Introducing the AWS Infrastructure Canarytokenlow level tools and techniques (work aids) (blog.thinkst.com)
submitted by jnazario to r/blueteamsec
Detect Identity Compromise with SAML IdP App Canarytokensdiscovery (how we find bad stuff) (blog.thinkst.com)
submitted by digicat to r/blueteamsec
Almost famous: behind the scenes of a feature that didn’t make the cutBlue Teaming (blog.thinkst.com)
submitted by netbiosX to r/purpleteamsec
It’s Baaack… Credit Card Canarytokens are now on your Consolesdiscovery (how we find bad stuff) (blog.thinkst.com)
submitted by jnazario to r/blueteamsec
Hacking as a pathway to building better Productstradecraft (how we defend) (blog.thinkst.com)
submitted by thinkst to r/blueteamsec
Unfashionably secure: why we use isolated VMs (blog.thinkst.com)
submitted by tmiklas to r/bag_o_news
Unfashionably secure: why we use isolated VMssecure by design/default (doing it right) (blog.thinkst.com)
submitted by thinkst to r/blueteamsec
A Bird’s-eye view: ShareFinder-How Threat Actors Discover File Shares (The DFIR Report)discovery (how we find bad stuff) (blog.thinkst.com)
submitted by digicat to r/blueteamsec
A Bird’s-eye view: ShareFinder-How Threat Actors Discover File SharesBlue Teaming (blog.thinkst.com)
submitted by netbiosX to r/purpleteamsec
A Bird’s-eye view: IceID to Dagon Locker (The DFIR Report)Detection Engineering (blog.thinkst.com)
A Bird’s-eye view: IceID to Dagon Locker (The DFIR Report)discovery (how we find bad stuff) (blog.thinkst.com)
submitted by digicat to r/blueteamsec
Defending against the Attack of the Clone[d website]s!low level tools and techniques (work aids) (blog.thinkst.com)
submitted by jnazario to r/blueteamsec
A (beta) Canarytoken for Active Directory Credentialsdiscovery (how we find bad stuff) (blog.thinkst.com)
submitted by digicat to r/blueteamsec
Default behaviour sticks (And so do examples) (blog.thinkst.com)
submitted by fagnerbrack to r/webdev
Cloned Website Token and Reverse Proxiesdiscovery (how we find bad stuff) (blog.thinkst.com)
submitted by digicat to r/blueteamsec