#blueteam — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #blueteam, aggregated by home.social.
-
🔐 Formation Hackfest 2026 : Sécurité Physique 101-201-202
Cette formation s'attaque à la sécurité physique, souvent négligé ou mal compris, même s'il précède l'infosécurité.
🔵 Lundi 26 oct : 101 - #blueTeam
🔴 Mardi 27 & mercredi 28 oct : 201 - #redTeam
🛠️ Jeudi 29 oct : 202 - Rétro-ingénierie systèmes de sécurité électroniquesInfos & inscription 👉 https://hackfest.ca/formations/?utm_source=mastodon&utm_medium=socmed&utm_campaign=securitePhysique_sept2026
-
🔐 Formation Hackfest 2026 : Sécurité Physique 101-201-202
Cette formation s'attaque à la sécurité physique, souvent négligé ou mal compris, même s'il précède l'infosécurité.
🔵 Lundi 26 oct : 101 - #blueTeam
🔴 Mardi 27 & mercredi 28 oct : 201 - #redTeam
🛠️ Jeudi 29 oct : 202 - Rétro-ingénierie systèmes de sécurité électroniquesInfos & inscription 👉 https://hackfest.ca/formations/?utm_source=mastodon&utm_medium=socmed&utm_campaign=securitePhysique_sept2026
-
🔐 Formation Hackfest 2026 : Sécurité Physique 101-201-202
Cette formation s'attaque à la sécurité physique, souvent négligé ou mal compris, même s'il précède l'infosécurité.
🔵 Lundi 26 oct : 101 - #blueTeam
🔴 Mardi 27 & mercredi 28 oct : 201 - #redTeam
🛠️ Jeudi 29 oct : 202 - Rétro-ingénierie systèmes de sécurité électroniquesInfos & inscription 👉 https://hackfest.ca/formations/?utm_source=mastodon&utm_medium=socmed&utm_campaign=securitePhysique_sept2026
-
🔐 Formation Hackfest 2026 : Sécurité Physique 101-201-202
Cette formation s'attaque à la sécurité physique, souvent négligé ou mal compris, même s'il précède l'infosécurité.
🔵 Lundi 26 oct : 101 - #blueTeam
🔴 Mardi 27 & mercredi 28 oct : 201 - #redTeam
🛠️ Jeudi 29 oct : 202 - Rétro-ingénierie systèmes de sécurité électroniquesInfos & inscription 👉 https://hackfest.ca/formations/?utm_source=mastodon&utm_medium=socmed&utm_campaign=securitePhysique_sept2026
-
🔐 Formation Hackfest 2026 : Sécurité Physique 101-201-202
Cette formation s'attaque à la sécurité physique, souvent négligé ou mal compris, même s'il précède l'infosécurité.
🔵 Lundi 26 oct : 101 - #blueTeam
🔴 Mardi 27 & mercredi 28 oct : 201 - #redTeam
🛠️ Jeudi 29 oct : 202 - Rétro-ingénierie systèmes de sécurité électroniquesInfos & inscription 👉 https://hackfest.ca/formations/?utm_source=mastodon&utm_medium=socmed&utm_campaign=securitePhysique_sept2026
-
What started as a project out of vendor frustration and spite, became a plucky git repo to nerf cyber crime riding trusted services. I'm so happy when defenders tell me how BS Lists helped them in their $job.
Similar to LOLRMM, LOTT, and ClickGrab, it's a passion project maintained by a single individual.
[ xkcd.gif ]And this model puts these projects at-risk long-term.Because the author of BS Lists apparently can't be bothered to wear his helmet during rock and icefall danger, new lists will be published on IFIN, a 501(c)(3) cyber intel non-profit. Older lists will be migrated where appropriate.
With this announcement, there is a 2050 domain-strong RPC Node list to combat #Etherhiding I encourage defenders to check out.
https://lists.ifin.network/lists/rpc-nodes/
I also have 3 more lists in queue.
-
AI is not your biggest cyber threat.
Your shitty patching process probably is.
A slightly sarcastic take on AI hype, CISOs, security theatre, broken processes, legacy IT, SOC reality and why automation changes the speed of attacks more than the nature of the problem.
https://0ut3r.space/2026/08/08/ai-is-not-your-biggest-cyber-threat/
#cybersecurity #infosec #AI #CISO #BlueTeam #RedTeam #SOC #SecurityEngineering
-
We still have not processed 49 hours of new #cve #cvealert data due to system update and new source connection https://www.valtersit.com/cve will become much better and after that vendors is next on the list. #defcon #devops #devsecops #sysadmin #cybersecurity #redteam #blueteam #hackers #infosec #linux #python #developers #ubuntu #ethicalhacking #ethicalhacker #angular #android
-
With your help, we can elect more Democrats to office. We're looking for passionate people to join our national team of pragmatic progressives. #VoteBlue #Vote #Blue #VoteDemocrat #BlueTeam #Democrats 💙💙💙 www.voteblue.win/apply
-
Honeypots, when set up correctly, can become sensors that reveal attacker behavior. Add that with Suricata's rules and tuning, and they can provide clear, named alerts that cut away the noise.
Our Luke Davis set up a T-Pot with Suricata for 3 days, and it flagged probes for OpenSSH “regreSSHion” (CVE-2024-6387) and Treck TCP/IP (CVE-2020-11910), as well as highlighting cloud IP scanning.
Honeypots can be great as an early detection method and a hands-on training tool for students, SOC analysts, and Blue Teams to practise detection and response in safe environments.
📌Read the full blog here: https://www.pentestpartners.com/security-blog/spot-trouble-early-with-honeypots-and-suricata/
#CyberSecurity #Honeypots #Suricata #ThreatDetection #BlueTeam
-
🐽 Snort Command Cheat Sheet: Understand Network Threats Like a Pro
Snort is a powerful open-source tool used for Network Intrusion Detection and Prevention (NIDS/NIPS). It's widely adopted by blue teams and security professionals to monitor, alert, and defend against malicious network activity.
🧠 Key Usage Modes (No Code Needed):
• Test Mode: Check configuration files before deployment
• Packet Sniffing Mode: Monitor live traffic and display it in real time
• Packet Logging Mode: Capture packets and store them for analysis
• IDS Mode: Analyze traffic against rule sets and raise alerts
• Silent Mode: Run in the background while logging events🛡️ Snort is great for:
• Detecting port scans and suspicious payloads
• Monitoring traffic for policy violations
• Integrating with SIEM solutions
• Practicing blue team defensive strategiesDisclaimer: This content is intended strictly for educational and awareness purposes. Use intrusion detection systems responsibly and ethically.
#Snort #NetworkSecurity #CyberSecurity #InfoSec #BlueTeam #IDS #EducationOnly #IntrusionDetection #SOCTools #PacketAnalysis
-
Inside the Mind of a Hacker #CyberSecurity #HackerMindset #DigitalDefense #InfoSec #CyberThreats #TTPs #PhishingAwareness #PrivilegeEscalation #NetworkSecurity #MalwareAnalysis #EthicalHacking #OpSec #BlueTeam #RedTeam #CyberIntel #DeadSwitch #CyberGhost #KnowYourEnemy #SilenceIsTactical #FearTheSwitch
http://tomsitcafe.com/2025/04/08/inside-the-mind-of-a-hacker/
-
Abusing Ubuntu 24.04 features for root privilege escalation:
https://snyk.io/blog/abusing-ubuntu-root-privilege-escalation/
#cybersecurity #infosec #linux #ubuntu #vulnerability #eop #privescalation #redteam #informationsecurity #blueteam
-
There is something so satisfying in kicking off an entire RFC1918 scan.
Doing a single port at a brisk but safe (for my environment) pace.
~/# nmap -Pn -n -p <single port number> -T4 --open 10.0.0.0/8
~/# nmap -Pn -n -p <single port number> -T4 --open 172.16.0.0/12
~/# nmap -Pn -n -p <single port number> -T4 --open 192.168.0.0/16
(command broken out for dramatic effect - also note that I break out each of those CIDRs into /24's so that if anything breaks, I can pick up easier where the last known good ended. It's scripted and I prefer it this way.)
I am not doing a ping sweep or a DNS resolution. I'm assuming all hosts are up. And I'm looking for every host with a single port open. So even if they dont respond to pings (or something is preventing pings), I should get an answer back.
Note, I could certainly do faster (T5 or masscan, gawd) - but this is about as fast as I'm going to do in my environment and still be safe.
Also, only looking for open ports right now - no fingerprinting yet.
A cool thing about this approach is many intrusion detection still will only look for multiple ports on a single host to trigger an alert. Some still ignore many hosts / single port scans (to their detriment).
We've long sense purple teamed this, so I sent a notification to SOC letting them know my actions and asking them nicely (I bribed them last week) to not stop me, lol.
Should take a couple weeks to a month at this pace and in my environment to hit every single one of the just shy of 18,000,000 hosts 😂
#pentesting #hacking #infosec #penetrationtesting #blueteam #redteam #intrusionDetection
-
Introducing the newest major @tidalcyber TTP intelligence content roundup, the Initial Access & Malware Delivery Landscape matrix, now live in our free Community Edition platform: https://app.tidalcyber.com/share/43836024-a194-4ac7-9659-b51e88632e7f
The matrix covers 25 major & emerging #malware typically used to gain early footholds in victim environments, often leading to ingress of more impactful threats, especially #ransomware, #infostealers, cryptominers, & more. It includes many recognizable names (#QakBot, #IcedID, #Emotet, #Bumblebee, #Gootloader) plus several newer and less-discussed threats
The matrix includes 13 custom Technique Sets for threats not currently tracked in the #mitreattack knowledge base. All technique references derive from a large volume of recent, public #threat reporting (click the labels in the ribbon at the top of the matrix to view relevant source URLs for each threat)
An interactive link analysis visualization of connections among these threats, also derived from public reports, is also available here: https://onodo.org/visualizations/235067/
Community Edition matrices support easy identification of shared (and outlier) techniques among multiple threats, and quick & easy overlay or pivoting to defensive & offensive security capabilities relevant to your own #security stack. We’ll have a blog out soon reviewing our analysis of top & trending techniques common among these initial access threats
Tidal’s #Adversary Intelligence team remains focused on providing up-to-date #TTPintelligence, especially around traditionally under-represented yet widely relevant threats like crimeware. Other popular matrices in this theme include our Ransomware & Data Extortion Landscape matrix (https://app.tidalcyber.com/share/9a0fd4e6-1daf-4f98-a91d-b73003eb2d6a) and Major & Emerging Infostealers matrix (https://app.tidalcyber.com/share/ec62f5e0-bd40-476b-a560-7ad2779ea9e3), which each cover 20+ threats
Financially motivated adversaries often display a rapid pace of #TTP evolution, and this is especially apparent for #initialaccess threats. Register for our webinar on May 31 dedicated to TTP evolution, its drivers, and discussion around what defenders can do to address it and its implications: https://hubs.la/Q01NC23k0
#SharedWithTidal #threatinformeddefense #malware #infostealer #cryptominer #IAB #blueteam #detectionengineering #purpleteam #cyber