Blue Team Academy

Fabio Sobiecki

Um podcast para você quer proteger empresas e pessoas de ataques hackers

  1. 23 Aug

    WannaCry Explained: How One Worm Took Down the NHS in a Day

    One piece of malware. No phishing. No user clicking anything. And on May 12, 2017, WannaCry took the UK's National Health Service offline in a single afternoon — 19,000 appointments cancelled, MRI scanners locked out, ambulances diverted.In this Breach File we walk through exactly what happened: the 59-day gap between the Microsoft patch and detonation, how the Shadow Brokers' leak of EternalBlue armed Lazarus Group to build a self-propagating cryptoworm, and how the kernel memory corruption in SMBv1 actually worked — no jargon, no glossing.Then we run it through the Threat and Control Method: Inventory, Threats, Controls, Scale — the same four-step loop we teach at Blue Team Academy for turning IT experience into blue team judgment.If you already work in IT — sysadmin, network engineer, help desk, cloud, ops — WannaCry is the clearest existing worked example of how the environments you already run get turned into weapons, and how ordinary IT hygiene applied with a defender's intent would have stopped almost all of it.━━━━━━━━━━━━━━━━━━━━━━━━━━CHAPTERS━━━━━━━━━━━━━━━━━━━━━━━━━━00:00 The Attack That Needed No Clicks00:24 Why WannaCry Still Matters01:18 Timeline of an Epidemic03:33 Lazarus Group and the Nation-State Threat05:21 How EternalBlue Actually Worked09:10 The $4 Billion Human Cost10:24 The Defense — Inventory, Threats, Controls, Scale15:11 Why This Isn't History16:03 Cybersecurity Is Not Rocket Science━━━━━━━━━━━━━━━━━━━━━━━━━━READ THE FULL BREACH FILE━━━━━━━━━━━━━━━━━━━━━━━━━━Full written breakdown with sources and code samples:https://blueteam-academy.com/breaches/wannacry-ransomware-attack-eternalblue-cryptoworm/━━━━━━━━━━━━━━━━━━━━━━━━━━BLUE TEAM ACADEMY━━━━━━━━━━━━━━━━━━━━━━━━━━We help experienced IT professionals move into defensive cybersecurity — without starting over. We teach the Threat and Control Method: a repeatable four-step decision process (Inventory → Threats → Controls → Scale) applied to real incidents like this one.Learn more: https://www2.blueteam-academy.com/from-it-to-cybersecurity/Keep IT Safe newsletter: https://www2.blueteam-academy.com/keep-it-safe-signupBlog: https://blueteam-academy.com/blogInstagram: @blueteamacad━━━━━━━━━━━━━━━━━━━━━━━━━━SOURCES━━━━━━━━━━━━━━━━━━━━━━━━━━- Microsoft Security Bulletin MS17-010 (March 14, 2017)- CISA/US-CERT Alert TA17-132A — WannaCry indicators- U.S. Department of Justice indictment of Park Jin Hyok (September 6, 2018)- UK National Audit Office — "Investigation: WannaCry cyber attack and the NHS" (October 2017)- Europol statement, May 2017 — 200,000 systems / 150 countries- MITRE ATT&CK — EternalBlue / T1210━━━━━━━━━━━━━━━━━━━━━━━━━━#Cybersecurity #BlueTeam #WannaCry #Ransomware #EternalBlue

  2. 21 Aug

    Break Into Cybersecurity Without Quitting Your IT Job

    You want to move into cybersecurity, but can't afford to quit your IT job. Here's the 5-step path most career advice never tells you about.The standard advice — quit, bootcamp, grind, take a $40k entry-level role — is wrong for anyone with real financial obligations. There's a better path. It runs THROUGH your current IT job, not around it.In this video, we walk through the exact 5-step transition that IT professionals use to move into defensive cybersecurity while keeping their paycheck, protecting their family, and building real security experience along the way.━━━━━━━━━━━━━━━━━━━━━━━━━━━📩 GET THE PATH IN YOUR INBOXEvery week, our Keep IT Safe newsletter breaks down real breaches, defensive techniques, and career moves for IT pros making the jump to cybersecurity.→ https://www2.blueteam-academy.com/keep-it-safe-signup🎯 MAKE THE TRANSITION DELIBERATEThe Blue Team Academy program walks you through the Threat & Control Method end to end — templates, walkthroughs, and the decision criteria we couldn't fit into 13 minutes.→ https://www2.blueteam-academy.com/from-it-to-cybersecurity/📖 READ THE FULL ARTICLE→ https://blueteam-academy.com/blog/transition-to-cybersecurity-without-quitting-your-job/━━━━━━━━━━━━━━━━━━━━━━━━━━━⏱ CHAPTERS00:00 — The sentence that stops most transitions00:40 — The real numbers (BLS, ISC2, CyberSeek)02:05 — Step 1: Turn your IT role into unpaid security experience04:35 — Step 2: The Threat & Control Method07:15 — Step 3: A sustainable study routine09:15 — Step 4: Aim for the internal lateral move first11:15 — Step 5: Show your work in public12:35 — The bottom line━━━━━━━━━━━━━━━━━━━━━━━━━━━📚 SOURCES- U.S. Bureau of Labor Statistics — Occupational Outlook Handbook, Information Security Analysts https://www.bls.gov/ooh/computer-and-information-technology/information-security-analysts.htm- ISC2 Cybersecurity Workforce Study 2024 https://www.isc2.org/research- CyberSeek — Cybersecurity Career Pathway https://www.cyberseek.org/━━━━━━━━━━━━━━━━━━━━━━━━━━━🔗 RELATED- The Threat & Control Method explained https://blueteam-academy.com/blog/threat-and-control-method/- The full blue team career path for IT professionals https://blueteam-academy.com/blog/cybersecurity-career-path/━━━━━━━━━━━━━━━━━━━━━━━━━━━About Blue Team AcademyBlue Team Academy trains experienced IT professionals to move into defensive cybersecurity — without starting over. We teach the Threat & Control Method: a repeatable framework for turning IT experience into blue team decision-making.#Cybersecurity #ITCareer #BlueTeam

  3. 16 Aug

    Everyone Explains the Dark Web. Nobody Teaches You to Monitor It.

    Search "dark web" and you get the same spooky iceberg explainer a thousand times over. Useless if you already run infrastructure. This is the one nobody makes: how a blue team actually does dark web monitoring — how you watch for your company's leaked credentials, catch Tor traffic leaving your own network, and turn a scary alert into a defensible plan.Built for the IT pro moving into defense: sysadmins, network engineers, help desk, cloud, and infrastructure folks. Most of what makes dark web monitoring work isn't hacker magic — it's the network and endpoint fundamentals you already touch every day, pointed in a new direction.⏱️ CHAPTERS0:00 Your login might already be for sale0:50 Who this is for1:30 Surface, deep, and dark web — the version a defender needs3:20 Why you can't just Google your leaked data5:20 The 4 signals real monitoring watches for7:50 Detecting the dark web on your OWN network10:20 DIY vs. professional monitoring — the honest answer11:50 Turn the alert into a plan: Inventory → Threats → Controls → Scale14:10 You're not starting from zero📩 KEEP IT SAFE — our free weekly newsletterOne practical, no-hype breakdown like this for IT pros moving into defense, every week:https://www2.blueteam-academy.com/keep-it-safe-signup🎓 TRAIN WITH BLUE TEAM ACADEMYLearn the full Threat & Control Method — the decision process a working defender uses, taught for people coming from IT:https://www2.blueteam-academy.com/from-it-to-cybersecurity/📖 READ THE FULL BREAKDOWNhttps://blueteam-academy.com/blog/dark-web-monitoring-blue-team/🔗 SOURCES & REFERENCES- MITRE ATT&CK — Valid Accounts (T1078): https://attack.mitre.org/techniques/T1078/- MITRE ATT&CK — Multi-Factor Authentication (M1032): https://attack.mitre.org/mitigations/M1032/- MITRE ATT&CK — Account Use Policies (M1036): https://attack.mitre.org/mitigations/M1036/- NIST SP 800-53 Rev. 5 — IA-2, AC-17- Deep/dark web size estimates: Trend Micro (2026)Subscribe / follow Blue Team Academy for a new breakdown each week. That's the whole ask.#DarkWebMonitoring #BlueTeam #CyberSecurity

  4. 13 Aug

    Help Desk to SOC Analyst: You're Missing 1 Pillar, Not 3

    You're not starting from zero. If you work help desk, sysadmin, or IT support, you already run the exact same loop a SOC analyst runs — monitor, triage, investigate, document, escalate. This video breaks down the one real skill gap, what the alert queue actually looks like day to day, and a four-step plan to close the gap without wasting a year on the wrong certifications.📖 Full written breakdown, sources, and the Threat & Control Method: https://blueteam-academy.com/blog/help-desk-to-soc-analyst/📩 Get this kind of breakdown every week — the Keep IT Safe newsletter: https://www2.blueteam-academy.com/keep-it-safe-signup🎓 Ready to build the whole decision process, not just the SOC piece? https://www2.blueteam-academy.com/from-it-to-cybersecurity/TIMESTAMPS 00:00 They called the help desk, not the firewall 01:35 The claim: you're missing 1 pillar, not 3 02:32 Help desk vs SOC — the job posting comparison 03:39 Why the queue is drowning (2,000-4,500 alerts/day) 05:05 What a real alert looks like (+ the Target lesson) 06:44 The three pillars — and the one you're missing 08:02 The Threat & Control Method, applied to your career 09:56 The tools trap (and what to study instead) 11:32 The honest US salary and market numbers 14:15 You're not starting from zeroSOURCES CITED U.S. Bureau of Labor Statistics, Occupational Outlook Handbook (2024-34 projections) · ISC2 2025 Cybersecurity Workforce Study · FBI public advisory on help-desk social engineering (2025) · Tines Voice of the SOC research#BlueTeam #SOCAnalyst #Cybersecurity #ITCareer #CareerChange

  5. 9 Aug

    Zero Trust Explained for IT Pros (No Vendor Hype)

    Zero Trust for IT professionals — what it actually is, minus the vendor hype. NIST SP 800-207 in plain language, the six myths worth clearing up, and why your AD, MFA, and endpoint work already counts as a head start.Zero Trust is simultaneously the most oversold phrase in cybersecurity and one of the most useful ideas in it. If you already run infrastructure — sysadmin, network, cloud, ops — this breaks down the architecture using the systems you administer every day, then shows you where to actually start.No product pitch. No fear-mongering. Just the reasoning a blue team defender uses, explained simply.━━━━━━━━━━━━━━━━━━━━CHAPTERS━━━━━━━━━━━━━━━━━━━━0:00 The most oversold phrase in cybersecurity0:35 The moat dried up: why the perimeter stopped mattering1:45 What Zero Trust actually is (never trust, always verify)3:00 Where the term came from: Kindervag & Forrester, 20104:00 The architecture in plain English: NIST SP 800-2075:45 What Zero Trust is NOT: 6 myths7:15 A tale of two networks: the same attack, two outcomes9:15 Why IT pros are already halfway there10:15 How to actually start: Inventory → Threats → Controls → Scale11:15 The real shift (and where to go next)━━━━━━━━━━━━━━━━━━━━READ THE FULL BREAKDOWN━━━━━━━━━━━━━━━━━━━━Every source linked, written for reference:https://blueteam-academy.com/blog/zero-trust-it-professionals/━━━━━━━━━━━━━━━━━━━━GO DEEPER━━━━━━━━━━━━━━━━━━━━The decision process behind this video — Inventory → Threats → Controls → Scale — is what we teach. Learn to reason through any environment, not memorize tools:https://www2.blueteam-academy.com/from-it-to-cybersecurity/Get Keep IT Safe — practical defensive security breakdowns for IT professionals, in your inbox:https://www2.blueteam-academy.com/keep-it-safe-signup━━━━━━━━━━━━━━━━━━━━SOURCES━━━━━━━━━━━━━━━━━━━━- NIST SP 800-207, Zero Trust Architecture (2020): https://csrc.nist.gov/pubs/sp/800/207/final- NIST SP 1800-35, Implementing a Zero Trust Architecture (2025): https://csrc.nist.gov/pubs/sp/1800/35/final- CISA Zero Trust Maturity Model 2.0: https://www.cisa.gov/zero-trust-maturity-model- Forrester — "No More Chewy Centers," John Kindervag (2010)━━━━━━━━━━━━━━━━━━━━CONNECT━━━━━━━━━━━━━━━━━━━━LinkedIn: https://www.linkedin.com/showcase/blue-team-academyInstagram: https://www.instagram.com/blueteamacadX: https://x.com/BlueTeamAcadCybersecurity is not rocket science.#ZeroTrust #CyberSecurity #BlueTeam

  6. 6 Aug

    Cybersecurity Career Path for IT Pros (2026): Roles, Salaries & What Gets You Hired

    The cybersecurity career path, mapped for people already in IT: the roles, salaries, certs, and the one skill that actually gets you hired.If you already work in IT — help desk, sysadmin, networking, cloud, ops — you're not starting from zero. This is the full cybersecurity career path for IT professionals: which entry-level security roles fit your background, how to pick between blue team, offensive, and GRC, what the work really pays in 2026 (with real BLS and CyberSeek data), the certifications that matter and the order to stack them, and the way of thinking that separates people who *have* certs from people who get hired.No bootcamp hype. No guaranteed-job promises. Just the map.Because cybersecurity is not rocket science — and if you already work in IT, you're closer to it than anyone's told you.⏱️ CHAPTERS00:00 Why the cybersecurity career path feels impossible00:36 3 things every IT pro needs to hear first02:03 Where your path starts: entry-level security roles04:36 Blue team vs offensive vs GRC — pick a lane06:39 Cybersecurity salaries in 2026 (real BLS data)08:26 Certifications, stacked in the right order10:16 Why passing the exam isn't the job11:58 How a defender actually thinks15:13 Your 12–24 month roadmap17:40 The one skill that gets you hired📘 READ THE FULL GUIDEThe complete written breakdown, with every source linked:https://blueteam-academy.com/blog/cybersecurity-career-path/🎯 READY TO WALK THE PATH?Blue Team Academy is training built around the Threat & Control Method — you learn to think, decide, and act like a defender, not memorize tools you'll forget:https://www2.blueteam-academy.com/from-it-to-cybersecurity/📩 NOT READY YET? START WITH THE NEWSLETTERKeep IT Safe breaks down the IT-to-cyber transition one practical idea at a time — no hype, no spam:https://www2.blueteam-academy.com/keep-it-safe-signup🔍 SOURCES- U.S. Bureau of Labor Statistics — Information Security Analysts (median wage $124,910, May 2024; 29% projected growth 2024–2034)- CyberSeek — cybersecurity role taxonomy & certification demand- NICE Framework (CISA/NICCS)#Cybersecurity #CybersecurityCareer #BlueTeam

About

Um podcast para você quer proteger empresas e pessoas de ataques hackers