Scenario 3: The Configuration Change No One Admitted To | CyberLex Blue Team Academy

Scenario 3: The Configuration Change No One Admitted To | CyberLex Blue Team Academy

EPISODE 3 — “The Configuration Change No One Admitted To”

A single configuration change.

No ticket.

No approval.

No explanation.

This is where attackers start quiet… and defenders learn to listen.

In Episode 3 of CyberLex Blue Team Academy, we investigate a subtle modification that turns into a full lesson in early reconnaissance, privilege misuse, and the psychology of stealth attacks. What looks harmless becomes a deep dive into system integrity, audit trails, and how real defenders uncover the truth behind “innocent” settings.

What you’ll learn in this episode:

  • How attackers alter configurations to reduce visibility

  • How to detect unauthorized changes using logs & baselines

  • Why timestamp drift exposes hidden activity

  • How to correlate login anomalies with configuration edits

  • The difference between “system changes” and attacker obfuscation

  • How endpoint behavior reveals lateral movement

  • Why visibility reduction is often the first phase of a breach

What we cover:

  • Unauthorized config drift

  • Event correlation and timeline reconstruction

  • Beaconing patterns in outbound DNS traffic

  • Admin session anomalies

  • How attackers test visibility gaps before escalating

  • Real-world stealth TTPs

  • Defender response strategy

Perfect for:

  • Security+ learners building real system awareness

  • CC beginners wanting to understand log integrity

  • CySA+ students mastering anomaly detection

  • CCSP learners exploring cloud and system changes

  • SOC analysts, sysadmins, IT professionals

  • Anyone learning to catch subtle attacker movements

One setting changed everything.

And noticing it changed the outcome.

Listen to Episode 3 now — The Configuration Change No One Admitted To.

Your awareness sharpens here.

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(22)

Episode 10 — The Scheduled Task That Recreated Itself | Security Operations: Persistence & Automated Rebuild Loops

Episode 10 — The Scheduled Task That Recreated Itself | Security Operations: Persistence & Automated Rebuild Loops

EPISODE 10 — THE SCHEDULED TASK THAT RECREATED ITSELF Security+ Domain 4 concepts • CySA+ threat analytics • SOC persistence detectionPersistence is the attacker’s greatest weapon. And one of the stea...

2 Jan 3min

Episode 9 — The DNS Query That Didn’t Match Any Pattern | Security Operations: DNS Analysis & C2 Detection

Episode 9 — The DNS Query That Didn’t Match Any Pattern | Security Operations: DNS Analysis & C2 Detection

EPISODE 9 — THE DNS QUERY THAT DIDN’T MATCH ANY PATTERN Security+ Domain 4 concepts • CySA+ network analytics • SOC DNS anomaly detectionDNS is one of the most misunderstood — and most exploited — pro...

26 Dec 20253min

Episode 8 — The Process That Hid in Memory | Security Operations: EDR Detection & Fileless Attacks

Episode 8 — The Process That Hid in Memory | Security Operations: EDR Detection & Fileless Attacks

EPISODE 8 — THE PROCESS THAT HID IN MEMORY Security+ Domain 4 concepts • CySA+ behavioral analytics • SOC fileless attack detectionModern attackers don’t always drop files. Sometimes the entire attack...

19 Dec 20253min

Episode 7 — The Cloud Bucket Created at 3:14 A.M. | Security Operations: Cloud Monitoring & Rogue Resource Detection

Episode 7 — The Cloud Bucket Created at 3:14 A.M. | Security Operations: Cloud Monitoring & Rogue Resource Detection

CyberLex Blue Team Academy — Where Defenders Are Forged.EPISODE 7 — THE CLOUD BUCKET CREATED AT 3:14 A.M. Security+ Domain 4 concepts • CySA+ cloud analytics • SOC cloud misconfiguration detectionClou...

14 Dec 20253min

Episode 6 — The Email That Passed Every Check | Security Operations: Email Threat Detection & Identity Attacks

Episode 6 — The Email That Passed Every Check | Security Operations: Email Threat Detection & Identity Attacks

CyberLex Blue Team Academy — Where Defenders Are Forged.EPISODE 6 — THE EMAIL THAT PASSED EVERY CHECK Security+ Domain 4 concepts • CySA+ email threat analytics • SOC identity attack detectionSome of ...

13 Dec 20253min

Episode 5 — The Firewall Rule That Quietly Opened | Security Operations: Enterprise Controls & Outbound Anomalies

Episode 5 — The Firewall Rule That Quietly Opened | Security Operations: Enterprise Controls & Outbound Anomalies

CyberLex Blue Team Academy — Where Defenders Are Forged.EPISODE 5 — THE FIREWALL RULE THAT QUIETLY OPENED Security+ Domain 4 concepts • CySA+ network analytics • SOC enterprise control monitoringSome ...

12 Dec 20253min

Episode 4 — The Login That Didn’t Belong to the User | Security Operations: IAM Anomalies & Behavioral Detection

Episode 4 — The Login That Didn’t Belong to the User | Security Operations: IAM Anomalies & Behavioral Detection

CyberLex Blue Team Academy — Where Defenders Are Forged.EPISODE 4 — THE LOGIN THAT DIDN’T BELONG TO THE USER Security+ Domain 4 concepts • CySA+ authentication analytics • SOC identity anomaly detecti...

11 Dec 20253min

Episode 3 — The Vulnerability That Came Back | Security Operations: Vulnerability Lifecycle & Configuration Drift

Episode 3 — The Vulnerability That Came Back | Security Operations: Vulnerability Lifecycle & Configuration Drift

CyberLex Blue Team Academy — Where Defenders Are Forged.EPISODE 3 — THE VULNERABILITY THAT CAME BACK Security+ Domain 4 concepts • CySA+ vulnerability analytics • SOC lifecycle investigationIn Securit...

10 Dec 20253min

Populärt inom Teknik

natets-morka-sida
uppgang-och-fall
elbilsveckan
bilar-med-sladd
market-makers
rss-laddstationen-med-elbilen-i-sverige
skogsforum-podcast
rss-en-ai-till-kaffet
rss-elektrikerpodden
rss-technokratin
rss-ai-med-jonas-benjamin
rss-uppgang-och-fall
rss-sakerhetspodcasten
rss-veckans-ai
rss-snacka-om-ai
bli-saker-podden
developers-mer-an-bara-kod
rss-powerboat-sverige-podcast
rss-it-sakerhetspodden
rss-fabriken-2