#blueteam — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #blueteam, aggregated by home.social.
-
2026-09-05 RDP #Honeypot IOCs - 2556 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
141.11.96.210 - 2409
103.178.235.50 - 27
217.160.240.135 - 27Top ASNs:
Unknown - 2409
AS396982 - 48
AS140810 - 27Top Accounts:
hello - 2469
Administr - 12
0siivpyz - 12Top ISPs:
Private Customer - 2409
Google LLC - 48
VPSTTT - 27Top Clients:
Unknown - 2556Top Software:
Unknown - 2556Top Keyboards:
Unknown - 2556Top IP Classification:
proxy - 2409
hosting - 99
hosting & proxy - 39Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-05 RDP #Honeypot IOCs - 2556 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
141.11.96.210 - 2409
103.178.235.50 - 27
217.160.240.135 - 27Top ASNs:
Unknown - 2409
AS396982 - 48
AS140810 - 27Top Accounts:
hello - 2469
Administr - 12
0siivpyz - 12Top ISPs:
Private Customer - 2409
Google LLC - 48
VPSTTT - 27Top Clients:
Unknown - 2556Top Software:
Unknown - 2556Top Keyboards:
Unknown - 2556Top IP Classification:
proxy - 2409
hosting - 99
hosting & proxy - 39Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-05 RDP #Honeypot IOCs - 2556 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
141.11.96.210 - 2409
103.178.235.50 - 27
217.160.240.135 - 27Top ASNs:
Unknown - 2409
AS396982 - 48
AS140810 - 27Top Accounts:
hello - 2469
Administr - 12
0siivpyz - 12Top ISPs:
Private Customer - 2409
Google LLC - 48
VPSTTT - 27Top Clients:
Unknown - 2556Top Software:
Unknown - 2556Top Keyboards:
Unknown - 2556Top IP Classification:
proxy - 2409
hosting - 99
hosting & proxy - 39Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-05 RDP #Honeypot IOCs - 2556 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
141.11.96.210 - 2409
103.178.235.50 - 27
217.160.240.135 - 27Top ASNs:
Unknown - 2409
AS396982 - 48
AS140810 - 27Top Accounts:
hello - 2469
Administr - 12
0siivpyz - 12Top ISPs:
Private Customer - 2409
Google LLC - 48
VPSTTT - 27Top Clients:
Unknown - 2556Top Software:
Unknown - 2556Top Keyboards:
Unknown - 2556Top IP Classification:
proxy - 2409
hosting - 99
hosting & proxy - 39Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-05 RDP #Honeypot IOCs - 1704 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
141.11.96.210 - 1606
103.178.235.50 - 18
217.160.240.135 - 18Top ASNs:
Unknown - 1606
AS396982 - 32
AS140810 - 18Top Accounts:
hello - 1646
Administr - 8
0siivpyz - 8Top ISPs:
Private Customer - 1606
Google LLC - 32
VPSTTT - 18Top Clients:
Unknown - 1704Top Software:
Unknown - 1704Top Keyboards:
Unknown - 1704Top IP Classification:
proxy - 1606
hosting - 66
hosting & proxy - 26Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-05 RDP #Honeypot IOCs - 1704 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
141.11.96.210 - 1606
103.178.235.50 - 18
217.160.240.135 - 18Top ASNs:
Unknown - 1606
AS396982 - 32
AS140810 - 18Top Accounts:
hello - 1646
Administr - 8
0siivpyz - 8Top ISPs:
Private Customer - 1606
Google LLC - 32
VPSTTT - 18Top Clients:
Unknown - 1704Top Software:
Unknown - 1704Top Keyboards:
Unknown - 1704Top IP Classification:
proxy - 1606
hosting - 66
hosting & proxy - 26Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-05 RDP #Honeypot IOCs - 1704 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
141.11.96.210 - 1606
103.178.235.50 - 18
217.160.240.135 - 18Top ASNs:
Unknown - 1606
AS396982 - 32
AS140810 - 18Top Accounts:
hello - 1646
Administr - 8
0siivpyz - 8Top ISPs:
Private Customer - 1606
Google LLC - 32
VPSTTT - 18Top Clients:
Unknown - 1704Top Software:
Unknown - 1704Top Keyboards:
Unknown - 1704Top IP Classification:
proxy - 1606
hosting - 66
hosting & proxy - 26Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-05 RDP #Honeypot IOCs - 1704 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
141.11.96.210 - 1606
103.178.235.50 - 18
217.160.240.135 - 18Top ASNs:
Unknown - 1606
AS396982 - 32
AS140810 - 18Top Accounts:
hello - 1646
Administr - 8
0siivpyz - 8Top ISPs:
Private Customer - 1606
Google LLC - 32
VPSTTT - 18Top Clients:
Unknown - 1704Top Software:
Unknown - 1704Top Keyboards:
Unknown - 1704Top IP Classification:
proxy - 1606
hosting - 66
hosting & proxy - 26Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-05 RDP #Honeypot IOCs - 852 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
141.11.96.210 - 803
103.178.235.50 - 9
217.160.240.135 - 9Top ASNs:
Unknown - 803
AS396982 - 16
AS140810 - 9Top Accounts:
hello - 823
Administr - 4
0siivpyz - 4Top ISPs:
Private Customer - 803
Google LLC - 16
VPSTTT - 9Top Clients:
Unknown - 852Top Software:
Unknown - 852Top Keyboards:
Unknown - 852Top IP Classification:
proxy - 803
hosting - 33
hosting & proxy - 13Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-05 RDP #Honeypot IOCs - 852 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
141.11.96.210 - 803
103.178.235.50 - 9
217.160.240.135 - 9Top ASNs:
Unknown - 803
AS396982 - 16
AS140810 - 9Top Accounts:
hello - 823
Administr - 4
0siivpyz - 4Top ISPs:
Private Customer - 803
Google LLC - 16
VPSTTT - 9Top Clients:
Unknown - 852Top Software:
Unknown - 852Top Keyboards:
Unknown - 852Top IP Classification:
proxy - 803
hosting - 33
hosting & proxy - 13Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-05 RDP #Honeypot IOCs - 852 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
141.11.96.210 - 803
103.178.235.50 - 9
217.160.240.135 - 9Top ASNs:
Unknown - 803
AS396982 - 16
AS140810 - 9Top Accounts:
hello - 823
Administr - 4
0siivpyz - 4Top ISPs:
Private Customer - 803
Google LLC - 16
VPSTTT - 9Top Clients:
Unknown - 852Top Software:
Unknown - 852Top Keyboards:
Unknown - 852Top IP Classification:
proxy - 803
hosting - 33
hosting & proxy - 13Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-05 RDP #Honeypot IOCs - 852 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
141.11.96.210 - 803
103.178.235.50 - 9
217.160.240.135 - 9Top ASNs:
Unknown - 803
AS396982 - 16
AS140810 - 9Top Accounts:
hello - 823
Administr - 4
0siivpyz - 4Top ISPs:
Private Customer - 803
Google LLC - 16
VPSTTT - 9Top Clients:
Unknown - 852Top Software:
Unknown - 852Top Keyboards:
Unknown - 852Top IP Classification:
proxy - 803
hosting - 33
hosting & proxy - 13Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
SOC-Analyst Lern- & Praxishandbuch
Ich habe mir in den letzten Wochen ein eigenes SOC-Analyst Lern- & Praxishandbuch erstellt.
Gedacht ist es vor allem für Einsteiger, Interessierte und alle, die sich einen strukturierten Überblick über Security Operations und SOC verschaffen möchten.
Enthalten sind unter anderem Themen wie Netzwerke, SIEM, EDR/XDR, Threat Intelligence, Incident Response, Detection Engineering, Cloud Security, Malware-Analyse, Forensik sowie praktische Lernpfade und Tool-Empfehlungen.
Für mich war wichtig, Theorie und Praxis möglichst verständlich zusammenzubringen und gleichzeitig zu zeigen, was man als angehender SOC Analyst wirklich lernen und üben sollte.
Download: SOC-Analyst – Das umfassende Lern- & Praxishandbuch:
:boost_ok:
#CyberSecurity #SOC #BlueTeam #SecurityOperations #ITSecurity
-
SOC-Analyst Lern- & Praxishandbuch
Ich habe mir in den letzten Wochen ein eigenes SOC-Analyst Lern- & Praxishandbuch erstellt.
Gedacht ist es vor allem für Einsteiger, Interessierte und alle, die sich einen strukturierten Überblick über Security Operations und SOC verschaffen möchten.
Enthalten sind unter anderem Themen wie Netzwerke, SIEM, EDR/XDR, Threat Intelligence, Incident Response, Detection Engineering, Cloud Security, Malware-Analyse, Forensik sowie praktische Lernpfade und Tool-Empfehlungen.
Für mich war wichtig, Theorie und Praxis möglichst verständlich zusammenzubringen und gleichzeitig zu zeigen, was man als angehender SOC Analyst wirklich lernen und üben sollte.
Download: SOC-Analyst – Das umfassende Lern- & Praxishandbuch:
:boost_ok:
#CyberSecurity #SOC #BlueTeam #SecurityOperations #ITSecurity
-
SOC-Analyst Lern- & Praxishandbuch
Ich habe mir in den letzten Wochen ein eigenes SOC-Analyst Lern- & Praxishandbuch erstellt.
Gedacht ist es vor allem für Einsteiger, Interessierte und alle, die sich einen strukturierten Überblick über Security Operations und SOC verschaffen möchten.
Enthalten sind unter anderem Themen wie Netzwerke, SIEM, EDR/XDR, Threat Intelligence, Incident Response, Detection Engineering, Cloud Security, Malware-Analyse, Forensik sowie praktische Lernpfade und Tool-Empfehlungen.
Für mich war wichtig, Theorie und Praxis möglichst verständlich zusammenzubringen und gleichzeitig zu zeigen, was man als angehender SOC Analyst wirklich lernen und üben sollte.
Download: SOC-Analyst – Das umfassende Lern- & Praxishandbuch:
:boost_ok:
#CyberSecurity #SOC #BlueTeam #SecurityOperations #ITSecurity
-
SOC-Analyst Lern- & Praxishandbuch
Ich habe mir in den letzten Wochen ein eigenes SOC-Analyst Lern- & Praxishandbuch erstellt.
Gedacht ist es vor allem für Einsteiger, Interessierte und alle, die sich einen strukturierten Überblick über Security Operations und SOC verschaffen möchten.
Enthalten sind unter anderem Themen wie Netzwerke, SIEM, EDR/XDR, Threat Intelligence, Incident Response, Detection Engineering, Cloud Security, Malware-Analyse, Forensik sowie praktische Lernpfade und Tool-Empfehlungen.
Für mich war wichtig, Theorie und Praxis möglichst verständlich zusammenzubringen und gleichzeitig zu zeigen, was man als angehender SOC Analyst wirklich lernen und üben sollte.
Download: SOC-Analyst – Das umfassende Lern- & Praxishandbuch:
:boost_ok:
#CyberSecurity #SOC #BlueTeam #SecurityOperations #ITSecurity
-
SOC-Analyst Lern- & Praxishandbuch
Ich habe mir in den letzten Wochen ein eigenes SOC-Analyst Lern- & Praxishandbuch erstellt.
Gedacht ist es vor allem für Einsteiger, Interessierte und alle, die sich einen strukturierten Überblick über Security Operations und SOC verschaffen möchten.
Enthalten sind unter anderem Themen wie Netzwerke, SIEM, EDR/XDR, Threat Intelligence, Incident Response, Detection Engineering, Cloud Security, Malware-Analyse, Forensik sowie praktische Lernpfade und Tool-Empfehlungen.
Für mich war wichtig, Theorie und Praxis möglichst verständlich zusammenzubringen und gleichzeitig zu zeigen, was man als angehender SOC Analyst wirklich lernen und üben sollte.
Download: SOC-Analyst – Das umfassende Lern- & Praxishandbuch:
:boost_ok:
#CyberSecurity #SOC #BlueTeam #SecurityOperations #ITSecurity
-
Ich habe mir in den letzten Wochen ein eigenes SOC-Analyst Lern- & Praxishandbuch erstellt.
Gedacht ist es vor allem für Einsteiger, Interessierte und alle, die sich einen strukturierten Überblick über Security Operations und SOC verschaffen möchten.
Enthalten sind unter anderem Themen wie Netzwerke, SIEM, EDR/XDR, Threat Intelligence, Incident Response, Detection Engineering, Cloud Security, Malware-Analyse, Forensik sowie praktische Lernpfade und Tool-Empfehlungen.
Für mich war wichtig, Theorie und Praxis möglichst verständlich zusammenzubringen und gleichzeitig zu zeigen, was man als angehender SOC Analyst wirklich lernen und üben sollte.
Download: SOC-Analyst – Das umfassende Lern- & Praxishandbuch:
:boost_ok:
#CyberSecurity #SOC #BlueTeam #SecurityOperations #ITSecurity
-
Empty scoreboard.
80 teams.
14 days.Someone's name goes first.
WATCHLIST is a free 24-hour CTF built around one investigation.
24 challenges - memory forensics,
disk forensics, DNS exfil, ADSB analysis, live SSH honeypot.All connected to the same case.
First blood on each challenge gets logged permanently
by The Machine.Sep 19 03:30 UTC. Free entry. Teams 1-6.
Prizes: $750 / $500 / $250ctf.xposedornot.com
CTFtime: ctftime.org/event/3326 -
Empty scoreboard.
80 teams.
14 days.Someone's name goes first.
WATCHLIST is a free 24-hour CTF built around one investigation.
24 challenges - memory forensics,
disk forensics, DNS exfil, ADSB analysis, live SSH honeypot.All connected to the same case.
First blood on each challenge gets logged permanently
by The Machine.Sep 19 03:30 UTC. Free entry. Teams 1-6.
Prizes: $750 / $500 / $250ctf.xposedornot.com
CTFtime: ctftime.org/event/3326 -
Empty scoreboard.
80 teams.
14 days.Someone's name goes first.
WATCHLIST is a free 24-hour CTF built around one investigation.
24 challenges - memory forensics,
disk forensics, DNS exfil, ADSB analysis, live SSH honeypot.All connected to the same case.
First blood on each challenge gets logged permanently
by The Machine.Sep 19 03:30 UTC. Free entry. Teams 1-6.
Prizes: $750 / $500 / $250ctf.xposedornot.com
CTFtime: ctftime.org/event/3326 -
Empty scoreboard.
80 teams.
14 days.Someone's name goes first.
WATCHLIST is a free 24-hour CTF built around one investigation.
24 challenges - memory forensics,
disk forensics, DNS exfil, ADSB analysis, live SSH honeypot.All connected to the same case.
First blood on each challenge gets logged permanently
by The Machine.Sep 19 03:30 UTC. Free entry. Teams 1-6.
Prizes: $750 / $500 / $250ctf.xposedornot.com
CTFtime: ctftime.org/event/3326 -
Empty scoreboard.
80 teams.
14 days.Someone's name goes first.
WATCHLIST is a free 24-hour CTF built around one investigation.
24 challenges - memory forensics,
disk forensics, DNS exfil, ADSB analysis, live SSH honeypot.All connected to the same case.
First blood on each challenge gets logged permanently
by The Machine.Sep 19 03:30 UTC. Free entry. Teams 1-6.
Prizes: $750 / $500 / $250ctf.xposedornot.com
CTFtime: ctftime.org/event/3326 -
2026-09-04 RDP #Honeypot IOCs - 633 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
209.38.73.59 - 510
79.137.100.124 - 27
45.156.128.61 - 18Top ASNs:
AS14061 - 510
AS396982 - 27
AS16276 - 27Top Accounts:
hello - 549
Administr - 21
root - 18Top ISPs:
DigitalOcean, LLC - 510
Google LLC - 27
OVH SAS - 27Top Clients:
Unknown - 633Top Software:
Unknown - 633Top Keyboards:
Unknown - 633Top IP Classification:
hosting - 603
Unknown - 24
hosting & proxy - 6Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-04 RDP #Honeypot IOCs - 633 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
209.38.73.59 - 510
79.137.100.124 - 27
45.156.128.61 - 18Top ASNs:
AS14061 - 510
AS396982 - 27
AS16276 - 27Top Accounts:
hello - 549
Administr - 21
root - 18Top ISPs:
DigitalOcean, LLC - 510
Google LLC - 27
OVH SAS - 27Top Clients:
Unknown - 633Top Software:
Unknown - 633Top Keyboards:
Unknown - 633Top IP Classification:
hosting - 603
Unknown - 24
hosting & proxy - 6Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-04 RDP #Honeypot IOCs - 633 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
209.38.73.59 - 510
79.137.100.124 - 27
45.156.128.61 - 18Top ASNs:
AS14061 - 510
AS396982 - 27
AS16276 - 27Top Accounts:
hello - 549
Administr - 21
root - 18Top ISPs:
DigitalOcean, LLC - 510
Google LLC - 27
OVH SAS - 27Top Clients:
Unknown - 633Top Software:
Unknown - 633Top Keyboards:
Unknown - 633Top IP Classification:
hosting - 603
Unknown - 24
hosting & proxy - 6Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-04 RDP #Honeypot IOCs - 633 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
209.38.73.59 - 510
79.137.100.124 - 27
45.156.128.61 - 18Top ASNs:
AS14061 - 510
AS396982 - 27
AS16276 - 27Top Accounts:
hello - 549
Administr - 21
root - 18Top ISPs:
DigitalOcean, LLC - 510
Google LLC - 27
OVH SAS - 27Top Clients:
Unknown - 633Top Software:
Unknown - 633Top Keyboards:
Unknown - 633Top IP Classification:
hosting - 603
Unknown - 24
hosting & proxy - 6Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-04 RDP #Honeypot IOCs - 422 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
209.38.73.59 - 340
79.137.100.124 - 18
45.156.128.61 - 12Top ASNs:
AS14061 - 340
AS396982 - 18
AS16276 - 18Top Accounts:
hello - 366
Administr - 14
root - 12Top ISPs:
DigitalOcean, LLC - 340
Google LLC - 18
OVH SAS - 18Top Clients:
Unknown - 422Top Software:
Unknown - 422Top Keyboards:
Unknown - 422Top IP Classification:
hosting - 402
Unknown - 16
hosting & proxy - 4Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-04 RDP #Honeypot IOCs - 422 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
209.38.73.59 - 340
79.137.100.124 - 18
45.156.128.61 - 12Top ASNs:
AS14061 - 340
AS396982 - 18
AS16276 - 18Top Accounts:
hello - 366
Administr - 14
root - 12Top ISPs:
DigitalOcean, LLC - 340
Google LLC - 18
OVH SAS - 18Top Clients:
Unknown - 422Top Software:
Unknown - 422Top Keyboards:
Unknown - 422Top IP Classification:
hosting - 402
Unknown - 16
hosting & proxy - 4Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-04 RDP #Honeypot IOCs - 422 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
209.38.73.59 - 340
79.137.100.124 - 18
45.156.128.61 - 12Top ASNs:
AS14061 - 340
AS396982 - 18
AS16276 - 18Top Accounts:
hello - 366
Administr - 14
root - 12Top ISPs:
DigitalOcean, LLC - 340
Google LLC - 18
OVH SAS - 18Top Clients:
Unknown - 422Top Software:
Unknown - 422Top Keyboards:
Unknown - 422Top IP Classification:
hosting - 402
Unknown - 16
hosting & proxy - 4Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-04 RDP #Honeypot IOCs - 422 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
209.38.73.59 - 340
79.137.100.124 - 18
45.156.128.61 - 12Top ASNs:
AS14061 - 340
AS396982 - 18
AS16276 - 18Top Accounts:
hello - 366
Administr - 14
root - 12Top ISPs:
DigitalOcean, LLC - 340
Google LLC - 18
OVH SAS - 18Top Clients:
Unknown - 422Top Software:
Unknown - 422Top Keyboards:
Unknown - 422Top IP Classification:
hosting - 402
Unknown - 16
hosting & proxy - 4Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-04 RDP #Honeypot IOCs - 211 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
209.38.73.59 - 170
79.137.100.124 - 9
45.156.128.61 - 6Top ASNs:
AS14061 - 170
AS396982 - 9
AS16276 - 9Top Accounts:
hello - 183
Administr - 7
root - 6Top ISPs:
DigitalOcean, LLC - 170
Google LLC - 9
OVH SAS - 9Top Clients:
Unknown - 211Top Software:
Unknown - 211Top Keyboards:
Unknown - 211Top IP Classification:
hosting - 201
Unknown - 8
hosting & proxy - 2Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-04 RDP #Honeypot IOCs - 211 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
209.38.73.59 - 170
79.137.100.124 - 9
45.156.128.61 - 6Top ASNs:
AS14061 - 170
AS396982 - 9
AS16276 - 9Top Accounts:
hello - 183
Administr - 7
root - 6Top ISPs:
DigitalOcean, LLC - 170
Google LLC - 9
OVH SAS - 9Top Clients:
Unknown - 211Top Software:
Unknown - 211Top Keyboards:
Unknown - 211Top IP Classification:
hosting - 201
Unknown - 8
hosting & proxy - 2Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-04 RDP #Honeypot IOCs - 211 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
209.38.73.59 - 170
79.137.100.124 - 9
45.156.128.61 - 6Top ASNs:
AS14061 - 170
AS396982 - 9
AS16276 - 9Top Accounts:
hello - 183
Administr - 7
root - 6Top ISPs:
DigitalOcean, LLC - 170
Google LLC - 9
OVH SAS - 9Top Clients:
Unknown - 211Top Software:
Unknown - 211Top Keyboards:
Unknown - 211Top IP Classification:
hosting - 201
Unknown - 8
hosting & proxy - 2Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-09-04 RDP #Honeypot IOCs - 211 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
209.38.73.59 - 170
79.137.100.124 - 9
45.156.128.61 - 6Top ASNs:
AS14061 - 170
AS396982 - 9
AS16276 - 9Top Accounts:
hello - 183
Administr - 7
root - 6Top ISPs:
DigitalOcean, LLC - 170
Google LLC - 9
OVH SAS - 9Top Clients:
Unknown - 211Top Software:
Unknown - 211Top Keyboards:
Unknown - 211Top IP Classification:
hosting - 201
Unknown - 8
hosting & proxy - 2Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
I looked at reasons why Palo Alto Cortex uses this very old piece of public domain software in their EDR agent, and what can we learn from it.
https://death.sk/posts/clips_detection_engine/
#blueteam #dfir #xdr #edr -
Qu’est-ce qu’un WAF ? Principes et mise en pratique https://www.it-connect.fr/waf-web-application-firewall-debutant/ #Pourlesdébutants #Cybersécurité #BlueTeam #Web
-
RE: https://infosec.exchange/@badsamurai/117016191874879106
This week in BS Lists, AI Meeting Notetakers, the Shadow AI that's siphoning sensitive data from your organization.
If not approved, block these in your web proxy, firewall, and SEG. You may be limited in what you can do in Teams/Zoom, but this will help deter and nerf their usability.
Upgrade to a ban-sledge with additional LinkedIn URLs. I also included some of the most common attendee formats to hunt in your SIEM.
But
notetakerwill get you real far.https://github.com/BadSamuraiDev/bs-lists/blob/main/ai-meeting-notetakers.md
-
From now on all #CVe #CVEAlert additional to #yara #Sigma and #Suricate rules will have #Splunk #Wazuh rules all for FREE no tracking no registration, no payments! #cybersecurity #devsecops #devops #infosec #redteam #blueteam #github #gitlab #git #developers #developer info source and follow for more updates as there will be more EX: https://www.valtersit.com/cve/CVE-2026-9734/
-
🚀 SO-CRATES 1.1 is here — now with Light Mode! ☀️
The tool you loved as OhMyPCAP keeps getting better.
Your all-in-one Docker/Podman container for rapid analysis of PCAPs, logs, and binaries just leveled up.
✅ PCAPs → Suricata alerts, rich metadata, ASCII transcripts, stream carving
✅ Logs → Sigma alerts + originals
✅ Binaries → YARA matches + metadataPerfect for air-gapped environments, malware analysis, IR, threat hunting, forensics & teaching.
What’s your preference?
→ Dark Mode 🖤
→ Light Mode ☀️
→ Why not both?
→ Needs glorious 4-color CGA option lol
Comment below!#DFIR #Cybersecurity #BlueTeam #ThreatHunting #Suricata #YARA #Sigma #DarkMode #LightMode
-
🚀Introducing SO-CRATES 1.0 — Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!
SO-CRATES is a single container image for analyzing pcap files, log files, and binary files. It was formerly known as OhMyPCAP.
Here's what you can do with SO-CRATES:
✅analyze pcap files and then review Suricata alerts, metadata, and extracted files
✅import log files and then review Sigma alerts and the original log entries
✅import binary files and then review YARA matches and file metadataAll of this runs in a single Docker/Podman container — perfect for air-gapped environments, malware analysis, incident response, threat hunting, forensics & teaching.
Who’s trying it out? Drop a ❤️ and reply with your main use case!
#DFIR #Cybersecurity #BlueTeam #ThreatHunting #Suricata #YARA #Sigma
-
Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257)
In this article, I break down how the vulnerability works, affected configurations, exploitation scenarios, and the mitigation steps organizations should take to protect their remote access infrastructure.
https://denizhalil.com/2026/06/02/cve-2026-0257-pan-os-globalprotect-authentication-bypass/
#CyberSecurity #PaloAlto #GlobalProtect #PANOS #CVE20260257 #VulnerabilityManagement #ThreatDetection #NetworkSecurity #BlueTeam #RedTeam #InfoSec #DenizHalil
-
🇰🇵 300+ Fortune 500 companies hired a North Korean engineer.
None of them knew it at the time.
In 2024-2025, DPRK operators used stolen US identities, AI-modified avatars and real-time#Deepfake interviews to infiltrate Fortune 500 and mid-market tech companies.
→ Stolen US identity + AI-generated profile
→ Live #AI assisted interview manipulation
→ Domestic facilitator handling onboarding
→ Corporate laptop sent to a US “laptop farm”
→ KVM/VPN tunnel from Pyongyang via Russian or Chinese relays
→ Salaries redirected through facilitator accounts → ~90% skimmed to the DPRK regimeMore than 300 companies impacted. Estimated revenue stream: ~$600M/year.
Funds allegedly routed to DPRK Bureau 39 and the ballistic missile programme.
$17.8M traced in facilitator accounts in the Christina Chapman case alone. Detection took months, not minutes. Traditional monitoring and standard #SOC visibility would likely not have detected the operation. Mandiant tracks the cluster as #UNC5267.
This is no longer simple cybercrime. It is state-sponsored infiltration blending #CyberSecurity, #IdentityFraud, #OSINT, remote work infrastructure abuse and AI-powered social engineering.
The future of #CTI and insider-threat detection is already here.
→ https://cidu.io/articles/dprk-it-worker-laptop-farm-2026
#NorthKorea #DPRK #CyberThreatIntelligence #CyberEspionage #CyberWarfare #Infosec #BlueTeam #ThreatIntel #Geopolitics #RemoteWork #VPN #KVM #Fortune500
-
🇰🇵 300+ Fortune 500 companies hired a North Korean engineer.
None of them knew it at the time.
In 2024-2025, DPRK operators used stolen US identities, AI-modified avatars and real-time#Deepfake interviews to infiltrate Fortune 500 and mid-market tech companies.
→ Stolen US identity + AI-generated profile
→ Live #AI assisted interview manipulation
→ Domestic facilitator handling onboarding
→ Corporate laptop sent to a US “laptop farm”
→ KVM/VPN tunnel from Pyongyang via Russian or Chinese relays
→ Salaries redirected through facilitator accounts → ~90% skimmed to the DPRK regimeMore than 300 companies impacted. Estimated revenue stream: ~$600M/year.
Funds allegedly routed to DPRK Bureau 39 and the ballistic missile programme.
$17.8M traced in facilitator accounts in the Christina Chapman case alone. Detection took months, not minutes. Traditional monitoring and standard #SOC visibility would likely not have detected the operation. Mandiant tracks the cluster as #UNC5267.
This is no longer simple cybercrime. It is state-sponsored infiltration blending #CyberSecurity, #IdentityFraud, #OSINT, remote work infrastructure abuse and AI-powered social engineering.
The future of #CTI and insider-threat detection is already here.
→ https://cidu.io/articles/dprk-it-worker-laptop-farm-2026
#NorthKorea #DPRK #CyberThreatIntelligence #CyberEspionage #CyberWarfare #Infosec #BlueTeam #ThreatIntel #Geopolitics #RemoteWork #VPN #KVM #Fortune500
-
What is Silver Ticket Attack: A Comprehensive Guide
In this article, I cover how Silver Ticket attacks work, common exploitation scenarios, detection techniques, and mitigation strategies.
https://denizhalil.com/2026/05/27/silver-ticket-attack-comprehensive-guide/#CyberSecurity #ActiveDirectory #SilverTicket #Kerberos #CredentialAccess #RedTeam #BlueTeam #Pentesting #WindowsSecurity #InfoSec #ThreatDetection #DenizHalil
-
🚀 OhMyPCAP 4.0.0 is HERE!
The ultimate FOSS PCAP analyzer just got a massive upgrade for deeper file intelligence.
New in v4.0:
• Upgraded to YARA Forge Full ruleset — more comprehensive malware & threat detection
• Exiftool + rich file metadata analysis — get more file information even if there are no YARA matchesAll the power you love is still here:
Suricata alerts, file alerts, Sankey diagrams, full-text search, ASCII transcripts, hexdumps, stream carving + single Docker/Podman container (perfect for air-gapped or quick spins).Ideal for malware analysis, incident response, threat hunting, forensics & teaching.
Who’s pulling this version right now? Drop a ❤️+ reply with your main use case (malware samples? CTFs? real-world incidents? teaching?)
#PCAP #DFIR #Cybersecurity #Infosec #BlueTeam #ThreatHunting #Suricata #YARA #MalwareAnalysis
-
Kerbrute: Enumerating Active Directory Accounts
In this article, I cover how Kerberoasting works, common attack techniques, detection methods, and practical defense strategies.
🔗 https://denizhalil.com/2026/05/21/kerberoasting-attack-defense-guide/
#CyberSecurity #ActiveDirectory #Kerberoasting #Kerberos #CredentialAccess #RedTeam #BlueTeam #Pentesting #WindowsSecurity #InfoSec #ThreatDetection #DenizHalil
-
Basic Active Directory Enumeration: A Comprehensive Guide
In this article, I cover how Kerberoasting works, common attack techniques, detection methods, and practical defense strategies.
https://denizhalil.com/2025/05/05/basic-active-directory-enumeration-a-comprehensive-guide/#CyberSecurity #ActiveDirectory #Kerberoasting #Kerberos #CredentialAccess #RedTeam #BlueTeam #Pentesting #WindowsSecurity #InfoSec #ThreatDetection #DenizHalil
-
What is Kerberoasting Attack – Kerberoasting: A Comprehensive Guide
In this article, I cover how Kerberoasting works, common attack techniques, detection methods, and practical defense strategies.
https://denizhalil.com/2026/05/21/kerberoasting-attack-defense-guide/#CyberSecurity #ActiveDirectory #Kerberoasting #Kerberos #CredentialAccess #RedTeam #BlueTeam #Pentesting #WindowsSecurity #InfoSec #ThreatDetection #DenizHalil
-
Catch me at CyberSec 2026 in Taiwan ! 🇹🇼 🧋
My colleague and I will be discussing the evolution of AI in the cybersecurity landscape. Is Gen AI replacing the analyst, or empowering them?🤖Join our session to see a live demonstration of how LLMs handle complex security analysis and how accuracy improves with expert feedback. Let’s connect and talk about the future of the SOC!
https://cybersec.ithome.com.tw/2026/session/4327
#CyberSec2026 #Cybersecurity #GenAI #BlueTeam #TaiwanTech #SOC #IncidentResponse