#blueteam — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #blueteam, aggregated by home.social.
-
What started as a project out of vendor frustration and spite, became a plucky git repo to nerf cyber crime riding trusted services. I'm so happy when defenders tell me how BS Lists helped them in their $job.
Similar to LOLRMM, LOTT, and ClickGrab, it's a passion project maintained by a single individual.
[ xkcd.gif ]And this model puts these projects at-risk long-term.Because the author of BS Lists apparently can't be bothered to wear his helmet during rock and icefall danger, new lists will be published on IFIN, a 501(c)(3) cyber intel non-profit. Older lists will be migrated where appropriate.
With this announcement, there is a 2050 domain-strong RPC Node list to combat #Etherhiding I encourage defenders to check out.
https://lists.ifin.network/lists/rpc-nodes/
I also have 3 more lists in queue.
-
2026-09-12 RDP #Honeypot IOCs - 34326 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
14.225.19.59 - 30099
147.182.250.28 - 4032
104.64.217.122 - 60Top ASNs:
AS135905 - 30099
AS14061 - 4050
AS63949 - 66Top Accounts:
hello - 34233
Administr - 33
anonymous - 9Top ISPs:
Vietnam Posts and Telecommunications Group - 30099
DigitalOcean, LLC - 4050
Akamai Technologies, Inc. - 66Top Clients:
Unknown - 34326Top Software:
Unknown - 34326Top Keyboards:
Unknown - 34326Top IP Classification:
Unknown - 30114
hosting - 4212Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-12 RDP #Honeypot IOCs - 34326 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
14.225.19.59 - 30099
147.182.250.28 - 4032
104.64.217.122 - 60Top ASNs:
AS135905 - 30099
AS14061 - 4050
AS63949 - 66Top Accounts:
hello - 34233
Administr - 33
anonymous - 9Top ISPs:
Vietnam Posts and Telecommunications Group - 30099
DigitalOcean, LLC - 4050
Akamai Technologies, Inc. - 66Top Clients:
Unknown - 34326Top Software:
Unknown - 34326Top Keyboards:
Unknown - 34326Top IP Classification:
Unknown - 30114
hosting - 4212Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-12 RDP #Honeypot IOCs - 34326 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
14.225.19.59 - 30099
147.182.250.28 - 4032
104.64.217.122 - 60Top ASNs:
AS135905 - 30099
AS14061 - 4050
AS63949 - 66Top Accounts:
hello - 34233
Administr - 33
anonymous - 9Top ISPs:
Vietnam Posts and Telecommunications Group - 30099
DigitalOcean, LLC - 4050
Akamai Technologies, Inc. - 66Top Clients:
Unknown - 34326Top Software:
Unknown - 34326Top Keyboards:
Unknown - 34326Top IP Classification:
Unknown - 30114
hosting - 4212Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-12 RDP #Honeypot IOCs - 34326 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
14.225.19.59 - 30099
147.182.250.28 - 4032
104.64.217.122 - 60Top ASNs:
AS135905 - 30099
AS14061 - 4050
AS63949 - 66Top Accounts:
hello - 34233
Administr - 33
anonymous - 9Top ISPs:
Vietnam Posts and Telecommunications Group - 30099
DigitalOcean, LLC - 4050
Akamai Technologies, Inc. - 66Top Clients:
Unknown - 34326Top Software:
Unknown - 34326Top Keyboards:
Unknown - 34326Top IP Classification:
Unknown - 30114
hosting - 4212Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-12 RDP #Honeypot IOCs - 34324 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
14.225.19.59 - 30097
147.182.250.28 - 4032
104.64.217.122 - 60Top ASNs:
AS135905 - 30097
AS14061 - 4050
AS63949 - 66Top Accounts:
hello - 34231
Administr - 33
anonymous - 9Top ISPs:
Vietnam Posts and Telecommunications Group - 30097
DigitalOcean, LLC - 4050
Akamai Technologies, Inc. - 66Top Clients:
Unknown - 34324Top Software:
Unknown - 34324Top Keyboards:
Unknown - 34324Top IP Classification:
Unknown - 30112
hosting - 4212Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-12 RDP #Honeypot IOCs - 34324 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
14.225.19.59 - 30097
147.182.250.28 - 4032
104.64.217.122 - 60Top ASNs:
AS135905 - 30097
AS14061 - 4050
AS63949 - 66Top Accounts:
hello - 34231
Administr - 33
anonymous - 9Top ISPs:
Vietnam Posts and Telecommunications Group - 30097
DigitalOcean, LLC - 4050
Akamai Technologies, Inc. - 66Top Clients:
Unknown - 34324Top Software:
Unknown - 34324Top Keyboards:
Unknown - 34324Top IP Classification:
Unknown - 30112
hosting - 4212Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-12 RDP #Honeypot IOCs - 34324 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
14.225.19.59 - 30097
147.182.250.28 - 4032
104.64.217.122 - 60Top ASNs:
AS135905 - 30097
AS14061 - 4050
AS63949 - 66Top Accounts:
hello - 34231
Administr - 33
anonymous - 9Top ISPs:
Vietnam Posts and Telecommunications Group - 30097
DigitalOcean, LLC - 4050
Akamai Technologies, Inc. - 66Top Clients:
Unknown - 34324Top Software:
Unknown - 34324Top Keyboards:
Unknown - 34324Top IP Classification:
Unknown - 30112
hosting - 4212Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-12 RDP #Honeypot IOCs - 34324 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
14.225.19.59 - 30097
147.182.250.28 - 4032
104.64.217.122 - 60Top ASNs:
AS135905 - 30097
AS14061 - 4050
AS63949 - 66Top Accounts:
hello - 34231
Administr - 33
anonymous - 9Top ISPs:
Vietnam Posts and Telecommunications Group - 30097
DigitalOcean, LLC - 4050
Akamai Technologies, Inc. - 66Top Clients:
Unknown - 34324Top Software:
Unknown - 34324Top Keyboards:
Unknown - 34324Top IP Classification:
Unknown - 30112
hosting - 4212Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-12 RDP #Honeypot IOCs - 34322 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
14.225.19.59 - 30095
147.182.250.28 - 4032
104.64.217.122 - 60Top ASNs:
AS135905 - 30095
AS14061 - 4050
AS63949 - 66Top Accounts:
hello - 34229
Administr - 33
anonymous - 9Top ISPs:
Vietnam Posts and Telecommunications Group - 30095
DigitalOcean, LLC - 4050
Akamai Technologies, Inc. - 66Top Clients:
Unknown - 34322Top Software:
Unknown - 34322Top Keyboards:
Unknown - 34322Top IP Classification:
Unknown - 30110
hosting - 4212Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-12 RDP #Honeypot IOCs - 34322 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
14.225.19.59 - 30095
147.182.250.28 - 4032
104.64.217.122 - 60Top ASNs:
AS135905 - 30095
AS14061 - 4050
AS63949 - 66Top Accounts:
hello - 34229
Administr - 33
anonymous - 9Top ISPs:
Vietnam Posts and Telecommunications Group - 30095
DigitalOcean, LLC - 4050
Akamai Technologies, Inc. - 66Top Clients:
Unknown - 34322Top Software:
Unknown - 34322Top Keyboards:
Unknown - 34322Top IP Classification:
Unknown - 30110
hosting - 4212Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-12 RDP #Honeypot IOCs - 34322 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
14.225.19.59 - 30095
147.182.250.28 - 4032
104.64.217.122 - 60Top ASNs:
AS135905 - 30095
AS14061 - 4050
AS63949 - 66Top Accounts:
hello - 34229
Administr - 33
anonymous - 9Top ISPs:
Vietnam Posts and Telecommunications Group - 30095
DigitalOcean, LLC - 4050
Akamai Technologies, Inc. - 66Top Clients:
Unknown - 34322Top Software:
Unknown - 34322Top Keyboards:
Unknown - 34322Top IP Classification:
Unknown - 30110
hosting - 4212Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-12 RDP #Honeypot IOCs - 34322 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
14.225.19.59 - 30095
147.182.250.28 - 4032
104.64.217.122 - 60Top ASNs:
AS135905 - 30095
AS14061 - 4050
AS63949 - 66Top Accounts:
hello - 34229
Administr - 33
anonymous - 9Top ISPs:
Vietnam Posts and Telecommunications Group - 30095
DigitalOcean, LLC - 4050
Akamai Technologies, Inc. - 66Top Clients:
Unknown - 34322Top Software:
Unknown - 34322Top Keyboards:
Unknown - 34322Top IP Classification:
Unknown - 30110
hosting - 4212Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
New by me: CybersecKyle Security How-To Series: Light Offensive to Think Defensively, Part 4 - From Findings to Fixes with a Short Report
#Cybersecurity #InfoSec #RiskManagement #BlueTeam #CybersecKyleHowTo
-
Linux Security Auditing with Lynis
In this article, I cover how to use Lynis for Linux security auditing, system hardening, and practical vulnerability assessment.
🔗 https://denizhalil.com/2025/03/17/linux-security-auditing-with-lynis/
#CyberSecurity #LinuxSecurity #Lynis #SecurityAuditing #SystemHardening #BlueTeam #DevSecOps #InfoSec #Linux #ITSecurity #SecurityEngineering #DenizHalil
-
Linux Security Auditing with Lynis
In this article, I cover how to use Lynis for Linux security auditing, system hardening, and practical vulnerability assessment.
https://denizhalil.com/2025/03/17/linux-security-auditing-with-lynis/
#CyberSecurity #LinuxSecurity #Lynis #SecurityAuditing #SystemHardening #BlueTeam #DevSecOps #InfoSec #Linux #ITSecurity #SecurityEngineering #DenizHalil
-
Released v1.3.3. of #Yaralyzer, my surprisingly popular tool for visualizing YARA rule matches with colors (a lot of colors).
1. --export-png images lets you export images of the analysis
2. almost all command line options (including multi argument ones like --yara-rules-dir) can be permanently set via environment variables or .yaralyzer file
3. couple of small bug fixes and debugging related command line options
You can try it on the web here: https://yaratoolkit.securitybreak.io/
(I didn't build this website, Thomas Roccia from Microsoft just integrated Yaralyzer into his existing site)- Github: https://github.com/michelcrypt4d4mus/yaralyzer
- Pypi: https://pypi.org/project/yaralyzer/
- on macOS you can also get it with #Homebrew by installing Pdfalyzer: brew install pdfalyzer#ascii #asciiArt #blueteam #cybersecurity #detectionEngineering #DFIR #forensics #FOSS #GPL #hacking #infosec #KaliLinux #maldoc #malware #malwareAnalysis #malwareDetection #openSource #pypi #python #redteam #reverseEngineering #reversing #Threatassessment #threathunting #YARA #YARArule #YARArules
-
Server Security Checklist — Essential Hardening Guide
Securing your servers isn’t optional — it’s your first line of defense against data breaches, ransomware, insider threats, and lateral movement. Use this checklist as a baseline for Linux, Windows, cloud, hybrid, or on-prem servers.
⸻
🔧 1. System & OS Hardening
• Keep OS & packages updated (apply security patches frequently).
• Remove / disable unused services & software.
• Enforce secure boot + BIOS/UEFI passwords.
• Disable auto-login and guest accounts.
• Use minimal OS images only (reduce attack surface).⸻
🔐 2. Access Control
• Enforce strong passwords & MFA everywhere.
• Use RBAC & least privilege access.
• Disable root/Administrator login over SSH/RDP.
• Rotate credentials & keys regularly.
• Implement just-in-time access for privileged users.⸻
🌐 3. Network Security
• Restrict inbound/outbound traffic via firewalls.
• Segment critical servers from general LANs/VLANs.
• Disable unused ports & protocols.
• Enable DoS/DDoS protection.
• Apply zero-trust network principles.⸻
🔑 4. Secure Remote Access
• Use SSH key-based authentication (disable password login).
• Enforce VPN for admin access.
• Log & monitor all remote access sessions.
• Disable legacy protocols (Telnet, FTP, SMBv1).
• Require bastion/jump host for critical access.⸻
📊 5. Logging & Monitoring
• Enable centralized logging (syslog / SIEM).
• Track failed login attempts & anomalies.
• Configure alerts for privilege escalation or config changes.
• Monitor log tampering.
• Retain logs securely for audits & forensics.⸻
🔒 6. Data Protection
• Encrypt data at rest (LUKS, BitLocker, etc.).
• Encrypt data in transit (TLS 1.2+).
• Strict database access policies.
• Regular, offline, immutable backups.
• Test restore procedures (don’t assume backups work).⸻
🔁 7. Application & Patch Management
• Keep middleware, frameworks, and apps patched.
• Delete default credentials & sample files.
• Enable code signing for software packages.
• Use secure coding practices (OWASP Top 10).
• Implement dependency scanning (Snyk, Trivy, etc.).⸻
🛡️ 8. Malware & Intrusion Defense
• Deploy EDR/AV on endpoints.
• Enable IDS/IPS at network edge.
• Automatic vulnerability scans (schedule weekly/monthly).
• Monitor persistence techniques (cron, startup scripts).
• Block known malicious IP ranges & TLDs.⸻
🏢 9. Physical & Cloud Security
• Restrict physical access to server racks/rooms.
• Enable provider security tools (AWS Security Groups, Azure NSG, IAM).
• Harden cloud images (CIS benchmarks).
• Review cloud logging & audit trails regularly.
• Disable unused cloud API keys / roles.⸻
📜 10. Policy & Compliance
• Use CIS / NIST / ISO-27001 benchmarks.
• Track & document every access change.
• Force annual access reviews & key rotation.
• Perform regular security training for admins.
• Maintain disaster recovery & incident plans.⸻
➕ Additional 5 Critical Controls (Advanced Hardening)
🧠 11. Privileged Access Management (PAM)
• Use jump hosts & session recording.
• Just-In-Time access for admins.
• Store keys in secure vaults (HashiCorp Vault, CyberArk).🚨 12. Real-Time Threat Detection
• Use behavioral analytics → UEBA/XDR.
• AI-based anomaly detection recommended.
• Block suspicious IPs automatically.🧪 13. Red Team & Pentesting
• Run regular internal pentests.
• Validate configuration weaknesses.
• Simulate phishing + lateral movement scenarios.🧱 14. Container / VM Isolation
• Use AppArmor, SELinux, Seccomp profiles.
• Limit Docker socket access & root containers.
• Scan images before deployment.📦 15. Automated Configuration Management
• Use IaC (Terraform, Ansible, Puppet) for repeatable and secure builds.
• Detect drift using compliance scanning.
• Version control all infrastructure.⸻
🧠 Core Reminder
A server is only as secure as the team who maintains it.
Hardening isn’t one task — it’s an ongoing#ServerSecurity #SystemHardening #InfoSec #CyberSecurity #BlueTeam
#DevSecOps #SysAdmin #ThreatDetection #AccessControl #NetworkSecurity
#LinuxSecurity #SecureArchitecture #RiskMitigation #SecurityChecklist
#CloudSecurity #InfrastructureSecurity #ZeroTrust #SecurityMonitoring -
Post-Earnings Dip: Why You Shouldn't Get Too Comfortable on Cybersecurity Gains
Just when you thought it was safe to go back in the market, cybersecurity stocks like Palo Alto Networks take a hit after strong quarterly results. But what does this mean for your online safety?
As cybersecurity companies continue to report impressive earnings, it's essential to remember that security is an ongoing battle. New vulnerabilities and threats emerge daily, making it crucial to stay vigilant.
So, are you taking the necessary steps to protect your digital fortress? What's your top concern when it comes to cybersecurity? Share with us in the comments below!
#CybersecurityMatters #DigitalSafetyFirst #StaySecure
#InfoSec # Cybersecurity #BlueTeam
Read more: https://short.steelefortress.com/ffww3t
-
Used some #AI to jury rig a basic API documentation site for The Yaralyzer, my unexpectedly popular tool for visualizing and forcibly decoding #YARA matches in binary data.
* GitHub: https://github.com/michelcrypt4d4mus/yaralyzer
* PyPi: https://pypi.org/project/yaralyzer/
* API documentation: https://michelcrypt4d4mus.github.io/yaralyzer/api/
* Can also be installed (indirectly) via homebrew if you install The #Pdfalyzer (different tool)#ascii #asciiArt #blueteam #cybersecurity #detectionengineering #DFIR #forensics #FOSS #hacking #infosec #KaliLinux #malware #malwareDetection #malwareAnalysis #openSource #pdfalyzer #redteam #reverseEngineering #reversing #threathunting #yaralyze #yaralyzer #YARA #YARArule #YARArules
-
Just released version 1.16.8 of The Pdfalyzer with a bunch of new and updated #YARA rules to scan #PDF files for malicious content. Links in the quoted toot below.
https://universeodon.com/@cryptadamist/114768170683991686
#ascii #asciiArt #blueteam #cybersecurity #detectionEngineering #DFIR #forensics #FOSS #hacking #homebrew #infosec #KaliLinux #malware #malwareDetection #malwareAnalysis #openSource #pdf #pdfs #pdfalyzer #pypi #python #redteam #reverseEngineering #reversing #Threatassessment #threathunting #yaralyze #yaralyzer #YARA #YARArule #YARArules
-
just released version 1.0.1 of The Yaralyzer, my unexpectedly popular tool for visualizing and forcibly decoding #YARA matches in binary data. Fixes a small bug when trying to choose a byte offset to force a UTF-16 or UTF-32 decoding of matched bytes.
someone set up Yaralyzer as a #Kali package; not sure if that's made it into a release yet but if not the links are below.
https://universeodon.com/@cryptadamist/113642071681749608
#ascii #asciiArt #blueteam #cybersecurity #detectionengineering #DFIR #forensics #FOSS #hacking #infosec #KaliLinux #malware #malwareDetection #malwareAnalysis #openSource #pdfalyzer #redteam #reverseEngineering #reversing #threathunting #yaralyze #yaralyzer #YARA #YARArule #YARArules
-
I can't recommend it enough. Check and harden your Active Directory with #PingCastle! This powerful tool identifies vulnerabilities, spots misconfigurations, generates a convenient, comprehensive report to guide your security efforts, and helps you ensure your Active Directory remains robust and secure. No installation required.
https://www.pingcastle.com/download/ -
I can't recommend it enough. Check and harden your Active Directory with #PingCastle! This powerful tool identifies vulnerabilities, spots misconfigurations, generates a convenient, comprehensive report to guide your security efforts, and helps you ensure your Active Directory remains robust and secure. No installation required.
https://www.pingcastle.com/download/ -
I can't recommend it enough. Check and harden your Active Directory with #PingCastle! This powerful tool identifies vulnerabilities, spots misconfigurations, generates a convenient, comprehensive report to guide your security efforts, and helps you ensure your Active Directory remains robust and secure. No installation required.
https://www.pingcastle.com/download/ -
I can't recommend it enough. Check and harden your Active Directory with #PingCastle! This powerful tool identifies vulnerabilities, spots misconfigurations, generates a convenient, comprehensive report to guide your security efforts, and helps you ensure your Active Directory remains robust and secure. No installation required.
https://www.pingcastle.com/download/ -
Look what finally arrived!!! 🥳📚
I was already feeling a bit jealous; everyone already received their preordered copy, but my author copy was still missing until now 😄
⭐️📖 Get the book: https://packt.link/MiriamCW
-
I am looking for Yara rules to check for malware in PDF, images and office files.
I thought it would be easy to find a repository with such rules, as I am sure I
am not the only one scanning these kind of files. So far I found this:
https://github.com/Yara-Rules/rules
There are repositories pointing to other repositories (like https://github.com/InQuest/awesome-yara)
but none of them seem to be up to date nor have many rule files.
I would expect such a repository to contain thousends of Yara files...Does such a public repository exist?
Is Yara not in use anymore? Many repositories seem abandoned.
I have the feeling that I am missing something...