<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>BlueTeam on Purpleshift</title><link>https://purpleshift.io/tags/blueteam/</link><description>Recent content in BlueTeam on Purpleshift</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026</copyright><lastBuildDate>Mon, 06 Apr 2026 07:12:39 +0000</lastBuildDate><atom:link href="https://purpleshift.io/tags/blueteam/index.xml" rel="self" type="application/rss+xml"/><item><title>Invisible attacks with bind mount</title><link>https://purpleshift.io/purple/2026-04-06-oqqa/</link><pubDate>Mon, 06 Apr 2026 07:12:39 +0000</pubDate><guid>https://purpleshift.io/purple/2026-04-06-oqqa/</guid><description>A technique much simpler than rootkit can make a malicious process invisible</description></item><item><title>Incidents 2025: MDR and IR Report</title><link>https://purpleshift.io/purple/2026-03-31-fusf/</link><pubDate>Tue, 31 Mar 2026 10:51:13 +0000</pubDate><guid>https://purpleshift.io/purple/2026-03-31-fusf/</guid><description>Combining MDR and IR statistics provides a better understanding of current and emerging threats</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/purple/2026-03-31-fusf/MDR-report-2026-cover.png"/></item><item><title>Attribution by Slang: Exposing Horabot</title><link>https://purpleshift.io/purple/2026-03-18-nffa/</link><pubDate>Wed, 18 Mar 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/purple/2026-03-18-nffa/</guid><description>How our MDR team investigated a Brazilian hacker attack on Mexico</description></item><item><title>Incidents 2020-2025: Industry Statistics</title><link>https://purpleshift.io/purple/2026-03-02-etxv/</link><pubDate>Tue, 03 Mar 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/purple/2026-03-02-etxv/</guid><description>What types of attacks are leading in different sectors in different years?</description></item><item><title>History of Critical Incidents</title><link>https://purpleshift.io/articles/2026-03-02-critical-incidents/</link><pubDate>Mon, 02 Mar 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/articles/2026-03-02-critical-incidents/</guid><description>How critical incidents of different types were distributed across industries in 2020-2025</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/articles/2026-03-02-critical-incidents/featured_fishing.png"/></item><item><title>Hidden Tunnel: Proxying through WebSocket Secure</title><link>https://purpleshift.io/purple/2026-02-24-qjtc/</link><pubDate>Tue, 24 Feb 2026 05:35:02 +0000</pubDate><guid>https://purpleshift.io/purple/2026-02-24-qjtc/</guid><description>Another story of non-standard remote access</description></item><item><title>Attack with Four Remote Access Channels</title><link>https://purpleshift.io/purple/2026-02-19-tvxz/</link><pubDate>Thu, 19 Feb 2026 04:30:32 +0000</pubDate><guid>https://purpleshift.io/purple/2026-02-19-tvxz/</guid><description>Attackers used Velociraptor, VS Code Tunnel, Cloudflare Tunnel, and Zoho Assist</description></item><item><title>How to detect Notepad++ attack</title><link>https://purpleshift.io/purple/2026-02-05-kmwb/</link><pubDate>Thu, 05 Feb 2026 06:56:04 +0000</pubDate><guid>https://purpleshift.io/purple/2026-02-05-kmwb/</guid><description>Attackers were distributing malware from Notepad++ update center</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/purple/2026-02-05-kmwb/featured_Notepad_hack.png"/></item><item><title>Bypassing authentication in Fortinet products via SSO</title><link>https://purpleshift.io/purple/2026-02-04-gjgx/</link><pubDate>Wed, 04 Feb 2026 08:21:47 +0000</pubDate><guid>https://purpleshift.io/purple/2026-02-04-gjgx/</guid><description>An attacker with a FortiCloud account can log in to other users&amp;rsquo; FortiOS</description></item><item><title>Cognitive Biases in SOC Analysts' Work</title><link>https://purpleshift.io/purple/2026-01-19-akaq/</link><pubDate>Mon, 19 Jan 2026 10:52:55 +0000</pubDate><guid>https://purpleshift.io/purple/2026-01-19-akaq/</guid><description>Anchoring effect, reasoning by analogy, and other logical errors</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/purple/2026-01-19-akaq/featured_Suspicious_Service.png"/></item><item><title>Human factor in cyber defense: when the enemy is our own mindset</title><link>https://purpleshift.io/articles/2026-01-16-mindset/</link><pubDate>Fri, 16 Jan 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/articles/2026-01-16-mindset/</guid><description>The most common biases that occur in SOC and how to avoid them</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/articles/2026-01-16-mindset/featured_Confirmation_Bias.png"/></item><item><title>Disabling Windows Defender via symlink</title><link>https://purpleshift.io/purple/2026-01-12-bmka/</link><pubDate>Mon, 12 Jan 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/purple/2026-01-12-bmka/</guid><description>Built-in antivirus could be switched off without any third-party software</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/purple/2026-01-12-bmka/featured_Defender.png"/></item><item><title>Top-10 posts of PurpleShift in 2025</title><link>https://purpleshift.io/purple/2025-12-26-ikap/</link><pubDate>Fri, 26 Dec 2025 09:47:52 +0000</pubDate><guid>https://purpleshift.io/purple/2025-12-26-ikap/</guid><description>We selected posts that got the most likes</description></item><item><title>Attacking Security Researchers via Visual Studio</title><link>https://purpleshift.io/articles/2025-05-01-attacking-security-researchers-via-visual-studio/</link><pubDate>Fri, 05 Jul 2024 00:00:00 +0000</pubDate><guid>https://purpleshift.io/articles/2025-05-01-attacking-security-researchers-via-visual-studio/</guid><description>A new technique to exploit VS IDE using SUO files</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/articles/2025-05-01-attacking-security-researchers-via-visual-studio/featured-payload.png"/></item></channel></rss>