<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet href="https://rss.buzzsprout.com/styles.xsl" type="text/xsl"?>
<rss version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:podcast="https://podcastindex.org/namespace/1.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:psc="http://podlove.org/simple-chapters" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <atom:link href="https://rss.buzzsprout.com/1142720.rss" rel="self" type="application/rss+xml" />
  <atom:link href="https://pubsubhubbub.appspot.com/" rel="hub" xmlns="http://www.w3.org/2005/Atom" />
  <title>Blueprint: Build the Best in Cyber Defense</title>

  <lastBuildDate>Mon, 20 Jul 2026 05:25:46 -0400</lastBuildDate>
  <link>https://www.sans.org/podcasts/blueprint/</link>
  <language>en-us</language>
  <copyright>© 2026 SANS Institute</copyright>
  <podcast:locked>yes</podcast:locked>
    <podcast:guid>68ff20d2-dba6-5b6f-be43-46b574250861</podcast:guid>
  <itunes:author>SANS Institute</itunes:author>
  <itunes:type>episodic</itunes:type>
  <itunes:explicit>false</itunes:explicit>
  <description><![CDATA[<p>Are you a cyber defender looking to keep up on the newest tools, technology, and security concepts? Then BLUEPRINT is the podcast for you! Tune in to hear the latest in cyber defense and security operations from blue team leaders and experts. With a focus on learning, BLUEPRINT includes interviews with today’s top security practitioners defending the world’s most respected brands, and in-depth explanations on the newest technologies, protocols, and defensive tools. BLUEPRINT, is a podcast hosted by John Hubbard and brought to you by the SANS Institute. BLUEPRINT - your one-stop shop for taking your defense skills to the next level!</p>]]></description>
  <generator>Buzzsprout (https://www.buzzsprout.com)</generator>
  <itunes:owner>
    <itunes:name>SANS Institute</itunes:name>
  </itunes:owner>
  <image>
     <url>https://storage.buzzsprout.com/gcgze40gevy2qm2qc2snmsxep890?.jpg</url>
     <title>Blueprint: Build the Best in Cyber Defense</title>
     <link>https://www.sans.org/podcasts/blueprint/</link>
  </image>
  <itunes:image href="https://storage.buzzsprout.com/gcgze40gevy2qm2qc2snmsxep890?.jpg" />
  <itunes:category text="Technology" />
  <podcast:person role="host" img="https://storage.buzzsprout.com/cblpz4dwvbkzm58qqxaxcpjku9oo">John Hubbard</podcast:person>
  <item>
    <itunes:title>Building Trust Into Agentic SOC Tools with Oren Saban</itunes:title>
    <title>Building Trust Into Agentic SOC Tools with Oren Saban</title>
    <itunes:summary><![CDATA[SANS Cloud Security Exchange Summit 2026 - Aug. 17-18, San Francisco: https://www.sans.org/mlp/cloud-security-exchange-2026 Save $50 off registration with special promo code "Cloud_Promo50"!  Agentic SOC platforms are no longer a future pitch — they're shipping, and teams are using them to triage and investigate cases end to end. But speed and automation only matter if you can trust the output. John sits down with Oren Saban to unpack what it actually takes to build a trustworthy agentic SOC ...]]></itunes:summary>
    <description><![CDATA[<p>SANS Cloud Security Exchange Summit 2026 - Aug. 17-18, San Francisco: <a href='https://www.sans.org/mlp/cloud-security-exchange-2026'>https://www.sans.org/mlp/cloud-security-exchange-2026</a><br/>Save $50 off registration with special promo code &quot;Cloud_Promo50&quot;!<br/><br/>Agentic SOC platforms are no longer a future pitch — they&apos;re shipping, and teams are using them to triage and investigate cases end to end. But speed and automation only matter if you can trust the output. John sits down with Oren Saban to unpack what it actually takes to build a trustworthy agentic SOC tool.</p><p>They cover why these platforms are built as swarms of specialized agents rather than one generalist model, the role organizational context and data quality play in getting good results, how teams measure confidence and catch AI mistakes before they become missed detections, which analyst skills are becoming obsolete and which matter more than ever, and the emerging risk of prompt injection attacks against AI-powered SOC tools.</p><p>If you&apos;re evaluating these platforms — or trying to figure out what trust actually means when AI is doing most of the investigating — this conversation lays out the real tradeoffs.<br/><br/>Oren on LinkedIn: <a href='https://www.linkedin.com/in/oren-saban/'>https://www.linkedin.com/in/oren-saban/</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>SANS Cloud Security Exchange Summit 2026 - Aug. 17-18, San Francisco: <a href='https://www.sans.org/mlp/cloud-security-exchange-2026'>https://www.sans.org/mlp/cloud-security-exchange-2026</a><br/>Save $50 off registration with special promo code &quot;Cloud_Promo50&quot;!<br/><br/>Agentic SOC platforms are no longer a future pitch — they&apos;re shipping, and teams are using them to triage and investigate cases end to end. But speed and automation only matter if you can trust the output. John sits down with Oren Saban to unpack what it actually takes to build a trustworthy agentic SOC tool.</p><p>They cover why these platforms are built as swarms of specialized agents rather than one generalist model, the role organizational context and data quality play in getting good results, how teams measure confidence and catch AI mistakes before they become missed detections, which analyst skills are becoming obsolete and which matter more than ever, and the emerging risk of prompt injection attacks against AI-powered SOC tools.</p><p>If you&apos;re evaluating these platforms — or trying to figure out what trust actually means when AI is doing most of the investigating — this conversation lays out the real tradeoffs.<br/><br/>Oren on LinkedIn: <a href='https://www.linkedin.com/in/oren-saban/'>https://www.linkedin.com/in/oren-saban/</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/19425096-building-trust-into-agentic-soc-tools-with-oren-saban.mp3" length="32243632" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-19425096</guid>
    <pubDate>Thu, 02 Jul 2026 05:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1142720/19425096/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1142720/19425096/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1142720/19425096/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1142720/19425096/transcript.vtt" type="text/vtt" />
    <itunes:duration>2680</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>5</itunes:season>
    <itunes:episode>12</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Preventing Silent Failures with Nir Loya Dahan</itunes:title>
    <title>Preventing Silent Failures with Nir Loya Dahan</title>
    <itunes:summary><![CDATA[This episode is sponsored by Fig. This episode features a conversation with Nir Loya Dahan, Co-Founder and CPO at Fig, recorded at RSAC 2026. Our discussion covers telemetry health and SOC infrastructure resilience: what breaks in a log pipeline, why silent failures are so hard to catch, and how detection teams can build more confidence in their data foundation. Resources: Nir's Email: nir@fig.security Fig Website: https://www.fig.security Contact, Courses, and More: For feedback, reviews, gu...]]></itunes:summary>
    <description><![CDATA[<p><b>This episode is sponsored by Fig.</b></p><p>This episode features a conversation with Nir Loya Dahan, Co-Founder and CPO at Fig, recorded at RSAC 2026. Our discussion covers telemetry health and SOC infrastructure resilience: what breaks in a log pipeline, why silent failures are so hard to catch, and how detection teams can build more confidence in their data foundation.</p><p><b>Resources</b>:</p><p>Nir&apos;s Email: nir@fig.security</p><p>Fig Website: https://www.fig.security</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p><b>This episode is sponsored by Fig.</b></p><p>This episode features a conversation with Nir Loya Dahan, Co-Founder and CPO at Fig, recorded at RSAC 2026. Our discussion covers telemetry health and SOC infrastructure resilience: what breaks in a log pipeline, why silent failures are so hard to catch, and how detection teams can build more confidence in their data foundation.</p><p><b>Resources</b>:</p><p>Nir&apos;s Email: nir@fig.security</p><p>Fig Website: https://www.fig.security</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/19069329-preventing-silent-failures-with-nir-loya-dahan.mp3" length="40019540" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-19069329</guid>
    <pubDate>Thu, 18 Jun 2026 05:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1142720/19069329/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1142720/19069329/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1142720/19069329/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1142720/19069329/transcript.vtt" type="text/vtt" />
    <itunes:duration>3328</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>5</itunes:season>
    <itunes:episode>11</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The 2 AM Call: A Ransomware Negotiator&#39;s Playbook with Wade Gettle</itunes:title>
    <title>The 2 AM Call: A Ransomware Negotiator&#39;s Playbook with Wade Gettle</title>
    <itunes:summary><![CDATA[What happens after you discover ransomware? You have to talk to the attackers. And that conversation can make or break your entire response. In this episode, Wade Gettle, a professional ransomware negotiator, pulls back the curtain on the high-stakes world of threat actor negotiations. Wade is the person who gets the call at 2 AM when organizations are facing their worst moment, and he's handled negotiations across every scenario imaginable. You'll learn: What actually happens in the first 72...]]></itunes:summary>
    <description><![CDATA[<p><b>What happens after you discover ransomware? You have to talk to the attackers. And that conversation can make or break your entire response.</b></p><p>In this episode, Wade Gettle, a professional ransomware negotiator, pulls back the curtain on the high-stakes world of threat actor negotiations. Wade is the person who gets the call at 2 AM when organizations are facing their worst moment, and he&apos;s handled negotiations across every scenario imaginable.</p><p><b>You&apos;ll learn:</b></p><ul><li>What actually happens in the first 72 hours of a ransomware incident</li><li>The psychological tactics threat actors use to manufacture urgency and pressure</li><li>Why those 24-hour deadlines aren&apos;t real—and how to buy yourself time</li><li>How threat actors research your financials, insurance policies, and supply chain before making contact</li><li>When data validation saves companies from paying ransoms for data that isn&apos;t even theirs</li><li>The real cost of ransomware (spoiler: it&apos;s 10x the ransom amount)</li><li>Why paying doesn&apos;t guarantee your data back—or that you won&apos;t get hit again</li><li>Third-party breaches: the biggest risk vector right now</li></ul><p><b>Key takeaway:</b> Ransomware negotiations are psychological warfare disguised as business transactions. The best defense is being more prepared than the attackers expect you to be.</p><p><b>Resources mentioned in this episode:</b></p><ul><li><a href='https://ransomware.live'>ransomware.live</a> (ransomware group tracking, info, conversations and more)</li><li><a href='https://ransomlook.io'>ransomlook.io</a> (ransomware group tracking and statistics)</li><li>ChatGPT Ransomware Negotiation Simulator: <a href='https://chatgpt.com/g/g-679a6253574c8191a998145044b9c651-ransomsim-ransomware-negotiation-trainer'>https://chatgpt.com/g/g-679a6253574c8191a998145044b9c651-ransomsim-ransomware-negotiation-trainer</a></li><li>Wade Gettle on LinkedIn: <a href='https://www.linkedin.com/in/wade-gettle-7733704a/'>https://www.linkedin.com/in/wade-gettle-7733704a/</a></li></ul><p><b>About the guest:</b> Wade Gettle is a Senior Advisor at Flashpoint and serves as a Cyber Mission Planner for the New York Army National Guard. With a background in intelligence analysis, incident response, and threat intelligence, Wade brings calm to the storm when organizations face their most critical security incidents.</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p><b>What happens after you discover ransomware? You have to talk to the attackers. And that conversation can make or break your entire response.</b></p><p>In this episode, Wade Gettle, a professional ransomware negotiator, pulls back the curtain on the high-stakes world of threat actor negotiations. Wade is the person who gets the call at 2 AM when organizations are facing their worst moment, and he&apos;s handled negotiations across every scenario imaginable.</p><p><b>You&apos;ll learn:</b></p><ul><li>What actually happens in the first 72 hours of a ransomware incident</li><li>The psychological tactics threat actors use to manufacture urgency and pressure</li><li>Why those 24-hour deadlines aren&apos;t real—and how to buy yourself time</li><li>How threat actors research your financials, insurance policies, and supply chain before making contact</li><li>When data validation saves companies from paying ransoms for data that isn&apos;t even theirs</li><li>The real cost of ransomware (spoiler: it&apos;s 10x the ransom amount)</li><li>Why paying doesn&apos;t guarantee your data back—or that you won&apos;t get hit again</li><li>Third-party breaches: the biggest risk vector right now</li></ul><p><b>Key takeaway:</b> Ransomware negotiations are psychological warfare disguised as business transactions. The best defense is being more prepared than the attackers expect you to be.</p><p><b>Resources mentioned in this episode:</b></p><ul><li><a href='https://ransomware.live'>ransomware.live</a> (ransomware group tracking, info, conversations and more)</li><li><a href='https://ransomlook.io'>ransomlook.io</a> (ransomware group tracking and statistics)</li><li>ChatGPT Ransomware Negotiation Simulator: <a href='https://chatgpt.com/g/g-679a6253574c8191a998145044b9c651-ransomsim-ransomware-negotiation-trainer'>https://chatgpt.com/g/g-679a6253574c8191a998145044b9c651-ransomsim-ransomware-negotiation-trainer</a></li><li>Wade Gettle on LinkedIn: <a href='https://www.linkedin.com/in/wade-gettle-7733704a/'>https://www.linkedin.com/in/wade-gettle-7733704a/</a></li></ul><p><b>About the guest:</b> Wade Gettle is a Senior Advisor at Flashpoint and serves as a Cyber Mission Planner for the New York Army National Guard. With a background in intelligence analysis, incident response, and threat intelligence, Wade brings calm to the storm when organizations face their most critical security incidents.</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/18643145-the-2-am-call-a-ransomware-negotiator-s-playbook-with-wade-gettle.mp3" length="35309362" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-18643145</guid>
    <pubDate>Mon, 09 Feb 2026 09:00:00 -0500</pubDate>
    <itunes:duration>2935</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>5</itunes:season>
    <itunes:episode>10</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Infiltration Alert! How to Catch Fake IT Employees in Your Network with Zak Stufflebeam</itunes:title>
    <title>Infiltration Alert! How to Catch Fake IT Employees in Your Network with Zak Stufflebeam</title>
    <itunes:summary><![CDATA[This episode is a big one! We kick off 2026 with a critical lessons learned on how to detect and prevent the threat of fake IT workers infiltrating your organization through the story of a REAL compromise. In this episode, repeat guest Zak Stufflebeam shares a detailed case study involving a major investigation of multiple counterfeit IT employees within a company. The episode provides valuable insights and actionable detection tactics, covering everything from unusual VPN activity and AI-gen...]]></itunes:summary>
    <description><![CDATA[<p>This episode is a big one! We kick off 2026 with a critical lessons learned on how to detect and prevent the threat of fake IT workers infiltrating your organization through the story of a REAL compromise. In this episode, repeat guest Zak Stufflebeam shares a detailed case study involving a major investigation of multiple counterfeit IT employees within a company. The episode provides valuable insights and actionable detection tactics, covering everything from unusual VPN activity and AI-generated resumes to suspicious interview responses and unauthorized access requests. </p><p>With the rise of remote work, this episode is essential listening for cyber defenders aiming to ensure their networks are clean and defensible in the new year.</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>This episode is a big one! We kick off 2026 with a critical lessons learned on how to detect and prevent the threat of fake IT workers infiltrating your organization through the story of a REAL compromise. In this episode, repeat guest Zak Stufflebeam shares a detailed case study involving a major investigation of multiple counterfeit IT employees within a company. The episode provides valuable insights and actionable detection tactics, covering everything from unusual VPN activity and AI-generated resumes to suspicious interview responses and unauthorized access requests. </p><p>With the rise of remote work, this episode is essential listening for cyber defenders aiming to ensure their networks are clean and defensible in the new year.</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/18446617-infiltration-alert-how-to-catch-fake-it-employees-in-your-network-with-zak-stufflebeam.mp3" length="69659095" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-18446617</guid>
    <pubDate>Mon, 05 Jan 2026 11:00:00 -0500</pubDate>
    <itunes:duration>5797</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>5</itunes:season>
    <itunes:episode>9</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Leading by Example: Confidence and Responsibility in Cybersecurity with Zak Stufflebeam</itunes:title>
    <title>Leading by Example: Confidence and Responsibility in Cybersecurity with Zak Stufflebeam</title>
    <itunes:summary><![CDATA[In this episode, we sit down with Zak Stufflebeam, Director of Cybersecurity at a publicly traded insurance company. Zak shares his unique journey from the military to leading security operations, emphasizing essential leadership principles learned along the way. From his early days in basic training to leading complex cybersecurity teams, Zak’s story is one of perseverance, adaptability, and unwavering commitment. He delves into vital leadership lessons, the importance of confidence, and str...]]></itunes:summary>
    <description><![CDATA[<p>In this episode, we sit down with Zak Stufflebeam, Director of Cybersecurity at a publicly traded insurance company. Zak shares his unique journey from the military to leading security operations, emphasizing essential leadership principles learned along the way. From his early days in basic training to leading complex cybersecurity teams, Zak’s story is one of perseverance, adaptability, and unwavering commitment. He delves into vital leadership lessons, the importance of confidence, and strategies to maintain focus and calm under pressure. This episode is packed with insights for aspiring SOC analysts and leaders looking to make an impact in their field.</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>In this episode, we sit down with Zak Stufflebeam, Director of Cybersecurity at a publicly traded insurance company. Zak shares his unique journey from the military to leading security operations, emphasizing essential leadership principles learned along the way. From his early days in basic training to leading complex cybersecurity teams, Zak’s story is one of perseverance, adaptability, and unwavering commitment. He delves into vital leadership lessons, the importance of confidence, and strategies to maintain focus and calm under pressure. This episode is packed with insights for aspiring SOC analysts and leaders looking to make an impact in their field.</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/17516145-leading-by-example-confidence-and-responsibility-in-cybersecurity-with-zak-stufflebeam.mp3" length="47887191" type="audio/mpeg" />
    <itunes:author>SANS Institute</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17516145</guid>
    <pubDate>Tue, 19 Aug 2025 05:00:00 -0400</pubDate>
    <itunes:duration>3983</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>5</itunes:season>
    <itunes:episode>8</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>From the SANS Cyber Leaders Podcast: Fighting Back with John Hubbard</itunes:title>
    <title>From the SANS Cyber Leaders Podcast: Fighting Back with John Hubbard</title>
    <itunes:summary><![CDATA[This podcast episode is from the SANS Cyber Leaders Podcast. The episode features Blueprint host John Hubbard, where he talks with hosts James Lyne and Ciaran Martin on the ever-changing threat landscape and how SOC teams can stay ahead. John shares his expertise on spotting threats early, how to test your defences before the real attackers show up, and why he’s on a mission to simplify cybersecurity operations for the next generation of defenders. Contact, Courses, and More: For feedback, re...]]></itunes:summary>
    <description><![CDATA[<p><b>This podcast episode is from the </b><a href='https://www.sans.org/podcasts/cyber-leaders/'><b>SANS Cyber Leaders Podcast</b></a><b>.</b></p><p>The episode features Blueprint host John Hubbard, where he talks with hosts James Lyne and Ciaran Martin on<b> </b>the ever-changing threat landscape and how SOC teams can stay ahead. John shares his expertise on spotting threats early, how to test your defences before the real attackers show up, and why he’s on a mission to simplify cybersecurity operations for the next generation of defenders.</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p><b>This podcast episode is from the </b><a href='https://www.sans.org/podcasts/cyber-leaders/'><b>SANS Cyber Leaders Podcast</b></a><b>.</b></p><p>The episode features Blueprint host John Hubbard, where he talks with hosts James Lyne and Ciaran Martin on<b> </b>the ever-changing threat landscape and how SOC teams can stay ahead. John shares his expertise on spotting threats early, how to test your defences before the real attackers show up, and why he’s on a mission to simplify cybersecurity operations for the next generation of defenders.</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/17404685-from-the-sans-cyber-leaders-podcast-fighting-back-with-john-hubbard.mp3" length="37722142" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/d479ce9bzc840yz7gy4wzcrgttrs?.jpg" />
    <itunes:author>SANS Institute</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17404685</guid>
    <pubDate>Fri, 27 Jun 2025 05:00:00 -0400</pubDate>
    <itunes:duration>3141</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>5</itunes:season>
    <itunes:episodeType>bonus</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Redefining Security Operations: Lessons in AI Integration with James Spiteri</itunes:title>
    <title>Redefining Security Operations: Lessons in AI Integration with James Spiteri</title>
    <itunes:summary><![CDATA[In this episode of Blueprint, host John Hubbard sits down with James Spiteri from Elastic to explore the transformative power of AI on the SOC. They delve into how advanced AI technologies, such as agentic AI models, MCP protocol, and automation, are reshaping the SOC landscape. Discover how AI enhances SOC efficiency, reduces mundane tasks, and integrates context-aware capabilities. Learn about the real-world applications, from automation in cybersecurity operations to the challenges and pro...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of Blueprint, host John Hubbard sits down with James Spiteri from Elastic to explore the transformative power of AI on the SOC. They delve into how advanced AI technologies, such as agentic AI models, MCP protocol, and automation, are reshaping the SOC landscape. Discover how AI enhances SOC efficiency, reduces mundane tasks, and integrates context-aware capabilities. Learn about the real-world applications, from automation in cybersecurity operations to the challenges and promises of large language models. This discussion covers the ethical considerations, potential risks, and the promising future of SOCs powered by AI. Tune in to get inspired and see how AI might revolutionize your cyber defense strategies.</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of Blueprint, host John Hubbard sits down with James Spiteri from Elastic to explore the transformative power of AI on the SOC. They delve into how advanced AI technologies, such as agentic AI models, MCP protocol, and automation, are reshaping the SOC landscape. Discover how AI enhances SOC efficiency, reduces mundane tasks, and integrates context-aware capabilities. Learn about the real-world applications, from automation in cybersecurity operations to the challenges and promises of large language models. This discussion covers the ethical considerations, potential risks, and the promising future of SOCs powered by AI. Tune in to get inspired and see how AI might revolutionize your cyber defense strategies.</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/17323857-redefining-security-operations-lessons-in-ai-integration-with-james-spiteri.mp3" length="48162881" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-17323857</guid>
    <pubDate>Thu, 12 Jun 2025 06:00:00 -0400</pubDate>
    <itunes:duration>4006</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>5</itunes:season>
    <itunes:episode>7</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>From Special Forces to Cybersecurity: Rich Greene on Communication and Persuasion in Infosec</itunes:title>
    <title>From Special Forces to Cybersecurity: Rich Greene on Communication and Persuasion in Infosec</title>
    <itunes:summary><![CDATA[In this episode, we sit down with Rich Greene, a former United States Army Special Forces Green Beret and current SANS instructor for SEC275 and SEC301. Rich shares his incredible journey spanning 20 years in the Army, including his transition from military communication roles into the realm of cybersecurity. He talks about the importance of fundamentals in cybersecurity, the power of effective communication and persuasion, and dispels common misconceptions about entering the cyber field. Ric...]]></itunes:summary>
    <description><![CDATA[<p>In this episode, we sit down with Rich Greene, a former United States Army Special Forces Green Beret and current SANS instructor for SEC275 and SEC301. Rich shares his incredible journey spanning 20 years in the Army, including his transition from military communication roles into the realm of cybersecurity. He talks about the importance of fundamentals in cybersecurity, the power of effective communication and persuasion, and dispels common misconceptions about entering the cyber field. Rich also highlights his passion for teaching and how his military background has shaped his approach to instruction and information security. Tune in for invaluable advice that applies to anyone no matter your role!. </p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>In this episode, we sit down with Rich Greene, a former United States Army Special Forces Green Beret and current SANS instructor for SEC275 and SEC301. Rich shares his incredible journey spanning 20 years in the Army, including his transition from military communication roles into the realm of cybersecurity. He talks about the importance of fundamentals in cybersecurity, the power of effective communication and persuasion, and dispels common misconceptions about entering the cyber field. Rich also highlights his passion for teaching and how his military background has shaped his approach to instruction and information security. Tune in for invaluable advice that applies to anyone no matter your role!. </p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/16916516-from-special-forces-to-cybersecurity-rich-greene-on-communication-and-persuasion-in-infosec.mp3" length="34106121" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-16916516</guid>
    <pubDate>Wed, 09 Apr 2025 14:00:00 -0400</pubDate>
    <itunes:duration>2835</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>5</itunes:season>
    <itunes:episode>6</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>SOC Dashboards Done Right with Ryan Thompson</itunes:title>
    <title>SOC Dashboards Done Right with Ryan Thompson</title>
    <itunes:summary><![CDATA[In this episode, we sit down with Ryan Thompson, a seasoned expert in building dashboards that actually detect real threats—not just look pretty. With experience at Elastic, Alert Logic, and top EDR vendors, Ryan shares deep insights into the science behind effective dashboards and how security teams can cut through the noise to find the threats on your network. We cover: Why most SOC dashboards fail to deliver real insights—and how to fix them.The right way to structure dashboards for SIEM, ...]]></itunes:summary>
    <description><![CDATA[<p>In this episode, we sit down with <b>Ryan Thompson</b>, a seasoned expert in building dashboards that actually <b>detect real threats</b>—not just look pretty. With experience at Elastic, Alert Logic, and top EDR vendors, Ryan shares deep insights into <b>the science behind effective dashboards</b> and how security teams can <b>cut through the noise to find the threats on your network</b>.</p><p>We cover:</p><ul><li>Why most SOC dashboards <b>fail to deliver real insights</b>—and how to fix them.</li><li>The <b>right way to structure dashboards</b> for SIEM, EDR, and threat hunting.</li><li>How to <b>visualize security data effectively</b> to make detection faster.</li><li>The balance between <b>automation, alerts, and analyst intuition</b>.</li></ul><p>If you’re a <b>SOC analyst, detection engineer, or security leader</b> looking to elevate your dashboard game and sharpen your cyber threat detection skills, this is an episode you won’t want to miss!</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>In this episode, we sit down with <b>Ryan Thompson</b>, a seasoned expert in building dashboards that actually <b>detect real threats</b>—not just look pretty. With experience at Elastic, Alert Logic, and top EDR vendors, Ryan shares deep insights into <b>the science behind effective dashboards</b> and how security teams can <b>cut through the noise to find the threats on your network</b>.</p><p>We cover:</p><ul><li>Why most SOC dashboards <b>fail to deliver real insights</b>—and how to fix them.</li><li>The <b>right way to structure dashboards</b> for SIEM, EDR, and threat hunting.</li><li>How to <b>visualize security data effectively</b> to make detection faster.</li><li>The balance between <b>automation, alerts, and analyst intuition</b>.</li></ul><p>If you’re a <b>SOC analyst, detection engineer, or security leader</b> looking to elevate your dashboard game and sharpen your cyber threat detection skills, this is an episode you won’t want to miss!</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/16605339-soc-dashboards-done-right-with-ryan-thompson.mp3" length="45470742" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-16605339</guid>
    <pubDate>Tue, 18 Feb 2025 09:00:00 -0500</pubDate>
    <itunes:duration>3782</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>5</itunes:season>
    <itunes:episode>5</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Success Simplified - The 3 Step Process for Hitting Your Career Goals in 2025 with John Hubbard</itunes:title>
    <title>Success Simplified - The 3 Step Process for Hitting Your Career Goals in 2025 with John Hubbard</title>
    <itunes:summary><![CDATA[Surprise!! It's a mini solo episode to kick off the new year and it's on one of the most important topics there is - how to achieve your goals in 2025 and beyond!  In this episode I talk about a topic I've never covered anywhere before - my personal system for productivity and how it helps me, and can likely you help you stay on track for those 2025 goals and stay aligned with what is most important in your life.   Check this episode out for some useful productivity tips, inspiration, re...]]></itunes:summary>
    <description><![CDATA[<p>Surprise!! It&apos;s a mini solo episode to kick off the new year and it&apos;s on one of the most important topics there is - how to achieve your goals in 2025 and beyond!<br/><br/>In this episode I talk about a topic I&apos;ve never covered anywhere before - my personal system for productivity and how it helps me, and can likely you help you stay on track for those 2025 goals and stay aligned with what is most important in your life. <br/><br/>Check this episode out for some useful productivity tips, inspiration, recommendations for some of my favorite books, and fuel to get fired up for 2025! <br/><br/>HAPPY NEW YEAR! <br/><br/>Note: The episode thumbnail is the actual picture that I took of the quote that I mention seeing in the coffee shop that day in 2018. <br/><br/>Episode Notes</p><ul><li><a href='https://www.youtube.com/watch?v=u4ZoJKF_VuA'>Simon Sinek - Start With Why</a></li><li><a href='https://personalmba.com/five-fold-why/'>The 5-Fold Why Technique</a></li><li>Book - <a href='https://12weekyear.com/'>The 12 Week Year</a></li><li>Book - <a href='https://the1thing.com/book/'>The ONE Thing</a></li><li><a href='https://obsidian.md/'>Obsidian</a></li><li><a href='https://www.eisenhower.me/eisenhower-matrix/'>The Eisenhower Matrix</a></li><li>Book - <a href='https://austinkleon.com/steal/'>Steal Like An Artist</a></li><li>Book - <a href='https://www.oliverburkeman.com/books'>4000 Weeks: Time Management for Mortals</a></li></ul><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>Surprise!! It&apos;s a mini solo episode to kick off the new year and it&apos;s on one of the most important topics there is - how to achieve your goals in 2025 and beyond!<br/><br/>In this episode I talk about a topic I&apos;ve never covered anywhere before - my personal system for productivity and how it helps me, and can likely you help you stay on track for those 2025 goals and stay aligned with what is most important in your life. <br/><br/>Check this episode out for some useful productivity tips, inspiration, recommendations for some of my favorite books, and fuel to get fired up for 2025! <br/><br/>HAPPY NEW YEAR! <br/><br/>Note: The episode thumbnail is the actual picture that I took of the quote that I mention seeing in the coffee shop that day in 2018. <br/><br/>Episode Notes</p><ul><li><a href='https://www.youtube.com/watch?v=u4ZoJKF_VuA'>Simon Sinek - Start With Why</a></li><li><a href='https://personalmba.com/five-fold-why/'>The 5-Fold Why Technique</a></li><li>Book - <a href='https://12weekyear.com/'>The 12 Week Year</a></li><li>Book - <a href='https://the1thing.com/book/'>The ONE Thing</a></li><li><a href='https://obsidian.md/'>Obsidian</a></li><li><a href='https://www.eisenhower.me/eisenhower-matrix/'>The Eisenhower Matrix</a></li><li>Book - <a href='https://austinkleon.com/steal/'>Steal Like An Artist</a></li><li>Book - <a href='https://www.oliverburkeman.com/books'>4000 Weeks: Time Management for Mortals</a></li></ul><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/16364138-success-simplified-the-3-step-process-for-hitting-your-career-goals-in-2025-with-john-hubbard.mp3" length="21668351" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/10d9u5e1eac9k8le2sjlkl3og2gt?.jpg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-16364138</guid>
    <pubDate>Wed, 01 Jan 2025 09:00:00 -0500</pubDate>
    <itunes:duration>1798</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>5</itunes:season>
    <itunes:episode>4</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>How Phishing Resistant Credentials Work with Mark Morowczynski and Tarek Dawoud</itunes:title>
    <title>How Phishing Resistant Credentials Work with Mark Morowczynski and Tarek Dawoud</title>
    <itunes:summary><![CDATA[Mark Morowczynski returns for his 4th(!) time with his Microsoft coworker and identity and authentication expert Tarek Dawoud in this incredibly insightful conversation on the what, why, and how of  phishing resistant credentials that YOU can implement right now!   This conversation covers: What makes MFA phishable?What phishing resistant credentials are and how they workThe history and modern methods for phishing resistant credentialsWhat attacks will be used once we move to phishi...]]></itunes:summary>
    <description><![CDATA[<p>Mark Morowczynski returns for his 4th(!) time with his Microsoft coworker and identity and authentication expert Tarek Dawoud in this incredibly insightful conversation on the what, why, and how of  phishing resistant credentials that YOU can implement right now!<br/> <br/>This conversation covers:</p><ul><li>What makes MFA phishable?</li><li>What phishing resistant credentials are and how they work</li><li>The history and modern methods for phishing resistant credentials</li><li>What attacks will be used once we move to phishing resistant credentials, and how to prevent and detect it</li><li>How verified digital identities and corporate identification can help further reduce risk of help desk based attacks</li><li>Shifting the culture to adopt a passwordless login</li><li>Key logs to detect identity attacks</li><li>Resources for learning KQL</li></ul><p><br/>Episode Links:</p><ul><li>Tarek Explains Phishing Resistant Authentication: <a href='https://www.youtube.com/watch?v=3wtwUh6iyxY'>https://www.youtube.com/watch?v=3wtwUh6iyxY</a></li><li>Microsoft Digital Defense Report: <a href='https://www.microsoft.com/en-us/security/security-insider/intelligence-reports/microsoft-digital-defense-report-2024'>https://www.microsoft.com/en-us/security/security-insider/intelligence-reports/microsoft-digital-defense-report-2024</a></li><li>Nuance: <a href='https://www.nuance.com/index.html'>https://www.nuance.com/index.html</a></li><li>Book - The Definitive Guide to KQL: <a href='https://www.microsoftpressstore.com/store/definitive-guide-to-kql-using-kusto-query-language-9780138293383'>https://www.microsoftpressstore.com/store/definitive-guide-to-kql-using-kusto-query-language-9780138293383 </a></li><li>KQL Github Repo: <a href='https://github.com/kqlmspress'>github.com/kqlmspress</a> </li><li>Kusto Detective Agency: <a href='https://detective.kusto.io/'>https://detective.kusto.io/</a></li></ul><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>Mark Morowczynski returns for his 4th(!) time with his Microsoft coworker and identity and authentication expert Tarek Dawoud in this incredibly insightful conversation on the what, why, and how of  phishing resistant credentials that YOU can implement right now!<br/> <br/>This conversation covers:</p><ul><li>What makes MFA phishable?</li><li>What phishing resistant credentials are and how they work</li><li>The history and modern methods for phishing resistant credentials</li><li>What attacks will be used once we move to phishing resistant credentials, and how to prevent and detect it</li><li>How verified digital identities and corporate identification can help further reduce risk of help desk based attacks</li><li>Shifting the culture to adopt a passwordless login</li><li>Key logs to detect identity attacks</li><li>Resources for learning KQL</li></ul><p><br/>Episode Links:</p><ul><li>Tarek Explains Phishing Resistant Authentication: <a href='https://www.youtube.com/watch?v=3wtwUh6iyxY'>https://www.youtube.com/watch?v=3wtwUh6iyxY</a></li><li>Microsoft Digital Defense Report: <a href='https://www.microsoft.com/en-us/security/security-insider/intelligence-reports/microsoft-digital-defense-report-2024'>https://www.microsoft.com/en-us/security/security-insider/intelligence-reports/microsoft-digital-defense-report-2024</a></li><li>Nuance: <a href='https://www.nuance.com/index.html'>https://www.nuance.com/index.html</a></li><li>Book - The Definitive Guide to KQL: <a href='https://www.microsoftpressstore.com/store/definitive-guide-to-kql-using-kusto-query-language-9780138293383'>https://www.microsoftpressstore.com/store/definitive-guide-to-kql-using-kusto-query-language-9780138293383 </a></li><li>KQL Github Repo: <a href='https://github.com/kqlmspress'>github.com/kqlmspress</a> </li><li>Kusto Detective Agency: <a href='https://detective.kusto.io/'>https://detective.kusto.io/</a></li></ul><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/15895371-how-phishing-resistant-credentials-work-with-mark-morowczynski-and-tarek-dawoud.mp3" length="39000840" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-15895371</guid>
    <pubDate>Mon, 02 Dec 2024 02:00:00 -0500</pubDate>
    <itunes:duration>3243</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>5</itunes:season>
    <itunes:episode>3</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>How GenAI is Changing Your SOC for the Better with Seth Misenar</itunes:title>
    <title>How GenAI is Changing Your SOC for the Better with Seth Misenar</title>
    <itunes:summary><![CDATA[In this mega-discussion with Seth Misenar on GenAI and LLM usage for security operations we cover some very interesting questions such as:  - The importance of natural language processing in Sec Ops - How AI is helping us detect phishing email - Where and how AI is lowering the bar for entry-level security SOC roles - Should we worry about AI hallucinations or AI taking our jobs? - What is a reasoning model and how is it different than what we've seen so far? - The future of AI - Multimo...]]></itunes:summary>
    <description><![CDATA[<p>In this mega-discussion with Seth Misenar on GenAI and LLM usage for security operations we cover some very interesting questions such as: </p><p>- The importance of natural language processing in Sec Ops<br/>- How AI is helping us detect phishing email<br/>- Where and how AI is lowering the bar for entry-level security SOC roles<br/>- Should we worry about AI hallucinations or AI taking our jobs?<br/>- What is a reasoning model and how is it different than what we&apos;ve seen so far?<br/>- The future of AI - Multimodal interaction, Larger Context Windows, RAG, and more<br/>- What is Agentic AI and why will it change the game?</p><p>Episode Links:</p><ul><li>The book from Manning Seth liked as a thoughtful accessible on-ramp: <a href='https://urldefense.com/v3/__https:/www.manning.com/books/introduction-to-generative-ai__;!!MlQdS1fu!XpQ_7CW-eArPO70Gwmj5uma-O_pl1HXKN2UKHwHrbPdWdiPfGwUJTxviTTfR2kacDzDvGgo9atliwsDcHA$'>https://www.manning.com/books/introduction-to-generative-ai</a></li><li>Coursera prompt engineering course series: <a href='https://urldefense.com/v3/__https:/coursera.org/specializations/prompt-engineering__;!!MlQdS1fu!XpQ_7CW-eArPO70Gwmj5uma-O_pl1HXKN2UKHwHrbPdWdiPfGwUJTxviTTfR2kacDzDvGgo9atka9gHl3g$'>https://coursera.org/specializations/prompt-engineering</a></li><li>Gandalf Online Prompt Injection Challenges from Lakera (FYI Seth finds a lot of Lakera’s content to be really high-quality and useful): <a href='https://urldefense.com/v3/__https:/gandalf.lakera.ai/baseline__;!!MlQdS1fu!XpQ_7CW-eArPO70Gwmj5uma-O_pl1HXKN2UKHwHrbPdWdiPfGwUJTxviTTfR2kacDzDvGgo9atlclsflCg$'>https://gandalf.lakera.ai/baseline</a></li><li>“Nonsense on stilts” reference from Gary Marcus in response to the Google employee claiming LaMDA was sentient: <a href='https://urldefense.com/v3/__https:/garymarcus.substack.com/p/nonsense-on-stilts?utm_source=twitter&amp;sd=pf__;!!MlQdS1fu!XpQ_7CW-eArPO70Gwmj5uma-O_pl1HXKN2UKHwHrbPdWdiPfGwUJTxviTTfR2kacDzDvGgo9atkVK_Zl7w$'>https://garymarcus.substack.com/p/nonsense-on-stilts?utm_source=twitter&amp;sd=pf</a>. </li><li>AI as a monster with a smiley face image: <a href='https://urldefense.com/v3/__https:/knowyourmeme.com/memes/shoggoth-with-smiley-face-artificial-intelligence__;!!MlQdS1fu!XpQ_7CW-eArPO70Gwmj5uma-O_pl1HXKN2UKHwHrbPdWdiPfGwUJTxviTTfR2kacDzDvGgo9atmy3nJh1A$'>https://knowyourmeme.com/memes/shoggoth-with-smiley-face-artificial-intelligence</a></li><li>Ethan Mollick is the Wharton professor Seth mentioned, Seth says his “One Useful Thing” Substack is a valuable and thought provoking source: <a href='https://urldefense.com/v3/__https:/www.oneusefulthing.org/__;!!MlQdS1fu!XpQ_7CW-eArPO70Gwmj5uma-O_pl1HXKN2UKHwHrbPdWdiPfGwUJTxviTTfR2kacDzDvGgo9atnSNlZHow$'>https://www.oneusefulthing.org/</a>. Also his book, Co-Intelligence: Living and Working with AI, would also be worth checking out: <a href='https://urldefense.com/v3/__https:/www.penguinrandomhouse.com/books/741805/co-intelligence-by-ethan-mollick/__;!!MlQdS1fu!XpQ_7CW-eArPO70Gwmj5uma-O_pl1HXKN2UKHwHrbPdWdiPfGwUJTxviTTfR2kacDzDvGgo9atlSgwCOXQ$'>https://www.penguinrandomhouse.com/book</a></li></ul><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>In this mega-discussion with Seth Misenar on GenAI and LLM usage for security operations we cover some very interesting questions such as: </p><p>- The importance of natural language processing in Sec Ops<br/>- How AI is helping us detect phishing email<br/>- Where and how AI is lowering the bar for entry-level security SOC roles<br/>- Should we worry about AI hallucinations or AI taking our jobs?<br/>- What is a reasoning model and how is it different than what we&apos;ve seen so far?<br/>- The future of AI - Multimodal interaction, Larger Context Windows, RAG, and more<br/>- What is Agentic AI and why will it change the game?</p><p>Episode Links:</p><ul><li>The book from Manning Seth liked as a thoughtful accessible on-ramp: <a href='https://urldefense.com/v3/__https:/www.manning.com/books/introduction-to-generative-ai__;!!MlQdS1fu!XpQ_7CW-eArPO70Gwmj5uma-O_pl1HXKN2UKHwHrbPdWdiPfGwUJTxviTTfR2kacDzDvGgo9atliwsDcHA$'>https://www.manning.com/books/introduction-to-generative-ai</a></li><li>Coursera prompt engineering course series: <a href='https://urldefense.com/v3/__https:/coursera.org/specializations/prompt-engineering__;!!MlQdS1fu!XpQ_7CW-eArPO70Gwmj5uma-O_pl1HXKN2UKHwHrbPdWdiPfGwUJTxviTTfR2kacDzDvGgo9atka9gHl3g$'>https://coursera.org/specializations/prompt-engineering</a></li><li>Gandalf Online Prompt Injection Challenges from Lakera (FYI Seth finds a lot of Lakera’s content to be really high-quality and useful): <a href='https://urldefense.com/v3/__https:/gandalf.lakera.ai/baseline__;!!MlQdS1fu!XpQ_7CW-eArPO70Gwmj5uma-O_pl1HXKN2UKHwHrbPdWdiPfGwUJTxviTTfR2kacDzDvGgo9atlclsflCg$'>https://gandalf.lakera.ai/baseline</a></li><li>“Nonsense on stilts” reference from Gary Marcus in response to the Google employee claiming LaMDA was sentient: <a href='https://urldefense.com/v3/__https:/garymarcus.substack.com/p/nonsense-on-stilts?utm_source=twitter&amp;sd=pf__;!!MlQdS1fu!XpQ_7CW-eArPO70Gwmj5uma-O_pl1HXKN2UKHwHrbPdWdiPfGwUJTxviTTfR2kacDzDvGgo9atkVK_Zl7w$'>https://garymarcus.substack.com/p/nonsense-on-stilts?utm_source=twitter&amp;sd=pf</a>. </li><li>AI as a monster with a smiley face image: <a href='https://urldefense.com/v3/__https:/knowyourmeme.com/memes/shoggoth-with-smiley-face-artificial-intelligence__;!!MlQdS1fu!XpQ_7CW-eArPO70Gwmj5uma-O_pl1HXKN2UKHwHrbPdWdiPfGwUJTxviTTfR2kacDzDvGgo9atmy3nJh1A$'>https://knowyourmeme.com/memes/shoggoth-with-smiley-face-artificial-intelligence</a></li><li>Ethan Mollick is the Wharton professor Seth mentioned, Seth says his “One Useful Thing” Substack is a valuable and thought provoking source: <a href='https://urldefense.com/v3/__https:/www.oneusefulthing.org/__;!!MlQdS1fu!XpQ_7CW-eArPO70Gwmj5uma-O_pl1HXKN2UKHwHrbPdWdiPfGwUJTxviTTfR2kacDzDvGgo9atnSNlZHow$'>https://www.oneusefulthing.org/</a>. Also his book, Co-Intelligence: Living and Working with AI, would also be worth checking out: <a href='https://urldefense.com/v3/__https:/www.penguinrandomhouse.com/books/741805/co-intelligence-by-ethan-mollick/__;!!MlQdS1fu!XpQ_7CW-eArPO70Gwmj5uma-O_pl1HXKN2UKHwHrbPdWdiPfGwUJTxviTTfR2kacDzDvGgo9atlSgwCOXQ$'>https://www.penguinrandomhouse.com/book</a></li></ul><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/15893963-how-genai-is-changing-your-soc-for-the-better-with-seth-misenar.mp3" length="68540324" type="audio/mpeg" />
    <itunes:author>SANS Institute</itunes:author>
    <guid isPermaLink="false">Buzzsprout-15893963</guid>
    <pubDate>Wed, 09 Oct 2024 07:00:00 -0400</pubDate>
    <itunes:duration>5704</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>5</itunes:season>
    <itunes:episode>2</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title> From Clues to Containment - Unraveling A Gift Card Fraud Scheme with Mark Jeanmougin</itunes:title>
    <title> From Clues to Containment - Unraveling A Gift Card Fraud Scheme with Mark Jeanmougin</title>
    <itunes:summary><![CDATA[In this episode, we take you behind the scenes of a complex gift card fraud investigation. Join host John Hubbard and guest Mark Jeanmougin as they explore the intricate details of uncovering and combating a clever case of cyber fraud. In this episode Mark discusses how the incident was identified, investigated, contained, and what lessons were learned along the way. Episode Links: - Mark's LinkedIn Profile: https://www.linkedin.com/in/markjx/ - Mark's Teaching Schedule: https://www.sans.org/...]]></itunes:summary>
    <description><![CDATA[<p>In this episode, we take you behind the scenes of a complex gift card fraud investigation. Join host John Hubbard and guest Mark Jeanmougin as they explore the intricate details of uncovering and combating a clever case of cyber fraud. In this episode Mark discusses how the incident was identified, investigated, contained, and what lessons were learned along the way.</p><p>Episode Links:<br/>- Mark&apos;s LinkedIn Profile: <a href='https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.linkedin.com%2Fin%2Fmarkjx%2F&amp;data=05%7C02%7CBSnyder%40sans.org%7C28a6b0b19d3644e7c25608dce7e4fe2e%7C06746f2723b44e85a3714c261f45dc12%7C1%7C0%7C638640217936925119%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&amp;sdata=Ugo66iwChn4SE%2FAAO%2BoP9BSwzQOkYSbrLhRSl94C0KA%3D&amp;reserved=0'>https://www.linkedin.com/in/markjx/</a><br/>- Mark&apos;s Teaching Schedule: <a href='https://www.sans.org/profiles/mark-jeanmougin/'>https://www.sans.org/profiles/mark-jeanmougin/</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>In this episode, we take you behind the scenes of a complex gift card fraud investigation. Join host John Hubbard and guest Mark Jeanmougin as they explore the intricate details of uncovering and combating a clever case of cyber fraud. In this episode Mark discusses how the incident was identified, investigated, contained, and what lessons were learned along the way.</p><p>Episode Links:<br/>- Mark&apos;s LinkedIn Profile: <a href='https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.linkedin.com%2Fin%2Fmarkjx%2F&amp;data=05%7C02%7CBSnyder%40sans.org%7C28a6b0b19d3644e7c25608dce7e4fe2e%7C06746f2723b44e85a3714c261f45dc12%7C1%7C0%7C638640217936925119%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&amp;sdata=Ugo66iwChn4SE%2FAAO%2BoP9BSwzQOkYSbrLhRSl94C0KA%3D&amp;reserved=0'>https://www.linkedin.com/in/markjx/</a><br/>- Mark&apos;s Teaching Schedule: <a href='https://www.sans.org/profiles/mark-jeanmougin/'>https://www.sans.org/profiles/mark-jeanmougin/</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/15893949-from-clues-to-containment-unraveling-a-gift-card-fraud-scheme-with-mark-jeanmougin.mp3" length="26161146" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-15893949</guid>
    <pubDate>Wed, 09 Oct 2024 07:00:00 -0400</pubDate>
    <itunes:duration>2173</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>5</itunes:season>
    <itunes:episode>1</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Bonus Episode: What does it take to author a cybersecurity book?</itunes:title>
    <title>Bonus Episode: What does it take to author a cybersecurity book?</title>
    <itunes:summary><![CDATA[Have you ever wondered what it takes to write and publish an information security book? In this special bonus episode following season 4, John discusses with Kathryn, Ingrid, and Carson the challenges and rewards of self-publishing, and the kind of effort that goes into producing a book like "11 Strategies of a World-Class Cybersecurity Operations Center".  This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations ...]]></itunes:summary>
    <description><![CDATA[<p>Have you ever wondered what it takes to write and publish an information security book? In this special bonus episode following season 4, John discusses with Kathryn, Ingrid, and Carson the challenges and rewards of self-publishing, and the kind of effort that goes into producing a book like &quot;11 Strategies of a World-Class Cybersecurity Operations Center&quot;.<br/><br/>This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of the book with the book’s authors Kathryn Knerler, Ingrid Parker, and Carson Zimmerman.<br/><br/>-----------<br/><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/><br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/><br/>Check out the details at sansurl.com/450 Hope to see you in class!</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>Have you ever wondered what it takes to write and publish an information security book? In this special bonus episode following season 4, John discusses with Kathryn, Ingrid, and Carson the challenges and rewards of self-publishing, and the kind of effort that goes into producing a book like &quot;11 Strategies of a World-Class Cybersecurity Operations Center&quot;.<br/><br/>This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of the book with the book’s authors Kathryn Knerler, Ingrid Parker, and Carson Zimmerman.<br/><br/>-----------<br/><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/><br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/><br/>Check out the details at sansurl.com/450 Hope to see you in class!</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/13343411-bonus-episode-what-does-it-take-to-author-a-cybersecurity-book.mp3" length="65686138" type="audio/mpeg" />
    <itunes:author>SANS Institute</itunes:author>
    <guid isPermaLink="false">Buzzsprout-13343411</guid>
    <pubDate>Thu, 03 Aug 2023 10:00:00 -0400</pubDate>
    <itunes:duration>5466</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>12</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Strategy 11: Turn up the Volume by Expanding SOC Functionality</itunes:title>
    <title>Strategy 11: Turn up the Volume by Expanding SOC Functionality</title>
    <itunes:summary><![CDATA["This final chapter of the book is no simple closer! "Turn Up the Volume by Expanding SOC Functionality" covers testing that your SOC is functioning as intended through activities such as Threat Hunting, Red and Purple Teaming, Adversary Emulation, Breach and Attack Simulation, tabletop exercises and more. There's even a discussion of cyber deception types and tactics, and how it can be used to further frustrate attackers. Join John, Kathryn, Ingrid, and Carson in this final chapter episode f...]]></itunes:summary>
    <description><![CDATA[<p>&quot;This final chapter of the book is no simple closer! &quot;Turn Up the Volume by Expanding SOC Functionality&quot; covers testing that your SOC is functioning as intended through activities such as Threat Hunting, Red and Purple Teaming, Adversary Emulation, Breach and Attack Simulation, tabletop exercises and more. There&apos;s even a discussion of cyber deception types and tactics, and how it can be used to further frustrate attackers. Join John, Kathryn, Ingrid, and Carson in this final chapter episode for some not to be missed tips! <br/><br/>This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of the book with the book’s authors Kathryn Knerler, Ingrid Parker, and Carson Zimmerman.<br/><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/><br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/><br/>Check out the details at sansurl.com/450 Hope to see you in class!</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>&quot;This final chapter of the book is no simple closer! &quot;Turn Up the Volume by Expanding SOC Functionality&quot; covers testing that your SOC is functioning as intended through activities such as Threat Hunting, Red and Purple Teaming, Adversary Emulation, Breach and Attack Simulation, tabletop exercises and more. There&apos;s even a discussion of cyber deception types and tactics, and how it can be used to further frustrate attackers. Join John, Kathryn, Ingrid, and Carson in this final chapter episode for some not to be missed tips! <br/><br/>This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of the book with the book’s authors Kathryn Knerler, Ingrid Parker, and Carson Zimmerman.<br/><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/><br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/><br/>Check out the details at sansurl.com/450 Hope to see you in class!</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/13246795-strategy-11-turn-up-the-volume-by-expanding-soc-functionality.mp3" length="62437108" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/1n6swmymm1qs3climtvrevlrknxm?.jpg" />
    <itunes:author>SANS Institute</itunes:author>
    <guid isPermaLink="false">Buzzsprout-13246795</guid>
    <pubDate>Tue, 18 Jul 2023 15:00:00 -0400</pubDate>
    <itunes:duration>5198</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>11</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Strategy 10: Measure Performance to Improve Performance</itunes:title>
    <title>Strategy 10: Measure Performance to Improve Performance</title>
    <itunes:summary><![CDATA["Metrics, is there any more confusing and contentious topic in cybersecurity? In this episode the authors cover their advice and approach to measuring your team so that issues can be quickly identified and performance can continuously improve!  This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of the book with the book’s authors Kathryn Knerler, Ingrid Par...]]></itunes:summary>
    <description><![CDATA[<p>&quot;Metrics, is there any more confusing and contentious topic in cybersecurity? In this episode the authors cover their advice and approach to measuring your team so that issues can be quickly identified and performance can continuously improve!<br/><br/>This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of the book with the book’s authors Kathryn Knerler, Ingrid Parker, and Carson Zimmerman.<br/><br/>Sponsor&apos;s Note:<br/><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/><br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/><br/>Check out the details at sansurl.com/450 Hope to see you in class!</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>&quot;Metrics, is there any more confusing and contentious topic in cybersecurity? In this episode the authors cover their advice and approach to measuring your team so that issues can be quickly identified and performance can continuously improve!<br/><br/>This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of the book with the book’s authors Kathryn Knerler, Ingrid Parker, and Carson Zimmerman.<br/><br/>Sponsor&apos;s Note:<br/><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/><br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/><br/>Check out the details at sansurl.com/450 Hope to see you in class!</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/13193797-strategy-10-measure-performance-to-improve-performance.mp3" length="38048385" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/wrjbs0ah2yt0xn9v78o4nsjmf47i?.jpg" />
    <itunes:author>SANS Institute</itunes:author>
    <guid isPermaLink="false">Buzzsprout-13193797</guid>
    <pubDate>Mon, 10 Jul 2023 09:00:00 -0400</pubDate>
    <itunes:duration>3166</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>10</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Strategy 9: Communicate Clearly, Collaborate Often, Share Generously</itunes:title>
    <title>Strategy 9: Communicate Clearly, Collaborate Often, Share Generously</title>
    <itunes:summary><![CDATA["Research has shown that communication is one of the most important factors for success in security incident response teams. In this chapter, the authors discuss the critical types of information that must be shared within the SOC, with the constituency, and with the greater cybersecurity community.   SANS Cyber Defense Discord Invite - sansurl.com/cyber-defense-discord  This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber S...]]></itunes:summary>
    <description><![CDATA[<p>&quot;Research has shown that communication is one of the most important factors for success in security incident response teams. In this chapter, the authors discuss the critical types of information that must be shared within the SOC, with the constituency, and with the greater cybersecurity community. <br/><br/>SANS Cyber Defense Discord Invite - sansurl.com/cyber-defense-discord<br/><br/>This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of the book with the book’s authors Kathryn Knerler, Ingrid Parker, and Carson Zimmerman.<br/><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/><br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/><br/>Check out the details at sansurl.com/450 Hope to see you in class!</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>&quot;Research has shown that communication is one of the most important factors for success in security incident response teams. In this chapter, the authors discuss the critical types of information that must be shared within the SOC, with the constituency, and with the greater cybersecurity community. <br/><br/>SANS Cyber Defense Discord Invite - sansurl.com/cyber-defense-discord<br/><br/>This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of the book with the book’s authors Kathryn Knerler, Ingrid Parker, and Carson Zimmerman.<br/><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/><br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/><br/>Check out the details at sansurl.com/450 Hope to see you in class!</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/13167443-strategy-9-communicate-clearly-collaborate-often-share-generously.mp3" length="45854481" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/3inq197k6k3ifnunpzb683h7lutq?.jpg" />
    <itunes:author>SANS Institute</itunes:author>
    <guid isPermaLink="false">Buzzsprout-13167443</guid>
    <pubDate>Wed, 05 Jul 2023 15:00:00 -0400</pubDate>
    <itunes:duration>3816</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>9</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>Strategy 8: Leverage Tools and Support Analyst Workflow</itunes:title>
    <title>Strategy 8: Leverage Tools and Support Analyst Workflow</title>
    <itunes:summary><![CDATA[Tool choice can be a make-or-break decision for security analysts, driving whether getting work done is a struggle, or an efficient, stress-free experience. How can we select the right tools for the job? Which tools are most important? Answers to these questions and more are in this week's episode of Blueprint!  This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a ch...]]></itunes:summary>
    <description><![CDATA[<p>Tool choice can be a make-or-break decision for security analysts, driving whether getting work done is a struggle, or an efficient, stress-free experience. How can we select the right tools for the job? Which tools are most important? Answers to these questions and more are in this week&apos;s episode of Blueprint!<br/><br/>This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of the book with the book’s authors Kathryn Knerler, Ingrid Parker, and Carson Zimmerman.<br/><br/><b>Sponsor&apos;s Note:<br/></b><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/><br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/><br/>Check out the details at sansurl.com/450 - Hope to see you in class!</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>Tool choice can be a make-or-break decision for security analysts, driving whether getting work done is a struggle, or an efficient, stress-free experience. How can we select the right tools for the job? Which tools are most important? Answers to these questions and more are in this week&apos;s episode of Blueprint!<br/><br/>This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of the book with the book’s authors Kathryn Knerler, Ingrid Parker, and Carson Zimmerman.<br/><br/><b>Sponsor&apos;s Note:<br/></b><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/><br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/><br/>Check out the details at sansurl.com/450 - Hope to see you in class!</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/13111847-strategy-8-leverage-tools-and-support-analyst-workflow.mp3" length="61716739" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/swps2rzhcpp1lgn2xt2isuq7hm1f?.jpg" />
    <itunes:author>SANS Institute</itunes:author>
    <guid isPermaLink="false">Buzzsprout-13111847</guid>
    <pubDate>Mon, 26 Jun 2023 16:00:00 -0400</pubDate>
    <itunes:duration>5138</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>8</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Blueprint Live at the SANS Blue Team Summit 2023</itunes:title>
    <title>Blueprint Live at the SANS Blue Team Summit 2023</title>
    <itunes:summary><![CDATA[In this special live recording from the SANS Blue Team Summit 2023, Kathryn Knerler, Ingrid Parker, and Carson Zimmerman joined John Hubbard they share their insights and expertise with attendees by answering their pressing questions. From discussing the most effective strategies for building a successful SOC to sharing tips on how to stay ahead of emerging cyber threats, our guests provide invaluable advice for those who work in a security operations center (SOC). If you're looking to take y...]]></itunes:summary>
    <description><![CDATA[<p>In this special live recording from the SANS Blue Team Summit 2023, Kathryn Knerler, Ingrid Parker, and Carson Zimmerman joined John Hubbard they share their insights and expertise with attendees by answering their pressing questions. From discussing the most effective strategies for building a successful SOC to sharing tips on how to stay ahead of emerging cyber threats, our guests provide invaluable advice for those who work in a security operations center (SOC). If you&apos;re looking to take your SOC to the next level or are simply interested in the latest developments in cybersecurity, this episode is a must-listen. Tune in to hear from some of the most respected experts in the field and gain valuable insights that could make all the difference in how you approach cybersecurity.<br/><br/>This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of the book with the book’s authors Kathryn Knerler, Ingrid Parker, and Carson Zimmerman.<br/><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/><br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/><br/>Check out the details at sansurl.com/450 Hope to see you in class!</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>In this special live recording from the SANS Blue Team Summit 2023, Kathryn Knerler, Ingrid Parker, and Carson Zimmerman joined John Hubbard they share their insights and expertise with attendees by answering their pressing questions. From discussing the most effective strategies for building a successful SOC to sharing tips on how to stay ahead of emerging cyber threats, our guests provide invaluable advice for those who work in a security operations center (SOC). If you&apos;re looking to take your SOC to the next level or are simply interested in the latest developments in cybersecurity, this episode is a must-listen. Tune in to hear from some of the most respected experts in the field and gain valuable insights that could make all the difference in how you approach cybersecurity.<br/><br/>This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of the book with the book’s authors Kathryn Knerler, Ingrid Parker, and Carson Zimmerman.<br/><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/><br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/><br/>Check out the details at sansurl.com/450 Hope to see you in class!</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/13088790-blueprint-live-at-the-sans-blue-team-summit-2023.mp3" length="46662115" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/rfvt8moomd61avnur3mee5i9pss1?.jpg" />
    <itunes:author>SANS Institute</itunes:author>
    <guid isPermaLink="false">Buzzsprout-13088790</guid>
    <pubDate>Thu, 22 Jun 2023 10:00:00 -0400</pubDate>
    <itunes:duration>3883</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episodeType>bonus</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Strategy 7: Select and Collect the Right Data</itunes:title>
    <title>Strategy 7: Select and Collect the Right Data</title>
    <itunes:summary><![CDATA[There's no denying that the average security team is completely overwhelmed with options for data to collect. With a deluge of endpoint, network, and cloud data sources to collect, how to do we identify and collect the most useful data sources? That's the topic of this episode. Join Kathryn, Ingrid, Carson, and John in this episode for a discussion on tactical data collection that will ensure your team doesn't miss the signs of an impending incident!  This special season of the Blueprint Podc...]]></itunes:summary>
    <description><![CDATA[<p>There&apos;s no denying that the average security team is completely overwhelmed with options for data to collect. With a deluge of endpoint, network, and cloud data sources to collect, how to do we identify and collect the most useful data sources? That&apos;s the topic of this episode. Join Kathryn, Ingrid, Carson, and John in this episode for a discussion on tactical data collection that will ensure your team doesn&apos;t miss the signs of an impending incident!<br/><br/>This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of the book with the book’s authors Kathryn Knerler, Ingrid Parker, and Carson Zimmerman.<br/><br/><br/>-----------<br/>Support for the Blueprint podcast comes from the SANS Institute.<br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/>Check out the details at sansurl.com/450 Hope to see you in class!<br/>Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube<br/>Follow John Hubbard: Twitter | LinkedIn</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>There&apos;s no denying that the average security team is completely overwhelmed with options for data to collect. With a deluge of endpoint, network, and cloud data sources to collect, how to do we identify and collect the most useful data sources? That&apos;s the topic of this episode. Join Kathryn, Ingrid, Carson, and John in this episode for a discussion on tactical data collection that will ensure your team doesn&apos;t miss the signs of an impending incident!<br/><br/>This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of the book with the book’s authors Kathryn Knerler, Ingrid Parker, and Carson Zimmerman.<br/><br/><br/>-----------<br/>Support for the Blueprint podcast comes from the SANS Institute.<br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/>Check out the details at sansurl.com/450 Hope to see you in class!<br/>Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube<br/>Follow John Hubbard: Twitter | LinkedIn</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/13069260-strategy-7-select-and-collect-the-right-data.mp3" length="45610164" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/o4atx1uo1rvbdua56kpqcf6dsuc5?.jpg" />
    <itunes:author>SANS Institute</itunes:author>
    <guid isPermaLink="false">Buzzsprout-13069260</guid>
    <pubDate>Mon, 19 Jun 2023 17:00:00 -0400</pubDate>
    <itunes:duration>3796</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>7</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Strategy 6: Illuminate Adversaries with Cyber Threat Intelligence</itunes:title>
    <title>Strategy 6: Illuminate Adversaries with Cyber Threat Intelligence</title>
    <itunes:summary><![CDATA[Every security team has limited budget and time, how do you know where to focus? Cyber Threat Intelligence provides those answers! In this episode, Ingrid, Carson and Kathryn describe how we can use CTI to focus our defensive efforts to understand our most likely attacks and attackers and move towards prioritizing what truly matters.  This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode Jo...]]></itunes:summary>
    <description><![CDATA[<p>Every security team has limited budget and time, how do you know where to focus? Cyber Threat Intelligence provides those answers! In this episode, Ingrid, Carson and Kathryn describe how we can use CTI to focus our defensive efforts to understand our most likely attacks and attackers and move towards prioritizing what truly matters.<br/><br/>This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of the book with the book’s authors Kathryn Knerler, Ingrid Parker, and Carson Zimmerman.<br/><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/>Check out the details at sansurl.com/450 Hope to see you in class!<br/>Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube<br/>Follow John Hubbard: Twitter | LinkedIn</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>Every security team has limited budget and time, how do you know where to focus? Cyber Threat Intelligence provides those answers! In this episode, Ingrid, Carson and Kathryn describe how we can use CTI to focus our defensive efforts to understand our most likely attacks and attackers and move towards prioritizing what truly matters.<br/><br/>This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of the book with the book’s authors Kathryn Knerler, Ingrid Parker, and Carson Zimmerman.<br/><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/>Check out the details at sansurl.com/450 Hope to see you in class!<br/>Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube<br/>Follow John Hubbard: Twitter | LinkedIn</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/13026491-strategy-6-illuminate-adversaries-with-cyber-threat-intelligence.mp3" length="41646677" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/hizqfh7y64wn6lsgl88q4o383llt?.jpg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-13026491</guid>
    <pubDate>Mon, 12 Jun 2023 16:00:00 -0400</pubDate>
    <itunes:duration>3465</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>6</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Strategy 5: Prioritize Incident Response</itunes:title>
    <title>Strategy 5: Prioritize Incident Response</title>
    <itunes:summary><![CDATA[No security team is perfect, so in this episode, authors Carson, Ingrid, and Kathryn discuss what it takes to prepare for fast, effective incident response capability. Covering preparation, planning and execution, Strategy 5 will teach your team how to jump into action at the earliest sign of problems.  This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of ...]]></itunes:summary>
    <description><![CDATA[<p>No security team is perfect, so in this episode, authors Carson, Ingrid, and Kathryn discuss what it takes to prepare for fast, effective incident response capability. Covering preparation, planning and execution, Strategy 5 will teach your team how to jump into action at the earliest sign of problems.<br/><br/>This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of the book with the book’s authors Kathryn Knerler, Ingrid Parker, and Carson Zimmerman.<br/><br/>Sponsor&apos;s Note<br/><br/>-----------<br/>Support for the Blueprint podcast comes from the SANS Institute.<br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/>Check out the details at sansurl.com/450 Hope to see you in class!<br/>Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube<br/>Follow John Hubbard: Twitter | LinkedIn</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>No security team is perfect, so in this episode, authors Carson, Ingrid, and Kathryn discuss what it takes to prepare for fast, effective incident response capability. Covering preparation, planning and execution, Strategy 5 will teach your team how to jump into action at the earliest sign of problems.<br/><br/>This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of the book with the book’s authors Kathryn Knerler, Ingrid Parker, and Carson Zimmerman.<br/><br/>Sponsor&apos;s Note<br/><br/>-----------<br/>Support for the Blueprint podcast comes from the SANS Institute.<br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/>Check out the details at sansurl.com/450 Hope to see you in class!<br/>Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube<br/>Follow John Hubbard: Twitter | LinkedIn</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/12980457-strategy-5-prioritize-incident-response.mp3" length="61508936" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/byc1it91an6zrl01pv26kajxhb5l?.jpg" />
    <itunes:author>SANS Institute</itunes:author>
    <guid isPermaLink="false">Buzzsprout-12980457</guid>
    <pubDate>Mon, 05 Jun 2023 10:00:00 -0400</pubDate>
    <itunes:duration>5121</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>5</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Strategy 4: Hire AND Grow Quality Staff</itunes:title>
    <title>Strategy 4: Hire AND Grow Quality Staff</title>
    <itunes:summary><![CDATA[In this episode we dive deep on the "People" factor of the SOC. Who should you hire, what skills should you hire for, what backgrounds are most likely to lead to success for your team? We also get into what happens after the hire - training, growth, and supporting your team in their skill and career development. This one is a must-listen for all the managers out there. We're all trying to build the highest skilled, most supportive team with low turnover, and the tips our authors bring to this...]]></itunes:summary>
    <description><![CDATA[<p>In this episode we dive deep on the &quot;People&quot; factor of the SOC. Who should you hire, what skills should you hire for, what backgrounds are most likely to lead to success for your team? We also get into what happens after the hire - training, growth, and supporting your team in their skill and career development. This one is a must-listen for all the managers out there. We&apos;re all trying to build the highest skilled, most supportive team with low turnover, and the tips our authors bring to this episode on chapter 4 - &quot;Hire AND Grow Quality Staff&quot; will be crucial in that mission.<br/><br/>This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of the book with the book’s authors Kathryn Knerler, Ingrid Parker, and Carson Zimmerman.<br/><br/>-----------<br/><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/><br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/><br/>Check out the details at sansurl.com/450 Hope to see you in class!<br/><br/>Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube<br/>Follow John Hubbard: Twitter | LinkedIn</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>In this episode we dive deep on the &quot;People&quot; factor of the SOC. Who should you hire, what skills should you hire for, what backgrounds are most likely to lead to success for your team? We also get into what happens after the hire - training, growth, and supporting your team in their skill and career development. This one is a must-listen for all the managers out there. We&apos;re all trying to build the highest skilled, most supportive team with low turnover, and the tips our authors bring to this episode on chapter 4 - &quot;Hire AND Grow Quality Staff&quot; will be crucial in that mission.<br/><br/>This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of the book with the book’s authors Kathryn Knerler, Ingrid Parker, and Carson Zimmerman.<br/><br/>-----------<br/><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/><br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/><br/>Check out the details at sansurl.com/450 Hope to see you in class!<br/><br/>Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube<br/>Follow John Hubbard: Twitter | LinkedIn</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/12926690-strategy-4-hire-and-grow-quality-staff.mp3" length="52989738" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/vaayahms2igesqmgdux657gj5vr8?.jpg" />
    <itunes:author>SANS Institute</itunes:author>
    <guid isPermaLink="false">Buzzsprout-12926690</guid>
    <pubDate>Mon, 29 May 2023 05:00:00 -0400</pubDate>
    <itunes:duration>4411</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>4</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Strategy 3: Build a SOC Structure to Match Your Organizational Needs</itunes:title>
    <title>Strategy 3: Build a SOC Structure to Match Your Organizational Needs</title>
    <itunes:summary><![CDATA[In this episode we discuss how to decide on the right org structure and capabilities of your SOC. This includes questions like tiered vs. tierless models, which capabilities the SOC should focus on, centralized vs. distributed SOCs, outsourcing of duties and staff augmentation considerations, and also where the SOC might sit in the larger chart of your organization. Every SOC needs to be tailored to best meet the mission, and chapter 3 - "Build a SOC Structure to Match Your Organizational Nee...]]></itunes:summary>
    <description><![CDATA[<p>In this episode we discuss how to decide on the right org structure and capabilities of your SOC. This includes questions like tiered vs. tierless models, which capabilities the SOC should focus on, centralized vs. distributed SOCs, outsourcing of duties and staff augmentation considerations, and also where the SOC might sit in the larger chart of your organization. Every SOC needs to be tailored to best meet the mission, and chapter 3 - &quot;Build a SOC Structure to Match Your Organizational Needs&quot; will help you get there.<br/><br/>This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of the book with the book’s authors Kathryn Knerler, Ingrid Parker, and Carson Zimmerman.<br/><br/>Sponsor&apos;s Note<br/><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/><br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/><br/>Check out the details at sansurl.com/450 Hope to see you in class!<br/>Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube<br/>Follow John Hubbard: Twitter | LinkedIn</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>In this episode we discuss how to decide on the right org structure and capabilities of your SOC. This includes questions like tiered vs. tierless models, which capabilities the SOC should focus on, centralized vs. distributed SOCs, outsourcing of duties and staff augmentation considerations, and also where the SOC might sit in the larger chart of your organization. Every SOC needs to be tailored to best meet the mission, and chapter 3 - &quot;Build a SOC Structure to Match Your Organizational Needs&quot; will help you get there.<br/><br/>This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of the book with the book’s authors Kathryn Knerler, Ingrid Parker, and Carson Zimmerman.<br/><br/>Sponsor&apos;s Note<br/><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/><br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/><br/>Check out the details at sansurl.com/450 Hope to see you in class!<br/>Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube<br/>Follow John Hubbard: Twitter | LinkedIn</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/12895131-strategy-3-build-a-soc-structure-to-match-your-organizational-needs.mp3" length="51900394" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/d5uujvjr7zxbrrtq5il08kse07rd?.jpg" />
    <itunes:author>SANS Institute</itunes:author>
    <guid isPermaLink="false">Buzzsprout-12895131</guid>
    <pubDate>Mon, 22 May 2023 09:00:00 -0400</pubDate>
    <itunes:duration>4320</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>3</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Strategy 2: Give the SOC the Authority to Do Its Job</itunes:title>
    <title>Strategy 2: Give the SOC the Authority to Do Its Job</title>
    <itunes:summary><![CDATA[Though a SOC is responsible for protecting your organization's assets, it is not the owner of those systems. If the SOC is not established with a clear charter and authority to act, it may quickly become difficult to be effective. Who should the SOC report to, what should be in a SOC charter, and how can we make these tough decisions? Those are the questions covered in this episode of our special "11 Strategies" season. This episode covers chapter 2 of the book - "Give the SOC the Authority t...]]></itunes:summary>
    <description><![CDATA[<p>Though a SOC is responsible for protecting your organization&apos;s assets, it is not the owner of those systems. If the SOC is not established with a clear charter and authority to act, it may quickly become difficult to be effective. Who should the SOC report to, what should be in a SOC charter, and how can we make these tough decisions? Those are the questions covered in this episode of our special &quot;11 Strategies&quot; season. This episode covers chapter 2 of the book - &quot;Give the SOC the Authority to Do Its Job&quot;.<br/><br/>This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of the book with the book’s authors Kathryn Knerler, Ingrid Parker, and Carson Zimmerman.<br/><br/><br/>Visit <a href='https://www.mitre.org/news-insights/publication/11-strategies-world-class-cybersecurity-operations-center'>Mitre&apos;s page</a> for more information <br/>-----------<br/><br/>Sponsor&apos;s Note<br/><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/>Check out the details at sansurl.com/450 Hope to see you in class!<br/>Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube<br/>Follow John Hubbard: Twitter | LinkedIn</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>Though a SOC is responsible for protecting your organization&apos;s assets, it is not the owner of those systems. If the SOC is not established with a clear charter and authority to act, it may quickly become difficult to be effective. Who should the SOC report to, what should be in a SOC charter, and how can we make these tough decisions? Those are the questions covered in this episode of our special &quot;11 Strategies&quot; season. This episode covers chapter 2 of the book - &quot;Give the SOC the Authority to Do Its Job&quot;.<br/><br/>This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of the book with the book’s authors Kathryn Knerler, Ingrid Parker, and Carson Zimmerman.<br/><br/><br/>Visit <a href='https://www.mitre.org/news-insights/publication/11-strategies-world-class-cybersecurity-operations-center'>Mitre&apos;s page</a> for more information <br/>-----------<br/><br/>Sponsor&apos;s Note<br/><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/>Check out the details at sansurl.com/450 Hope to see you in class!<br/>Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube<br/>Follow John Hubbard: Twitter | LinkedIn</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/12851037-strategy-2-give-the-soc-the-authority-to-do-its-job.mp3" length="26595515" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/4vxiwsbtp7dvuz5w7mnslm2tl14y?.jpg" />
    <itunes:author>SANS Institute</itunes:author>
    <guid isPermaLink="false">Buzzsprout-12851037</guid>
    <pubDate>Mon, 15 May 2023 09:00:00 -0400</pubDate>
    <itunes:duration>2211</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>2</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Strategy 1: Know What You Are Protecting and Why</itunes:title>
    <title>Strategy 1: Know What You Are Protecting and Why</title>
    <itunes:summary><![CDATA[As the saying goes, "If you don't know where you're going, any road will take you there!" - an approach that is disastrous to a SOC. In order to succeed, the SOC must have a clear understanding of where they are going, how they're going to get there, and why. In this episode of our "11 Strategies" season we discuss chapter 1 of the book - "Know What You're Protecting and Why". Understanding your organization and the environment the SOC must perform in forms the foundation of all security team...]]></itunes:summary>
    <description><![CDATA[<p>As the saying goes, &quot;If you don&apos;t know where you&apos;re going, any road will take you there!&quot; - an approach that is disastrous to a SOC. In order to succeed, the SOC must have a clear understanding of where they are going, how they&apos;re going to get there, and why. In this episode of our &quot;11 Strategies&quot; season we discuss chapter 1 of the book - &quot;Know What You&apos;re Protecting and Why&quot;. Understanding your organization and the environment the SOC must perform in forms the foundation of all security team activity. In this episode the authors discuss the critical aspects of knowing what you&apos;re protecting. This includes consider your organization&apos;s mission, the legal, regulatory, and compliance environment, the technical capabilities you may or may not have, and the users that will inhabit the network and the actions they&apos;re going to be performing. Understanding these factors ensures your team starts off on the right path and keeps a common goal in view.<br/><br/>This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of the book with the book’s authors Kathryn Knerler, Ingrid Parker, and Carson Zimmerman.&quot;<br/><br/>Visit this <a href='https://www.mitre.org/news-insights/publication/11-strategies-world-class-cybersecurity-operations-center'>Mitre</a> page to find more information.<br/><br/>-----------<br/><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/><br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/><br/>Check out the details at <a href='http://sansurl.com/450'>sansurl.com/450</a> Hope to see you in class!<br/>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a><br/>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>As the saying goes, &quot;If you don&apos;t know where you&apos;re going, any road will take you there!&quot; - an approach that is disastrous to a SOC. In order to succeed, the SOC must have a clear understanding of where they are going, how they&apos;re going to get there, and why. In this episode of our &quot;11 Strategies&quot; season we discuss chapter 1 of the book - &quot;Know What You&apos;re Protecting and Why&quot;. Understanding your organization and the environment the SOC must perform in forms the foundation of all security team activity. In this episode the authors discuss the critical aspects of knowing what you&apos;re protecting. This includes consider your organization&apos;s mission, the legal, regulatory, and compliance environment, the technical capabilities you may or may not have, and the users that will inhabit the network and the actions they&apos;re going to be performing. Understanding these factors ensures your team starts off on the right path and keeps a common goal in view.<br/><br/>This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of the book with the book’s authors Kathryn Knerler, Ingrid Parker, and Carson Zimmerman.&quot;<br/><br/>Visit this <a href='https://www.mitre.org/news-insights/publication/11-strategies-world-class-cybersecurity-operations-center'>Mitre</a> page to find more information.<br/><br/>-----------<br/><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/><br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/><br/>Check out the details at <a href='http://sansurl.com/450'>sansurl.com/450</a> Hope to see you in class!<br/>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a><br/>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/12799587-strategy-1-know-what-you-are-protecting-and-why.mp3" length="44826277" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/9n5k6oh4ooqa7nue3bawjqe35zs7?.jpg" />
    <itunes:author>SANS Institute</itunes:author>
    <guid isPermaLink="false">Buzzsprout-12799587</guid>
    <pubDate>Mon, 08 May 2023 06:00:00 -0400</pubDate>
    <itunes:duration>3730</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>1</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>11 Strategies of a World-Class Security Operations Center: Fundamentals</itunes:title>
    <title>11 Strategies of a World-Class Security Operations Center: Fundamentals</title>
    <itunes:summary><![CDATA[Welcome to a brand new season of Blueprint! In this intro episode we discuss "Fundamentals" chapter of the "11 Strategies of a World Class Cybersecurity Operations Center" with the authors. We get into the motivation behind updating the book and why its lessons are more important than ever in 2023. This chapter includes discussion of the functions of a SOC, basics of workflow, CTI and contextual data sources, and why ops tempo and speed is a critical factor in SOC success.  This special seaso...]]></itunes:summary>
    <description><![CDATA[<p>Welcome to a brand new season of Blueprint! In this intro episode we discuss &quot;Fundamentals&quot; chapter of the &quot;11 Strategies of a World Class Cybersecurity Operations Center&quot; with the authors. We get into the motivation behind updating the book and why its lessons are more important than ever in 2023. This chapter includes discussion of the functions of a SOC, basics of workflow, CTI and contextual data sources, and why ops tempo and speed is a critical factor in SOC success.<br/><br/>This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of the book with the book’s authors Kathryn Knerler, Ingrid Parker, and Carson Zimmerman.<br/><br/>Visit this <a href='https://www.mitre.org/news-insights/publication/11-strategies-world-class-cybersecurity-operations-center'>Mitre</a> page to find more information.<br/><br/>-----------<br/><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/><br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/><br/>Check out the details at <a href='http://sansurl.com/450'>sansurl.com/450</a> Hope to see you in class!<br/>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a><br/>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>Welcome to a brand new season of Blueprint! In this intro episode we discuss &quot;Fundamentals&quot; chapter of the &quot;11 Strategies of a World Class Cybersecurity Operations Center&quot; with the authors. We get into the motivation behind updating the book and why its lessons are more important than ever in 2023. This chapter includes discussion of the functions of a SOC, basics of workflow, CTI and contextual data sources, and why ops tempo and speed is a critical factor in SOC success.<br/><br/>This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of the book with the book’s authors Kathryn Knerler, Ingrid Parker, and Carson Zimmerman.<br/><br/>Visit this <a href='https://www.mitre.org/news-insights/publication/11-strategies-world-class-cybersecurity-operations-center'>Mitre</a> page to find more information.<br/><br/>-----------<br/><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/><br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/><br/>Check out the details at <a href='http://sansurl.com/450'>sansurl.com/450</a> Hope to see you in class!<br/>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a><br/>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/12799519-11-strategies-of-a-world-class-security-operations-center-fundamentals.mp3" length="39852267" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/lug1di55tv2d6qehldlh74x2kjls?.jpg" />
    <itunes:author>SANS Institute</itunes:author>
    <guid isPermaLink="false">Buzzsprout-12799519</guid>
    <pubDate>Mon, 08 May 2023 05:00:00 -0400</pubDate>
    <podcast:soundbite startTime="498.5" duration="19.0" />
    <itunes:duration>3316</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episode>0</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Get Ready, A Very Special Season 4 Is On the Way!</itunes:title>
    <title>Get Ready, A Very Special Season 4 Is On the Way!</title>
    <itunes:summary><![CDATA[Hello Blueprint listeners! We’re excited to announce that the release of season 4 of Blueprint is just around the corner, and we’ve got something very special cooked up for you. We’ve teamed up with the authors of MITRE’s “11 Strategies of a World-Class Cybersecurity Operations Center” and over the next few months, we’ll be releasing episodes walking through each chapter with all 3 authors! We’ll be deep diving into what makes a SOC successful, get a first-hand account of why each strategy wa...]]></itunes:summary>
    <description><![CDATA[<p>Hello Blueprint listeners! We’re excited to announce that the release of season 4 of Blueprint is just around the corner, and we’ve got something very special cooked up for you. We’ve teamed up with the authors of MITRE’s “11 Strategies of a World-Class Cybersecurity Operations Center” and over the next few months, we’ll be releasing episodes walking through each chapter with all 3 authors! We’ll be deep diving into what makes a SOC successful, get a first-hand account of why each strategy was chosen, and practical advice on each how to implement each strategy along the way. Join Blueprint host John Hubbard with authors Kat Knerler, Ingrid Parker, and Carson Zimmerman for this exciting new season, coming to your podcast aggregator on May 8th!<br/><br/>You can find the video of each podcast at:<br/>https://www.youtube.com/@SANSCyberDefense <br/><br/>The first two episodes will be released on Monday, May 8. Following that there will be a new episode out every Monday. </p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>Hello Blueprint listeners! We’re excited to announce that the release of season 4 of Blueprint is just around the corner, and we’ve got something very special cooked up for you. We’ve teamed up with the authors of MITRE’s “11 Strategies of a World-Class Cybersecurity Operations Center” and over the next few months, we’ll be releasing episodes walking through each chapter with all 3 authors! We’ll be deep diving into what makes a SOC successful, get a first-hand account of why each strategy was chosen, and practical advice on each how to implement each strategy along the way. Join Blueprint host John Hubbard with authors Kat Knerler, Ingrid Parker, and Carson Zimmerman for this exciting new season, coming to your podcast aggregator on May 8th!<br/><br/>You can find the video of each podcast at:<br/>https://www.youtube.com/@SANSCyberDefense <br/><br/>The first two episodes will be released on Monday, May 8. Following that there will be a new episode out every Monday. </p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/12757015-get-ready-a-very-special-season-4-is-on-the-way.mp3" length="2033328" type="audio/mpeg" />
    <itunes:author>SANS Institute</itunes:author>
    <guid isPermaLink="false">Buzzsprout-12757015</guid>
    <pubDate>Mon, 01 May 2023 09:00:00 -0400</pubDate>
    <itunes:duration>162</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>4</itunes:season>
    <itunes:episodeType>trailer</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Brandon Evans: Cloud Security - Threats and Opportunities</itunes:title>
    <title>Brandon Evans: Cloud Security - Threats and Opportunities</title>
    <itunes:summary><![CDATA[Ever wonder how a cloud and application security expert views risks of cloud workloads? Well, wonder no more because on this episode we have Brandon Evans - SANS Certified Instructor and lead author of SEC510: Public Cloud Security. We cover the why and how of moving their applications to the cloud, the key considerations for a successful cloud security posture, and how building your infrastructure with a cloud-native mindset can and should lead to an improved security posture.   BONUS: ...]]></itunes:summary>
    <description><![CDATA[<p>Ever wonder how a cloud and application security expert views risks of cloud workloads? Well, wonder no more because on this episode we have Brandon Evans - SANS Certified Instructor and lead author of SEC510: Public Cloud Security. We cover the why and how of moving their applications to the cloud, the key considerations for a successful cloud security posture, and how building your infrastructure with a cloud-native mindset can and should lead to an improved security posture. <br/><br/>BONUS: Be sure to stay tuned to the end of the episode for a very special announcement from Brandon on the new SANS Cloud Ace podcast. Coming to all podcast directories on September 28. <br/><br/></p><p><b>Our Guest - Brandon Evans</b></p><p>Brandon works for Zoom Video Communications, in which he leads their internal Application Security training. As an application developer for most of his professional career, he moved into security full-time largely because of his many formal trainings through SANS. He’s a contributor to the OWASP Serverless Top 10 Project and a co-leader for the Nashville OWASP chapter. Brandon is lead author for <a href='https://www.sans.org/cyber-security-courses/public-cloud-security-aws-azure-gcp/'>SEC510: Public Cloud Security: AWS, Azure, and GCP</a> and a contributor and instructor for <a href='https://www.sans.org/cyber-security-courses/cloud-security-devsecops-automation/'>SEC540: Cloud Security and DevSecOps Automation</a>. <br/><br/>Resources:<br/>sans.org/cloud - SANS Cloud Resources<br/>https://brandone.github.io/pixel-puzzles/ - Brandon’s Pixel Puzzle game</p><p><b>Sponsor&apos;s Note:</b></p><p>Support for the Blueprint podcast comes from the SANS Institute.</p><p>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.</p><p>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.</p><p>Check out the details at <a href='https://sansurl.com/450'>sansurl.com/450</a>  Hope to see you in class!</p><p><br/></p><p>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a></p><p>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><br/><br/></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>Ever wonder how a cloud and application security expert views risks of cloud workloads? Well, wonder no more because on this episode we have Brandon Evans - SANS Certified Instructor and lead author of SEC510: Public Cloud Security. We cover the why and how of moving their applications to the cloud, the key considerations for a successful cloud security posture, and how building your infrastructure with a cloud-native mindset can and should lead to an improved security posture. <br/><br/>BONUS: Be sure to stay tuned to the end of the episode for a very special announcement from Brandon on the new SANS Cloud Ace podcast. Coming to all podcast directories on September 28. <br/><br/></p><p><b>Our Guest - Brandon Evans</b></p><p>Brandon works for Zoom Video Communications, in which he leads their internal Application Security training. As an application developer for most of his professional career, he moved into security full-time largely because of his many formal trainings through SANS. He’s a contributor to the OWASP Serverless Top 10 Project and a co-leader for the Nashville OWASP chapter. Brandon is lead author for <a href='https://www.sans.org/cyber-security-courses/public-cloud-security-aws-azure-gcp/'>SEC510: Public Cloud Security: AWS, Azure, and GCP</a> and a contributor and instructor for <a href='https://www.sans.org/cyber-security-courses/cloud-security-devsecops-automation/'>SEC540: Cloud Security and DevSecOps Automation</a>. <br/><br/>Resources:<br/>sans.org/cloud - SANS Cloud Resources<br/>https://brandone.github.io/pixel-puzzles/ - Brandon’s Pixel Puzzle game</p><p><b>Sponsor&apos;s Note:</b></p><p>Support for the Blueprint podcast comes from the SANS Institute.</p><p>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.</p><p>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.</p><p>Check out the details at <a href='https://sansurl.com/450'>sansurl.com/450</a>  Hope to see you in class!</p><p><br/></p><p>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a></p><p>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><br/><br/></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/11310505-brandon-evans-cloud-security-threats-and-opportunities.mp3" length="35752050" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/8j7v3d3dshcmtizp05v66pwopbn2?.jpg" />
    <itunes:author>SANS Institute</itunes:author>
    <guid isPermaLink="false">Buzzsprout-11310505</guid>
    <pubDate>Tue, 13 Sep 2022 09:00:00 -0400</pubDate>
    <itunes:duration>2975</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>37</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Joe Lykowski: Building a Transparent, Data-Driven SOC</itunes:title>
    <title>Joe Lykowski: Building a Transparent, Data-Driven SOC</title>
    <itunes:summary><![CDATA[In this episode we speak with Joe Lykowski - Cyber Defense Lead at a major manufacturing company on what it takes to build a mature, transparent, and effective SOC. Joe brings years of experience to the table in running a large organization’s security team and in this interview he draws out some of his favorite tips, strategies and more on metrics, building the right team, and what to prioritize as you build up a SOC for an org of any size.    Our Guest - Joe Lykowski  A graduate of West...]]></itunes:summary>
    <description><![CDATA[<p>In this episode we speak with Joe Lykowski - Cyber Defense Lead at a major manufacturing company on what it takes to build a mature, transparent, and effective SOC. Joe brings years of experience to the table in running a large organization’s security team and in this interview he draws out some of his favorite tips, strategies and more on metrics, building the right team, and what to prioritize as you build up a SOC for an org of any size.  <br/><br/><b>Our Guest - Joe Lykowski<br/><br/></b>A graduate of Western Michigan University, Joe has 19 years of professional IT experience ranging from academia, industrial control systems and manufacturing IT, mobile device service management, telepresence services, endpoint protection, and cyber security operations. His current role focused on leading a global team of cyber defenders with the core goal of protecting Dow from the growing cybersecurity threats.</p><p>Follow Joe on Twitter: @JosephLykowski</p><p><br/><b>Sponsor&apos;s Note:</b></p><p>Support for the Blueprint podcast comes from the SANS Institute.</p><p>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.</p><p>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.</p><p>Check out the details at <a href='https://sansurl.com/450'>sansurl.com/450</a>  Hope to see you in class!</p><p><br/></p><p>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a></p><p>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><br/></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>In this episode we speak with Joe Lykowski - Cyber Defense Lead at a major manufacturing company on what it takes to build a mature, transparent, and effective SOC. Joe brings years of experience to the table in running a large organization’s security team and in this interview he draws out some of his favorite tips, strategies and more on metrics, building the right team, and what to prioritize as you build up a SOC for an org of any size.  <br/><br/><b>Our Guest - Joe Lykowski<br/><br/></b>A graduate of Western Michigan University, Joe has 19 years of professional IT experience ranging from academia, industrial control systems and manufacturing IT, mobile device service management, telepresence services, endpoint protection, and cyber security operations. His current role focused on leading a global team of cyber defenders with the core goal of protecting Dow from the growing cybersecurity threats.</p><p>Follow Joe on Twitter: @JosephLykowski</p><p><br/><b>Sponsor&apos;s Note:</b></p><p>Support for the Blueprint podcast comes from the SANS Institute.</p><p>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.</p><p>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.</p><p>Check out the details at <a href='https://sansurl.com/450'>sansurl.com/450</a>  Hope to see you in class!</p><p><br/></p><p>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a></p><p>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><br/></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/11269290-joe-lykowski-building-a-transparent-data-driven-soc.mp3" length="39723180" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/watjvgh3dnfl44wythgy2einj1dc?.jpg" />
    <itunes:author>SANS Institute</itunes:author>
    <guid isPermaLink="false">Buzzsprout-11269290</guid>
    <pubDate>Tue, 06 Sep 2022 10:00:00 -0400</pubDate>
    <itunes:duration>3306</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>36</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Rob Lee: Training and Reskilling in Cyber Security</itunes:title>
    <title>Rob Lee: Training and Reskilling in Cyber Security</title>
    <itunes:summary><![CDATA[Many of us are either looking to start a cyber security career, improve our knowledge and skills to further our career, or hire a team that has the most skilled and promising candidates. In this special episode with Rob Lee, Chief Curriculum Director of the SANS Institute, we discuss strategies for building, improving, and testing your cyber security group’s skill levels, and working to keep our knowledge as current as possible - a critical skill for anyone in the fast moving world of cyber s...]]></itunes:summary>
    <description><![CDATA[<p>Many of us are either looking to start a cyber security career, improve our knowledge and skills to further our career, or hire a team that has the most skilled and promising candidates. In this special episode with Rob Lee, Chief Curriculum Director of the SANS Institute, we discuss strategies for building, improving, and testing your cyber security group’s skill levels, and working to keep our knowledge as current as possible - a critical skill for anyone in the fast moving world of cyber security.<br/><br/><b>Rob Lee</b></p><p>Rob Lee is the Chief Curriculum Director and Faculty Lead at SANS Institute and runs his own consulting business specializing in information security, incident response, threat hunting, and digital forensics. With more than 20 years of experience in digital forensics, vulnerability and exploit discovery, intrusion detection/prevention, and incident response, he is known as “The Godfather of DFIR”. Rob co-authored the book <em>Know Your Enemy, 2nd Edition</em>, and is course co-author of <a href='https://www.sans.org/cyber-security-courses/windows-forensic-analysis/?msc=instructor-rob-lee'>FOR500: Windows Forensic Analysis</a> and <a href='https://www.sans.org/cyber-security-courses/advanced-incident-response-threat-hunting-training?msc=instructor-rob-lee'>FOR508: Advanced Incident Response, Threat Hunting, and Digital Forensics</a>.<br/><br/></p><p><b>Sponsor&apos;s Note:</b></p><p>Support for the Blueprint podcast comes from the SANS Institute.</p><p>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.</p><p>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.</p><p>Check out the details at <a href='https://sansurl.com/450'>sansurl.com/450</a>  Hope to see you in class!</p><p><br/></p><p>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a></p><p>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><br/></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>Many of us are either looking to start a cyber security career, improve our knowledge and skills to further our career, or hire a team that has the most skilled and promising candidates. In this special episode with Rob Lee, Chief Curriculum Director of the SANS Institute, we discuss strategies for building, improving, and testing your cyber security group’s skill levels, and working to keep our knowledge as current as possible - a critical skill for anyone in the fast moving world of cyber security.<br/><br/><b>Rob Lee</b></p><p>Rob Lee is the Chief Curriculum Director and Faculty Lead at SANS Institute and runs his own consulting business specializing in information security, incident response, threat hunting, and digital forensics. With more than 20 years of experience in digital forensics, vulnerability and exploit discovery, intrusion detection/prevention, and incident response, he is known as “The Godfather of DFIR”. Rob co-authored the book <em>Know Your Enemy, 2nd Edition</em>, and is course co-author of <a href='https://www.sans.org/cyber-security-courses/windows-forensic-analysis/?msc=instructor-rob-lee'>FOR500: Windows Forensic Analysis</a> and <a href='https://www.sans.org/cyber-security-courses/advanced-incident-response-threat-hunting-training?msc=instructor-rob-lee'>FOR508: Advanced Incident Response, Threat Hunting, and Digital Forensics</a>.<br/><br/></p><p><b>Sponsor&apos;s Note:</b></p><p>Support for the Blueprint podcast comes from the SANS Institute.</p><p>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.</p><p>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.</p><p>Check out the details at <a href='https://sansurl.com/450'>sansurl.com/450</a>  Hope to see you in class!</p><p><br/></p><p>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a></p><p>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><br/></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/11228902-rob-lee-training-and-reskilling-in-cyber-security.mp3" length="36558034" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/qppik8zx9wi6i7qofrbub215chgs?.jpg" />
    <itunes:author>SANS Institute</itunes:author>
    <guid isPermaLink="false">Buzzsprout-11228902</guid>
    <pubDate>Tue, 30 Aug 2022 09:00:00 -0400</pubDate>
    <itunes:duration>3043</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>35</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Jaron Bradley: Securing Enterprise macOS</itunes:title>
    <title>Jaron Bradley: Securing Enterprise macOS</title>
    <itunes:summary><![CDATA[In this episode of the Blueprint Podcast, we cover monitoring and securing macOS in an enterprise environment at scale with Jaron Bradley, Threat Detection lead at Jamf. We discuss the ups and downs of Apple's approach to macOS data collection over the years, the data sources and types that are accessible to defenders, what 3rd party agents bring to the table for security monitoring, and much more. Plus, Jaron gives us some great bonus tips for finding persistence mechanisms and malicious pro...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of the Blueprint Podcast, we cover monitoring and securing macOS in an enterprise environment at scale with Jaron Bradley, Threat Detection lead at Jamf. We discuss the ups and downs of Apple&apos;s approach to macOS data collection over the years, the data sources and types that are accessible to defenders, what 3rd party agents bring to the table for security monitoring, and much more. Plus, Jaron gives us some great bonus tips for finding persistence mechanisms and malicious processes in enterprise macOS devices.<br/><br/><b>Our Guest - Jaron Bradley</b></p><p>Jaron has a background in Incident Response, threat hunting, and detections development. After focusing on large scale APT attacks he developed an interest in the more niche spaces of lesser explored operating systems. He has experience as both a SOC analyst as well as detections engineering at the endpoint level.Jaron currently works as the macOS Detections Lead at Jamf Threat Labs and manages his own security tools and content for security researchers atthemittenmac.com. He is also the author of OS X Incident Response Scripting and Analysis. A book he claims is slightly outdated but still relevant to a lot of macOS analysis today.</p><p>Resources mentioned in this episode<br/><br/>Websites</p><ul><li><a href='https://urldefense.com/v3/__https://www.themittenmac.com__;!!MlQdS1fu!XpJbP2685_SRbupIogpsl3hZzoSiLRlT-Gvcy63ymq2EfcjOeCtO_xvBa8LQSFet5k97xdXu64vSkHMVxmeF$'>https://www.themittenmac.com</a> (my website)</li><li><a href='https://urldefense.com/v3/__http://objective-see.com__;!!MlQdS1fu!XpJbP2685_SRbupIogpsl3hZzoSiLRlT-Gvcy63ymq2EfcjOeCtO_xvBa8LQSFet5k97xdXu64vSkPanaPMC$'>objective-see.com</a> (great mac security website)</li><li>Major Blogs Referenced by Jamf Threat Labs<ul><li><a href='https://urldefense.com/v3/__https://www.jamf.com/blog/shlayer-malware-abusing-gatekeeper-bypass-on-macos/__;!!MlQdS1fu!XpJbP2685_SRbupIogpsl3hZzoSiLRlT-Gvcy63ymq2EfcjOeCtO_xvBa8LQSFet5k97xdXu64vSkDkrmYQB$'>https://www.jamf.com/blog/shlayer-malware-abusing-gatekeeper-bypass-on-macos/</a></li><li><a href='https://urldefense.com/v3/__https://www.jamf.com/blog/zero-day-tcc-bypass-discovered-in-xcsset-malware/__;!!MlQdS1fu!XpJbP2685_SRbupIogpsl3hZzoSiLRlT-Gvcy63ymq2EfcjOeCtO_xvBa8LQSFet5k97xdXu64vSkNU4bYm7$'>https://www.jamf.com/blog/zero-day-tcc-bypass-discovered-in-xcsset-malware/</a></li><li><a href='https://urldefense.com/v3/__https://www.jamf.com/blog/jamf-threat-labs-safari-vuln-gatekeeper-bypass/__;!!MlQdS1fu!XpJbP2685_SRbupIogpsl3hZzoSiLRlT-Gvcy63ymq2EfcjOeCtO_xvBa8LQSFet5k97xdXu64vSkKpBIgxV$'>https://www.jamf.com/blog/jamf-threat-labs-safari-vuln-gatekeeper-bypass/</a></li><li><a href='https://urldefense.com/v3/__https://www.jamf.com/threat-labs/__;!!MlQdS1fu!XpJbP2685_SRbupIogpsl3hZzoSiLRlT-Gvcy63ymq2EfcjOeCtO_xvBa8LQSFet5k97xdXu64vSkFWmjFjp$'>https://www.jamf.com/threat-labs/</a> (threat labs home)</li></ul></li></ul><p>Conferences</p><ul><li>Jamf Nation User Conference -&gt; <a href='https://urldefense.com/v3/__https://www.jamf.com/events/jamf-nation-user-conference/2022/__;!!MlQdS1fu!XpJbP2685_SRbupIogpsl3hZzoSiLRlT-Gvcy63ymq2EfcjOeCtO_xvBa8LQSFet5k97xdXu64vSkOlgakcv$'>https://www.jamf.com/events/jamf-nation-user-conference/2022/</a></li><li>Objective by the sea 5.0 -&gt; <a href='https://urldefense.com/v3/__https://objectivebythesea.org/v5/index.html__;!!MlQdS1fu!XpJbP2685_SRbupIogpsl3hZzoSiLRlT-Gvcy63ymq2EfcjOeCtO_xvBa8LQSFet5k97xdXu64vSkCFCo0sw$'>https://objectivebythesea.org/v5/index.html</a></li></ul><p>Support for the Blueprint podcast comes from the SANS Institute.</p><p>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a></p><p>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><br/></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of the Blueprint Podcast, we cover monitoring and securing macOS in an enterprise environment at scale with Jaron Bradley, Threat Detection lead at Jamf. We discuss the ups and downs of Apple&apos;s approach to macOS data collection over the years, the data sources and types that are accessible to defenders, what 3rd party agents bring to the table for security monitoring, and much more. Plus, Jaron gives us some great bonus tips for finding persistence mechanisms and malicious processes in enterprise macOS devices.<br/><br/><b>Our Guest - Jaron Bradley</b></p><p>Jaron has a background in Incident Response, threat hunting, and detections development. After focusing on large scale APT attacks he developed an interest in the more niche spaces of lesser explored operating systems. He has experience as both a SOC analyst as well as detections engineering at the endpoint level.Jaron currently works as the macOS Detections Lead at Jamf Threat Labs and manages his own security tools and content for security researchers atthemittenmac.com. He is also the author of OS X Incident Response Scripting and Analysis. A book he claims is slightly outdated but still relevant to a lot of macOS analysis today.</p><p>Resources mentioned in this episode<br/><br/>Websites</p><ul><li><a href='https://urldefense.com/v3/__https://www.themittenmac.com__;!!MlQdS1fu!XpJbP2685_SRbupIogpsl3hZzoSiLRlT-Gvcy63ymq2EfcjOeCtO_xvBa8LQSFet5k97xdXu64vSkHMVxmeF$'>https://www.themittenmac.com</a> (my website)</li><li><a href='https://urldefense.com/v3/__http://objective-see.com__;!!MlQdS1fu!XpJbP2685_SRbupIogpsl3hZzoSiLRlT-Gvcy63ymq2EfcjOeCtO_xvBa8LQSFet5k97xdXu64vSkPanaPMC$'>objective-see.com</a> (great mac security website)</li><li>Major Blogs Referenced by Jamf Threat Labs<ul><li><a href='https://urldefense.com/v3/__https://www.jamf.com/blog/shlayer-malware-abusing-gatekeeper-bypass-on-macos/__;!!MlQdS1fu!XpJbP2685_SRbupIogpsl3hZzoSiLRlT-Gvcy63ymq2EfcjOeCtO_xvBa8LQSFet5k97xdXu64vSkDkrmYQB$'>https://www.jamf.com/blog/shlayer-malware-abusing-gatekeeper-bypass-on-macos/</a></li><li><a href='https://urldefense.com/v3/__https://www.jamf.com/blog/zero-day-tcc-bypass-discovered-in-xcsset-malware/__;!!MlQdS1fu!XpJbP2685_SRbupIogpsl3hZzoSiLRlT-Gvcy63ymq2EfcjOeCtO_xvBa8LQSFet5k97xdXu64vSkNU4bYm7$'>https://www.jamf.com/blog/zero-day-tcc-bypass-discovered-in-xcsset-malware/</a></li><li><a href='https://urldefense.com/v3/__https://www.jamf.com/blog/jamf-threat-labs-safari-vuln-gatekeeper-bypass/__;!!MlQdS1fu!XpJbP2685_SRbupIogpsl3hZzoSiLRlT-Gvcy63ymq2EfcjOeCtO_xvBa8LQSFet5k97xdXu64vSkKpBIgxV$'>https://www.jamf.com/blog/jamf-threat-labs-safari-vuln-gatekeeper-bypass/</a></li><li><a href='https://urldefense.com/v3/__https://www.jamf.com/threat-labs/__;!!MlQdS1fu!XpJbP2685_SRbupIogpsl3hZzoSiLRlT-Gvcy63ymq2EfcjOeCtO_xvBa8LQSFet5k97xdXu64vSkFWmjFjp$'>https://www.jamf.com/threat-labs/</a> (threat labs home)</li></ul></li></ul><p>Conferences</p><ul><li>Jamf Nation User Conference -&gt; <a href='https://urldefense.com/v3/__https://www.jamf.com/events/jamf-nation-user-conference/2022/__;!!MlQdS1fu!XpJbP2685_SRbupIogpsl3hZzoSiLRlT-Gvcy63ymq2EfcjOeCtO_xvBa8LQSFet5k97xdXu64vSkOlgakcv$'>https://www.jamf.com/events/jamf-nation-user-conference/2022/</a></li><li>Objective by the sea 5.0 -&gt; <a href='https://urldefense.com/v3/__https://objectivebythesea.org/v5/index.html__;!!MlQdS1fu!XpJbP2685_SRbupIogpsl3hZzoSiLRlT-Gvcy63ymq2EfcjOeCtO_xvBa8LQSFet5k97xdXu64vSkCFCo0sw$'>https://objectivebythesea.org/v5/index.html</a></li></ul><p>Support for the Blueprint podcast comes from the SANS Institute.</p><p>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a></p><p>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><br/></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/11188338-jaron-bradley-securing-enterprise-macos.mp3" length="42244588" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/enhkmj25kthi2y3wlpfcl7ir3n6b?.jpg" />
    <itunes:author>SANS Institute</itunes:author>
    <guid isPermaLink="false">Buzzsprout-11188338</guid>
    <pubDate>Tue, 23 Aug 2022 09:00:00 -0400</pubDate>
    <itunes:duration>3516</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>34</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Alexia Crumpton: MITRE ATT&amp;CK for Defenders</itunes:title>
    <title>Alexia Crumpton: MITRE ATT&amp;CK for Defenders</title>
    <itunes:summary><![CDATA[One of the best frameworks that showed up within the last 5 or so years is undoubtedly the MITRE ATT&amp;CK® framework. Many of us may know about it in passing and even reference from time to time, but very few people seem to know the true depth of knowledge contained - everything from analytics to threat groups, specific mitigation and detection opportunities, and with the newest versions, even specific data sources. In this episode we talk to the Defensive Lead of ATT&amp;CK from MITRE, Lex...]]></itunes:summary>
    <description><![CDATA[<p>One of the best frameworks that showed up within the last 5 or so years is undoubtedly the MITRE ATT&amp;CK® framework. Many of us may know about it in passing and even reference from time to time, but very few people seem to know the true depth of knowledge contained - everything from analytics to threat groups, specific mitigation and detection opportunities, and with the newest versions, even specific data sources. In this episode we talk to the Defensive Lead of ATT&amp;CK from MITRE, Lex Crumpton, about what every blue team member needs to know about this framework, and more!<br/><br/><b>Alexia Crumpton</b></p><p>Alexia Crumpton is a Defensive Cyber Operations Researcher with over seven years of experience in software development, SOCs, and Malware Reverse Engineering. Her passion lies in heuristic behavior analysis in regards to adversary TTPs and countermeasures used to defend against them. <br/><br/></p><p><b>Follow Alexia</b></p><p>LinkedIn: https://www.linkedin.com/in/alexia-crumpton-99930659/</p><p><br/></p><p>Resources mentioned in this episode:<br/><br/><a href='https://urldefense.com/v3/__https:/car.mitre.org/__;!!MlQdS1fu!SZR1w_n8P12w0HhgY_nxBU7QJc4YCScFcZKLbG9SQcsOIl9KB6I14IYIAlL-AA9VovLjYubUL_IKNw$'>CAR</a> - The MITRE Cyber Analytics Repository (CAR) is a knowledge base of analytics developed by <a href='https://urldefense.com/v3/__https:/www.mitre.org__;!!MlQdS1fu!SZR1w_n8P12w0HhgY_nxBU7QJc4YCScFcZKLbG9SQcsOIl9KB6I14IYIAlL-AA9VovLjYubDRSrjdQ$'>MITRE</a> based on the <a href='https://urldefense.com/v3/__https:/attack.mitre.org/__;!!MlQdS1fu!SZR1w_n8P12w0HhgY_nxBU7QJc4YCScFcZKLbG9SQcsOIl9KB6I14IYIAlL-AA9VovLjYuYiZHLdNw$'>MITRE ATT&amp;CK</a> adversary model.</p><p><br/>Top ATT&amp;CK Techniques – <a href='https://urldefense.com/v3/__https:/medium.com/mitre-engenuity/where-to-begin-prioritizing-att-ck-techniques-c535b50983f4__;!!MlQdS1fu!SZR1w_n8P12w0HhgY_nxBU7QJc4YCScFcZKLbG9SQcsOIl9KB6I14IYIAlL-AA9VovLjYuaixqD3zA$'>Medium Blog</a>, <a href='https://urldefense.com/v3/__https:/github.com/center-for-threat-informed-defense/top-attack-techniques__;!!MlQdS1fu!SZR1w_n8P12w0HhgY_nxBU7QJc4YCScFcZKLbG9SQcsOIl9KB6I14IYIAlL-AA9VovLjYuZ3VxRM7w$'>Github</a>, <a href='https://urldefense.com/v3/__https:/medium.com/mitre-engenuity/where-to-begin-prioritizing-att-ck-techniques-c535b50983f4__;!!MlQdS1fu!SZR1w_n8P12w0HhgY_nxBU7QJc4YCScFcZKLbG9SQcsOIl9KB6I14IYIAlL-AA9VovLjYuaixqD3zA$'>Calculator</a> <br/><br/><b>Sponsor&apos;s Note:</b></p><p>Support for the Blueprint podcast comes from the SANS Institute.</p><p>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.</p><p>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need t</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>One of the best frameworks that showed up within the last 5 or so years is undoubtedly the MITRE ATT&amp;CK® framework. Many of us may know about it in passing and even reference from time to time, but very few people seem to know the true depth of knowledge contained - everything from analytics to threat groups, specific mitigation and detection opportunities, and with the newest versions, even specific data sources. In this episode we talk to the Defensive Lead of ATT&amp;CK from MITRE, Lex Crumpton, about what every blue team member needs to know about this framework, and more!<br/><br/><b>Alexia Crumpton</b></p><p>Alexia Crumpton is a Defensive Cyber Operations Researcher with over seven years of experience in software development, SOCs, and Malware Reverse Engineering. Her passion lies in heuristic behavior analysis in regards to adversary TTPs and countermeasures used to defend against them. <br/><br/></p><p><b>Follow Alexia</b></p><p>LinkedIn: https://www.linkedin.com/in/alexia-crumpton-99930659/</p><p><br/></p><p>Resources mentioned in this episode:<br/><br/><a href='https://urldefense.com/v3/__https:/car.mitre.org/__;!!MlQdS1fu!SZR1w_n8P12w0HhgY_nxBU7QJc4YCScFcZKLbG9SQcsOIl9KB6I14IYIAlL-AA9VovLjYubUL_IKNw$'>CAR</a> - The MITRE Cyber Analytics Repository (CAR) is a knowledge base of analytics developed by <a href='https://urldefense.com/v3/__https:/www.mitre.org__;!!MlQdS1fu!SZR1w_n8P12w0HhgY_nxBU7QJc4YCScFcZKLbG9SQcsOIl9KB6I14IYIAlL-AA9VovLjYubDRSrjdQ$'>MITRE</a> based on the <a href='https://urldefense.com/v3/__https:/attack.mitre.org/__;!!MlQdS1fu!SZR1w_n8P12w0HhgY_nxBU7QJc4YCScFcZKLbG9SQcsOIl9KB6I14IYIAlL-AA9VovLjYuYiZHLdNw$'>MITRE ATT&amp;CK</a> adversary model.</p><p><br/>Top ATT&amp;CK Techniques – <a href='https://urldefense.com/v3/__https:/medium.com/mitre-engenuity/where-to-begin-prioritizing-att-ck-techniques-c535b50983f4__;!!MlQdS1fu!SZR1w_n8P12w0HhgY_nxBU7QJc4YCScFcZKLbG9SQcsOIl9KB6I14IYIAlL-AA9VovLjYuaixqD3zA$'>Medium Blog</a>, <a href='https://urldefense.com/v3/__https:/github.com/center-for-threat-informed-defense/top-attack-techniques__;!!MlQdS1fu!SZR1w_n8P12w0HhgY_nxBU7QJc4YCScFcZKLbG9SQcsOIl9KB6I14IYIAlL-AA9VovLjYuZ3VxRM7w$'>Github</a>, <a href='https://urldefense.com/v3/__https:/medium.com/mitre-engenuity/where-to-begin-prioritizing-att-ck-techniques-c535b50983f4__;!!MlQdS1fu!SZR1w_n8P12w0HhgY_nxBU7QJc4YCScFcZKLbG9SQcsOIl9KB6I14IYIAlL-AA9VovLjYuaixqD3zA$'>Calculator</a> <br/><br/><b>Sponsor&apos;s Note:</b></p><p>Support for the Blueprint podcast comes from the SANS Institute.</p><p>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.</p><p>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need t</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/11147493-alexia-crumpton-mitre-att-ck-for-defenders.mp3" length="30604267" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/u23nt2pkblv9qwkr970i78epeddy?.jpg" />
    <itunes:author>John Hubbard</itunes:author>
    <guid isPermaLink="false">Buzzsprout-11147493</guid>
    <pubDate>Tue, 16 Aug 2022 09:00:00 -0400</pubDate>
    <itunes:duration>2546</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>33</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Cat Self: macOS and Linux Security</itunes:title>
    <title>Cat Self: macOS and Linux Security</title>
    <itunes:summary><![CDATA[Ever wonder why there’s so little information regarding macOS and Linux-oriented attacks? In this episode, we get the answer from  the multi-talented Cat Self - an Adversary Emulation Engineer at MITRE, Cyber Threat Intelligence Team Leader on ATT&amp;CK Evaluations and macOS/ Lead on MITRE ATT&amp;CK Enterprise. We discuss defense tools,  attacker TTPs, and what to consider when approaching defense for a macOS and Linux environment, and what trends we can expect in the future for t...]]></itunes:summary>
    <description><![CDATA[<p>Ever wonder why there’s so little information regarding macOS and Linux-oriented attacks? In this episode, we get the answer from  the multi-talented Cat Self - an Adversary Emulation Engineer at MITRE, Cyber Threat Intelligence Team Leader on ATT&amp;CK Evaluations and macOS/ Lead on MITRE ATT&amp;CK Enterprise. We discuss defense tools,  attacker TTPs, and what to consider when approaching defense for a macOS and Linux environment, and what trends we can expect in the future for these operating systems. Check out the resources below for links mentioned during this enlightening conversation!<br/><br/>Our Guest: <b>Cat Self</b></p><p>Cat Self is the CTI Lead for MITRE ATT&amp;CK® Evaluations, macOS/Linux Lead for ATT&amp;CK® and serves as a leader of people at MITRE. Cat started her cyber security career at Target and has worked as a developer, internal red team operator, and Threat Hunter. Cat is a former military intelligence veteran and pays it forward through mentorship, technical macOS hunting workshops, and public speaking. Outside of work, she is often planning an epic adventure or climbing mountains in foreign lands. </p><p><br/></p><p><b>Follow Cat on Social Media</b></p><p>Twitter: <a href='https://twitter.com/coolestcatiknow?lang=en'>@coolestcatiknow</a></p><p>LinkedIn: <a href='https://www.linkedin.com/in/coolestcatiknow/'>Cat Self</a></p><p><br/></p><p>Resources mentioned in this episode:<br/><br/>A highlight of new security changes in macOS Ventura:</p><p><a href='https://www.sentinelone.com/blog/apples-macos-ventura-7-new-security-changes-to-be-aware-of/'>https://www.sentinelone.com/blog/apples-macos-ventura-7-new-security-changes-to-be-aware-of/</a></p><p> </p><p>For securing <b>a</b> macOS device, I highly recommend installing Patrick Wardle’s endpoint tools. <a href='https://objective-see.org/tools.html'>https://objective-see.org/tools.html</a> My favorites are BlockBlock, KnockKnock, Lulu, &amp; Netiquette. </p><p> </p><p><b>Cat&apos;s “GoTo” blogs</b></p><p>Patrick Wardle <a href='https://www.objective-see.com/'>Objective-See</a></p><p>Jaron Bradley<a href='https://themittenmac.com/blog/'> The Mitten Mac</a></p><p>Howard Oakley <a href='https://eclecticlight.co/category/macs/'>The Eclectic Light Company</a></p><p>Cody Thomas <a href='https://medium.com/@its_a_feature_'>Medium</a></p><p>Sarah Edwards <a href='https://www.mac4n6.com/'>mac4n6</a></p><p>Leo Pitt <a href='https://medium.com/@D00MFist'>Medium</a></p><p>Christopher Ross <a href='https://medium.com/@xorrior'>Medium</a></p><p>Csaba Fitzl <a href='https://theevilbit.github.io/beyond/'>THEEVILBIT Blog</a></p><p> </p><p><b>Open Source Projects</b></p><p>Playbooks with Datasets to practice <a href='https://github.com/OTRF/ThreatHunter-Playbook'>OTRF</a></p><p>Code snippets aligned to MITRE ATT&amp;CK <a href='https://github.com/redcanaryco/atomic-red-team'>Atomic Red Team</a></p><p>Jupyter notebook environment setup by <a href='https://medium.com/codex/how-to-setup-jupyter-notebook-on-mac-b0c2e3c66e60'>Anna Pastushko</a></p><p>Virtual environment setup <a href='https://holdmybeersecurity.com/2021/01/27/ir-tales-the-quest-for-the-holy-siem-elastic-stack-sysmon-osquery/'>Hold My Beer</a></p><p><br/></p><p><b>Sponsor&apos;s Note:</b></p><p>Support for the Blueprint podcast comes from the SANS Institute.</p><p>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.</p><p>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands </p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>Ever wonder why there’s so little information regarding macOS and Linux-oriented attacks? In this episode, we get the answer from  the multi-talented Cat Self - an Adversary Emulation Engineer at MITRE, Cyber Threat Intelligence Team Leader on ATT&amp;CK Evaluations and macOS/ Lead on MITRE ATT&amp;CK Enterprise. We discuss defense tools,  attacker TTPs, and what to consider when approaching defense for a macOS and Linux environment, and what trends we can expect in the future for these operating systems. Check out the resources below for links mentioned during this enlightening conversation!<br/><br/>Our Guest: <b>Cat Self</b></p><p>Cat Self is the CTI Lead for MITRE ATT&amp;CK® Evaluations, macOS/Linux Lead for ATT&amp;CK® and serves as a leader of people at MITRE. Cat started her cyber security career at Target and has worked as a developer, internal red team operator, and Threat Hunter. Cat is a former military intelligence veteran and pays it forward through mentorship, technical macOS hunting workshops, and public speaking. Outside of work, she is often planning an epic adventure or climbing mountains in foreign lands. </p><p><br/></p><p><b>Follow Cat on Social Media</b></p><p>Twitter: <a href='https://twitter.com/coolestcatiknow?lang=en'>@coolestcatiknow</a></p><p>LinkedIn: <a href='https://www.linkedin.com/in/coolestcatiknow/'>Cat Self</a></p><p><br/></p><p>Resources mentioned in this episode:<br/><br/>A highlight of new security changes in macOS Ventura:</p><p><a href='https://www.sentinelone.com/blog/apples-macos-ventura-7-new-security-changes-to-be-aware-of/'>https://www.sentinelone.com/blog/apples-macos-ventura-7-new-security-changes-to-be-aware-of/</a></p><p> </p><p>For securing <b>a</b> macOS device, I highly recommend installing Patrick Wardle’s endpoint tools. <a href='https://objective-see.org/tools.html'>https://objective-see.org/tools.html</a> My favorites are BlockBlock, KnockKnock, Lulu, &amp; Netiquette. </p><p> </p><p><b>Cat&apos;s “GoTo” blogs</b></p><p>Patrick Wardle <a href='https://www.objective-see.com/'>Objective-See</a></p><p>Jaron Bradley<a href='https://themittenmac.com/blog/'> The Mitten Mac</a></p><p>Howard Oakley <a href='https://eclecticlight.co/category/macs/'>The Eclectic Light Company</a></p><p>Cody Thomas <a href='https://medium.com/@its_a_feature_'>Medium</a></p><p>Sarah Edwards <a href='https://www.mac4n6.com/'>mac4n6</a></p><p>Leo Pitt <a href='https://medium.com/@D00MFist'>Medium</a></p><p>Christopher Ross <a href='https://medium.com/@xorrior'>Medium</a></p><p>Csaba Fitzl <a href='https://theevilbit.github.io/beyond/'>THEEVILBIT Blog</a></p><p> </p><p><b>Open Source Projects</b></p><p>Playbooks with Datasets to practice <a href='https://github.com/OTRF/ThreatHunter-Playbook'>OTRF</a></p><p>Code snippets aligned to MITRE ATT&amp;CK <a href='https://github.com/redcanaryco/atomic-red-team'>Atomic Red Team</a></p><p>Jupyter notebook environment setup by <a href='https://medium.com/codex/how-to-setup-jupyter-notebook-on-mac-b0c2e3c66e60'>Anna Pastushko</a></p><p>Virtual environment setup <a href='https://holdmybeersecurity.com/2021/01/27/ir-tales-the-quest-for-the-holy-siem-elastic-stack-sysmon-osquery/'>Hold My Beer</a></p><p><br/></p><p><b>Sponsor&apos;s Note:</b></p><p>Support for the Blueprint podcast comes from the SANS Institute.</p><p>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.</p><p>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands </p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/11106734-cat-self-macos-and-linux-security.mp3" length="40749898" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/jsw9kexuvi3qj3kul4yq8svfgray?.jpg" />
    <itunes:author>John Hubbard</itunes:author>
    <guid isPermaLink="false">Buzzsprout-11106734</guid>
    <pubDate>Tue, 09 Aug 2022 07:00:00 -0400</pubDate>
    <itunes:duration>3391</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>32</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Corissa Koopmans and Mark Morowczynski: Azure AD Threat Detection and Logging</itunes:title>
    <title>Corissa Koopmans and Mark Morowczynski: Azure AD Threat Detection and Logging</title>
    <itunes:summary><![CDATA[Nearly every organization is using Microsoft Azure AD services in some respect, but monitoring Azure AD for threats is a significantly different skill that traditional Windows logging. In this episode we have 2 experts from Microsoft, Corissa Koopmans, and 3rd time returning guest Mark Morowczynski, to tell us about the important work that’s been done to help organizations understand their data and detect Azure AD attacks. We cover log sources, the new Microsoft security operations guide, sta...]]></itunes:summary>
    <description><![CDATA[<p>Nearly every organization is using Microsoft Azure AD services in some respect, but monitoring Azure AD for threats is a significantly different skill that traditional Windows logging. In this episode we have 2 experts from Microsoft, Corissa Koopmans, and 3rd time returning guest Mark Morowczynski, to tell us about the important work that’s been done to help organizations understand their data and detect Azure AD attacks. We cover log sources, the new Microsoft security operations guide, standardized dashboards and visualizations you can leverage to jump right in with best practice, and much more. You don’t want to miss this one!<br/><br/><b>Corissa Koopmans and Mark Morowczynski</b></p><p>Corissa Koopmans (@Corissalea) is part of the &quot;Get to Production&quot; team in the Microsoft Identity and Network Access Division, focusing on incorporating customer feedback to improve our products. She is very active in driving community contribution to AzureMonitor Log Analytics and increasing awareness of the power of log data by presenting at industry events including BSides, The Experts Conference (TEC), SPARK, &amp; Microsoft MVP Summits.<br/><br/>Mark Morowczynski (@markmorow) is a Principal Program Manager on the customer success team in the Microsoft Identity division. He spends most of his time working with customers on their deployments of Azure Active Directory. Previously he was Premier Field Engineer supporting Active Directory, Active Directory Federation Services and Windows Client performance. He&apos;s spoken at various industry events such as Black Hat, Defcon Blue TeamVillage, Blue Team Con, GrayHat, several BSides, and more. He can be frequently found on Twitter as @markmorow arguing about baseball and making sometimes funny gifs.</p><p>Azure AD SecOps -<b> </b><a href='http://aka.ms/azureadsecops'><b>aka.ms/azureadsecops</b></a><b><br/><br/></b>Azure Monitor Log Analytics and KQL resources: <a href='http://aka.ms/KQLBlueTeam'><b>aka.ms/KQLBlueTeam</b></a><b><br/><br/></b>For community contribution, please follow these prerequisites (these steps are also available at <a href='http://aka.ms/KQLBlueTeam'><b>aka.ms/KQLBlueTeam</b></a>l):<br/>1.      Have a GitHub account<br/>2.      Belong to the <a href='https://urldefense.com/v3/__https://repos.opensource.microsoft.com/orgs/microsoft/teams/azure-ad-workbooks__;!!MlQdS1fu!TWv9E2sZXp4YBrJFU7N92ksN-4CfXDE7tipAUGccDLKAN8dNERkcx3NhDbWVkwnJRUwiNPNFFbDUk2eLxQ$'><b>Microsoft Organization in GitHub</b></a><br/>a.      If you do not yet belong, click on this link: <a href='https://repos.opensource.microsoft.com/'><b>https://repos.opensource.microsoft.com/</b></a> and then select “<a href='https://urldefense.com/v3/__https://github.com/microsoft/Application-Insights-Workbooks__;!!MlQdS1fu!TWv9E2sZXp4YBrJFU7N92ksN-4CfXDE7tipAUGccDLKAN8dNERkcx3NhDbWVkwnJRUwiNPNFFbAaV34fvQ$'><b>Microsoft</b></a><b>” </b>to join their organization<br/>3.      Be a member of the<b> </b><a href='https://urldefense.com/v3/__https://repos.opensource.microsoft.com/orgs/microsoft/teams/azure-ad-workbooks__;!!MlQdS1fu!TWv9E2sZXp4YBrJFU7N92ksN-4CfXDE7tipAUGccDLKAN8dNERkcx3NhDbWVkwnJRUwiNPNFFbDUk2eLxQ$'><b>@azure-ad-workbooks</b></a> team in GitHub<br/>a.      if you are not yet a member, go to the <a href='https://urldefense.com/v3/__https://repos.opensource.microsoft.com/orgs/microsoft/teams/azure-ad-workbooks__;!!MlQdS1fu!TWv9E2sZXp4YBrJFU7N92ksN-4CfXDE7tipAUGccDLKAN8dNERkcx3NhDbWVkwnJRUwiNPNFFbDUk2eLxQ$'><b>Microsoft Organization in GitHub</b></a> and search for the <a href='https://urldefense.com/v3/__https://repos.opensource.microsoft.com/orgs/microsoft/teams/azure-ad-workbooks__;!!MlQdS1fu!TWv9E2sZXp4YBrJFU7N92ksN-4CfXDE7tipAUGccDLKAN8dNERkcx3NhDbWVkwnJRUwiNPNFFbDUk2eLxQ$'><b>@azure-ad-workbooks</b></a> team and request access for approval by owner</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>Nearly every organization is using Microsoft Azure AD services in some respect, but monitoring Azure AD for threats is a significantly different skill that traditional Windows logging. In this episode we have 2 experts from Microsoft, Corissa Koopmans, and 3rd time returning guest Mark Morowczynski, to tell us about the important work that’s been done to help organizations understand their data and detect Azure AD attacks. We cover log sources, the new Microsoft security operations guide, standardized dashboards and visualizations you can leverage to jump right in with best practice, and much more. You don’t want to miss this one!<br/><br/><b>Corissa Koopmans and Mark Morowczynski</b></p><p>Corissa Koopmans (@Corissalea) is part of the &quot;Get to Production&quot; team in the Microsoft Identity and Network Access Division, focusing on incorporating customer feedback to improve our products. She is very active in driving community contribution to AzureMonitor Log Analytics and increasing awareness of the power of log data by presenting at industry events including BSides, The Experts Conference (TEC), SPARK, &amp; Microsoft MVP Summits.<br/><br/>Mark Morowczynski (@markmorow) is a Principal Program Manager on the customer success team in the Microsoft Identity division. He spends most of his time working with customers on their deployments of Azure Active Directory. Previously he was Premier Field Engineer supporting Active Directory, Active Directory Federation Services and Windows Client performance. He&apos;s spoken at various industry events such as Black Hat, Defcon Blue TeamVillage, Blue Team Con, GrayHat, several BSides, and more. He can be frequently found on Twitter as @markmorow arguing about baseball and making sometimes funny gifs.</p><p>Azure AD SecOps -<b> </b><a href='http://aka.ms/azureadsecops'><b>aka.ms/azureadsecops</b></a><b><br/><br/></b>Azure Monitor Log Analytics and KQL resources: <a href='http://aka.ms/KQLBlueTeam'><b>aka.ms/KQLBlueTeam</b></a><b><br/><br/></b>For community contribution, please follow these prerequisites (these steps are also available at <a href='http://aka.ms/KQLBlueTeam'><b>aka.ms/KQLBlueTeam</b></a>l):<br/>1.      Have a GitHub account<br/>2.      Belong to the <a href='https://urldefense.com/v3/__https://repos.opensource.microsoft.com/orgs/microsoft/teams/azure-ad-workbooks__;!!MlQdS1fu!TWv9E2sZXp4YBrJFU7N92ksN-4CfXDE7tipAUGccDLKAN8dNERkcx3NhDbWVkwnJRUwiNPNFFbDUk2eLxQ$'><b>Microsoft Organization in GitHub</b></a><br/>a.      If you do not yet belong, click on this link: <a href='https://repos.opensource.microsoft.com/'><b>https://repos.opensource.microsoft.com/</b></a> and then select “<a href='https://urldefense.com/v3/__https://github.com/microsoft/Application-Insights-Workbooks__;!!MlQdS1fu!TWv9E2sZXp4YBrJFU7N92ksN-4CfXDE7tipAUGccDLKAN8dNERkcx3NhDbWVkwnJRUwiNPNFFbAaV34fvQ$'><b>Microsoft</b></a><b>” </b>to join their organization<br/>3.      Be a member of the<b> </b><a href='https://urldefense.com/v3/__https://repos.opensource.microsoft.com/orgs/microsoft/teams/azure-ad-workbooks__;!!MlQdS1fu!TWv9E2sZXp4YBrJFU7N92ksN-4CfXDE7tipAUGccDLKAN8dNERkcx3NhDbWVkwnJRUwiNPNFFbDUk2eLxQ$'><b>@azure-ad-workbooks</b></a> team in GitHub<br/>a.      if you are not yet a member, go to the <a href='https://urldefense.com/v3/__https://repos.opensource.microsoft.com/orgs/microsoft/teams/azure-ad-workbooks__;!!MlQdS1fu!TWv9E2sZXp4YBrJFU7N92ksN-4CfXDE7tipAUGccDLKAN8dNERkcx3NhDbWVkwnJRUwiNPNFFbDUk2eLxQ$'><b>Microsoft Organization in GitHub</b></a> and search for the <a href='https://urldefense.com/v3/__https://repos.opensource.microsoft.com/orgs/microsoft/teams/azure-ad-workbooks__;!!MlQdS1fu!TWv9E2sZXp4YBrJFU7N92ksN-4CfXDE7tipAUGccDLKAN8dNERkcx3NhDbWVkwnJRUwiNPNFFbDUk2eLxQ$'><b>@azure-ad-workbooks</b></a> team and request access for approval by owner</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/11064031-corissa-koopmans-and-mark-morowczynski-azure-ad-threat-detection-and-logging.mp3" length="34186745" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/r4w9a12t4uambodpo3joiev571f5?.jpg" />
    <itunes:author>John Hubbard</itunes:author>
    <guid isPermaLink="false">Buzzsprout-11064031</guid>
    <pubDate>Tue, 02 Aug 2022 05:00:00 -0400</pubDate>
    <itunes:duration>2844</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>31</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Tony Turner: Securing the Cyber Supply Chain</itunes:title>
    <title>Tony Turner: Securing the Cyber Supply Chain</title>
    <itunes:summary><![CDATA[John and Fortress Vice President of Research and Development Tony Turner share their wisdom on trends they are seeing in the cyber industry and offer advice as to how we should be looking at the Cyber Supply Chain in 2022 and beyond.  Follow Tony Turner LinkedIn: https://www.linkedin.com/in/tonyturnercissp/ Web: https://www.fortressinfosec.com/team/tony-turner   Sponsor's Note: Support for the Blueprint podcast comes from the SANS Institute. If you like the topics covered in this podcast and ...]]></itunes:summary>
    <description><![CDATA[<p>John and Fortress Vice President of Research and Development Tony Turner share their wisdom on trends they are seeing in the cyber industry and offer advice as to how we should be looking at the Cyber Supply Chain in 2022 and beyond.<br/><br/><b>Follow Tony Turner</b></p><p>LinkedIn: https://www.linkedin.com/in/tonyturnercissp/</p><p>Web: https://www.fortressinfosec.com/team/tony-turner</p><p><br/></p><p><b>Sponsor&apos;s Note:</b></p><p>Support for the Blueprint podcast comes from the SANS Institute.</p><p>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.</p><p>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.</p><p>Check out the details at <a href='https://sansurl.com/450'>sansurl.com/450</a>  Hope to see you in class!</p><p><br/></p><p>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a></p><p>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>John and Fortress Vice President of Research and Development Tony Turner share their wisdom on trends they are seeing in the cyber industry and offer advice as to how we should be looking at the Cyber Supply Chain in 2022 and beyond.<br/><br/><b>Follow Tony Turner</b></p><p>LinkedIn: https://www.linkedin.com/in/tonyturnercissp/</p><p>Web: https://www.fortressinfosec.com/team/tony-turner</p><p><br/></p><p><b>Sponsor&apos;s Note:</b></p><p>Support for the Blueprint podcast comes from the SANS Institute.</p><p>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.</p><p>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.</p><p>Check out the details at <a href='https://sansurl.com/450'>sansurl.com/450</a>  Hope to see you in class!</p><p><br/></p><p>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a></p><p>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/11029430-tony-turner-securing-the-cyber-supply-chain.mp3" length="33923357" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/iynz4huj1rm8mt2gz7g0hmgsuiuz?.jpg" />
    <itunes:author>John Hubbard</itunes:author>
    <guid isPermaLink="false">Buzzsprout-11029430</guid>
    <pubDate>Tue, 26 Jul 2022 07:00:00 -0400</pubDate>
    <itunes:duration>2823</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>30</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Mark Orlando: Building a Stronger Blue Team</itunes:title>
    <title>Mark Orlando: Building a Stronger Blue Team</title>
    <itunes:summary><![CDATA[There are many technical factors that contribute to the success of a security operations team, but you need more than just tech skills for mounting a solid defense. In this episode of Blueprint we bring back previous guest Mark Orlando to talk about his BlackHat 2022 presentation with Dr. Daniel Shore (PhD in workplace psychology) . We discuss team dynamics, how the mapping of multi-team systems can improve the flow of your incident response activities, and much more.   Check out the related ...]]></itunes:summary>
    <description><![CDATA[<p>There are many technical factors that contribute to the success of a security operations team, but you need more than just tech skills for mounting a solid defense. In this episode of Blueprint we bring back previous guest Mark Orlando to talk about his BlackHat 2022 presentation with Dr. Daniel Shore (PhD in workplace psychology) . We discuss team dynamics, how the mapping of multi-team systems can improve the flow of your incident response activities, and much more. <br/><br/>Check out the related BlackHat talk here: https://www.youtube.com/watch?v=CtkJ84bc50g<br/><br/><b>Our Guest - Mark Orlando</b></p><p>Mark Orlando is a SANS Associate Instructor, co-author <a href='https://www.sans.org/cyber-security-courses/building-and-leading-security-operations-centers/'>MGT551: Building and Leading Security Operations Centers</a>, instructor for <a href='https://www.sans.org/cyber-security-courses/blue-team-fundamentals-security-operations-analysis?msc=instructor-mark-orlando'>SEC450: Blue Team Fundamentals: Security Operations and Analysis</a>, and the Co-Founder and CEO of Bionic Cyber. Prior to Bionic, Mark built, assessed, and managed security teams at the Pentagon, the White House, the Department of Energy, and numerous Fortune 500 clients. Mark has presented on security operations and assessment at DefCon&apos;s Blue Team Village, the Institute for Applied Network Security (IANS) Forum, BSidesDC, and the RSA Conference and has been quoted in the New York Times, the Washington Post, Forbes, and many other publications. He holds a Bachelor&apos;s Degree in Advanced Information Technology from George Mason University and served in the US Marine Corps as an Artillery Non-Commissioned Officer.</p><p><br/><b>Follow Mark Orlando</b></p><p>Twitter: https://twitter.com/markaorlando</p><p>LinkedIn: https://www.linkedin.com/in/marko16/</p><p>Web: https://www.sans.org/profiles/mark-orlando/</p><p><br/></p><p><b>Sponsor&apos;s Note:</b></p><p>Support for the Blueprint podcast comes from the SANS Institute.</p><p>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.</p><p>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.</p><p>Check out the details at <a href='https://sansurl.com/450'>sansurl.com/450</a>  Hope to see you in class!</p><p><br/></p><p>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a></p><p>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>There are many technical factors that contribute to the success of a security operations team, but you need more than just tech skills for mounting a solid defense. In this episode of Blueprint we bring back previous guest Mark Orlando to talk about his BlackHat 2022 presentation with Dr. Daniel Shore (PhD in workplace psychology) . We discuss team dynamics, how the mapping of multi-team systems can improve the flow of your incident response activities, and much more. <br/><br/>Check out the related BlackHat talk here: https://www.youtube.com/watch?v=CtkJ84bc50g<br/><br/><b>Our Guest - Mark Orlando</b></p><p>Mark Orlando is a SANS Associate Instructor, co-author <a href='https://www.sans.org/cyber-security-courses/building-and-leading-security-operations-centers/'>MGT551: Building and Leading Security Operations Centers</a>, instructor for <a href='https://www.sans.org/cyber-security-courses/blue-team-fundamentals-security-operations-analysis?msc=instructor-mark-orlando'>SEC450: Blue Team Fundamentals: Security Operations and Analysis</a>, and the Co-Founder and CEO of Bionic Cyber. Prior to Bionic, Mark built, assessed, and managed security teams at the Pentagon, the White House, the Department of Energy, and numerous Fortune 500 clients. Mark has presented on security operations and assessment at DefCon&apos;s Blue Team Village, the Institute for Applied Network Security (IANS) Forum, BSidesDC, and the RSA Conference and has been quoted in the New York Times, the Washington Post, Forbes, and many other publications. He holds a Bachelor&apos;s Degree in Advanced Information Technology from George Mason University and served in the US Marine Corps as an Artillery Non-Commissioned Officer.</p><p><br/><b>Follow Mark Orlando</b></p><p>Twitter: https://twitter.com/markaorlando</p><p>LinkedIn: https://www.linkedin.com/in/marko16/</p><p>Web: https://www.sans.org/profiles/mark-orlando/</p><p><br/></p><p><b>Sponsor&apos;s Note:</b></p><p>Support for the Blueprint podcast comes from the SANS Institute.</p><p>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.</p><p>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.</p><p>Check out the details at <a href='https://sansurl.com/450'>sansurl.com/450</a>  Hope to see you in class!</p><p><br/></p><p>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a></p><p>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/10980235-mark-orlando-building-a-stronger-blue-team.mp3" length="35546431" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/r9yjon01fcri2d0wyy692zbub4kd?.jpg" />
    <itunes:author>John Hubbard</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10980235</guid>
    <pubDate>Tue, 19 Jul 2022 05:00:00 -0400</pubDate>
    <itunes:duration>2959</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>29</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Blueprint Live at SANSFIRE 2022: A panel with Heather Mahalik, Katie Nickels and Jeff McJunkin</itunes:title>
    <title>Blueprint Live at SANSFIRE 2022: A panel with Heather Mahalik, Katie Nickels and Jeff McJunkin</title>
    <itunes:summary><![CDATA[Host John Hubbard, Blueprint host and SANS Cyber Defense Curriculum Lead, moderated a panel of cyber security experts including Heather Mahalik, Katie Nickels and Jeff McJunkin for this powerful discussion.  John and guests share their wisdom on trends they are seeing in the cyber industry and offer advice as to how we should be looking at cyber defense in 2022 and beyond.  Guests:  Heather Mahalik Katie Nickels Jeff McJunkin  Filmed live at SANSFIRE 2022 Sponsor's Note: Support for the Bluep...]]></itunes:summary>
    <description><![CDATA[<p>Host John Hubbard, Blueprint host and SANS Cyber Defense Curriculum Lead, moderated a panel of cyber security experts including Heather Mahalik, Katie Nickels and Jeff McJunkin for this powerful discussion.<br/><br/>John and guests share their wisdom on trends they are seeing in the cyber industry and offer advice as to how we should be looking at cyber defense in 2022 and beyond.<br/><br/><b>Guests: <br/></b>Heather Mahalik<br/>Katie Nickels<br/>Jeff McJunkin<br/><br/><b>Filmed live at SANSFIRE 2022</b></p><p><b>Sponsor&apos;s Note:</b></p><p>Support for the Blueprint podcast comes from the SANS Institute.</p><p>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.</p><p>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.</p><p>Check out the details at <a href='https://sansurl.com/450'>sansurl.com/450</a>  Hope to see you in class!</p><p><br/></p><p>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a></p><p>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>Host John Hubbard, Blueprint host and SANS Cyber Defense Curriculum Lead, moderated a panel of cyber security experts including Heather Mahalik, Katie Nickels and Jeff McJunkin for this powerful discussion.<br/><br/>John and guests share their wisdom on trends they are seeing in the cyber industry and offer advice as to how we should be looking at cyber defense in 2022 and beyond.<br/><br/><b>Guests: <br/></b>Heather Mahalik<br/>Katie Nickels<br/>Jeff McJunkin<br/><br/><b>Filmed live at SANSFIRE 2022</b></p><p><b>Sponsor&apos;s Note:</b></p><p>Support for the Blueprint podcast comes from the SANS Institute.</p><p>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.</p><p>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.</p><p>Check out the details at <a href='https://sansurl.com/450'>sansurl.com/450</a>  Hope to see you in class!</p><p><br/></p><p>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a></p><p>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/10961907-blueprint-live-at-sansfire-2022-a-panel-with-heather-mahalik-katie-nickels-and-jeff-mcjunkin.mp3" length="42331118" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/vu28cnlby0pvo8aejn5ieqzb1n0d?.jpg" />
    <itunes:author>John Hubbard</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10961907</guid>
    <pubDate>Thu, 14 Jul 2022 10:00:00 -0400</pubDate>
    <itunes:duration>3523</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>28</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>David Hoelzer: Threat Detection with Machine Learning and AI</itunes:title>
    <title>David Hoelzer: Threat Detection with Machine Learning and AI</title>
    <itunes:summary><![CDATA[Many of us with the typical IT and security backgrounds might not have the slightest idea what to expect when we hear the terms “this product uses advanced machine learning…”, but that claim certainly conjures up a lot of skepticism due to the opaque nature of the algorithms in many of these products. In this episode we discuss what AI and ML are best used for, and what they can, can’t, and shouldn’t be used for with guest Dave Hoelzer.  Our Guest - Dave Hoelzer David Hoelzer, a SANS Fellow a...]]></itunes:summary>
    <description><![CDATA[<p>Many of us with the typical IT and security backgrounds might not have the slightest idea what to expect when we hear the terms “this product uses advanced machine learning…”, but that claim certainly conjures up a lot of skepticism due to the opaque nature of the algorithms in many of these products. In this episode we discuss what AI and ML are best used for, and what they can, can’t, and shouldn’t be used for with guest Dave Hoelzer.</p><p><br/><b>Our Guest - Dave Hoelzer</b></p><p>David Hoelzer, a SANS Fellow and author of more than twenty days of SANS courseware, is an expert in a variety of information security fields, having served in most major roles in the IT and security industries over the past twenty-five years. Currently, David serves as the principal examiner and director of research for Enclave Forensics, a New York/Las Vegas based incident response and forensics company. He also serves as the chief information security officer for Cyber-Defense, an open-source security software solution provider.</p><p><br/></p><p><b>Follow Dave</b></p><p>Twitter: <a href='https://twitter.com/it_audit'>https://twitter.com/it_audit</a> </p><p>LinkedIn: <a href='https://www.linkedin.com/in/davidhoelzer/'>https://www.linkedin.com/in/davidhoelzer/</a> </p><p>--</p><p>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a></p><p>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>Many of us with the typical IT and security backgrounds might not have the slightest idea what to expect when we hear the terms “this product uses advanced machine learning…”, but that claim certainly conjures up a lot of skepticism due to the opaque nature of the algorithms in many of these products. In this episode we discuss what AI and ML are best used for, and what they can, can’t, and shouldn’t be used for with guest Dave Hoelzer.</p><p><br/><b>Our Guest - Dave Hoelzer</b></p><p>David Hoelzer, a SANS Fellow and author of more than twenty days of SANS courseware, is an expert in a variety of information security fields, having served in most major roles in the IT and security industries over the past twenty-five years. Currently, David serves as the principal examiner and director of research for Enclave Forensics, a New York/Las Vegas based incident response and forensics company. He also serves as the chief information security officer for Cyber-Defense, an open-source security software solution provider.</p><p><br/></p><p><b>Follow Dave</b></p><p>Twitter: <a href='https://twitter.com/it_audit'>https://twitter.com/it_audit</a> </p><p>LinkedIn: <a href='https://www.linkedin.com/in/davidhoelzer/'>https://www.linkedin.com/in/davidhoelzer/</a> </p><p>--</p><p>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a></p><p>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/10943041-david-hoelzer-threat-detection-with-machine-learning-and-ai.mp3" length="35831739" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/ie1d57dpts92mxined25ycrngt9m?.jpg" />
    <itunes:author>John Hubbard</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10943041</guid>
    <pubDate>Tue, 12 Jul 2022 06:00:00 -0400</pubDate>
    <itunes:duration>2982</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>27</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>James Rowley: Creating and Running an Insider Threat Program</itunes:title>
    <title>James Rowley: Creating and Running an Insider Threat Program</title>
    <itunes:summary><![CDATA[While malicious insiders are a threat that most of us would like to imagine we might never have to deal with, it’s still one of the cyber threats you must realistically consider and plan for. But how do you identify malicious intent and potential attacks from those already inside our network that have legitimate access to our data? Check out this episode where James Rowley lays out what you need to consider when it comes to insider threat detection.   Our Guest - James Rowley James Rowle...]]></itunes:summary>
    <description><![CDATA[<p>While malicious insiders are a threat that most of us would like to imagine we might never have to deal with, it’s still one of the cyber threats you must realistically consider and plan for. But how do you identify malicious intent and potential attacks from those already inside our network that have legitimate access to our data? Check out this episode where James Rowley lays out what you need to consider when it comes to insider threat detection. </p><p><br/><b>Our Guest - James Rowley</b></p><p>James Rowley is a cybersecurity-consultant-turned-dectection-engineer building the next generation of insider threat detections. As a Detection Engineer, James is responsible for merging the world of blue team and insider threat, moving the needle on how we approach insider detections within cyberspace. James outside of the workspace is passionate about most things related to outdoors, beer, whiskey, wine, food, travel, and Minnesota sports teams. You will find James enjoying these things and more with his fiance and two dogs, Marshall (Bernese Mountain Dog) and Maya (Basset Hound).</p><p>--</p><p><b>Sponsor&apos;s Note:</b></p><p>Support for the Blueprint podcast comes from the SANS Institute.</p><p>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.</p><p>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.</p><p>Check out the details at <a href='http://sans.org/sec450'>http://sans.org/sec450</a> Hope to see you in class!</p><p>--</p><p>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a></p><p>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>While malicious insiders are a threat that most of us would like to imagine we might never have to deal with, it’s still one of the cyber threats you must realistically consider and plan for. But how do you identify malicious intent and potential attacks from those already inside our network that have legitimate access to our data? Check out this episode where James Rowley lays out what you need to consider when it comes to insider threat detection. </p><p><br/><b>Our Guest - James Rowley</b></p><p>James Rowley is a cybersecurity-consultant-turned-dectection-engineer building the next generation of insider threat detections. As a Detection Engineer, James is responsible for merging the world of blue team and insider threat, moving the needle on how we approach insider detections within cyberspace. James outside of the workspace is passionate about most things related to outdoors, beer, whiskey, wine, food, travel, and Minnesota sports teams. You will find James enjoying these things and more with his fiance and two dogs, Marshall (Bernese Mountain Dog) and Maya (Basset Hound).</p><p>--</p><p><b>Sponsor&apos;s Note:</b></p><p>Support for the Blueprint podcast comes from the SANS Institute.</p><p>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.</p><p>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.</p><p>Check out the details at <a href='http://sans.org/sec450'>http://sans.org/sec450</a> Hope to see you in class!</p><p>--</p><p>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a></p><p>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/10943032-james-rowley-creating-and-running-an-insider-threat-program.mp3" length="43008437" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/fcq1fesgm1xbmp2xy7v70tqagapb?.jpg" />
    <itunes:author>John Hubbard</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10943032</guid>
    <pubDate>Tue, 12 Jul 2022 04:00:00 -0400</pubDate>
    <itunes:duration>3580</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>26</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Dean Parsons: Cyber Security for OT and ICS</itunes:title>
    <title>Dean Parsons: Cyber Security for OT and ICS</title>
    <itunes:summary><![CDATA[With ransomware and other highly disruptive attacks on the rise, there are few systems more important to defend than our critical infrastructure and ICS equipment. How should we think about defending these systems vs our typical IT network though? In this episode, Dean Parsons is here to give us that answer.  Our Guest - Dean Parsons Dean brings over 20 years of technical and management experience to the classroom. He has worked in both Information Technology and Industrial Control Syste...]]></itunes:summary>
    <description><![CDATA[<p>With ransomware and other highly disruptive attacks on the rise, there are few systems more important to defend than our critical infrastructure and ICS equipment. How should we think about defending these systems vs our typical IT network though? In this episode, Dean Parsons is here to give us that answer. </p><p><b>Our Guest - Dean Parsons</b></p><p>Dean brings over 20 years of technical and management experience to the classroom. He has worked in both Information Technology and Industrial Control System (ICS) Cyber Defense in critical infrastructure sectors such as telecommunications, and electricity generation, transmission, distribution, and oil &amp; gas refineries, storage, and distribution. Dean is an ambassador for defending industrial systems and an advocate for the safety, reliability, and cyber protection of critical infrastructure. His mission as an instructor is to empower each of his students, and he earnestly preaches that “Defense is Do-able!” </p><p>Over the course of his career, Dean’s accomplishments include establishing entire ICS security programs for critical infrastructure sectors, successfully containing and eradicating malware and ransomware infections in electricity generation and manufacturing control networks, performing malware analysis triage and ICS digital forensics, building converged IT/OT incident response and threat hunt teams, and conducting ICS assessments in electric substations, oil and gas refineries, manufacturing, and telecommunications networks. </p><p>A SANS Certified Instructor, Dean teaches <a href='http://www.sans.org/ics515'>ICS515: ICS Visibility, Detection, and Response</a> and is a co-author of the new SANS Course <a href='http://www.sans.org/ics418'>ICS418: ICS Security Essentials for Managers</a>. Dean is a member of the SANS GIAC Advisory Board and holds many cybersecurity professional certifications including the GICSP, GRID, GSLC, and GCIA, as well as the CISSP®. He is a proud native of Newfoundland and holds a BS in computer science from Memorial University of Newfoundland.</p><p><br/></p><p><b>Follow Dean Parsons</b></p><p>Twitter: <a href='https://twitter.com/deancybersec'>https://twitter.com/deancybersec</a></p><p>LinkedIn: <a href='https://www.linkedin.com/in/dean-parsons-cybersecurity/'>https://www.linkedin.com/in/dean-parsons-cybersecurity/</a></p><p><br/></p><p><b>Resources mentioned in this episode</b></p><p>OSINT / Site-visit Cheat Sheet</p><p>https://www.sans.org/posters/ics-site-visit-plan/</p><p><br/></p><p>ICS Cyber Kill Chain Whitepaper:</p><p>https://www.sans.org/white-papers/36297/?msc=blog-ics-library</p><p><br/></p><p>ICS specific Network Security Monitoring:</p><p>https://www.sans.org/posters/industrial-network-security-monitoring/</p><p><br/></p><p>Top 5 ICS Incident Response Tabletops</p><p>https://www.sans.org/blog/top-5-ics-incident-response-tabletops-and-how-to-run-them/</p><p><br/></p><p>My weekly ICS Defense Force LiveStream</p><p>https://www.youtube.com/playlist?list=PLjoUWqjR7qXhdZIcC8LgEBogrTyeoKqRT</p><p><br/></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>With ransomware and other highly disruptive attacks on the rise, there are few systems more important to defend than our critical infrastructure and ICS equipment. How should we think about defending these systems vs our typical IT network though? In this episode, Dean Parsons is here to give us that answer. </p><p><b>Our Guest - Dean Parsons</b></p><p>Dean brings over 20 years of technical and management experience to the classroom. He has worked in both Information Technology and Industrial Control System (ICS) Cyber Defense in critical infrastructure sectors such as telecommunications, and electricity generation, transmission, distribution, and oil &amp; gas refineries, storage, and distribution. Dean is an ambassador for defending industrial systems and an advocate for the safety, reliability, and cyber protection of critical infrastructure. His mission as an instructor is to empower each of his students, and he earnestly preaches that “Defense is Do-able!” </p><p>Over the course of his career, Dean’s accomplishments include establishing entire ICS security programs for critical infrastructure sectors, successfully containing and eradicating malware and ransomware infections in electricity generation and manufacturing control networks, performing malware analysis triage and ICS digital forensics, building converged IT/OT incident response and threat hunt teams, and conducting ICS assessments in electric substations, oil and gas refineries, manufacturing, and telecommunications networks. </p><p>A SANS Certified Instructor, Dean teaches <a href='http://www.sans.org/ics515'>ICS515: ICS Visibility, Detection, and Response</a> and is a co-author of the new SANS Course <a href='http://www.sans.org/ics418'>ICS418: ICS Security Essentials for Managers</a>. Dean is a member of the SANS GIAC Advisory Board and holds many cybersecurity professional certifications including the GICSP, GRID, GSLC, and GCIA, as well as the CISSP®. He is a proud native of Newfoundland and holds a BS in computer science from Memorial University of Newfoundland.</p><p><br/></p><p><b>Follow Dean Parsons</b></p><p>Twitter: <a href='https://twitter.com/deancybersec'>https://twitter.com/deancybersec</a></p><p>LinkedIn: <a href='https://www.linkedin.com/in/dean-parsons-cybersecurity/'>https://www.linkedin.com/in/dean-parsons-cybersecurity/</a></p><p><br/></p><p><b>Resources mentioned in this episode</b></p><p>OSINT / Site-visit Cheat Sheet</p><p>https://www.sans.org/posters/ics-site-visit-plan/</p><p><br/></p><p>ICS Cyber Kill Chain Whitepaper:</p><p>https://www.sans.org/white-papers/36297/?msc=blog-ics-library</p><p><br/></p><p>ICS specific Network Security Monitoring:</p><p>https://www.sans.org/posters/industrial-network-security-monitoring/</p><p><br/></p><p>Top 5 ICS Incident Response Tabletops</p><p>https://www.sans.org/blog/top-5-ics-incident-response-tabletops-and-how-to-run-them/</p><p><br/></p><p>My weekly ICS Defense Force LiveStream</p><p>https://www.youtube.com/playlist?list=PLjoUWqjR7qXhdZIcC8LgEBogrTyeoKqRT</p><p><br/></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/10943001-dean-parsons-cyber-security-for-ot-and-ics.mp3" length="40703422" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/nlj44ovxxddnyeoqvuhyhy20hi7r?.jpg" />
    <itunes:author>John Hubbard</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10943001</guid>
    <pubDate>Tue, 12 Jul 2022 03:00:00 -0400</pubDate>
    <itunes:duration>3388</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>3</itunes:season>
    <itunes:episode>25</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>John Hubbard: Your Top Cyber Defense Questions Answered from Seasons 1 + 2</itunes:title>
    <title>John Hubbard: Your Top Cyber Defense Questions Answered from Seasons 1 + 2</title>
    <itunes:summary><![CDATA[It's a special mailbag episode from John Hubbard! After two seasons, John asked the listeners what questions they had for him.  He touched on the current XDR trend, how other teams can support SOC activities, defining security mindset, and more.  Contact, Courses, and More: For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live! Check out John's SOC Training Courses for SOC Analysts and Leaders: SEC450: SOC Analyst Trai...]]></itunes:summary>
    <description><![CDATA[<p>It&apos;s a special mailbag episode from John Hubbard! After two seasons, John asked the listeners what questions they had for him.  He touched on the current XDR trend, how other teams can support SOC activities, defining security mindset, and more. </p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>It&apos;s a special mailbag episode from John Hubbard! After two seasons, John asked the listeners what questions they had for him.  He touched on the current XDR trend, how other teams can support SOC activities, defining security mindset, and more. </p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/10888293-john-hubbard-your-top-cyber-defense-questions-answered-from-seasons-1-2.mp3" length="14550213" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/akyssyc2uw5i8et407g34hw2xm1n?.jpg" />
    <itunes:author>John Hubbard</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10888293</guid>
    <pubDate>Fri, 01 Jul 2022 02:00:00 -0400</pubDate>
    <itunes:duration>1208</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>bonus</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>John Hubbard: Key lessons and takeaways from Blueprint Season 2 + A Special Announcement!</itunes:title>
    <title>John Hubbard: Key lessons and takeaways from Blueprint Season 2 + A Special Announcement!</title>
    <itunes:summary><![CDATA[In this solo episode to wrap up season 2, John discusses some of the key takeaways from the guests interviwed throughout this year, and has some very exciting news for all blue teamers on a brand new GIAC certification. ;)  Link: (GIAC GSOC LINK HERE)  John is a Security Operations Center (SOC) consultant and speaker, a Certified SANS instructor, and the course author of two SANS courses, SEC450: Blue Team Fundamentals - Security Operations and Analysis and MGT551: Building and Leading Securi...]]></itunes:summary>
    <description><![CDATA[<p>In this solo episode to wrap up season 2, John discusses some of the key takeaways from the guests interviwed throughout this year, and has some very exciting news for all blue teamers on a brand new GIAC certification. ;)<br/><br/>Link: (GIAC GSOC LINK HERE)<br/><br/>John is a Security Operations Center (SOC) consultant and speaker, a Certified SANS instructor, and the course author of two SANS courses, <a href='https://www.sans.org/course/blue-team-fundamentals-security-operations-analysis?msc=instructor-john-hubbard'>SEC450: Blue Team Fundamentals - Security Operations and Analysis</a> and <a href='https://www.sans.org/cyber-security-courses/building-and-leading-security-operations-centers/'>MGT551: Building and Leading Security Operations Centers</a>. <br/><br/><b>Follow John</b> <br/>Twitter: @SecHubb <br/>YouTube: <a href='https://www.youtube.com/user/jhub908'>youtube.com/user/jhub908</a><br/>LinkedIn:<a href='https://www.linkedin.com/in/johnlhubbard/'> in/johnlhubbard</a><br/><br/>All Blueprint Podcast Episodes: <a href='http://sans.org/blueprint-podcast'>sans.org/blueprint-podcast</a><br/><br/></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>In this solo episode to wrap up season 2, John discusses some of the key takeaways from the guests interviwed throughout this year, and has some very exciting news for all blue teamers on a brand new GIAC certification. ;)<br/><br/>Link: (GIAC GSOC LINK HERE)<br/><br/>John is a Security Operations Center (SOC) consultant and speaker, a Certified SANS instructor, and the course author of two SANS courses, <a href='https://www.sans.org/course/blue-team-fundamentals-security-operations-analysis?msc=instructor-john-hubbard'>SEC450: Blue Team Fundamentals - Security Operations and Analysis</a> and <a href='https://www.sans.org/cyber-security-courses/building-and-leading-security-operations-centers/'>MGT551: Building and Leading Security Operations Centers</a>. <br/><br/><b>Follow John</b> <br/>Twitter: @SecHubb <br/>YouTube: <a href='https://www.youtube.com/user/jhub908'>youtube.com/user/jhub908</a><br/>LinkedIn:<a href='https://www.linkedin.com/in/johnlhubbard/'> in/johnlhubbard</a><br/><br/>All Blueprint Podcast Episodes: <a href='http://sans.org/blueprint-podcast'>sans.org/blueprint-podcast</a><br/><br/></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/8605308-john-hubbard-key-lessons-and-takeaways-from-blueprint-season-2-a-special-announcement.mp3" length="15999806" type="audio/mpeg" />
    <itunes:author>John Hubbard</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8605308</guid>
    <pubDate>Tue, 08 Jun 2021 05:00:00 -0400</pubDate>
    <itunes:duration>1326</itunes:duration>
    <itunes:keywords>cyber defense, blue team, cyber security</itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>23</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Mark Morowczynski &amp; Thomas Detzner: Microsoft Incident Response Playbooks</itunes:title>
    <title>Mark Morowczynski &amp; Thomas Detzner: Microsoft Incident Response Playbooks</title>
    <itunes:summary><![CDATA[We all need solid, well though-out playbooks to help standardize our respons to common threat scenarios. In this episode we speak with Thomas Detzner and Mark Morowczynski about the brand new set of Microsoft incident response playbooks that were just released. This is a brand new effort to meticulously document prerequisites, investigation steps, and remediation process for common scenarios most commonly seen by the Microsoft incident response teams, and you definitely won't want to miss it....]]></itunes:summary>
    <description><![CDATA[<p>We all need solid, well though-out playbooks to help standardize our respons to common threat scenarios. In this episode we speak with Thomas Detzner and Mark Morowczynski about the brand new set of Microsoft incident response playbooks that were just released. This is a brand new effort to meticulously document prerequisites, investigation steps, and remediation process for common scenarios most commonly seen by the Microsoft incident response teams, and you definitely won&apos;t want to miss it.<br/><br/><b>Our Guests: Thomas Detzner and Mark Morowczynski</b><br/>Thomas Detzner is a Project Leader  for Microsoft, creating guidance for Azure AD IR.<br/><br/>Mark Morowczynski (@markmorow) is a Principal Program Manager on the customer success team in the Microsoft Identity division. He spends most of his time working with customers on their deployments of Azure Active Directory. He can be frequently found on Twitter as @markmorow arguing about baseball and making sometimes funny gifs.<br/><br/><b>Links:</b><a href='https://aka.ms/irplaybooks'><b><br/></b>https://aka.ms/irplaybook</a>s - Playbooks discussed in this episode<a href='https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-security-baselines'><br/>https://docs.microsoft.com/en-us/azure/active-directory/reports-monitoring/tutorial-azure-monitor-stream-logs-to-event-hub#access-data-from-your-event-hub</a> - Azure Event Hub<br/><a href='https://techcommunity.microsoft.com/t5/microsoft-security-baselines/security-baseline-final-for-windows-10-v1909-and-windows-server/ba-p/1023093'>https://techcommunity.microsoft.com/t5/microsoft-security-baselines/security-baseline-final-for-windows-10-v1909-and-windows-server/ba-p/1023093</a> - Security Baslines<a href='https://docs.microsoft.com/en-us/security/benchmark/azure/introduction'><br/></a><a href='https://www.microsoft.com/en-us/download/details.aspx?id=52630'>https://www.microsoft.com/en-us/download/details.aspx?id=52630</a> - Security Auditing and Monitoring Reference<br/><br/><b>Sponsor&apos;s Note:</b><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/><br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/><br/>Check out the details at <a href='https://sansurl.com/450'>sansurl.com/450</a>! Hope to see you in class!<br/>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a><br/>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a><br/><br/></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>We all need solid, well though-out playbooks to help standardize our respons to common threat scenarios. In this episode we speak with Thomas Detzner and Mark Morowczynski about the brand new set of Microsoft incident response playbooks that were just released. This is a brand new effort to meticulously document prerequisites, investigation steps, and remediation process for common scenarios most commonly seen by the Microsoft incident response teams, and you definitely won&apos;t want to miss it.<br/><br/><b>Our Guests: Thomas Detzner and Mark Morowczynski</b><br/>Thomas Detzner is a Project Leader  for Microsoft, creating guidance for Azure AD IR.<br/><br/>Mark Morowczynski (@markmorow) is a Principal Program Manager on the customer success team in the Microsoft Identity division. He spends most of his time working with customers on their deployments of Azure Active Directory. He can be frequently found on Twitter as @markmorow arguing about baseball and making sometimes funny gifs.<br/><br/><b>Links:</b><a href='https://aka.ms/irplaybooks'><b><br/></b>https://aka.ms/irplaybook</a>s - Playbooks discussed in this episode<a href='https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-security-baselines'><br/>https://docs.microsoft.com/en-us/azure/active-directory/reports-monitoring/tutorial-azure-monitor-stream-logs-to-event-hub#access-data-from-your-event-hub</a> - Azure Event Hub<br/><a href='https://techcommunity.microsoft.com/t5/microsoft-security-baselines/security-baseline-final-for-windows-10-v1909-and-windows-server/ba-p/1023093'>https://techcommunity.microsoft.com/t5/microsoft-security-baselines/security-baseline-final-for-windows-10-v1909-and-windows-server/ba-p/1023093</a> - Security Baslines<a href='https://docs.microsoft.com/en-us/security/benchmark/azure/introduction'><br/></a><a href='https://www.microsoft.com/en-us/download/details.aspx?id=52630'>https://www.microsoft.com/en-us/download/details.aspx?id=52630</a> - Security Auditing and Monitoring Reference<br/><br/><b>Sponsor&apos;s Note:</b><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/><br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/><br/>Check out the details at <a href='https://sansurl.com/450'>sansurl.com/450</a>! Hope to see you in class!<br/>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a><br/>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a><br/><br/></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/8605219-mark-morowczynski-thomas-detzner-microsoft-incident-response-playbooks.mp3" length="30431948" type="audio/mpeg" />
    <itunes:author>Mark Morowczynski &amp; Thomas Detzner</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8605219</guid>
    <pubDate>Tue, 01 Jun 2021 05:00:00 -0400</pubDate>
    <itunes:duration>2529</itunes:duration>
    <itunes:keywords>cyber defense, blue team, security operations, security operations center, cyber security, azure, microsoft</itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>22</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>AJ Yawn: Cloud, Compliance and Automating Security</itunes:title>
    <title>AJ Yawn: Cloud, Compliance and Automating Security</title>
    <itunes:summary><![CDATA[Compliance and audit checks can be painful, and that's before you introduce additional cloud services and technology. In this episode featuring AJ Yawn we discuss some incredibly useful and actionable cloud security concepts and tools that can help your team boost visibility and reduce user permissions to help prevent breaches before they happen. In addition, we discuss what a good compliance audit should be, and how to turn audits from painful to incredibly valuable.  Resources mentioned in ...]]></itunes:summary>
    <description><![CDATA[<p>Compliance and audit checks can be painful, and that&apos;s before you introduce additional cloud services and technology. In this episode featuring AJ Yawn we discuss some incredibly useful and actionable cloud security concepts and tools that can help your team boost visibility and reduce user permissions to help prevent breaches before they happen. In addition, we discuss what a good compliance audit <em>should</em> be, and how to turn audits from painful to incredibly valuable.<br/><br/><b>Resources mentioned in this episode:</b><br/>- AWS CloudTrail: <a href='https://aws.amazon.com/cloudtrail/'>https://aws.amazon.com/cloudtrail/</a><br/>- AWS Well-Architected Framework:<a href='https://aws.amazon.com/architecture/well-architected/'>https://aws.amazon.com/architecture/well-architected</a>/ <br/>- AWS Config<a href='https://aws.amazon.com/config'>: https://aws.amazon.com/config</a> <br/>- AWS Organizations:<a href='https://aws.amazon.com/organizations/'>https://aws.amazon.com/organizations</a>/ <br/>- AWS Service Control Policies (SCP)<a href='https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps.html'>: https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps.html</a> <br/><br/><b>Our Guest - AJ Yawn </b><br/>AJ Yawn is the Co-Founder and CEO of <a href='https://urldefense.com/v3/__https://t.sidekickopen80.com/s1t/c/5/f18dQhb0S7kF8bpW5bVTNnrV59hl3kW7_k2841CXdp3VPwNcg56l748W2bzNK_1PP6TG101?te=W3R5hFj26QkHmW4mKDsT4rFyV5W3Q_1J-3Fbt5S0&amp;si=8000000003023122&amp;pi=01dbc36e-c0aa-407c-93bf-d7dc24230cdd__;!!MlQdS1fu!AMg3lND9qwEO8FJpjE1avUTv2GABL5NqxuFZXlOGA5Uc60kkLPFsq8JUGMk$'>ByteChek</a>. He is a seasoned cloud security professional that possesses over a decade of senior information security experience with extensive experience managing a wide range of cybersecurity compliance assessments (SOC 2, ISO 27001, HIPAA, etc.) for a variety of SaaS, IaaS, and PaaS providers.</p><p>AJ advises startups on cloud security and serves on the Board of Directors of the ISC2 Miami chapter as the Education Chair, he is also a Founding Board member of the National Association of Black Compliance and Risk Management professions, regularly speaks on information security podcasts, events, and he contributes blogs and articles to the information security community including publications such as CISOMag, InfosecMag, HackerNoon, and ISC2.</p><p><b>Sponsor&apos;s Note:</b><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>Are you looking for the best in-depth training for your cyber defense team? Look no further than SANS blue team curriculum courses!<br/><br/>Whether you focus on network or host data, Windows or Linux, or even specialize in open source intel, SIEM, SOC, or defensive architecture, the SANS Blue Team curriculum has the course for you. From long-time classics like SEC503 Network Intrusion Detection to the newer SEC530 Defensible Security Architecture and Engineering and SEC487 Open Source Intelligence Gathering - we&apos;ve got you covered, no matter what your specialty.<br/><br/>With an extensive archive of free webcasts on the SANS site, and free online demos available for most courses, you can easily check out the SANS blue team catalog and see which course is the best fit for you and your team.<br/><br/>Check out the constantly growing list of available courses at <a href='http://sansurl.com/blueteamops'>sansurl.com/blueteamops</a><br/>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a><br/>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a><br/><br/></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>Compliance and audit checks can be painful, and that&apos;s before you introduce additional cloud services and technology. In this episode featuring AJ Yawn we discuss some incredibly useful and actionable cloud security concepts and tools that can help your team boost visibility and reduce user permissions to help prevent breaches before they happen. In addition, we discuss what a good compliance audit <em>should</em> be, and how to turn audits from painful to incredibly valuable.<br/><br/><b>Resources mentioned in this episode:</b><br/>- AWS CloudTrail: <a href='https://aws.amazon.com/cloudtrail/'>https://aws.amazon.com/cloudtrail/</a><br/>- AWS Well-Architected Framework:<a href='https://aws.amazon.com/architecture/well-architected/'>https://aws.amazon.com/architecture/well-architected</a>/ <br/>- AWS Config<a href='https://aws.amazon.com/config'>: https://aws.amazon.com/config</a> <br/>- AWS Organizations:<a href='https://aws.amazon.com/organizations/'>https://aws.amazon.com/organizations</a>/ <br/>- AWS Service Control Policies (SCP)<a href='https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps.html'>: https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps.html</a> <br/><br/><b>Our Guest - AJ Yawn </b><br/>AJ Yawn is the Co-Founder and CEO of <a href='https://urldefense.com/v3/__https://t.sidekickopen80.com/s1t/c/5/f18dQhb0S7kF8bpW5bVTNnrV59hl3kW7_k2841CXdp3VPwNcg56l748W2bzNK_1PP6TG101?te=W3R5hFj26QkHmW4mKDsT4rFyV5W3Q_1J-3Fbt5S0&amp;si=8000000003023122&amp;pi=01dbc36e-c0aa-407c-93bf-d7dc24230cdd__;!!MlQdS1fu!AMg3lND9qwEO8FJpjE1avUTv2GABL5NqxuFZXlOGA5Uc60kkLPFsq8JUGMk$'>ByteChek</a>. He is a seasoned cloud security professional that possesses over a decade of senior information security experience with extensive experience managing a wide range of cybersecurity compliance assessments (SOC 2, ISO 27001, HIPAA, etc.) for a variety of SaaS, IaaS, and PaaS providers.</p><p>AJ advises startups on cloud security and serves on the Board of Directors of the ISC2 Miami chapter as the Education Chair, he is also a Founding Board member of the National Association of Black Compliance and Risk Management professions, regularly speaks on information security podcasts, events, and he contributes blogs and articles to the information security community including publications such as CISOMag, InfosecMag, HackerNoon, and ISC2.</p><p><b>Sponsor&apos;s Note:</b><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>Are you looking for the best in-depth training for your cyber defense team? Look no further than SANS blue team curriculum courses!<br/><br/>Whether you focus on network or host data, Windows or Linux, or even specialize in open source intel, SIEM, SOC, or defensive architecture, the SANS Blue Team curriculum has the course for you. From long-time classics like SEC503 Network Intrusion Detection to the newer SEC530 Defensible Security Architecture and Engineering and SEC487 Open Source Intelligence Gathering - we&apos;ve got you covered, no matter what your specialty.<br/><br/>With an extensive archive of free webcasts on the SANS site, and free online demos available for most courses, you can easily check out the SANS blue team catalog and see which course is the best fit for you and your team.<br/><br/>Check out the constantly growing list of available courses at <a href='http://sansurl.com/blueteamops'>sansurl.com/blueteamops</a><br/>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a><br/>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a><br/><br/></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/8535355-aj-yawn-cloud-compliance-and-automating-security.mp3" length="40351121" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/ofezdd7cnh8hdd9f2h91o4rydhqo?.jpg" />
    <itunes:author>AJ Yawn</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8535355</guid>
    <pubDate>Tue, 25 May 2021 05:00:00 -0400</pubDate>
    <itunes:duration>3359</itunes:duration>
    <itunes:keywords>cyber defense, blue team, security operations, security operations center, cyber security, cloud, cloud framework, cloud security</itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>21</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Jamie Williams: Adversary Emulation</itunes:title>
    <title>Jamie Williams: Adversary Emulation</title>
    <itunes:summary><![CDATA[There are numerous ways to test your SOC's detection and prevention capabilities, but not all are created equal. Each has their own strengths and weaknesses, and can be done on a different time scale.This week, we focus on arguably one of the most important - adversary emulation. In this episode we speak with Jamie Williams from the MITRE ATT&amp;CK team about why adversary emulation is important, how it works, how you can get started regardless of the size of your team, and how to track and ...]]></itunes:summary>
    <description><![CDATA[<p>There are numerous ways to test your SOC&apos;s detection and prevention capabilities, but not all are created equal. Each has their own strengths and weaknesses, and can be done on a different time scale.This week, we focus on arguably one of the most important - adversary emulation. In this episode we speak with Jamie Williams from the MITRE ATT&amp;CK team about why adversary emulation is important, how it works, how you can get started regardless of the size of your team, and how to track and run an adversary emulation test.<br/><br/><b>Our guest: Jamie Williams</b><br/>Jamie Williams is a Principal Adversary Emulation Engineer for the MITRE Corporation where he works on various exciting efforts involving security operations and research, specializing in adversary emulation and behavior-based detections. He also leads teams that help shape and deliver the “adversary-touch” within ATT&amp;CK® and ATT&amp;CK Evaluations.</p><p>Follow Jamie Williams on Twitter (<a href='https://twitter.com/jamieantisocial'>@jamieantisocial</a>) and LinkedIn (<a href='https://www.linkedin.com/in/jamie-williams-108369190/'>/in/jamie-williams-108369190</a>).<br/><br/><b>Sponsor&apos;s Note<br/></b>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>Since the debut of SEC450, we’ve always had students interested in a matching course covering the management and leadership aspects of running a SOC. If you like the topics in this podcast and would like to learn more about Blue Team leadership and management, check out the new MGT551: Building and Leading Security Operations Centers. This new course is designed for Security Team leaders looking to build, grow and operate a security operation center with peak efficiency. It’s a hands-on technical leadership course, that takes you through everything from scoping threat groups to use case creation, threat hunting, planning, SOC maturity and detection assessment and much much more.<br/><br/>Check out the course syllabus, labs and a free demo at <a href='https://sansurl.com/551'>sansurl.com/551</a> <br/>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a><br/>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>There are numerous ways to test your SOC&apos;s detection and prevention capabilities, but not all are created equal. Each has their own strengths and weaknesses, and can be done on a different time scale.This week, we focus on arguably one of the most important - adversary emulation. In this episode we speak with Jamie Williams from the MITRE ATT&amp;CK team about why adversary emulation is important, how it works, how you can get started regardless of the size of your team, and how to track and run an adversary emulation test.<br/><br/><b>Our guest: Jamie Williams</b><br/>Jamie Williams is a Principal Adversary Emulation Engineer for the MITRE Corporation where he works on various exciting efforts involving security operations and research, specializing in adversary emulation and behavior-based detections. He also leads teams that help shape and deliver the “adversary-touch” within ATT&amp;CK® and ATT&amp;CK Evaluations.</p><p>Follow Jamie Williams on Twitter (<a href='https://twitter.com/jamieantisocial'>@jamieantisocial</a>) and LinkedIn (<a href='https://www.linkedin.com/in/jamie-williams-108369190/'>/in/jamie-williams-108369190</a>).<br/><br/><b>Sponsor&apos;s Note<br/></b>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>Since the debut of SEC450, we’ve always had students interested in a matching course covering the management and leadership aspects of running a SOC. If you like the topics in this podcast and would like to learn more about Blue Team leadership and management, check out the new MGT551: Building and Leading Security Operations Centers. This new course is designed for Security Team leaders looking to build, grow and operate a security operation center with peak efficiency. It’s a hands-on technical leadership course, that takes you through everything from scoping threat groups to use case creation, threat hunting, planning, SOC maturity and detection assessment and much much more.<br/><br/>Check out the course syllabus, labs and a free demo at <a href='https://sansurl.com/551'>sansurl.com/551</a> <br/>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a><br/>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/8535324-jamie-williams-adversary-emulation.mp3" length="35329651" type="audio/mpeg" />
    <link>https://sans.org/blueprint-podcast</link>
    <itunes:image href="https://storage.buzzsprout.com/qt2fou0x0lvvcu95ob5g3c4uh4ld?.jpg" />
    <itunes:author>Jamie Williams</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8535324</guid>
    <pubDate>Tue, 18 May 2021 05:00:00 -0400</pubDate>
    <itunes:duration>2941</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>20</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Josh Johnson: PowerShell and Defensive Automation for the Blue Team</itunes:title>
    <title>Josh Johnson: PowerShell and Defensive Automation for the Blue Team</title>
    <itunes:summary><![CDATA[PowerShell may seem intimidating, but it can be one of the most amazing and useful tools at your disposal...if you know how to use it. In this episode, we have Josh Johnson, author of the new SANS course "SEC586: Blue Team Operations - Defensive Powershell" giving you a masterful crash course in:   - The importance of PowerShell - How PowerShell works, and how to set yourself up to use it - Blue team use cases for log analysis, incident response and more - How to stopping attackers from lever...]]></itunes:summary>
    <description><![CDATA[<p>PowerShell may seem intimidating, but it can be one of the most amazing and useful tools at your disposal...if you know how to use it. In this episode, we have Josh Johnson, author of the new SANS course &quot;SEC586: Blue Team Operations - Defensive Powershell&quot; giving you a masterful crash course in: <br/><br/>- The importance of PowerShell<br/>- How PowerShell works, and how to set yourself up to use it<br/>- Blue team use cases for log analysis, incident response and more<br/>- How to stopping attackers from leveraging PowerShell<br/>- Some of the amazing automation and playbook opportunities you may be missing out on.<br/><br/>Lots of actionable content for defenders here, don&apos;t miss in this episode!<br/><br/><br/><b>Our Guest: Josh Johnson</b><br/>Josh Johnson is a SANS Certified Instructor and course author of SEC586: Blue Team Operations: Defensive PowerShell. He has been working in the Information Security industry for over 10 years in varying roles with responsibilities ranging from penetration testing to incident response. Josh was Purple Teaming since before it had a name and used his offensive security skill set to find and pursue his true passion - Blue Team. Since then, he has been helping organizations of all sizes, and in varying industries from healthcare to retail to finance, improve their cyber defense capabilities.</p><p><a href='https://www.sans.org/profiles/profile'><b>More About Josh</b></a><b><br/><br/>Follow Josh:  </b><a href='https://twitter.com/jcjohnson34'><b>Twitter</b></a><b> | </b><a href='https://www.linkedin.com/in/jcjohnson34/'><b>LinkedIn</b></a><b><br/><br/>Sponsor&apos;s Note:</b><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/><br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/><br/>Check out the details at sansurl.com/450! Hope to see you in class!<br/><br/>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a><br/>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a><b><br/><br/></b><br/></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>PowerShell may seem intimidating, but it can be one of the most amazing and useful tools at your disposal...if you know how to use it. In this episode, we have Josh Johnson, author of the new SANS course &quot;SEC586: Blue Team Operations - Defensive Powershell&quot; giving you a masterful crash course in: <br/><br/>- The importance of PowerShell<br/>- How PowerShell works, and how to set yourself up to use it<br/>- Blue team use cases for log analysis, incident response and more<br/>- How to stopping attackers from leveraging PowerShell<br/>- Some of the amazing automation and playbook opportunities you may be missing out on.<br/><br/>Lots of actionable content for defenders here, don&apos;t miss in this episode!<br/><br/><br/><b>Our Guest: Josh Johnson</b><br/>Josh Johnson is a SANS Certified Instructor and course author of SEC586: Blue Team Operations: Defensive PowerShell. He has been working in the Information Security industry for over 10 years in varying roles with responsibilities ranging from penetration testing to incident response. Josh was Purple Teaming since before it had a name and used his offensive security skill set to find and pursue his true passion - Blue Team. Since then, he has been helping organizations of all sizes, and in varying industries from healthcare to retail to finance, improve their cyber defense capabilities.</p><p><a href='https://www.sans.org/profiles/profile'><b>More About Josh</b></a><b><br/><br/>Follow Josh:  </b><a href='https://twitter.com/jcjohnson34'><b>Twitter</b></a><b> | </b><a href='https://www.linkedin.com/in/jcjohnson34/'><b>LinkedIn</b></a><b><br/><br/>Sponsor&apos;s Note:</b><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/><br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/><br/>Check out the details at sansurl.com/450! Hope to see you in class!<br/><br/>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a><br/>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a><b><br/><br/></b><br/></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/8452437-josh-johnson-powershell-and-defensive-automation-for-the-blue-team.mp3" length="35060866" type="audio/mpeg" />
    <link>http://sans.org/blueprint-podcast</link>
    <itunes:image href="https://storage.buzzsprout.com/2sz9wku7okp1zizj1gtq4ffsg40z?.jpg" />
    <itunes:author>Josh Johnson</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8452437</guid>
    <pubDate>Tue, 11 May 2021 05:00:00 -0400</pubDate>
    <itunes:duration>2919</itunes:duration>
    <itunes:keywords>PowerShell, cyber defense, blue team, security operations, security operations center, cyber security</itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>19</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Chris Baker: Get A Handle On Your Vulnerabilities</itunes:title>
    <title>Chris Baker: Get A Handle On Your Vulnerabilities</title>
    <itunes:summary><![CDATA[This episode is all about vulnerability management - both the technical and human aspects. Looking to start up a new vulnerability management team? Drowning in vulnerabilities to fix and don't know where to start? Struggling to get system owners to take action? Trying to find ways to communicate the importance and status of your patching efforts?   Check out this episode with vulnerability management expert Chris Baker for answer these to questions and much more!  Our Guest: Chris Baker Chris...]]></itunes:summary>
    <description><![CDATA[<p>This episode is all about vulnerability management - both the technical and human aspects. Looking to start up a new vulnerability management team? Drowning in vulnerabilities to fix and don&apos;t know where to start? Struggling to get system owners to take action? Trying to find ways to communicate the importance and status of your patching efforts? <br/><br/>Check out this episode with vulnerability management expert Chris Baker for answer these to questions and much more!<br/><br/><b>Our Guest: Chris Baker<br/></b>Chris Baker is an Information Security Leader with a deep background in information security including strategy development and operational excellence that has created highly efficient teams and delivered large impacts to the business value chain. He is a skilled risk management and information security professional with the versatility to lead large and diverse matrix teams and deep-dive into complex technical problems. A proven track record of collaborating effectively at all business levels while directing changes on a global, enterprise-wide scale.</p><p><br/><b>Follow Chris Baker<br/></b><a href='https://urldefense.com/v3/__https://www.twitter.com/bakerc__;!!MlQdS1fu!GDF5SpoKwWwm5y788D1DEAuOBqV92nP7HahmlmJ5sw7K54RkAqZHz2i1EzY$'>@bakerc</a> | <a href='https://urldefense.com/v3/__https://www.linkedin.com/in/cwbaker__;!!MlQdS1fu!GDF5SpoKwWwm5y788D1DEAuOBqV92nP7HahmlmJ5sw7K54RkAqZHnZDv1hs$'>LinkedIn</a></p><p><br/><b>Sponsor Note<br/></b>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>Are you looking for the best in-depth training for your cyber defense team? Look no further than SANS blue team curriculum courses!<br/><br/>Whether you focus on network or host data, Windows or Linux, or even specialize in open source intel, SIEM, SOC, or defensive architecture, the SANS Blue Team curriculum has the course for you. From long-time classics like SEC503 Network Intrusion Detection to the newer SEC530 Defensible Security Architecture and Engineering and SEC487 Open Source Intelligence Gathering - we&apos;ve got you covered, no matter what your specialty.<br/><br/>With an extensive archive of free webcasts on the SANS site, and free online demos available for most courses, you can easily check out the SANS blue team catalog and see which course is the best fit for you and your team.<br/><br/>Check out the constantly growing list of available courses at <a href='https://sansurl.com/blueteamops'>sansurl.com/blueteamops</a><br/>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a><br/>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><br/></p><p><br/><br/></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>This episode is all about vulnerability management - both the technical and human aspects. Looking to start up a new vulnerability management team? Drowning in vulnerabilities to fix and don&apos;t know where to start? Struggling to get system owners to take action? Trying to find ways to communicate the importance and status of your patching efforts? <br/><br/>Check out this episode with vulnerability management expert Chris Baker for answer these to questions and much more!<br/><br/><b>Our Guest: Chris Baker<br/></b>Chris Baker is an Information Security Leader with a deep background in information security including strategy development and operational excellence that has created highly efficient teams and delivered large impacts to the business value chain. He is a skilled risk management and information security professional with the versatility to lead large and diverse matrix teams and deep-dive into complex technical problems. A proven track record of collaborating effectively at all business levels while directing changes on a global, enterprise-wide scale.</p><p><br/><b>Follow Chris Baker<br/></b><a href='https://urldefense.com/v3/__https://www.twitter.com/bakerc__;!!MlQdS1fu!GDF5SpoKwWwm5y788D1DEAuOBqV92nP7HahmlmJ5sw7K54RkAqZHz2i1EzY$'>@bakerc</a> | <a href='https://urldefense.com/v3/__https://www.linkedin.com/in/cwbaker__;!!MlQdS1fu!GDF5SpoKwWwm5y788D1DEAuOBqV92nP7HahmlmJ5sw7K54RkAqZHnZDv1hs$'>LinkedIn</a></p><p><br/><b>Sponsor Note<br/></b>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>Are you looking for the best in-depth training for your cyber defense team? Look no further than SANS blue team curriculum courses!<br/><br/>Whether you focus on network or host data, Windows or Linux, or even specialize in open source intel, SIEM, SOC, or defensive architecture, the SANS Blue Team curriculum has the course for you. From long-time classics like SEC503 Network Intrusion Detection to the newer SEC530 Defensible Security Architecture and Engineering and SEC487 Open Source Intelligence Gathering - we&apos;ve got you covered, no matter what your specialty.<br/><br/>With an extensive archive of free webcasts on the SANS site, and free online demos available for most courses, you can easily check out the SANS blue team catalog and see which course is the best fit for you and your team.<br/><br/>Check out the constantly growing list of available courses at <a href='https://sansurl.com/blueteamops'>sansurl.com/blueteamops</a><br/>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a><br/>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><br/></p><p><br/><br/></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/8451744-chris-baker-get-a-handle-on-your-vulnerabilities.mp3" length="28684534" type="audio/mpeg" />
    <link>http://sans.org/blueprint-podcast</link>
    <itunes:image href="https://storage.buzzsprout.com/hezag5j17jwrfysg7sdacfjpfisl?.jpg" />
    <itunes:author>Chris Baker</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8451744</guid>
    <pubDate>Tue, 04 May 2021 05:00:00 -0400</pubDate>
    <itunes:duration>2387</itunes:duration>
    <itunes:keywords>cyber defense, blue team, security operations, security operations center, cyber security, vulnerability management</itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>18</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Mick Douglas &amp; Flynn Weeks: Simplifying your Logging Strategy with the What2Log Project</itunes:title>
    <title>Mick Douglas &amp; Flynn Weeks: Simplifying your Logging Strategy with the What2Log Project</title>
    <itunes:summary><![CDATA[A common question from many defenders is "Which logs are the most important?” In this episode, Mick Douglas and Flynn Weeks join us to describe their What2Log project, which aims to simplify this problem for all of us!  Our Guests: Mick Douglas &amp; Flynn Weeks Mick Douglas is the Managing Partner of InfoSec Innovations. He is a SANS certified instructor and is a member of the IANS faculty. In his spare time, he tries in vain to improve his photography skills and goes hiking looking for the ...]]></itunes:summary>
    <description><![CDATA[<p>A common question from many defenders is &quot;Which logs are the most important?” In this episode, Mick Douglas and Flynn Weeks join us to describe their What2Log project, which aims to simplify this problem for all of us!<br/><br/><b>Our Guests: Mick Douglas &amp; Flynn Weeks<br/></b>Mick Douglas is the Managing Partner of InfoSec Innovations. He is a SANS certified instructor and is a member of the IANS faculty. In his spare time, he tries in vain to improve his photography skills and goes hiking looking for the perfect shot.<br/><br/>Flynn is a senior Cybersecurity student and intern at InfoSec Innovations. Forensics, and in turn, logging, are passions of hers. In her spare time, she enjoys her time spent with pets and hiking. <br/><br/><b>Follow Mick and Flynn<br/></b>Twitter:  Mick <a href='https://twitter.com/bettersafetynet'>@bettersafetynet</a> and Flynn <a href='https://twitter.com/soundsofthetime'>@soundsofthetime</a><br/><br/><br/></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>A common question from many defenders is &quot;Which logs are the most important?” In this episode, Mick Douglas and Flynn Weeks join us to describe their What2Log project, which aims to simplify this problem for all of us!<br/><br/><b>Our Guests: Mick Douglas &amp; Flynn Weeks<br/></b>Mick Douglas is the Managing Partner of InfoSec Innovations. He is a SANS certified instructor and is a member of the IANS faculty. In his spare time, he tries in vain to improve his photography skills and goes hiking looking for the perfect shot.<br/><br/>Flynn is a senior Cybersecurity student and intern at InfoSec Innovations. Forensics, and in turn, logging, are passions of hers. In her spare time, she enjoys her time spent with pets and hiking. <br/><br/><b>Follow Mick and Flynn<br/></b>Twitter:  Mick <a href='https://twitter.com/bettersafetynet'>@bettersafetynet</a> and Flynn <a href='https://twitter.com/soundsofthetime'>@soundsofthetime</a><br/><br/><br/></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/8387922-mick-douglas-flynn-weeks-simplifying-your-logging-strategy-with-the-what2log-project.mp3" length="33247535" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/zqffo0b79u3v0bq77qtxqewozajo?.jpg" />
    <itunes:author>Mick Douglas and Flynn Weeks</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8387922</guid>
    <pubDate>Tue, 27 Apr 2021 05:00:00 -0400</pubDate>
    <itunes:duration>2766</itunes:duration>
    <itunes:keywords>cyber defense, blue team, security operations, security operations center, cyber security</itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>17</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Anton Chuvakin: The Current State and Future of Security Operations</itunes:title>
    <title>Anton Chuvakin: The Current State and Future of Security Operations</title>
    <itunes:summary><![CDATA[In today’s episode, John is joined by Anton Chuvakin to discuss current and future security operations technology, which tools are the most important and which are becoming less important over time, the rules of automation in the SOC and how Anton would setup a modern Security Operations Center for a Cloud native organization.  Today's Guest: Anton Chuvakin Dr. Anton Chuvakin is a recognized security expert in the field of log management, SIEM and PCI DSS compliance. He is now involved with s...]]></itunes:summary>
    <description><![CDATA[<p>In today’s episode, John is joined by Anton Chuvakin to discuss current and future security operations technology, which tools are the most important and which are becoming less important over time, the rules of automation in the SOC and how Anton would setup a modern Security Operations Center for a Cloud native organization.<br/><br/><b>Today&apos;s Guest: Anton Chuvakin</b><br/><a href='http://www.chuvakin.org/'><b>Dr. Anton Chuvakin</b></a> is a recognized security expert in the field of log management, SIEM and PCI DSS compliance. He is now involved with security solution strategy at <a href='https://cloud.google.com/'>Google Cloud</a>, where he arrived via <a href='https://chronicle.security/'>Chronicle Security (an Alphabet company)</a> acquisition in July 2019. </p><p>He is an author of books <a href='http://www.amazon.com/Security-Warrior-Cyrus-Peikari/dp/0596005458'>&quot;Security Warrior&quot;</a>, <a href='http://www.amazon.com/dp/1597496359/'>&quot;Logging and Log Management: The Authoritative Guide to Understanding the Concepts Surrounding Logging and Log Management&quot;</a> and &quot;<a href='http://www.amazon.com/PCI-Compliance-Third-Understand-Implement/dp/159749948X/'>&quot;PCI Compliance, Third Edition: Understand and Implement Effective PCI Data Security Standard Compliance&quot;</a>&quot; (<a href='http://www.pcicompliancebook.info/'>book website</a>) and a contributor to &quot;Know Your Enemy II&quot;, &quot;Information Security Management Handbook&quot; and other books. </p><p>Anton has published <a href='http://www.info-secure.org/'>dozens of papers</a> on log management, SIEM, correlation, security data analysis, PCI DSS, security management. His blog <a href='http://www.securitywarrior.org/'>&quot;Security Warrior&quot;</a> was one of the most popular in the industry. In addition, Anton teaches classes and <a href='http://www.chuvakin.org/secpublic.html'>presents</a> at many security conferences across the world; he addressed audiences in United States, UK, Australia, Singapore, Spain, Russia and other countries. He works on <a href='http://chuvakin.blogspot.com/search/label/CEE'>emerging security standards</a> and serves on advisory boards of several security start-ups.</p><p><br/><b>Follow Anton<br/></b>Twitter:  <a href='https://twitter.com/anton_chuvakin'>@anton_chuvakin</a><br/>LinkedIn: <a href='https://www.linkedin.com/in/chuvakin/'>/in/chuvakin</a><br/><br/>Check out the constantly growing list of available courses at <a href='https://sansurl.com/blueteamops'>sansurl.com/blueteamops</a><br/>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a><br/>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>In today’s episode, John is joined by Anton Chuvakin to discuss current and future security operations technology, which tools are the most important and which are becoming less important over time, the rules of automation in the SOC and how Anton would setup a modern Security Operations Center for a Cloud native organization.<br/><br/><b>Today&apos;s Guest: Anton Chuvakin</b><br/><a href='http://www.chuvakin.org/'><b>Dr. Anton Chuvakin</b></a> is a recognized security expert in the field of log management, SIEM and PCI DSS compliance. He is now involved with security solution strategy at <a href='https://cloud.google.com/'>Google Cloud</a>, where he arrived via <a href='https://chronicle.security/'>Chronicle Security (an Alphabet company)</a> acquisition in July 2019. </p><p>He is an author of books <a href='http://www.amazon.com/Security-Warrior-Cyrus-Peikari/dp/0596005458'>&quot;Security Warrior&quot;</a>, <a href='http://www.amazon.com/dp/1597496359/'>&quot;Logging and Log Management: The Authoritative Guide to Understanding the Concepts Surrounding Logging and Log Management&quot;</a> and &quot;<a href='http://www.amazon.com/PCI-Compliance-Third-Understand-Implement/dp/159749948X/'>&quot;PCI Compliance, Third Edition: Understand and Implement Effective PCI Data Security Standard Compliance&quot;</a>&quot; (<a href='http://www.pcicompliancebook.info/'>book website</a>) and a contributor to &quot;Know Your Enemy II&quot;, &quot;Information Security Management Handbook&quot; and other books. </p><p>Anton has published <a href='http://www.info-secure.org/'>dozens of papers</a> on log management, SIEM, correlation, security data analysis, PCI DSS, security management. His blog <a href='http://www.securitywarrior.org/'>&quot;Security Warrior&quot;</a> was one of the most popular in the industry. In addition, Anton teaches classes and <a href='http://www.chuvakin.org/secpublic.html'>presents</a> at many security conferences across the world; he addressed audiences in United States, UK, Australia, Singapore, Spain, Russia and other countries. He works on <a href='http://chuvakin.blogspot.com/search/label/CEE'>emerging security standards</a> and serves on advisory boards of several security start-ups.</p><p><br/><b>Follow Anton<br/></b>Twitter:  <a href='https://twitter.com/anton_chuvakin'>@anton_chuvakin</a><br/>LinkedIn: <a href='https://www.linkedin.com/in/chuvakin/'>/in/chuvakin</a><br/><br/>Check out the constantly growing list of available courses at <a href='https://sansurl.com/blueteamops'>sansurl.com/blueteamops</a><br/>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a><br/>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/8322743-anton-chuvakin-the-current-state-and-future-of-security-operations.mp3" length="33960816" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/mnzwfgf0mjenciylajm03an4059b?.jpg" />
    <itunes:author>Anton Chuvakin</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8322743</guid>
    <pubDate>Tue, 20 Apr 2021 05:00:00 -0400</pubDate>
    <itunes:duration>2827</itunes:duration>
    <itunes:keywords>cyber defense, blue team, security operations, security operations center, cyber security</itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>16</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Rob van Os: Maturing your Cyber Defense</itunes:title>
    <title>Rob van Os: Maturing your Cyber Defense</title>
    <itunes:summary><![CDATA[Are you a manager looking to build or improve your SOC? Are you trying to understand how to measure your SOCs maturity or use cases or your threat hunting efforts? If so, today’s episode with Rob van Os is for you. In this episode, we discuss the SOC CMM for SOC maturity measurement, the magma use case framework for building and tracking SOC use cases, and the Tahiti threat hunting methodology for showing ROI on threat hunting.   Our Guest is Rob van Os Rob van Os, MSc., CISSP, ISSAP is a sen...]]></itunes:summary>
    <description><![CDATA[<p>Are you a manager looking to build or improve your SOC? Are you trying to understand how to measure your SOCs maturity or use cases or your threat hunting efforts? If so, today’s episode with Rob van Os is for you. In this episode, we discuss the SOC CMM for SOC maturity measurement, the magma use case framework for building and tracking SOC use cases, and the Tahiti threat hunting methodology for showing ROI on threat hunting.<br/><br/><br/><b>Our Guest is Rob van Os<br/></b>Rob van Os, MSc., CISSP, ISSAP is a senior security advisor working for CZ group. Until recently, Rob was the Product Owner of the Cyber Defense Center of a Dutch bank and as such responsible for cyber security operations. Rob obtained a Bachelor&apos;s degree in Computer Science in 2009 and a Master&apos;s degree in Information Security in 2016. Rob is the author of the SOC-CMM and lead author of the MaGMa UCF and the TaHiTI methodology.<b> <br/><br/>Follow Rob:<br/>Linkedin: </b><a href='https://www.linkedin.com/in/cyberdefensespecialist/'>/in/cyberdefensespecialist</a><b> <br/>Website:  </b><a href='https://www.soc-cmm.com/'><b>https://www.soc-cmm.com/ </b></a><b> <br/><br/>Sponsor&apos;s Note:<br/></b>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/><br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/><br/>Check out the constantly growing list of available courses at <a href='https://sansurl.com/blueteamops'>sansurl.com/blueteamops</a><br/>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a><br/>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>Are you a manager looking to build or improve your SOC? Are you trying to understand how to measure your SOCs maturity or use cases or your threat hunting efforts? If so, today’s episode with Rob van Os is for you. In this episode, we discuss the SOC CMM for SOC maturity measurement, the magma use case framework for building and tracking SOC use cases, and the Tahiti threat hunting methodology for showing ROI on threat hunting.<br/><br/><br/><b>Our Guest is Rob van Os<br/></b>Rob van Os, MSc., CISSP, ISSAP is a senior security advisor working for CZ group. Until recently, Rob was the Product Owner of the Cyber Defense Center of a Dutch bank and as such responsible for cyber security operations. Rob obtained a Bachelor&apos;s degree in Computer Science in 2009 and a Master&apos;s degree in Information Security in 2016. Rob is the author of the SOC-CMM and lead author of the MaGMa UCF and the TaHiTI methodology.<b> <br/><br/>Follow Rob:<br/>Linkedin: </b><a href='https://www.linkedin.com/in/cyberdefensespecialist/'>/in/cyberdefensespecialist</a><b> <br/>Website:  </b><a href='https://www.soc-cmm.com/'><b>https://www.soc-cmm.com/ </b></a><b> <br/><br/>Sponsor&apos;s Note:<br/></b>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/><br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/><br/>Check out the constantly growing list of available courses at <a href='https://sansurl.com/blueteamops'>sansurl.com/blueteamops</a><br/>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a><br/>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/8319764-rob-van-os-maturing-your-cyber-defense.mp3" length="35296377" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/pe1gczcrofw272ina7owq5gg0o84?.jpg" />
    <itunes:author>Rob van Os</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8319764</guid>
    <pubDate>Tue, 13 Apr 2021 05:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1142720/8319764/transcript" type="text/html" />
    <itunes:duration>2938</itunes:duration>
    <itunes:keywords>cyber defense, blue team, security operations, security operations center, cyber security</itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>15</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>true</itunes:explicit>
  </item>
  <item>
    <itunes:title>AppSec, DevOps and DevSecOps</itunes:title>
    <title>AppSec, DevOps and DevSecOps</title>
    <itunes:summary><![CDATA[What is AppSec, DevOps and DevSecOps? In this episode we discuss why defenders should know more about these terms and what the consequences are of ignoring these new and critical fields.  Tanya Janca, also known as SheHacksPurple, is the best-selling author of ‘Alice and Bob Learn Application Security’. She is also the founder of We Hack Purple, an online learning academy, community and podcast that revolves around teaching everyone to create secure software. Tanya has been coding and working...]]></itunes:summary>
    <description><![CDATA[<p>What is AppSec, DevOps and DevSecOps? In this episode we discuss why defenders should know more about these terms and what the consequences are of ignoring these new and critical fields.<br/><br/>Tanya Janca, also known as <a href='https://shehackspurple.ca/'>SheHacksPurple</a>, is the best-selling author of ‘<a href='https://aliceandboblearn.com/'>Alice and Bob Learn Application Security</a>’. She is also the founder of We Hack Purple, an online learning academy, community and podcast that revolves around teaching <em>everyone</em> to create secure software. Tanya has been coding and working in IT for over twenty years, won countless awards, and has been everywhere from startups to public service to tech giants (Microsoft, Adobe, &amp; Nokia). She has worn many hats; startup founder, pentester, CISO, AppSec Engineer, and software developer. She is an award-winning public speaker, active blogger &amp; streamer and has delivered hundreds of talks and trainings on 6 continents. She values diversity, inclusion and kindness, which shines through in her countless initiatives.</p><p>Advisor: <a href='https://nordvpn.com'>Nord VPN</a>, <a href='http://clouddefense.ai/'>Cloud Defense</a>, <a href='https://www.neuralegion.com/'>NeuraLegion</a>, <a href='https://www.ictc-ctic.ca/'>ICTC PAC</a>, <a href='https://womenofsecurity.com/'>WoSEC</a></p><p>Founder: <a href='https://wehackpurple.com/'>We Hack Purple</a>, <a href='https://womenofsecurity.com/'>WoSEC International</a> (Women of Security), <a href='https://www.youtube.com/owasp_devslop'>OWASP DevSlop</a>, <a href='https://twitter.com/search?q=%23cybermentoringmonday&amp;src=typed_query&amp;f=live'>#CyberMentoringMonday</a></p><p><br/><br/><b>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/><br/>Check out the constantly growing list of available courses at sansurl.com/blueteamops<br/></b>Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube<br/>Follow John Hubbard: Twitter | LinkedIn</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>What is AppSec, DevOps and DevSecOps? In this episode we discuss why defenders should know more about these terms and what the consequences are of ignoring these new and critical fields.<br/><br/>Tanya Janca, also known as <a href='https://shehackspurple.ca/'>SheHacksPurple</a>, is the best-selling author of ‘<a href='https://aliceandboblearn.com/'>Alice and Bob Learn Application Security</a>’. She is also the founder of We Hack Purple, an online learning academy, community and podcast that revolves around teaching <em>everyone</em> to create secure software. Tanya has been coding and working in IT for over twenty years, won countless awards, and has been everywhere from startups to public service to tech giants (Microsoft, Adobe, &amp; Nokia). She has worn many hats; startup founder, pentester, CISO, AppSec Engineer, and software developer. She is an award-winning public speaker, active blogger &amp; streamer and has delivered hundreds of talks and trainings on 6 continents. She values diversity, inclusion and kindness, which shines through in her countless initiatives.</p><p>Advisor: <a href='https://nordvpn.com'>Nord VPN</a>, <a href='http://clouddefense.ai/'>Cloud Defense</a>, <a href='https://www.neuralegion.com/'>NeuraLegion</a>, <a href='https://www.ictc-ctic.ca/'>ICTC PAC</a>, <a href='https://womenofsecurity.com/'>WoSEC</a></p><p>Founder: <a href='https://wehackpurple.com/'>We Hack Purple</a>, <a href='https://womenofsecurity.com/'>WoSEC International</a> (Women of Security), <a href='https://www.youtube.com/owasp_devslop'>OWASP DevSlop</a>, <a href='https://twitter.com/search?q=%23cybermentoringmonday&amp;src=typed_query&amp;f=live'>#CyberMentoringMonday</a></p><p><br/><br/><b>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/><br/>Check out the constantly growing list of available courses at sansurl.com/blueteamops<br/></b>Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube<br/>Follow John Hubbard: Twitter | LinkedIn</p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/8218230-appsec-devops-and-devsecops.mp3" length="31598343" type="audio/mpeg" />
    <link>http://sans.org/blueprint-podcast</link>
    <itunes:image href="https://storage.buzzsprout.com/s27zomqtnnwwid7cmhdyjrdbpe0z?.jpg" />
    <itunes:author>Tanya Janca</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8218230</guid>
    <pubDate>Tue, 06 Apr 2021 05:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1142720/8218230/transcript" type="text/html" />
    <itunes:duration>2629</itunes:duration>
    <itunes:keywords>cyber defense, blue team, security operations, security operations center, cyber security, AppSec, DevOps, DevSecOps</itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>14</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Playbook for Security Onion</itunes:title>
    <title>Playbook for Security Onion</title>
    <itunes:summary><![CDATA[Driving consistency and maintaining a high standard for alert response is a problem all SOCs must face, but how? In this episode, Josh Brower describes his efforts to combine automated detection signature deployment and use case database management into a single, easy to use app for Security Onion. Whether you use Security Onion or not, this episode dives into the design principles and workflow Josh used when designing the new open-source Playbook app and there’s something to learn from it fo...]]></itunes:summary>
    <description><![CDATA[<p>Driving consistency and maintaining a high standard for alert response is a problem all SOCs must face, but how? In this episode, Josh Brower describes his efforts to combine automated detection signature deployment and use case database management into a single, easy to use app for Security Onion. Whether you use Security Onion or not, this episode dives into the design principles and workflow Josh used when designing the new open-source Playbook app and there’s something to learn from it for everyone on the Blue Team.<br/><br/><b>Our Guest - Josh Brower<br/></b>Josh Brower has been crashing computers since his teens, and now feels fortunate to be doing it professionally. He has spent the last 12 years focusing on InfoSec, particularly network and endpoint detection. He also enjoys teaching around InfoSec issues, especially to non-technical learners - helping them to understand how their actions in the digital world have real-world consequences, as well as how to proactively reduce the risk.<br/><br/><b>Follow Josh<br/></b>Twitter: <a href='https://twitter.com/DefensiveDepth'><b>@DefensiveDepth</b></a><br/>LinkedIn: <a href='https://www.linkedin.com/in/joshbrower/'><b>/in/joshbrower</b></a> <br/>Web: <a href='https://defensivedepth.com/'><b>https://defensivedepth.com</b></a><br/><br/><br/><b>Support for the Blueprint podcast comes from the SANS Institute<br/></b>Are you looking for the best in-depth training for your cyber defense team? Look no further than SANS blue team curriculum courses!<br/><br/>Whether you focus on network or host data, Windows or Linux, or even specialize in open source intel, SIEM, SOC, or defensive architecture, the SANS Blue Team curriculum has the course for you. From long-time classics like SEC503 Network Intrusion Detection to the newer SEC530 Defensible Security Architecture and Engineering and SEC487 Open Source Intelligence Gathering - we&apos;ve got you covered, no matter what your specialty.<br/><br/>With an extensive archive of free webcasts on the SANS site, and free online demos available for most courses, you can easily check out the SANS blue team catalog and see which course is the best fit for you and your team.<br/><br/>Check out the constantly growing list of available courses at <a href='https://sansurl.com/blueteamops'>sansurl.com/blueteamops</a><br/>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a><br/>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a><br/><br/></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>Driving consistency and maintaining a high standard for alert response is a problem all SOCs must face, but how? In this episode, Josh Brower describes his efforts to combine automated detection signature deployment and use case database management into a single, easy to use app for Security Onion. Whether you use Security Onion or not, this episode dives into the design principles and workflow Josh used when designing the new open-source Playbook app and there’s something to learn from it for everyone on the Blue Team.<br/><br/><b>Our Guest - Josh Brower<br/></b>Josh Brower has been crashing computers since his teens, and now feels fortunate to be doing it professionally. He has spent the last 12 years focusing on InfoSec, particularly network and endpoint detection. He also enjoys teaching around InfoSec issues, especially to non-technical learners - helping them to understand how their actions in the digital world have real-world consequences, as well as how to proactively reduce the risk.<br/><br/><b>Follow Josh<br/></b>Twitter: <a href='https://twitter.com/DefensiveDepth'><b>@DefensiveDepth</b></a><br/>LinkedIn: <a href='https://www.linkedin.com/in/joshbrower/'><b>/in/joshbrower</b></a> <br/>Web: <a href='https://defensivedepth.com/'><b>https://defensivedepth.com</b></a><br/><br/><br/><b>Support for the Blueprint podcast comes from the SANS Institute<br/></b>Are you looking for the best in-depth training for your cyber defense team? Look no further than SANS blue team curriculum courses!<br/><br/>Whether you focus on network or host data, Windows or Linux, or even specialize in open source intel, SIEM, SOC, or defensive architecture, the SANS Blue Team curriculum has the course for you. From long-time classics like SEC503 Network Intrusion Detection to the newer SEC530 Defensible Security Architecture and Engineering and SEC487 Open Source Intelligence Gathering - we&apos;ve got you covered, no matter what your specialty.<br/><br/>With an extensive archive of free webcasts on the SANS site, and free online demos available for most courses, you can easily check out the SANS blue team catalog and see which course is the best fit for you and your team.<br/><br/>Check out the constantly growing list of available courses at <a href='https://sansurl.com/blueteamops'>sansurl.com/blueteamops</a><br/>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a><br/>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a><br/><br/></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/8217638-playbook-for-security-onion.mp3" length="23705461" type="audio/mpeg" />
    <link>http://sans.org/blueprint-podcast</link>
    <itunes:image href="https://storage.buzzsprout.com/ljwwqljvz6cfgq65jtoeseepaxzx?.jpg" />
    <itunes:author>Josh Brower</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8217638</guid>
    <pubDate>Tue, 30 Mar 2021 07:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1142720/8217638/transcript" type="text/html" />
    <itunes:duration>1972</itunes:duration>
    <itunes:keywords>cyber defense, blue team, security operations, security operations center, cyber security, security onion, playbook app</itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>13</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The Blue Teamer&#39;s Blueprint for Malware Triage</itunes:title>
    <title>The Blue Teamer&#39;s Blueprint for Malware Triage</title>
    <itunes:summary><![CDATA[Even if you're not a malware analyst, any blue teamer should be able to do some initial basic malware sample triage. The good news is that this is quite easy to do using freely available tools once you know what is available. Join John in this conversation with Ryan Chapman as they discuss how to reverse engineer malware and why you might want to do so.  Our Guest - Ryan Chapman Ryan Chapman works as a Principal Incident Response analyst. He also teaches SANS FOR610: Reverse Engineering Malwa...]]></itunes:summary>
    <description><![CDATA[<p>Even if you&apos;re not a malware analyst, any blue teamer should be able to do some initial basic malware sample triage. The good news is that this is quite easy to do using freely available tools once you know what is available. Join John in this conversation with Ryan Chapman as they discuss how to reverse engineer malware and why you might want to do so.<b><br/><br/>Our Guest - Ryan Chapman<br/></b>Ryan Chapman works as a Principal Incident Response analyst. He also teaches SANS FOR610: Reverse Engineering Malware and is the lead organizer for CactusCon, Arizona&apos;s hcaker conference. Ryan has worked in Security Operations Center and Computer Incident Response Team roles that handled incidents from inception all the way through remediation. Reviewing log traffic; researching domains and IPs; hunting through log aggregation utilities; sifting through pack captures; analyzing malware; and performing host and network forensics are all things that Ryan loves to do. With Ryan, it&apos;s all about the blue team!<br/><b><br/>Follow Ryan</b><br/>Twitter: <a href='https://twitter.com/rj_chap'>@rj_chap</a><br/>LinkedIn: <a href='https://www.linkedin.com/in/ryanjchapman/'>/in/ryanjchapman</a><br/>Web: <a href='https://incidentresponse.training/'>https://incidentresponse.training</a><b><br/><br/>Sponsor&apos;s Note:<br/></b>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/><br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/><br/>Check out the details at <a href='https://sansurl.com/450'>sansurl.com/450</a>  Hope to see you in class!<br/><b><br/></b>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a><br/>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>Even if you&apos;re not a malware analyst, any blue teamer should be able to do some initial basic malware sample triage. The good news is that this is quite easy to do using freely available tools once you know what is available. Join John in this conversation with Ryan Chapman as they discuss how to reverse engineer malware and why you might want to do so.<b><br/><br/>Our Guest - Ryan Chapman<br/></b>Ryan Chapman works as a Principal Incident Response analyst. He also teaches SANS FOR610: Reverse Engineering Malware and is the lead organizer for CactusCon, Arizona&apos;s hcaker conference. Ryan has worked in Security Operations Center and Computer Incident Response Team roles that handled incidents from inception all the way through remediation. Reviewing log traffic; researching domains and IPs; hunting through log aggregation utilities; sifting through pack captures; analyzing malware; and performing host and network forensics are all things that Ryan loves to do. With Ryan, it&apos;s all about the blue team!<br/><b><br/>Follow Ryan</b><br/>Twitter: <a href='https://twitter.com/rj_chap'>@rj_chap</a><br/>LinkedIn: <a href='https://www.linkedin.com/in/ryanjchapman/'>/in/ryanjchapman</a><br/>Web: <a href='https://incidentresponse.training/'>https://incidentresponse.training</a><b><br/><br/>Sponsor&apos;s Note:<br/></b>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/>If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.<br/><br/>This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.<br/><br/>Check out the details at <a href='https://sansurl.com/450'>sansurl.com/450</a>  Hope to see you in class!<br/><b><br/></b>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a><br/>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/8100003-the-blue-teamer-s-blueprint-for-malware-triage.mp3" length="47991539" type="audio/mpeg" />
    <link>http://sans.org/blueprint-podcast</link>
    <itunes:image href="https://storage.buzzsprout.com/wurgnp3yplyz0kuc4ytmdlvf7xbk?.jpg" />
    <itunes:author>Ryan Chapman</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8100003</guid>
    <pubDate>Tue, 30 Mar 2021 06:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1142720/8100003/transcript" type="text/html" />
    <podcast:soundbite startTime="278.0" duration="60.0" />
    <itunes:duration>3996</itunes:duration>
    <itunes:keywords>cyber defense, blue team, security operations, security operations center, cyber security, malware</itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>12</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>SOC Metrics: Measuring Success and Preventing Burnout</itunes:title>
    <title>SOC Metrics: Measuring Success and Preventing Burnout</title>
    <itunes:summary><![CDATA[Looking for a new way to approach the difficult problem of measuring and improving your SOC? Check out this episode to hear how to use methods pioneered in the manufacturing and reliability industry to help wrap your head around, and solve this complex issue. You don’t want to miss this episode with Jon Hencinski, Director of Operations at Expel who covers all of this and more.  Our guest - Jon Hencinski Jon Hencinski is the Director of Global Operations at Expel. In this role, he’s responsib...]]></itunes:summary>
    <description><![CDATA[<p>Looking for a new way to approach the difficult problem of measuring and improving your SOC? Check out this episode to hear how to use methods pioneered in the manufacturing and reliability industry to help wrap your head around, and solve this complex issue. You don’t want to miss this episode with Jon Hencinski, Director of Operations at Expel who covers all of this and more.<br/><br/><b>Our guest - Jon Hencinski<br/></b>Jon Hencinski is the Director of Global Operations at Expel. In this role, he’s responsible for the day-to-day operations of Expel’s security operations center (SOC) and detection and response engineering. He oversees how Expel recruits, trains, and develops security analysts. Jon has over a decade of experience in the areas of SOC operations, threat detection, and incident response. Prior to Expel, Jon worked at FireEye, BAE Systems, and was an adjunct professor at The George Washington University.<br/><br/><b>Follow Jon</b><br/>Twitter: <a href='https://twitter.com/jhencinski'><b>@jhencinski</b></a><br/>LinkedIn: <a href='https://www.linkedin.com/in/jonathanhencinski/'><b>/in/jonathanhencinski</b></a><br/>Web: <a href='https://hencinski.medium.com/'><b>https://hencinski.medium.com</b></a><b><br/><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/></b>Since the debut of SEC450, we’ve always had students interested in a matching course covering the management and leadership aspects of running a SOC. If you like the topics in this podcast and would like to learn more about Blue Team leadership and management, check out the new MGT551: Building and Leading Security Operations Centers. This new course is designed for Security Team leaders looking to build, grow and operate a security operation center with peak efficiency. It’s a hands-on technical leadership course, that takes you through everything from scoping threat groups to use case creation, threat hunting, planning, SOC maturity and detection assessment and much much more.<br/><br/>Check out the course syllabus, labs and a free demo at <a href='https://sansurl.com/551'>sansurl.com/551</a><b> <br/></b><br/>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a><br/>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>Looking for a new way to approach the difficult problem of measuring and improving your SOC? Check out this episode to hear how to use methods pioneered in the manufacturing and reliability industry to help wrap your head around, and solve this complex issue. You don’t want to miss this episode with Jon Hencinski, Director of Operations at Expel who covers all of this and more.<br/><br/><b>Our guest - Jon Hencinski<br/></b>Jon Hencinski is the Director of Global Operations at Expel. In this role, he’s responsible for the day-to-day operations of Expel’s security operations center (SOC) and detection and response engineering. He oversees how Expel recruits, trains, and develops security analysts. Jon has over a decade of experience in the areas of SOC operations, threat detection, and incident response. Prior to Expel, Jon worked at FireEye, BAE Systems, and was an adjunct professor at The George Washington University.<br/><br/><b>Follow Jon</b><br/>Twitter: <a href='https://twitter.com/jhencinski'><b>@jhencinski</b></a><br/>LinkedIn: <a href='https://www.linkedin.com/in/jonathanhencinski/'><b>/in/jonathanhencinski</b></a><br/>Web: <a href='https://hencinski.medium.com/'><b>https://hencinski.medium.com</b></a><b><br/><br/>Support for the Blueprint podcast comes from the SANS Institute.<br/><br/></b>Since the debut of SEC450, we’ve always had students interested in a matching course covering the management and leadership aspects of running a SOC. If you like the topics in this podcast and would like to learn more about Blue Team leadership and management, check out the new MGT551: Building and Leading Security Operations Centers. This new course is designed for Security Team leaders looking to build, grow and operate a security operation center with peak efficiency. It’s a hands-on technical leadership course, that takes you through everything from scoping threat groups to use case creation, threat hunting, planning, SOC maturity and detection assessment and much much more.<br/><br/>Check out the course syllabus, labs and a free demo at <a href='https://sansurl.com/551'>sansurl.com/551</a><b> <br/></b><br/>Follow SANS Cyber Defense: <a href='https://twitter.com/sansdefense'>Twitter</a> | <a href='https://www.linkedin.com/showcase/sans-cyber-security/'>LinkedIn</a> | <a href='https://www.youtube.com/c/SANSBlueTeamOps'>YouTube</a><br/>Follow John Hubbard: <a href='https://twitter.com/sechubb'>Twitter</a> | <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/8217538-soc-metrics-measuring-success-and-preventing-burnout.mp3" length="35487702" type="audio/mpeg" />
    <link>http://sans.org/blueprint-podcast</link>
    <itunes:image href="https://storage.buzzsprout.com/mq28qei0u4kgeobhqm2qtnxvu4da?.jpg" />
    <itunes:author>Jon Hencinski</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8217538</guid>
    <pubDate>Tue, 30 Mar 2021 05:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1142720/8217538/transcript" type="text/html" />
    <itunes:duration>2954</itunes:duration>
    <itunes:keywords>cyber defense, blue team, security operations, security operations center, cyber security</itunes:keywords>
    <itunes:season>2</itunes:season>
    <itunes:episode>11</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>A Machine Learning Primer for the Blue Team</itunes:title>
    <title>A Machine Learning Primer for the Blue Team</title>
    <itunes:summary><![CDATA[Austin Taylor discusses the promise and reality of cyber security-centric data science, and how you can use machine learning for solving practical security problems.  Twitter Handles: @HuntOperator | @SecHubb | @SANSDefense  All Blueprint Podcast Episodes: sans.org/blueprint-podcast Contact, Courses, and More: For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live! Check out John's SOC Training Courses for SOC Analysts and Leader...]]></itunes:summary>
    <description><![CDATA[<p>Austin Taylor discusses the promise and reality of cyber security-centric data science, and how you can use machine learning for solving practical security problems.<br/><br/>Twitter Handles: <a href='https://twitter.com/HuntOperator'>@HuntOperator</a> | <a href='https://www.twitter.com/sechubb'>@SecHubb</a> | <a href='https://www.twitter.com/sansdefense'>@SANSDefense<br/><br/></a>All Blueprint Podcast Episodes: <a href='http://sans.org/blueprint-podcast'>sans.org/blueprint-podcast</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>Austin Taylor discusses the promise and reality of cyber security-centric data science, and how you can use machine learning for solving practical security problems.<br/><br/>Twitter Handles: <a href='https://twitter.com/HuntOperator'>@HuntOperator</a> | <a href='https://www.twitter.com/sechubb'>@SecHubb</a> | <a href='https://www.twitter.com/sansdefense'>@SANSDefense<br/><br/></a>All Blueprint Podcast Episodes: <a href='http://sans.org/blueprint-podcast'>sans.org/blueprint-podcast</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/4934351-a-machine-learning-primer-for-the-blue-team.mp3" length="28965605" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/4aqulvz5qrp6bz4wzeie7mke1vhl?.jpg" />
    <itunes:author>Austin Taylor</itunes:author>
    <guid isPermaLink="false">Buzzsprout-4934351</guid>
    <pubDate>Tue, 11 Aug 2020 05:00:00 -0400</pubDate>
    <itunes:duration>2411</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>10</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Empowering Security Researchers Around the World!</itunes:title>
    <title>Empowering Security Researchers Around the World!</title>
    <itunes:summary><![CDATA[Roberto Rodriguez explains the awesome projects and initiatives he is working on to help blue teams perform advanced data collection, analysis, and threat hunting.  Twitter Handles: @Cyb3rWard0g | @SecHubb | @SANSDefense  All Blueprint Podcast Episodes: sans.org/blueprint-podcast Contact, Courses, and More: For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live! Check out John's SOC Training Courses for SOC Analysts and Leaders: ...]]></itunes:summary>
    <description><![CDATA[<p>Roberto Rodriguez explains the awesome projects and initiatives he is working on to help blue teams perform advanced data collection, analysis, and threat hunting.<br/><br/>Twitter Handles: <a href='https://twitter.com/Cyb3rWard0g'>@Cyb3rWard0g</a> | <a href='https://www.twitter.com/sechubb'>@SecHubb</a> | <a href='https://www.twitter.com/sansdefense'>@SANSDefense<br/><br/></a>All Blueprint Podcast Episodes: <a href='http://sans.org/blueprint-podcast'>sans.org/blueprint-podcast</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>Roberto Rodriguez explains the awesome projects and initiatives he is working on to help blue teams perform advanced data collection, analysis, and threat hunting.<br/><br/>Twitter Handles: <a href='https://twitter.com/Cyb3rWard0g'>@Cyb3rWard0g</a> | <a href='https://www.twitter.com/sechubb'>@SecHubb</a> | <a href='https://www.twitter.com/sansdefense'>@SANSDefense<br/><br/></a>All Blueprint Podcast Episodes: <a href='http://sans.org/blueprint-podcast'>sans.org/blueprint-podcast</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/4831121-empowering-security-researchers-around-the-world.mp3" length="29292602" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/y14emjblvx97b0z80zvm0bezmx25?.jpg" />
    <itunes:author>Roberto Rodriguez</itunes:author>
    <guid isPermaLink="false">Buzzsprout-4831121</guid>
    <pubDate>Tue, 04 Aug 2020 05:00:00 -0400</pubDate>
    <itunes:duration>2438</itunes:duration>
    <itunes:keywords>cyber defense, blue team, cyber security</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>9</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Locking Down and Monitoring Cloud Infrastructure</itunes:title>
    <title>Locking Down and Monitoring Cloud Infrastructure</title>
    <itunes:summary><![CDATA[Cloud expert Kyle Dickinson discusses common cloud infrastructure attacks, and how you can detect and prevent them before they happen to your organization.  Twitter Handles: @KyleHaxWhy | @SecHubb | @SANSDefense  All Blueprint Podcast Episodes: sans.org/blueprint-podcast Contact, Courses, and More: For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live! Check out John's SOC Training Courses for SOC Analysts and Leaders: SEC450: S...]]></itunes:summary>
    <description><![CDATA[<p>Cloud expert Kyle Dickinson discusses common cloud infrastructure attacks, and how you can detect and prevent them before they happen to your organization.<br/><br/>Twitter Handles: <a href='https://www.twitter.com/kylehaxwhy'>@KyleHaxWhy</a> | <a href='https://www.twitter.com/sechubb'>@SecHubb</a> | <a href='https://www.twitter.com/sansdefense'>@SANSDefense<br/><br/></a>All Blueprint Podcast Episodes: <a href='http://sans.org/blueprint-podcast'>sans.org/blueprint-podcast</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>Cloud expert Kyle Dickinson discusses common cloud infrastructure attacks, and how you can detect and prevent them before they happen to your organization.<br/><br/>Twitter Handles: <a href='https://www.twitter.com/kylehaxwhy'>@KyleHaxWhy</a> | <a href='https://www.twitter.com/sechubb'>@SecHubb</a> | <a href='https://www.twitter.com/sansdefense'>@SANSDefense<br/><br/></a>All Blueprint Podcast Episodes: <a href='http://sans.org/blueprint-podcast'>sans.org/blueprint-podcast</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/4691612-locking-down-and-monitoring-cloud-infrastructure.mp3" length="29782729" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/s136ud7zhitykgvssjh3dcwkzoji?.jpg" />
    <itunes:author>Kyle Dickinson</itunes:author>
    <guid isPermaLink="false">Buzzsprout-4691612</guid>
    <pubDate>Tue, 28 Jul 2020 05:00:00 -0400</pubDate>
    <itunes:duration>2478</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>8</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Passwordless - Can it Be Done?</itunes:title>
    <title>Passwordless - Can it Be Done?</title>
    <itunes:summary><![CDATA[Mark and Libby share the new technologies in use at Microsoft to dramatically decrease the need for the use of passwords in the enterprise.  Twitter Handles: @markmorow | @TruBluDevil | @SecHubb | @SANSDefense  All Blueprint Podcast Episodes: sans.org/blueprint-podcast Contact, Courses, and More: For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live! Check out John's SOC Training Courses for SOC Analysts and Leaders: SEC450: SOC...]]></itunes:summary>
    <description><![CDATA[<p>Mark and Libby share the new technologies in use at Microsoft to dramatically decrease the need for the use of passwords in the enterprise.<br/><br/>Twitter Handles: <a href='https://twitter.com/markmorow'>@markmorow</a> | <a href='https://twitter.com/TruBluDevil'>@TruBluDevil</a> | <a href='https://www.twitter.com/sechubb'>@SecHubb</a> | <a href='https://www.twitter.com/sansdefense'>@SANSDefense<br/><br/></a>All Blueprint Podcast Episodes: <a href='http://sans.org/blueprint-podcast'>sans.org/blueprint-podcast</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>Mark and Libby share the new technologies in use at Microsoft to dramatically decrease the need for the use of passwords in the enterprise.<br/><br/>Twitter Handles: <a href='https://twitter.com/markmorow'>@markmorow</a> | <a href='https://twitter.com/TruBluDevil'>@TruBluDevil</a> | <a href='https://www.twitter.com/sechubb'>@SecHubb</a> | <a href='https://www.twitter.com/sansdefense'>@SANSDefense<br/><br/></a>All Blueprint Podcast Episodes: <a href='http://sans.org/blueprint-podcast'>sans.org/blueprint-podcast</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/4584251-passwordless-can-it-be-done.mp3" length="29351100" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/nwje15z3ffrxobo3g603529v1vpw?.jpg" />
    <itunes:author>Mark Morowczynski and Libby Brown</itunes:author>
    <guid isPermaLink="false">Buzzsprout-4584251</guid>
    <pubDate>Tue, 21 Jul 2020 04:00:00 -0400</pubDate>
    <itunes:duration>2441</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>7</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Training Yourself in a Quarantined World</itunes:title>
    <title>Training Yourself in a Quarantined World</title>
    <itunes:summary><![CDATA[Dave and Ryan speak with John about resources for training yourself, and the challenges of setting up a large-scale cyber lab to simulate an advanced attack for their Splunk Boss of the SOC competition.  Twitter Handles: @daveherrald | @meansec | @SecHubb | @SANSDefense  All Blueprint Podcast Episodes: sans.org/blueprint-podcast   Contact, Courses, and More: For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live! Check out John's...]]></itunes:summary>
    <description><![CDATA[<p>Dave and Ryan speak with John about resources for training yourself, and the challenges of setting up a large-scale cyber lab to simulate an advanced attack for their Splunk Boss of the SOC competition.<br/><br/>Twitter Handles: <a href='https://www.twitter.com/daveherrald'>@daveherrald</a> | <a href='https://www.twitter.com/meansec'>@meansec</a> | <a href='https://www.twitter.com/sechubb'>@SecHubb</a> | <a href='https://www.twitter.com/sansdefense'>@SANSDefense<br/><br/></a>All Blueprint Podcast Episodes: <a href='http://sans.org/blueprint-podcast'>sans.org/blueprint-podcast</a><br/><br/></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>Dave and Ryan speak with John about resources for training yourself, and the challenges of setting up a large-scale cyber lab to simulate an advanced attack for their Splunk Boss of the SOC competition.<br/><br/>Twitter Handles: <a href='https://www.twitter.com/daveherrald'>@daveherrald</a> | <a href='https://www.twitter.com/meansec'>@meansec</a> | <a href='https://www.twitter.com/sechubb'>@SecHubb</a> | <a href='https://www.twitter.com/sansdefense'>@SANSDefense<br/><br/></a>All Blueprint Podcast Episodes: <a href='http://sans.org/blueprint-podcast'>sans.org/blueprint-podcast</a><br/><br/></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/4506770-training-yourself-in-a-quarantined-world.mp3" length="24856594" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/c07nivibo626u8m2cb0bith0lmu9?.jpg" />
    <itunes:author>Dave Herrald and Ryan Kovar</itunes:author>
    <guid isPermaLink="false">Buzzsprout-4506770</guid>
    <pubDate>Tue, 14 Jul 2020 04:00:00 -0400</pubDate>
    <itunes:duration>2067</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>6</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Understanding and Applying Threat Intelligence </itunes:title>
    <title>Understanding and Applying Threat Intelligence </title>
    <itunes:summary><![CDATA[Katie Nickels talks about what threat intelligence is, where to get it, what you should expect from it, and how the SOC should be using it.   Twitter Handles: @likethecoins | @SecHubb | @SANSDefense  All Blueprint Podcast Episodes: sans.org/blueprint-podcast Contact, Courses, and More: For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live! Check out John's SOC Training Courses for SOC Analysts and Leaders: SEC450: SOC Analyst Tr...]]></itunes:summary>
    <description><![CDATA[<p>Katie Nickels talks about what threat intelligence is, where to get it, what you should expect from it, and how the SOC should be using it. <br/><br/>Twitter Handles: <a href='https://www.twitter.com/likethecoins'>@likethecoins</a> | <a href='https://www.twitter.com/sechubb'>@SecHubb</a> | <a href='https://www.twitter.com/sansdefense'>@SANSDefense</a><br/><br/>All Blueprint Podcast Episodes: <a href='http://sans.org/blueprint-podcast'>sans.org/blueprint-podcast</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>Katie Nickels talks about what threat intelligence is, where to get it, what you should expect from it, and how the SOC should be using it. <br/><br/>Twitter Handles: <a href='https://www.twitter.com/likethecoins'>@likethecoins</a> | <a href='https://www.twitter.com/sechubb'>@SecHubb</a> | <a href='https://www.twitter.com/sansdefense'>@SANSDefense</a><br/><br/>All Blueprint Podcast Episodes: <a href='http://sans.org/blueprint-podcast'>sans.org/blueprint-podcast</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/4341632-understanding-and-applying-threat-intelligence.mp3" length="28573863" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/pplekrvhizvi93nm9rrdw9kw8l65?.jpg" />
    <itunes:author>Katie Nickels</itunes:author>
    <guid isPermaLink="false">Buzzsprout-4341632</guid>
    <pubDate>Tue, 07 Jul 2020 04:00:00 -0400</pubDate>
    <itunes:duration>2377</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>5</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Privacy Laws: The Future Driver of Cyber Security</itunes:title>
    <title>Privacy Laws: The Future Driver of Cyber Security</title>
    <itunes:summary><![CDATA[Mary Chaney shares what types of laws we should be concerned about. She discusses her thoughts on privacy laws and how that will drive cyber security, and what she’s doing to get more diverse representation in the industry at all levels.   Twitter Handles: @MaryNChaney | @SecHubb | @SANSDefense  All Blueprint Podcast Episodes: sans.org/blueprint-podcast Contact, Courses, and More: For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpo...]]></itunes:summary>
    <description><![CDATA[<p>Mary Chaney shares what types of laws we should be concerned about. She discusses her thoughts on privacy laws and how that will drive cyber security, and what she’s doing to get more diverse representation in the industry at all levels. <br/><br/>Twitter Handles: <a href='https://twitter.com/MaryNChaney'>@MaryNChaney</a> | <a href='https://twitter.com/SecHubb'>@SecHubb</a> | <a href='https://www.twitter.com/sansdefense'>@SANSDefense</a><br/><br/>All Blueprint Podcast Episodes: <a href='http://sans.org/blueprint-podcast'>sans.org/blueprint-podcast</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>Mary Chaney shares what types of laws we should be concerned about. She discusses her thoughts on privacy laws and how that will drive cyber security, and what she’s doing to get more diverse representation in the industry at all levels. <br/><br/>Twitter Handles: <a href='https://twitter.com/MaryNChaney'>@MaryNChaney</a> | <a href='https://twitter.com/SecHubb'>@SecHubb</a> | <a href='https://www.twitter.com/sansdefense'>@SANSDefense</a><br/><br/>All Blueprint Podcast Episodes: <a href='http://sans.org/blueprint-podcast'>sans.org/blueprint-podcast</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/4341623-privacy-laws-the-future-driver-of-cyber-security.mp3" length="28449330" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/ck76tsqjtooerg1pjsbwj8zgjvhu?.jpg" />
    <itunes:author>Mary Chaney</itunes:author>
    <guid isPermaLink="false">Buzzsprout-4341623</guid>
    <pubDate>Tue, 30 Jun 2020 04:00:00 -0400</pubDate>
    <itunes:duration>2367</itunes:duration>
    <itunes:keywords>cyber defense, blue team, cyber security, cyber law, privacy law, diversity and inclusion, </itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>4</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Creativity and Choices: Talking About Thinking</itunes:title>
    <title>Creativity and Choices: Talking About Thinking</title>
    <itunes:summary><![CDATA[Chris Sanders and Stef Rand discuss qualitative research they conducted on how to use divergent or convergent thinking for improving the quality of your analysis.  Twitter Handles: @ChrisSanders88 | @techieStef | @SecHubb | @SANSDefense  All Blueprint Podcast Episodes: sans.org/blueprint-podcast    Contact, Courses, and More: For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live! Check out John's SOC Training Courses for SOC Ana...]]></itunes:summary>
    <description><![CDATA[<p>Chris Sanders and Stef Rand discuss qualitative research they conducted on how to use divergent or convergent thinking for improving the quality of your analysis.<br/><br/>Twitter Handles: <a href='https://twitter.com/chrissanders88'>@ChrisSanders88</a> | <a href='https://twitter.com/techieStef'>@techieStef</a> | <a href='https://www.twitter.com/sechubb'>@SecHubb</a> | <a href='https://www.twitter.com/sansdefense'>@SANSDefense</a><br/><br/>All Blueprint Podcast Episodes: <a href='http://sans.org/blueprint-podcast'>sans.org/blueprint-podcast</a><br/><br/><br/></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>Chris Sanders and Stef Rand discuss qualitative research they conducted on how to use divergent or convergent thinking for improving the quality of your analysis.<br/><br/>Twitter Handles: <a href='https://twitter.com/chrissanders88'>@ChrisSanders88</a> | <a href='https://twitter.com/techieStef'>@techieStef</a> | <a href='https://www.twitter.com/sechubb'>@SecHubb</a> | <a href='https://www.twitter.com/sansdefense'>@SANSDefense</a><br/><br/>All Blueprint Podcast Episodes: <a href='http://sans.org/blueprint-podcast'>sans.org/blueprint-podcast</a><br/><br/><br/></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/4239110-creativity-and-choices-talking-about-thinking.mp3" length="30749803" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/6upao64lllqul4k57zrxdt76mgle?.jpg" />
    <itunes:author>Chris Sanders and Stephanie Rand</itunes:author>
    <guid isPermaLink="false">Buzzsprout-4239110</guid>
    <pubDate>Tue, 23 Jun 2020 04:00:00 -0400</pubDate>
    <itunes:duration>2558</itunes:duration>
    <itunes:keywords>cyber defense, blue team, cyber security, divergent thinking, convergent thinking, chris sanders, stephanie rand,</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>3</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Shock to the System: Re-Evaluating Your Security Operations</itunes:title>
    <title>Shock to the System: Re-Evaluating Your Security Operations</title>
    <itunes:summary><![CDATA[In our very first guest interview with Mark Orlando, John asks Mark questions to help us re-evaluate our security operations.  Twitter Handles: @MarkAOrlando | @SecHubb  All Blueprint Podcast Episodes: sans.org/blueprint-podcast Contact, Courses, and More: For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live! Check out John's SOC Training Courses for SOC Analysts and Leaders: SEC450: SOC Analyst Training - Applied Skills for Cy...]]></itunes:summary>
    <description><![CDATA[<p>In our very first guest interview with Mark Orlando, John asks Mark questions to help us re-evaluate our security operations.<br/><br/>Twitter Handles: <a href='https://twitter.com/markaorlando'>@MarkAOrlando</a> | <a href='https://twitter.com/SecHubb'>@SecHubb</a><br/><br/>All Blueprint Podcast Episodes: <a href='http://sans.org/blueprint-podcast'>sans.org/blueprint-podcast</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>In our very first guest interview with Mark Orlando, John asks Mark questions to help us re-evaluate our security operations.<br/><br/>Twitter Handles: <a href='https://twitter.com/markaorlando'>@MarkAOrlando</a> | <a href='https://twitter.com/SecHubb'>@SecHubb</a><br/><br/>All Blueprint Podcast Episodes: <a href='http://sans.org/blueprint-podcast'>sans.org/blueprint-podcast</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/4169168-shock-to-the-system-re-evaluating-your-security-operations.mp3" length="23737333" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/cycf8gzvzidiw6s6h23xe349qvig?.jpg" />
    <itunes:author>Mark Orlando</itunes:author>
    <guid isPermaLink="false">Buzzsprout-4169168</guid>
    <pubDate>Tue, 16 Jun 2020 04:00:00 -0400</pubDate>
    <itunes:duration>1975</itunes:duration>
    <itunes:keywords>security operations, SOC</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>2</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The Art of Blue Teaming</itunes:title>
    <title>The Art of Blue Teaming</title>
    <itunes:summary><![CDATA[Hear host John Hubbard share info on his background, his inspiration and goals for this podcast and his insights on ‘The Art of Blue Teaming”.  Twitter Handles: @SecHubb | @SANSDefense  All Blueprint Podcast Episodes: sans.org/blueprint-podcast Contact, Courses, and More: For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live! Check out John's SOC Training Courses for SOC Analysts and Leaders: SEC450: SOC Analyst Training - Appli...]]></itunes:summary>
    <description><![CDATA[<p>Hear host John Hubbard share info on his background, his inspiration and goals for this podcast and his insights on ‘The Art of Blue Teaming”.<br/><br/>Twitter Handles: <a href='https://www.twitter.com/sechubb'>@SecHubb</a> | <a href='https://www.twitter.com/sansdefense'>@SANSDefense<br/><br/></a>All Blueprint Podcast Episodes: <a href='http://sans.org/blueprint-podcast'>sans.org/blueprint-podcast</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>Hear host John Hubbard share info on his background, his inspiration and goals for this podcast and his insights on ‘The Art of Blue Teaming”.<br/><br/>Twitter Handles: <a href='https://www.twitter.com/sechubb'>@SecHubb</a> | <a href='https://www.twitter.com/sansdefense'>@SANSDefense<br/><br/></a>All Blueprint Podcast Episodes: <a href='http://sans.org/blueprint-podcast'>sans.org/blueprint-podcast</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/4169066-the-art-of-blue-teaming.mp3" length="18102154" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/5qfomrm2cmax3rwhtaz6wzfcc7jo?.jpg" />
    <itunes:author>John Hubbard</itunes:author>
    <guid isPermaLink="false">Buzzsprout-4169066</guid>
    <pubDate>Tue, 16 Jun 2020 04:00:00 -0400</pubDate>
    <itunes:duration>1505</itunes:duration>
    <itunes:keywords>blue team operations, blue team security, blue team cyber security</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>1</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Introducing Blueprint</itunes:title>
    <title>Introducing Blueprint</title>
    <itunes:summary><![CDATA[Blueprint brings you the latest in cyber defense and security operations from top blue team leaders. Blueprint is brought to you by the SANS Institute and is hosted by SANS Certified Instructor John Hubbard.   Twitter Handles: @SecHubb | @SANSDefense  All Blueprint Podcast Episodes: sans.org/blueprint-podcast Contact, Courses, and More: For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live! Check out John's SOC Training Courses ...]]></itunes:summary>
    <description><![CDATA[<p>Blueprint brings you the latest in cyber defense and security operations from top blue team leaders. Blueprint is brought to you by the SANS Institute and is hosted by SANS Certified Instructor John Hubbard.<br/><br/><br/>Twitter Handles: <a href='https://www.twitter.com/sechubb'>@SecHubb</a> | <a href='https://www.twitter.com/sansdefense'>@SANSDefense<br/><br/></a>All Blueprint Podcast Episodes: <a href='http://sans.org/blueprint-podcast'>sans.org/blueprint-podcast</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></description>
    <content:encoded><![CDATA[<p>Blueprint brings you the latest in cyber defense and security operations from top blue team leaders. Blueprint is brought to you by the SANS Institute and is hosted by SANS Certified Instructor John Hubbard.<br/><br/><br/>Twitter Handles: <a href='https://www.twitter.com/sechubb'>@SecHubb</a> | <a href='https://www.twitter.com/sansdefense'>@SANSDefense<br/><br/></a>All Blueprint Podcast Episodes: <a href='http://sans.org/blueprint-podcast'>sans.org/blueprint-podcast</a></p><p><b>Contact, Courses, and More:</b></p><p>For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to <a href='https://blueprintpodcast.live/'>blueprintpodcast.live</a>!</p><p>Check out John&apos;s SOC Training Courses for SOC Analysts and Leaders:</p><ul><li><a href='https://sans.org/sec450'>SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations</a></li><li><a href='https://sans.org/ldr551'>LDR551: Building and Leader Security Operations Centers</a></li></ul><p>Follow and Connect with John:  <a href='https://www.linkedin.com/in/johnlhubbard/'>LinkedIn</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1142720/episodes/4056653-introducing-blueprint.mp3" length="1556487" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/r2svuf1krt4rcmsruk7g0ewmvba5?.jpg" />
    <itunes:author>John Hubbard</itunes:author>
    <guid isPermaLink="false">Buzzsprout-4056653</guid>
    <pubDate>Tue, 09 Jun 2020 05:00:00 -0400</pubDate>
    <podcast:soundbite startTime="4.05" duration="60.0" />
    <itunes:duration>123</itunes:duration>
    <itunes:keywords>cyber defense, blue team, security operations, security operations center, cyber security</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episodeType>trailer</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
</channel>
</rss>
