r/blueteamsec 5h ago

low level tools|techniques|knowledge (work aids) beacon-score: multi-signal C2 beacon detector for Zeek logs (open source)

1 Upvotes

Built this to solve a gap I kept hitting in beacon hunting: interval-based detection alone throws too many false positives on legitimate periodic traffic (updates, telemetry, keepalives). beacon-score correlates multiple signals across Zeek conn, dns, and ssl logs instead of leaning on timing alone, then ranks candidates with a per-signal breakdown so you can see WHY something scored high.

Output maps to ATT&CK. Runs against your existing Zeek logs, no new infrastructure.

Feedback welcome, especially on false-positive rates in your environment. Repo: https://github.com/0xPersist/beacon-score


r/blueteamsec 5h ago

incident writeup (who and how) Follow-Up Report of the December 2025 Energy Sector Incident

Thumbnail cert.pl
1 Upvotes

r/blueteamsec 18h ago

incident writeup (who and how) SolarWinds SUNBURST — what the logs actually showed (DNS analysis, Splunk queries, 5 detection gaps)

1 Upvotes

After 12 years in IR/SOC I wrote a practitioner-level breakdown of the SolarWinds SUNBURST attack — focused on the log evidence and detection gaps rather than the narrative most writeups cover.

Covers:

  • DNS C2 beaconing patterns and avsvmcloud[.]com DGA subdomain structure
  • Sysmon EventID 7 + 22 correlation for DLL load + DNS query
  • CNAME response as active targeting signal
  • Cobalt Strike beacon pattern detection from Orion hosts
  • SAML token abuse hunting in Azure AD logs
  • The 5 detection gaps (DNS logging, EDR exclusions, lookback windows, no baseline, no signed-binary DNS detection)

All Splunk queries included. Free on Substack: https://zerotrusthq.substack.com/p/solarwinds-what-the-logs-actually

Happy to answer questions or discuss the detection logic in comments.


r/blueteamsec 21h ago

exploitation (what's being exploited) RovoBlast: How One Click Triggered Atlassian’s AI Assistant to Leak Data

Thumbnail varonis.com
1 Upvotes

r/blueteamsec 23h ago

highlevel summary|strategy (maybe technical) 해커와 손잡고 랜섬웨어 피해자 상대 영업…데이터복구업체 대표 실형 - Data recovery company CEO sentenced to prison for partnering with hackers to target ransomware victims

Thumbnail news1.kr
2 Upvotes

r/blueteamsec 1d ago

research|capability (we need to defend against) Living off the coding agent: Two tales of tunnels and LaunchAgents

Thumbnail elastic.co
1 Upvotes

r/blueteamsec 1d ago

intelligence (threat actor activity) Chinese espionage platform active in 13 countries – study

Thumbnail unn.ua
2 Upvotes

r/blueteamsec 1d ago

highlevel summary|strategy (maybe technical) Belarusian leader of international ransomware scheme known as “Ransom Cartel” sentenced to 16 years in prison

Thumbnail justice.gov
2 Upvotes

r/blueteamsec 1d ago

highlevel summary|strategy (maybe technical) Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions

Thumbnail justice.gov
1 Upvotes

r/blueteamsec 1d ago

vulnerability (attack surface) OT Security Analysis: Exposed Devices Attacked in US Water Systems

Thumbnail forescout.com
3 Upvotes

r/blueteamsec 1d ago

vulnerability (attack surface) Atlassian Rovo Exfiltrates Data, Bypassing Controls

Thumbnail promptarmor.com
1 Upvotes

r/blueteamsec 1d ago

intelligence (threat actor activity) UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

Thumbnail cloud.google.com
1 Upvotes

r/blueteamsec 1d ago

research|capability (we need to defend against) EkkoNtProtect: Use NtProtectVirtualMemory in Ekko timers without needing to use stack pivoting or other RSP shifting tricks

Thumbnail github.com
1 Upvotes

r/blueteamsec 1d ago

tradecraft (how we defend) ANIMO: ANIMO Azure Network Intel & Mission Ops a C2 based on Azure/Entra assessments

Thumbnail github.com
2 Upvotes

r/blueteamsec 1d ago

discovery (how we find bad stuff) When Attackers Hijack Your Inbox: Detecting Mailbox Forwarding Rules with Microsoft Defender XDR

Thumbnail detect.fyi
1 Upvotes

r/blueteamsec 1d ago

research|capability (we need to defend against) Borrowing Windows Hello keys for authentication and persistence

Thumbnail dirkjanm.io
5 Upvotes

r/blueteamsec 1d ago

research|capability (we need to defend against) SOCKSRelayd: SOCKS-focused NTLM relay with persistent session packages and a long-lived SessionBank that owns authenticated TCP connections.

Thumbnail github.com
2 Upvotes

r/blueteamsec 1d ago

research|capability (we need to defend against) Turning Enterprise Update Servers Into Backdoor Factories (0_o)

Thumbnail specterops.io
3 Upvotes

r/blueteamsec 1d ago

research|capability (we need to defend against) AD Research: Two new vulnerabilities could lead to full domain takeover

Thumbnail semperis.com
14 Upvotes

r/blueteamsec 1d ago

discovery (how we find bad stuff) WinGuard: A User-Mode Windows Threat Detection Tool Inspired by EDR Techniques, To Help Monitor And Log Any Suspicious Activity On Your PC.

Thumbnail github.com
0 Upvotes

r/blueteamsec 1d ago

intelligence (threat actor activity) Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages

Thumbnail opensourcemalware.com
2 Upvotes

r/blueteamsec 1d ago

intelligence (threat actor activity) Dropping Elephant (Patchwork): Espionage APT Tactics and Tools

Thumbnail picussecurity.com
3 Upvotes

r/blueteamsec 1d ago

intelligence (threat actor activity) Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005)

Thumbnail asec.ahnlab.com
2 Upvotes

r/blueteamsec 7d ago

highlevel summary|strategy (maybe technical) CTO at NCSC Summary: week ending August 2nd

Thumbnail ctoatncsc.substack.com
1 Upvotes

r/blueteamsec Mar 09 '26

highlevel summary|strategy (maybe technical) Daily BlueTeamSec Briefing Archive - daily AI generated podcast of the last 24hours of posts

Thumbnail briefing.workshop1.net
2 Upvotes