Sign in

Markus

@mascho.bsky.social
537 followers 115 following 47 posts

💻 Blue Team Training @ Blue Cape Security

PostsRepliesMedia
Markus @mascho.bsky.social · 05/08/2025
Dropped our Practical Windows Forensic Analyst cert! 🔥👀 bluecapesecurity.com/pwfa
bluecapesecurity.com
Analyst I: Core Forensic Track Enrollment - Blue Cape Security
Elevate your DFIR skills in our 3-part workshop series. Get hands-on with real-world scenarios from cybersecurity basics to advanced forensic analysis.
000
Markus @mascho.bsky.social · 21/07/2025
Is this still on?
010
Markus @mascho.bsky.social · 13/05/2025
Just dropped: Our hands-on Windows Forensics investigation scenarios are live! 🔍 -> 20% OFF with code START200 bluecapesecurity.com/practice/#FO... Enjoy!
bluecapesecurity.com
Practice - Blue Cape Security
Enrollment now open: FOR200 Investigation Scenarios Limited Time Offer: 20% OFF FOR200 and HERO BundleCode: START200 — Ends May 23 PRACTICE Hands-On, RealisticInvestigation Scenarios Apply your skills...
000
Markus @mascho.bsky.social · 19/03/2025
We just released a course that embodies our core principles: learn + practice + assess > and it’s free! DFIR Foundations and Techniques: Professional Skills and Readiness => For SecOps and DFIR professionals Full course: tinyurl.com/mu77u3ab Youtube playlist: tinyurl.com/2s3n7nfx #dfir #secops
001
Markus @mascho.bsky.social · 12/02/2025
Still reminiscing about the incredible time at @wildwesthackinfest.bsky.social last week and now counting down to IntelliCon next week in Austin! If you haven’t grabbed your ticket yet, there’s still time: www.intelliguards.com/event-detail...
051
Markus @mascho.bsky.social · 30/01/2025
Final modules for our 301 Enterprise DFIR course have been uploaded. What a journey after developing, analyzing and recording all the materials over many months of work! I'm excited about the course and also looking forward to head to the WWHF conference next week. Reach out if you are there!
000
Markus @mascho.bsky.social · 28/01/2025
Proud to present our brand new training page and offering for individuals @ Blue Cape Security: - 301 Enterprise DFIR course launched - HERO Bundle including 101 / 201 / 301 courses - Blue Team Master Program is public again bluecapesecurity.com/individual-t... HMU for questions or feedback! 💙
bluecapesecurity.com
Course and Programs | Individual Training - Blue Cape Security
Practical Cybersecurity Training Built for Real-World Investigations Hands-On, Scenario-Based Training to Master Cyber Threats and Elevate Your Career training roadmap on-demand courses Our courses in...
021
Markus @mascho.bsky.social · 23/01/2025
We have a giveaway of our brand new course bundle over at LinkedIn for those interested: www.linkedin.com/posts/blueca... Only 2 more days!
linkedin.com
Blue Cape Security on LinkedIn: #cybersecurity #bluecapesecurity #incidentresponse #dfirtraining… | 11 comments
🎉 Big Giveaway: Win our brand new HERO Bundle (101 / 201 / 301 courses)! Here’s how to enter: → Follow us here on LinkedIn (@BlueCapeSecurity) → Like this… | 11 comments on LinkedIn
000
Markus @mascho.bsky.social · 22/01/2025
Lots of great things coming next week! 301 Enterprise DFIR course - Launch Party with a special guest, new course bundles and more! Live Stream: youtube.com/live/MgG_pT1...
010
Markus @mascho.bsky.social · 16/01/2025
Since enabling Apple Intelligence an uncontrollable amount of notifications keep popping up (e.g. continuously when I'm screen sharing on Zoom). It doesn't seem they've gotten much smarter navigating me to my webinars either..
110
Reposted by Markus
Eric Capuano @eric.zip · 07/01/2025
🚀 Excited to announce the alpha release of NIMS - a Notion-based Incident Management System! Designed for SOC/IR teams, NIMS helps streamline incident management and collaboration using Notion's powerful database features. #InfoSec #DFIR #IncidentResponse #SecOps #Notion
Logo for Notion Incident Management System (NIMS)
47321
Markus @mascho.bsky.social · 03/01/2025
How do you track DFIR timelines and findings? There doesn't seem to be a one size fits all solution in the industry. Most commonly used are still spreadsheets, where Crowdstrike actually released a pretty nice IR Tracker template a while ago: www.crowdstrike.com/en-us/blog/c...
crowdstrike.com
CrowdStrike Services Releases Free Incident Response Tracker
This blog post provides an overview of the newly released CrowdStrike Incident Response Tracker and how it is leveraged by our experts on the front lines.
365
Markus @mascho.bsky.social · 31/12/2024
The best conference in the industry is only 1 month away 🤠 I'll be teaching the 2-day Ransomware Attack Simulation and Investigation for Blue Teamers workshop with in-person and virtual seats available! I’m looking forward to reconnecting with old friends and making new ones at this amazing event!
bluecapesecurity.com
031
Markus @mascho.bsky.social · 28/12/2024
For those looking to practice a realistic #DFIR scenario, here is a free case for you to investigate. Provided artifacts: - Disk Triage Collection - Memory Image + pagefile.sys: - PCAP File Link: bluecapesecurity.com/courses/elev...
bluecapesecurity.com
Elevate Your DFIR Skills: Deeper Insights and Practical Applications - Blue Cape Security
194
Markus @mascho.bsky.social · 27/12/2024
AWS: Welcome back! Your t2.xlarge EC2's have been running happily over the holidays 🥲
000
Markus @mascho.bsky.social · 22/12/2024
Practical Windows Forensics - Cheat sheet 💙 Full PDF version: github.com/bluecapesecu...
083
Markus @mascho.bsky.social · 18/12/2024
Looking forward to present our maturity model tomorrow live! Finally visualized the way how we do trainings for teams and individuals. Link: bluecapesecurity.com/register
010
Markus @mascho.bsky.social · 16/12/2024
Microsoft incident data sets. Haven’t had a chance to test this, but certainly looks interesting. www.kaggle.com/datasets/Mic...
kaggle.com
Microsoft Security Incident Prediction
Can you predict the next big security incident before it happens?
031
Markus @mascho.bsky.social · 13/12/2024
Oh hey we have a webinar coming up next week! -> Thursday, December 19th I'll be sharing our DFIR Training Roadmap that we've been working on since the beginnings of Blue Cape Security (which is more than 2 years now) 🥹 us06web.zoom.us/webinar/regi...
us06web.zoom.us
Welcome! You are invited to join a webinar: Blue Cape Security DFIR Training Roadmap for Cybersecurity Professionals. After registering, you will receive a confirmation email about joining the webinar...
Join Markus Schober, CEO of Blue Cape Security, for a 45-minute Live webinar on December 19th at 1:00 PM ET / 10:00 AM PT. This session will introduce the Blue Cape Security DFIR Training Roadmap—a pr...
021
Markus @mascho.bsky.social · 13/12/2024
Was just planning on releasing a new DFIR course module on log analysis, but I just uploaded: 2+ hours video 11 Splunk hands-on labs (with over 30 queries) 2 Sigma hands-on labs Why do these things always get out of hand?
030
Markus @mascho.bsky.social · 10/12/2024
Currently working on a course module using Sigma detection rules. A few resources I came across and didn't know about previously were: - Sigma rule search engine: sigmasearchengine.com - Sigma VSC plugin: marketplace.visualstudio.com/items?itemNa... Making Sigma rule creation much more fun :)
sigmasearchengine.com
Sigma Search Engine
141
Markus @mascho.bsky.social · 09/12/2024
Any one have any recommendations for video cutting tools? Just for effective cutting of recorded videos for courses. Wondershare Filmora is pretty good, but always curious about what else is out there.
000
Markus @mascho.bsky.social · 06/12/2024
Revolutionizing Security Operations: The Path Toward AI-Augmented SOCs open.substack.com/pub/software... Highly recommend this post to get a grasp on how AI is transforming security operations.
open.substack.com
Revolutionizing Security Operations: The Path Toward AI-Augmented SOCs
Exploring the processes, challenges, solutions, and path toward a future of AI-Augmented Security Operations Centers (SOC)
010
Markus @mascho.bsky.social · 05/12/2024
A curated list of Windows execution artifacts - this is just awesome work by @harrisonamj.com! blog.1234n6.com/available-ar...
blog.1234n6.com
Available Artifacts - Evidence of Execution
UPDATED 2024-12-04 UPDATED 2019-01-04 This week I have been working a case where I was required to identify users on a Windows Server 2003 system who had knowledge of, or had run, a particular unau...
161
Markus @mascho.bsky.social · 04/12/2024
I couldn't agree more! ...personnel are responsible for maximizing the use of technology, streamlining processes, and honing their skills to identify and address current and emerging threats. My take on how people can do more with less: www.linkedin.com/posts/markus...
000
Markus @mascho.bsky.social · 03/12/2024
For course creators there's nothing worse than having to ensure students are downloading entire VMs, installing applications on various OSs, getting licenses etc, only to tell them about updates and changes further down the road. Especially, with on-demand trainings.
110
Markus @mascho.bsky.social · 02/12/2024
About to drop PCAP and Zeek log analysis modules for the new 301 DFIR course @ Blue Cape Security! Let the Ransomware scenario investigation begin 🔍
131
Markus @mascho.bsky.social · 26/11/2024
Excited to share that our 301 Enterprise DFIR course is now open for enrollment! Join now to get drip-content releases weekly: bluecapesecurity.com/courses/301-... And we started our Black Friday sale! Code *BLACKFRIDAY24* gets you 25% OFF on all courses and bundles: bluecapesecurity.com/courses/
bluecapesecurity.com
301: Enterprise DFIR - Blue Cape Security
040
Reposted by Markus
Eric Capuano @eric.zip · 17/11/2024
Starter Pack containing #infosec trainers — if I missed any, lmk! go.bsky.app/V5iocw6
399831
Markus @mascho.bsky.social · 24/11/2024
I've been playing around with various cloud-based solutions to set up labs and forensic workstations for our DFIR workshops. Specifically, we want to use a Windows 2022 host and Ubuntu WSL (based on this guide, which is based on VirtualBox bluecapesecurity.com/build-your-f...). 🧵
bluecapesecurity.com
Build Your Forensic Workstation - Blue Cape Security
Build Your Forensic Workstation​ This tutoral describes how to set up a highly-functioning forensic workstation to conduct DFIR investigations. Are you looking to learn how to perform a digital forens...
3102
Markus @mascho.bsky.social · 15/11/2024
Making my first post here and already trying to be useful. 💡 I just came across this nugget while preparing for our DFIR class next week. There is a cheat sheet for Splunk SPL out there: www.splunk.com/en_us/blog/l... (pdf at the bottom)
splunk.com
Splunk Cheat Sheet: Query, SPL, RegEx, & Commands | Splunk
In this blog post we'll cover the basics Queries, Commands, RegEx, SPL, and more for using Splunk Cloud and Splunk Enterprise
151