Explorez tous les épisodes du podcast Blueprint: Build the Best in Cyber Defense
| Titre | Date | Durée | |
|---|---|---|---|
| Redefining Security Operations: Lessons in AI Integration with James Spiteri | 12 Jun 2025 | 01:07:57 | |
Click here to send us your ideas and feedback on Blueprint! In this episode of Blueprint, host John Hubbard sits down with James Spiteri from Elastic to explore the transformative power of AI on the SOC. They delve into how advanced AI technologies, such as agentic AI models, MCP protocol, and automation, are reshaping the SOC landscape. Discover how AI enhances SOC efficiency, reduces mundane tasks, and integrates context-aware capabilities. Learn about the real-world applications, from automation in cybersecurity operations to the challenges and promises of large language models. This discussion covers the ethical considerations, potential risks, and the promising future of SOCs powered by AI. Tune in to get inspired and see how AI might revolutionize your cyber defense strategies. Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| From Special Forces to Cybersecurity: Rich Greene on Communication and Persuasion in Infosec | 09 Apr 2025 | 00:48:25 | |
Click here to send us your ideas and feedback on Blueprint! In this episode, we sit down with Rich Greene, a former United States Army Special Forces Green Beret and current SANS instructor for SEC275 and SEC301. Rich shares his incredible journey spanning 20 years in the Army, including his transition from military communication roles into the realm of cybersecurity. He talks about the importance of fundamentals in cybersecurity, the power of effective communication and persuasion, and dispels common misconceptions about entering the cyber field. Rich also highlights his passion for teaching and how his military background has shaped his approach to instruction and information security. Tune in for invaluable advice that applies to anyone no matter your role!. Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Strategy 9: Communicate Clearly, Collaborate Often, Share Generously | 05 Jul 2023 | 01:04:47 | |
Click here to send us your ideas and feedback on Blueprint! "Research has shown that communication is one of the most important factors for success in security incident response teams. In this chapter, the authors discuss the critical types of information that must be shared within the SOC, with the constituency, and with the greater cybersecurity community. Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Strategy 8: Leverage Tools and Support Analyst Workflow | 26 Jun 2023 | 01:26:49 | |
Click here to send us your ideas and feedback on Blueprint! Tool choice can be a make-or-break decision for security analysts, driving whether getting work done is a struggle, or an efficient, stress-free experience. How can we select the right tools for the job? Which tools are most important? Answers to these questions and more are in this week's episode of Blueprint! Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Blueprint Live at the SANS Blue Team Summit 2023 | 22 Jun 2023 | 01:05:54 | |
Click here to send us your ideas and feedback on Blueprint! In this special live recording from the SANS Blue Team Summit 2023, Kathryn Knerler, Ingrid Parker, and Carson Zimmerman joined John Hubbard they share their insights and expertise with attendees by answering their pressing questions. From discussing the most effective strategies for building a successful SOC to sharing tips on how to stay ahead of emerging cyber threats, our guests provide invaluable advice for those who work in a security operations center (SOC). If you're looking to take your SOC to the next level or are simply interested in the latest developments in cybersecurity, this episode is a must-listen. Tune in to hear from some of the most respected experts in the field and gain valuable insights that could make all the difference in how you approach cybersecurity. Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Strategy 7: Select and Collect the Right Data | 19 Jun 2023 | 01:04:27 | |
Click here to send us your ideas and feedback on Blueprint! There's no denying that the average security team is completely overwhelmed with options for data to collect. With a deluge of endpoint, network, and cloud data sources to collect, how to do we identify and collect the most useful data sources? That's the topic of this episode. Join Kathryn, Ingrid, Carson, and John in this episode for a discussion on tactical data collection that will ensure your team doesn't miss the signs of an impending incident! Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Strategy 6: Illuminate Adversaries with Cyber Threat Intelligence | 12 Jun 2023 | 00:58:56 | |
Click here to send us your ideas and feedback on Blueprint! Every security team has limited budget and time, how do you know where to focus? Cyber Threat Intelligence provides those answers! In this episode, Ingrid, Carson and Kathryn describe how we can use CTI to focus our defensive efforts to understand our most likely attacks and attackers and move towards prioritizing what truly matters. Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Strategy 5: Prioritize Incident Response | 05 Jun 2023 | 01:26:32 | |
Click here to send us your ideas and feedback on Blueprint! No security team is perfect, so in this episode, authors Carson, Ingrid, and Kathryn discuss what it takes to prepare for fast, effective incident response capability. Covering preparation, planning and execution, Strategy 5 will teach your team how to jump into action at the earliest sign of problems. Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Strategy 4: Hire AND Grow Quality Staff | 29 May 2023 | 01:14:42 | |
Click here to send us your ideas and feedback on Blueprint! In this episode we dive deep on the "People" factor of the SOC. Who should you hire, what skills should you hire for, what backgrounds are most likely to lead to success for your team? We also get into what happens after the hire - training, growth, and supporting your team in their skill and career development. This one is a must-listen for all the managers out there. We're all trying to build the highest skilled, most supportive team with low turnover, and the tips our authors bring to this episode on chapter 4 - "Hire AND Grow Quality Staff" will be crucial in that mission. Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Strategy 3: Build a SOC Structure to Match Your Organizational Needs | 22 May 2023 | 01:13:11 | |
Click here to send us your ideas and feedback on Blueprint! In this episode we discuss how to decide on the right org structure and capabilities of your SOC. This includes questions like tiered vs. tierless models, which capabilities the SOC should focus on, centralized vs. distributed SOCs, outsourcing of duties and staff augmentation considerations, and also where the SOC might sit in the larger chart of your organization. Every SOC needs to be tailored to best meet the mission, and chapter 3 - "Build a SOC Structure to Match Your Organizational Needs" will help you get there. Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Strategy 2: Give the SOC the Authority to Do Its Job | 15 May 2023 | 00:38:02 | |
Click here to send us your ideas and feedback on Blueprint! Though a SOC is responsible for protecting your organization's assets, it is not the owner of those systems. If the SOC is not established with a clear charter and authority to act, it may quickly become difficult to be effective. Who should the SOC report to, what should be in a SOC charter, and how can we make these tough decisions? Those are the questions covered in this episode of our special "11 Strategies" season. This episode covers chapter 2 of the book - "Give the SOC the Authority to Do Its Job". Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Strategy 1: Know What You Are Protecting and Why | 08 May 2023 | 01:03:21 | |
Click here to send us your ideas and feedback on Blueprint! As the saying goes, "If you don't know where you're going, any road will take you there!" - an approach that is disastrous to a SOC. In order to succeed, the SOC must have a clear understanding of where they are going, how they're going to get there, and why. In this episode of our "11 Strategies" season we discuss chapter 1 of the book - "Know What You're Protecting and Why". Understanding your organization and the environment the SOC must perform in forms the foundation of all security team activity. In this episode the authors discuss the critical aspects of knowing what you're protecting. This includes consider your organization's mission, the legal, regulatory, and compliance environment, the technical capabilities you may or may not have, and the users that will inhabit the network and the actions they're going to be performing. Understanding these factors ensures your team starts off on the right path and keeps a common goal in view. Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| SOC Dashboards Done Right with Ryan Thompson | 18 Feb 2025 | 01:03:02 | |
Click here to send us your ideas and feedback on Blueprint! In this episode, we sit down with Ryan Thompson, a seasoned expert in building dashboards that actually detect real threats—not just look pretty. With experience at Elastic, Alert Logic, and top EDR vendors, Ryan shares deep insights into the science behind effective dashboards and how security teams can cut through the noise to find the threats on your network. We cover:
If you’re a SOC analyst, detection engineer, or security leader looking to elevate your dashboard game and sharpen your cyber threat detection skills, this is an episode you won’t want to miss! Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| 11 Strategies of a World-Class Security Operations Center: Fundamentals | 08 May 2023 | 00:56:26 | |
Click here to send us your ideas and feedback on Blueprint! Welcome to a brand new season of Blueprint! In this intro episode we discuss "Fundamentals" chapter of the "11 Strategies of a World Class Cybersecurity Operations Center" with the authors. We get into the motivation behind updating the book and why its lessons are more important than ever in 2023. This chapter includes discussion of the functions of a SOC, basics of workflow, CTI and contextual data sources, and why ops tempo and speed is a critical factor in SOC success. Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Get Ready, A Very Special Season 4 Is On the Way! | 01 May 2023 | 00:03:53 | |
Click here to send us your ideas and feedback on Blueprint! Hello Blueprint listeners! We’re excited to announce that the release of season 4 of Blueprint is just around the corner, and we’ve got something very special cooked up for you. We’ve teamed up with the authors of MITRE’s “11 Strategies of a World-Class Cybersecurity Operations Center” and over the next few months, we’ll be releasing episodes walking through each chapter with all 3 authors! We’ll be deep diving into what makes a SOC successful, get a first-hand account of why each strategy was chosen, and practical advice on each how to implement each strategy along the way. Join Blueprint host John Hubbard with authors Kat Knerler, Ingrid Parker, and Carson Zimmerman for this exciting new season, coming to your podcast aggregator on May 8th! Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Brandon Evans: Cloud Security - Threats and Opportunities | 13 Sep 2022 | 00:50:46 | |
Click here to send us your ideas and feedback on Blueprint! Ever wonder how a cloud and application security expert views risks of cloud workloads? Well, wonder no more because on this episode we have Brandon Evans - SANS Certified Instructor and lead author of SEC510: Public Cloud Security. We cover the why and how of moving their applications to the cloud, the key considerations for a successful cloud security posture, and how building your infrastructure with a cloud-native mindset can and should lead to an improved security posture. Our Guest - Brandon Evans Brandon works for Zoom Video Communications, in which he leads their internal Application Security training. As an application developer for most of his professional career, he moved into security full-time largely because of his many formal trainings through SANS. He’s a contributor to the OWASP Serverless Top 10 Project and a co-leader for the Nashville OWASP chapter. Brandon is lead author for SEC510: Public Cloud Security: AWS, Azure, and GCP and a contributor and instructor for SEC540: Cloud Security and DevSecOps Automation. Sponsor's Note: Support for the Blueprint podcast comes from the SANS Institute. If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals. This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career. Check out the details at sansurl.com/450 Hope to see you in class! Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube Follow John Hubbard: Twitter | LinkedIn Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Joe Lykowski: Building a Transparent, Data-Driven SOC | 06 Sep 2022 | 00:56:17 | |
Click here to send us your ideas and feedback on Blueprint! In this episode we speak with Joe Lykowski - Cyber Defense Lead at a major manufacturing company on what it takes to build a mature, transparent, and effective SOC. Joe brings years of experience to the table in running a large organization’s security team and in this interview he draws out some of his favorite tips, strategies and more on metrics, building the right team, and what to prioritize as you build up a SOC for an org of any size. Follow Joe on Twitter: @JosephLykowski
Support for the Blueprint podcast comes from the SANS Institute. If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals. This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career. Check out the details at sansurl.com/450 Hope to see you in class! Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube Follow John Hubbard: Twitter | LinkedIn Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Rob Lee: Training and Reskilling in Cyber Security | 30 Aug 2022 | 00:51:53 | |
Click here to send us your ideas and feedback on Blueprint! Many of us are either looking to start a cyber security career, improve our knowledge and skills to further our career, or hire a team that has the most skilled and promising candidates. In this special episode with Rob Lee, Chief Curriculum Director of the SANS Institute, we discuss strategies for building, improving, and testing your cyber security group’s skill levels, and working to keep our knowledge as current as possible - a critical skill for anyone in the fast moving world of cyber security. Rob Lee is the Chief Curriculum Director and Faculty Lead at SANS Institute and runs his own consulting business specializing in information security, incident response, threat hunting, and digital forensics. With more than 20 years of experience in digital forensics, vulnerability and exploit discovery, intrusion detection/prevention, and incident response, he is known as “The Godfather of DFIR”. Rob co-authored the book Know Your Enemy, 2nd Edition, and is course co-author of FOR500: Windows Forensic Analysis and FOR508: Advanced Incident Response, Threat Hunting, and Digital Forensics. Sponsor's Note: Support for the Blueprint podcast comes from the SANS Institute. If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals. This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career. Check out the details at sansurl.com/450 Hope to see you in class! Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube Follow John Hubbard: Twitter | LinkedIn Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Jaron Bradley: Securing Enterprise macOS | 23 Aug 2022 | 00:59:47 | |
Click here to send us your ideas and feedback on Blueprint! In this episode of the Blueprint Podcast, we cover monitoring and securing macOS in an enterprise environment at scale with Jaron Bradley, Threat Detection lead at Jamf. We discuss the ups and downs of Apple's approach to macOS data collection over the years, the data sources and types that are accessible to defenders, what 3rd party agents bring to the table for security monitoring, and much more. Plus, Jaron gives us some great bonus tips for finding persistence mechanisms and malicious processes in enterprise macOS devices. Jaron has a background in Incident Response, threat hunting, and detections development. After focusing on large scale APT attacks he developed an interest in the more niche spaces of lesser explored operating systems. He has experience as both a SOC analyst as well as detections engineering at the endpoint level.Jaron currently works as the macOS Detections Lead at Jamf Threat Labs and manages his own security tools and content for security researchers atthemittenmac.com. He is also the author of OS X Incident Response Scripting and Analysis. A book he claims is slightly outdated but still relevant to a lot of macOS analysis today. Resources mentioned in this episode
Conferences
Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Alexia Crumpton: MITRE ATT&CK for Defenders | 16 Aug 2022 | 00:43:36 | |
Click here to send us your ideas and feedback on Blueprint! One of the best frameworks that showed up within the last 5 or so years is undoubtedly the MITRE ATT&CK® framework. Many of us may know about it in passing and even reference from time to time, but very few people seem to know the true depth of knowledge contained - everything from analytics to threat groups, specific mitigation and detection opportunities, and with the newest versions, even specific data sources. In this episode we talk to the Defensive Lead of ATT&CK from MITRE, Lex Crumpton, about what every blue team member needs to know about this framework, and more! Alexia Crumpton is a Defensive Cyber Operations Researcher with over seven years of experience in software development, SOCs, and Malware Reverse Engineering. Her passion lies in heuristic behavior analysis in regards to adversary TTPs and countermeasures used to defend against them. Follow Alexia LinkedIn: https://www.linkedin.com/in/alexia-crumpton-99930659/ Resources mentioned in this episode:
Support for the Blueprint podcast comes from the SANS Institute. If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals. This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need t Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Cat Self: macOS and Linux Security | 09 Aug 2022 | 00:57:42 | |
Click here to send us your ideas and feedback on Blueprint! Ever wonder why there’s so little information regarding macOS and Linux-oriented attacks? In this episode, we get the answer from the multi-talented Cat Self - an Adversary Emulation Engineer at MITRE, Cyber Threat Intelligence Team Leader on ATT&CK Evaluations and macOS/ Lead on MITRE ATT&CK Enterprise. We discuss defense tools, attacker TTPs, and what to consider when approaching defense for a macOS and Linux environment, and what trends we can expect in the future for these operating systems. Check out the resources below for links mentioned during this enlightening conversation! Cat Self is the CTI Lead for MITRE ATT&CK® Evaluations, macOS/Linux Lead for ATT&CK® and serves as a leader of people at MITRE. Cat started her cyber security career at Target and has worked as a developer, internal red team operator, and Threat Hunter. Cat is a former military intelligence veteran and pays it forward through mentorship, technical macOS hunting workshops, and public speaking. Outside of work, she is often planning an epic adventure or climbing mountains in foreign lands. Follow Cat on Social Media Twitter: @coolestcatiknow LinkedIn: Cat Self Resources mentioned in this episode: https://www.sentinelone.com/blog/apples-macos-ventura-7-new-security-changes-to-be-aware-of/
For securing a macOS device, I highly recommend installing Patrick Wardle’s endpoint tools. https://objective-see.org/tools.html My favorites are BlockBlock, KnockKnock, Lulu, & Netiquette.
Cat's “GoTo” blogs Patrick Wardle Objective-See Jaron Bradley The Mitten Mac Howard Oakley The Eclectic Light Company Cody Thomas Medium Sarah Edwards mac4n6 Leo Pitt Medium Christopher Ross Medium Csaba Fitzl THEEVILBIT Blog
Open Source Projects Playbooks with Datasets to practice OTRF Code snippets aligned to MITRE ATT&CK Atomic Red Team Jupyter notebook environment setup by Anna Pastushko Virtual environment setup Hold My Beer Sponsor's Note: Support for the Blueprint podcast comes from the SANS Institute. If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host a Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Corissa Koopmans and Mark Morowczynski: Azure AD Threat Detection and Logging | 02 Aug 2022 | 00:48:35 | |
Click here to send us your ideas and feedback on Blueprint! Nearly every organization is using Microsoft Azure AD services in some respect, but monitoring Azure AD for threats is a significantly different skill that traditional Windows logging. In this episode we have 2 experts from Microsoft, Corissa Koopmans, and 3rd time returning guest Mark Morowczynski, to tell us about the important work that’s been done to help organizations understand their data and detect Azure AD attacks. We cover log sources, the new Microsoft security operations guide, standardized dashboards and visualizations you can leverage to jump right in with best practice, and much more. You don’t want to miss this one! Corissa Koopmans (@Corissalea) is part of the "Get to Production" team in the Microsoft Identity and Network Access Division, focusing on incorporating customer feedback to improve our products. She is very active in driving community contribution to AzureMonitor Log Analytics and increasing awareness of the power of log data by presenting at industry events including BSides, The Experts Conference (TEC), SPARK, & Microsoft MVP Summits. Azure AD SecOps - aka.ms/azureadsecops Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Tony Turner: Securing the Cyber Supply Chain | 26 Jul 2022 | 00:48:14 | |
Click here to send us your ideas and feedback on Blueprint! John and Fortress Vice President of Research and Development Tony Turner share their wisdom on trends they are seeing in the cyber industry and offer advice as to how we should be looking at the Cyber Supply Chain in 2022 and beyond. LinkedIn: https://www.linkedin.com/in/tonyturnercissp/ Web: https://www.fortressinfosec.com/team/tony-turner Sponsor's Note: Support for the Blueprint podcast comes from the SANS Institute. If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals. This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career. Check out the details at sansurl.com/450 Hope to see you in class! Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube Follow John Hubbard: Twitter | LinkedIn Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Success Simplified - The 3 Step Process for Hitting Your Career Goals in 2025 with John Hubbard | 01 Jan 2025 | 00:29:58 | |
Click here to send us your ideas and feedback on Blueprint! Surprise!! It's a mini solo episode to kick off the new year and it's on one of the most important topics there is - how to achieve your goals in 2025 and beyond!
Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Mark Orlando: Building a Stronger Blue Team | 19 Jul 2022 | 00:50:29 | |
Click here to send us your ideas and feedback on Blueprint! There are many technical factors that contribute to the success of a security operations team, but you need more than just tech skills for mounting a solid defense. In this episode of Blueprint we bring back previous guest Mark Orlando to talk about his BlackHat 2022 presentation with Dr. Daniel Shore (PhD in workplace psychology) . We discuss team dynamics, how the mapping of multi-team systems can improve the flow of your incident response activities, and much more. Mark Orlando is a SANS Associate Instructor, co-author MGT551: Building and Leading Security Operations Centers, instructor for SEC450: Blue Team Fundamentals: Security Operations and Analysis, and the Co-Founder and CEO of Bionic Cyber. Prior to Bionic, Mark built, assessed, and managed security teams at the Pentagon, the White House, the Department of Energy, and numerous Fortune 500 clients. Mark has presented on security operations and assessment at DefCon's Blue Team Village, the Institute for Applied Network Security (IANS) Forum, BSidesDC, and the RSA Conference and has been quoted in the New York Times, the Washington Post, Forbes, and many other publications. He holds a Bachelor's Degree in Advanced Information Technology from George Mason University and served in the US Marine Corps as an Artillery Non-Commissioned Officer.
Twitter: https://twitter.com/markaorlando LinkedIn: https://www.linkedin.com/in/marko16/ Web: https://www.sans.org/profiles/mark-orlando/ Sponsor's Note: Support for the Blueprint podcast comes from the SANS Institute. If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals. This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career. Check out the details at sansurl.com/450 Hope to see you in class! Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube Follow John Hubbard: Twitter | LinkedIn Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Blueprint Live at SANSFIRE 2022: A panel with Heather Mahalik, Katie Nickels and Jeff McJunkin | 14 Jul 2022 | 00:59:54 | |
Click here to send us your ideas and feedback on Blueprint! Host John Hubbard, Blueprint host and SANS Cyber Defense Curriculum Lead, moderated a panel of cyber security experts including Heather Mahalik, Katie Nickels and Jeff McJunkin for this powerful discussion. Sponsor's Note: Support for the Blueprint podcast comes from the SANS Institute. If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals. This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career. Check out the details at sansurl.com/450 Hope to see you in class! Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube Follow John Hubbard: Twitter | LinkedIn Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| David Hoelzer: Threat Detection with Machine Learning and AI | 12 Jul 2022 | 00:50:53 | |
Click here to send us your ideas and feedback on Blueprint! Many of us with the typical IT and security backgrounds might not have the slightest idea what to expect when we hear the terms “this product uses advanced machine learning…”, but that claim certainly conjures up a lot of skepticism due to the opaque nature of the algorithms in many of these products. In this episode we discuss what AI and ML are best used for, and what they can, can’t, and shouldn’t be used for with guest Dave Hoelzer.
David Hoelzer, a SANS Fellow and author of more than twenty days of SANS courseware, is an expert in a variety of information security fields, having served in most major roles in the IT and security industries over the past twenty-five years. Currently, David serves as the principal examiner and director of research for Enclave Forensics, a New York/Las Vegas based incident response and forensics company. He also serves as the chief information security officer for Cyber-Defense, an open-source security software solution provider. Follow Dave Twitter: https://twitter.com/it_audit LinkedIn: https://www.linkedin.com/in/davidhoelzer/ -- Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube Follow John Hubbard: Twitter | LinkedIn Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| James Rowley: Creating and Running an Insider Threat Program | 12 Jul 2022 | 01:00:50 | |
Click here to send us your ideas and feedback on Blueprint! While malicious insiders are a threat that most of us would like to imagine we might never have to deal with, it’s still one of the cyber threats you must realistically consider and plan for. But how do you identify malicious intent and potential attacks from those already inside our network that have legitimate access to our data? Check out this episode where James Rowley lays out what you need to consider when it comes to insider threat detection.
James Rowley is a cybersecurity-consultant-turned-dectection-engineer building the next generation of insider threat detections. As a Detection Engineer, James is responsible for merging the world of blue team and insider threat, moving the needle on how we approach insider detections within cyberspace. James outside of the workspace is passionate about most things related to outdoors, beer, whiskey, wine, food, travel, and Minnesota sports teams. You will find James enjoying these things and more with his fiance and two dogs, Marshall (Bernese Mountain Dog) and Maya (Basset Hound). -- Sponsor's Note: Support for the Blueprint podcast comes from the SANS Institute. If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals. This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career. Check out the details at http://sans.org/sec450 Hope to see you in class! -- Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube Follow John Hubbard: Twitter | LinkedIn Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Dean Parsons: Cyber Security for OT and ICS | 12 Jul 2022 | 00:57:38 | |
Click here to send us your ideas and feedback on Blueprint! With ransomware and other highly disruptive attacks on the rise, there are few systems more important to defend than our critical infrastructure and ICS equipment. How should we think about defending these systems vs our typical IT network though? In this episode, Dean Parsons is here to give us that answer. Our Guest - Dean Parsons Dean brings over 20 years of technical and management experience to the classroom. He has worked in both Information Technology and Industrial Control System (ICS) Cyber Defense in critical infrastructure sectors such as telecommunications, and electricity generation, transmission, distribution, and oil & gas refineries, storage, and distribution. Dean is an ambassador for defending industrial systems and an advocate for the safety, reliability, and cyber protection of critical infrastructure. His mission as an instructor is to empower each of his students, and he earnestly preaches that “Defense is Do-able!” Over the course of his career, Dean’s accomplishments include establishing entire ICS security programs for critical infrastructure sectors, successfully containing and eradicating malware and ransomware infections in electricity generation and manufacturing control networks, performing malware analysis triage and ICS digital forensics, building converged IT/OT incident response and threat hunt teams, and conducting ICS assessments in electric substations, oil and gas refineries, manufacturing, and telecommunications networks. A SANS Certified Instructor, Dean teaches ICS515: ICS Visibility, Detection, and Response and is a co-author of the new SANS Course ICS418: ICS Security Essentials for Managers. Dean is a member of the SANS GIAC Advisory Board and holds many cybersecurity professional certifications including the GICSP, GRID, GSLC, and GCIA, as well as the CISSP®. He is a proud native of Newfoundland and holds a BS in computer science from Memorial University of Newfoundland. Follow Dean Parsons Twitter: https://twitter.com/deancybersec LinkedIn: https://www.linkedin.com/in/dean-parsons-cybersecurity/ Resources mentioned in this episode OSINT / Site-visit Cheat Sheet https://www.sans.org/posters/ics-site-visit-plan/ ICS Cyber Kill Chain Whitepaper: https://www.sans.org/white-papers/36297/?msc=blog-ics-library ICS specific Network Security Monitoring: https://www.sans.org/posters/industrial-network-security-monitoring/ Top 5 ICS Incident Response Tabletops https://www.sans.org/blog/top-5-ics-incident-response-tabletops-and-how-to-run-them/ My weekly ICS Defense Force LiveStream https://www.youtube.com/playlist?list=PLjoUWqjR7qXhdZIcC8LgEBogrTyeoKqRT Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| John Hubbard: Your Top Cyber Defense Questions Answered from Seasons 1 + 2 | 01 Jul 2022 | 00:21:19 | |
Click here to send us your ideas and feedback on Blueprint! It's a special mailbag episode from John Hubbard! After two seasons, John asked the listeners what questions they had for him. He touched on the current XDR trend, how other teams can support SOC activities, defining security mindset, and more. Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| John Hubbard: Key lessons and takeaways from Blueprint Season 2 + A Special Announcement! | 08 Jun 2021 | 00:23:17 | |
Click here to send us your ideas and feedback on Blueprint! In this solo episode to wrap up season 2, John discusses some of the key takeaways from the guests interviwed throughout this year, and has some very exciting news for all blue teamers on a brand new GIAC certification. ;) Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Mark Morowczynski & Thomas Detzner: Microsoft Incident Response Playbooks | 01 Jun 2021 | 00:43:19 | |
Click here to send us your ideas and feedback on Blueprint! We all need solid, well though-out playbooks to help standardize our respons to common threat scenarios. In this episode we speak with Thomas Detzner and Mark Morowczynski about the brand new set of Microsoft incident response playbooks that were just released. This is a brand new effort to meticulously document prerequisites, investigation steps, and remediation process for common scenarios most commonly seen by the Microsoft incident response teams, and you definitely won't want to miss it. Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| AJ Yawn: Cloud, Compliance and Automating Security | 25 May 2021 | 00:57:10 | |
Click here to send us your ideas and feedback on Blueprint! Compliance and audit checks can be painful, and that's before you introduce additional cloud services and technology. In this episode featuring AJ Yawn we discuss some incredibly useful and actionable cloud security concepts and tools that can help your team boost visibility and reduce user permissions to help prevent breaches before they happen. In addition, we discuss what a good compliance audit should be, and how to turn audits from painful to incredibly valuable. AJ advises startups on cloud security and serves on the Board of Directors of the ISC2 Miami chapter as the Education Chair, he is also a Founding Board member of the National Association of Black Compliance and Risk Management professions, regularly speaks on information security podcasts, events, and he contributes blogs and articles to the information security community including publications such as CISOMag, InfosecMag, HackerNoon, and ISC2. Sponsor's Note: Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Jamie Williams: Adversary Emulation | 18 May 2021 | 00:50:11 | |
Click here to send us your ideas and feedback on Blueprint! There are numerous ways to test your SOC's detection and prevention capabilities, but not all are created equal. Each has their own strengths and weaknesses, and can be done on a different time scale.This week, we focus on arguably one of the most important - adversary emulation. In this episode we speak with Jamie Williams from the MITRE ATT&CK team about why adversary emulation is important, how it works, how you can get started regardless of the size of your team, and how to track and run an adversary emulation test. Follow Jamie Williams on Twitter (@jamieantisocial) and LinkedIn (/in/jamie-williams-108369190). Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| How Phishing Resistant Credentials Work with Mark Morowczynski and Tarek Dawoud | 02 Dec 2024 | 00:55:13 | |
Click here to send us your ideas and feedback on Blueprint! Mark Morowczynski returns for his 4th(!) time with his Microsoft coworker and identity and authentication expert Tarek Dawoud in this incredibly insightful conversation on the what, why, and how of phishing resistant credentials that YOU can implement right now!
Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Josh Johnson: PowerShell and Defensive Automation for the Blue Team | 11 May 2021 | 00:49:49 | |
Click here to send us your ideas and feedback on Blueprint! PowerShell may seem intimidating, but it can be one of the most amazing and useful tools at your disposal...if you know how to use it. In this episode, we have Josh Johnson, author of the new SANS course "SEC586: Blue Team Operations - Defensive Powershell" giving you a masterful crash course in: More About Josh Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Chris Baker: Get A Handle On Your Vulnerabilities | 04 May 2021 | 00:40:58 | |
Click here to send us your ideas and feedback on Blueprint! This episode is all about vulnerability management - both the technical and human aspects. Looking to start up a new vulnerability management team? Drowning in vulnerabilities to fix and don't know where to start? Struggling to get system owners to take action? Trying to find ways to communicate the importance and status of your patching efforts?
Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Mick Douglas & Flynn Weeks: Simplifying your Logging Strategy with the What2Log Project | 27 Apr 2021 | 00:47:17 | |
Click here to send us your ideas and feedback on Blueprint! A common question from many defenders is "Which logs are the most important?” In this episode, Mick Douglas and Flynn Weeks join us to describe their What2Log project, which aims to simplify this problem for all of us! Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Anton Chuvakin: The Current State and Future of Security Operations | 20 Apr 2021 | 00:48:17 | |
Click here to send us your ideas and feedback on Blueprint! In today’s episode, John is joined by Anton Chuvakin to discuss current and future security operations technology, which tools are the most important and which are becoming less important over time, the rules of automation in the SOC and how Anton would setup a modern Security Operations Center for a Cloud native organization. He is an author of books "Security Warrior", "Logging and Log Management: The Authoritative Guide to Understanding the Concepts Surrounding Logging and Log Management" and ""PCI Compliance, Third Edition: Understand and Implement Effective PCI Data Security Standard Compliance"" (book website) and a contributor to "Know Your Enemy II", "Information Security Management Handbook" and other books. Anton has published dozens of papers on log management, SIEM, correlation, security data analysis, PCI DSS, security management. His blog "Security Warrior" was one of the most popular in the industry. In addition, Anton teaches classes and presents at many security conferences across the world; he addressed audiences in United States, UK, Australia, Singapore, Spain, Russia and other countries. He works on emerging security standards and serves on advisory boards of several security start-ups.
Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Rob van Os: Maturing your Cyber Defense | 13 Apr 2021 | 00:50:09 | |
Click here to send us your ideas and feedback on Blueprint! Are you a manager looking to build or improve your SOC? Are you trying to understand how to measure your SOCs maturity or use cases or your threat hunting efforts? If so, today’s episode with Rob van Os is for you. In this episode, we discuss the SOC CMM for SOC maturity measurement, the magma use case framework for building and tracking SOC use cases, and the Tahiti threat hunting methodology for showing ROI on threat hunting. Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| AppSec, DevOps and DevSecOps | 06 Apr 2021 | 00:45:00 | |
Click here to send us your ideas and feedback on Blueprint! What is AppSec, DevOps and DevSecOps? In this episode we discuss why defenders should know more about these terms and what the consequences are of ignoring these new and critical fields. Advisor: Nord VPN, Cloud Defense, NeuraLegion, ICTC PAC, WoSEC Founder: We Hack Purple, WoSEC International (Women of Security), OWASP DevSlop, #CyberMentoringMonday
Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Playbook for Security Onion | 30 Mar 2021 | 00:34:02 | |
Click here to send us your ideas and feedback on Blueprint! Driving consistency and maintaining a high standard for alert response is a problem all SOCs must face, but how? In this episode, Josh Brower describes his efforts to combine automated detection signature deployment and use case database management into a single, easy to use app for Security Onion. Whether you use Security Onion or not, this episode dives into the design principles and workflow Josh used when designing the new open-source Playbook app and there’s something to learn from it for everyone on the Blue Team. Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| The Blue Teamer's Blueprint for Malware Triage | 30 Mar 2021 | 01:07:46 | |
Click here to send us your ideas and feedback on Blueprint! Even if you're not a malware analyst, any blue teamer should be able to do some initial basic malware sample triage. The good news is that this is quite easy to do using freely available tools once you know what is available. Join John in this conversation with Ryan Chapman as they discuss how to reverse engineer malware and why you might want to do so. Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| SOC Metrics: Measuring Success and Preventing Burnout | 30 Mar 2021 | 00:50:25 | |
Click here to send us your ideas and feedback on Blueprint! Looking for a new way to approach the difficult problem of measuring and improving your SOC? Check out this episode to hear how to use methods pioneered in the manufacturing and reliability industry to help wrap your head around, and solve this complex issue. You don’t want to miss this episode with Jon Hencinski, Director of Operations at Expel who covers all of this and more. Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| A Machine Learning Primer for the Blue Team | 11 Aug 2020 | 00:41:21 | |
Click here to send us your ideas and feedback on Blueprint! Austin Taylor discusses the promise and reality of cyber security-centric data science, and how you can use machine learning for solving practical security problems. Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| How GenAI is Changing Your SOC for the Better with Seth Misenar | 09 Oct 2024 | 01:36:15 | |
Click here to send us your ideas and feedback on Blueprint! In this mega-discussion with Seth Misenar on GenAI and LLM usage for security operations we cover some very interesting questions such as: - The importance of natural language processing in Sec Ops Episode Links:
Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Empowering Security Researchers Around the World! | 04 Aug 2020 | 00:41:48 | |
Click here to send us your ideas and feedback on Blueprint! Roberto Rodriguez explains the awesome projects and initiatives he is working on to help blue teams perform advanced data collection, analysis, and threat hunting. Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Locking Down and Monitoring Cloud Infrastructure | 28 Jul 2020 | 00:42:29 | |
Click here to send us your ideas and feedback on Blueprint! Cloud expert Kyle Dickinson discusses common cloud infrastructure attacks, and how you can detect and prevent them before they happen to your organization. Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Passwordless - Can it Be Done? | 21 Jul 2020 | 00:41:52 | |
Click here to send us your ideas and feedback on Blueprint! Mark and Libby share the new technologies in use at Microsoft to dramatically decrease the need for the use of passwords in the enterprise. Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||
| Training Yourself in a Quarantined World | 14 Jul 2020 | 00:35:38 | |
Click here to send us your ideas and feedback on Blueprint! Dave and Ryan speak with John about resources for training yourself, and the challenges of setting up a large-scale cyber lab to simulate an advanced attack for their Splunk Boss of the SOC competition. Check out John's SOC Training Courses for SOC Analysts and Leaders:
Follow and Connect with John: LinkedIn | |||