#defensivesecurity — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #defensivesecurity, aggregated by home.social.
-
#PanelDiscussion
Adversary Village at @defcon 34!
Join Adam Pennington (ATT&CK Lead, @mitreattack), Sarah Hume (Purple Team Service Lead, Security Risk Advisors), Cheryl Biswas (Threat Intel Specialist), and Olaf Hartong (Defensive Specialist, FalconForce) for the panel discussion “From Threat-Intel to Tested Defense, the Adversary Simulation Playbook” on 7 Aug 2026 at DEF CON Creator Stage 3.
Adversary Village schedule:
https://adversaryvillage.org/adversary-events/DEFCON-34/
#AdversaryVillage #DEFCON34
#PanelDiscussion #ThreatIntelligence #AdversarySimulation
#PurpleTeam #DefensiveSecurity -
The cybersecurity certification landscape
https://negativepid.blog/the-cybersecurity-certification-landscape/#defensiveSecurity #threatHunting #forensics #offensiveSecurity #ethicalHacking #cybersecurityCareers #cybersecurityCerts #certifications #Cybersecurity #ITcareers #onlineSecurity #negativepid
-
The cybersecurity certification landscape
https://negativepid.blog/the-cybersecurity-certification-landscape/#defensiveSecurity #threatHunting #forensics #offensiveSecurity #ethicalHacking #cybersecurityCareers #cybersecurityCerts #certifications #Cybersecurity #ITcareers #onlineSecurity #negativepid
-
https://podverse.fm/episode/S224ePoTN Great episode #defensivesecurity podcast , no I’m not advertising Podverse it’s just what I use.
-
The decades-old Finger protocol is being abused in new ClickFix malware campaigns. Attackers are using Finger to pull remote commands onto Windows systems, leading to Python-based malware or NetSupport RAT infections. Newer variants even check for analysis tools before execution.
Anyone else seeing Finger traffic or legacy protocol misuse recently?
Follow for more updates.#Malware #ClickFix #InfoSec #ThreatIntel #WindowsSecurity #CyberSecurity #RAT #LegacyProtocols #DefensiveSecurity
-
📋 Server Security Checklist — Essential Hardening Guide 🛡️
Securing servers is critical to protect sensitive data, applications, and networks. Here’s a quick checklist every sysadmin and security engineer should follow to reduce risk and strengthen resilience. ⚡🔐
1️⃣ System & OS Hardening
🔹 Keep OS and packages updated (apply patches regularly).
🔹 Remove or disable unused services & software.
🔹 Configure secure boot and BIOS/UEFI passwords.2️⃣ Access Control
🔹 Enforce strong passwords + MFA for all accounts.
🔹 Use role-based access (least privilege).
🔹 Disable root/administrator login over SSH/RDP.3️⃣ Network Security
🔹 Restrict inbound/outbound traffic with firewalls.
🔹 Segment critical servers from general networks.
🔹 Disable unused ports & protocols.4️⃣ Secure Remote Access
🔹 Use SSH with key-based auth (disable password logins).
🔹 Enforce VPNs for admin access.
🔹 Monitor and log remote sessions.5️⃣ Logging & Monitoring
🔹 Enable centralized logging (syslog/SIEM).
🔹 Monitor failed login attempts & unusual activity.
🔹 Configure alerts for critical events.6️⃣ Data Protection
🔹 Encrypt sensitive data at rest & in transit (TLS, disk encryption).
🔹 Regularly back up data to secure, offline storage.
🔹 Apply strict database access policies.7️⃣ Application & Patch Management
🔹 Keep middleware, frameworks, and apps patched.
🔹 Remove default credentials and sample configs.
🔹 Use secure coding practices.8️⃣ Malware & Intrusion Defense
🔹 Deploy antivirus/EDR for endpoints.
🔹 Enable IDS/IPS at the network edge.
🔹 Scan regularly for vulnerabilities.9️⃣ Physical & Cloud Security
🔹 Restrict physical access to server rooms.
🔹 Harden cloud instances with provider tools (security groups, IAM).
🔹 Regularly review cloud audit logs.🔟 Policy & Compliance
🔹 Apply CIS/NIST benchmarks.
🔹 Document access, configs, and changes.
🔹 Train admins in security best practices.#ServerSecurity #CyberSecurity #InfoSec #BlueTeam #SysAdmin #ITSecurity #SecurityChecklist #DefensiveSecurity
-
🔐 Cybersecurity isn’t one-dimensional.
Defensive: firewalls, antimalware, access control.
Offensive: pentesting, Red Teaming, exploit testing.
Hybrid: incident response, disaster recovery, threat intel.
At RELIANOID, we combine these layers to keep organizations resilient in a fast-changing threat landscape. 🛡️
#Cybersecurity #DefensiveSecurity #OffensiveSecurity #HybridSecurity #RELIANOID
https://www.relianoid.com/resources/knowledge-base/misc/key-concepts-in-cybersecurity-defensive-offensive-and-hybrid-approaches/ -
A HUGE thank you to Mental Health Hacker's first PLATINUM sponsor, @blumirasec
This will enable us to bring even MORE to the @blueteamvillage
this year! Our partnership with BTV will enable us to help bring resources, content, and giveaways at @defcon this year! See ya'll soon!!A Security Tool Your IT Team Can Actually Use
Blumira simplifies cybersecurity by combining ease of use with powerful protection. We enable teams big and small to defend effectively.
#defcon #defcon33 #blueteam #defensivesecurity #siem #mentalhealth
-
The Silent Superpower – Cybercrime in 2025
https://youtu.be/Kq5KaE1wAkU #cybersecurity #cybercrime #ransomware #malware #riskmanagement #defensivesecurity -
It took until the Second Edition, but now the audiobook version of The Defensive Security Handbook has been released!!
Share with your friends, your co-workers, your leadership, family that you kind of like, etc
#newrelease #secondedition #defensivesecurity #infosec #audiobook #cybersecurity
-
🔐 Cybersecurity Essentials: In this diagram, we help you understand the key cybersecurity approaches needed for resilience.
At RELIANOID, we support organizations by monitoring and securing all these layers in a dynamic threat landscape. 🛡️
#Cybersecurity #DefensiveSecurity #OffensiveSecurity #HybridApproach #Firewall #Antimalware #AccessControl #DataLossPrevention #PenetrationTesting #RedTeaming #DisasterRecovery #ThreatIntelligence #RELIANOID #DataProtection
-
Riding the AI Waves: The Rise of Artificial Intelligence to Combat Cyber Threats
https://thehackernews.com/2024/01/riding-ai-waves-rise-of-artificial.html #cybersecurity #AI #defensivesecurity -
Cobalt Strike, a Defender’s Guide: https://thedfirreport.com/2021/08/29/cobalt-strike-a-defenders-guide/
-
#Kali #Linux 2023.1 Release ( #KaliPurple & Python Changes) | Kali Linux Blog
Over the years, we have perfected what we have specialized in, offensive #security. We are now starting to branch into a new area, defensive security! We are doing an initial technical preview pre-launch of “Kali Purple”. This is still in its infancy and is going to need time to mature.
#DefensiveSecurity -
The Locksmith Active Directory (AD) Certificate Services (CS) remediation tool has been updated: https://github.com/TrimarcJake/Locksmith
New features:
- Support for Restricted Admin Mode. If RAM is detected, Locksmith will ask to be re-run using the -Credential switch.
- If the AD Powershell module is not installed on Win 10/11, Locksmith will attempt to install it for you.
Note: previously only available on server-class OSes.
- New functions for checking user type and elevation status.
- Auto-generated snippets for ownership issues (a subset of ESC4/ESC5).
- Support for non-English Active Directory environments!Next planned updates:
- Add individual CA Hosts to $SafeUsers using SIDs.
- Perform additional environment checks before attempting to run.
- Rename modes to something that makes sense.#IAM #IdentitySecurity #CertificateServices #ActiveDirectory #ActiveDirectoryCertificateServices #ADCS #PKI #Locksmith #OpenSource #DefensiveSecurity #DefensiveSecurityTooling #Pizza
-
@jerry @lerg Great to hear you guys finally doing another #DefensiveSecurity Podcast :) Thanks, it was a fun listen, and I hope you can keep it up !!
-
These are still my favorite capabilities in Defender for Cloud. But, one addition I haven't added yet is Defender for DevOps! More on that in a other post.
https://zimmergren.net/top-capabilities-in-microsoft-defender-for-cloud/
-
Locksmith has been updated: https://github.com/TrimarcJake/Locksmith
New features:
- Improved on-screen explanation of what the script is doing
- Improved output formatting
- Confirmation now required before the AD CS environment is changed
- If Locksmith changes your environment, a script is created to easily revert those changes.
- Less false positives
- If Active Directory module is not installed, Locksmith will attempt to install it for you.Next planned updates:
- Strict Mode support
- RDP Restricted Admin support#IAM #IdentitySecurity #CertificateServices #ActiveDirectory #ActiveDirectoryCertificateServices #ADCS #Locksmith #OpenSource #DefensiveSecurity #DefensiveSecurityTooling #Pizza
-
Just found this #OpenBSD based project:
Still in alpha testing !
Contributors needed...
#BSD #infosec #floss #opensource #cybersécurité #testdintrusion #pentesting #privacy #hacking #FullDiskEncryption #BugHunters #cybersecurity #SecurityResearchers #OffensiveSecurity #DefensiveSecurity
-
Another #DefensiveSecurity podcast, another time I have to call out @jerry on not mentioning the Fediverse along with birdsite at the end. :P
-
Catching up on #DefensiveSecurity podcast; great Sunday listening. Although still annoyed by @jerry not mentioning his Mastodon account when mentioning his birdsite account...
-
So, just listened to the newest episode of the #DefensiveSecurity podcast.
One of the topics touched on was WannaCry/NotPetia - it's been over a year since they hit, and @jerry made some good points about why these infections keep happening (have a listen, worth it!).
But one thing I felt was sorely missing: the way three-letter-agencies basically made us all less secure. EternalBlue, after all, was #NSA's tool that got leaked.
US CERT budget: ~$93mln
NSA official budget: ~$10bln -
Hey @jerry, I really enjoy your #DefensiveSecurity podcast and appreciate the insights there. One thing though -- why do you guys advertise your birdsite accounts, but never mention your Fediverse presence?
I mean, wouldn't it be worthwhile to boost the Fediverse a bit with the kind of platform you have? Perhaps some of your listeners are here but don't even know you are?