home.social

#blueteam — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #blueteam, aggregated by home.social.

  1. 2026-09-05 RDP #Honeypot IOCs - 2556 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    141.11.96.210 - 2409
    103.178.235.50 - 27
    217.160.240.135 - 27

    Top ASNs:
    Unknown - 2409
    AS396982 - 48
    AS140810 - 27

    Top Accounts:
    hello - 2469
    Administr - 12
    0siivpyz - 12

    Top ISPs:
    Private Customer - 2409
    Google LLC - 48
    VPSTTT - 27

    Top Clients:
    Unknown - 2556

    Top Software:
    Unknown - 2556

    Top Keyboards:
    Unknown - 2556

    Top IP Classification:
    proxy - 2409
    hosting - 99
    hosting & proxy - 39

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  2. 2026-09-05 RDP #Honeypot IOCs - 2556 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    141.11.96.210 - 2409
    103.178.235.50 - 27
    217.160.240.135 - 27

    Top ASNs:
    Unknown - 2409
    AS396982 - 48
    AS140810 - 27

    Top Accounts:
    hello - 2469
    Administr - 12
    0siivpyz - 12

    Top ISPs:
    Private Customer - 2409
    Google LLC - 48
    VPSTTT - 27

    Top Clients:
    Unknown - 2556

    Top Software:
    Unknown - 2556

    Top Keyboards:
    Unknown - 2556

    Top IP Classification:
    proxy - 2409
    hosting - 99
    hosting & proxy - 39

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  3. 2026-09-05 RDP #Honeypot IOCs - 2556 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    141.11.96.210 - 2409
    103.178.235.50 - 27
    217.160.240.135 - 27

    Top ASNs:
    Unknown - 2409
    AS396982 - 48
    AS140810 - 27

    Top Accounts:
    hello - 2469
    Administr - 12
    0siivpyz - 12

    Top ISPs:
    Private Customer - 2409
    Google LLC - 48
    VPSTTT - 27

    Top Clients:
    Unknown - 2556

    Top Software:
    Unknown - 2556

    Top Keyboards:
    Unknown - 2556

    Top IP Classification:
    proxy - 2409
    hosting - 99
    hosting & proxy - 39

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  4. 2026-09-05 RDP #Honeypot IOCs - 2556 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    141.11.96.210 - 2409
    103.178.235.50 - 27
    217.160.240.135 - 27

    Top ASNs:
    Unknown - 2409
    AS396982 - 48
    AS140810 - 27

    Top Accounts:
    hello - 2469
    Administr - 12
    0siivpyz - 12

    Top ISPs:
    Private Customer - 2409
    Google LLC - 48
    VPSTTT - 27

    Top Clients:
    Unknown - 2556

    Top Software:
    Unknown - 2556

    Top Keyboards:
    Unknown - 2556

    Top IP Classification:
    proxy - 2409
    hosting - 99
    hosting & proxy - 39

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  5. 2026-09-05 RDP #Honeypot IOCs - 1704 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    141.11.96.210 - 1606
    103.178.235.50 - 18
    217.160.240.135 - 18

    Top ASNs:
    Unknown - 1606
    AS396982 - 32
    AS140810 - 18

    Top Accounts:
    hello - 1646
    Administr - 8
    0siivpyz - 8

    Top ISPs:
    Private Customer - 1606
    Google LLC - 32
    VPSTTT - 18

    Top Clients:
    Unknown - 1704

    Top Software:
    Unknown - 1704

    Top Keyboards:
    Unknown - 1704

    Top IP Classification:
    proxy - 1606
    hosting - 66
    hosting & proxy - 26

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  6. 2026-09-05 RDP #Honeypot IOCs - 1704 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    141.11.96.210 - 1606
    103.178.235.50 - 18
    217.160.240.135 - 18

    Top ASNs:
    Unknown - 1606
    AS396982 - 32
    AS140810 - 18

    Top Accounts:
    hello - 1646
    Administr - 8
    0siivpyz - 8

    Top ISPs:
    Private Customer - 1606
    Google LLC - 32
    VPSTTT - 18

    Top Clients:
    Unknown - 1704

    Top Software:
    Unknown - 1704

    Top Keyboards:
    Unknown - 1704

    Top IP Classification:
    proxy - 1606
    hosting - 66
    hosting & proxy - 26

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  7. 2026-09-05 RDP #Honeypot IOCs - 1704 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    141.11.96.210 - 1606
    103.178.235.50 - 18
    217.160.240.135 - 18

    Top ASNs:
    Unknown - 1606
    AS396982 - 32
    AS140810 - 18

    Top Accounts:
    hello - 1646
    Administr - 8
    0siivpyz - 8

    Top ISPs:
    Private Customer - 1606
    Google LLC - 32
    VPSTTT - 18

    Top Clients:
    Unknown - 1704

    Top Software:
    Unknown - 1704

    Top Keyboards:
    Unknown - 1704

    Top IP Classification:
    proxy - 1606
    hosting - 66
    hosting & proxy - 26

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  8. 2026-09-05 RDP #Honeypot IOCs - 1704 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    141.11.96.210 - 1606
    103.178.235.50 - 18
    217.160.240.135 - 18

    Top ASNs:
    Unknown - 1606
    AS396982 - 32
    AS140810 - 18

    Top Accounts:
    hello - 1646
    Administr - 8
    0siivpyz - 8

    Top ISPs:
    Private Customer - 1606
    Google LLC - 32
    VPSTTT - 18

    Top Clients:
    Unknown - 1704

    Top Software:
    Unknown - 1704

    Top Keyboards:
    Unknown - 1704

    Top IP Classification:
    proxy - 1606
    hosting - 66
    hosting & proxy - 26

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  9. 2026-09-05 RDP #Honeypot IOCs - 852 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    141.11.96.210 - 803
    103.178.235.50 - 9
    217.160.240.135 - 9

    Top ASNs:
    Unknown - 803
    AS396982 - 16
    AS140810 - 9

    Top Accounts:
    hello - 823
    Administr - 4
    0siivpyz - 4

    Top ISPs:
    Private Customer - 803
    Google LLC - 16
    VPSTTT - 9

    Top Clients:
    Unknown - 852

    Top Software:
    Unknown - 852

    Top Keyboards:
    Unknown - 852

    Top IP Classification:
    proxy - 803
    hosting - 33
    hosting & proxy - 13

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  10. 2026-09-05 RDP #Honeypot IOCs - 852 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    141.11.96.210 - 803
    103.178.235.50 - 9
    217.160.240.135 - 9

    Top ASNs:
    Unknown - 803
    AS396982 - 16
    AS140810 - 9

    Top Accounts:
    hello - 823
    Administr - 4
    0siivpyz - 4

    Top ISPs:
    Private Customer - 803
    Google LLC - 16
    VPSTTT - 9

    Top Clients:
    Unknown - 852

    Top Software:
    Unknown - 852

    Top Keyboards:
    Unknown - 852

    Top IP Classification:
    proxy - 803
    hosting - 33
    hosting & proxy - 13

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  11. 2026-09-05 RDP #Honeypot IOCs - 852 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    141.11.96.210 - 803
    103.178.235.50 - 9
    217.160.240.135 - 9

    Top ASNs:
    Unknown - 803
    AS396982 - 16
    AS140810 - 9

    Top Accounts:
    hello - 823
    Administr - 4
    0siivpyz - 4

    Top ISPs:
    Private Customer - 803
    Google LLC - 16
    VPSTTT - 9

    Top Clients:
    Unknown - 852

    Top Software:
    Unknown - 852

    Top Keyboards:
    Unknown - 852

    Top IP Classification:
    proxy - 803
    hosting - 33
    hosting & proxy - 13

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  12. 2026-09-05 RDP #Honeypot IOCs - 852 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    141.11.96.210 - 803
    103.178.235.50 - 9
    217.160.240.135 - 9

    Top ASNs:
    Unknown - 803
    AS396982 - 16
    AS140810 - 9

    Top Accounts:
    hello - 823
    Administr - 4
    0siivpyz - 4

    Top ISPs:
    Private Customer - 803
    Google LLC - 16
    VPSTTT - 9

    Top Clients:
    Unknown - 852

    Top Software:
    Unknown - 852

    Top Keyboards:
    Unknown - 852

    Top IP Classification:
    proxy - 803
    hosting - 33
    hosting & proxy - 13

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  13. SOC-Analyst Lern- & Praxishandbuch

    Ich habe mir in den letzten Wochen ein eigenes SOC-Analyst Lern- & Praxishandbuch erstellt.

    Gedacht ist es vor allem für Einsteiger, Interessierte und alle, die sich einen strukturierten Überblick über Security Operations und SOC verschaffen möchten.

    Enthalten sind unter anderem Themen wie Netzwerke, SIEM, EDR/XDR, Threat Intelligence, Incident Response, Detection Engineering, Cloud Security, Malware-Analyse, Forensik sowie praktische Lernpfade und Tool-Empfehlungen.

    Für mich war wichtig, Theorie und Praxis möglichst verständlich zusammenzubringen und gleichzeitig zu zeigen, was man als angehender SOC Analyst wirklich lernen und üben sollte.

    Download: SOC-Analyst – Das umfassende Lern- & Praxishandbuch:

    🔗 app.filen.io/#/d/7b65fb81-b0fc

    :boost_ok:

    #CyberSecurity #SOC #BlueTeam #SecurityOperations #ITSecurity

  14. SOC-Analyst Lern- & Praxishandbuch

    Ich habe mir in den letzten Wochen ein eigenes SOC-Analyst Lern- & Praxishandbuch erstellt.

    Gedacht ist es vor allem für Einsteiger, Interessierte und alle, die sich einen strukturierten Überblick über Security Operations und SOC verschaffen möchten.

    Enthalten sind unter anderem Themen wie Netzwerke, SIEM, EDR/XDR, Threat Intelligence, Incident Response, Detection Engineering, Cloud Security, Malware-Analyse, Forensik sowie praktische Lernpfade und Tool-Empfehlungen.

    Für mich war wichtig, Theorie und Praxis möglichst verständlich zusammenzubringen und gleichzeitig zu zeigen, was man als angehender SOC Analyst wirklich lernen und üben sollte.

    Download: SOC-Analyst – Das umfassende Lern- & Praxishandbuch:

    🔗 app.filen.io/#/d/7b65fb81-b0fc

    :boost_ok:

    #CyberSecurity #SOC #BlueTeam #SecurityOperations #ITSecurity

  15. SOC-Analyst Lern- & Praxishandbuch

    Ich habe mir in den letzten Wochen ein eigenes SOC-Analyst Lern- & Praxishandbuch erstellt.

    Gedacht ist es vor allem für Einsteiger, Interessierte und alle, die sich einen strukturierten Überblick über Security Operations und SOC verschaffen möchten.

    Enthalten sind unter anderem Themen wie Netzwerke, SIEM, EDR/XDR, Threat Intelligence, Incident Response, Detection Engineering, Cloud Security, Malware-Analyse, Forensik sowie praktische Lernpfade und Tool-Empfehlungen.

    Für mich war wichtig, Theorie und Praxis möglichst verständlich zusammenzubringen und gleichzeitig zu zeigen, was man als angehender SOC Analyst wirklich lernen und üben sollte.

    Download: SOC-Analyst – Das umfassende Lern- & Praxishandbuch:

    🔗 app.filen.io/#/d/7b65fb81-b0fc

    :boost_ok:

    #CyberSecurity #SOC #BlueTeam #SecurityOperations #ITSecurity

  16. SOC-Analyst Lern- & Praxishandbuch

    Ich habe mir in den letzten Wochen ein eigenes SOC-Analyst Lern- & Praxishandbuch erstellt.

    Gedacht ist es vor allem für Einsteiger, Interessierte und alle, die sich einen strukturierten Überblick über Security Operations und SOC verschaffen möchten.

    Enthalten sind unter anderem Themen wie Netzwerke, SIEM, EDR/XDR, Threat Intelligence, Incident Response, Detection Engineering, Cloud Security, Malware-Analyse, Forensik sowie praktische Lernpfade und Tool-Empfehlungen.

    Für mich war wichtig, Theorie und Praxis möglichst verständlich zusammenzubringen und gleichzeitig zu zeigen, was man als angehender SOC Analyst wirklich lernen und üben sollte.

    Download: SOC-Analyst – Das umfassende Lern- & Praxishandbuch:

    🔗 app.filen.io/#/d/7b65fb81-b0fc

    :boost_ok:

    #CyberSecurity #SOC #BlueTeam #SecurityOperations #ITSecurity

  17. SOC-Analyst Lern- & Praxishandbuch

    Ich habe mir in den letzten Wochen ein eigenes SOC-Analyst Lern- & Praxishandbuch erstellt.

    Gedacht ist es vor allem für Einsteiger, Interessierte und alle, die sich einen strukturierten Überblick über Security Operations und SOC verschaffen möchten.

    Enthalten sind unter anderem Themen wie Netzwerke, SIEM, EDR/XDR, Threat Intelligence, Incident Response, Detection Engineering, Cloud Security, Malware-Analyse, Forensik sowie praktische Lernpfade und Tool-Empfehlungen.

    Für mich war wichtig, Theorie und Praxis möglichst verständlich zusammenzubringen und gleichzeitig zu zeigen, was man als angehender SOC Analyst wirklich lernen und üben sollte.

    Download: SOC-Analyst – Das umfassende Lern- & Praxishandbuch:

    🔗 app.filen.io/#/d/7b65fb81-b0fc

    :boost_ok:

    #CyberSecurity #SOC #BlueTeam #SecurityOperations #ITSecurity

  18. Ich habe mir in den letzten Wochen ein eigenes SOC-Analyst Lern- & Praxishandbuch erstellt.

    Gedacht ist es vor allem für Einsteiger, Interessierte und alle, die sich einen strukturierten Überblick über Security Operations und SOC verschaffen möchten.

    Enthalten sind unter anderem Themen wie Netzwerke, SIEM, EDR/XDR, Threat Intelligence, Incident Response, Detection Engineering, Cloud Security, Malware-Analyse, Forensik sowie praktische Lernpfade und Tool-Empfehlungen.

    Für mich war wichtig, Theorie und Praxis möglichst verständlich zusammenzubringen und gleichzeitig zu zeigen, was man als angehender SOC Analyst wirklich lernen und üben sollte.

    Download: SOC-Analyst – Das umfassende Lern- & Praxishandbuch:

    🔗 app.filen.io/#/d/7b65fb81-b0fc

    :boost_ok:

    #CyberSecurity #SOC #BlueTeam #SecurityOperations #ITSecurity

  19. Empty scoreboard.
    80 teams.
    14 days.

    Someone's name goes first.

    WATCHLIST is a free 24-hour CTF built around one investigation.

    24 challenges - memory forensics,
    disk forensics, DNS exfil, ADSB analysis, live SSH honeypot.

    All connected to the same case.

    First blood on each challenge gets logged permanently
    by The Machine.

    Sep 19 03:30 UTC. Free entry. Teams 1-6.
    Prizes: $750 / $500 / $250

    ctf.xposedornot.com
    CTFtime: ctftime.org/event/3326

    #CTF #DFIR #forensics #infosec #blueteam

  20. Empty scoreboard.
    80 teams.
    14 days.

    Someone's name goes first.

    WATCHLIST is a free 24-hour CTF built around one investigation.

    24 challenges - memory forensics,
    disk forensics, DNS exfil, ADSB analysis, live SSH honeypot.

    All connected to the same case.

    First blood on each challenge gets logged permanently
    by The Machine.

    Sep 19 03:30 UTC. Free entry. Teams 1-6.
    Prizes: $750 / $500 / $250

    ctf.xposedornot.com
    CTFtime: ctftime.org/event/3326

    #CTF #DFIR #forensics #infosec #blueteam

  21. Empty scoreboard.
    80 teams.
    14 days.

    Someone's name goes first.

    WATCHLIST is a free 24-hour CTF built around one investigation.

    24 challenges - memory forensics,
    disk forensics, DNS exfil, ADSB analysis, live SSH honeypot.

    All connected to the same case.

    First blood on each challenge gets logged permanently
    by The Machine.

    Sep 19 03:30 UTC. Free entry. Teams 1-6.
    Prizes: $750 / $500 / $250

    ctf.xposedornot.com
    CTFtime: ctftime.org/event/3326

    #CTF #DFIR #forensics #infosec #blueteam

  22. Empty scoreboard.
    80 teams.
    14 days.

    Someone's name goes first.

    WATCHLIST is a free 24-hour CTF built around one investigation.

    24 challenges - memory forensics,
    disk forensics, DNS exfil, ADSB analysis, live SSH honeypot.

    All connected to the same case.

    First blood on each challenge gets logged permanently
    by The Machine.

    Sep 19 03:30 UTC. Free entry. Teams 1-6.
    Prizes: $750 / $500 / $250

    ctf.xposedornot.com
    CTFtime: ctftime.org/event/3326

    #CTF #DFIR #forensics #infosec #blueteam

  23. Empty scoreboard.
    80 teams.
    14 days.

    Someone's name goes first.

    WATCHLIST is a free 24-hour CTF built around one investigation.

    24 challenges - memory forensics,
    disk forensics, DNS exfil, ADSB analysis, live SSH honeypot.

    All connected to the same case.

    First blood on each challenge gets logged permanently
    by The Machine.

    Sep 19 03:30 UTC. Free entry. Teams 1-6.
    Prizes: $750 / $500 / $250

    ctf.xposedornot.com
    CTFtime: ctftime.org/event/3326

    #CTF #DFIR #forensics #infosec #blueteam

  24. 2026-09-04 RDP #Honeypot IOCs - 633 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    209.38.73.59 - 510
    79.137.100.124 - 27
    45.156.128.61 - 18

    Top ASNs:
    AS14061 - 510
    AS396982 - 27
    AS16276 - 27

    Top Accounts:
    hello - 549
    Administr - 21
    root - 18

    Top ISPs:
    DigitalOcean, LLC - 510
    Google LLC - 27
    OVH SAS - 27

    Top Clients:
    Unknown - 633

    Top Software:
    Unknown - 633

    Top Keyboards:
    Unknown - 633

    Top IP Classification:
    hosting - 603
    Unknown - 24
    hosting & proxy - 6

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  25. 2026-09-04 RDP #Honeypot IOCs - 633 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    209.38.73.59 - 510
    79.137.100.124 - 27
    45.156.128.61 - 18

    Top ASNs:
    AS14061 - 510
    AS396982 - 27
    AS16276 - 27

    Top Accounts:
    hello - 549
    Administr - 21
    root - 18

    Top ISPs:
    DigitalOcean, LLC - 510
    Google LLC - 27
    OVH SAS - 27

    Top Clients:
    Unknown - 633

    Top Software:
    Unknown - 633

    Top Keyboards:
    Unknown - 633

    Top IP Classification:
    hosting - 603
    Unknown - 24
    hosting & proxy - 6

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  26. 2026-09-04 RDP #Honeypot IOCs - 633 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    209.38.73.59 - 510
    79.137.100.124 - 27
    45.156.128.61 - 18

    Top ASNs:
    AS14061 - 510
    AS396982 - 27
    AS16276 - 27

    Top Accounts:
    hello - 549
    Administr - 21
    root - 18

    Top ISPs:
    DigitalOcean, LLC - 510
    Google LLC - 27
    OVH SAS - 27

    Top Clients:
    Unknown - 633

    Top Software:
    Unknown - 633

    Top Keyboards:
    Unknown - 633

    Top IP Classification:
    hosting - 603
    Unknown - 24
    hosting & proxy - 6

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  27. 2026-09-04 RDP #Honeypot IOCs - 633 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    209.38.73.59 - 510
    79.137.100.124 - 27
    45.156.128.61 - 18

    Top ASNs:
    AS14061 - 510
    AS396982 - 27
    AS16276 - 27

    Top Accounts:
    hello - 549
    Administr - 21
    root - 18

    Top ISPs:
    DigitalOcean, LLC - 510
    Google LLC - 27
    OVH SAS - 27

    Top Clients:
    Unknown - 633

    Top Software:
    Unknown - 633

    Top Keyboards:
    Unknown - 633

    Top IP Classification:
    hosting - 603
    Unknown - 24
    hosting & proxy - 6

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  28. 2026-09-04 RDP #Honeypot IOCs - 422 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    209.38.73.59 - 340
    79.137.100.124 - 18
    45.156.128.61 - 12

    Top ASNs:
    AS14061 - 340
    AS396982 - 18
    AS16276 - 18

    Top Accounts:
    hello - 366
    Administr - 14
    root - 12

    Top ISPs:
    DigitalOcean, LLC - 340
    Google LLC - 18
    OVH SAS - 18

    Top Clients:
    Unknown - 422

    Top Software:
    Unknown - 422

    Top Keyboards:
    Unknown - 422

    Top IP Classification:
    hosting - 402
    Unknown - 16
    hosting & proxy - 4

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  29. 2026-09-04 RDP #Honeypot IOCs - 422 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    209.38.73.59 - 340
    79.137.100.124 - 18
    45.156.128.61 - 12

    Top ASNs:
    AS14061 - 340
    AS396982 - 18
    AS16276 - 18

    Top Accounts:
    hello - 366
    Administr - 14
    root - 12

    Top ISPs:
    DigitalOcean, LLC - 340
    Google LLC - 18
    OVH SAS - 18

    Top Clients:
    Unknown - 422

    Top Software:
    Unknown - 422

    Top Keyboards:
    Unknown - 422

    Top IP Classification:
    hosting - 402
    Unknown - 16
    hosting & proxy - 4

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  30. 2026-09-04 RDP #Honeypot IOCs - 422 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    209.38.73.59 - 340
    79.137.100.124 - 18
    45.156.128.61 - 12

    Top ASNs:
    AS14061 - 340
    AS396982 - 18
    AS16276 - 18

    Top Accounts:
    hello - 366
    Administr - 14
    root - 12

    Top ISPs:
    DigitalOcean, LLC - 340
    Google LLC - 18
    OVH SAS - 18

    Top Clients:
    Unknown - 422

    Top Software:
    Unknown - 422

    Top Keyboards:
    Unknown - 422

    Top IP Classification:
    hosting - 402
    Unknown - 16
    hosting & proxy - 4

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  31. 2026-09-04 RDP #Honeypot IOCs - 422 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    209.38.73.59 - 340
    79.137.100.124 - 18
    45.156.128.61 - 12

    Top ASNs:
    AS14061 - 340
    AS396982 - 18
    AS16276 - 18

    Top Accounts:
    hello - 366
    Administr - 14
    root - 12

    Top ISPs:
    DigitalOcean, LLC - 340
    Google LLC - 18
    OVH SAS - 18

    Top Clients:
    Unknown - 422

    Top Software:
    Unknown - 422

    Top Keyboards:
    Unknown - 422

    Top IP Classification:
    hosting - 402
    Unknown - 16
    hosting & proxy - 4

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  32. 2026-09-04 RDP #Honeypot IOCs - 211 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    209.38.73.59 - 170
    79.137.100.124 - 9
    45.156.128.61 - 6

    Top ASNs:
    AS14061 - 170
    AS396982 - 9
    AS16276 - 9

    Top Accounts:
    hello - 183
    Administr - 7
    root - 6

    Top ISPs:
    DigitalOcean, LLC - 170
    Google LLC - 9
    OVH SAS - 9

    Top Clients:
    Unknown - 211

    Top Software:
    Unknown - 211

    Top Keyboards:
    Unknown - 211

    Top IP Classification:
    hosting - 201
    Unknown - 8
    hosting & proxy - 2

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  33. 2026-09-04 RDP #Honeypot IOCs - 211 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    209.38.73.59 - 170
    79.137.100.124 - 9
    45.156.128.61 - 6

    Top ASNs:
    AS14061 - 170
    AS396982 - 9
    AS16276 - 9

    Top Accounts:
    hello - 183
    Administr - 7
    root - 6

    Top ISPs:
    DigitalOcean, LLC - 170
    Google LLC - 9
    OVH SAS - 9

    Top Clients:
    Unknown - 211

    Top Software:
    Unknown - 211

    Top Keyboards:
    Unknown - 211

    Top IP Classification:
    hosting - 201
    Unknown - 8
    hosting & proxy - 2

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  34. 2026-09-04 RDP #Honeypot IOCs - 211 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    209.38.73.59 - 170
    79.137.100.124 - 9
    45.156.128.61 - 6

    Top ASNs:
    AS14061 - 170
    AS396982 - 9
    AS16276 - 9

    Top Accounts:
    hello - 183
    Administr - 7
    root - 6

    Top ISPs:
    DigitalOcean, LLC - 170
    Google LLC - 9
    OVH SAS - 9

    Top Clients:
    Unknown - 211

    Top Software:
    Unknown - 211

    Top Keyboards:
    Unknown - 211

    Top IP Classification:
    hosting - 201
    Unknown - 8
    hosting & proxy - 2

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  35. 2026-09-04 RDP #Honeypot IOCs - 211 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    209.38.73.59 - 170
    79.137.100.124 - 9
    45.156.128.61 - 6

    Top ASNs:
    AS14061 - 170
    AS396982 - 9
    AS16276 - 9

    Top Accounts:
    hello - 183
    Administr - 7
    root - 6

    Top ISPs:
    DigitalOcean, LLC - 170
    Google LLC - 9
    OVH SAS - 9

    Top Clients:
    Unknown - 211

    Top Software:
    Unknown - 211

    Top Keyboards:
    Unknown - 211

    Top IP Classification:
    hosting - 201
    Unknown - 8
    hosting & proxy - 2

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  36. Microsoft’s new notetaker block in Teams will drive AI notetakers more invisible, known as bot free. Many of them already support this.

    They install to the user folder. Some are Chrome extensions. And a few gleefully tout how invisible they are.

    Hunt in the windows registry \ConsentStore\microphone\NonPackage to see what could be hijacking the mic and recording meetings.

    Expanded block list forthcoming. Then maybe a Windows & Mac sensor. What a ridiculous blight.

    #blueteam #microsoftTeams #threatHunt #ainotetaker

  37. Bitwarden introduces “Cupid Vault” — a 2-user shared Organization vault available on the free plan.

    Security considerations:
    • End-to-end encryption
    • Vault isolation from personal storage
    • Fingerprint phrase verification (anti-ATMIT enrollment control)
    • Bidirectional sharing
    • Revocable access

    Limitations: 2 users, 2 collections. No RBAC granularity (reserved for paid tiers).

    Question for practitioners:
    Is secure shared vault architecture preferable to federated identity or delegated access models for small trust groups?

    Source: bleepingcomputer.com/news/secu

    Join the discussion below.
    Follow @technadu for actionable security insights.

    #InfoSec #PasswordManagement #ZeroTrust #Encryption #AccessControl #CyberDefense #Authentication #SecurityArchitecture #BlueTeam #PrivacyEngineering

  38. Server Security Checklist — Essential Hardening Guide

    Securing your servers isn’t optional — it’s your first line of defense against data breaches, ransomware, insider threats, and lateral movement. Use this checklist as a baseline for Linux, Windows, cloud, hybrid, or on-prem servers.

    🔧 1. System & OS Hardening
    • Keep OS & packages updated (apply security patches frequently).
    • Remove / disable unused services & software.
    • Enforce secure boot + BIOS/UEFI passwords.
    • Disable auto-login and guest accounts.
    • Use minimal OS images only (reduce attack surface).

    🔐 2. Access Control
    • Enforce strong passwords & MFA everywhere.
    • Use RBAC & least privilege access.
    • Disable root/Administrator login over SSH/RDP.
    • Rotate credentials & keys regularly.
    • Implement just-in-time access for privileged users.

    🌐 3. Network Security
    • Restrict inbound/outbound traffic via firewalls.
    • Segment critical servers from general LANs/VLANs.
    • Disable unused ports & protocols.
    • Enable DoS/DDoS protection.
    • Apply zero-trust network principles.

    🔑 4. Secure Remote Access
    • Use SSH key-based authentication (disable password login).
    • Enforce VPN for admin access.
    • Log & monitor all remote access sessions.
    • Disable legacy protocols (Telnet, FTP, SMBv1).
    • Require bastion/jump host for critical access.

    📊 5. Logging & Monitoring
    • Enable centralized logging (syslog / SIEM).
    • Track failed login attempts & anomalies.
    • Configure alerts for privilege escalation or config changes.
    • Monitor log tampering.
    • Retain logs securely for audits & forensics.

    🔒 6. Data Protection
    • Encrypt data at rest (LUKS, BitLocker, etc.).
    • Encrypt data in transit (TLS 1.2+).
    • Strict database access policies.
    • Regular, offline, immutable backups.
    • Test restore procedures (don’t assume backups work).

    🔁 7. Application & Patch Management
    • Keep middleware, frameworks, and apps patched.
    • Delete default credentials & sample files.
    • Enable code signing for software packages.
    • Use secure coding practices (OWASP Top 10).
    • Implement dependency scanning (Snyk, Trivy, etc.).

    🛡️ 8. Malware & Intrusion Defense
    • Deploy EDR/AV on endpoints.
    • Enable IDS/IPS at network edge.
    • Automatic vulnerability scans (schedule weekly/monthly).
    • Monitor persistence techniques (cron, startup scripts).
    • Block known malicious IP ranges & TLDs.

    🏢 9. Physical & Cloud Security
    • Restrict physical access to server racks/rooms.
    • Enable provider security tools (AWS Security Groups, Azure NSG, IAM).
    • Harden cloud images (CIS benchmarks).
    • Review cloud logging & audit trails regularly.
    • Disable unused cloud API keys / roles.

    📜 10. Policy & Compliance
    • Use CIS / NIST / ISO-27001 benchmarks.
    • Track & document every access change.
    • Force annual access reviews & key rotation.
    • Perform regular security training for admins.
    • Maintain disaster recovery & incident plans.

    ➕ Additional 5 Critical Controls (Advanced Hardening)

    🧠 11. Privileged Access Management (PAM)
    • Use jump hosts & session recording.
    • Just-In-Time access for admins.
    • Store keys in secure vaults (HashiCorp Vault, CyberArk).

    🚨 12. Real-Time Threat Detection
    • Use behavioral analytics → UEBA/XDR.
    • AI-based anomaly detection recommended.
    • Block suspicious IPs automatically.

    🧪 13. Red Team & Pentesting
    • Run regular internal pentests.
    • Validate configuration weaknesses.
    • Simulate phishing + lateral movement scenarios.

    🧱 14. Container / VM Isolation
    • Use AppArmor, SELinux, Seccomp profiles.
    • Limit Docker socket access & root containers.
    • Scan images before deployment.

    📦 15. Automated Configuration Management
    • Use IaC (Terraform, Ansible, Puppet) for repeatable and secure builds.
    • Detect drift using compliance scanning.
    • Version control all infrastructure.

    🧠 Core Reminder

    A server is only as secure as the team who maintains it.
    Hardening isn’t one task — it’s an ongoing

    #ServerSecurity #SystemHardening #InfoSec #CyberSecurity #BlueTeam
    #DevSecOps #SysAdmin #ThreatDetection #AccessControl #NetworkSecurity
    #LinuxSecurity #SecureArchitecture #RiskMitigation #SecurityChecklist
    #CloudSecurity #InfrastructureSecurity #ZeroTrust #SecurityMonitoring

  39. Happy Monday folks, I hope you had a restful weekend and managed to take a breather from all things cyber! Time to get back into it though, so let me give you hand - catch up on the week’s infosec news with the latest issue of our newsletter:

    opalsec.substack.com/p/soc-gou

    #Emotet are back and are using…OneNote lures? ISO disk images? Malvertising? Nah – they’re sticking with tier tried and true TTPs – their Red Dawn maldoc template from last year; macro-enabled documents as lures, and null-byte padding to evade automated scanners.

    We’ve highlighted a report on the Xenomorph #Android Banking Trojan, which added support for targeting accounts of over 400 banks; automated bypassing of MFA-protected app logins, and a Session Token stealer module. With capabilities like these becoming the norm, is it time to take a closer look at the threat Mobile Malware could pose to enterprise networks?

    North Korean hackers have demonstrated yet again that they’re tracking and integrating the latest techniques, and investing in malware development. A recent campaign saw eight new pieces of malware distributed throughout the kill chain, leveraging #Microsoft #InTune to deliver payloads and an in-memory dropper to abuse the #BYOVD technique and evade EDR solutions.

    A joint investigation by #Mandiant and #SonicWall has unearthed a two-year campaign by Chinese actors, enabled through exploitation of unpatched SMA100 appliances and delivery of tailored payloads. A critical vulnerability reported by #Fortinet this week helps reinforce the point that perimeter devices need to be patched with urgency, as it’s a well-documented target for Chinese-affiliated actors.

    #HiatusRAT is a novel malware targeting #DrayTek routers, sniffing network traffic and proxying C2 traffic to forward-deployed implants. TTPs employed in recent #BatLoader and #Qakbot campaigns are also worth taking note of, as is #GoBruteforcer, a new malware family targeting specific web server applications to brute force logins and deploy an IRC bot for C2.

    Those in Vulnerability Management should take particular note of the #Veeam vulnerability, which appears trivial to exploit and actually delivers plaintext credentials to the attacker. CISA have also taken note of nearly 40k exploit attempts of a 2 year old code-exec-as-root vulnerability in the #VMWare Cloud Foundation product in the last two months, so make sure you’re patched against it.

    #Redteam members have some excellent reading to look forward to, looking at HTTP request smuggling to harvest AD credentials and persisting with a MitM Exchange server, as well as a detailed post that examines #CobaltStrike’s reflective loading capability;

    The #blueteam has some great tradecraft tips from @inversecos on #Azure DFIR, as well as tools to help scan websites for malicious objects, and to combat the new #Stealc #infostealer and well-established Raccoon Stealer.

    Catch all this and much more in this week's newsletter:

    opalsec.substack.com/p/soc-gou

    #infosec #cyber #news #cybernews #infosec #infosecnews #informationsecurity #cybersecurity #newsletter #hacking #security #technology #hacker #vulnerability #vulnerabilities #malware #ransomware #dfir #soc #threatintel #threatintelligence #DarkWeb #mdm #dprk #FortiOS #FortiProxy