home.social

#blueteam — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #blueteam, aggregated by home.social.

  1. AI is not your biggest cyber threat.

    Your shitty patching process probably is.

    A slightly sarcastic take on AI hype, CISOs, security theatre, broken processes, legacy IT, SOC reality and why automation changes the speed of attacks more than the nature of the problem.

    0ut3r.space/2026/08/08/ai-is-n

    #cybersecurity #infosec #AI #CISO #BlueTeam #RedTeam #SOC #SecurityEngineering

  2. From now on all #CVe #CVEAlert additional to #yara #Sigma and #Suricate rules will have #Splunk #Wazuh rules all for FREE no tracking no registration, no payments! #cybersecurity #devsecops #devops #infosec #redteam #blueteam #github #gitlab #git #developers #developer info source and follow for more updates as there will be more EX: valtersit.com/cve/CVE-2026-973

  3. Linux Privilege Escalation Cheat Sheet: Techniques and Prevention.

    In this cheat sheet, I break down essential enumeration commands, common escalation paths, and practical techniques every security professional should know.
    denizhalil.com/2025/06/30/linu

    #CyberSecurity #LinuxSecurity #PrivilegeEscalation #Pentesting #RedTeam #BlueTeam #InfoSec #ethicalhacking #SecurityEngineering #itsecurity

  4. UDP Network Monitoring with C++: A Comprehensive Guide

    In this guide, I demonstrate how to build a UDP packet sniffer in C++ using raw sockets, parse packet headers, and extract key data like source/destination IPs and ports.
    denizhalil.com/2025/07/14/udp-

    #CyberSecurity #NetworkMonitoring #PacketSniffer #UDP #Cpp #NetworkSecurity #InfoSec #BlueTeam #RedTeam #InfoSec #securityengineering #denizhalil

  5. Python C2 Server for Red Teaming: A Comprehensive Hands-On Guide

    In this guide, I walk through building a Python-based C2 server, covering its architecture, encrypted communication, and real-world operational workflow.
    denizhalil.com/2025/12/15/pyth

    #CyberSecurity #RedTeam #C2 #commandandcontrol #Python #offensivesecurity #Pentesting #infosec #threatdetection #blueteam #securityengineering #ethicalhacking

  6. SSH Tunneling and Port Forwarding Techniques: A Comprehensive Guide

    In this article, I cover:
    * How SSH tunneling works under the hood
    * Local, remote, and dynamic port forwarding techniques
    * Real-world use cases (databases, internal services, pivoting)
    * Security risks and hardening recommendations

    denizhalil.com/2026/02/02/ssh-

    #CyberSecurity #sshtunneling #portforwarding #NetworkSecurity #Linux #RedTeam #BlueTeam #Pentesting #InfoSec #securityengineering #EthicalHacking #ITSecurity

  7. Server Security Checklist — Essential Hardening Guide

    Securing your servers isn’t optional — it’s your first line of defense against data breaches, ransomware, insider threats, and lateral movement. Use this checklist as a baseline for Linux, Windows, cloud, hybrid, or on-prem servers.

    🔧 1. System & OS Hardening
    • Keep OS & packages updated (apply security patches frequently).
    • Remove / disable unused services & software.
    • Enforce secure boot + BIOS/UEFI passwords.
    • Disable auto-login and guest accounts.
    • Use minimal OS images only (reduce attack surface).

    🔐 2. Access Control
    • Enforce strong passwords & MFA everywhere.
    • Use RBAC & least privilege access.
    • Disable root/Administrator login over SSH/RDP.
    • Rotate credentials & keys regularly.
    • Implement just-in-time access for privileged users.

    🌐 3. Network Security
    • Restrict inbound/outbound traffic via firewalls.
    • Segment critical servers from general LANs/VLANs.
    • Disable unused ports & protocols.
    • Enable DoS/DDoS protection.
    • Apply zero-trust network principles.

    🔑 4. Secure Remote Access
    • Use SSH key-based authentication (disable password login).
    • Enforce VPN for admin access.
    • Log & monitor all remote access sessions.
    • Disable legacy protocols (Telnet, FTP, SMBv1).
    • Require bastion/jump host for critical access.

    📊 5. Logging & Monitoring
    • Enable centralized logging (syslog / SIEM).
    • Track failed login attempts & anomalies.
    • Configure alerts for privilege escalation or config changes.
    • Monitor log tampering.
    • Retain logs securely for audits & forensics.

    🔒 6. Data Protection
    • Encrypt data at rest (LUKS, BitLocker, etc.).
    • Encrypt data in transit (TLS 1.2+).
    • Strict database access policies.
    • Regular, offline, immutable backups.
    • Test restore procedures (don’t assume backups work).

    🔁 7. Application & Patch Management
    • Keep middleware, frameworks, and apps patched.
    • Delete default credentials & sample files.
    • Enable code signing for software packages.
    • Use secure coding practices (OWASP Top 10).
    • Implement dependency scanning (Snyk, Trivy, etc.).

    🛡️ 8. Malware & Intrusion Defense
    • Deploy EDR/AV on endpoints.
    • Enable IDS/IPS at network edge.
    • Automatic vulnerability scans (schedule weekly/monthly).
    • Monitor persistence techniques (cron, startup scripts).
    • Block known malicious IP ranges & TLDs.

    🏢 9. Physical & Cloud Security
    • Restrict physical access to server racks/rooms.
    • Enable provider security tools (AWS Security Groups, Azure NSG, IAM).
    • Harden cloud images (CIS benchmarks).
    • Review cloud logging & audit trails regularly.
    • Disable unused cloud API keys / roles.

    📜 10. Policy & Compliance
    • Use CIS / NIST / ISO-27001 benchmarks.
    • Track & document every access change.
    • Force annual access reviews & key rotation.
    • Perform regular security training for admins.
    • Maintain disaster recovery & incident plans.

    ➕ Additional 5 Critical Controls (Advanced Hardening)

    🧠 11. Privileged Access Management (PAM)
    • Use jump hosts & session recording.
    • Just-In-Time access for admins.
    • Store keys in secure vaults (HashiCorp Vault, CyberArk).

    🚨 12. Real-Time Threat Detection
    • Use behavioral analytics → UEBA/XDR.
    • AI-based anomaly detection recommended.
    • Block suspicious IPs automatically.

    🧪 13. Red Team & Pentesting
    • Run regular internal pentests.
    • Validate configuration weaknesses.
    • Simulate phishing + lateral movement scenarios.

    🧱 14. Container / VM Isolation
    • Use AppArmor, SELinux, Seccomp profiles.
    • Limit Docker socket access & root containers.
    • Scan images before deployment.

    📦 15. Automated Configuration Management
    • Use IaC (Terraform, Ansible, Puppet) for repeatable and secure builds.
    • Detect drift using compliance scanning.
    • Version control all infrastructure.

    🧠 Core Reminder

    A server is only as secure as the team who maintains it.
    Hardening isn’t one task — it’s an ongoing

    #ServerSecurity #SystemHardening #InfoSec #CyberSecurity #BlueTeam
    #DevSecOps #SysAdmin #ThreatDetection #AccessControl #NetworkSecurity
    #LinuxSecurity #SecureArchitecture #RiskMitigation #SecurityChecklist
    #CloudSecurity #InfrastructureSecurity #ZeroTrust #SecurityMonitoring

  8. New blog post live for my Sentinel Saturday series! :1000: :apartyblobcat:
    Read the blog 👉 marshsecurity.org/sentinel-sat

    In this post, I explore the power of using Microsoft Sentinel Tasks as part of your automation workflows.

    Most teams aren’t getting the full #value out of Tasks in Microsoft Sentinel. Are you? When you combine Sentinel Tasks with automation, they become a game-changer.

    - Auto-create tasks when automation fails (so nothing slips through the cracks)
    - Auto-complete tasks when automation succeeds
    - Use tasks to verify automation outcomes
    - Build engineering feedback loops and automation #QA

    Read the blog 👉 marshsecurity.org/sentinel-sat

    #MicrosoftSentinel #SentinelAutomation #CyberSecurity #SOCAutomation
    #CloudSecurity #AzureSecurity #SIEM #SecOps #Automation #InfoSec
    #CyberSecurityCommunity #BlueTeam #ThreatDetection #SecurityEngineering #SecurityOperations

  9. There so many trainings and certification out there in the infosec field. This one gives a good overview. With that you can make your own training plan.

    #cybersecurity #trainings #blueteam #redteam #infosec #purpleteam #career

    pauljerimy.com/security-certif

  10. SOLAR Quest: как покорить Весторос и прокачать навыки команды Blue team

    Привет, меня зовут Павел Фролов aka @CyberFrollo Я возглавляю отдел разработки департамента «Киберполигон» в ГК «Солар». Наша команда разрабатывает платформу для проведения кибертренировок Solar CyberMir. В январе 2025 года вышла новая версия Solar CyberMir 7.0 , и в этой статье я расскажу о главной фиче — движке Solar Quest, который построен на теории графов. На примере квеста из вселенной «Игры престолов» вы увидите, как Solar Quest позволяет проводить образовательные мероприятия и повышать уровень кибербезопасности в компании/ Наша платформа позволяет проводить киберучения, раскатывать и управлять цифровыми двойниками на инфраструктуре заказчиков, развивать навыки кибербезопасности у сотрудников ИБ-подразделений. Подробнее о возможностях нашего киберполигона – в проекте «Хакни свой потенциал». Формат КШТ — один из востребованных форматов среди наших заказчиков, наряду с One day SOC и One day Response. В таких учениях обычно участвуют топ-менеджеры, ИБ- и IT-специалисты. При отработке инцидентов они взаимодействуют между собой, анализируют, насколько хорошо знают собственные регламенты ИБ и как они работают на практике, учитывают требования регуляторов и лучшие практики кибербезопасности. Плюс «прокачивают» навыки управления командой в случае атаки киберпреступников на компанию. Данный формат мероприятий обычно проводится с помощью картонных карточек, участников собирают в одном месте и под чутким присмотром тренера проходит мероприятие. Однако, очное проведение КШТ подходит далеко не всем, т.к. многие заказчики работают в удалённом или гибридном формате. Еще одним запросом от заказчиков является отработка заданий и регламентов без отрыва от работы, так как компании не всегда могут выделить свою команду на день или дольше. Поэтому для проведения кибертренировок на платформе CyberMir решили добавить тип мероприятий КШТ, чтобы в рамках одной платформы решать задачи наших заказчиков удалённо и в удобное для них время.

    habr.com/ru/companies/solarsec

    #киберучения #cybersecurity #blueteam

  11. Happy Monday everyone!

    The Cisco Talos Intelligence Group shares their findings of APT #SneakyChef using the #SugarGh0st malware that targets a scope of contries in the EMEA region who use documents that appear to belong to government agencies. The researchers state that this campaign is on a wider scale than the previously witnessed back in November of 2023 but with all the same calling cards (link to older article is the second bullet of the summary, its a good read as well).

    Looking at the older report, we get an idea of what these documents did and how the group gained access to their victims machines and some technical details:

    Notable MITRE ATT&CK Tactics, Techniques, and sub-techniques:
    TA0001 - Initial Access
    T1566.001 - Phishing: Spearphishing Attachment - A RAR document containing an LNK file was delivered to the victims. In the recent campaign, an SFX script executes to drop a decoy document, DLL loader, encrypted SugarGh0st, and a malicious VB script.

    TA0003 - Persistence
    T1037.001 - Boot or Logon Initialization Scripts: Logon Script (Windows) - The malicious VB script gained persistence by writing a command to the registry key "UserInitMprLogonScript" which will run whatever script is defined in the value when a user that belongs to either a local workgroup or domain logs into the system. The command in this instances was "regsvr32.exe /s %temp%\update.dll (the DLL came from the malicious SFX script).

    TA0004/TA0005 - Privilige Escalation or Defense Evasion
    T1055 - Process Injection - After the user logs into a machine, the command that targets the DLL dropped in the attack executes. This command reads the encrypted SugarGh0st RAT "authz.lib", decrypts it and injects it into a process.

    These are just some of the TTPs seen in the new attack but I would highly recommend checking out the older article to get some more technical information about past behaviors associated with SneakyChef and the SugarGh0st RAT. Enjoy and Happy Hunting!

    Article Source:
    SneakyChef espionage group targets government agencies with SugarGh0st and more infection techniques
    blog.talosintelligence.com/sne

    November 2023 Article:
    blog.talosintelligence.com/new

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday #Intel471

  12. Analysis of #infostealer #malware pretending to be a hack for #roblox anticheat.

    This week I delivered one lecture about cyber attacks and three 45-minutes malware analysis workshops with #anyrun and #cyberchef for high school students in #Roznava, #Slovakia.

    #Education #CyberSecurity #blueteam #dfir #sandbox

    infosec.exchange/@securitydung

  13. Интервью с руководителем отдела анализа защищённости Angara Security Михаилом Суховым о пентесте

    Я много бывал за последнее время на разных ИБ‑мероприятиях, где проходили различные киберучения. Много писал об уязвимостях, об ИБ‑решениях, борющихся с ними, специалистах, выявляющих бреши в инфраструктурах. И как раз на последней ИБ‑конференции я решил поговорить с одним из участников киберучений. Тем более для меня понятие «пентест» всегда было очень расплывчатым, я мало сталкивался с ним по работе в IT. Вопросы я задавал иногда очень простые (они могут даже показаться глупыми), но хотелось понять портрет практикующего пентестера. Итак, я поговорил с руководителем отдела анализа защищённости Angara Security Михаилом Суховым о работе пентестера и его стандартных инструментах. Приятного чтения!

    habr.com/ru/articles/782600/

    #пентест #пентестинг #информационная_безопасность #redteam #blueteam #soc #pentest #angara_security #киберучения #уязвимости

  14. Another week, another newsletter - catch up on the week's infosec news here:

    opalsec.substack.com/p/soc-gou

    Researchers have found that nearly two years on, 2 in 3 installs of #Apache #Superset are still using default Flask Secret Keys - a configuration flaw which would allow an attacker to forge session cookies and access said servers with full administrative privileges.

    #Kritec is a commodity #skimmer found installed on compromised #Magecart sites, with its code heavily obfuscated and customised to match the site's aesthetic in order to con users out of credit card details.

    #FIN7 look to be popping instances of the #Veeam backup software that are unpatched for a recent vulnerability; a revised #ViperSoftX #infostealer now targets #1password and #keepass password vaults, and #TA505 deliver a new infostealer through a #GoogleAds campaign

    #LockBit & #CL0P ransomware affiliates have been abusing a month-old vulnerability in the #PaperCut print management software to drop ransomware. With the cat out of the bag, security researchers have decided now is a great time to drop a PoC exploit on Github - I mean, why not let the skiddies get in on the action too, right?

    The #blueteam have some great research worth reading on #Smishing via #AWS; detections for #SliverC2 and different implementations of #PsExec, as well as #Sigma integration for #SentinelOne and a #KQL hack for monitoring LOLDrivers.

    Have a great week ahead folks, I hope this newsletter proves helpful!

    opalsec.substack.com/p/soc-gou

    #infosec #cyber #news #newsletter #cybernews #infosec #infosecnews #informationsecurity #cybersecurity #hacking #security #technology #hacker #vulnerability #vulnerabilities #malware #ransomware #affiliate #dfir #soc #threatintel #threatintelligence #threathunting #detection #threatdetection #detectionengineering #flask #python #fraud #malvertising #clop #PoC #exploit #securityresearch #LOLBAS #LOLBIN #BYOVD