home.social

#blueteam — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #blueteam, aggregated by home.social.

  1. 2026-09-18 RDP #Honeypot IOCs - 756 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    134.209.180.117 - 510
    104.64.217.122 - 87
    118.69.191.219 - 42

    Top ASNs:
    AS14061 - 510
    AS63949 - 90
    AS18403 - 42

    Top Accounts:
    hello - 642
    Administr - 18
    ident - 18

    Top ISPs:
    DigitalOcean, LLC - 510
    Akamai Technologies, Inc. - 90
    Vietnam Internet Network Information Center - 42

    Top Clients:
    Unknown - 756

    Top Software:
    Unknown - 756

    Top Keyboards:
    Unknown - 756

    Top IP Classification:
    hosting - 684
    Unknown - 48
    proxy - 18

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  2. 2026-09-18 RDP #Honeypot IOCs - 756 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    134.209.180.117 - 510
    104.64.217.122 - 87
    118.69.191.219 - 42

    Top ASNs:
    AS14061 - 510
    AS63949 - 90
    AS18403 - 42

    Top Accounts:
    hello - 642
    Administr - 18
    ident - 18

    Top ISPs:
    DigitalOcean, LLC - 510
    Akamai Technologies, Inc. - 90
    Vietnam Internet Network Information Center - 42

    Top Clients:
    Unknown - 756

    Top Software:
    Unknown - 756

    Top Keyboards:
    Unknown - 756

    Top IP Classification:
    hosting - 684
    Unknown - 48
    proxy - 18

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  3. 2026-09-18 RDP #Honeypot IOCs - 756 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    134.209.180.117 - 510
    104.64.217.122 - 87
    118.69.191.219 - 42

    Top ASNs:
    AS14061 - 510
    AS63949 - 90
    AS18403 - 42

    Top Accounts:
    hello - 642
    Administr - 18
    ident - 18

    Top ISPs:
    DigitalOcean, LLC - 510
    Akamai Technologies, Inc. - 90
    Vietnam Internet Network Information Center - 42

    Top Clients:
    Unknown - 756

    Top Software:
    Unknown - 756

    Top Keyboards:
    Unknown - 756

    Top IP Classification:
    hosting - 684
    Unknown - 48
    proxy - 18

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  4. 2026-09-18 RDP #Honeypot IOCs - 756 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    134.209.180.117 - 510
    104.64.217.122 - 87
    118.69.191.219 - 42

    Top ASNs:
    AS14061 - 510
    AS63949 - 90
    AS18403 - 42

    Top Accounts:
    hello - 642
    Administr - 18
    ident - 18

    Top ISPs:
    DigitalOcean, LLC - 510
    Akamai Technologies, Inc. - 90
    Vietnam Internet Network Information Center - 42

    Top Clients:
    Unknown - 756

    Top Software:
    Unknown - 756

    Top Keyboards:
    Unknown - 756

    Top IP Classification:
    hosting - 684
    Unknown - 48
    proxy - 18

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  5. 2026-09-18 RDP #Honeypot IOCs - 504 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    134.209.180.117 - 340
    104.64.217.122 - 58
    118.69.191.219 - 28

    Top ASNs:
    AS14061 - 340
    AS63949 - 60
    AS18403 - 28

    Top Accounts:
    hello - 428
    Administr - 12
    ident - 12

    Top ISPs:
    DigitalOcean, LLC - 340
    Akamai Technologies, Inc. - 60
    Vietnam Internet Network Information Center - 28

    Top Clients:
    Unknown - 504

    Top Software:
    Unknown - 504

    Top Keyboards:
    Unknown - 504

    Top IP Classification:
    hosting - 456
    Unknown - 32
    proxy - 12

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  6. 2026-09-18 RDP #Honeypot IOCs - 504 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    134.209.180.117 - 340
    104.64.217.122 - 58
    118.69.191.219 - 28

    Top ASNs:
    AS14061 - 340
    AS63949 - 60
    AS18403 - 28

    Top Accounts:
    hello - 428
    Administr - 12
    ident - 12

    Top ISPs:
    DigitalOcean, LLC - 340
    Akamai Technologies, Inc. - 60
    Vietnam Internet Network Information Center - 28

    Top Clients:
    Unknown - 504

    Top Software:
    Unknown - 504

    Top Keyboards:
    Unknown - 504

    Top IP Classification:
    hosting - 456
    Unknown - 32
    proxy - 12

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  7. 2026-09-18 RDP #Honeypot IOCs - 504 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    134.209.180.117 - 340
    104.64.217.122 - 58
    118.69.191.219 - 28

    Top ASNs:
    AS14061 - 340
    AS63949 - 60
    AS18403 - 28

    Top Accounts:
    hello - 428
    Administr - 12
    ident - 12

    Top ISPs:
    DigitalOcean, LLC - 340
    Akamai Technologies, Inc. - 60
    Vietnam Internet Network Information Center - 28

    Top Clients:
    Unknown - 504

    Top Software:
    Unknown - 504

    Top Keyboards:
    Unknown - 504

    Top IP Classification:
    hosting - 456
    Unknown - 32
    proxy - 12

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  8. 2026-09-18 RDP #Honeypot IOCs - 504 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    134.209.180.117 - 340
    104.64.217.122 - 58
    118.69.191.219 - 28

    Top ASNs:
    AS14061 - 340
    AS63949 - 60
    AS18403 - 28

    Top Accounts:
    hello - 428
    Administr - 12
    ident - 12

    Top ISPs:
    DigitalOcean, LLC - 340
    Akamai Technologies, Inc. - 60
    Vietnam Internet Network Information Center - 28

    Top Clients:
    Unknown - 504

    Top Software:
    Unknown - 504

    Top Keyboards:
    Unknown - 504

    Top IP Classification:
    hosting - 456
    Unknown - 32
    proxy - 12

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  9. 2026-09-18 RDP #Honeypot IOCs - 252 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    134.209.180.117 - 170
    104.64.217.122 - 29
    118.69.191.219 - 14

    Top ASNs:
    AS14061 - 170
    AS63949 - 30
    AS18403 - 14

    Top Accounts:
    hello - 214
    Administr - 6
    ident - 6

    Top ISPs:
    DigitalOcean, LLC - 170
    Akamai Technologies, Inc. - 30
    Vietnam Internet Network Information Center - 14

    Top Clients:
    Unknown - 252

    Top Software:
    Unknown - 252

    Top Keyboards:
    Unknown - 252

    Top IP Classification:
    hosting - 228
    Unknown - 16
    proxy - 6

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  10. 2026-09-18 RDP #Honeypot IOCs - 252 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    134.209.180.117 - 170
    104.64.217.122 - 29
    118.69.191.219 - 14

    Top ASNs:
    AS14061 - 170
    AS63949 - 30
    AS18403 - 14

    Top Accounts:
    hello - 214
    Administr - 6
    ident - 6

    Top ISPs:
    DigitalOcean, LLC - 170
    Akamai Technologies, Inc. - 30
    Vietnam Internet Network Information Center - 14

    Top Clients:
    Unknown - 252

    Top Software:
    Unknown - 252

    Top Keyboards:
    Unknown - 252

    Top IP Classification:
    hosting - 228
    Unknown - 16
    proxy - 6

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  11. 2026-09-18 RDP #Honeypot IOCs - 252 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    134.209.180.117 - 170
    104.64.217.122 - 29
    118.69.191.219 - 14

    Top ASNs:
    AS14061 - 170
    AS63949 - 30
    AS18403 - 14

    Top Accounts:
    hello - 214
    Administr - 6
    ident - 6

    Top ISPs:
    DigitalOcean, LLC - 170
    Akamai Technologies, Inc. - 30
    Vietnam Internet Network Information Center - 14

    Top Clients:
    Unknown - 252

    Top Software:
    Unknown - 252

    Top Keyboards:
    Unknown - 252

    Top IP Classification:
    hosting - 228
    Unknown - 16
    proxy - 6

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  12. 2026-09-18 RDP #Honeypot IOCs - 252 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    134.209.180.117 - 170
    104.64.217.122 - 29
    118.69.191.219 - 14

    Top ASNs:
    AS14061 - 170
    AS63949 - 30
    AS18403 - 14

    Top Accounts:
    hello - 214
    Administr - 6
    ident - 6

    Top ISPs:
    DigitalOcean, LLC - 170
    Akamai Technologies, Inc. - 30
    Vietnam Internet Network Information Center - 14

    Top Clients:
    Unknown - 252

    Top Software:
    Unknown - 252

    Top Keyboards:
    Unknown - 252

    Top IP Classification:
    hosting - 228
    Unknown - 16
    proxy - 6

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  13. 2026-09-17 RDP #Honeypot IOCs - 5520 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    147.182.250.28 - 4791
    134.209.180.117 - 462
    104.64.217.122 - 30

    Top ASNs:
    AS14061 - 5268
    AS63949 - 81
    AS396982 - 27

    Top Accounts:
    hello - 5367
    142.93.8.59 - 30
    Administr - 30

    Top ISPs:
    DigitalOcean, LLC - 5268
    Akamai Technologies, Inc. - 81
    Google LLC - 27

    Top Clients:
    Unknown - 5520

    Top Software:
    Unknown - 5520

    Top Keyboards:
    Unknown - 5520

    Top IP Classification:
    hosting - 5418
    Unknown - 69
    proxy - 18

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  14. 2026-09-17 RDP #Honeypot IOCs - 5520 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    147.182.250.28 - 4791
    134.209.180.117 - 462
    104.64.217.122 - 30

    Top ASNs:
    AS14061 - 5268
    AS63949 - 81
    AS396982 - 27

    Top Accounts:
    hello - 5367
    142.93.8.59 - 30
    Administr - 30

    Top ISPs:
    DigitalOcean, LLC - 5268
    Akamai Technologies, Inc. - 81
    Google LLC - 27

    Top Clients:
    Unknown - 5520

    Top Software:
    Unknown - 5520

    Top Keyboards:
    Unknown - 5520

    Top IP Classification:
    hosting - 5418
    Unknown - 69
    proxy - 18

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  15. 2026-09-17 RDP #Honeypot IOCs - 5520 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    147.182.250.28 - 4791
    134.209.180.117 - 462
    104.64.217.122 - 30

    Top ASNs:
    AS14061 - 5268
    AS63949 - 81
    AS396982 - 27

    Top Accounts:
    hello - 5367
    142.93.8.59 - 30
    Administr - 30

    Top ISPs:
    DigitalOcean, LLC - 5268
    Akamai Technologies, Inc. - 81
    Google LLC - 27

    Top Clients:
    Unknown - 5520

    Top Software:
    Unknown - 5520

    Top Keyboards:
    Unknown - 5520

    Top IP Classification:
    hosting - 5418
    Unknown - 69
    proxy - 18

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  16. 2026-09-17 RDP #Honeypot IOCs - 5520 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    147.182.250.28 - 4791
    134.209.180.117 - 462
    104.64.217.122 - 30

    Top ASNs:
    AS14061 - 5268
    AS63949 - 81
    AS396982 - 27

    Top Accounts:
    hello - 5367
    142.93.8.59 - 30
    Administr - 30

    Top ISPs:
    DigitalOcean, LLC - 5268
    Akamai Technologies, Inc. - 81
    Google LLC - 27

    Top Clients:
    Unknown - 5520

    Top Software:
    Unknown - 5520

    Top Keyboards:
    Unknown - 5520

    Top IP Classification:
    hosting - 5418
    Unknown - 69
    proxy - 18

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  17. 2026-09-17 RDP #Honeypot IOCs - 3680 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    147.182.250.28 - 3194
    134.209.180.117 - 308
    104.64.217.122 - 20

    Top ASNs:
    AS14061 - 3512
    AS63949 - 54
    AS396982 - 18

    Top Accounts:
    hello - 3578
    142.93.8.59 - 20
    Administr - 20

    Top ISPs:
    DigitalOcean, LLC - 3512
    Akamai Technologies, Inc. - 54
    Google LLC - 18

    Top Clients:
    Unknown - 3680

    Top Software:
    Unknown - 3680

    Top Keyboards:
    Unknown - 3680

    Top IP Classification:
    hosting - 3612
    Unknown - 46
    proxy - 12

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  18. 2026-09-17 RDP #Honeypot IOCs - 3680 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    147.182.250.28 - 3194
    134.209.180.117 - 308
    104.64.217.122 - 20

    Top ASNs:
    AS14061 - 3512
    AS63949 - 54
    AS396982 - 18

    Top Accounts:
    hello - 3578
    142.93.8.59 - 20
    Administr - 20

    Top ISPs:
    DigitalOcean, LLC - 3512
    Akamai Technologies, Inc. - 54
    Google LLC - 18

    Top Clients:
    Unknown - 3680

    Top Software:
    Unknown - 3680

    Top Keyboards:
    Unknown - 3680

    Top IP Classification:
    hosting - 3612
    Unknown - 46
    proxy - 12

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  19. 2026-09-17 RDP #Honeypot IOCs - 3680 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    147.182.250.28 - 3194
    134.209.180.117 - 308
    104.64.217.122 - 20

    Top ASNs:
    AS14061 - 3512
    AS63949 - 54
    AS396982 - 18

    Top Accounts:
    hello - 3578
    142.93.8.59 - 20
    Administr - 20

    Top ISPs:
    DigitalOcean, LLC - 3512
    Akamai Technologies, Inc. - 54
    Google LLC - 18

    Top Clients:
    Unknown - 3680

    Top Software:
    Unknown - 3680

    Top Keyboards:
    Unknown - 3680

    Top IP Classification:
    hosting - 3612
    Unknown - 46
    proxy - 12

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  20. 2026-09-17 RDP #Honeypot IOCs - 3680 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    147.182.250.28 - 3194
    134.209.180.117 - 308
    104.64.217.122 - 20

    Top ASNs:
    AS14061 - 3512
    AS63949 - 54
    AS396982 - 18

    Top Accounts:
    hello - 3578
    142.93.8.59 - 20
    Administr - 20

    Top ISPs:
    DigitalOcean, LLC - 3512
    Akamai Technologies, Inc. - 54
    Google LLC - 18

    Top Clients:
    Unknown - 3680

    Top Software:
    Unknown - 3680

    Top Keyboards:
    Unknown - 3680

    Top IP Classification:
    hosting - 3612
    Unknown - 46
    proxy - 12

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  21. 2026-09-17 RDP #Honeypot IOCs - 1840 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    147.182.250.28 - 1597
    134.209.180.117 - 154
    104.64.217.122 - 10

    Top ASNs:
    AS14061 - 1756
    AS63949 - 27
    AS396982 - 9

    Top Accounts:
    hello - 1789
    142.93.8.59 - 10
    Administr - 10

    Top ISPs:
    DigitalOcean, LLC - 1756
    Akamai Technologies, Inc. - 27
    Google LLC - 9

    Top Clients:
    Unknown - 1840

    Top Software:
    Unknown - 1840

    Top Keyboards:
    Unknown - 1840

    Top IP Classification:
    hosting - 1806
    Unknown - 23
    proxy - 6

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  22. 2026-09-17 RDP #Honeypot IOCs - 1840 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    147.182.250.28 - 1597
    134.209.180.117 - 154
    104.64.217.122 - 10

    Top ASNs:
    AS14061 - 1756
    AS63949 - 27
    AS396982 - 9

    Top Accounts:
    hello - 1789
    142.93.8.59 - 10
    Administr - 10

    Top ISPs:
    DigitalOcean, LLC - 1756
    Akamai Technologies, Inc. - 27
    Google LLC - 9

    Top Clients:
    Unknown - 1840

    Top Software:
    Unknown - 1840

    Top Keyboards:
    Unknown - 1840

    Top IP Classification:
    hosting - 1806
    Unknown - 23
    proxy - 6

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  23. 2026-09-17 RDP #Honeypot IOCs - 1840 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    147.182.250.28 - 1597
    134.209.180.117 - 154
    104.64.217.122 - 10

    Top ASNs:
    AS14061 - 1756
    AS63949 - 27
    AS396982 - 9

    Top Accounts:
    hello - 1789
    142.93.8.59 - 10
    Administr - 10

    Top ISPs:
    DigitalOcean, LLC - 1756
    Akamai Technologies, Inc. - 27
    Google LLC - 9

    Top Clients:
    Unknown - 1840

    Top Software:
    Unknown - 1840

    Top Keyboards:
    Unknown - 1840

    Top IP Classification:
    hosting - 1806
    Unknown - 23
    proxy - 6

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  24. 2026-09-17 RDP #Honeypot IOCs - 1840 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    147.182.250.28 - 1597
    134.209.180.117 - 154
    104.64.217.122 - 10

    Top ASNs:
    AS14061 - 1756
    AS63949 - 27
    AS396982 - 9

    Top Accounts:
    hello - 1789
    142.93.8.59 - 10
    Administr - 10

    Top ISPs:
    DigitalOcean, LLC - 1756
    Akamai Technologies, Inc. - 27
    Google LLC - 9

    Top Clients:
    Unknown - 1840

    Top Software:
    Unknown - 1840

    Top Keyboards:
    Unknown - 1840

    Top IP Classification:
    hosting - 1806
    Unknown - 23
    proxy - 6

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  25. Mini Blue Team Diaries story:

    There was a break-in over the weekend at one of our US offices. We occupied one floor of a shared office building, and two crooks managed to get in by going to an open floor above ours and breaking a lock on the fire escape.

    Rather brilliantly, a building security guard was doing rounds and actually caught the pair stuffing iPads from conference rooms into a rucksack. However, when challenged they claimed to be employees and were left alone.

    Anyway they ended up with about a half dozen iPads from Zoom rooms. Annoying but not the end of the world.

    Those iPads were clearly sold on, as they were connected to an MDM server and started to pop up in locations all over the city over the course of the next week.

    One of them was especially interesting. Because it was connected to our MDM Apple ID, it was syncing files to iCloud. This included photos. We noticed a lot of selfies of one particular dude show up. The dude looked a lot like one of the guys who we’d seen in our office on our security cameras. Yup.

    We of course passed on all the information, including the location of the selfie generating iPad, to law enforcement.

    I wish there was a more interesting ending - but they never followed up on the lead, of course. So the iPads lived on, slowly filling up with various photos and memories from the crook and the people they’d been sold on to.

    Read more, slightly less mini stories, at infosecdiaries.com

    #DFIR #infosec #InfoSecDiaries #BlueTeam

  26. Mini Blue Team Diaries story:

    There was a break-in over the weekend at one of our US offices. We occupied one floor of a shared office building, and two crooks managed to get in by going to an open floor above ours and breaking a lock on the fire escape.

    Rather brilliantly, a building security guard was doing rounds and actually caught the pair stuffing iPads from conference rooms into a rucksack. However, when challenged they claimed to be employees and were left alone.

    Anyway they ended up with about a half dozen iPads from Zoom rooms. Annoying but not the end of the world.

    Those iPads were clearly sold on, as they were connected to an MDM server and started to pop up in locations all over the city over the course of the next week.

    One of them was especially interesting. Because it was connected to our MDM Apple ID, it was syncing files to iCloud. This included photos. We noticed a lot of selfies of one particular dude show up. The dude looked a lot like one of the guys who we’d seen in our office on our security cameras. Yup.

    We of course passed on all the information, including the location of the selfie generating iPad, to law enforcement.

    I wish there was a more interesting ending - but they never followed up on the lead, of course. So the iPads lived on, slowly filling up with various photos and memories from the crook and the people they’d been sold on to.

    Read more, slightly less mini stories, at infosecdiaries.com

    #DFIR #infosec #InfoSecDiaries #BlueTeam

  27. Mini Blue Team Diaries story:

    There was a break-in over the weekend at one of our US offices. We occupied one floor of a shared office building, and two crooks managed to get in by going to an open floor above ours and breaking a lock on the fire escape.

    Rather brilliantly, a building security guard was doing rounds and actually caught the pair stuffing iPads from conference rooms into a rucksack. However, when challenged they claimed to be employees and were left alone.

    Anyway they ended up with about a half dozen iPads from Zoom rooms. Annoying but not the end of the world.

    Those iPads were clearly sold on, as they were connected to an MDM server and started to pop up in locations all over the city over the course of the next week.

    One of them was especially interesting. Because it was connected to our MDM Apple ID, it was syncing files to iCloud. This included photos. We noticed a lot of selfies of one particular dude show up. The dude looked a lot like one of the guys who we’d seen in our office on our security cameras. Yup.

    We of course passed on all the information, including the location of the selfie generating iPad, to law enforcement.

    I wish there was a more interesting ending - but they never followed up on the lead, of course. So the iPads lived on, slowly filling up with various photos and memories from the crook and the people they’d been sold on to.

    Read more, slightly less mini stories, at infosecdiaries.com

    #DFIR #infosec #InfoSecDiaries #BlueTeam

  28. Mini Blue Team Diaries story:

    There was a break-in over the weekend at one of our US offices. We occupied one floor of a shared office building, and two crooks managed to get in by going to an open floor above ours and breaking a lock on the fire escape.

    Rather brilliantly, a building security guard was doing rounds and actually caught the pair stuffing iPads from conference rooms into a rucksack. However, when challenged they claimed to be employees and were left alone.

    Anyway they ended up with about a half dozen iPads from Zoom rooms. Annoying but not the end of the world.

    Those iPads were clearly sold on, as they were connected to an MDM server and started to pop up in locations all over the city over the course of the next week.

    One of them was especially interesting. Because it was connected to our MDM Apple ID, it was syncing files to iCloud. This included photos. We noticed a lot of selfies of one particular dude show up. The dude looked a lot like one of the guys who we’d seen in our office on our security cameras. Yup.

    We of course passed on all the information, including the location of the selfie generating iPad, to law enforcement.

    I wish there was a more interesting ending - but they never followed up on the lead, of course. So the iPads lived on, slowly filling up with various photos and memories from the crook and the people they’d been sold on to.

    Read more, slightly less mini stories, at infosecdiaries.com

    #DFIR #infosec #InfoSecDiaries #BlueTeam

  29. Mini Blue Team Diaries story:

    There was a break-in over the weekend at one of our US offices. We occupied one floor of a shared office building, and two crooks managed to get in by going to an open floor above ours and breaking a lock on the fire escape.

    Rather brilliantly, a building security guard was doing rounds and actually caught the pair stuffing iPads from conference rooms into a rucksack. However, when challenged they claimed to be employees and were left alone.

    Anyway they ended up with about a half dozen iPads from Zoom rooms. Annoying but not the end of the world.

    Those iPads were clearly sold on, as they were connected to an MDM server and started to pop up in locations all over the city over the course of the next week.

    One of them was especially interesting. Because it was connected to our MDM Apple ID, it was syncing files to iCloud. This included photos. We noticed a lot of selfies of one particular dude show up. The dude looked a lot like one of the guys who we’d seen in our office on our security cameras. Yup.

    We of course passed on all the information, including the location of the selfie generating iPad, to law enforcement.

    I wish there was a more interesting ending - but they never followed up on the lead, of course. So the iPads lived on, slowly filling up with various photos and memories from the crook and the people they’d been sold on to.

    Read more, slightly less mini stories, at infosecdiaries.com

    #DFIR #infosec #InfoSecDiaries #BlueTeam

  30. Mini Blue Team Diaries story:

    There was a break in over the weekend at one of our US offices. We occupied one floor of a shared office building, and two crooks managed to get in by going to an open floor above ours and breaking a lock on the fire escape.

    Rather brilliantly, a building security guard was doing rounds and actually caught the pair stuffing iPads from conference rooms into a rucksack, however, when challenged they claimed to be employees and were left alone.

    Anyway they ended up with about a half dozen iPads from Zoom rooms. Annoying but not the end of the world.

    Those iPads were clearly sold on, as they were connected to MDM and started to pop up in locations all over the city over the course of the next week.

    One of them was especially interesting. Because it was connected to our MDM Apple ID, it was syncing files to iCloud. This included photos. We noticed a lot of selfies of one particular dude show up. The dude looked a lot like one of the guys who we’d seen in our office on our security cameras. Yup.

    We of course passed on all the information, including the location of the selfie generating iPad, to law enforcement.

    I wish there was a more interesting ending - but they never followed up on the lead, of course. So the iPads lived on, slowly filling up with various photos and memories from the crook and the people they’d been sold on to. We could’ve locked them or bricked them, but this was more fun.

    Read more, slightly less mini stories, at infosecdiaries.com

    #DFIR #infosec #InfoSecDiaries #BlueTeam

  31. Mini Blue Team Diaries story:

    There was a break in over the weekend at one of our US offices. We occupied one floor of a shared office building, and two crooks managed to get in by going to an open floor above ours and breaking a lock on the fire escape.

    Rather brilliantly, a building security guard was doing rounds and actually caught the pair stuffing iPads from conference rooms into a rucksack, however, when challenged they claimed to be employees and were left alone.

    Anyway they ended up with about a half dozen iPads from Zoom rooms. Annoying but not the end of the world.

    Those iPads were clearly sold on, as they were connected to MDM and started to pop up in locations all over the city over the course of the next week.

    One of them was especially interesting. Because it was connected to our MDM Apple ID, it was syncing files to iCloud. This included photos. We noticed a lot of selfies of one particular dude show up. The dude looked a lot like one of the guys who we’d seen in our office on our security cameras. Yup.

    We of course passed on all the information, including the location of the selfie generating iPad, to law enforcement.

    I wish there was a more interesting ending - but they never followed up on the lead, of course. So the iPads lived on, slowly filling up with various photos and memories from the crook and the people they’d been sold on to. We could’ve locked them or bricked them, but this was more fun.

    Read more, slightly less mini stories, at infosecdiaries.com

    #DFIR #infosec #InfoSecDiaries #BlueTeam

  32. Mini Blue Team Diaries story:

    There was a break in over the weekend at one of our US offices. We occupied one floor of a shared office building, and two crooks managed to get in by going to an open floor above ours and breaking a lock on the fire escape.

    Rather brilliantly, a building security guard was doing rounds and actually caught the pair stuffing iPads from conference rooms into a rucksack, however, when challenged they claimed to be employees and were left alone.

    Anyway they ended up with about a half dozen iPads from Zoom rooms. Annoying but not the end of the world.

    Those iPads were clearly sold on, as they were connected to MDM and started to pop up in locations all over the city over the course of the next week.

    One of them was especially interesting. Because it was connected to our MDM Apple ID, it was syncing files to iCloud. This included photos. We noticed a lot of selfies of one particular dude show up. The dude looked a lot like one of the guys who we’d seen in our office on our security cameras. Yup.

    We of course passed on all the information, including the location of the selfie generating iPad, to law enforcement.

    I wish there was a more interesting ending - but they never followed up on the lead, of course. So the iPads lived on, slowly filling up with various photos and memories from the crook and the people they’d been sold on to. We could’ve locked them or bricked them, but this was more fun.

    Read more, slightly less mini stories, at infosecdiaries.com

    #DFIR #infosec #InfoSecDiaries #BlueTeam

  33. Mini Blue Team Diaries story:

    There was a break in over the weekend at one of our US offices. We occupied one floor of a shared office building, and two crooks managed to get in by going to an open floor above ours and breaking a lock on the fire escape.

    Rather brilliantly, a building security guard was doing rounds and actually caught the pair stuffing iPads from conference rooms into a rucksack, however, when challenged they claimed to be employees and were left alone.

    Anyway they ended up with about a half dozen iPads from Zoom rooms. Annoying but not the end of the world.

    Those iPads were clearly sold on, as they were connected to MDM and started to pop up in locations all over the city over the course of the next week.

    One of them was especially interesting. Because it was connected to our MDM Apple ID, it was syncing files to iCloud. This included photos. We noticed a lot of selfies of one particular dude show up. The dude looked a lot like one of the guys who we’d seen in our office on our security cameras. Yup.

    We of course passed on all the information, including the location of the selfie generating iPad, to law enforcement.

    I wish there was a more interesting ending - but they never followed up on the lead, of course. So the iPads lived on, slowly filling up with various photos and memories from the crook and the people they’d been sold on to. We could’ve locked them or bricked them, but this was more fun.

    Read more, slightly less mini stories, at infosecdiaries.com

    #DFIR #infosec #InfoSecDiaries #BlueTeam

  34. Mini Blue Team Diaries story:

    There was a break in over the weekend at one of our US offices. We occupied one floor of a shared office building, and two crooks managed to get in by going to an open floor above ours and breaking a lock on the fire escape.

    Rather brilliantly, a building security guard was doing rounds and actually caught the pair stuffing iPads from conference rooms into a rucksack, however, when challenged they claimed to be employees and were left alone.

    Anyway they ended up with about a half dozen iPads from Zoom rooms. Annoying but not the end of the world.

    Those iPads were clearly sold on, as they were connected to MDM and started to pop up in locations all over the city over the course of the next week.

    One of them was especially interesting. Because it was connected to our MDM Apple ID, it was syncing files to iCloud. This included photos. We noticed a lot of selfies of one particular dude show up. The dude looked a lot like one of the guys who we’d seen in our office on our security cameras. Yup.

    We of course passed on all the information, including the location of the selfie generating iPad, to law enforcement.

    I wish there was a more interesting ending - but they never followed up on the lead, of course. So the iPads lived on, slowly filling up with various photos and memories from the crook and the people they’d been sold on to. We could’ve locked them or bricked them, but this was more fun.

    Read more, slightly less mini stories, at infosecdiaries.com

    #DFIR #infosec #InfoSecDiaries #BlueTeam