Markus's Avatar

Markus

@mascho.bsky.social

πŸ’» Blue Team Training @ Blue Cape Security

537 Followers  |  115 Following  |  47 Posts  |  Joined: 14.11.2024
Posts Following

Posts by Markus (@mascho.bsky.social)

Preview
Analyst I: Core Forensic Track Enrollment - Blue Cape Security Elevate your DFIR skills in our 3-part workshop series. Get hands-on with real-world scenarios from cybersecurity basics to advanced forensic analysis.

Dropped our Practical Windows Forensic Analyst cert! πŸ”₯πŸ‘€

bluecapesecurity.com/pwfa

05.08.2025 03:47 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Is this still on?

21.07.2025 05:25 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Practice - Blue Cape Security Enrollment now open: FOR200 Investigation Scenarios Limited Time Offer: 20% OFF FOR200 and HERO BundleCode: START200 β€” Ends May 23 PRACTICE Hands-On, RealisticInvestigation Scenarios Apply your skills...

Just dropped: Our hands-on Windows Forensics investigation scenarios are live! πŸ”

-> 20% OFF with code START200

bluecapesecurity.com/practice/#FO...

Enjoy!

13.05.2025 18:18 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

We just released a course that embodies our core principles: learn + practice + assess > and it’s free!

DFIR Foundations and Techniques: Professional Skills and Readiness

=> For SecOps and DFIR professionals

Full course: tinyurl.com/mu77u3ab
Youtube playlist: tinyurl.com/2s3n7nfx

#dfir #secops

19.03.2025 17:42 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

Still reminiscing about the incredible time at @wildwesthackinfest.bsky.social last week and now counting down to IntelliCon next week in Austin! If you haven’t grabbed your ticket yet, there’s still time: www.intelliguards.com/event-detail...

12.02.2025 13:46 β€” πŸ‘ 5    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Final modules for our 301 Enterprise DFIR course have been uploaded. What a journey after developing, analyzing and recording all the materials over many months of work!

I'm excited about the course and also looking forward to head to the WWHF conference next week. Reach out if you are there!

30.01.2025 23:07 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Course and Programs | Individual Training - Blue Cape Security Practical Cybersecurity Training Built for Real-World Investigations Hands-On, Scenario-Based Training to Master Cyber Threats and Elevate Your Career training roadmap on-demand courses Our courses in...

Proud to present our brand new training page and offering for individuals @ Blue Cape Security:

- 301 Enterprise DFIR course launched

- HERO Bundle including 101 / 201 / 301 courses

- Blue Team Master Program is public again

bluecapesecurity.com/individual-t...

HMU for questions or feedback! πŸ’™

28.01.2025 14:42 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Blue Cape Security on LinkedIn: #cybersecurity #bluecapesecurity #incidentresponse #dfirtraining… | 11 comments πŸŽ‰ Big Giveaway: Win our brand new HERO Bundle (101 / 201 / 301 courses)! Here’s how to enter: β†’ Follow us here on LinkedIn (@BlueCapeSecurity) β†’ Like this… | 11 comments on LinkedIn

We have a giveaway of our brand new course bundle over at LinkedIn for those interested: www.linkedin.com/posts/blueca...

Only 2 more days!

23.01.2025 14:47 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Lots of great things coming next week! 301 Enterprise DFIR course - Launch Party with a special guest, new course bundles and more!

Live Stream: youtube.com/live/MgG_pT1...

22.01.2025 03:58 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Persistent "Zoom is Accessing Your Screen… - Apple Community

Zoom bug: discussions.apple.com/thread/25588...

16.01.2025 04:35 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Since enabling Apple Intelligence an uncontrollable amount of notifications keep popping up (e.g. continuously when I'm screen sharing on Zoom). It doesn't seem they've gotten much smarter navigating me to my webinars either..

16.01.2025 04:31 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Logo for Notion Incident Management System (NIMS)

Logo for Notion Incident Management System (NIMS)

πŸš€ Excited to announce the alpha release of NIMS - a Notion-based Incident Management System!

Designed for SOC/IR teams, NIMS helps streamline incident management and collaboration using Notion's powerful database features.

#InfoSec #DFIR #IncidentResponse #SecOps #Notion

07.01.2025 00:42 β€” πŸ‘ 73    πŸ” 21    πŸ’¬ 4    πŸ“Œ 5
Preview
CrowdStrike Services Releases Free Incident Response Tracker This blog post provides an overview of the newly released CrowdStrike Incident Response Tracker and how it is leveraged by our experts on the front lines.

How do you track DFIR timelines and findings? There doesn't seem to be a one size fits all solution in the industry.

Most commonly used are still spreadsheets, where Crowdstrike actually released a pretty nice IR Tracker template a while ago: www.crowdstrike.com/en-us/blog/c...

03.01.2025 19:41 β€” πŸ‘ 6    πŸ” 5    πŸ’¬ 3    πŸ“Œ 0

Sounds interesting. Just subscribed and looking forward to listen to it!

02.01.2025 17:49 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

The best conference in the industry is only 1 month away 🀠

I'll be teaching the 2-day Ransomware Attack Simulation and Investigation for Blue Teamers workshop with in-person and virtual seats available!

I’m looking forward to reconnecting with old friends and making new ones at this amazing event!

31.12.2024 19:12 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Blue Cape Security on LinkedIn: Elevate Your DFIR Skills: Deeper Insights and Practical Applications |… πŸ” Perform your own DFIR investigation - Suspicious File Download Incident Our Security Operations Center (SOC) detected that the employee Alice downloaded a…

Good question - here is the more detailed description of the case: www.linkedin.com/posts/blueca...

28.12.2024 17:54 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Elevate Your DFIR Skills: Deeper Insights and Practical Applications - Blue Cape Security

For those looking to practice a realistic #DFIR scenario, here is a free case for you to investigate.

Provided artifacts:
- Disk Triage Collection
- Memory Image + pagefile.sys:
- PCAP File

Link: bluecapesecurity.com/courses/elev...

28.12.2024 16:18 β€” πŸ‘ 9    πŸ” 4    πŸ’¬ 1    πŸ“Œ 0

AWS: Welcome back! Your t2.xlarge EC2's have been running happily over the holidays πŸ₯²

27.12.2024 23:41 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Practical Windows Forensics - Cheat sheet πŸ’™

Full PDF version: github.com/bluecapesecu...

22.12.2024 03:18 β€” πŸ‘ 8    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0
Post image

Looking forward to present our maturity model tomorrow live! Finally visualized the way how we do trainings for teams and individuals.

Link: bluecapesecurity.com/register

18.12.2024 22:45 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Microsoft Security Incident Prediction Can you predict the next big security incident before it happens?

Microsoft incident data sets. Haven’t had a chance to test this, but certainly looks interesting.
www.kaggle.com/datasets/Mic...

16.12.2024 20:36 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Welcome! You are invited to join a webinar: Blue Cape Security DFIR Training Roadmap for Cybersecurity Professionals. After registering, you will receive a confirmation email about joining the webinar... Join Markus Schober, CEO of Blue Cape Security, for a 45-minute Live webinar on December 19th at 1:00 PM ET / 10:00 AM PT. This session will introduce the Blue Cape Security DFIR Training Roadmapβ€”a pr...

Oh hey we have a webinar coming up next week!

-> Thursday, December 19th

I'll be sharing our DFIR Training Roadmap that we've been working on since the beginnings of Blue Cape Security (which is more than 2 years now) πŸ₯Ή

us06web.zoom.us/webinar/regi...

13.12.2024 17:17 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Was just planning on releasing a new DFIR course module on log analysis, but I just uploaded:

2+ hours video
11 Splunk hands-on labs (with over 30 queries)
2 Sigma hands-on labs

Why do these things always get out of hand?

13.12.2024 05:05 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
sigconverter.io - sigma rule converter

Oh and of course the converter engine: sigconverter.io

#sigmahq

10.12.2024 16:58 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Sigma Search Engine

Currently working on a course module using Sigma detection rules. A few resources I came across and didn't know about previously were:

- Sigma rule search engine: sigmasearchengine.com
- Sigma VSC plugin: marketplace.visualstudio.com/items?itemNa...

Making Sigma rule creation much more fun :)

10.12.2024 15:16 β€” πŸ‘ 4    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0

Any one have any recommendations for video cutting tools? Just for effective cutting of recorded videos for courses. Wondershare Filmora is pretty good, but always curious about what else is out there.

09.12.2024 00:48 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

There's much to unpack, but the key issue is big corporations dodging taxes, which leads to an unfair contribution to society. Employees cover the system, while corporations exploit tax loopholes and government resources, yet offer none or poor healthcare amongst other things in favor of profits.

06.12.2024 17:01 β€” πŸ‘ 5    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Revolutionizing Security Operations: The Path Toward AI-Augmented SOCs Exploring the processes, challenges, solutions, and path toward a future of AI-Augmented Security Operations Centers (SOC)

Revolutionizing Security Operations: The Path Toward AI-Augmented SOCs open.substack.com/pub/software...

Highly recommend this post to get a grasp on how AI is transforming security operations.

06.12.2024 16:26 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Available Artifacts - Evidence of Execution UPDATED 2024-12-04 UPDATED 2019-01-04 This week I have been working a case where I was required to identify users on a Windows Server 2003 system who had knowledge of, or had run, a particular unau...

A curated list of Windows execution artifacts - this is just awesome work by @harrisonamj.com!

blog.1234n6.com/available-ar...

05.12.2024 18:07 β€” πŸ‘ 6    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0