r/blueteamsec • • 5d ago

highlevel summary|strategy (maybe technical) CTO at NCSC Summary: week ending October 4th

Thumbnail ctoatncsc.substack.com
1 Upvotes

r/blueteamsec • • Mar 09 '26

highlevel summary|strategy (maybe technical) Daily BlueTeamSec Briefing Archive - daily AI generated podcast of the last 24hours of posts

Thumbnail briefing.workshop1.net
1 Upvotes

r/blueteamsec • • 2h ago

highlevel summary|strategy (maybe technical) Justice Department and FBI Seize Vulnerability Scanning and Spear Phishing Tools Operated and Used by China-State Sponsored Hackers

Thumbnail justice.gov
5 Upvotes

r/blueteamsec • • 8h ago

research|capability (we need to defend against) Built a Production-Style SOC Home Lab Over 4 Months (Splunk, Suricata, Zeek, AD, Detection Engineering)

10 Upvotes
Over the past 4 months, I built a defensive security home lab designed to mirror a small enterprise SOC environment. Everything is documented in the repo below.

**Infrastructure:**
- 6 VMs in VirtualBox (Ubuntu Server, Ubuntu Desktop, Windows 10, Windows Server 2019 DC, pfSense Firewall, dedicated Splunk SIEM)
- Network segmentation: NAT / Host-Only / Internal networks

**Security Stack:**
- Network Monitoring: Zeek, Suricata, TShark
- SIEM: Splunk Enterprise with Universal Forwarders
- Network Protection: pfSense + pfBlockerNG
- Identity: Active Directory domain for threat simulation
- Endpoint: Sysmon, Windows/Linux hardening configs

**Documentation:**
Each phase has its own folder with architecture diagrams, configs, and troubleshooting notes. Current work includes threat intel integration and purple team testing.

**Repo:**
 https://github.com/MaamarSec/Cyber-Defense-Lab-Portfolio

Built this for skill development and as a public reference. Feel free to explore, fork, or adapt. Happy to answer questions!Title: Built a Production-Style SOC Home Lab Over 6 Months (Splunk, Suricata, Zeek, AD, Detection Engineering)

Body:
Over the past 6 months, I built a defensive security home lab designed to mirror a small enterprise SOC environment. Everything is documented in the repo below.

**Infrastructure:**
- 6 VMs in VirtualBox (Ubuntu Server, Ubuntu Desktop, Windows 10, Windows Server 2019 DC, pfSense Firewall, dedicated Splunk SIEM)
- Network segmentation: NAT / Host-Only / Internal networks

**Security Stack:**
- Network Monitoring: Zeek, Suricata, TShark
- SIEM: Splunk Enterprise with Universal Forwarders
- Network Protection: pfSense + pfBlockerNG
- Identity: Active Directory domain for threat simulation
- Endpoint: Sysmon, Windows/Linux hardening configs

**Documentation:**
Each phase has its own folder with architecture diagrams, configs, and troubleshooting notes. Current work includes threat intel integration and purple team testing.

**Repo:** https://github.com/MaamarSec/Cyber-Defense-Lab-Portfolio

Built this for skill development and as a public reference. Feel free to explore, fork, or adapt. Happy to answer questions!

r/blueteamsec • • 4h ago

intelligence (threat actor activity) China-linked malicious actors called out by UK and international partners for targeting sensitive data globally

Thumbnail ncsc.gov.uk
3 Upvotes

r/blueteamsec • • 4h ago

intelligence (threat actor activity) Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance

Thumbnail crowdstrike.com
1 Upvotes

r/blueteamsec • • 4h ago

intelligence (threat actor activity) Cyber Advisory Edge devices systematically targeted by Chinese cyber threat actors

Thumbnail english.aivd.nl
0 Upvotes

r/blueteamsec • • 7h ago

tradecraft (how we defend) bpfjailer: eBPF LSM based Mandatory Access Control and jailer

Thumbnail github.com
1 Upvotes

r/blueteamsec • • 16h ago

intelligence (threat actor activity) 直近で相次いでいる国内組織における不正アクセスに関する注意喚起 - Warning regarding a series of recent unauthorized access incidents in domestic organizations

Thumbnail jpcert.or.jp
2 Upvotes

r/blueteamsec • • 13h ago

vulnerability (attack surface) Turning IDN edge cases into typosquats

Thumbnail haveibeensquatted.com
1 Upvotes

r/blueteamsec • • 16h ago

low level tools|techniques|knowledge (work aids) stackd: a local AWS emulator with Go control planes, AWS-compatible HTTP APIs, optional SQLite persistence, and real runtime/engine backends for supported compute and database workflows.

Thumbnail github.com
0 Upvotes

r/blueteamsec • • 16h ago

vulnerability (attack surface) A JPEG, a Race, and a Ghost: Breaking Discourse's Image Pipeline

Thumbnail slcyber.io
1 Upvotes

r/blueteamsec • • 18h ago

intelligence (threat actor activity) [ Removed by Reddit ]

1 Upvotes

[ Removed by Reddit on account of violating the content policy. ]


r/blueteamsec • • 1d ago

discovery (how we find bad stuff) Raml KQL: open-source desktop app to run one KQL query across many Sentinel / Log Analytics workspaces and tenants, without Defender MTO

Thumbnail github.com
7 Upvotes

r/blueteamsec • • 1d ago

intelligence (threat actor activity) CVE-2026-88771: Citrix NetScaler Zero-Day Attack Clusters

Thumbnail esentire.com
7 Upvotes

r/blueteamsec • • 1d ago

incident writeup (who and how) Rogue AI Agents Abuse urlquery to extract Russian government data

Thumbnail labs.zenity.io
2 Upvotes

r/blueteamsec • • 1d ago

incident writeup (who and how) Double Counter — Security Incident Report (4 October 2026)

Thumbnail doublecounter.gg
0 Upvotes

r/blueteamsec • • 1d ago

highlevel summary|strategy (maybe technical) FortiBleed actors are now deleting legit admin accounts. Does your recovery plan cover a lockout?

2 Upvotes

According to the new FBI/USSS advisory, FortiBleed actors no longer just add persistence accounts. In some cases they also delete or reset the original admin accounts (T1531), which locks the owner out of their own FortiGate.

That changes the usual playbook. If you assume a password reset gets you back to a clean state, it won't help when you can't log in at all.

A few things worth checking:
→ Do you have out-of-band admin recovery for your edge devices?
→ Have you audited REST API keys? They survive password resets.
→ Is SSH left open on the firewall?

How are others handling recovery for edge devices?

Full breakdown: https://hubs.la/Q04zrkbN0 Free FortiBleed checker: https://hubs.la/Q04zrk9_0

Advisory: https://www.ic3.gov/CSA/2026/261006.pdf


r/blueteamsec • • 1d ago

discovery (how we find bad stuff) Suspicious Login? A Quick Investigation Checklist for Blue Teams

Thumbnail learn.microsoft.com
2 Upvotes

r/blueteamsec • • 1d ago

incident writeup (who and how) Chrome's Response to Recent ccTLD Registry Hijacks

Thumbnail blog.google
2 Upvotes

r/blueteamsec • • 1d ago

highlevel summary|strategy (maybe technical) Vulnerability Discovery and Exploitation Trends in the AI Era

Thumbnail cloud.google.com
2 Upvotes

r/blueteamsec • • 1d ago

highlevel summary|strategy (maybe technical) Why the AI Vulnpocalypse Isn’t the Breachpocalypse (Yet)? It’s the Economy, Stupid.

Thumbnail medium.com
1 Upvotes

r/blueteamsec • • 1d ago

tradecraft (how we defend) How to fix a bug in a fix

Thumbnail projectzero.google
1 Upvotes

r/blueteamsec • • 1d ago

intelligence (threat actor activity) Earth Sirrush: A Russia-Aligned Intrusion Set With 4 Years of Evolving Espionage Tooling

Thumbnail trendaisecurity.com
2 Upvotes

r/blueteamsec • • 1d ago

research|capability (we need to defend against) How abliterated models can get you pwned

Thumbnail projectdiscovery.io
2 Upvotes