Specializing in pen testing, red teaming, and Active SOC. We share our knowledge through blogs, webcasts, open-source tools, and Backdoors & Breaches game.

BHIS | #InfoSec Webcast - Available Now! Your 5 Year Plan into InfoSec w/ @strandjs Recorded: 8/9/2017 Watch: blackhillsinfosec.com/webcas…
14
51
315
**NEW** BHIS | Blog Want to learn how digital forensics differs from incident response, and how to collect, preserve, and document evidence so it holds up in court if an incident ever gets there? Forensic Data: How To Acquire and Retain Vital Evidence By: Ronald A Mays Jr Published: 9/23/2026 blackhillsinfosec.com/forens… /
3
12
1,495
A fake verification page loads. 41 seconds later your user pastes a command into the Run dialog and runs it. Four chains, five months, one provider none of them gave up. Pull your egress for AS202412. Then read this. activesoc.blackhillsinfosec.…
1
3
19
2,096
This week's lineup: news, Azure, and incident response. See you there 🫵😉 events.zoom.us/eo/AqZceUFfoY…
1
8
1,541
Embrace the suck. It's the fastest way through it.
5
29
2,100
CISA just cut 6 free cybersecurity assessment programs for critical infrastructure, the same orgs that can't afford commercial alternatives. John Strand says the timing couldn't be worse. nationalcybersecurity.com/ci…
1
8
34
2,689
**NEW** BHIS | Blog Want to learn how adversaries leave tracks the moment they touch a system — and how to find them before they dig in? Threat Hunting on the Endpoint: Hunting Adversaries Where They Live By: Faan Rossouw Published: 9/16/2026 Learn more: blackhillsinfosec.com/threat…
7
37
3,807
Hunting CVE-2026-85706 in GitLab logs? A 400 saying "branch is required" is not a failed attempt. It means the file was read. We proved it by planting files with known contents and watching the error change. activesoc.blackhillsinfosec.…
1
6
16
3,111
AI agents hijacked a wiki. Humans blew up substations. Our own Ashley Knowles weighs in on what should actually worry us more right now. machine.news/system-shocks-r…
1
2
7
1,544
Side Quest: ENJOY YOUR WEEKEND!
1
10
1,679
Hacking back is now (partially..) legal for U.S. companies. Our founder John Strand breaks down what Trump's new memo actually allows and the big questions still unresolved. cybrsecmedia.com/trumps-hack…
2
7
1,522
Big shoutout to Hayden Covington! He's taking the stage at redacteCON on September 19th at Colorado Mesa University to talk about Building Custom AI Agents for real security ops: triage support, detection engineering, enrichment workflows, reporting, and more. If you're in Western Colorado or Eastern Utah, this is the region's only cybersecurity con and it's stacked with great sessions. Come catch Hayden live and say hi!
1
2
1,238
Attackers burned two rounds of domains on email bomb + fake Teams help desk lures, then stopped registering domains at all. Free M365 trial tenants: no WHOIS, no reputation, unlimited supply. Time from first Teams message to ClickFix execution: 2m32s. Lance McNeese on 8 weeks of tracking this campaign, with IOCs and hardening steps: activesoc.blackhillsinfosec.…
2
18
109
37,179
**NEW** BHIS | Blog Want to Learn How SOAR Can Cut Your SOC's Alert Volume by optimizing workflows, centralizing your security alert management, and minimizing threat response time? Soar 101: Security, Orchestration, Automation, and Response By: Hayden Covington Published: 9/9/2026 Learn more: blackhillsinfosec.com/soar-1…
4
18
1,642
Most SOCs watch. ActiveSOC fights back. Built by career defenders who spar daily with one of the industry's most seasoned offensive teams: attack surface monitoring, cyber deception, continuous monitoring, adversarial emulation, hands-on training, and direct access to the full BHIS expert bench. Threats don't wait. Neither do we. activesoc.blackhillsinfosec.…
2
12
1,583
Buying a pentest without knowing what to look for is like buying a car without checking under the hood. Join us Thursday, Sept 10 for "Penetration Tests: Know Before You Buy." This is a free webcast breaking down what separates a real, valuable pentest from a checkbox exercise. Learn what to ask for, what red flags to watch for, and how to make sure you're actually getting your money's worth! events.zoom.us/ev/ArY9wzsUzL…
2
5
20
1,714
Happy Labor Day, we'll re-enable on Tuesday!
1
6
1,574
Labor Day first, then straight into AI-powered pentesting and a shift into buyers knowledge! Come hangout and say hi! events.zoom.us/eo/AqZceUFfoY…
4
12
1,663
Analysis concluded in record time. Verdict: looks exactly like malware, is malware...
5
1,642
Critical infrastructure keeps getting tested and this time a UK power plant. John Strand breaks down why the US grid's interconnected nature and slow modernization make it an even bigger risk. Worth a read for anyone in energy, OT, or critical infrastructure security! machine.news/iranian-hackers…
1
3
1,697