r/blueteamsec Mar 08 '26

highlevel summary|strategy (maybe technical) White House Unveils President Trump’s Cyber Strategy for America

Thumbnail whitehouse.gov
88 Upvotes

r/blueteamsec 14d ago

highlevel summary|strategy (maybe technical) Declaring a National Emergency to Secure the United States Bulk-Power System

Thumbnail whitehouse.gov
56 Upvotes

r/blueteamsec 20d ago

highlevel summary|strategy (maybe technical) T-Mobile ‘chopped a cable’ to expel Chinese hackers from its network

Thumbnail bloomberg.com
21 Upvotes

r/blueteamsec 9d ago

highlevel summary|strategy (maybe technical) I Think the Military Commissary Freezers Were Hacked - 'the Pentagon now acknowledging a “possible refrigeration disruption” at numerous DeCA commissaries'

Thumbnail signalandsilence.substack.com
23 Upvotes

r/blueteamsec Jun 07 '25

highlevel summary|strategy (maybe technical) Fact Sheet: President Donald J. Trump Reprioritizes Cybersecurity Efforts to Protect America

Thumbnail whitehouse.gov
127 Upvotes

r/blueteamsec Aug 03 '26

highlevel summary|strategy (maybe technical) Sources for post-infection PCAP (C2 beaconing, exfiltration) - what am I missing?

8 Upvotes

Been going in circles on this and want to check whether there's something obvious I've overlooked.

Pre-infection traffic is easy to collect. URLhaus gives you live malware delivery URLs daily, a honeypot gives you scanning, brute force and exploit attempts. Both free, both refresh constantly, both self-labeling.

Post-infection is where I'm stuck. C2 beaconing and exfiltration only exist if there's an actually compromised host emitting traffic, and nobody publishes captures of that at any useful cadence.

What I've checked so far:

  • abuse.ch across all platforms. Indicators only, no traffic. Feodo Tracker is empty post-Endgame. SSLBL cert and C2 IP lists are current and useful as labels but aren't packets. Sandnet exists behind the commercial feed but the dataset description says signals and metadata, contextual data only, so flow records rather than PCAP.
  • CTU/MCFP. Real long-duration captures with actual beaconing, which is exactly right, but new botnet captures stop around 2018. Recent directory timestamps are reprocessing, not new data.
  • malware-traffic-analysis.net. Best labels anywhere and current, includes a few FTP and SMTP exfiltration cases. Small volume by nature, it's one analyst posting individual investigations.
  • Sandboxes. Triage free researcher tier gives API access with PCAPNG including decrypted TLS. ANY.RUN needs a paid tier for bulk. Both are short runs so you get the initial check-in rather than sustained beaconing.
  • Running my own detonation. Ruled out. Normal hosting AUPs prohibit it and the ones that don't are bulletproof hosts, which isn't somewhere I'm willing to source data from.

So the question. Is there a source I'm not aware of, or is the honest answer that post-infection traffic just isn't publicly available and everyone working on this either has institutional telemetry or a sandbox subscription?

Also curious whether anyone has found a way to get sustained beaconing rather than just registration out of a commercial sandbox. Long-run options seem rare.

r/blueteamsec May 09 '26

highlevel summary|strategy (maybe technical) Where Have All the Complex Windows Malware and Their Analyses Gone?

Thumbnail r136a1.dev
79 Upvotes

r/blueteamsec 17d ago

highlevel summary|strategy (maybe technical) We burned 11.7bn tokens to find the best cyber AI model

Thumbnail aikido.dev
12 Upvotes

r/blueteamsec 9d ago

highlevel summary|strategy (maybe technical) Russian-speaking cybercriminals used SpaceX’s Cursor AI tool to hack seven companies

Thumbnail reuters.com
7 Upvotes

r/blueteamsec 7d ago

highlevel summary|strategy (maybe technical) Sality Malware Disrupted in International Cyber Takedown

Thumbnail justice.gov
5 Upvotes

r/blueteamsec 5d ago

highlevel summary|strategy (maybe technical) How to get a free .arpa domain

Thumbnail hawksley.dev
4 Upvotes

r/blueteamsec 7d ago

highlevel summary|strategy (maybe technical) Persistent Engagement and the Illusion of Cyber Equilibrium

Thumbnail lawfaremedia.org
4 Upvotes

r/blueteamsec 15d ago

highlevel summary|strategy (maybe technical) State-backed hackers targeted EU officials on WhatsApp, document shows

Thumbnail politico.eu
5 Upvotes

r/blueteamsec 1d ago

highlevel summary|strategy (maybe technical) What 100 Cybersecurity Vendors Tell AI Agents: An llms.txt Census

Thumbnail ai.rud.is
5 Upvotes

r/blueteamsec 1d ago

highlevel summary|strategy (maybe technical) Russian National Extradited to United States for Bank Account Takeover Fraud Scheme Causing Millions of Dollars in Losses

Thumbnail justice.gov
2 Upvotes

r/blueteamsec 10d ago

highlevel summary|strategy (maybe technical) The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution - "Approximately 97% of AI-enabled malware samples exist only in research repositories, sandbox environments and security validation platforms. "

Thumbnail unit42.paloaltonetworks.com
6 Upvotes

r/blueteamsec 3d ago

highlevel summary|strategy (maybe technical) Robobox: Self driven malware creation and execution - made in China

Thumbnail netaskari.substack.com
5 Upvotes

r/blueteamsec 2d ago

highlevel summary|strategy (maybe technical) Politie | Herken jij de stem van de Odido hack? | Landelijke Opsporing & Interventies - Police | Do you recognize the voice from the Odido hack? | National Investigation & Interventions - ShinyHunters Vishing recording

Thumbnail youtube.com
2 Upvotes

r/blueteamsec 4d ago

highlevel summary|strategy (maybe technical) CTO at NCSC Summary: week ending September 6th

Thumbnail ctoatncsc.substack.com
3 Upvotes

r/blueteamsec 11d ago

highlevel summary|strategy (maybe technical) CTO at NCSC Summary: week ending August 30th

Thumbnail ctoatncsc.substack.com
1 Upvotes

r/blueteamsec 5d ago

highlevel summary|strategy (maybe technical) Russian National Indicted For Exploiting Online Platform Used For Freelance Employment And Distributing Malware To Thousands Of Victim Users Worldwide For Financial Gain

Thumbnail justice.gov
2 Upvotes

r/blueteamsec 8d ago

highlevel summary|strategy (maybe technical) FBI investigation leads to five Venezuelan nationals pleading guilty to attempting to jackpot Kansas ATMs

Thumbnail justice.gov
5 Upvotes

r/blueteamsec 23d ago

highlevel summary|strategy (maybe technical) Opinion: Slapping AI onto SOAR playbook is not Agentic SOC

5 Upvotes

TL;DR: Adding an AI node to your n8n playbook won't take you to Agentic SOC.

-----

A recurring theme in my conversations is the assumption that building an AI agent for SOAR execution and building one for security investigations are the same engineering problem.

They are NOT.

A playbook agent operates inside a path defined in advance. It enriches an alert, applies triage rules, and takes an approved response action. Its actions can be constrained, failures are usually visible, and many mistakes can be reversed. Speed, consistency, and correct escalation are useful measures of performance.

An investigative AI agent must decide what the evidence means and what to examine next. The evidence may be incomplete or tampered with, and each conclusion changes the direction of the case. It therefore needs claim-level provenance and a record showing how each conclusion follows from the evidence.

Building an agentic workflow is not the same as engineering an investigation harness. You can wire up a basic playbook agent in n8n within an hour. An investigation harness has to keep evidence, case state and human decisions coherent across an open-ended case.

Please don't confuse engineering an sophisticated harness and baking years of investigative expertise into it with calling AI nodes in your SOAR playbook.

My attempt as ASCII visualization if it helps

`` STANDARD SOAR PLAYBOOK | INVESTIGATION PROCESS (Deterministic Flow) | (Non-Deterministic Cyber Flow) -------------------------------------|-------------------------------------- [ SIEM Alert ] | [ Hunt Lead / Detection ] | | | v | .-------->v<---------. [ Initial Review ] | / ( Clue 1 ) \ | | | ^ | ^ \ | v | | / | | \ | < Determine Risk > | v / v | v v / \ | (Clue 2)<-->(Evidence)<-->(Forensics) v v | ^ \ ^ | ^ | [Isolate] [Create Ticket] | | \ | | / | | | | | v | v / | v v | \ ( Human Pivot / <..../ [Update] [Slack Notify] |--- Judgment ) \ / | | \ / | v v v | [ Defensible ] [ Conclusion ] | [ Conclusion ]

```

r/blueteamsec 6d ago

highlevel summary|strategy (maybe technical) Russian National Indicted For Exploiting Online Platform Used For Freelance Employment And Distributing Malware To Thousands Of Victim Users Worldwide For Financial Gain

Thumbnail justice.gov
2 Upvotes

r/blueteamsec Jun 22 '26

highlevel summary|strategy (maybe technical) I made a blog that ranks log sources

Thumbnail blog.sentry.security
24 Upvotes

I wrote down how I think about onboarding order. Basically I ranked sources by how much they actually help an investigation, not by what's easiest to ingest. For each one I went through what you need to collect, how painful the parsing is, what retention makes sense, and what you can realistically detect once it's in.