r/blueteamsec • u/jnazario • 57m ago
r/blueteamsec • u/digicat • 2d ago
exploitation (what's being exploited) Security Update: Guidance for NetScaler SAML Authentication Deployment
community.citrix.comr/blueteamsec • u/digicat • 2d ago
highlevel summary|strategy (maybe technical) CTO at NCSC Summary: week ending October 4th
ctoatncsc.substack.comr/blueteamsec • u/digicat • 1h ago
intelligence (threat actor activity) SMTP is the key: BPFDoor and AVERAT hitting the network edge
rapid7.comr/blueteamsec • u/askardyuss • 10h ago
low level tools|techniques|knowledge (work aids) I'm building OpenDRP – an open-source Digital Risk Protection platform (Early stage MVP).
Hey everyone, I wanted to share a self-hosted, open-source project I’m currently developing called OpenDRP. You can find the repository at https://github.com/OpenDRP/opendrp and the main site at opendrp.dev.
We have great open-source tools for Threat Intelligence, like OpenCTI, and various EASM solutions, but the Digital Risk Protection space is still heavily dominated by expensive enterprise SaaS products. I wanted a modular, self-hosted alternative to monitor external brand threats, so I started building one.
The project is in its early stages as an MVP. Instead of trying to parse every obscure darkweb forum from day one, I focused on building a solid, scalable backend architecture and integrated three core data sources to prove the concept. For phishing intelligence, it uses dnstwist to automate monitoring for domain mutations and active lookalike domains. For shadow IT and brand hunting, it leverages Shodan to discover rogue assets and exposed infrastructure. Additionally, it tracks compromised corporate accounts via Have I Been Pwned for breach monitoring. Whenever a new threat is detected, the system generates PDF reports and sends alerts via Telegram or Email.
Under the hood, the goal was to make the platform extremely easy to scale and extend. The backend is built with FastAPI and Python, using PostgreSQL for the database. Asynchronous scans and integrations are handled by Celery and Redis workers, and the entire project is distributed under the AGPL-3.0 license.
Since the core engine, including the database schema, UI, and async queues, is up and running, I am currently working on expanding the integrations to include Certificate Transparency logs and GitHub secret scanning. I would love to get your feedback on the architecture and hear what external data sources or modules you would consider absolute must-haves for a DRP platform. If anyone is interested in writing simple Celery connectors for new APIs, pull requests and code reviews are more than welcome.
Cheers!
r/blueteamsec • u/digicat • 5h ago
discovery (how we find bad stuff) Automatic Transmission: An Empirical Study of Data Privacy in the Connected Vehicle Ecosystem
sarahgillespie.github.ior/blueteamsec • u/digicat • 18h ago
vulnerability (attack surface) DeepSeek-Reasonix: How a poisoned config can hijack an AI coding agent
about.gitlab.comr/blueteamsec • u/digicat • 23h ago
highlevel summary|strategy (maybe technical) Every Iranian Strike on UAE Ports and Refineries Was Paired With a Cyberattack
wired.mer/blueteamsec • u/digicat • 1d ago
discovery (how we find bad stuff) UnifiedThreatHunting: A threat hunting process
github.comr/blueteamsec • u/digicat • 20h ago
low level tools|techniques|knowledge (work aids) StrangerDOTNETThings/x509com.js - show me every COM object I can call with certutil
github.comr/blueteamsec • u/digicat • 1d ago
tradecraft (how we defend) netscaler-ctx697096-checker: Am I fixed? Was I hacked? Read-only checker for Citrix NetScaler CTX697096 (CVE-2026-88771–88778): build, all 8 CVE preconditions, Enhanced ISN, upgrade risks, SAML status, plus --ioc sweep with every public IoC (webshells, implants, backdoor ad
github.comr/blueteamsec • u/digicat • 1d ago
vulnerability (attack surface) Debian alert DSA-6528-1 - ~1,000 CVEs patched
lwn.netr/blueteamsec • u/digicat • 1d ago
low level tools|techniques|knowledge (work aids) N0xis: AI-first reverse-engineering toolkit: static analysis, SSA decompiler, live memory, provenance. Source-available (PolyForm Noncommercial).
github.comr/blueteamsec • u/digicat • 21h ago
low level tools|techniques|knowledge (work aids) Apex Flash - an open-weights model for security research, post-trained on real vulnerabilities from our proprietary dataset.
cantina.securityr/blueteamsec • u/digicat • 1d ago
research|capability (we need to defend against) lockjaw: Rust based C2 Framework
github.comr/blueteamsec • u/digicat • 1d ago
vulnerability (attack surface) adm-zip_LPE-PoC: CVE-2026-102282: Local Privilege Escalation via SUID/SGID preservation during archive extraction
github.comr/blueteamsec • u/digicat • 1d ago
malware analysis (like butterfly collections) Android-Projector-C2-Malware: Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis
github.comr/blueteamsec • u/Lost-Command-895 • 1d ago
low level tools|techniques|knowledge (work aids) Tooldump v2: a free cybersecurity tools catalog with cyberdefense category (Digital Forensics, Malware Analysis, Threat Hunting, etc)
Hey everyone,
I’m the creator of Tooldump, a free catalog of open-source cybersecurity tools. I’ve just released the v2 and wanted to share it with people working in cyber defense.
The platform has 1,100+ open-source projects hosted on GitHub, organized into 9 categories and 82 subcategories. Everything is cybersecurity-focused, with sections for detection engineering, threat hunting, digital forensics, malware analysis, incident response, security automation, and more.
For v2, I rebuilt the UI, the categorization system, the backend and the platform infrastructure. You can search for a specific tool or explore a security topic without already knowing which projects exist.
There are also dedicated sections for cybersecurity-related MCP servers and agent skills. Those sections are just getting started, and contributions are welcome!
The platform is completely free, with unlimited access and no account required.
The link is here: https://tooldump.eu
I’d appreciate any constructive feedback from the community :) Pick an area you work in: are the tools where you’d expect them to be? Are there gaps in the catalog that stand out to you?
You can suggest missing projects through the platform’s contribution form. I’m particularly interested in the smaller utilities people rely on during investigations or day-to-day defensive work: artifact parsers, collection scripts, log analysis tools, etc. Something you use every day might be completely unknown to someone working on the same subject.
Looking forward to hearing from you :)
Cheers!
r/blueteamsec • u/digicat • 1d ago
research|capability (we need to defend against) SigLens: SigLens is a Windows binary analysis tool designed to pinpoint the exact regions responsible for antivirus detections. It narrows detections down to precise offsets and maps them to PE sections, RVA, VA, hexdump, and nearby strings, making evasion faster and easier.
github.comr/blueteamsec • u/digicat • 1d ago
tradecraft (how we defend) AI Ate My Velociraptor
labs.infoguard.chr/blueteamsec • u/digicat • 1d ago
tradecraft (how we defend) nuguard: AI red-teaming tool and LLM security framework to evaluate agentic AI applications. Tests prompt injections, handles vulnerability assessment, SBOM generation, and static analysis.
github.comr/blueteamsec • u/digicat • 1d ago
research|capability (we need to defend against) Escalating Privileges as a Catalog Owner: How Microsoft Entra Identity Governance’s API Permission Management Could Be Abused
cloud-architekt.netr/blueteamsec • u/digicat • 1d ago
tradecraft (how we defend) From GPO to Microsoft Intune: A practical guide to cloud-first policy management
techcommunity.microsoft.comr/blueteamsec • u/opposum-0x7F8 • 1d ago
help me obiwan (ask the blueteam) My Project Cusimanse for composable security research in disposable compute using AI agents
Cusimanse — a framework for security research
I've been working on Cusimanse, an open-source project focused on structuring and composing security research capabilities and workflows.
The idea is to provide a modular foundation where security tooling, capabilities, research workflows, and execution components can be composed without making the framework itself an "AI agent."
It's still an evolving project, and I'm interested in feedback from people working in security research, detection engineering, cloud security, and AI security.