#blueteam — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #blueteam, aggregated by home.social.
-
2026-09-18 RDP #Honeypot IOCs - 756 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
134.209.180.117 - 510
104.64.217.122 - 87
118.69.191.219 - 42Top ASNs:
AS14061 - 510
AS63949 - 90
AS18403 - 42Top Accounts:
hello - 642
Administr - 18
ident - 18Top ISPs:
DigitalOcean, LLC - 510
Akamai Technologies, Inc. - 90
Vietnam Internet Network Information Center - 42Top Clients:
Unknown - 756Top Software:
Unknown - 756Top Keyboards:
Unknown - 756Top IP Classification:
hosting - 684
Unknown - 48
proxy - 18Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-18 RDP #Honeypot IOCs - 756 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
134.209.180.117 - 510
104.64.217.122 - 87
118.69.191.219 - 42Top ASNs:
AS14061 - 510
AS63949 - 90
AS18403 - 42Top Accounts:
hello - 642
Administr - 18
ident - 18Top ISPs:
DigitalOcean, LLC - 510
Akamai Technologies, Inc. - 90
Vietnam Internet Network Information Center - 42Top Clients:
Unknown - 756Top Software:
Unknown - 756Top Keyboards:
Unknown - 756Top IP Classification:
hosting - 684
Unknown - 48
proxy - 18Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-18 RDP #Honeypot IOCs - 756 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
134.209.180.117 - 510
104.64.217.122 - 87
118.69.191.219 - 42Top ASNs:
AS14061 - 510
AS63949 - 90
AS18403 - 42Top Accounts:
hello - 642
Administr - 18
ident - 18Top ISPs:
DigitalOcean, LLC - 510
Akamai Technologies, Inc. - 90
Vietnam Internet Network Information Center - 42Top Clients:
Unknown - 756Top Software:
Unknown - 756Top Keyboards:
Unknown - 756Top IP Classification:
hosting - 684
Unknown - 48
proxy - 18Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-18 RDP #Honeypot IOCs - 756 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
134.209.180.117 - 510
104.64.217.122 - 87
118.69.191.219 - 42Top ASNs:
AS14061 - 510
AS63949 - 90
AS18403 - 42Top Accounts:
hello - 642
Administr - 18
ident - 18Top ISPs:
DigitalOcean, LLC - 510
Akamai Technologies, Inc. - 90
Vietnam Internet Network Information Center - 42Top Clients:
Unknown - 756Top Software:
Unknown - 756Top Keyboards:
Unknown - 756Top IP Classification:
hosting - 684
Unknown - 48
proxy - 18Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-18 RDP #Honeypot IOCs - 504 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
134.209.180.117 - 340
104.64.217.122 - 58
118.69.191.219 - 28Top ASNs:
AS14061 - 340
AS63949 - 60
AS18403 - 28Top Accounts:
hello - 428
Administr - 12
ident - 12Top ISPs:
DigitalOcean, LLC - 340
Akamai Technologies, Inc. - 60
Vietnam Internet Network Information Center - 28Top Clients:
Unknown - 504Top Software:
Unknown - 504Top Keyboards:
Unknown - 504Top IP Classification:
hosting - 456
Unknown - 32
proxy - 12Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-18 RDP #Honeypot IOCs - 504 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
134.209.180.117 - 340
104.64.217.122 - 58
118.69.191.219 - 28Top ASNs:
AS14061 - 340
AS63949 - 60
AS18403 - 28Top Accounts:
hello - 428
Administr - 12
ident - 12Top ISPs:
DigitalOcean, LLC - 340
Akamai Technologies, Inc. - 60
Vietnam Internet Network Information Center - 28Top Clients:
Unknown - 504Top Software:
Unknown - 504Top Keyboards:
Unknown - 504Top IP Classification:
hosting - 456
Unknown - 32
proxy - 12Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-18 RDP #Honeypot IOCs - 504 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
134.209.180.117 - 340
104.64.217.122 - 58
118.69.191.219 - 28Top ASNs:
AS14061 - 340
AS63949 - 60
AS18403 - 28Top Accounts:
hello - 428
Administr - 12
ident - 12Top ISPs:
DigitalOcean, LLC - 340
Akamai Technologies, Inc. - 60
Vietnam Internet Network Information Center - 28Top Clients:
Unknown - 504Top Software:
Unknown - 504Top Keyboards:
Unknown - 504Top IP Classification:
hosting - 456
Unknown - 32
proxy - 12Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-18 RDP #Honeypot IOCs - 504 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
134.209.180.117 - 340
104.64.217.122 - 58
118.69.191.219 - 28Top ASNs:
AS14061 - 340
AS63949 - 60
AS18403 - 28Top Accounts:
hello - 428
Administr - 12
ident - 12Top ISPs:
DigitalOcean, LLC - 340
Akamai Technologies, Inc. - 60
Vietnam Internet Network Information Center - 28Top Clients:
Unknown - 504Top Software:
Unknown - 504Top Keyboards:
Unknown - 504Top IP Classification:
hosting - 456
Unknown - 32
proxy - 12Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-18 RDP #Honeypot IOCs - 252 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
134.209.180.117 - 170
104.64.217.122 - 29
118.69.191.219 - 14Top ASNs:
AS14061 - 170
AS63949 - 30
AS18403 - 14Top Accounts:
hello - 214
Administr - 6
ident - 6Top ISPs:
DigitalOcean, LLC - 170
Akamai Technologies, Inc. - 30
Vietnam Internet Network Information Center - 14Top Clients:
Unknown - 252Top Software:
Unknown - 252Top Keyboards:
Unknown - 252Top IP Classification:
hosting - 228
Unknown - 16
proxy - 6Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-18 RDP #Honeypot IOCs - 252 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
134.209.180.117 - 170
104.64.217.122 - 29
118.69.191.219 - 14Top ASNs:
AS14061 - 170
AS63949 - 30
AS18403 - 14Top Accounts:
hello - 214
Administr - 6
ident - 6Top ISPs:
DigitalOcean, LLC - 170
Akamai Technologies, Inc. - 30
Vietnam Internet Network Information Center - 14Top Clients:
Unknown - 252Top Software:
Unknown - 252Top Keyboards:
Unknown - 252Top IP Classification:
hosting - 228
Unknown - 16
proxy - 6Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-18 RDP #Honeypot IOCs - 252 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
134.209.180.117 - 170
104.64.217.122 - 29
118.69.191.219 - 14Top ASNs:
AS14061 - 170
AS63949 - 30
AS18403 - 14Top Accounts:
hello - 214
Administr - 6
ident - 6Top ISPs:
DigitalOcean, LLC - 170
Akamai Technologies, Inc. - 30
Vietnam Internet Network Information Center - 14Top Clients:
Unknown - 252Top Software:
Unknown - 252Top Keyboards:
Unknown - 252Top IP Classification:
hosting - 228
Unknown - 16
proxy - 6Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-18 RDP #Honeypot IOCs - 252 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
134.209.180.117 - 170
104.64.217.122 - 29
118.69.191.219 - 14Top ASNs:
AS14061 - 170
AS63949 - 30
AS18403 - 14Top Accounts:
hello - 214
Administr - 6
ident - 6Top ISPs:
DigitalOcean, LLC - 170
Akamai Technologies, Inc. - 30
Vietnam Internet Network Information Center - 14Top Clients:
Unknown - 252Top Software:
Unknown - 252Top Keyboards:
Unknown - 252Top IP Classification:
hosting - 228
Unknown - 16
proxy - 6Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-17 RDP #Honeypot IOCs - 5520 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
147.182.250.28 - 4791
134.209.180.117 - 462
104.64.217.122 - 30Top ASNs:
AS14061 - 5268
AS63949 - 81
AS396982 - 27Top Accounts:
hello - 5367
142.93.8.59 - 30
Administr - 30Top ISPs:
DigitalOcean, LLC - 5268
Akamai Technologies, Inc. - 81
Google LLC - 27Top Clients:
Unknown - 5520Top Software:
Unknown - 5520Top Keyboards:
Unknown - 5520Top IP Classification:
hosting - 5418
Unknown - 69
proxy - 18Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-17 RDP #Honeypot IOCs - 5520 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
147.182.250.28 - 4791
134.209.180.117 - 462
104.64.217.122 - 30Top ASNs:
AS14061 - 5268
AS63949 - 81
AS396982 - 27Top Accounts:
hello - 5367
142.93.8.59 - 30
Administr - 30Top ISPs:
DigitalOcean, LLC - 5268
Akamai Technologies, Inc. - 81
Google LLC - 27Top Clients:
Unknown - 5520Top Software:
Unknown - 5520Top Keyboards:
Unknown - 5520Top IP Classification:
hosting - 5418
Unknown - 69
proxy - 18Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-17 RDP #Honeypot IOCs - 5520 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
147.182.250.28 - 4791
134.209.180.117 - 462
104.64.217.122 - 30Top ASNs:
AS14061 - 5268
AS63949 - 81
AS396982 - 27Top Accounts:
hello - 5367
142.93.8.59 - 30
Administr - 30Top ISPs:
DigitalOcean, LLC - 5268
Akamai Technologies, Inc. - 81
Google LLC - 27Top Clients:
Unknown - 5520Top Software:
Unknown - 5520Top Keyboards:
Unknown - 5520Top IP Classification:
hosting - 5418
Unknown - 69
proxy - 18Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-17 RDP #Honeypot IOCs - 5520 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
147.182.250.28 - 4791
134.209.180.117 - 462
104.64.217.122 - 30Top ASNs:
AS14061 - 5268
AS63949 - 81
AS396982 - 27Top Accounts:
hello - 5367
142.93.8.59 - 30
Administr - 30Top ISPs:
DigitalOcean, LLC - 5268
Akamai Technologies, Inc. - 81
Google LLC - 27Top Clients:
Unknown - 5520Top Software:
Unknown - 5520Top Keyboards:
Unknown - 5520Top IP Classification:
hosting - 5418
Unknown - 69
proxy - 18Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-17 RDP #Honeypot IOCs - 3680 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
147.182.250.28 - 3194
134.209.180.117 - 308
104.64.217.122 - 20Top ASNs:
AS14061 - 3512
AS63949 - 54
AS396982 - 18Top Accounts:
hello - 3578
142.93.8.59 - 20
Administr - 20Top ISPs:
DigitalOcean, LLC - 3512
Akamai Technologies, Inc. - 54
Google LLC - 18Top Clients:
Unknown - 3680Top Software:
Unknown - 3680Top Keyboards:
Unknown - 3680Top IP Classification:
hosting - 3612
Unknown - 46
proxy - 12Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-17 RDP #Honeypot IOCs - 3680 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
147.182.250.28 - 3194
134.209.180.117 - 308
104.64.217.122 - 20Top ASNs:
AS14061 - 3512
AS63949 - 54
AS396982 - 18Top Accounts:
hello - 3578
142.93.8.59 - 20
Administr - 20Top ISPs:
DigitalOcean, LLC - 3512
Akamai Technologies, Inc. - 54
Google LLC - 18Top Clients:
Unknown - 3680Top Software:
Unknown - 3680Top Keyboards:
Unknown - 3680Top IP Classification:
hosting - 3612
Unknown - 46
proxy - 12Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-17 RDP #Honeypot IOCs - 3680 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
147.182.250.28 - 3194
134.209.180.117 - 308
104.64.217.122 - 20Top ASNs:
AS14061 - 3512
AS63949 - 54
AS396982 - 18Top Accounts:
hello - 3578
142.93.8.59 - 20
Administr - 20Top ISPs:
DigitalOcean, LLC - 3512
Akamai Technologies, Inc. - 54
Google LLC - 18Top Clients:
Unknown - 3680Top Software:
Unknown - 3680Top Keyboards:
Unknown - 3680Top IP Classification:
hosting - 3612
Unknown - 46
proxy - 12Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-17 RDP #Honeypot IOCs - 3680 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
147.182.250.28 - 3194
134.209.180.117 - 308
104.64.217.122 - 20Top ASNs:
AS14061 - 3512
AS63949 - 54
AS396982 - 18Top Accounts:
hello - 3578
142.93.8.59 - 20
Administr - 20Top ISPs:
DigitalOcean, LLC - 3512
Akamai Technologies, Inc. - 54
Google LLC - 18Top Clients:
Unknown - 3680Top Software:
Unknown - 3680Top Keyboards:
Unknown - 3680Top IP Classification:
hosting - 3612
Unknown - 46
proxy - 12Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-17 RDP #Honeypot IOCs - 1840 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
147.182.250.28 - 1597
134.209.180.117 - 154
104.64.217.122 - 10Top ASNs:
AS14061 - 1756
AS63949 - 27
AS396982 - 9Top Accounts:
hello - 1789
142.93.8.59 - 10
Administr - 10Top ISPs:
DigitalOcean, LLC - 1756
Akamai Technologies, Inc. - 27
Google LLC - 9Top Clients:
Unknown - 1840Top Software:
Unknown - 1840Top Keyboards:
Unknown - 1840Top IP Classification:
hosting - 1806
Unknown - 23
proxy - 6Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-17 RDP #Honeypot IOCs - 1840 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
147.182.250.28 - 1597
134.209.180.117 - 154
104.64.217.122 - 10Top ASNs:
AS14061 - 1756
AS63949 - 27
AS396982 - 9Top Accounts:
hello - 1789
142.93.8.59 - 10
Administr - 10Top ISPs:
DigitalOcean, LLC - 1756
Akamai Technologies, Inc. - 27
Google LLC - 9Top Clients:
Unknown - 1840Top Software:
Unknown - 1840Top Keyboards:
Unknown - 1840Top IP Classification:
hosting - 1806
Unknown - 23
proxy - 6Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-17 RDP #Honeypot IOCs - 1840 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
147.182.250.28 - 1597
134.209.180.117 - 154
104.64.217.122 - 10Top ASNs:
AS14061 - 1756
AS63949 - 27
AS396982 - 9Top Accounts:
hello - 1789
142.93.8.59 - 10
Administr - 10Top ISPs:
DigitalOcean, LLC - 1756
Akamai Technologies, Inc. - 27
Google LLC - 9Top Clients:
Unknown - 1840Top Software:
Unknown - 1840Top Keyboards:
Unknown - 1840Top IP Classification:
hosting - 1806
Unknown - 23
proxy - 6Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-17 RDP #Honeypot IOCs - 1840 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
147.182.250.28 - 1597
134.209.180.117 - 154
104.64.217.122 - 10Top ASNs:
AS14061 - 1756
AS63949 - 27
AS396982 - 9Top Accounts:
hello - 1789
142.93.8.59 - 10
Administr - 10Top ISPs:
DigitalOcean, LLC - 1756
Akamai Technologies, Inc. - 27
Google LLC - 9Top Clients:
Unknown - 1840Top Software:
Unknown - 1840Top Keyboards:
Unknown - 1840Top IP Classification:
hosting - 1806
Unknown - 23
proxy - 6Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
Mini Blue Team Diaries story:
There was a break-in over the weekend at one of our US offices. We occupied one floor of a shared office building, and two crooks managed to get in by going to an open floor above ours and breaking a lock on the fire escape.
Rather brilliantly, a building security guard was doing rounds and actually caught the pair stuffing iPads from conference rooms into a rucksack. However, when challenged they claimed to be employees and were left alone.
Anyway they ended up with about a half dozen iPads from Zoom rooms. Annoying but not the end of the world.
Those iPads were clearly sold on, as they were connected to an MDM server and started to pop up in locations all over the city over the course of the next week.
One of them was especially interesting. Because it was connected to our MDM Apple ID, it was syncing files to iCloud. This included photos. We noticed a lot of selfies of one particular dude show up. The dude looked a lot like one of the guys who we’d seen in our office on our security cameras. Yup.
We of course passed on all the information, including the location of the selfie generating iPad, to law enforcement.
I wish there was a more interesting ending - but they never followed up on the lead, of course. So the iPads lived on, slowly filling up with various photos and memories from the crook and the people they’d been sold on to.
Read more, slightly less mini stories, at infosecdiaries.com
-
Mini Blue Team Diaries story:
There was a break-in over the weekend at one of our US offices. We occupied one floor of a shared office building, and two crooks managed to get in by going to an open floor above ours and breaking a lock on the fire escape.
Rather brilliantly, a building security guard was doing rounds and actually caught the pair stuffing iPads from conference rooms into a rucksack. However, when challenged they claimed to be employees and were left alone.
Anyway they ended up with about a half dozen iPads from Zoom rooms. Annoying but not the end of the world.
Those iPads were clearly sold on, as they were connected to an MDM server and started to pop up in locations all over the city over the course of the next week.
One of them was especially interesting. Because it was connected to our MDM Apple ID, it was syncing files to iCloud. This included photos. We noticed a lot of selfies of one particular dude show up. The dude looked a lot like one of the guys who we’d seen in our office on our security cameras. Yup.
We of course passed on all the information, including the location of the selfie generating iPad, to law enforcement.
I wish there was a more interesting ending - but they never followed up on the lead, of course. So the iPads lived on, slowly filling up with various photos and memories from the crook and the people they’d been sold on to.
Read more, slightly less mini stories, at infosecdiaries.com
-
Mini Blue Team Diaries story:
There was a break-in over the weekend at one of our US offices. We occupied one floor of a shared office building, and two crooks managed to get in by going to an open floor above ours and breaking a lock on the fire escape.
Rather brilliantly, a building security guard was doing rounds and actually caught the pair stuffing iPads from conference rooms into a rucksack. However, when challenged they claimed to be employees and were left alone.
Anyway they ended up with about a half dozen iPads from Zoom rooms. Annoying but not the end of the world.
Those iPads were clearly sold on, as they were connected to an MDM server and started to pop up in locations all over the city over the course of the next week.
One of them was especially interesting. Because it was connected to our MDM Apple ID, it was syncing files to iCloud. This included photos. We noticed a lot of selfies of one particular dude show up. The dude looked a lot like one of the guys who we’d seen in our office on our security cameras. Yup.
We of course passed on all the information, including the location of the selfie generating iPad, to law enforcement.
I wish there was a more interesting ending - but they never followed up on the lead, of course. So the iPads lived on, slowly filling up with various photos and memories from the crook and the people they’d been sold on to.
Read more, slightly less mini stories, at infosecdiaries.com
-
Mini Blue Team Diaries story:
There was a break-in over the weekend at one of our US offices. We occupied one floor of a shared office building, and two crooks managed to get in by going to an open floor above ours and breaking a lock on the fire escape.
Rather brilliantly, a building security guard was doing rounds and actually caught the pair stuffing iPads from conference rooms into a rucksack. However, when challenged they claimed to be employees and were left alone.
Anyway they ended up with about a half dozen iPads from Zoom rooms. Annoying but not the end of the world.
Those iPads were clearly sold on, as they were connected to an MDM server and started to pop up in locations all over the city over the course of the next week.
One of them was especially interesting. Because it was connected to our MDM Apple ID, it was syncing files to iCloud. This included photos. We noticed a lot of selfies of one particular dude show up. The dude looked a lot like one of the guys who we’d seen in our office on our security cameras. Yup.
We of course passed on all the information, including the location of the selfie generating iPad, to law enforcement.
I wish there was a more interesting ending - but they never followed up on the lead, of course. So the iPads lived on, slowly filling up with various photos and memories from the crook and the people they’d been sold on to.
Read more, slightly less mini stories, at infosecdiaries.com
-
Mini Blue Team Diaries story:
There was a break-in over the weekend at one of our US offices. We occupied one floor of a shared office building, and two crooks managed to get in by going to an open floor above ours and breaking a lock on the fire escape.
Rather brilliantly, a building security guard was doing rounds and actually caught the pair stuffing iPads from conference rooms into a rucksack. However, when challenged they claimed to be employees and were left alone.
Anyway they ended up with about a half dozen iPads from Zoom rooms. Annoying but not the end of the world.
Those iPads were clearly sold on, as they were connected to an MDM server and started to pop up in locations all over the city over the course of the next week.
One of them was especially interesting. Because it was connected to our MDM Apple ID, it was syncing files to iCloud. This included photos. We noticed a lot of selfies of one particular dude show up. The dude looked a lot like one of the guys who we’d seen in our office on our security cameras. Yup.
We of course passed on all the information, including the location of the selfie generating iPad, to law enforcement.
I wish there was a more interesting ending - but they never followed up on the lead, of course. So the iPads lived on, slowly filling up with various photos and memories from the crook and the people they’d been sold on to.
Read more, slightly less mini stories, at infosecdiaries.com
-
Mini Blue Team Diaries story:
There was a break in over the weekend at one of our US offices. We occupied one floor of a shared office building, and two crooks managed to get in by going to an open floor above ours and breaking a lock on the fire escape.
Rather brilliantly, a building security guard was doing rounds and actually caught the pair stuffing iPads from conference rooms into a rucksack, however, when challenged they claimed to be employees and were left alone.
Anyway they ended up with about a half dozen iPads from Zoom rooms. Annoying but not the end of the world.
Those iPads were clearly sold on, as they were connected to MDM and started to pop up in locations all over the city over the course of the next week.
One of them was especially interesting. Because it was connected to our MDM Apple ID, it was syncing files to iCloud. This included photos. We noticed a lot of selfies of one particular dude show up. The dude looked a lot like one of the guys who we’d seen in our office on our security cameras. Yup.
We of course passed on all the information, including the location of the selfie generating iPad, to law enforcement.
I wish there was a more interesting ending - but they never followed up on the lead, of course. So the iPads lived on, slowly filling up with various photos and memories from the crook and the people they’d been sold on to. We could’ve locked them or bricked them, but this was more fun.
Read more, slightly less mini stories, at https://infosecdiaries.com
-
Mini Blue Team Diaries story:
There was a break in over the weekend at one of our US offices. We occupied one floor of a shared office building, and two crooks managed to get in by going to an open floor above ours and breaking a lock on the fire escape.
Rather brilliantly, a building security guard was doing rounds and actually caught the pair stuffing iPads from conference rooms into a rucksack, however, when challenged they claimed to be employees and were left alone.
Anyway they ended up with about a half dozen iPads from Zoom rooms. Annoying but not the end of the world.
Those iPads were clearly sold on, as they were connected to MDM and started to pop up in locations all over the city over the course of the next week.
One of them was especially interesting. Because it was connected to our MDM Apple ID, it was syncing files to iCloud. This included photos. We noticed a lot of selfies of one particular dude show up. The dude looked a lot like one of the guys who we’d seen in our office on our security cameras. Yup.
We of course passed on all the information, including the location of the selfie generating iPad, to law enforcement.
I wish there was a more interesting ending - but they never followed up on the lead, of course. So the iPads lived on, slowly filling up with various photos and memories from the crook and the people they’d been sold on to. We could’ve locked them or bricked them, but this was more fun.
Read more, slightly less mini stories, at https://infosecdiaries.com
-
Mini Blue Team Diaries story:
There was a break in over the weekend at one of our US offices. We occupied one floor of a shared office building, and two crooks managed to get in by going to an open floor above ours and breaking a lock on the fire escape.
Rather brilliantly, a building security guard was doing rounds and actually caught the pair stuffing iPads from conference rooms into a rucksack, however, when challenged they claimed to be employees and were left alone.
Anyway they ended up with about a half dozen iPads from Zoom rooms. Annoying but not the end of the world.
Those iPads were clearly sold on, as they were connected to MDM and started to pop up in locations all over the city over the course of the next week.
One of them was especially interesting. Because it was connected to our MDM Apple ID, it was syncing files to iCloud. This included photos. We noticed a lot of selfies of one particular dude show up. The dude looked a lot like one of the guys who we’d seen in our office on our security cameras. Yup.
We of course passed on all the information, including the location of the selfie generating iPad, to law enforcement.
I wish there was a more interesting ending - but they never followed up on the lead, of course. So the iPads lived on, slowly filling up with various photos and memories from the crook and the people they’d been sold on to. We could’ve locked them or bricked them, but this was more fun.
Read more, slightly less mini stories, at https://infosecdiaries.com
-
Mini Blue Team Diaries story:
There was a break in over the weekend at one of our US offices. We occupied one floor of a shared office building, and two crooks managed to get in by going to an open floor above ours and breaking a lock on the fire escape.
Rather brilliantly, a building security guard was doing rounds and actually caught the pair stuffing iPads from conference rooms into a rucksack, however, when challenged they claimed to be employees and were left alone.
Anyway they ended up with about a half dozen iPads from Zoom rooms. Annoying but not the end of the world.
Those iPads were clearly sold on, as they were connected to MDM and started to pop up in locations all over the city over the course of the next week.
One of them was especially interesting. Because it was connected to our MDM Apple ID, it was syncing files to iCloud. This included photos. We noticed a lot of selfies of one particular dude show up. The dude looked a lot like one of the guys who we’d seen in our office on our security cameras. Yup.
We of course passed on all the information, including the location of the selfie generating iPad, to law enforcement.
I wish there was a more interesting ending - but they never followed up on the lead, of course. So the iPads lived on, slowly filling up with various photos and memories from the crook and the people they’d been sold on to. We could’ve locked them or bricked them, but this was more fun.
Read more, slightly less mini stories, at https://infosecdiaries.com
-
Mini Blue Team Diaries story:
There was a break in over the weekend at one of our US offices. We occupied one floor of a shared office building, and two crooks managed to get in by going to an open floor above ours and breaking a lock on the fire escape.
Rather brilliantly, a building security guard was doing rounds and actually caught the pair stuffing iPads from conference rooms into a rucksack, however, when challenged they claimed to be employees and were left alone.
Anyway they ended up with about a half dozen iPads from Zoom rooms. Annoying but not the end of the world.
Those iPads were clearly sold on, as they were connected to MDM and started to pop up in locations all over the city over the course of the next week.
One of them was especially interesting. Because it was connected to our MDM Apple ID, it was syncing files to iCloud. This included photos. We noticed a lot of selfies of one particular dude show up. The dude looked a lot like one of the guys who we’d seen in our office on our security cameras. Yup.
We of course passed on all the information, including the location of the selfie generating iPad, to law enforcement.
I wish there was a more interesting ending - but they never followed up on the lead, of course. So the iPads lived on, slowly filling up with various photos and memories from the crook and the people they’d been sold on to. We could’ve locked them or bricked them, but this was more fun.
Read more, slightly less mini stories, at https://infosecdiaries.com