home.social

#blueteam — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #blueteam, aggregated by home.social.

  1. 2026-09-05 RDP #Honeypot IOCs - 2556 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    141.11.96.210 - 2409
    103.178.235.50 - 27
    217.160.240.135 - 27

    Top ASNs:
    Unknown - 2409
    AS396982 - 48
    AS140810 - 27

    Top Accounts:
    hello - 2469
    Administr - 12
    0siivpyz - 12

    Top ISPs:
    Private Customer - 2409
    Google LLC - 48
    VPSTTT - 27

    Top Clients:
    Unknown - 2556

    Top Software:
    Unknown - 2556

    Top Keyboards:
    Unknown - 2556

    Top IP Classification:
    proxy - 2409
    hosting - 99
    hosting & proxy - 39

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  2. 2026-09-05 RDP #Honeypot IOCs - 2556 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    141.11.96.210 - 2409
    103.178.235.50 - 27
    217.160.240.135 - 27

    Top ASNs:
    Unknown - 2409
    AS396982 - 48
    AS140810 - 27

    Top Accounts:
    hello - 2469
    Administr - 12
    0siivpyz - 12

    Top ISPs:
    Private Customer - 2409
    Google LLC - 48
    VPSTTT - 27

    Top Clients:
    Unknown - 2556

    Top Software:
    Unknown - 2556

    Top Keyboards:
    Unknown - 2556

    Top IP Classification:
    proxy - 2409
    hosting - 99
    hosting & proxy - 39

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  3. 2026-09-05 RDP #Honeypot IOCs - 2556 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    141.11.96.210 - 2409
    103.178.235.50 - 27
    217.160.240.135 - 27

    Top ASNs:
    Unknown - 2409
    AS396982 - 48
    AS140810 - 27

    Top Accounts:
    hello - 2469
    Administr - 12
    0siivpyz - 12

    Top ISPs:
    Private Customer - 2409
    Google LLC - 48
    VPSTTT - 27

    Top Clients:
    Unknown - 2556

    Top Software:
    Unknown - 2556

    Top Keyboards:
    Unknown - 2556

    Top IP Classification:
    proxy - 2409
    hosting - 99
    hosting & proxy - 39

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  4. 2026-09-05 RDP #Honeypot IOCs - 2556 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    141.11.96.210 - 2409
    103.178.235.50 - 27
    217.160.240.135 - 27

    Top ASNs:
    Unknown - 2409
    AS396982 - 48
    AS140810 - 27

    Top Accounts:
    hello - 2469
    Administr - 12
    0siivpyz - 12

    Top ISPs:
    Private Customer - 2409
    Google LLC - 48
    VPSTTT - 27

    Top Clients:
    Unknown - 2556

    Top Software:
    Unknown - 2556

    Top Keyboards:
    Unknown - 2556

    Top IP Classification:
    proxy - 2409
    hosting - 99
    hosting & proxy - 39

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  5. 2026-09-05 RDP #Honeypot IOCs - 1704 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    141.11.96.210 - 1606
    103.178.235.50 - 18
    217.160.240.135 - 18

    Top ASNs:
    Unknown - 1606
    AS396982 - 32
    AS140810 - 18

    Top Accounts:
    hello - 1646
    Administr - 8
    0siivpyz - 8

    Top ISPs:
    Private Customer - 1606
    Google LLC - 32
    VPSTTT - 18

    Top Clients:
    Unknown - 1704

    Top Software:
    Unknown - 1704

    Top Keyboards:
    Unknown - 1704

    Top IP Classification:
    proxy - 1606
    hosting - 66
    hosting & proxy - 26

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  6. 2026-09-05 RDP #Honeypot IOCs - 1704 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    141.11.96.210 - 1606
    103.178.235.50 - 18
    217.160.240.135 - 18

    Top ASNs:
    Unknown - 1606
    AS396982 - 32
    AS140810 - 18

    Top Accounts:
    hello - 1646
    Administr - 8
    0siivpyz - 8

    Top ISPs:
    Private Customer - 1606
    Google LLC - 32
    VPSTTT - 18

    Top Clients:
    Unknown - 1704

    Top Software:
    Unknown - 1704

    Top Keyboards:
    Unknown - 1704

    Top IP Classification:
    proxy - 1606
    hosting - 66
    hosting & proxy - 26

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  7. 2026-09-05 RDP #Honeypot IOCs - 1704 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    141.11.96.210 - 1606
    103.178.235.50 - 18
    217.160.240.135 - 18

    Top ASNs:
    Unknown - 1606
    AS396982 - 32
    AS140810 - 18

    Top Accounts:
    hello - 1646
    Administr - 8
    0siivpyz - 8

    Top ISPs:
    Private Customer - 1606
    Google LLC - 32
    VPSTTT - 18

    Top Clients:
    Unknown - 1704

    Top Software:
    Unknown - 1704

    Top Keyboards:
    Unknown - 1704

    Top IP Classification:
    proxy - 1606
    hosting - 66
    hosting & proxy - 26

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  8. 2026-09-05 RDP #Honeypot IOCs - 1704 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    141.11.96.210 - 1606
    103.178.235.50 - 18
    217.160.240.135 - 18

    Top ASNs:
    Unknown - 1606
    AS396982 - 32
    AS140810 - 18

    Top Accounts:
    hello - 1646
    Administr - 8
    0siivpyz - 8

    Top ISPs:
    Private Customer - 1606
    Google LLC - 32
    VPSTTT - 18

    Top Clients:
    Unknown - 1704

    Top Software:
    Unknown - 1704

    Top Keyboards:
    Unknown - 1704

    Top IP Classification:
    proxy - 1606
    hosting - 66
    hosting & proxy - 26

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  9. 2026-09-05 RDP #Honeypot IOCs - 852 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    141.11.96.210 - 803
    103.178.235.50 - 9
    217.160.240.135 - 9

    Top ASNs:
    Unknown - 803
    AS396982 - 16
    AS140810 - 9

    Top Accounts:
    hello - 823
    Administr - 4
    0siivpyz - 4

    Top ISPs:
    Private Customer - 803
    Google LLC - 16
    VPSTTT - 9

    Top Clients:
    Unknown - 852

    Top Software:
    Unknown - 852

    Top Keyboards:
    Unknown - 852

    Top IP Classification:
    proxy - 803
    hosting - 33
    hosting & proxy - 13

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  10. 2026-09-05 RDP #Honeypot IOCs - 852 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    141.11.96.210 - 803
    103.178.235.50 - 9
    217.160.240.135 - 9

    Top ASNs:
    Unknown - 803
    AS396982 - 16
    AS140810 - 9

    Top Accounts:
    hello - 823
    Administr - 4
    0siivpyz - 4

    Top ISPs:
    Private Customer - 803
    Google LLC - 16
    VPSTTT - 9

    Top Clients:
    Unknown - 852

    Top Software:
    Unknown - 852

    Top Keyboards:
    Unknown - 852

    Top IP Classification:
    proxy - 803
    hosting - 33
    hosting & proxy - 13

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  11. 2026-09-05 RDP #Honeypot IOCs - 852 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    141.11.96.210 - 803
    103.178.235.50 - 9
    217.160.240.135 - 9

    Top ASNs:
    Unknown - 803
    AS396982 - 16
    AS140810 - 9

    Top Accounts:
    hello - 823
    Administr - 4
    0siivpyz - 4

    Top ISPs:
    Private Customer - 803
    Google LLC - 16
    VPSTTT - 9

    Top Clients:
    Unknown - 852

    Top Software:
    Unknown - 852

    Top Keyboards:
    Unknown - 852

    Top IP Classification:
    proxy - 803
    hosting - 33
    hosting & proxy - 13

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  12. 2026-09-05 RDP #Honeypot IOCs - 852 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    141.11.96.210 - 803
    103.178.235.50 - 9
    217.160.240.135 - 9

    Top ASNs:
    Unknown - 803
    AS396982 - 16
    AS140810 - 9

    Top Accounts:
    hello - 823
    Administr - 4
    0siivpyz - 4

    Top ISPs:
    Private Customer - 803
    Google LLC - 16
    VPSTTT - 9

    Top Clients:
    Unknown - 852

    Top Software:
    Unknown - 852

    Top Keyboards:
    Unknown - 852

    Top IP Classification:
    proxy - 803
    hosting - 33
    hosting & proxy - 13

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  13. SOC-Analyst Lern- & Praxishandbuch

    Ich habe mir in den letzten Wochen ein eigenes SOC-Analyst Lern- & Praxishandbuch erstellt.

    Gedacht ist es vor allem für Einsteiger, Interessierte und alle, die sich einen strukturierten Überblick über Security Operations und SOC verschaffen möchten.

    Enthalten sind unter anderem Themen wie Netzwerke, SIEM, EDR/XDR, Threat Intelligence, Incident Response, Detection Engineering, Cloud Security, Malware-Analyse, Forensik sowie praktische Lernpfade und Tool-Empfehlungen.

    Für mich war wichtig, Theorie und Praxis möglichst verständlich zusammenzubringen und gleichzeitig zu zeigen, was man als angehender SOC Analyst wirklich lernen und üben sollte.

    Download: SOC-Analyst – Das umfassende Lern- & Praxishandbuch:

    🔗 app.filen.io/#/d/7b65fb81-b0fc

    :boost_ok:

    #CyberSecurity #SOC #BlueTeam #SecurityOperations #ITSecurity

  14. SOC-Analyst Lern- & Praxishandbuch

    Ich habe mir in den letzten Wochen ein eigenes SOC-Analyst Lern- & Praxishandbuch erstellt.

    Gedacht ist es vor allem für Einsteiger, Interessierte und alle, die sich einen strukturierten Überblick über Security Operations und SOC verschaffen möchten.

    Enthalten sind unter anderem Themen wie Netzwerke, SIEM, EDR/XDR, Threat Intelligence, Incident Response, Detection Engineering, Cloud Security, Malware-Analyse, Forensik sowie praktische Lernpfade und Tool-Empfehlungen.

    Für mich war wichtig, Theorie und Praxis möglichst verständlich zusammenzubringen und gleichzeitig zu zeigen, was man als angehender SOC Analyst wirklich lernen und üben sollte.

    Download: SOC-Analyst – Das umfassende Lern- & Praxishandbuch:

    🔗 app.filen.io/#/d/7b65fb81-b0fc

    :boost_ok:

    #CyberSecurity #SOC #BlueTeam #SecurityOperations #ITSecurity

  15. SOC-Analyst Lern- & Praxishandbuch

    Ich habe mir in den letzten Wochen ein eigenes SOC-Analyst Lern- & Praxishandbuch erstellt.

    Gedacht ist es vor allem für Einsteiger, Interessierte und alle, die sich einen strukturierten Überblick über Security Operations und SOC verschaffen möchten.

    Enthalten sind unter anderem Themen wie Netzwerke, SIEM, EDR/XDR, Threat Intelligence, Incident Response, Detection Engineering, Cloud Security, Malware-Analyse, Forensik sowie praktische Lernpfade und Tool-Empfehlungen.

    Für mich war wichtig, Theorie und Praxis möglichst verständlich zusammenzubringen und gleichzeitig zu zeigen, was man als angehender SOC Analyst wirklich lernen und üben sollte.

    Download: SOC-Analyst – Das umfassende Lern- & Praxishandbuch:

    🔗 app.filen.io/#/d/7b65fb81-b0fc

    :boost_ok:

    #CyberSecurity #SOC #BlueTeam #SecurityOperations #ITSecurity

  16. SOC-Analyst Lern- & Praxishandbuch

    Ich habe mir in den letzten Wochen ein eigenes SOC-Analyst Lern- & Praxishandbuch erstellt.

    Gedacht ist es vor allem für Einsteiger, Interessierte und alle, die sich einen strukturierten Überblick über Security Operations und SOC verschaffen möchten.

    Enthalten sind unter anderem Themen wie Netzwerke, SIEM, EDR/XDR, Threat Intelligence, Incident Response, Detection Engineering, Cloud Security, Malware-Analyse, Forensik sowie praktische Lernpfade und Tool-Empfehlungen.

    Für mich war wichtig, Theorie und Praxis möglichst verständlich zusammenzubringen und gleichzeitig zu zeigen, was man als angehender SOC Analyst wirklich lernen und üben sollte.

    Download: SOC-Analyst – Das umfassende Lern- & Praxishandbuch:

    🔗 app.filen.io/#/d/7b65fb81-b0fc

    :boost_ok:

    #CyberSecurity #SOC #BlueTeam #SecurityOperations #ITSecurity

  17. SOC-Analyst Lern- & Praxishandbuch

    Ich habe mir in den letzten Wochen ein eigenes SOC-Analyst Lern- & Praxishandbuch erstellt.

    Gedacht ist es vor allem für Einsteiger, Interessierte und alle, die sich einen strukturierten Überblick über Security Operations und SOC verschaffen möchten.

    Enthalten sind unter anderem Themen wie Netzwerke, SIEM, EDR/XDR, Threat Intelligence, Incident Response, Detection Engineering, Cloud Security, Malware-Analyse, Forensik sowie praktische Lernpfade und Tool-Empfehlungen.

    Für mich war wichtig, Theorie und Praxis möglichst verständlich zusammenzubringen und gleichzeitig zu zeigen, was man als angehender SOC Analyst wirklich lernen und üben sollte.

    Download: SOC-Analyst – Das umfassende Lern- & Praxishandbuch:

    🔗 app.filen.io/#/d/7b65fb81-b0fc

    :boost_ok:

    #CyberSecurity #SOC #BlueTeam #SecurityOperations #ITSecurity

  18. Ich habe mir in den letzten Wochen ein eigenes SOC-Analyst Lern- & Praxishandbuch erstellt.

    Gedacht ist es vor allem für Einsteiger, Interessierte und alle, die sich einen strukturierten Überblick über Security Operations und SOC verschaffen möchten.

    Enthalten sind unter anderem Themen wie Netzwerke, SIEM, EDR/XDR, Threat Intelligence, Incident Response, Detection Engineering, Cloud Security, Malware-Analyse, Forensik sowie praktische Lernpfade und Tool-Empfehlungen.

    Für mich war wichtig, Theorie und Praxis möglichst verständlich zusammenzubringen und gleichzeitig zu zeigen, was man als angehender SOC Analyst wirklich lernen und üben sollte.

    Download: SOC-Analyst – Das umfassende Lern- & Praxishandbuch:

    🔗 app.filen.io/#/d/7b65fb81-b0fc

    :boost_ok:

    #CyberSecurity #SOC #BlueTeam #SecurityOperations #ITSecurity

  19. Empty scoreboard.
    80 teams.
    14 days.

    Someone's name goes first.

    WATCHLIST is a free 24-hour CTF built around one investigation.

    24 challenges - memory forensics,
    disk forensics, DNS exfil, ADSB analysis, live SSH honeypot.

    All connected to the same case.

    First blood on each challenge gets logged permanently
    by The Machine.

    Sep 19 03:30 UTC. Free entry. Teams 1-6.
    Prizes: $750 / $500 / $250

    ctf.xposedornot.com
    CTFtime: ctftime.org/event/3326

    #CTF #DFIR #forensics #infosec #blueteam

  20. Empty scoreboard.
    80 teams.
    14 days.

    Someone's name goes first.

    WATCHLIST is a free 24-hour CTF built around one investigation.

    24 challenges - memory forensics,
    disk forensics, DNS exfil, ADSB analysis, live SSH honeypot.

    All connected to the same case.

    First blood on each challenge gets logged permanently
    by The Machine.

    Sep 19 03:30 UTC. Free entry. Teams 1-6.
    Prizes: $750 / $500 / $250

    ctf.xposedornot.com
    CTFtime: ctftime.org/event/3326

    #CTF #DFIR #forensics #infosec #blueteam

  21. Empty scoreboard.
    80 teams.
    14 days.

    Someone's name goes first.

    WATCHLIST is a free 24-hour CTF built around one investigation.

    24 challenges - memory forensics,
    disk forensics, DNS exfil, ADSB analysis, live SSH honeypot.

    All connected to the same case.

    First blood on each challenge gets logged permanently
    by The Machine.

    Sep 19 03:30 UTC. Free entry. Teams 1-6.
    Prizes: $750 / $500 / $250

    ctf.xposedornot.com
    CTFtime: ctftime.org/event/3326

    #CTF #DFIR #forensics #infosec #blueteam

  22. Empty scoreboard.
    80 teams.
    14 days.

    Someone's name goes first.

    WATCHLIST is a free 24-hour CTF built around one investigation.

    24 challenges - memory forensics,
    disk forensics, DNS exfil, ADSB analysis, live SSH honeypot.

    All connected to the same case.

    First blood on each challenge gets logged permanently
    by The Machine.

    Sep 19 03:30 UTC. Free entry. Teams 1-6.
    Prizes: $750 / $500 / $250

    ctf.xposedornot.com
    CTFtime: ctftime.org/event/3326

    #CTF #DFIR #forensics #infosec #blueteam

  23. Empty scoreboard.
    80 teams.
    14 days.

    Someone's name goes first.

    WATCHLIST is a free 24-hour CTF built around one investigation.

    24 challenges - memory forensics,
    disk forensics, DNS exfil, ADSB analysis, live SSH honeypot.

    All connected to the same case.

    First blood on each challenge gets logged permanently
    by The Machine.

    Sep 19 03:30 UTC. Free entry. Teams 1-6.
    Prizes: $750 / $500 / $250

    ctf.xposedornot.com
    CTFtime: ctftime.org/event/3326

    #CTF #DFIR #forensics #infosec #blueteam

  24. 2026-09-04 RDP #Honeypot IOCs - 633 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    209.38.73.59 - 510
    79.137.100.124 - 27
    45.156.128.61 - 18

    Top ASNs:
    AS14061 - 510
    AS396982 - 27
    AS16276 - 27

    Top Accounts:
    hello - 549
    Administr - 21
    root - 18

    Top ISPs:
    DigitalOcean, LLC - 510
    Google LLC - 27
    OVH SAS - 27

    Top Clients:
    Unknown - 633

    Top Software:
    Unknown - 633

    Top Keyboards:
    Unknown - 633

    Top IP Classification:
    hosting - 603
    Unknown - 24
    hosting & proxy - 6

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  25. 2026-09-04 RDP #Honeypot IOCs - 633 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    209.38.73.59 - 510
    79.137.100.124 - 27
    45.156.128.61 - 18

    Top ASNs:
    AS14061 - 510
    AS396982 - 27
    AS16276 - 27

    Top Accounts:
    hello - 549
    Administr - 21
    root - 18

    Top ISPs:
    DigitalOcean, LLC - 510
    Google LLC - 27
    OVH SAS - 27

    Top Clients:
    Unknown - 633

    Top Software:
    Unknown - 633

    Top Keyboards:
    Unknown - 633

    Top IP Classification:
    hosting - 603
    Unknown - 24
    hosting & proxy - 6

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  26. 2026-09-04 RDP #Honeypot IOCs - 633 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    209.38.73.59 - 510
    79.137.100.124 - 27
    45.156.128.61 - 18

    Top ASNs:
    AS14061 - 510
    AS396982 - 27
    AS16276 - 27

    Top Accounts:
    hello - 549
    Administr - 21
    root - 18

    Top ISPs:
    DigitalOcean, LLC - 510
    Google LLC - 27
    OVH SAS - 27

    Top Clients:
    Unknown - 633

    Top Software:
    Unknown - 633

    Top Keyboards:
    Unknown - 633

    Top IP Classification:
    hosting - 603
    Unknown - 24
    hosting & proxy - 6

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  27. 2026-09-04 RDP #Honeypot IOCs - 633 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    209.38.73.59 - 510
    79.137.100.124 - 27
    45.156.128.61 - 18

    Top ASNs:
    AS14061 - 510
    AS396982 - 27
    AS16276 - 27

    Top Accounts:
    hello - 549
    Administr - 21
    root - 18

    Top ISPs:
    DigitalOcean, LLC - 510
    Google LLC - 27
    OVH SAS - 27

    Top Clients:
    Unknown - 633

    Top Software:
    Unknown - 633

    Top Keyboards:
    Unknown - 633

    Top IP Classification:
    hosting - 603
    Unknown - 24
    hosting & proxy - 6

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  28. 2026-09-04 RDP #Honeypot IOCs - 422 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    209.38.73.59 - 340
    79.137.100.124 - 18
    45.156.128.61 - 12

    Top ASNs:
    AS14061 - 340
    AS396982 - 18
    AS16276 - 18

    Top Accounts:
    hello - 366
    Administr - 14
    root - 12

    Top ISPs:
    DigitalOcean, LLC - 340
    Google LLC - 18
    OVH SAS - 18

    Top Clients:
    Unknown - 422

    Top Software:
    Unknown - 422

    Top Keyboards:
    Unknown - 422

    Top IP Classification:
    hosting - 402
    Unknown - 16
    hosting & proxy - 4

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  29. 2026-09-04 RDP #Honeypot IOCs - 422 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    209.38.73.59 - 340
    79.137.100.124 - 18
    45.156.128.61 - 12

    Top ASNs:
    AS14061 - 340
    AS396982 - 18
    AS16276 - 18

    Top Accounts:
    hello - 366
    Administr - 14
    root - 12

    Top ISPs:
    DigitalOcean, LLC - 340
    Google LLC - 18
    OVH SAS - 18

    Top Clients:
    Unknown - 422

    Top Software:
    Unknown - 422

    Top Keyboards:
    Unknown - 422

    Top IP Classification:
    hosting - 402
    Unknown - 16
    hosting & proxy - 4

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  30. 2026-09-04 RDP #Honeypot IOCs - 422 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    209.38.73.59 - 340
    79.137.100.124 - 18
    45.156.128.61 - 12

    Top ASNs:
    AS14061 - 340
    AS396982 - 18
    AS16276 - 18

    Top Accounts:
    hello - 366
    Administr - 14
    root - 12

    Top ISPs:
    DigitalOcean, LLC - 340
    Google LLC - 18
    OVH SAS - 18

    Top Clients:
    Unknown - 422

    Top Software:
    Unknown - 422

    Top Keyboards:
    Unknown - 422

    Top IP Classification:
    hosting - 402
    Unknown - 16
    hosting & proxy - 4

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  31. 2026-09-04 RDP #Honeypot IOCs - 422 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    209.38.73.59 - 340
    79.137.100.124 - 18
    45.156.128.61 - 12

    Top ASNs:
    AS14061 - 340
    AS396982 - 18
    AS16276 - 18

    Top Accounts:
    hello - 366
    Administr - 14
    root - 12

    Top ISPs:
    DigitalOcean, LLC - 340
    Google LLC - 18
    OVH SAS - 18

    Top Clients:
    Unknown - 422

    Top Software:
    Unknown - 422

    Top Keyboards:
    Unknown - 422

    Top IP Classification:
    hosting - 402
    Unknown - 16
    hosting & proxy - 4

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  32. 2026-09-04 RDP #Honeypot IOCs - 211 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    209.38.73.59 - 170
    79.137.100.124 - 9
    45.156.128.61 - 6

    Top ASNs:
    AS14061 - 170
    AS396982 - 9
    AS16276 - 9

    Top Accounts:
    hello - 183
    Administr - 7
    root - 6

    Top ISPs:
    DigitalOcean, LLC - 170
    Google LLC - 9
    OVH SAS - 9

    Top Clients:
    Unknown - 211

    Top Software:
    Unknown - 211

    Top Keyboards:
    Unknown - 211

    Top IP Classification:
    hosting - 201
    Unknown - 8
    hosting & proxy - 2

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  33. 2026-09-04 RDP #Honeypot IOCs - 211 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    209.38.73.59 - 170
    79.137.100.124 - 9
    45.156.128.61 - 6

    Top ASNs:
    AS14061 - 170
    AS396982 - 9
    AS16276 - 9

    Top Accounts:
    hello - 183
    Administr - 7
    root - 6

    Top ISPs:
    DigitalOcean, LLC - 170
    Google LLC - 9
    OVH SAS - 9

    Top Clients:
    Unknown - 211

    Top Software:
    Unknown - 211

    Top Keyboards:
    Unknown - 211

    Top IP Classification:
    hosting - 201
    Unknown - 8
    hosting & proxy - 2

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  34. 2026-09-04 RDP #Honeypot IOCs - 211 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    209.38.73.59 - 170
    79.137.100.124 - 9
    45.156.128.61 - 6

    Top ASNs:
    AS14061 - 170
    AS396982 - 9
    AS16276 - 9

    Top Accounts:
    hello - 183
    Administr - 7
    root - 6

    Top ISPs:
    DigitalOcean, LLC - 170
    Google LLC - 9
    OVH SAS - 9

    Top Clients:
    Unknown - 211

    Top Software:
    Unknown - 211

    Top Keyboards:
    Unknown - 211

    Top IP Classification:
    hosting - 201
    Unknown - 8
    hosting & proxy - 2

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  35. 2026-09-04 RDP #Honeypot IOCs - 211 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    209.38.73.59 - 170
    79.137.100.124 - 9
    45.156.128.61 - 6

    Top ASNs:
    AS14061 - 170
    AS396982 - 9
    AS16276 - 9

    Top Accounts:
    hello - 183
    Administr - 7
    root - 6

    Top ISPs:
    DigitalOcean, LLC - 170
    Google LLC - 9
    OVH SAS - 9

    Top Clients:
    Unknown - 211

    Top Software:
    Unknown - 211

    Top Keyboards:
    Unknown - 211

    Top IP Classification:
    hosting - 201
    Unknown - 8
    hosting & proxy - 2

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  36. I looked at reasons why Palo Alto Cortex uses this very old piece of public domain software in their EDR agent, and what can we learn from it.
    death.sk/posts/clips_detection
    #blueteam #dfir #xdr #edr

  37. RE: infosec.exchange/@badsamurai/1

    This week in BS Lists, AI Meeting Notetakers, the Shadow AI that's siphoning sensitive data from your organization.

    If not approved, block these in your web proxy, firewall, and SEG. You may be limited in what you can do in Teams/Zoom, but this will help deter and nerf their usability.

    Upgrade to a ban-sledge with additional LinkedIn URLs. I also included some of the most common attendee formats to hunt in your SIEM.

    But notetaker will get you real far.

    github.com/BadSamuraiDev/bs-li

    #bslists #aimeeting #ainotetakers #dataprotection #blueteam

  38. From now on all #CVe #CVEAlert additional to #yara #Sigma and #Suricate rules will have #Splunk #Wazuh rules all for FREE no tracking no registration, no payments! #cybersecurity #devsecops #devops #infosec #redteam #blueteam #github #gitlab #git #developers #developer info source and follow for more updates as there will be more EX: valtersit.com/cve/CVE-2026-973

  39. 🚀 SO-CRATES 1.1 is here — now with Light Mode! ☀️

    The tool you loved as OhMyPCAP keeps getting better.

    Your all-in-one Docker/Podman container for rapid analysis of PCAPs, logs, and binaries just leveled up.

    ✅ PCAPs → Suricata alerts, rich metadata, ASCII transcripts, stream carving
    ✅ Logs → Sigma alerts + originals
    ✅ Binaries → YARA matches + metadata

    Perfect for air-gapped environments, malware analysis, IR, threat hunting, forensics & teaching.

    What’s your preference?
    → Dark Mode 🖤
    → Light Mode ☀️
    → Why not both?
    → Needs glorious 4-color CGA option lol
    Comment below!

    #DFIR #Cybersecurity #BlueTeam #ThreatHunting #Suricata #YARA #Sigma #DarkMode #LightMode

  40. 🚀Introducing SO-CRATES 1.0 — Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

    SO-CRATES is a single container image for analyzing pcap files, log files, and binary files. It was formerly known as OhMyPCAP.

    Here's what you can do with SO-CRATES:
    ✅analyze pcap files and then review Suricata alerts, metadata, and extracted files
    ✅import log files and then review Sigma alerts and the original log entries
    ✅import binary files and then review YARA matches and file metadata

    All of this runs in a single Docker/Podman container — perfect for air-gapped environments, malware analysis, incident response, threat hunting, forensics & teaching.

    Who’s trying it out? Drop a ❤️ and reply with your main use case!

    #DFIR #Cybersecurity #BlueTeam #ThreatHunting #Suricata #YARA #Sigma

    @securityonion
    @chrissanders88

  41. Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257)

    In this article, I break down how the vulnerability works, affected configurations, exploitation scenarios, and the mitigation steps organizations should take to protect their remote access infrastructure.

    denizhalil.com/2026/06/02/cve-

    #CyberSecurity #PaloAlto #GlobalProtect #PANOS #CVE20260257 #VulnerabilityManagement #ThreatDetection #NetworkSecurity #BlueTeam #RedTeam #InfoSec #DenizHalil

  42. 🇰🇵 300+ Fortune 500 companies hired a North Korean engineer.

    None of them knew it at the time.

    In 2024-2025, DPRK operators used stolen US identities, AI-modified avatars and real-time#Deepfake interviews to infiltrate Fortune 500 and mid-market tech companies.

    → Stolen US identity + AI-generated profile
    → Live #AI assisted interview manipulation
    → Domestic facilitator handling onboarding
    → Corporate laptop sent to a US “laptop farm”
    → KVM/VPN tunnel from Pyongyang via Russian or Chinese relays
    → Salaries redirected through facilitator accounts → ~90% skimmed to the DPRK regime

    More than 300 companies impacted. Estimated revenue stream: ~$600M/year.

    Funds allegedly routed to DPRK Bureau 39 and the ballistic missile programme.

    $17.8M traced in facilitator accounts in the Christina Chapman case alone. Detection took months, not minutes. Traditional monitoring and standard #SOC visibility would likely not have detected the operation. Mandiant tracks the cluster as #UNC5267.

    This is no longer simple cybercrime. It is state-sponsored infiltration blending #CyberSecurity, #IdentityFraud, #OSINT, remote work infrastructure abuse and AI-powered social engineering.

    The future of #CTI and insider-threat detection is already here.

    cidu.io/articles/dprk-it-worke

    #NorthKorea #DPRK #CyberThreatIntelligence #CyberEspionage #CyberWarfare #Infosec #BlueTeam #ThreatIntel #Geopolitics #RemoteWork #VPN #KVM #Fortune500

  43. 🇰🇵 300+ Fortune 500 companies hired a North Korean engineer.

    None of them knew it at the time.

    In 2024-2025, DPRK operators used stolen US identities, AI-modified avatars and real-time#Deepfake interviews to infiltrate Fortune 500 and mid-market tech companies.

    → Stolen US identity + AI-generated profile
    → Live #AI assisted interview manipulation
    → Domestic facilitator handling onboarding
    → Corporate laptop sent to a US “laptop farm”
    → KVM/VPN tunnel from Pyongyang via Russian or Chinese relays
    → Salaries redirected through facilitator accounts → ~90% skimmed to the DPRK regime

    More than 300 companies impacted. Estimated revenue stream: ~$600M/year.

    Funds allegedly routed to DPRK Bureau 39 and the ballistic missile programme.

    $17.8M traced in facilitator accounts in the Christina Chapman case alone. Detection took months, not minutes. Traditional monitoring and standard #SOC visibility would likely not have detected the operation. Mandiant tracks the cluster as #UNC5267.

    This is no longer simple cybercrime. It is state-sponsored infiltration blending #CyberSecurity, #IdentityFraud, #OSINT, remote work infrastructure abuse and AI-powered social engineering.

    The future of #CTI and insider-threat detection is already here.

    cidu.io/articles/dprk-it-worke

    #NorthKorea #DPRK #CyberThreatIntelligence #CyberEspionage #CyberWarfare #Infosec #BlueTeam #ThreatIntel #Geopolitics #RemoteWork #VPN #KVM #Fortune500

  44. 🚀 OhMyPCAP 4.0.0 is HERE!

    The ultimate FOSS PCAP analyzer just got a massive upgrade for deeper file intelligence.

    New in v4.0:
    • Upgraded to YARA Forge Full ruleset — more comprehensive malware & threat detection
    • Exiftool + rich file metadata analysis — get more file information even if there are no YARA matches

    All the power you love is still here:
    Suricata alerts, file alerts, Sankey diagrams, full-text search, ASCII transcripts, hexdumps, stream carving + single Docker/Podman container (perfect for air-gapped or quick spins).

    Ideal for malware analysis, incident response, threat hunting, forensics & teaching.

    Who’s pulling this version right now? Drop a ❤️+ reply with your main use case (malware samples? CTFs? real-world incidents? teaching?)

    #PCAP #DFIR #Cybersecurity #Infosec #BlueTeam #ThreatHunting #Suricata #YARA #MalwareAnalysis

    @chrissanders88 @lennyzeltser

  45. Catch me at CyberSec 2026 in Taiwan ! 🇹🇼 🧋

    My colleague and I will be discussing the evolution of AI in the cybersecurity landscape. Is Gen AI replacing the analyst, or empowering them?🤖

    Join our session to see a live demonstration of how LLMs handle complex security analysis and how accuracy improves with expert feedback. Let’s connect and talk about the future of the SOC!

    cybersec.ithome.com.tw/2026/se

    #CyberSec2026 #Cybersecurity #GenAI #BlueTeam #TaiwanTech #SOC #IncidentResponse