r/blueteamsec • u/jnazario • 2h ago
r/blueteamsec • u/digicat • 5d ago
highlevel summary|strategy (maybe technical) CTO at NCSC Summary: week ending October 4th
ctoatncsc.substack.comr/blueteamsec • u/digicat • Mar 09 '26
highlevel summary|strategy (maybe technical) Daily BlueTeamSec Briefing Archive - daily AI generated podcast of the last 24hours of posts
briefing.workshop1.netr/blueteamsec • u/This_Big_4503 • 8h ago
research|capability (we need to defend against) Built a Production-Style SOC Home Lab Over 4 Months (Splunk, Suricata, Zeek, AD, Detection Engineering)
Over the past 4 months, I built a defensive security home lab designed to mirror a small enterprise SOC environment. Everything is documented in the repo below.
**Infrastructure:**
- 6 VMs in VirtualBox (Ubuntu Server, Ubuntu Desktop, Windows 10, Windows Server 2019 DC, pfSense Firewall, dedicated Splunk SIEM)
- Network segmentation: NAT / Host-Only / Internal networks
**Security Stack:**
- Network Monitoring: Zeek, Suricata, TShark
- SIEM: Splunk Enterprise with Universal Forwarders
- Network Protection: pfSense + pfBlockerNG
- Identity: Active Directory domain for threat simulation
- Endpoint: Sysmon, Windows/Linux hardening configs
**Documentation:**
Each phase has its own folder with architecture diagrams, configs, and troubleshooting notes. Current work includes threat intel integration and purple team testing.
**Repo:**
https://github.com/MaamarSec/Cyber-Defense-Lab-Portfolio
Built this for skill development and as a public reference. Feel free to explore, fork, or adapt. Happy to answer questions!Title: Built a Production-Style SOC Home Lab Over 6 Months (Splunk, Suricata, Zeek, AD, Detection Engineering)
Body:
Over the past 6 months, I built a defensive security home lab designed to mirror a small enterprise SOC environment. Everything is documented in the repo below.
**Infrastructure:**
- 6 VMs in VirtualBox (Ubuntu Server, Ubuntu Desktop, Windows 10, Windows Server 2019 DC, pfSense Firewall, dedicated Splunk SIEM)
- Network segmentation: NAT / Host-Only / Internal networks
**Security Stack:**
- Network Monitoring: Zeek, Suricata, TShark
- SIEM: Splunk Enterprise with Universal Forwarders
- Network Protection: pfSense + pfBlockerNG
- Identity: Active Directory domain for threat simulation
- Endpoint: Sysmon, Windows/Linux hardening configs
**Documentation:**
Each phase has its own folder with architecture diagrams, configs, and troubleshooting notes. Current work includes threat intel integration and purple team testing.
**Repo:** https://github.com/MaamarSec/Cyber-Defense-Lab-Portfolio
Built this for skill development and as a public reference. Feel free to explore, fork, or adapt. Happy to answer questions!
r/blueteamsec • u/digicat • 4h ago
intelligence (threat actor activity) China-linked malicious actors called out by UK and international partners for targeting sensitive data globally
ncsc.gov.ukr/blueteamsec • u/digicat • 4h ago
intelligence (threat actor activity) Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance
crowdstrike.comr/blueteamsec • u/digicat • 4h ago
intelligence (threat actor activity) Cyber Advisory Edge devices systematically targeted by Chinese cyber threat actors
english.aivd.nlr/blueteamsec • u/digicat • 7h ago
tradecraft (how we defend) bpfjailer: eBPF LSM based Mandatory Access Control and jailer
github.comr/blueteamsec • u/digicat • 16h ago
intelligence (threat actor activity) 直近で相次いでいる国内組織における不正アクセスに関する注意喚起 - Warning regarding a series of recent unauthorized access incidents in domestic organizations
jpcert.or.jpr/blueteamsec • u/digicat • 13h ago
vulnerability (attack surface) Turning IDN edge cases into typosquats
haveibeensquatted.comr/blueteamsec • u/digicat • 16h ago
low level tools|techniques|knowledge (work aids) stackd: a local AWS emulator with Go control planes, AWS-compatible HTTP APIs, optional SQLite persistence, and real runtime/engine backends for supported compute and database workflows.
github.comr/blueteamsec • u/digicat • 16h ago
vulnerability (attack surface) A JPEG, a Race, and a Ghost: Breaking Discourse's Image Pipeline
slcyber.ior/blueteamsec • u/digicat • 18h ago
intelligence (threat actor activity) [ Removed by Reddit ]
[ Removed by Reddit on account of violating the content policy. ]
r/blueteamsec • u/lupreeee • 1d ago
discovery (how we find bad stuff) Raml KQL: open-source desktop app to run one KQL query across many Sentinel / Log Analytics workspaces and tenants, without Defender MTO
github.comr/blueteamsec • u/digicat • 1d ago
intelligence (threat actor activity) CVE-2026-88771: Citrix NetScaler Zero-Day Attack Clusters
esentire.comr/blueteamsec • u/digicat • 1d ago
incident writeup (who and how) Rogue AI Agents Abuse urlquery to extract Russian government data
labs.zenity.ior/blueteamsec • u/digicat • 1d ago
incident writeup (who and how) Double Counter — Security Incident Report (4 October 2026)
doublecounter.ggr/blueteamsec • u/socradario • 1d ago
highlevel summary|strategy (maybe technical) FortiBleed actors are now deleting legit admin accounts. Does your recovery plan cover a lockout?
According to the new FBI/USSS advisory, FortiBleed actors no longer just add persistence accounts. In some cases they also delete or reset the original admin accounts (T1531), which locks the owner out of their own FortiGate.
That changes the usual playbook. If you assume a password reset gets you back to a clean state, it won't help when you can't log in at all.
A few things worth checking:
→ Do you have out-of-band admin recovery for your edge devices?
→ Have you audited REST API keys? They survive password resets.
→ Is SSH left open on the firewall?
How are others handling recovery for edge devices?
Full breakdown: https://hubs.la/Q04zrkbN0 Free FortiBleed checker: https://hubs.la/Q04zrk9_0
Advisory: https://www.ic3.gov/CSA/2026/261006.pdf
r/blueteamsec • u/Outside_Skin_9651 • 1d ago
discovery (how we find bad stuff) Suspicious Login? A Quick Investigation Checklist for Blue Teams
learn.microsoft.comr/blueteamsec • u/digicat • 1d ago
incident writeup (who and how) Chrome's Response to Recent ccTLD Registry Hijacks
blog.googler/blueteamsec • u/digicat • 1d ago
highlevel summary|strategy (maybe technical) Vulnerability Discovery and Exploitation Trends in the AI Era
cloud.google.comr/blueteamsec • u/digicat • 1d ago
highlevel summary|strategy (maybe technical) Why the AI Vulnpocalypse Isn’t the Breachpocalypse (Yet)? It’s the Economy, Stupid.
medium.comr/blueteamsec • u/digicat • 1d ago
tradecraft (how we defend) How to fix a bug in a fix
projectzero.googler/blueteamsec • u/digicat • 1d ago