#blueteam — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #blueteam, aggregated by home.social.
-
2026-09-05 RDP #Honeypot IOCs - 2556 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
141.11.96.210 - 2409
103.178.235.50 - 27
217.160.240.135 - 27Top ASNs:
Unknown - 2409
AS396982 - 48
AS140810 - 27Top Accounts:
hello - 2469
Administr - 12
0siivpyz - 12Top ISPs:
Private Customer - 2409
Google LLC - 48
VPSTTT - 27Top Clients:
Unknown - 2556Top Software:
Unknown - 2556Top Keyboards:
Unknown - 2556Top IP Classification:
proxy - 2409
hosting - 99
hosting & proxy - 39Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-05 RDP #Honeypot IOCs - 2556 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
141.11.96.210 - 2409
103.178.235.50 - 27
217.160.240.135 - 27Top ASNs:
Unknown - 2409
AS396982 - 48
AS140810 - 27Top Accounts:
hello - 2469
Administr - 12
0siivpyz - 12Top ISPs:
Private Customer - 2409
Google LLC - 48
VPSTTT - 27Top Clients:
Unknown - 2556Top Software:
Unknown - 2556Top Keyboards:
Unknown - 2556Top IP Classification:
proxy - 2409
hosting - 99
hosting & proxy - 39Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-05 RDP #Honeypot IOCs - 2556 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
141.11.96.210 - 2409
103.178.235.50 - 27
217.160.240.135 - 27Top ASNs:
Unknown - 2409
AS396982 - 48
AS140810 - 27Top Accounts:
hello - 2469
Administr - 12
0siivpyz - 12Top ISPs:
Private Customer - 2409
Google LLC - 48
VPSTTT - 27Top Clients:
Unknown - 2556Top Software:
Unknown - 2556Top Keyboards:
Unknown - 2556Top IP Classification:
proxy - 2409
hosting - 99
hosting & proxy - 39Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-05 RDP #Honeypot IOCs - 2556 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
141.11.96.210 - 2409
103.178.235.50 - 27
217.160.240.135 - 27Top ASNs:
Unknown - 2409
AS396982 - 48
AS140810 - 27Top Accounts:
hello - 2469
Administr - 12
0siivpyz - 12Top ISPs:
Private Customer - 2409
Google LLC - 48
VPSTTT - 27Top Clients:
Unknown - 2556Top Software:
Unknown - 2556Top Keyboards:
Unknown - 2556Top IP Classification:
proxy - 2409
hosting - 99
hosting & proxy - 39Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-05 RDP #Honeypot IOCs - 1704 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
141.11.96.210 - 1606
103.178.235.50 - 18
217.160.240.135 - 18Top ASNs:
Unknown - 1606
AS396982 - 32
AS140810 - 18Top Accounts:
hello - 1646
Administr - 8
0siivpyz - 8Top ISPs:
Private Customer - 1606
Google LLC - 32
VPSTTT - 18Top Clients:
Unknown - 1704Top Software:
Unknown - 1704Top Keyboards:
Unknown - 1704Top IP Classification:
proxy - 1606
hosting - 66
hosting & proxy - 26Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-05 RDP #Honeypot IOCs - 1704 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
141.11.96.210 - 1606
103.178.235.50 - 18
217.160.240.135 - 18Top ASNs:
Unknown - 1606
AS396982 - 32
AS140810 - 18Top Accounts:
hello - 1646
Administr - 8
0siivpyz - 8Top ISPs:
Private Customer - 1606
Google LLC - 32
VPSTTT - 18Top Clients:
Unknown - 1704Top Software:
Unknown - 1704Top Keyboards:
Unknown - 1704Top IP Classification:
proxy - 1606
hosting - 66
hosting & proxy - 26Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-05 RDP #Honeypot IOCs - 1704 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
141.11.96.210 - 1606
103.178.235.50 - 18
217.160.240.135 - 18Top ASNs:
Unknown - 1606
AS396982 - 32
AS140810 - 18Top Accounts:
hello - 1646
Administr - 8
0siivpyz - 8Top ISPs:
Private Customer - 1606
Google LLC - 32
VPSTTT - 18Top Clients:
Unknown - 1704Top Software:
Unknown - 1704Top Keyboards:
Unknown - 1704Top IP Classification:
proxy - 1606
hosting - 66
hosting & proxy - 26Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-05 RDP #Honeypot IOCs - 1704 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
141.11.96.210 - 1606
103.178.235.50 - 18
217.160.240.135 - 18Top ASNs:
Unknown - 1606
AS396982 - 32
AS140810 - 18Top Accounts:
hello - 1646
Administr - 8
0siivpyz - 8Top ISPs:
Private Customer - 1606
Google LLC - 32
VPSTTT - 18Top Clients:
Unknown - 1704Top Software:
Unknown - 1704Top Keyboards:
Unknown - 1704Top IP Classification:
proxy - 1606
hosting - 66
hosting & proxy - 26Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-05 RDP #Honeypot IOCs - 852 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
141.11.96.210 - 803
103.178.235.50 - 9
217.160.240.135 - 9Top ASNs:
Unknown - 803
AS396982 - 16
AS140810 - 9Top Accounts:
hello - 823
Administr - 4
0siivpyz - 4Top ISPs:
Private Customer - 803
Google LLC - 16
VPSTTT - 9Top Clients:
Unknown - 852Top Software:
Unknown - 852Top Keyboards:
Unknown - 852Top IP Classification:
proxy - 803
hosting - 33
hosting & proxy - 13Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-05 RDP #Honeypot IOCs - 852 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
141.11.96.210 - 803
103.178.235.50 - 9
217.160.240.135 - 9Top ASNs:
Unknown - 803
AS396982 - 16
AS140810 - 9Top Accounts:
hello - 823
Administr - 4
0siivpyz - 4Top ISPs:
Private Customer - 803
Google LLC - 16
VPSTTT - 9Top Clients:
Unknown - 852Top Software:
Unknown - 852Top Keyboards:
Unknown - 852Top IP Classification:
proxy - 803
hosting - 33
hosting & proxy - 13Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-05 RDP #Honeypot IOCs - 852 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
141.11.96.210 - 803
103.178.235.50 - 9
217.160.240.135 - 9Top ASNs:
Unknown - 803
AS396982 - 16
AS140810 - 9Top Accounts:
hello - 823
Administr - 4
0siivpyz - 4Top ISPs:
Private Customer - 803
Google LLC - 16
VPSTTT - 9Top Clients:
Unknown - 852Top Software:
Unknown - 852Top Keyboards:
Unknown - 852Top IP Classification:
proxy - 803
hosting - 33
hosting & proxy - 13Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-05 RDP #Honeypot IOCs - 852 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
141.11.96.210 - 803
103.178.235.50 - 9
217.160.240.135 - 9Top ASNs:
Unknown - 803
AS396982 - 16
AS140810 - 9Top Accounts:
hello - 823
Administr - 4
0siivpyz - 4Top ISPs:
Private Customer - 803
Google LLC - 16
VPSTTT - 9Top Clients:
Unknown - 852Top Software:
Unknown - 852Top Keyboards:
Unknown - 852Top IP Classification:
proxy - 803
hosting - 33
hosting & proxy - 13Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
SOC-Analyst Lern- & Praxishandbuch
Ich habe mir in den letzten Wochen ein eigenes SOC-Analyst Lern- & Praxishandbuch erstellt.
Gedacht ist es vor allem für Einsteiger, Interessierte und alle, die sich einen strukturierten Überblick über Security Operations und SOC verschaffen möchten.
Enthalten sind unter anderem Themen wie Netzwerke, SIEM, EDR/XDR, Threat Intelligence, Incident Response, Detection Engineering, Cloud Security, Malware-Analyse, Forensik sowie praktische Lernpfade und Tool-Empfehlungen.
Für mich war wichtig, Theorie und Praxis möglichst verständlich zusammenzubringen und gleichzeitig zu zeigen, was man als angehender SOC Analyst wirklich lernen und üben sollte.
Download: SOC-Analyst – Das umfassende Lern- & Praxishandbuch:
:boost_ok:
#CyberSecurity #SOC #BlueTeam #SecurityOperations #ITSecurity
-
SOC-Analyst Lern- & Praxishandbuch
Ich habe mir in den letzten Wochen ein eigenes SOC-Analyst Lern- & Praxishandbuch erstellt.
Gedacht ist es vor allem für Einsteiger, Interessierte und alle, die sich einen strukturierten Überblick über Security Operations und SOC verschaffen möchten.
Enthalten sind unter anderem Themen wie Netzwerke, SIEM, EDR/XDR, Threat Intelligence, Incident Response, Detection Engineering, Cloud Security, Malware-Analyse, Forensik sowie praktische Lernpfade und Tool-Empfehlungen.
Für mich war wichtig, Theorie und Praxis möglichst verständlich zusammenzubringen und gleichzeitig zu zeigen, was man als angehender SOC Analyst wirklich lernen und üben sollte.
Download: SOC-Analyst – Das umfassende Lern- & Praxishandbuch:
:boost_ok:
#CyberSecurity #SOC #BlueTeam #SecurityOperations #ITSecurity
-
SOC-Analyst Lern- & Praxishandbuch
Ich habe mir in den letzten Wochen ein eigenes SOC-Analyst Lern- & Praxishandbuch erstellt.
Gedacht ist es vor allem für Einsteiger, Interessierte und alle, die sich einen strukturierten Überblick über Security Operations und SOC verschaffen möchten.
Enthalten sind unter anderem Themen wie Netzwerke, SIEM, EDR/XDR, Threat Intelligence, Incident Response, Detection Engineering, Cloud Security, Malware-Analyse, Forensik sowie praktische Lernpfade und Tool-Empfehlungen.
Für mich war wichtig, Theorie und Praxis möglichst verständlich zusammenzubringen und gleichzeitig zu zeigen, was man als angehender SOC Analyst wirklich lernen und üben sollte.
Download: SOC-Analyst – Das umfassende Lern- & Praxishandbuch:
:boost_ok:
#CyberSecurity #SOC #BlueTeam #SecurityOperations #ITSecurity
-
SOC-Analyst Lern- & Praxishandbuch
Ich habe mir in den letzten Wochen ein eigenes SOC-Analyst Lern- & Praxishandbuch erstellt.
Gedacht ist es vor allem für Einsteiger, Interessierte und alle, die sich einen strukturierten Überblick über Security Operations und SOC verschaffen möchten.
Enthalten sind unter anderem Themen wie Netzwerke, SIEM, EDR/XDR, Threat Intelligence, Incident Response, Detection Engineering, Cloud Security, Malware-Analyse, Forensik sowie praktische Lernpfade und Tool-Empfehlungen.
Für mich war wichtig, Theorie und Praxis möglichst verständlich zusammenzubringen und gleichzeitig zu zeigen, was man als angehender SOC Analyst wirklich lernen und üben sollte.
Download: SOC-Analyst – Das umfassende Lern- & Praxishandbuch:
:boost_ok:
#CyberSecurity #SOC #BlueTeam #SecurityOperations #ITSecurity
-
SOC-Analyst Lern- & Praxishandbuch
Ich habe mir in den letzten Wochen ein eigenes SOC-Analyst Lern- & Praxishandbuch erstellt.
Gedacht ist es vor allem für Einsteiger, Interessierte und alle, die sich einen strukturierten Überblick über Security Operations und SOC verschaffen möchten.
Enthalten sind unter anderem Themen wie Netzwerke, SIEM, EDR/XDR, Threat Intelligence, Incident Response, Detection Engineering, Cloud Security, Malware-Analyse, Forensik sowie praktische Lernpfade und Tool-Empfehlungen.
Für mich war wichtig, Theorie und Praxis möglichst verständlich zusammenzubringen und gleichzeitig zu zeigen, was man als angehender SOC Analyst wirklich lernen und üben sollte.
Download: SOC-Analyst – Das umfassende Lern- & Praxishandbuch:
:boost_ok:
#CyberSecurity #SOC #BlueTeam #SecurityOperations #ITSecurity
-
Ich habe mir in den letzten Wochen ein eigenes SOC-Analyst Lern- & Praxishandbuch erstellt.
Gedacht ist es vor allem für Einsteiger, Interessierte und alle, die sich einen strukturierten Überblick über Security Operations und SOC verschaffen möchten.
Enthalten sind unter anderem Themen wie Netzwerke, SIEM, EDR/XDR, Threat Intelligence, Incident Response, Detection Engineering, Cloud Security, Malware-Analyse, Forensik sowie praktische Lernpfade und Tool-Empfehlungen.
Für mich war wichtig, Theorie und Praxis möglichst verständlich zusammenzubringen und gleichzeitig zu zeigen, was man als angehender SOC Analyst wirklich lernen und üben sollte.
Download: SOC-Analyst – Das umfassende Lern- & Praxishandbuch:
:boost_ok:
#CyberSecurity #SOC #BlueTeam #SecurityOperations #ITSecurity
-
Empty scoreboard.
80 teams.
14 days.Someone's name goes first.
WATCHLIST is a free 24-hour CTF built around one investigation.
24 challenges - memory forensics,
disk forensics, DNS exfil, ADSB analysis, live SSH honeypot.All connected to the same case.
First blood on each challenge gets logged permanently
by The Machine.Sep 19 03:30 UTC. Free entry. Teams 1-6.
Prizes: $750 / $500 / $250ctf.xposedornot.com
CTFtime: ctftime.org/event/3326 -
Empty scoreboard.
80 teams.
14 days.Someone's name goes first.
WATCHLIST is a free 24-hour CTF built around one investigation.
24 challenges - memory forensics,
disk forensics, DNS exfil, ADSB analysis, live SSH honeypot.All connected to the same case.
First blood on each challenge gets logged permanently
by The Machine.Sep 19 03:30 UTC. Free entry. Teams 1-6.
Prizes: $750 / $500 / $250ctf.xposedornot.com
CTFtime: ctftime.org/event/3326 -
Empty scoreboard.
80 teams.
14 days.Someone's name goes first.
WATCHLIST is a free 24-hour CTF built around one investigation.
24 challenges - memory forensics,
disk forensics, DNS exfil, ADSB analysis, live SSH honeypot.All connected to the same case.
First blood on each challenge gets logged permanently
by The Machine.Sep 19 03:30 UTC. Free entry. Teams 1-6.
Prizes: $750 / $500 / $250ctf.xposedornot.com
CTFtime: ctftime.org/event/3326 -
Empty scoreboard.
80 teams.
14 days.Someone's name goes first.
WATCHLIST is a free 24-hour CTF built around one investigation.
24 challenges - memory forensics,
disk forensics, DNS exfil, ADSB analysis, live SSH honeypot.All connected to the same case.
First blood on each challenge gets logged permanently
by The Machine.Sep 19 03:30 UTC. Free entry. Teams 1-6.
Prizes: $750 / $500 / $250ctf.xposedornot.com
CTFtime: ctftime.org/event/3326 -
Empty scoreboard.
80 teams.
14 days.Someone's name goes first.
WATCHLIST is a free 24-hour CTF built around one investigation.
24 challenges - memory forensics,
disk forensics, DNS exfil, ADSB analysis, live SSH honeypot.All connected to the same case.
First blood on each challenge gets logged permanently
by The Machine.Sep 19 03:30 UTC. Free entry. Teams 1-6.
Prizes: $750 / $500 / $250ctf.xposedornot.com
CTFtime: ctftime.org/event/3326 -
2026-09-04 RDP #Honeypot IOCs - 633 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
209.38.73.59 - 510
79.137.100.124 - 27
45.156.128.61 - 18Top ASNs:
AS14061 - 510
AS396982 - 27
AS16276 - 27Top Accounts:
hello - 549
Administr - 21
root - 18Top ISPs:
DigitalOcean, LLC - 510
Google LLC - 27
OVH SAS - 27Top Clients:
Unknown - 633Top Software:
Unknown - 633Top Keyboards:
Unknown - 633Top IP Classification:
hosting - 603
Unknown - 24
hosting & proxy - 6Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-04 RDP #Honeypot IOCs - 633 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
209.38.73.59 - 510
79.137.100.124 - 27
45.156.128.61 - 18Top ASNs:
AS14061 - 510
AS396982 - 27
AS16276 - 27Top Accounts:
hello - 549
Administr - 21
root - 18Top ISPs:
DigitalOcean, LLC - 510
Google LLC - 27
OVH SAS - 27Top Clients:
Unknown - 633Top Software:
Unknown - 633Top Keyboards:
Unknown - 633Top IP Classification:
hosting - 603
Unknown - 24
hosting & proxy - 6Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-04 RDP #Honeypot IOCs - 633 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
209.38.73.59 - 510
79.137.100.124 - 27
45.156.128.61 - 18Top ASNs:
AS14061 - 510
AS396982 - 27
AS16276 - 27Top Accounts:
hello - 549
Administr - 21
root - 18Top ISPs:
DigitalOcean, LLC - 510
Google LLC - 27
OVH SAS - 27Top Clients:
Unknown - 633Top Software:
Unknown - 633Top Keyboards:
Unknown - 633Top IP Classification:
hosting - 603
Unknown - 24
hosting & proxy - 6Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-04 RDP #Honeypot IOCs - 633 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
209.38.73.59 - 510
79.137.100.124 - 27
45.156.128.61 - 18Top ASNs:
AS14061 - 510
AS396982 - 27
AS16276 - 27Top Accounts:
hello - 549
Administr - 21
root - 18Top ISPs:
DigitalOcean, LLC - 510
Google LLC - 27
OVH SAS - 27Top Clients:
Unknown - 633Top Software:
Unknown - 633Top Keyboards:
Unknown - 633Top IP Classification:
hosting - 603
Unknown - 24
hosting & proxy - 6Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-04 RDP #Honeypot IOCs - 422 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
209.38.73.59 - 340
79.137.100.124 - 18
45.156.128.61 - 12Top ASNs:
AS14061 - 340
AS396982 - 18
AS16276 - 18Top Accounts:
hello - 366
Administr - 14
root - 12Top ISPs:
DigitalOcean, LLC - 340
Google LLC - 18
OVH SAS - 18Top Clients:
Unknown - 422Top Software:
Unknown - 422Top Keyboards:
Unknown - 422Top IP Classification:
hosting - 402
Unknown - 16
hosting & proxy - 4Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-04 RDP #Honeypot IOCs - 422 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
209.38.73.59 - 340
79.137.100.124 - 18
45.156.128.61 - 12Top ASNs:
AS14061 - 340
AS396982 - 18
AS16276 - 18Top Accounts:
hello - 366
Administr - 14
root - 12Top ISPs:
DigitalOcean, LLC - 340
Google LLC - 18
OVH SAS - 18Top Clients:
Unknown - 422Top Software:
Unknown - 422Top Keyboards:
Unknown - 422Top IP Classification:
hosting - 402
Unknown - 16
hosting & proxy - 4Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-04 RDP #Honeypot IOCs - 422 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
209.38.73.59 - 340
79.137.100.124 - 18
45.156.128.61 - 12Top ASNs:
AS14061 - 340
AS396982 - 18
AS16276 - 18Top Accounts:
hello - 366
Administr - 14
root - 12Top ISPs:
DigitalOcean, LLC - 340
Google LLC - 18
OVH SAS - 18Top Clients:
Unknown - 422Top Software:
Unknown - 422Top Keyboards:
Unknown - 422Top IP Classification:
hosting - 402
Unknown - 16
hosting & proxy - 4Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-04 RDP #Honeypot IOCs - 422 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
209.38.73.59 - 340
79.137.100.124 - 18
45.156.128.61 - 12Top ASNs:
AS14061 - 340
AS396982 - 18
AS16276 - 18Top Accounts:
hello - 366
Administr - 14
root - 12Top ISPs:
DigitalOcean, LLC - 340
Google LLC - 18
OVH SAS - 18Top Clients:
Unknown - 422Top Software:
Unknown - 422Top Keyboards:
Unknown - 422Top IP Classification:
hosting - 402
Unknown - 16
hosting & proxy - 4Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-04 RDP #Honeypot IOCs - 211 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
209.38.73.59 - 170
79.137.100.124 - 9
45.156.128.61 - 6Top ASNs:
AS14061 - 170
AS396982 - 9
AS16276 - 9Top Accounts:
hello - 183
Administr - 7
root - 6Top ISPs:
DigitalOcean, LLC - 170
Google LLC - 9
OVH SAS - 9Top Clients:
Unknown - 211Top Software:
Unknown - 211Top Keyboards:
Unknown - 211Top IP Classification:
hosting - 201
Unknown - 8
hosting & proxy - 2Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-04 RDP #Honeypot IOCs - 211 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
209.38.73.59 - 170
79.137.100.124 - 9
45.156.128.61 - 6Top ASNs:
AS14061 - 170
AS396982 - 9
AS16276 - 9Top Accounts:
hello - 183
Administr - 7
root - 6Top ISPs:
DigitalOcean, LLC - 170
Google LLC - 9
OVH SAS - 9Top Clients:
Unknown - 211Top Software:
Unknown - 211Top Keyboards:
Unknown - 211Top IP Classification:
hosting - 201
Unknown - 8
hosting & proxy - 2Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-04 RDP #Honeypot IOCs - 211 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
209.38.73.59 - 170
79.137.100.124 - 9
45.156.128.61 - 6Top ASNs:
AS14061 - 170
AS396982 - 9
AS16276 - 9Top Accounts:
hello - 183
Administr - 7
root - 6Top ISPs:
DigitalOcean, LLC - 170
Google LLC - 9
OVH SAS - 9Top Clients:
Unknown - 211Top Software:
Unknown - 211Top Keyboards:
Unknown - 211Top IP Classification:
hosting - 201
Unknown - 8
hosting & proxy - 2Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-04 RDP #Honeypot IOCs - 211 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
209.38.73.59 - 170
79.137.100.124 - 9
45.156.128.61 - 6Top ASNs:
AS14061 - 170
AS396982 - 9
AS16276 - 9Top Accounts:
hello - 183
Administr - 7
root - 6Top ISPs:
DigitalOcean, LLC - 170
Google LLC - 9
OVH SAS - 9Top Clients:
Unknown - 211Top Software:
Unknown - 211Top Keyboards:
Unknown - 211Top IP Classification:
hosting - 201
Unknown - 8
hosting & proxy - 2Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
Microsoft’s new notetaker block in Teams will drive AI notetakers more invisible, known as bot free. Many of them already support this.
They install to the user folder. Some are Chrome extensions. And a few gleefully tout how invisible they are.
Hunt in the windows registry
\ConsentStore\microphone\NonPackageto see what could be hijacking the mic and recording meetings.Expanded block list forthcoming. Then maybe a Windows & Mac sensor. What a ridiculous blight.
-
Linux Security Auditing with Lynis
In this article, I cover how to use Lynis for Linux security auditing, system hardening, and practical vulnerability assessment.
🔗 https://denizhalil.com/2025/03/17/linux-security-auditing-with-lynis/
#CyberSecurity #LinuxSecurity #Lynis #SecurityAuditing #SystemHardening #BlueTeam #DevSecOps #InfoSec #Linux #ITSecurity #SecurityEngineering #DenizHalil
-
Linux Security Auditing with Lynis
In this article, I cover how to use Lynis for Linux security auditing, system hardening, and practical vulnerability assessment.
https://denizhalil.com/2025/03/17/linux-security-auditing-with-lynis/
#CyberSecurity #LinuxSecurity #Lynis #SecurityAuditing #SystemHardening #BlueTeam #DevSecOps #InfoSec #Linux #ITSecurity #SecurityEngineering #DenizHalil
-
Bitwarden introduces “Cupid Vault” — a 2-user shared Organization vault available on the free plan.
Security considerations:
• End-to-end encryption
• Vault isolation from personal storage
• Fingerprint phrase verification (anti-ATMIT enrollment control)
• Bidirectional sharing
• Revocable accessLimitations: 2 users, 2 collections. No RBAC granularity (reserved for paid tiers).
Question for practitioners:
Is secure shared vault architecture preferable to federated identity or delegated access models for small trust groups?Join the discussion below.
Follow @technadu for actionable security insights.#InfoSec #PasswordManagement #ZeroTrust #Encryption #AccessControl #CyberDefense #Authentication #SecurityArchitecture #BlueTeam #PrivacyEngineering
-
Server Security Checklist — Essential Hardening Guide
Securing your servers isn’t optional — it’s your first line of defense against data breaches, ransomware, insider threats, and lateral movement. Use this checklist as a baseline for Linux, Windows, cloud, hybrid, or on-prem servers.
⸻
🔧 1. System & OS Hardening
• Keep OS & packages updated (apply security patches frequently).
• Remove / disable unused services & software.
• Enforce secure boot + BIOS/UEFI passwords.
• Disable auto-login and guest accounts.
• Use minimal OS images only (reduce attack surface).⸻
🔐 2. Access Control
• Enforce strong passwords & MFA everywhere.
• Use RBAC & least privilege access.
• Disable root/Administrator login over SSH/RDP.
• Rotate credentials & keys regularly.
• Implement just-in-time access for privileged users.⸻
🌐 3. Network Security
• Restrict inbound/outbound traffic via firewalls.
• Segment critical servers from general LANs/VLANs.
• Disable unused ports & protocols.
• Enable DoS/DDoS protection.
• Apply zero-trust network principles.⸻
🔑 4. Secure Remote Access
• Use SSH key-based authentication (disable password login).
• Enforce VPN for admin access.
• Log & monitor all remote access sessions.
• Disable legacy protocols (Telnet, FTP, SMBv1).
• Require bastion/jump host for critical access.⸻
📊 5. Logging & Monitoring
• Enable centralized logging (syslog / SIEM).
• Track failed login attempts & anomalies.
• Configure alerts for privilege escalation or config changes.
• Monitor log tampering.
• Retain logs securely for audits & forensics.⸻
🔒 6. Data Protection
• Encrypt data at rest (LUKS, BitLocker, etc.).
• Encrypt data in transit (TLS 1.2+).
• Strict database access policies.
• Regular, offline, immutable backups.
• Test restore procedures (don’t assume backups work).⸻
🔁 7. Application & Patch Management
• Keep middleware, frameworks, and apps patched.
• Delete default credentials & sample files.
• Enable code signing for software packages.
• Use secure coding practices (OWASP Top 10).
• Implement dependency scanning (Snyk, Trivy, etc.).⸻
🛡️ 8. Malware & Intrusion Defense
• Deploy EDR/AV on endpoints.
• Enable IDS/IPS at network edge.
• Automatic vulnerability scans (schedule weekly/monthly).
• Monitor persistence techniques (cron, startup scripts).
• Block known malicious IP ranges & TLDs.⸻
🏢 9. Physical & Cloud Security
• Restrict physical access to server racks/rooms.
• Enable provider security tools (AWS Security Groups, Azure NSG, IAM).
• Harden cloud images (CIS benchmarks).
• Review cloud logging & audit trails regularly.
• Disable unused cloud API keys / roles.⸻
📜 10. Policy & Compliance
• Use CIS / NIST / ISO-27001 benchmarks.
• Track & document every access change.
• Force annual access reviews & key rotation.
• Perform regular security training for admins.
• Maintain disaster recovery & incident plans.⸻
➕ Additional 5 Critical Controls (Advanced Hardening)
🧠 11. Privileged Access Management (PAM)
• Use jump hosts & session recording.
• Just-In-Time access for admins.
• Store keys in secure vaults (HashiCorp Vault, CyberArk).🚨 12. Real-Time Threat Detection
• Use behavioral analytics → UEBA/XDR.
• AI-based anomaly detection recommended.
• Block suspicious IPs automatically.🧪 13. Red Team & Pentesting
• Run regular internal pentests.
• Validate configuration weaknesses.
• Simulate phishing + lateral movement scenarios.🧱 14. Container / VM Isolation
• Use AppArmor, SELinux, Seccomp profiles.
• Limit Docker socket access & root containers.
• Scan images before deployment.📦 15. Automated Configuration Management
• Use IaC (Terraform, Ansible, Puppet) for repeatable and secure builds.
• Detect drift using compliance scanning.
• Version control all infrastructure.⸻
🧠 Core Reminder
A server is only as secure as the team who maintains it.
Hardening isn’t one task — it’s an ongoing#ServerSecurity #SystemHardening #InfoSec #CyberSecurity #BlueTeam
#DevSecOps #SysAdmin #ThreatDetection #AccessControl #NetworkSecurity
#LinuxSecurity #SecureArchitecture #RiskMitigation #SecurityChecklist
#CloudSecurity #InfrastructureSecurity #ZeroTrust #SecurityMonitoring -
Happy Monday folks, I hope you had a restful weekend and managed to take a breather from all things cyber! Time to get back into it though, so let me give you hand - catch up on the week’s infosec news with the latest issue of our newsletter:
https://opalsec.substack.com/p/soc-goulash-weekend-wrap-up-09e?sd=pf
#Emotet are back and are using…OneNote lures? ISO disk images? Malvertising? Nah – they’re sticking with tier tried and true TTPs – their Red Dawn maldoc template from last year; macro-enabled documents as lures, and null-byte padding to evade automated scanners.
We’ve highlighted a report on the Xenomorph #Android Banking Trojan, which added support for targeting accounts of over 400 banks; automated bypassing of MFA-protected app logins, and a Session Token stealer module. With capabilities like these becoming the norm, is it time to take a closer look at the threat Mobile Malware could pose to enterprise networks?
North Korean hackers have demonstrated yet again that they’re tracking and integrating the latest techniques, and investing in malware development. A recent campaign saw eight new pieces of malware distributed throughout the kill chain, leveraging #Microsoft #InTune to deliver payloads and an in-memory dropper to abuse the #BYOVD technique and evade EDR solutions.
A joint investigation by #Mandiant and #SonicWall has unearthed a two-year campaign by Chinese actors, enabled through exploitation of unpatched SMA100 appliances and delivery of tailored payloads. A critical vulnerability reported by #Fortinet this week helps reinforce the point that perimeter devices need to be patched with urgency, as it’s a well-documented target for Chinese-affiliated actors.
#HiatusRAT is a novel malware targeting #DrayTek routers, sniffing network traffic and proxying C2 traffic to forward-deployed implants. TTPs employed in recent #BatLoader and #Qakbot campaigns are also worth taking note of, as is #GoBruteforcer, a new malware family targeting specific web server applications to brute force logins and deploy an IRC bot for C2.
Those in Vulnerability Management should take particular note of the #Veeam vulnerability, which appears trivial to exploit and actually delivers plaintext credentials to the attacker. CISA have also taken note of nearly 40k exploit attempts of a 2 year old code-exec-as-root vulnerability in the #VMWare Cloud Foundation product in the last two months, so make sure you’re patched against it.
#Redteam members have some excellent reading to look forward to, looking at HTTP request smuggling to harvest AD credentials and persisting with a MitM Exchange server, as well as a detailed post that examines #CobaltStrike’s reflective loading capability;
The #blueteam has some great tradecraft tips from @inversecos on #Azure DFIR, as well as tools to help scan websites for malicious objects, and to combat the new #Stealc #infostealer and well-established Raccoon Stealer.
Catch all this and much more in this week's newsletter:
https://opalsec.substack.com/p/soc-goulash-weekend-wrap-up-09e?sd=pf
#infosec #cyber #news #cybernews #infosec #infosecnews #informationsecurity #cybersecurity #newsletter #hacking #security #technology #hacker #vulnerability #vulnerabilities #malware #ransomware #dfir #soc #threatintel #threatintelligence #DarkWeb #mdm #dprk #FortiOS #FortiProxy