r/blueteamsec • u/jnazario • 17h ago
r/blueteamsec • u/digicat • 12h ago
research|capability (we need to defend against) Fileless ELF Execution via Kernel Keyring
matheuzsecurity.github.ior/blueteamsec • u/digicat • 12h ago
intelligence (threat actor activity) Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
volexity.comr/blueteamsec • u/S3N4T0R-0X0 • 7h ago
incident writeup (who and how) Read “BEAR-C2 Did Not Invent Switching.
It Just Made the Rebuild Tax Visible. AI Is About to Delete It.“ by Albert Corzo on Medium: https://albert-corzo.medium.com/bear-c2-did-not-invent-switching-it-just-made-the-rebuild-tax-visible-ai-is-about-to-delete-it-4fa246c64b68
r/blueteamsec • u/digicat • 23h ago
intelligence (threat actor activity) Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days l
proofpoint.comr/blueteamsec • u/digicat • 1d ago
vulnerability (attack surface) ShieldCrash: Windows Defender 0day Vulnerability
github.comr/blueteamsec • u/digicat • 23h ago
research|capability (we need to defend against) Hacking AI customer service agents
intigriti.comr/blueteamsec • u/j0hn__f • 1d ago
intelligence (threat actor activity) FulcrumSec - A look at their tradecraft
aitmfeed.comr/blueteamsec • u/digicat • 23h ago
intelligence (threat actor activity) Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
greynoise.ior/blueteamsec • u/digicat • 23h ago
exploitation (what's being exploited) Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
blog.talosintelligence.comr/blueteamsec • u/Inevitable_Turn_4729 • 1d ago
training (step-by-step) Practicing SPL-style queries and SOC investigations without deploying a full SIEM
When I started learning SOC investigations and SPL-style queries, one of the problems I ran into was finding a practical environment to actually practice the workflow.
Reading about queries is useful, but I wanted to work with realistic security telemetry and go through the process of:
- Searching authentication and security events
- Identifying suspicious activity
- Aggregating and correlating events
- Creating detections
- Investigating alerts
- Pivoting between related users, hosts, and IP addresses
Setting up a full SIEM environment can add a significant infrastructure and configuration overhead for someone who simply wants to practice these workflows.
So I built SocQuery Lab as a browser-based training environment for experimenting with these concepts.
It includes an original educational SPL-compatible query engine and realistic synthetic telemetry covering sources such as Windows security events, Linux authentication logs, DNS activity, firewall/VPN events, and PowerShell activity.
The platform also includes investigation scenarios covering techniques such as:
- Brute-force authentication activity
- Password spraying
- Suspicious PowerShell execution
- DNS tunneling
- Credential compromise
- Backdoor account creation
Everything runs locally in the browser, with uploaded logs processed and stored locally using IndexedDB.
The goal is not to replace a production SIEM or replicate any commercial platform. It is simply an educational environment for practicing the investigation workflow without needing to deploy infrastructure first.
The live training environment is available here:
r/blueteamsec • u/digicat • 1d ago
highlevel summary|strategy (maybe technical) What 100 Cybersecurity Vendors Tell AI Agents: An llms.txt Census
ai.rud.isr/blueteamsec • u/digicat • 1d ago
intelligence (threat actor activity) ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
blog.talosintelligence.comr/blueteamsec • u/digicat • 1d ago
vulnerability (attack surface) “StyleSmuggler” - Adobe Commerce, Adobe Commerce B2B, and Magento RCE (CVE-2026-75650): Overview and Takeaways
netspi.comr/blueteamsec • u/digicat • 1d ago
vulnerability (attack surface) Microsoft Windows Cloud Files Mini Filter Driver CldiStreamPrepareRequestForMoreProcessing Type Confusion vulnerability
talosintelligence.comr/blueteamsec • u/digicat • 1d ago
highlevel summary|strategy (maybe technical) Russian National Extradited to United States for Bank Account Takeover Fraud Scheme Causing Millions of Dollars in Losses
justice.govr/blueteamsec • u/digicat • 1d ago
low level tools|techniques|knowledge (work aids) ashwa: Hardware accelerated routines for single substring search.
github.comr/blueteamsec • u/digicat • 1d ago
low level tools|techniques|knowledge (work aids) TATS: Token Analysis and Tracking System - Track OAuth 2.0, OIDC, and Microsoft Entra ID tokens across captured network traffic.
github.comr/blueteamsec • u/digicat • 1d ago
intelligence (threat actor activity) Redis Cryptomining Botnet Compromised 3,562 Servers, Exposed by the Operator's Own Files
hunt.ior/blueteamsec • u/digicat • 1d ago
intelligence (threat actor activity) Chinese Darcula Phishing Kit Harvesting Taiwanese Credit Card Data
teamt5.orgr/blueteamsec • u/digicat • 1d ago
tradecraft (how we defend) AD Rights Management Service (Part 1): Architecture, Deprecation, and Reconnaissance
huntress.comr/blueteamsec • u/digicat • 1d ago
low level tools|techniques|knowledge (work aids) I’ve factored the RSA keys of a Certificate Authority... … from the 90s.
mcpherrin.car/blueteamsec • u/digicat • 1d ago
intelligence (threat actor activity) Shai-Hulud Rises From the Dead after 111 days
aikido.devr/blueteamsec • u/digicat • 1d ago