQ0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24ab3240-0087-476a-ba05-b1abdeaf2e79_540x400.jpeg 848w, https://substackcdn.com/image/fetch/$s_!VgQ0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24ab3240-0087-476a-ba05-b1abdeaf2e79_540x400.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!VgQ0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24ab3240-0087-476a-ba05-b1abdeaf2e79_540x400.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Cybersecurity, I&#8217;ve learned, is expansive and rarely straightforward. For most end users, security starts and ends with password strength; for most entry-level practitioners &#8211; me included &#8211; impossible travel has a way of masquerading as the ultimate <a href="https://csrc.nist.gov/glossary/term/indicator_of_compromise">IOC</a>; and for tenured researchers, definitive <a href="https://cloud.google.com/blog/topics/threat-intelligence/trade-offs-attribution/">attribution</a> can surface almost like a reflex. In a field defined by scale and complexity, the sheer volume of resources can make early learning feel paralyzing. Overwhelm, self-doubt, and indecision are common byproducts. You are not alone; rather than ignoring this existential truth, it&#8217;s worth naming it.</p><h3><strong>How We Ended Up Here</strong></h3><p>If you, reader, are anything like me, then you are familiar with the following process:</p><ol><li><p>Have a question about something</p></li><li><p>Research the answer</p></li><li><p>Intermission to go down multiple irrelevant rabbit holes</p></li><li><p>Find the answer to the original question</p></li><li><p>End up with 1000 new questions</p></li><li><p>Existential crisis</p></li><li><p>Repeat!</p></li></ol><p>This process is more so a rite of passage when entering the threat intelligence &amp; cybersecurity space. It is also a litmus test of tolerance against the inherent nature of the job - you will always have unanswered questions, and that is what makes the work so exciting.</p><p>One of my recent encounters with this process was, naturally, at 2 AM as I maniacally tried to figure out the answer to the very pressing question: &#8220;Where in cybersecurity do I fit?&#8221;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AsVj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83600713-e457-40e8-8489-1e2e2ddc37e1_500x275.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AsVj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83600713-e457-40e8-8489-1e2e2ddc37e1_500x275.jpeg 424w, https://substackcdn.com/image/fetch/$s_!AsVj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83600713-e457-40e8-8489-1e2e2ddc37e1_500x275.jpeg 848w, https://substackcdn.com/image/fetch/$s_!AsVj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83600713-e457-40e8-8489-1e2e2ddc37e1_500x275.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!AsVj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83600713-e457-40e8-8489-1e2e2ddc37e1_500x275.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AsVj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83600713-e457-40e8-8489-1e2e2ddc37e1_500x275.jpeg" width="500" height="275" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/83600713-e457-40e8-8489-1e2e2ddc37e1_500x275.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:275,&quot;width&quot;:500,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AsVj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83600713-e457-40e8-8489-1e2e2ddc37e1_500x275.jpeg 424w, https://substackcdn.com/image/fetch/$s_!AsVj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83600713-e457-40e8-8489-1e2e2ddc37e1_500x275.jpeg 848w, https://substackcdn.com/image/fetch/$s_!AsVj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83600713-e457-40e8-8489-1e2e2ddc37e1_500x275.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!AsVj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83600713-e457-40e8-8489-1e2e2ddc37e1_500x275.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This late-night rabbit hole was, in part, prompted by my discovery of Henry Jiang&#8217;s <a href="https://media.licdn.com/dms/image/v2/C4E12AQFEgFdbEtEl3Q/article-inline_image-shrink_1500_2232/article-inline_image-shrink_1500_2232/0/1619282900607?e=1772064000&amp;v=beta&amp;t=raW-W4jixLuE-x7BrJCMLxEtuhxs8BnGK7JMxcQXPCo">Map of Cybersecurity Domains</a><em>.</em> While Jiang outlines different facets of the industry in a very visually pleasing and palatable way, the map left me more confused than it did entice me to any one niche. Every domain connected to three others; technical paths bled into compliance tracks; creative OSINT work sat alongside cryptography and risk frameworks. The vastness wasn&#8217;t inspiring; it was paralyzing. Blue teaming, red teaming, security &amp; detection engineering, threat intelligence research&#8230; the list continues, my question still unanswered.</p><h3><strong>sudo whatdoichoose</strong></h3><p>Paralysis sets in when you&#8217;re optimizing for the perfect choice rather than taking the next step. Getting unstuck means understanding the mechanics of the loop you&#8217;re in, and then deliberately disrupting it.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DQQQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e03975-b3b6-403b-8681-5f217abc785d_643x406.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DQQQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e03975-b3b6-403b-8681-5f217abc785d_643x406.jpeg 424w, https://substackcdn.com/image/fetch/$s_!DQQQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e03975-b3b6-403b-8681-5f217abc785d_643x406.jpeg 848w, https://substackcdn.com/image/fetch/$s_!DQQQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e03975-b3b6-403b-8681-5f217abc785d_643x406.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!DQQQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e03975-b3b6-403b-8681-5f217abc785d_643x406.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DQQQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e03975-b3b6-403b-8681-5f217abc785d_643x406.jpeg" width="643" height="406" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/00e03975-b3b6-403b-8681-5f217abc785d_643x406.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:406,&quot;width&quot;:643,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;A person lying on a desk\n\nAI-generated content may be incorrect.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="A person lying on a desk

AI-generated content may be incorrect." title="A person lying on a desk

AI-generated content may be incorrect." srcset="https://substackcdn.com/image/fetch/$s_!DQQQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e03975-b3b6-403b-8681-5f217abc785d_643x406.jpeg 424w, https://substackcdn.com/image/fetch/$s_!DQQQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e03975-b3b6-403b-8681-5f217abc785d_643x406.jpeg 848w, https://substackcdn.com/image/fetch/$s_!DQQQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e03975-b3b6-403b-8681-5f217abc785d_643x406.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!DQQQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e03975-b3b6-403b-8681-5f217abc785d_643x406.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>Permission Denied: Why Paralysis Happens</strong></h3><ul><li><p><strong>The Paradox of Choice &amp; Hick&#8217;s Law</strong>: Unlike other fields with linear progressions, cybersecurity offers infinite branching paths that are constantly evolving. (If you want the science behind why this breaks your brain, look up <a href="https://www.bjjmentalmodels.com/hicks-law">Hick&#8217;s Law</a> &#8211; TLDR: more options = longer you&#8217;ll stare at the screen doing nothing).</p></li><li><p><strong>The &#8220;I </strong><em><strong>Need</strong></em><strong> to Know Everything&#8221; Trap</strong>: Security engineers &amp; researchers of all specialties are especially prone to this &#8211; if everything is connected, how do you choose just one thread?</p></li><li><p><strong>Imposter Syndrome as a Feature, Not a Bug</strong>: Everyone feels underqualified. The field moves faster than anyone can keep up. This is normal. Some moments will feel like your head is well above the water, and some will feel like your back is turned to a crashing wave.</p></li><li><p><strong>The Resource Rabbit Hole</strong>: You search &#8220;how to get started in threat intelligence&#8221; and get a seemingly uncountable number of YouTube videos, vendor blogs with conflicting methodologies, GitHub repos of varying quality &#8211; some abandoned, paid courses, and Twitter threads that all assume different baseline knowledge.</p></li></ul><p>Curating a comprehensive learning path becomes a full-time job. You spend three hours building a perfectly organized bookmark folder and a Notion page of resources, then feel so mentally exhausted you can&#8217;t actually start learning from them. The research <em>about</em> learning displaces the learning itself.</p><h3><strong>The Knowledge Depreciation Problem</strong></h3><p><em>Why it Feels Like You&#8217;re Always Starting Over</em></p><p>You finally wrap your head around basic Python scripting, and suddenly everyone&#8217;s saying you should learn Go or Rust for security tooling. You master the fundamentals of approaching and solving CTF or OSINT challenges, only for the platforms you learned on to get shut down or paywalled. You spend weeks understanding MITRE ATT&amp;CK techniques, and new research comes out that reshapes how those techniques are approached.</p><p>This isn&#8217;t unique to cybersecurity, but the velocity is brutal. By the time you feel competent with the basics, the landscape has shifted. This creates a vicious cycle: &#8220;Why should I invest time learning X if it&#8217;ll be obsolete as soon as I understand it?&#8221;</p><p>The paralysis here isn&#8217;t about too many choices &#8211; it&#8217;s about the fear that any choice you make has an expiration date. You&#8217;re not just learning a skill; you&#8217;re trying to hit a moving target that you can&#8217;t even see. Ask yourself: <em>what would happen if you stopped chasing the target altogether?</em> The answer may surprise you - and it&#8217;s coming up next.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">THOR Collective Dispatch is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[PACMap Is Live - And It’s Open Source!]]></title><description><![CDATA[and more importantly: free]]></description><link>https://dispatch.thorcollective.com/p/pacmap-is-live-and-its-open-source</link><guid isPermaLink="false">https://dispatch.thorcollective.com/p/pacmap-is-live-and-its-open-source</guid><dc:creator><![CDATA[Lauren Proehl]]></dc:creator><pubDate>Fri, 20 Feb 2026 00:00:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!rwzb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc936091-64f1-4976-b747-b84fecc57f11_785x775.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I built something. And I&#8217;m excited to share it with you.</p><p>For the last several weeks, I&#8217;ve been working on a project called <strong>PACMap</strong> - the Privacy, AI &amp; Cybersecurity Map. It&#8217;s a free, open-source regulatory intelligence platform that tracks global cybersecurity, data privacy, and AI regulations in one place.</p><p>It&#8217;s live now at <strong><a href="https://pacmap.dev/">pacmap.dev</a></strong>.</p><p></p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;5639d5ea-5492-4296-a90f-d531c0f4ab29&quot;,&quot;duration&quot;:null}"></div><p></p><h2>Why This Exists</h2><p>If you&#8217;ve ever had to answer the question <em>&#8220;what regulations apply to us?&#8221;</em> - you know the pain. You&#8217;re digging through government websites, PDFs, scattered news articles, and maybe paying for an expensive commercial database that still doesn&#8217;t have everything you need. There&#8217;s no single, free, well-organized source of truth for global cyber, privacy, and AI regulation data.</p><p>That bothered me. So I built one.</p><p>PACMap currently tracks <strong>800+ regulations</strong> across <strong>160+ jurisdictions</strong> worldwide, spanning legislation from the 1970s through proposed bills that haven&#8217;t been enacted yet. It covers four categories: cybersecurity, privacy and data protection, artificial intelligence, and cross-section laws that span multiple categories.</p><h2>What&#8217;s Inside</h2><p>Here&#8217;s what you get when you visit:</p><p>An <strong>interactive dashboard</strong> with summary stats, charts by category, region, and status - plus a heatmap globe showing regulatory density by country. A <strong>full-text search</strong> that lets you filter by jurisdiction, category, legislative status, date range, and keywords. <strong>Regulation detail pages</strong> with structured breakdowns of each law - scope, enforcement, key requirements, deadlines, cross-references, and links to official sources. A <strong>visual timeline</strong> of when regulations were proposed, adopted, and enforced. A <strong>compliance calendar</strong> for upcoming deadlines. <strong>Data confidence indicators</strong> on every entry so you know how reliable each record is. And an <strong>AI-powered research agent</strong> that automatically finds and adds new regulations weekly, so the platform stays current without manual updates.</p><p>The kind of thing you can use at your desk but also pull up in a board meeting without anyone asking why it looks like a hacking tool.</p><h2>The Builder&#8217;s Mindset</h2><p>Here&#8217;s where the THOR Collective thread comes in.</p><p>We&#8217;ve been talking all season about builders showing up. About AI lowering the barrier. About practitioners creating the tools they wish existed instead of waiting for a vendor to maybe get around to it.</p><p>PACMap is me doing exactly that.</p><p>I&#8217;m not a full-time software engineer. I&#8217;m a cybersecurity professional who got tired of a gap in the market and decided to close it myself. I used <strong>Claude Code</strong> as my primary development partner - Python backend with FastAPI, React frontend, the whole stack. The AI didn&#8217;t build it for me. I still had to know what I wanted, make the design decisions, validate the output, security scan everything, and push through every phase. But it made a solo side project of this scope actually possible.</p><p>That&#8217;s the real message: if you can clearly describe what you need and you&#8217;re willing to put in the work, you can build things that used to require a team.<br></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">THOR Collective Dispatch is a reader-supported publication. To receive new posts and support our work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>It&#8217;s Free. It&#8217;s Open Source. It&#8217;s Yours.</h2><p>No ads. No paywalls. PACMap is a free resource for the community. I may add a donation option down the road to cover that, but the platform itself will stay free.</p><h2>For the Community</h2><p>This is where the community part matters.</p><p>PACMap currently has 831 regulations ingested and growing. But there are hundreds more out there, and regulations change constantly. I need people to tell me what&#8217;s missing, what&#8217;s wrong, and what needs updating.</p><p>If you spot a regulation that&#8217;s not in there - let me know. If something&#8217;s outdated or inaccurate - flag it. If your jurisdiction isn&#8217;t well represented - I want to hear about it.</p><p>You can submit to the project at <strong>contact@pacmap.dev</strong> or through the usual THOR Collective channels.</p><h2>What&#8217;s Next</h2><p>The roadmap includes email alert subscriptions by jurisdiction or category, side-by-side regulation comparison, compliance mapping to frameworks like NIST CSF and ISO 27001, controls exports, a public API, and so much more.</p><p>But right now, the most important thing is that it&#8217;s live, it&#8217;s free, and it&#8217;s built for you.</p><p>Go check it out: <strong><a href="https://pacmap.dev/">pacmap.dev</a></strong></p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/p/pacmap-is-live-and-its-open-source/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://dispatch.thorcollective.com/p/pacmap-is-live-and-its-open-source/comments"><span>Leave a comment</span></a></p><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rwzb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc936091-64f1-4976-b747-b84fecc57f11_785x775.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rwzb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc936091-64f1-4976-b747-b84fecc57f11_785x775.png 424w, https://substackcdn.com/image/fetch/$s_!rwzb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc936091-64f1-4976-b747-b84fecc57f11_785x775.png 848w, https://substackcdn.com/image/fetch/$s_!rwzb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc936091-64f1-4976-b747-b84fecc57f11_785x775.png 1272w, https://substackcdn.com/image/fetch/$s_!rwzb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc936091-64f1-4976-b747-b84fecc57f11_785x775.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rwzb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc936091-64f1-4976-b747-b84fecc57f11_785x775.png" width="785" height="775" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bc936091-64f1-4976-b747-b84fecc57f11_785x775.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:775,&quot;width&quot;:785,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:30775,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://dispatch.thorcollective.com/i/188557040?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc936091-64f1-4976-b747-b84fecc57f11_785x775.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rwzb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc936091-64f1-4976-b747-b84fecc57f11_785x775.png 424w, https://substackcdn.com/image/fetch/$s_!rwzb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc936091-64f1-4976-b747-b84fecc57f11_785x775.png 848w, https://substackcdn.com/image/fetch/$s_!rwzb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc936091-64f1-4976-b747-b84fecc57f11_785x775.png 1272w, https://substackcdn.com/image/fetch/$s_!rwzb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc936091-64f1-4976-b747-b84fecc57f11_785x775.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div><hr></div><p><em>PACMap is an independent, community-oriented project. Corrections, suggestions, and missing regulation reports are always welcome.</em></p>]]></content:encoded></item><item><title><![CDATA[Ask-a-Thrunt3r: January 2026 - Season 2 Premiere 🐏]]></title><description><![CDATA[Mainly ramblings. And maybe some wisdom.]]></description><link>https://dispatch.thorcollective.com/p/ask-a-thrunt3r-january-2026-season</link><guid isPermaLink="false">https://dispatch.thorcollective.com/p/ask-a-thrunt3r-january-2026-season</guid><dc:creator><![CDATA[Lauren Proehl]]></dc:creator><pubDate>Tue, 17 Feb 2026 18:59:43 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/188287874/2ce477b780ff0718f92f501188ced312.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<h1>Ask-a-Thrunt3r: January 2026 - Season 2 Premiere &#128015;</h1><h2>&#128221; Episode Summary</h2><p>New year, same crew &#8212; and we&#8217;re building. The THOR Collective kicks off 2026 (Season 2!) with a deep dive into why this is the year security practitioners stop waiting on vendors and start building their own solutions. Lauren, Sydney, and John walk through the trio of Dispatch posts that kicked off the year &#8212; a manifesto series on building in security &#8212; and why the &#8220;I&#8217;m not technical enough&#8221; excuse doesn&#8217;t hold up anymore in the age of AI-assisted development.</p><p>From there, the hosts get into the real talk: what&#8217;s actually trending in security right now (spoiler: social engineering isn&#8217;t going anywhere, and the agentic attack surface is the new frontier), what&#8217;s overhyped (looking at you, &#8220;AI SOC that replaces all your analysts&#8221;), and what each of them is personally investing in this year. Sydney&#8217;s going deep on LLM evaluations and automated baselining. Lauren&#8217;s leveling up her rapid development and project scaffolding skills. John&#8217;s bouncing adversarial emulation ideas off AI &#8212; when it&#8217;ll let him.</p><p>The episode wraps with a lightning round covering certs vs. hands-on work, writing detections vs. hunting, specializing vs. staying broad, and prompt engineering vs. YOLOing it. Plus: conference announcements (CactusCon, WiCYS, BSides SF, RSA, DEF CON), puzzle swaps, PAI voice scaring partners, and Lauren&#8217;s Odyssey-inspired take on AI as Athena; a helper on your journey, not a replacement for the hero.</p><h2>&#9201;&#65039; Episode Breakdown</h2><ul><li><p>00:01 &#8211; Intro and welcome to Season 2</p></li><li><p>03:20 &#8211; January Dispatch Highlights: &#8220;2026, The Year Builders Show Up&#8221; by Lauren &amp; Sydney</p></li><li><p>09:22 &#8211; &#8220;Why You Should Build&#8221; by Lauren &#8211; breaking the psychological barrier</p></li><li><p>13:00 &#8211; &#8220;Why You Don&#8217;t Need a Desk to Build&#8221; by Sydney &#8211; shipping code from anywhere</p></li><li><p>16:32 &#8211; What are we trying to solve? The mission behind the builder series</p></li><li><p>18:40 &#8211; Staying current on AI: AI Daily Brief, Prompt GTFO, and community resources</p></li><li><p>20:45 &#8211; What&#8217;s trending: social engineering, browser extensions, OpenClaw/MoltBot, agentic attack surfaces</p></li><li><p>24:57 &#8211; AI finding vulnerabilities: OpenSSL discoveries and the CVE explosion</p></li><li><p>27:45 &#8211; What&#8217;s overhyped: the &#8220;AI SOC&#8221; replacing analysts narrative</p></li><li><p>30:00 &#8211; Risk tolerance and the human-in-the-loop debate</p></li><li><p>34:25 &#8211; What we&#8217;re investing in: LLM evaluations, automated baselining, rapid development, adversarial emulation</p></li><li><p>39:20 &#8211; What we&#8217;re ignoring: personal balance, saying no, giving up on red teaming</p></li><li><p>41:27 &#8211; Hot take: ignoring prompt engineering (and the Wispr Flow revolution)</p></li><li><p>43:00 &#8211; PAI voice scares</p></li><li><p>46:04 &#8211; Lightning Round: Certs vs. hands-on, detections vs. hunting, specialize vs. stay broad, prompt engineering vs. YOLO</p></li><li><p>53:00 &#8211; Conference circuit and closing: CactusCon, WiCYS, BSides SF, RSA, DEF CON, SecKC</p></li></ul><h2>&#127908; Hosts</h2><p><strong>Lauren Proehl (Host)</strong> &#8211; Manager of the group, chronic overcommitter, manifesto writer, and self-described &#8220;cautious optimist.&#8221; </p><p><strong>Sydney Marrone (Host)</strong> &#8211; Threat hunter turned builder. Shipping code from her phone, couch, bed, and probably CactusCon&#8217;s after party. Investing in LLM evaluations and automated baselining this year. </p><p><strong>John Grageda (Host)</strong> &#8211; Red teamer who uses AI for adversarial emulation and engagement planning, but notes the models still refuse to build offensive tooling (&#8221;nice try, buddy&#8221;). </p><h2>&#128279; Resources &amp; Mentions</h2><h3>January 2026 Dispatch Posts</h3><ul><li><p><strong><a href="https://dispatch.thorcollective.com/p/2026-the-year-builders-show-up">2026: The Year Builders Show Up</a></strong> by Lauren Proehl &amp; Sydney Marrone</p></li><li><p><strong><a href="https://dispatch.thorcollective.com/p/why-you-should-build">Why You Should Build</a></strong> by Lauren Proehl</p></li><li><p><strong><a href="https://dispatch.thorcollective.com/p/you-dont-need-a-desk-to-build">You Don&#8217;t Need a Desk to Build</a></strong> by Sydney Marrone</p></li></ul><h3>Tools &amp; Resources Mentioned</h3><ul><li><p><strong>Claude Code</strong> &#8211; AI coding assistant used by the hosts for building security tools and personal projects</p></li><li><p><strong><a href="https://danielmiessler.com/">PAI (Personal AI)</a></strong> by Daniel Miessler &#8211; personal AI assistant with voice capabilities</p></li><li><p><strong><a href="https://wisprflow.ai/">Wispr Flow</a></strong> &#8211; voice-to-text tool for talking at your AI instead of prompt engineering</p></li><li><p><strong><a href="https://detect.fyi/">Detect FYI</a></strong> &#8211; article by Alex Teixeira on automated baseline detections (30-day baseline + hourly deviation checks)</p></li><li><p><strong><a href="https://aidailybrief.ai/">AI Daily Brief</a></strong> &#8211; recommended podcast for staying current on AI news</p></li><li><p><strong><a href="https://www.youtube.com/@PromptorGTFO">Prompt GTFO</a></strong> &#8211; community resource on cybersecurity and AI</p></li><li><p><strong><a href="https://github.com/openclaw/openclaw">OpenClaw</a> / ClawBot / MoltBot</strong> &#8211; AI agents and social networks that had the hosts questioning reality</p></li></ul><h3>Vulnerability Research &amp; Bug Bounty</h3><ul><li><p><strong><a href="https://aisle.com/blog/aisle-discovered-12-out-of-12-openssl-vulnerabilities">AISLE Discovers 12 OpenSSL Vulnerabilities (Jan 2026)</a></strong> &#8211; AI-powered autonomous analyzer found all 12 CVEs in the January 2026 coordinated release, some dating back to 1998</p></li><li><p><strong><a href="https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/">The End of the curl Bug-Bounty (Daniel Stenberg)</a></strong> &#8211; curl ended its HackerOne bug bounty program January 31, 2026 due to flood of AI-generated slop reports</p></li><li><p><strong><a href="https://cloud.google.com/transform/how-google-does-it-building-ai-agents-cybersecurity-defense/">Google: Building AI Agents for Cybersecurity and Defense</a></strong> &#8211; Google&#8217;s approach to agentic defense and building security agents</p></li><li><p><strong><a href="https://slack.engineering/streamlining-security-investigations-with-agents/">Slack Engineering: Streamlining Security Investigations with Agents</a></strong> &#8211; Slack&#8217;s approach to agentic SOC defense using AI agent personas (Director, domain experts, Critic) that break investigations into phases</p></li></ul><h3>Key Concepts Discussed</h3><ul><li><p><strong>AI as Augmentation, Not Replacement</strong> &#8211; Lauren&#8217;s Athena analogy from The Odyssey: AI is a helper on your odyssey, not a replacement for the hero</p></li><li><p><strong>The Builder Mindset</strong> &#8211; scripts, queries, playbooks all count as building; you don&#8217;t need permission from the developer gods</p></li><li><p><strong>Return of Generalism</strong> &#8211; AI raising the floor for lower-level analysts, enabling dynamic workforce reallocation</p></li><li><p><strong>Agent Manager Future</strong> &#8211; the theory that everyone becomes a manager of teams of AI agents</p></li><li><p><strong>Trust but Verify</strong> &#8211; applies to both AI and humans; both make mistakes</p></li><li><p><strong>The Boot Camp Loop</strong> &#8211; AI helps break the cycle of training without applying</p></li><li><p><strong>Automated Baselining</strong> &#8211; 30-day baseline detection + hourly checks against deviations (Detect FYI approach)</p></li><li><p><strong>Agentic Attack Surface</strong> &#8211; the unknown frontier of securing AI agents and agentic workflows</p></li></ul><h3>Trends Discussed</h3><ul><li><p>Social engineering and phishing &#8211; still trending, now AI-enhanced</p></li><li><p>Browser extensions &#8211; emerging attack vector</p></li><li><p>OpenClaw/MoltBot ecosystem &#8211; AI agents with their own social networks</p></li><li><p>AI vulnerability discovery &#8211; 12 OpenSSL vulnerabilities found by AI, some allegedly decades old</p></li><li><p>CVE reports up ~39-40% last year</p></li><li><p>Google&#8217;s agentic defense approach &#8211; breaking prompts into investigation phases</p></li><li><p>Prompt injection &#8211; social engineering AI agents and models</p></li><li><p>Curl leaving HackerOne due to AI-generated bug bounty report influx</p></li></ul><h2>&#128226; Call to Action</h2><ul><li><p><strong>Read the January builder series on Dispatch</strong> &#8211; and start your own building journey; even a script that saves you a few minutes counts</p></li><li><p><strong>Try building something you&#8217;ll actually use</strong> &#8211; throw it on GitHub, start small, keep building</p></li><li><p><strong>Check out the AI Daily Brief podcast and Prompt GTFO</strong> &#8211; for staying current on AI and security</p></li><li><p><strong>Get Wispr Flow</strong> &#8211; if you struggle with prompt engineering, just talk at your AI</p></li><li><p><strong>Explore automated baselining</strong> &#8211; use the Detect FYI approach (30-day baseline + hourly deviation checks)</p></li><li><p><strong>Come find us at CactusCon</strong> &#8211; February 2026, THOR Collective is sponsoring the after party; swag will be available</p></li><li><p><strong>Write for THOR Collective</strong> &#8211; always looking for new voices, up-and-coming voices, and first-time publishers; reach out on socials</p></li></ul><h2>&#128236; Connect with THOR Collective</h2><h3>&#128483;&#65039; Social Media:</h3><ul><li><p>Twitter/X: <a href="https://x.com/THOR_Collective">@THOR_Collective</a></p></li><li><p>LinkedIn: <a href="https://www.linkedin.com/company/thorcollective">THOR Collective</a></p></li><li><p>BlueSky: <a href="https://bsky.app/profile/thorcollective.bsky.social">@thorcollective</a></p></li></ul><h3>&#128231; Contact:</h3><p>Reach out through any social channel for guest post opportunities, collaborations, or to share what you&#8217;re building in 2026</p>]]></content:encoded></item><item><title><![CDATA[How I Use LLMs for Security Work]]></title><description><![CDATA[I&#8217;ve been using LLM tools like Claude, Cursor, and ChatGPT extensively in my security & engineering work for the past couple years.]]></description><link>https://dispatch.thorcollective.com/p/how-i-use-llms-for-security-work</link><guid isPermaLink="false">https://dispatch.thorcollective.com/p/how-i-use-llms-for-security-work</guid><dc:creator><![CDATA[Josh Rickard]]></dc:creator><pubDate>Tue, 03 Feb 2026 19:30:15 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!8mB0!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f0d0d66-07ae-4f5b-a26a-b6d91cfc488e_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;ve been using LLM tools like Claude, Cursor, and ChatGPT extensively in my security &amp; engineering work for the past couple years. Not as a replacement for thinking&#8212;but they genuinely help me move faster through complex problems. If you&#8217;re a security analyst, SOC analyst, threat hunter or engineer who hasn&#8217;t found a rhythm with these tools yet, I&#8217;ll try to share what&#8217;s been working for me with the hope it helps you too.</p><p>Here&#8217;s the thing: most people prompt LLMs like they&#8217;re searching Google. They type a few keywords and expect magic. That doesn&#8217;t work, especially for security work where context and precision matter. You wouldn&#8217;t walk up to a senior analyst and say &#8220;phishing bad, clicked link, help&#8221; and expect useful output. Same principle applies here. The way you prompt these tools completely changes what you get back.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">THOR Collective Dispatch is a reader-supported publication. To receive new posts and support our work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>I don&#8217;t claim to be an expert by any means so please take this all as my opinion--I know there are many other ways to approach using LLMs. I&#8217;ve used approaches like:</p><ul><li><p>writing a design &amp; requirement document and feeding that into an LLM while writing examples shared below.</p></li><li><p>providing a repository of code and giving clear problem statements</p></li><li><p>question &amp; answer analysis</p></li><li><p>etc.</p></li></ul><p>Here&#8217;s some examples of how I think they can be most useful for security peeps just starting out with LLMs.</p><h2><strong>Role-Stacking: Set the Stage</strong></h2><p>One of the most effective techniques I&#8217;ve found is what I call &#8220;role-stacking.&#8221; Instead of just asking a question, I tell the LLM what perspectives I need it to consider. I also found that using my own experience when setting the stage is extremely helpful since it&#8217;s what I know.</p><p>Here&#8217;s an example:</p><pre><code><code>As a security analyst and phishing threat detection expert. As a software engineer experienced with Python, Flask, and Docker.

Create a simple Flask (bootstap, etc.) application to collect DNS, WHOIS/RDAP, HTML and other opensource threat intelligence for a given URL.
</code></code></pre><p>Notice what I did there. I&#8217;m not just asking &#8220;create a simple flask application.&#8221; I&#8217;m telling the LLM to think from multiple angles simultaneously&#8212;security analysis, phishing expertise, and software engineering. This produces output that bridges disciplines rather than staying siloed.</p><p>For SOC analysts, this might look like:</p><pre><code><code>As a SOC analyst experienced in alert triage. As a threat hunter 
familiar with MITRE ATT&amp;CK. As someone who has dealt with alert 
fatigue firsthand.

Analyze this detection rule and identify potential blind spots or false positive generators.
</code></code></pre><p>The role-stacking approach forces the LLM to consider your problem from multiple angles, which often shows you things you wouldn&#8217;t get from a single-perspective prompt.</p><h2><strong>Be Explicit About Your Technology Stack</strong></h2><p>LLMs perform dramatically better when you tell them what you&#8217;re actually working with. Be specific about the technologies, products, and constraints in your environment (as much as you know).</p><p>Here&#8217;s how I do it:</p><pre><code><code>As a senior security engineer and sr. software engineer. Experience 
with Docker, Kubernetes, caching, data streaming, gRPC, protobuf, 
JSONSchema, common data models, Puppeteer, Playwright, extensive 
experience with APIs, network communications, web frameworks, 
anti-bot detection, Chromium, Selenium, network captures, monitoring, 
knowledge about fingerprinting, cookie injection, evading behavioral 
turnstiles/captchas.

Using these technologies, products, tools, frameworks and knowledge 
bases, let's design an application that [specific goal]...
</code></code></pre><p>I know that looks like a lot. I mean, it is a lot. But here&#8217;s why it matters: the LLM now knows exactly what tools are on the table. It &#8220;shouldn&#8217;t&#8221; suggest solutions using technologies I don&#8217;t have (but it does sometimes but I have found this approach helps). It&#8217;ll reason within my actual constraints most of the time. When it does, it&#8217;s a huge benefit--especially when you&#8217;re trying to solve real problems in your actual environment&#8212;-not hypothetical ones.</p><p>For threat hunters, this might be:</p><pre><code><code>As a threat hunter with access to Splunk, CrowdStrike EDR, and 
network flow data. Working in a hybrid cloud environment with 
AWS and on-prem Windows infrastructure. Familiar with Sigma 
rules and MITRE ATT&amp;CK.

Help me develop a hunting hypothesis for [specific threat behavior].
</code></code></pre><h2><strong>Request Thoroughness Explicitly</strong></h2><p>So, how do you get past the surface-level responses? LLMs will often give you the quick answer&#8212;which is usually the shallow answer. If you want depth, you have to ask for it and provide a very specific example output.</p><p>I frequently use phrases like:</p><ul><li><p>&#8220;Take your time, think through carefully&#8221;</p></li><li><p>&#8220;Use critical systems thinking&#8221;</p></li><li><p>&#8220;Consider batch and streaming patterns, integration patterns, and how this evolves over time&#8221;</p></li><li><p>&#8220;Do not hallucinate and validate any decisions and findings&#8221;</p></li></ul><p>That last one is important. Honestly, these tools can confidently generate plausible-sounding nonsense. Telling them explicitly to validate their reasoning helps&#8212;not perfectly, but noticeably.</p><p>Here&#8217;s an example:</p><pre><code><code>Using your knowledge of cyber security and threat intelligence 
as it relates to phishing defense. We are evaluating several 
products to integrate into our detection pipeline.

We are evaluating VirusTotal GTI, Team Cymru, Feedly, and any.run.

Knowing all that, create an evaluation criteria process.

Take your time. Think through carefully. Do not hallucinate&#8212;validate 
any decisions and findings.
</code></code></pre><h2><strong>Ask for Current Information</strong></h2><p>This is especially important for security work where the landscape changes constantly. Tools, techniques, and threat actor behaviors evolve. Explicitly ask for updated context:</p><pre><code><code>Search for the latest information regarding security tools and products.

Evaluate the best option for a sandbox analysis tool when it 
comes to inspecting and analyzing both phishing links and 
attachments from phishing emails.
</code></code></pre><p>Will the LLM always have the latest data? No. Prompting it this way encourages it to reason about recency and often produces more thoughtful responses about what might have changed. Luckily, many of these tools have web search capabilities, so this prompt pattern becomes even more effective.</p><h2><strong>Think in Systems, Not Point Solutions</strong></h2><p>Security work is inherently about systems&#8212;interconnected components that create emergent behaviors (and emergent vulnerabilities). I prompt AI tools to think the same way.</p><p>Here&#8217;s an example from my own work:</p><pre><code><code>Imagine you have a platform which can use a list of indicators 
to hunt backwards in time for up to 30 days. The list of indicators 
per type (domains, IP addresses, URLs, files) will add about 
2 million new indicators per day that we must back-test/hunt for. 
As each day passes, the indicators exponentially grow in size.

Provide 5 options for building a system to handle and manage this data for X years. Remember to use critcial systems thinking.
</code></code></pre><p>This prompt describes a real systems problem&#8212;not a feature request. The tool now has to reason about data growth, retention strategies, computational constraints, and tradeoffs. That&#8217;s the kind of thinking that produces useful output.</p><p>For SOC analysts dealing with alert volume, try:</p><pre><code><code>Our SIEM generates approximately 50,000 alerts per day across 
200 detection rules. About 15% of our analyst time is spent on 
5 rules that generate 60% of the volume.

How should we approach optimizing this situation? Consider both short-term tactical fixes and 
longer-term strategic improvements.
</code></code></pre><h2><strong>Practical Tips for Getting Started</strong></h2><p>If you&#8217;re new to using LLMs for security work, here are some concrete starting points:</p><ul><li><p><strong>Start with role-stacking</strong>: Before every prompt, think about what perspectives would be valuable. Security analyst? Software engineer? Incident responder? Stack them.</p></li><li><p><strong>Be embarrassingly specific</strong>: Include your actual tools, technologies, and constraints. The more context, the better the output.</p></li><li><p><strong>Ask for validation</strong>: Explicitly request that the LLM validate its reasoning and not hallucinate. It helps.</p></li><li><p><strong>Think in systems</strong>: Frame your questions as systems problems, not isolated tasks.</p></li><li><p><strong>Iterate</strong>: Your first prompt won&#8217;t be perfect. Refine based on what you get back. Tell the tool what was useful and what wasn&#8217;t.</p></li></ul><p>Finally, if you really want to stretch how you think about LLMs. Once you have completed a project / idea tell the tool to write a mark down file that can be used next time when wanting to create a similar tool (or just a project in general).</p><p>An additional approach I have been playing with is asking the LLM to generate this markdown document in a way that considers current and future progressions of how we interface with LLMs and to build it in a way that is most efficient for the LLM itself.</p><p>For example:</p><pre><code><code>Assess this project as a whole and generate a markdown definiton that will be used in the future for similar projects. Think about the current adoption and patterns used to interact with LLMs as well as future progression based on industry trends.

Generate this document so that it is efficient, clear and precise for future iterations.
</code></code></pre><p>That&#8217;s it! These six techniques cover about 90% of how I get value from LLMs in my daily work.</p><h2><strong>A Note on People</strong></h2><p>With that being said, I want to be clear about something: these are tools to augment human judgment, not replace it. The value of a good security analyst isn&#8217;t their ability to generate text&#8212;it&#8217;s their judgment, their intuition, their ability to recognize what doesn&#8217;t fit.</p><p>LLMs help me move faster through the mechanical parts of my work. They help me explore ideas, draft documentation, reason through complex systems. But the decisions? Those are still mine.</p><p>As InfoSec professionals, we&#8217;re responsible for the security of real people and real organizations. LLms can help us do that job better&#8212;but only if we stay in the driver&#8217;s seat. Just remember that these tools are amplifiers&#8212;they amplify good thinking and bad thinking alike. Bring the good thinking.</p><h2><strong>What&#8217;s Next</strong></h2><p>I&#8217;m still learning how to use these tools effectively. The techniques I&#8217;ve shared here are simplified examples of what&#8217;s working for me right now, but I expect they&#8217;ll evolve as the tools themselves improve.</p><p>I&#8217;m currently building my own <code>agent</code> and <code>workflow</code> (state machines) so I may write about that next as I continue to learn and adapt on the many ways you can approach those problems.</p><p>In the real world, especially more complex work, I define my goals, general requirements, my constraints, ideal/desired inputs and outputs. Remember the more context you given an LLM the better it will be (e.g. provide reference API docs, schemas, query examples, etc.).</p><p>If you&#8217;ve found effective prompting patterns for security work, I&#8217;d love to hear about them. Reach out on LinkedIn or GitHub&#8212;let&#8217;s share what&#8217;s working.</p><p>I hope this helps some of you get more out of these tools. The threat landscape isn&#8217;t slowing down. Neither should we.</p><p>Enjoy!</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">THOR Collective Dispatch is a reader-supported publication. To receive new posts and support our work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p><br></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://dispatch.thorcollective.com/p/how-i-use-llms-for-security-work/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://dispatch.thorcollective.com/p/how-i-use-llms-for-security-work/comments"><span>Leave a comment</span></a></p><p></p>]]></content:encoded></item></channel></rss>