<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>Welbourne Security</title>
    <link>https://welbournesecurity.com/</link>
    <description>Practical blue-team learning, investigation scenarios, and CTF writeups.</description>
    <language>en-gb</language>
    <lastBuildDate>Fri, 31 Jul 2026 00:00:00 GMT</lastBuildDate>
    <item>
      <title>Writeup: Mement0</title>
      <link>https://welbournesecurity.com/writeups/htb/cyber-apocalypse-2026/aiml/mement0/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/htb/cyber-apocalypse-2026/aiml/mement0/#Writeup: Mement0</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate>
      <description>An offline AI/ML challenge where a scraping agent's CLAUDE.md standing memory and .claude skills are turned against it to recover a rite deleted from the record but kept in the repo's older history.</description>
    </item>
    <item>
      <title>Writeup: Saltlock Drift</title>
      <link>https://welbournesecurity.com/writeups/htb/cyber-apocalypse-2026/hardware/saltlock-drift/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/htb/cyber-apocalypse-2026/hardware/saltlock-drift/#Writeup: Saltlock Drift</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate>
      <description>A RollJam-style RF replay on a GateCar RF-433 fob: jam the receiver, sniff two presses, then replay an unused rolling code to unlock and reveal the token.</description>
    </item>
    <item>
      <title>Writeup: What the Shard Displayed</title>
      <link>https://welbournesecurity.com/writeups/htb/cyber-apocalypse-2026/hardware/what-the-shard-displayed/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/htb/cyber-apocalypse-2026/hardware/what-the-shard-displayed/#Writeup: What the Shard Displayed</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate>
      <description>Reconstruct a sigrok/PulseView logic-analyzer capture of an embedded display device to recover the image it painted, and the token drawn with it.</description>
    </item>
    <item>
      <title>Writeup: Ash-Vault Interlock</title>
      <link>https://welbournesecurity.com/writeups/htb/cyber-apocalypse-2026/ics/ash-vault-interlock/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/htb/cyber-apocalypse-2026/ics/ash-vault-interlock/#Writeup: Ash-Vault Interlock</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate>
      <description>Drive a Modbus/TCP interlock PLC and its HMI to halt an unstable cycle, force the seal-ready state, and release the checkpoint token from the alarm table.</description>
    </item>
    <item>
      <title>Writeup: Crownspire Transfer</title>
      <link>https://welbournesecurity.com/writeups/htb/cyber-apocalypse-2026/ics/crownspire-transfer/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/htb/cyber-apocalypse-2026/ics/crownspire-transfer/#Writeup: Crownspire Transfer</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate>
      <description>Use an IEC 60870-5-104 RTU and a captured maintenance session to force an interlocked power transfer and collect the feeder-trip checkpoint token.</description>
    </item>
    <item>
      <title>Writeup: Line Tap</title>
      <link>https://welbournesecurity.com/writeups/htb/cyber-apocalypse-2026/ics/line-tap/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/htb/cyber-apocalypse-2026/ics/line-tap/#Writeup: Line Tap</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate>
      <description>A forgotten RiverGate PLC still answers over telnet; sign in on old maintenance habits and read back the latest checkpoint token.</description>
    </item>
    <item>
      <title>Case Study: Stuxnet</title>
      <link>https://welbournesecurity.com/blue-team/case-studies/stuxnet/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/case-studies/stuxnet/#Case Study: Stuxnet</guid>
      <pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate>
      <description>The first malware known to cause physical destruction, using multiple zero-days and stolen certificates to cross an air gap and sabotage Iranian nuclear centrifuges while reporting normal readings to operators.</description>
    </item>
    <item>
      <title>Case Study: Target 2013</title>
      <link>https://welbournesecurity.com/blue-team/case-studies/target/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/case-studies/target/#Case Study: Target 2013</guid>
      <pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate>
      <description>Attackers phished an HVAC contractor, used its vendor-portal access to reach Target's flat internal network, and scraped 40 million card numbers from point-of-sale memory.</description>
    </item>
    <item>
      <title>Case Study: Equifax</title>
      <link>https://welbournesecurity.com/blue-team/case-studies/equifax/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/case-studies/equifax/#Case Study: Equifax</guid>
      <pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate>
      <description>Attackers exploited an unpatched Apache Struts flaw in a public web portal, found plaintext credentials, and quietly queried dozens of databases for months, stealing the personal data of about 147 million people.</description>
    </item>
    <item>
      <title>Case Study: NotPetya</title>
      <link>https://welbournesecurity.com/blue-team/case-studies/notpetya/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/case-studies/notpetya/#Case Study: NotPetya</guid>
      <pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate>
      <description>A destructive wiper disguised as ransomware that spread through a trojanised accounting-software update, then used a stolen NSA exploit and credential theft to cross flat networks in minutes.</description>
    </item>
    <item>
      <title>Case Study: WannaCry</title>
      <link>https://welbournesecurity.com/blue-team/case-studies/wannacry/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/case-studies/wannacry/#Case Study: WannaCry</guid>
      <pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate>
      <description>A ransomware worm that used the leaked EternalBlue SMB exploit to infect over 200,000 unpatched Windows systems in days, until an accidental kill-switch domain slowed it down.</description>
    </item>
    <item>
      <title>Case Study: Capital One</title>
      <link>https://welbournesecurity.com/blue-team/case-studies/capital-one/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/case-studies/capital-one/#Case Study: Capital One</guid>
      <pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate>
      <description>A misconfigured web application firewall let an attacker trick a cloud server into handing over its own IAM credentials, which were then used to copy more than 100 million customer records out of AWS S3.</description>
    </item>
    <item>
      <title>Case Study: SolarWinds SUNBURST</title>
      <link>https://welbournesecurity.com/blue-team/case-studies/sunburst/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/case-studies/sunburst/#Case Study: SolarWinds SUNBURST</guid>
      <pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate>
      <description>A stealthy supply-chain compromise that inserted a backdoor into signed SolarWinds Orion updates, then used DNS beaconing and forged SAML tokens to move quietly into cloud environments over months.</description>
    </item>
    <item>
      <title>Case Study: Colonial Pipeline</title>
      <link>https://welbournesecurity.com/blue-team/case-studies/colonial-pipeline/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/case-studies/colonial-pipeline/#Case Study: Colonial Pipeline</guid>
      <pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate>
      <description>A single leaked VPN password with no multi-factor authentication let DarkSide ransomware into Colonial's IT network, and the precautionary shutdown that followed cut fuel to much of the US East Coast.</description>
    </item>
    <item>
      <title>Case Study: Kaseya VSA / REvil</title>
      <link>https://welbournesecurity.com/blue-team/case-studies/kaseya/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/case-studies/kaseya/#Case Study: Kaseya VSA / REvil</guid>
      <pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate>
      <description>Attackers exploited zero-days in Kaseya's remote-management software and used its own trusted update channel to push REvil ransomware through managed service providers to roughly 1,500 downstream businesses at once.</description>
    </item>
    <item>
      <title>Case Study: Log4Shell</title>
      <link>https://welbournesecurity.com/blue-team/case-studies/log4shell/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/case-studies/log4shell/#Case Study: Log4Shell</guid>
      <pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate>
      <description>A trivially exploitable remote-code-execution flaw in the ubiquitous Log4j logging library, where a single attacker-controlled string in any log message could make a server fetch and run malicious code.</description>
    </item>
    <item>
      <title>Case Study: Uber 2022</title>
      <link>https://welbournesecurity.com/blue-team/case-studies/uber/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/case-studies/uber/#Case Study: Uber 2022</guid>
      <pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate>
      <description>An attacker bought a contractor's password, wore down their multi-factor authentication with repeated push prompts and a fake IT message, then found hardcoded admin credentials in a script that unlocked Uber's internal systems.</description>
    </item>
    <item>
      <title>Case Study: MOVEit / Cl0p</title>
      <link>https://welbournesecurity.com/blue-team/case-studies/moveit/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/case-studies/moveit/#Case Study: MOVEit / Cl0p</guid>
      <pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate>
      <description>A SQL-injection zero-day in the widely used MOVEit Transfer file-sharing product let the Cl0p group deploy a web shell and steal data from hundreds of organisations in a single mass-extortion campaign.</description>
    </item>
    <item>
      <title>Case Study: IOCONTROL</title>
      <link>https://welbournesecurity.com/blue-team/case-studies/iocontrol/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/case-studies/iocontrol/#Case Study: IOCONTROL</guid>
      <pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate>
      <description>A modular, Linux-based backdoor built to compromise internet-exposed IoT and OT devices, used by an Iran-linked group to reach fuel-management systems over an MQTT command channel.</description>
    </item>
    <item>
      <title>Learn: Active Directory Certificate Services</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/active-directory-certificate-services/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/active-directory-certificate-services/#Learn: Active Directory Certificate Services</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Active Directory Certificate Services issues and manages certificates used for user, device and service authentication inside a Windows public key infrastructure.</description>
    </item>
    <item>
      <title>Learn: Active Directory Federation Services</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/active-directory-federation-services/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/active-directory-federation-services/#Learn: Active Directory Federation Services</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Active Directory Federation Services acts as a security token service for federated sign-in and claims-based application access.</description>
    </item>
    <item>
      <title>Learn: Active Directory Web Services</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/active-directory-web-services/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/active-directory-web-services/#Learn: Active Directory Web Services</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Active Directory Web Services exposes Active Directory management functions to modern administrative tools.</description>
    </item>
    <item>
      <title>Learn: AMQP/RabbitMQ</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/amqp-rabbitmq/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/amqp-rabbitmq/#Learn: AMQP/RabbitMQ</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>AMQP/RabbitMQ moves queued messages between producers, brokers and consumers.</description>
    </item>
    <item>
      <title>Learn: Apache Cassandra</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/apache-cassandra/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/apache-cassandra/#Learn: Apache Cassandra</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Apache Cassandra provides a distributed wide-column database designed for resilient multi-node storage.</description>
    </item>
    <item>
      <title>Learn: Apache Kafka</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/apache-kafka/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/apache-kafka/#Learn: Apache Kafka</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Apache Kafka moves durable event streams between producers, brokers and consumers.</description>
    </item>
    <item>
      <title>Learn: Apache ZooKeeper</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/apache-zookeeper/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/apache-zookeeper/#Learn: Apache ZooKeeper</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Apache ZooKeeper coordinates distributed applications through shared configuration, naming and leader election.</description>
    </item>
    <item>
      <title>Learn: AWS EC2 Instance Metadata Service</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/aws-ec2-instance-metadata-service/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/aws-ec2-instance-metadata-service/#Learn: AWS EC2 Instance Metadata Service</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>AWS EC2 Instance Metadata Service provides an EC2 workload with instance metadata, user data and temporary role credentials through a link-local endpoint.</description>
    </item>
    <item>
      <title>Learn: Azure Instance Metadata Service</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/azure-instance-metadata-service/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/azure-instance-metadata-service/#Learn: Azure Instance Metadata Service</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Azure Instance Metadata Service provides Azure virtual machines with instance metadata and managed-identity token access through a link-local endpoint.</description>
    </item>
    <item>
      <title>Learn: BACnet/IP</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/bacnet-ip/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/bacnet-ip/#Learn: BACnet/IP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>BACnet/IP connects building automation controllers, sensors and management systems.</description>
    </item>
    <item>
      <title>Learn: BGP</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/bgp/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/bgp/#Learn: BGP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>BGP exchanges reachable network prefixes and path attributes between routing domains.</description>
    </item>
    <item>
      <title>Learn: Consul</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/consul/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/consul/#Learn: Consul</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Consul provides service discovery, health information, key-value data and service-mesh control functions.</description>
    </item>
    <item>
      <title>Learn: containerd and the Container Runtime Interface</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/containerd-and-cri/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/containerd-and-cri/#Learn: containerd and the Container Runtime Interface</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>containerd and the Container Runtime Interface manages container images, snapshots and runtime tasks for higher-level orchestrators such as Kubernetes.</description>
    </item>
    <item>
      <title>Learn: DHCP</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/dhcp/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/dhcp/#Learn: DHCP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>DHCP leases addressing, gateway and name-service configuration to clients.</description>
    </item>
    <item>
      <title>Learn: DNP3</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/dnp3/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/dnp3/#Learn: DNP3</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>DNP3 carries telemetry and control messages in utility and industrial environments.</description>
    </item>
    <item>
      <title>Learn: DNS</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/dns/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/dns/#Learn: DNS</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>DNS resolves names to records and helps clients locate systems and services.</description>
    </item>
    <item>
      <title>Learn: Docker Engine API</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/docker-engine-api/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/docker-engine-api/#Learn: Docker Engine API</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Docker Engine API controls Docker hosts, containers, images and volumes through an HTTP API.</description>
    </item>
    <item>
      <title>Learn: Docker Registry</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/docker-registry/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/docker-registry/#Learn: Docker Registry</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Docker Registry stores and distributes container image manifests and layers.</description>
    </item>
    <item>
      <title>Learn: Docker Swarm</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/docker-swarm/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/docker-swarm/#Learn: Docker Swarm</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Docker Swarm coordinates Docker nodes, services and overlay networks as a clustered orchestration platform.</description>
    </item>
    <item>
      <title>Learn: Elasticsearch</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/elasticsearch/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/elasticsearch/#Learn: Elasticsearch</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Elasticsearch provides search APIs and cluster transport for indexed data.</description>
    </item>
    <item>
      <title>Learn: Encrypted DNS</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/encrypted-dns/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/encrypted-dns/#Learn: Encrypted DNS</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Encrypted DNS protects DNS queries using DNS over HTTPS, DNS over TLS or related encrypted transports.</description>
    </item>
    <item>
      <title>Learn: etcd</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/etcd/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/etcd/#Learn: etcd</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>etcd stores Kubernetes and distributed-system state as a consistent key-value database.</description>
    </item>
    <item>
      <title>Learn: EtherNet/IP</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/ethernet-ip/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/ethernet-ip/#Learn: EtherNet/IP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>EtherNet/IP carries Common Industrial Protocol messaging for controllers, I/O and engineering systems.</description>
    </item>
    <item>
      <title>Learn: FTP</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/ftp/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/ftp/#Learn: FTP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>FTP transfers files using separate control and data connections.</description>
    </item>
    <item>
      <title>Learn: FTPS</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/ftps/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/ftps/#Learn: FTPS</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>FTPS adds TLS protection to FTP control and data channels.</description>
    </item>
    <item>
      <title>Learn: Git protocol</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/git-protocol/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/git-protocol/#Learn: Git protocol</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Git protocol serves Git repositories using the native unauthenticated transport.</description>
    </item>
    <item>
      <title>Learn: Global Catalog</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/global-catalog/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/global-catalog/#Learn: Global Catalog</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Global Catalog answers forest-wide Active Directory searches using a partial attribute set.</description>
    </item>
    <item>
      <title>Learn: Google Cloud metadata server</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/google-cloud-metadata-server/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/google-cloud-metadata-server/#Learn: Google Cloud metadata server</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Google Cloud metadata server provides Compute Engine workloads with instance data and service-account access tokens.</description>
    </item>
    <item>
      <title>Learn: HashiCorp Vault</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/hashicorp-vault/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/hashicorp-vault/#Learn: HashiCorp Vault</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>HashiCorp Vault brokers secrets, encryption operations and short-lived credentials under centrally managed policy.</description>
    </item>
    <item>
      <title>Learn: HTTP proxy</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/http-proxy/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/http-proxy/#Learn: HTTP proxy</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>HTTP proxy relays web requests for filtering, caching, inspection or controlled egress.</description>
    </item>
    <item>
      <title>Learn: HTTP</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/http/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/http/#Learn: HTTP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>HTTP carries web requests, API calls and application responses.</description>
    </item>
    <item>
      <title>Learn: HTTPS/TLS</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/https-tls/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/https-tls/#Learn: HTTPS/TLS</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>HTTPS/TLS protects web and application traffic with TLS, commonly using HTTP over TCP or QUIC.</description>
    </item>
    <item>
      <title>Learn: IEC 60870-5-104</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/iec-60870-5-104/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/iec-60870-5-104/#Learn: IEC 60870-5-104</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>IEC 60870-5-104 carries telecontrol messages between control centres and substations over IP.</description>
    </item>
    <item>
      <title>Learn: IKE/IPsec</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/ike-ipsec/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/ike-ipsec/#Learn: IKE/IPsec</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>IKE/IPsec negotiates keys and protects IP traffic with authenticated tunnels.</description>
    </item>
    <item>
      <title>Learn: IMAP</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/imap/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/imap/#Learn: IMAP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>IMAP synchronises mailbox folders and messages between clients and servers.</description>
    </item>
    <item>
      <title>Learn: IPMI and RMCP</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/ipmi-rmcp/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/ipmi-rmcp/#Learn: IPMI and RMCP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>IPMI and RMCP provides out-of-band hardware monitoring and management through a baseboard management controller.</description>
    </item>
    <item>
      <title>Learn: iSCSI</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/iscsi/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/iscsi/#Learn: iSCSI</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>iSCSI carries block-storage commands across IP networks.</description>
    </item>
    <item>
      <title>Learn: Kerberos</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/kerberos/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/kerberos/#Learn: Kerberos</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Kerberos issues time-limited tickets for authenticated access to services.</description>
    </item>
    <item>
      <title>Learn: kubelet</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/kubelet/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/kubelet/#Learn: kubelet</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>kubelet manages pods and exposes node-level status and execution interfaces.</description>
    </item>
    <item>
      <title>Learn: Kubernetes API</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/kubernetes-api/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/kubernetes-api/#Learn: Kubernetes API</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Kubernetes API controls Kubernetes objects, identities and cluster state.</description>
    </item>
    <item>
      <title>Learn: LDAP</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/ldap/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/ldap/#Learn: LDAP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>LDAP queries and changes directory objects such as users, groups and policies.</description>
    </item>
    <item>
      <title>Learn: LLMNR</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/llmnr/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/llmnr/#Learn: LLMNR</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>LLMNR provides local-link name resolution when DNS does not answer.</description>
    </item>
    <item>
      <title>Learn: mDNS</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/mdns/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/mdns/#Learn: mDNS</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>mDNS provides multicast name discovery on a local link without a central DNS server.</description>
    </item>
    <item>
      <title>Learn: Memcached</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/memcached/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/memcached/#Learn: Memcached</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Memcached holds transient application data in memory to reduce repeated database or computation work.</description>
    </item>
    <item>
      <title>Learn: Microsoft SQL Server</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/microsoft-sql-server/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/microsoft-sql-server/#Learn: Microsoft SQL Server</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Microsoft SQL Server hosts relational databases and exposes discovery and query services.</description>
    </item>
    <item>
      <title>Learn: Modbus/TCP</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/modbus-tcp/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/modbus-tcp/#Learn: Modbus/TCP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Modbus/TCP carries simple industrial read and write operations between controllers and supervisory systems.</description>
    </item>
    <item>
      <title>Learn: MongoDB</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/mongodb/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/mongodb/#Learn: MongoDB</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>MongoDB provides document database queries, replication and administration.</description>
    </item>
    <item>
      <title>Learn: MQTT</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/mqtt/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/mqtt/#Learn: MQTT</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>MQTT provides lightweight publish and subscribe messaging for devices and applications.</description>
    </item>
    <item>
      <title>Learn: MySQL/MariaDB</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/mysql-mariadb/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/mysql-mariadb/#Learn: MySQL/MariaDB</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>MySQL/MariaDB provides relational database sessions for applications and administrators.</description>
    </item>
    <item>
      <title>Learn: NATS</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/nats/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/nats/#Learn: NATS</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>NATS provides lightweight publish and subscribe messaging for applications and distributed systems.</description>
    </item>
    <item>
      <title>Learn: NetBIOS</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/netbios/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/netbios/#Learn: NetBIOS</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>NetBIOS supports legacy Windows naming, datagrams and session services.</description>
    </item>
    <item>
      <title>Learn: NFS</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/nfs/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/nfs/#Learn: NFS</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>NFS exports filesystems to Unix and Linux clients over the network.</description>
    </item>
    <item>
      <title>Learn: NTP</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/ntp/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/ntp/#Learn: NTP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>NTP synchronises clocks so systems and security evidence share a reliable time base.</description>
    </item>
    <item>
      <title>Learn: OAuth 2.0 and OpenID Connect</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/oauth-2-and-openid-connect/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/oauth-2-and-openid-connect/#Learn: OAuth 2.0 and OpenID Connect</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>OAuth 2.0 and OpenID Connect delegates application access and adds an identity layer through signed tokens and provider metadata.</description>
    </item>
    <item>
      <title>Learn: OPC UA</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/opc-ua/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/opc-ua/#Learn: OPC UA</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>OPC UA exchanges structured industrial data between clients, servers and gateways.</description>
    </item>
    <item>
      <title>Learn: OpenVPN</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/openvpn/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/openvpn/#Learn: OpenVPN</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>OpenVPN creates TLS-based remote-access or site-to-site virtual private networks.</description>
    </item>
    <item>
      <title>Learn: Oracle Net</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/oracle-net/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/oracle-net/#Learn: Oracle Net</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Oracle Net connects Oracle database clients to listeners and database services.</description>
    </item>
    <item>
      <title>Learn: OSPF</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/ospf/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/ospf/#Learn: OSPF</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>OSPF shares internal routes between routers inside an autonomous system.</description>
    </item>
    <item>
      <title>Learn: POP3</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/pop3/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/pop3/#Learn: POP3</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>POP3 downloads mailbox messages to a client.</description>
    </item>
    <item>
      <title>Learn: PostgreSQL</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/postgresql/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/postgresql/#Learn: PostgreSQL</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>PostgreSQL provides relational database sessions with extensible authentication and query features.</description>
    </item>
    <item>
      <title>Learn: PROFINET</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/profinet/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/profinet/#Learn: PROFINET</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>PROFINET connects industrial controllers, engineering systems and field devices for cyclic and acyclic automation traffic.</description>
    </item>
    <item>
      <title>Learn: Prometheus</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/prometheus/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/prometheus/#Learn: Prometheus</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Prometheus scrapes and stores time-series metrics and provides a query API for monitoring data.</description>
    </item>
    <item>
      <title>Learn: RADIUS</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/radius/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/radius/#Learn: RADIUS</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>RADIUS centralises network access authentication, authorisation and accounting.</description>
    </item>
    <item>
      <title>Learn: RDP</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/rdp/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/rdp/#Learn: RDP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>RDP provides interactive Windows desktop sessions and remote administration.</description>
    </item>
    <item>
      <title>Learn: Redis</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/redis/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/redis/#Learn: Redis</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Redis provides an in-memory key-value store often used for caching, queues and sessions.</description>
    </item>
    <item>
      <title>Learn: RPC/DCOM Endpoint Mapper</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/rpc-dcom-endpoint-mapper/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/rpc-dcom-endpoint-mapper/#Learn: RPC/DCOM Endpoint Mapper</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>RPC/DCOM Endpoint Mapper helps Windows clients locate dynamic RPC services used by administration and applications.</description>
    </item>
    <item>
      <title>Learn: rpcbind</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/rpcbind/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/rpcbind/#Learn: rpcbind</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>rpcbind maps ONC RPC program numbers to the ports where services are listening.</description>
    </item>
    <item>
      <title>Learn: rsync</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/rsync/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/rsync/#Learn: rsync</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>rsync synchronises files and directory trees efficiently between systems.</description>
    </item>
    <item>
      <title>Learn: RTP/RTCP</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/rtp-rtcp/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/rtp-rtcp/#Learn: RTP/RTCP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>RTP/RTCP carries real-time audio and video while RTCP reports quality and session statistics.</description>
    </item>
    <item>
      <title>Learn: SAML federation</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/saml-federation/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/saml-federation/#Learn: SAML federation</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>SAML federation exchanges signed identity assertions between an identity provider and relying applications.</description>
    </item>
    <item>
      <title>Learn: Siemens S7comm</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/siemens-s7comm/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/siemens-s7comm/#Learn: Siemens S7comm</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Siemens S7comm supports engineering and data exchange with Siemens S7 programmable controllers.</description>
    </item>
    <item>
      <title>Learn: SIP</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/sip/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/sip/#Learn: SIP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>SIP establishes, changes and ends voice or video sessions.</description>
    </item>
    <item>
      <title>Learn: SMB</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/smb/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/smb/#Learn: SMB</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>SMB provides Windows file, printer and named-pipe access and supports remote administration.</description>
    </item>
    <item>
      <title>Learn: SMTP</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/smtp/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/smtp/#Learn: SMTP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>SMTP moves email between servers and accepts authenticated message submission.</description>
    </item>
    <item>
      <title>Learn: SNMP</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/snmp/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/snmp/#Learn: SNMP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>SNMP reads device state and receives traps from managed infrastructure.</description>
    </item>
    <item>
      <title>Learn: SSH</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/ssh/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/ssh/#Learn: SSH</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>SSH provides encrypted remote shells, command execution, tunnelling and file transfer.</description>
    </item>
    <item>
      <title>Learn: Syslog</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/syslog/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/syslog/#Learn: Syslog</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Syslog transports operational and security messages from systems to collectors.</description>
    </item>
    <item>
      <title>Learn: TACACS+</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/tacacs-plus/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/tacacs-plus/#Learn: TACACS+</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>TACACS+ centralises administrative access decisions for network devices.</description>
    </item>
    <item>
      <title>Learn: Telnet</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/telnet/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/telnet/#Learn: Telnet</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Telnet provides a plaintext interactive terminal to remote systems and devices.</description>
    </item>
    <item>
      <title>Learn: TFTP</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/tftp/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/tftp/#Learn: TFTP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>TFTP transfers simple files for boot, firmware and device configuration workflows.</description>
    </item>
    <item>
      <title>Learn: VNC</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/vnc/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/vnc/#Learn: VNC</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>VNC shares graphical desktops using the Remote Framebuffer protocol.</description>
    </item>
    <item>
      <title>Learn: WinRM/WS-Man</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/winrm-wsman/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/winrm-wsman/#Learn: WinRM/WS-Man</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>WinRM/WS-Man provides standards-based remote management and PowerShell remoting.</description>
    </item>
    <item>
      <title>Learn: WireGuard</title>
      <link>https://welbournesecurity.com/blue-team/learn/services/wireguard/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/services/wireguard/#Learn: WireGuard</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>WireGuard creates lightweight encrypted IP tunnels using static public keys.</description>
    </item>
    <item>
      <title>Learn: AD CS certificate abuse</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/ad-cs-certificate-abuse/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/ad-cs-certificate-abuse/#Learn: AD CS certificate abuse</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>AD CS certificate abuse uses certificate template and enrolment policy abuse to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: AdminSDHolder and SDProp persistence</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/adminsdholder-and-sdprop-persistence/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/adminsdholder-and-sdprop-persistence/#Learn: AdminSDHolder and SDProp persistence</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>AdminSDHolder and SDProp persistence uses AdminSDHolder ACL propagation through SDProp to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Adversary-in-the-middle phishing and cookie theft</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/adversary-in-the-middle-phishing-and-cookie-theft/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/adversary-in-the-middle-phishing-and-cookie-theft/#Learn: Adversary-in-the-middle phishing and cookie theft</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Adversary-in-the-middle phishing and cookie theft uses reverse-proxy interception of authentication and session cookies to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: API key exposure and abuse</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/api-key-exposure-and-abuse/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/api-key-exposure-and-abuse/#Learn: API key exposure and abuse</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>API key exposure and abuse uses API key discovery followed by authenticated API calls to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Application token theft</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/application-token-theft/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/application-token-theft/#Learn: Application token theft</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Application token theft uses bearer token capture and replay to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: ARP spoofing</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/arp-spoofing/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/arp-spoofing/#Learn: ARP spoofing</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>ARP spoofing uses forged ARP replies that change neighbour-cache bindings to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: AS-REP roasting</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/as-rep-roasting/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/as-rep-roasting/#Learn: AS-REP roasting</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>AS-REP roasting uses Kerberos AS-REP responses for accounts without pre-authentication to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Authentication bypass</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/authentication-bypass/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/authentication-bypass/#Learn: Authentication bypass</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Authentication bypass uses application logic that reaches a protected action without a valid authentication decision to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: BGP route hijacking</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/bgp-route-hijacking/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/bgp-route-hijacking/#Learn: BGP route hijacking</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>BGP route hijacking uses unauthorised BGP origin or more-specific route advertisement to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Bootkit</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/bootkit/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/bootkit/#Learn: Bootkit</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Bootkit uses pre-operating-system code inserted into the boot chain to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Browser credential and session theft</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/browser-credential-and-session-theft/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/browser-credential-and-session-theft/#Learn: Browser credential and session theft</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Browser credential and session theft uses browser profile, credential-store and session database access to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Brute force and password guessing</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/brute-force-and-password-guessing/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/brute-force-and-password-guessing/#Learn: Brute force and password guessing</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Brute force and password guessing uses repeated authentication attempts against one identity to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Business email compromise</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/business-email-compromise/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/business-email-compromise/#Learn: Business email compromise</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Business email compromise uses mailbox or mail-flow manipulation using a trusted business identity to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: C2 beaconing</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/c2-beaconing/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/c2-beaconing/#Learn: C2 beaconing</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>C2 beaconing uses periodic command-channel check-ins over an allowed protocol to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: CI/CD secret leakage</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/ci-cd-secret-leakage/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/ci-cd-secret-leakage/#Learn: CI/CD secret leakage</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>CI/CD secret leakage uses pipeline log, variable, artefact or repository secret exposure to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Cloud access-key theft</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/cloud-access-key-theft/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/cloud-access-key-theft/#Learn: Cloud access-key theft</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Cloud access-key theft uses cloud access-key discovery and API use to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Cloud account takeover</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/cloud-account-takeover/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/cloud-account-takeover/#Learn: Cloud account takeover</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Cloud account takeover uses control-plane authentication with a compromised principal to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Cloud audit-log tampering</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/cloud-audit-log-tampering/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/cloud-audit-log-tampering/#Learn: Cloud audit-log tampering</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Cloud audit-log tampering uses logging policy disablement, exclusion or trail deletion to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Cloud IAM policy abuse</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/cloud-iam-policy-abuse/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/cloud-iam-policy-abuse/#Learn: Cloud IAM policy abuse</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Cloud IAM policy abuse uses IAM policy, role or trust-policy modification to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Cloud role privilege escalation</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/cloud-role-privilege-escalation/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/cloud-role-privilege-escalation/#Learn: Cloud role privilege escalation</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Cloud role privilege escalation uses role assumption or permission-chain escalation to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Cold boot attack</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/cold-boot-attack/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/cold-boot-attack/#Learn: Cold boot attack</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Cold boot attack uses residual encryption-key recovery from volatile memory after power interruption to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Conditional Access policy tampering</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/conditional-access-policy-tampering/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/conditional-access-policy-tampering/#Learn: Conditional Access policy tampering</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Conditional Access policy tampering uses identity policy change that weakens sign-in conditions to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Container escape</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/container-escape/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/container-escape/#Learn: Container escape</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Container escape uses container-to-host boundary escape through a runtime or kernel weakness to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Container runtime socket abuse</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/container-runtime-socket-abuse/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/container-runtime-socket-abuse/#Learn: Container runtime socket abuse</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Container runtime socket abuse uses privileged requests sent to an exposed container runtime socket to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Credential stuffing</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/credential-stuffing/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/credential-stuffing/#Learn: Credential stuffing</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Credential stuffing uses replay of breached username and password pairs across services to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Cron and systemd timer persistence</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/cron-and-systemd-timer-persistence/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/cron-and-systemd-timer-persistence/#Learn: Cron and systemd timer persistence</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Cron and systemd timer persistence uses scheduled Linux execution through cron or systemd timers to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Cross-site request forgery</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/cross-site-request-forgery/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/cross-site-request-forgery/#Learn: Cross-site request forgery</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Cross-site request forgery uses cross-origin request sent with a victim browser's ambient authority to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Cross-site scripting</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/cross-site-scripting/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/cross-site-scripting/#Learn: Cross-site scripting</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Cross-site scripting uses untrusted script execution inside a trusted web origin to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Cryptojacking</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/cryptojacking/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/cryptojacking/#Learn: Cryptojacking</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Cryptojacking uses unauthorised compute consumption for cryptocurrency mining to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Data exfiltration</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/data-exfiltration/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/data-exfiltration/#Learn: Data exfiltration</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Data exfiltration uses staged information transferred across an external trust boundary to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: DCShadow</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/dcshadow/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/dcshadow/#Learn: DCShadow</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>DCShadow uses rogue domain-controller registration followed by directory replication changes to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: DCSync</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/dcsync/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/dcsync/#Learn: DCSync</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>DCSync uses directory replication requests for credential data to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: DHCP spoofing</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/dhcp-spoofing/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/dhcp-spoofing/#Learn: DHCP spoofing</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>DHCP spoofing uses unauthorised DHCP offers that replace gateway or resolver settings to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: DLL search-order hijacking and side-loading</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/dll-search-order-hijacking-and-side-loading/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/dll-search-order-hijacking-and-side-loading/#Learn: DLL search-order hijacking and side-loading</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>DLL search-order hijacking and side-loading uses trusted process loading of an attacker-controlled library to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: DNS cache poisoning</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/dns-cache-poisoning/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/dns-cache-poisoning/#Learn: DNS cache poisoning</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>DNS cache poisoning uses forged DNS data accepted into a resolver cache to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: DNS tunnelling</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/dns-tunnelling/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/dns-tunnelling/#Learn: DNS tunnelling</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>DNS tunnelling uses encoded command or data carried in DNS names and responses to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Domain trust abuse</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/domain-trust-abuse/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/domain-trust-abuse/#Learn: Domain trust abuse</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Domain trust abuse uses authentication or authorisation across an abused domain trust to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Drive-by download</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/drive-by-download/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/drive-by-download/#Learn: Drive-by download</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Drive-by download uses browser-delivered content that triggers an unwanted download or execution chain to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Engineering workstation compromise</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/engineering-workstation-compromise/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/engineering-workstation-compromise/#Learn: Engineering workstation compromise</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Engineering workstation compromise uses engineering software and project access used to reach control assets to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Evil Maid</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/evil-maid/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/evil-maid/#Learn: Evil Maid</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Evil Maid uses unattended-device tampering with the boot or authentication chain to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Evil Twin</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/evil-twin/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/evil-twin/#Learn: Evil Twin</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Evil Twin uses rogue wireless network impersonating a trusted SSID to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Exposed container registries</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/exposed-container-registries/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/exposed-container-registries/#Learn: Exposed container registries</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Exposed container registries uses unauthorised registry enumeration, pull or push operations to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Exposed object storage</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/exposed-object-storage/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/exposed-object-storage/#Learn: Exposed object storage</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Exposed object storage uses public or over-permissive object-store access to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: File inclusion</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/file-inclusion/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/file-inclusion/#Learn: File inclusion</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>File inclusion uses application-controlled inclusion of a local or remote file to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Golden SAML</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/golden-saml/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/golden-saml/#Learn: Golden SAML</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Golden SAML uses forged federation assertions signed with compromised identity-provider material to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Golden Ticket</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/golden-ticket/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/golden-ticket/#Learn: Golden Ticket</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Golden Ticket uses forged Kerberos ticket-granting tickets using the domain KDC key to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: GraphQL abuse</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/graphql-abuse/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/graphql-abuse/#Learn: GraphQL abuse</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>GraphQL abuse uses GraphQL query, mutation, batching or introspection misuse to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Group Policy abuse</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/group-policy-abuse/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/group-policy-abuse/#Learn: Group Policy abuse</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Group Policy abuse uses malicious change distributed through a Group Policy Object to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Hardware implant</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/hardware-implant/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/hardware-implant/#Learn: Hardware implant</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Hardware implant uses physical insertion of a device that observes or alters a trusted path to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: HTTP request smuggling</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/http-request-smuggling/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/http-request-smuggling/#Learn: HTTP request smuggling</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>HTTP request smuggling uses front-end and back-end disagreement about HTTP message boundaries to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: IDOR and BOLA</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/idor-and-bola/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/idor-and-bola/#Learn: IDOR and BOLA</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>IDOR and BOLA uses direct object reference accepted without object-level authorisation to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Inhibit system recovery</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/inhibit-system-recovery/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/inhibit-system-recovery/#Learn: Inhibit system recovery</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Inhibit system recovery uses removal or disablement of backups and recovery paths to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Insecure deserialization</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/insecure-deserialization/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/insecure-deserialization/#Learn: Insecure deserialization</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Insecure deserialization uses attacker-controlled object data processed by an unsafe deserialiser to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Instance metadata credential theft</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/instance-metadata-credential-theft/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/instance-metadata-credential-theft/#Learn: Instance metadata credential theft</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Instance metadata credential theft uses workload request to a cloud instance metadata credential endpoint to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: IPMI and BMC abuse</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/ipmi-and-bmc-abuse/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/ipmi-and-bmc-abuse/#Learn: IPMI and BMC abuse</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>IPMI and BMC abuse uses BMC authentication and remote-management action outside approved administration to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: JWT forgery and algorithm confusion</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/jwt-forgery-and-algorithm-confusion/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/jwt-forgery-and-algorithm-confusion/#Learn: JWT forgery and algorithm confusion</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>JWT forgery and algorithm confusion uses token-signature or algorithm validation failure to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Kerberoasting</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/kerberoasting/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/kerberoasting/#Learn: Kerberoasting</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Kerberoasting uses Kerberos service-ticket request followed by offline password recovery to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Kerberos delegation abuse</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/kerberos-delegation-abuse/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/kerberos-delegation-abuse/#Learn: Kerberos delegation abuse</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Kerberos delegation abuse uses delegated Kerberos credentials used beyond their intended service path to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Kubernetes admission-controller and webhook abuse</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/kubernetes-admission-controller-and-webhook-abuse/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/kubernetes-admission-controller-and-webhook-abuse/#Learn: Kubernetes admission-controller and webhook abuse</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Kubernetes admission-controller and webhook abuse uses admission configuration or webhook response that alters cluster decisions to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Kubernetes RBAC privilege escalation</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/kubernetes-rbac-privilege-escalation/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/kubernetes-rbac-privilege-escalation/#Learn: Kubernetes RBAC privilege escalation</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Kubernetes RBAC privilege escalation uses RBAC binding or permission chain that grants stronger cluster rights to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Kubernetes Secrets theft</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/kubernetes-secrets-theft/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/kubernetes-secrets-theft/#Learn: Kubernetes Secrets theft</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Kubernetes Secrets theft uses Kubernetes API or datastore access to Secret objects to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Kubernetes service account token theft</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/kubernetes-service-account-token-theft/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/kubernetes-service-account-token-theft/#Learn: Kubernetes service account token theft</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Kubernetes service account token theft uses service-account token discovery and API replay to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: LaunchAgent and LaunchDaemon persistence</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/launchagent-and-launchdaemon-persistence/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/launchagent-and-launchdaemon-persistence/#Learn: LaunchAgent and LaunchDaemon persistence</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>LaunchAgent and LaunchDaemon persistence uses macOS launchd property-list persistence to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Living off the land binaries</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/living-off-the-land-binaries/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/living-off-the-land-binaries/#Learn: Living off the land binaries</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Living off the land binaries uses trusted signed utility used for an unintended execution or transfer action to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: LLMNR/NBT-NS poisoning</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/llmnr-nbt-ns-poisoning/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/llmnr-nbt-ns-poisoning/#Learn: LLMNR/NBT-NS poisoning</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>LLMNR/NBT-NS poisoning uses forged local name-resolution replies that redirect authentication to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Log clearing and defence impairment</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/log-clearing-and-defence-impairment/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/log-clearing-and-defence-impairment/#Learn: Log clearing and defence impairment</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Log clearing and defence impairment uses audit-record deletion or telemetry-control modification to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: LSASS credential dumping</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/lsass-credential-dumping/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/lsass-credential-dumping/#Learn: LSASS credential dumping</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>LSASS credential dumping uses access to credential material held by LSASS memory to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Malicious documents and macros</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/malicious-documents-and-macros/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/malicious-documents-and-macros/#Learn: Malicious documents and macros</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Malicious documents and macros uses document content that invokes script, template or child-process behaviour to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Mass assignment</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/mass-assignment/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/mass-assignment/#Learn: Mass assignment</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Mass assignment uses automatic object binding that accepts security-sensitive fields to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: MFA fatigue</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/mfa-fatigue/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/mfa-fatigue/#Learn: MFA fatigue</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>MFA fatigue uses repeated unsolicited approval prompts designed to obtain one acceptance to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: MFA method registration abuse</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/mfa-method-registration-abuse/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/mfa-method-registration-abuse/#Learn: MFA method registration abuse</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>MFA method registration abuse uses new authentication method registered under a compromised identity to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: NTDS.dit theft</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/ntdsdit-theft/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/ntdsdit-theft/#Learn: NTDS.dit theft</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>NTDS.dit theft uses copy or backup access to the Active Directory database and supporting keys to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: NTLM relay</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/ntlm-relay/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/ntlm-relay/#Learn: NTLM relay</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>NTLM relay uses forwarding of NTLM authentication to another accepting service to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: OAuth consent phishing</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/oauth-consent-phishing/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/oauth-consent-phishing/#Learn: OAuth consent phishing</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>OAuth consent phishing uses deceptive OAuth grant consent for a malicious application to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: On-path attack</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/on-path-attack/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/on-path-attack/#Learn: On-path attack</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>On-path attack uses traffic interception or alteration between communicating peers to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: OS command injection</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/os-command-injection/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/os-command-injection/#Learn: OS command injection</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>OS command injection uses untrusted application input interpreted by an operating-system command processor to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: OSPF route manipulation</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/ospf-route-manipulation/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/ospf-route-manipulation/#Learn: OSPF route manipulation</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>OSPF route manipulation uses forged or unauthorised OSPF adjacency and link-state information to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Overpass the Hash</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/overpass-the-hash/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/overpass-the-hash/#Learn: Overpass the Hash</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Overpass the Hash uses NTLM key material used to obtain Kerberos tickets to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: PAM backdoors and credential interception</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/pam-backdoors-and-credential-interception/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/pam-backdoors-and-credential-interception/#Learn: PAM backdoors and credential interception</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>PAM backdoors and credential interception uses malicious PAM module or configuration in the authentication stack to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Pass the Hash</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/pass-the-hash/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/pass-the-hash/#Learn: Pass the Hash</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Pass the Hash uses NTLM credential material replay without the plaintext password to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Pass the Ticket</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/pass-the-ticket/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/pass-the-ticket/#Learn: Pass the Ticket</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Pass the Ticket uses stolen Kerberos ticket inserted into another logon session to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Password spraying</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/password-spraying/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/password-spraying/#Learn: Password spraying</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Password spraying uses one or a few passwords tried across many identities to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Path traversal</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/path-traversal/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/path-traversal/#Learn: Path traversal</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Path traversal uses path normalisation weakness that escapes an intended directory to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Phishing</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/phishing/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/phishing/#Learn: Phishing</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Phishing uses deceptive message or site that solicits an unsafe action to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: PLC logic modification</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/plc-logic-modification/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/plc-logic-modification/#Learn: PLC logic modification</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>PLC logic modification uses unauthorised download or edit of controller logic to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Poisoned container images</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/poisoned-container-images/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/poisoned-container-images/#Learn: Poisoned container images</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Poisoned container images uses malicious content introduced into a trusted container image path to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Port scanning and service discovery</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/port-scanning-and-service-discovery/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/port-scanning-and-service-discovery/#Learn: Port scanning and service discovery</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port scanning and service discovery uses connection probes used to enumerate reachable listeners to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: PowerShell abuse</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/powershell-abuse/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/powershell-abuse/#Learn: PowerShell abuse</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>PowerShell abuse uses PowerShell host and .NET capabilities used for unauthorised actions to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Process injection</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/process-injection/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/process-injection/#Learn: Process injection</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Process injection uses code or execution state placed inside another process to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Public cloud snapshot sharing</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/public-cloud-snapshot-sharing/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/public-cloud-snapshot-sharing/#Learn: Public cloud snapshot sharing</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Public cloud snapshot sharing uses snapshot permissions changed to expose data to another principal to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Ransomware</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/ransomware/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/ransomware/#Learn: Ransomware</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Ransomware uses file encryption paired with recovery disruption and extortion to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: RDP abuse and session hijacking</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/rdp-abuse-and-session-hijacking/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/rdp-abuse-and-session-hijacking/#Learn: RDP abuse and session hijacking</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>RDP abuse and session hijacking uses remote desktop authentication or existing session control to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Registry Run key persistence</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/registry-run-key-persistence/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/registry-run-key-persistence/#Learn: Registry Run key persistence</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Registry Run key persistence uses Windows logon-start registry value modification to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Rogue access point</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/rogue-access-point/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/rogue-access-point/#Learn: Rogue access point</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Rogue access point uses unauthorised wireless access point bridging or impersonating a network to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: RTP media interception and injection</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/rtp-media-interception-and-injection/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/rtp-media-interception-and-injection/#Learn: RTP media interception and injection</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>RTP media interception and injection uses RTP stream discovery followed by packet capture or injection to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: SAM and LSA secrets dumping</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/sam-and-lsa-secrets-dumping/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/sam-and-lsa-secrets-dumping/#Learn: SAM and LSA secrets dumping</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>SAM and LSA secrets dumping uses offline or privileged access to local account and LSA secret stores to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Scheduled task persistence</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/scheduled-task-persistence/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/scheduled-task-persistence/#Learn: Scheduled task persistence</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Scheduled task persistence uses scheduled task registration that triggers later execution to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Secrets-manager theft</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/secrets-manager-theft/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/secrets-manager-theft/#Learn: Secrets-manager theft</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Secrets-manager theft uses authorised or stolen identity reading managed secret values to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Server-side request forgery</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/server-side-request-forgery/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/server-side-request-forgery/#Learn: Server-side request forgery</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Server-side request forgery uses server-originated request directed to an attacker-selected destination to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Serverless function abuse</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/serverless-function-abuse/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/serverless-function-abuse/#Learn: Serverless function abuse</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Serverless function abuse uses function code, trigger or identity changed for unauthorised execution to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Session fixation</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/session-fixation/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/session-fixation/#Learn: Session fixation</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Session fixation uses victim authentication bound to a session identifier chosen earlier to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Session hijacking</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/session-hijacking/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/session-hijacking/#Learn: Session hijacking</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Session hijacking uses stolen session state replayed to an accepting application to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Shadow Credentials</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/shadow-credentials/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/shadow-credentials/#Learn: Shadow Credentials</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Shadow Credentials uses directory key-credential link modified to enable certificate authentication to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Silver Ticket</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/silver-ticket/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/silver-ticket/#Learn: Silver Ticket</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Silver Ticket uses forged Kerberos service ticket using a service account key to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: SIP registration abuse and toll fraud</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/sip-registration-abuse-and-toll-fraud/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/sip-registration-abuse-and-toll-fraud/#Learn: SIP registration abuse and toll fraud</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>SIP registration abuse and toll fraud uses unauthorised SIP registration and call placement to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Skeleton Key</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/skeleton-key/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/skeleton-key/#Learn: Skeleton Key</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Skeleton Key uses domain-controller authentication logic modified to accept a secondary secret to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: SMB and admin share lateral movement</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/smb-and-admin-share-lateral-movement/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/smb-and-admin-share-lateral-movement/#Learn: SMB and admin share lateral movement</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>SMB and admin share lateral movement uses remote SMB administrative share and service-control activity to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: SNMP abuse</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/snmp-abuse/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/snmp-abuse/#Learn: SNMP abuse</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>SNMP abuse uses SNMP enumeration or write operation using exposed community or user credentials to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Spearphishing</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/spearphishing/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/spearphishing/#Learn: Spearphishing</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Spearphishing uses targeted deceptive delivery tailored to a person or organisation to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: SQL injection</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/sql-injection/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/sql-injection/#Learn: SQL injection</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>SQL injection uses untrusted input changing the structure of a database query to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: SSH abuse</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/ssh-abuse/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/ssh-abuse/#Learn: SSH abuse</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>SSH abuse uses unauthorised SSH authentication, forwarding or remote command execution to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: SSH authorized_keys persistence</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/ssh-authorized-keys-persistence/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/ssh-authorized-keys-persistence/#Learn: SSH authorized_keys persistence</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>SSH authorized_keys persistence uses public key added to an SSH authorised-keys file to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Startup folder persistence</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/startup-folder-persistence/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/startup-folder-persistence/#Learn: Startup folder persistence</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Startup folder persistence uses executable or shortcut placed in a Windows Startup folder to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Supply-chain compromise</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/supply-chain-compromise/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/supply-chain-compromise/#Learn: Supply-chain compromise</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Supply-chain compromise uses trusted supplier, build or update path modified before delivery to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Unauthorised control commands and safety-system manipulation</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/unauthorised-control-commands-and-safety-system-manipulation/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/unauthorised-control-commands-and-safety-system-manipulation/#Learn: Unauthorised control commands and safety-system manipulation</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Unauthorised control commands and safety-system manipulation uses industrial command or safety configuration changed outside authorised control to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: USB drop and baiting</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/usb-drop-and-baiting/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/usb-drop-and-baiting/#Learn: USB drop and baiting</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>USB drop and baiting uses removable media used to induce connection or file execution to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: VLAN hopping</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/vlan-hopping/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/vlan-hopping/#Learn: VLAN hopping</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>VLAN hopping uses frame tagging or trunk negotiation used to cross a VLAN boundary to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: VPN account abuse</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/vpn-account-abuse/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/vpn-account-abuse/#Learn: VPN account abuse</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>VPN account abuse uses stolen VPN identity used to enter a protected network to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Web shell</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/web-shell/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/web-shell/#Learn: Web shell</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Web shell uses server-side script providing persistent remote request execution to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Wi-Fi deauthentication</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/wi-fi-deauthentication/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/wi-fi-deauthentication/#Learn: Wi-Fi deauthentication</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Wi-Fi deauthentication uses forged 802.11 management frames that disconnect clients to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Windows service execution</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/windows-service-execution/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/windows-service-execution/#Learn: Windows service execution</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Windows service execution uses remote Service Control Manager creation and start operations to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Wiper and destructive malware</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/wiper-and-destructive-malware/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/wiper-and-destructive-malware/#Learn: Wiper and destructive malware</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Wiper and destructive malware uses deliberate destruction of files, disks or boot data to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: WMI event subscription persistence</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/wmi-event-subscription-persistence/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/wmi-event-subscription-persistence/#Learn: WMI event subscription persistence</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>WMI event subscription persistence uses permanent WMI filter, consumer and binding registration to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: Workload identity abuse</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/workload-identity-abuse/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/workload-identity-abuse/#Learn: Workload identity abuse</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Workload identity abuse uses workload token or federated identity used against cloud APIs to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: XML external entity injection</title>
      <link>https://welbournesecurity.com/blue-team/learn/attacks/xml-external-entity-injection/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/attacks/xml-external-entity-injection/#Learn: XML external entity injection</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>XML external entity injection uses XML parser resolution of attacker-controlled external entities to cross a trust boundary, change security state or gain unauthorised capability.</description>
    </item>
    <item>
      <title>Learn: AD CS CA private keys and certificates</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/ad-cs-ca-private-keys-and-certificates/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/ad-cs-ca-private-keys-and-certificates/#Learn: AD CS CA private keys and certificates</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>AD CS CA private keys and certificates can expose keys capable of issuing trusted authentication certificates.</description>
    </item>
    <item>
      <title>Learn: Application access and refresh tokens</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/application-access-and-refresh-tokens/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/application-access-and-refresh-tokens/#Learn: Application access and refresh tokens</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Application access and refresh tokens can expose delegated access that may bypass a fresh password prompt.</description>
    </item>
    <item>
      <title>Learn: AWS EC2 instance-profile credentials</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/aws-ec2-instance-profile-credentials/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/aws-ec2-instance-profile-credentials/#Learn: AWS EC2 instance-profile credentials</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>AWS EC2 instance-profile credentials can expose temporary AWS access key, secret key and session token material associated with an instance role.</description>
    </item>
    <item>
      <title>Learn: Azure managed-identity access tokens</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/azure-managed-identity-access-tokens/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/azure-managed-identity-access-tokens/#Learn: Azure managed-identity access tokens</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Azure managed-identity access tokens can expose short-lived Microsoft Entra access tokens issued to an Azure managed identity.</description>
    </item>
    <item>
      <title>Learn: Browser cookies and session stores</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/browser-cookies-and-session-stores/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/browser-cookies-and-session-stores/#Learn: Browser cookies and session stores</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Browser cookies and session stores can expose authenticated web sessions and refresh state.</description>
    </item>
    <item>
      <title>Learn: Browser password databases</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/browser-password-databases/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/browser-password-databases/#Learn: Browser password databases</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Browser password databases can expose saved usernames and encrypted passwords.</description>
    </item>
    <item>
      <title>Learn: Cached domain credentials</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/cached-domain-credentials/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/cached-domain-credentials/#Learn: Cached domain credentials</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Cached domain credentials can expose offline domain logon verifiers and account context.</description>
    </item>
    <item>
      <title>Learn: CI/CD runner and pipeline secrets</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/ci-cd-runner-and-pipeline-secrets/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/ci-cd-runner-and-pipeline-secrets/#Learn: CI/CD runner and pipeline secrets</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>CI/CD runner and pipeline secrets can expose deployment keys, signing material and automation tokens.</description>
    </item>
    <item>
      <title>Learn: Cloud CLI credential caches and files</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/cloud-cli-credential-caches-and-files/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/cloud-cli-credential-caches-and-files/#Learn: Cloud CLI credential caches and files</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Cloud CLI credential caches and files can expose cloud access keys, refresh tokens and active profile context.</description>
    </item>
    <item>
      <title>Learn: Code-signing certificates and private keys</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/code-signing-certificates-and-private-keys/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/code-signing-certificates-and-private-keys/#Learn: Code-signing certificates and private keys</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Code-signing certificates and private keys can expose private keys that let software or packages appear to come from a trusted publisher.</description>
    </item>
    <item>
      <title>Learn: Container-mounted secrets and environment values</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/container-mounted-secrets-and-environment-values/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/container-mounted-secrets-and-environment-values/#Learn: Container-mounted secrets and environment values</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Container-mounted secrets and environment values can expose runtime credentials injected into workloads.</description>
    </item>
    <item>
      <title>Learn: Database backups and dumps</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/database-backups-and-dumps/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/database-backups-and-dumps/#Learn: Database backups and dumps</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Database backups and dumps can expose bulk application data, credentials and business records.</description>
    </item>
    <item>
      <title>Learn: Docker config.json and registry credentials</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/docker-configjson-and-registry-credentials/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/docker-configjson-and-registry-credentials/#Learn: Docker config.json and registry credentials</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Docker config.json and registry credentials can expose container registry credentials and helper references.</description>
    </item>
    <item>
      <title>Learn: DPAPI master keys and credential blobs</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/dpapi-master-keys-and-credential-blobs/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/dpapi-master-keys-and-credential-blobs/#Learn: DPAPI master keys and credential blobs</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>DPAPI master keys and credential blobs can expose keys and encrypted blobs used by Windows applications.</description>
    </item>
    <item>
      <title>Learn: Environment files and application configuration secrets</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/environment-files-and-application-configuration-secrets/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/environment-files-and-application-configuration-secrets/#Learn: Environment files and application configuration secrets</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Environment files and application configuration secrets can expose database strings, API keys, tokens and application secrets.</description>
    </item>
    <item>
      <title>Learn: /etc/shadow</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/etc-shadow/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/etc-shadow/#Learn: /etc/shadow</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>/etc/shadow can expose Linux password hashes and account ageing data.</description>
    </item>
    <item>
      <title>Learn: Git credential stores and personal access tokens</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/git-credential-stores-and-personal-access-tokens/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/git-credential-stores-and-personal-access-tokens/#Learn: Git credential stores and personal access tokens</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Git credential stores and personal access tokens can expose repository credentials and personal access tokens.</description>
    </item>
    <item>
      <title>Learn: Google Cloud service-account keys and workload tokens</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/google-cloud-service-account-keys-and-workload-tokens/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/google-cloud-service-account-keys-and-workload-tokens/#Learn: Google Cloud service-account keys and workload tokens</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Google Cloud service-account keys and workload tokens can expose Google Cloud private keys or temporary OAuth access tokens representing a service account.</description>
    </item>
    <item>
      <title>Learn: Group Policy Preferences cpassword</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/group-policy-preferences-cpassword/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/group-policy-preferences-cpassword/#Learn: Group Policy Preferences cpassword</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Group Policy Preferences cpassword can expose legacy encrypted passwords distributed through Group Policy Preferences.</description>
    </item>
    <item>
      <title>Learn: Kerberos ticket cache</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/kerberos-ticket-cache/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/kerberos-ticket-cache/#Learn: Kerberos ticket cache</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Kerberos ticket cache can expose TGTs and service tickets that can represent authenticated sessions.</description>
    </item>
    <item>
      <title>Learn: Kubernetes client certificates and private keys</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/kubernetes-client-certificates-and-private-keys/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/kubernetes-client-certificates-and-private-keys/#Learn: Kubernetes client certificates and private keys</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Kubernetes client certificates and private keys can expose client identity material that may authorise direct Kubernetes API access.</description>
    </item>
    <item>
      <title>Learn: Kubernetes kubeconfig</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/kubernetes-kubeconfig/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/kubernetes-kubeconfig/#Learn: Kubernetes kubeconfig</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Kubernetes kubeconfig can expose cluster endpoints, identities, certificates and bearer tokens.</description>
    </item>
    <item>
      <title>Learn: Kubernetes Secrets objects</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/kubernetes-secrets-objects/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/kubernetes-secrets-objects/#Learn: Kubernetes Secrets objects</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Kubernetes Secrets objects can expose application passwords, keys, certificates and tokens stored as Kubernetes Secret data.</description>
    </item>
    <item>
      <title>Learn: Kubernetes service account tokens</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/kubernetes-service-account-tokens/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/kubernetes-service-account-tokens/#Learn: Kubernetes service account tokens</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Kubernetes service account tokens can expose workload identity tokens and cluster API access.</description>
    </item>
    <item>
      <title>Learn: LSASS memory</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/lsass-memory/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/lsass-memory/#Learn: LSASS memory</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>LSASS memory can expose active logon sessions, tickets and credential material.</description>
    </item>
    <item>
      <title>Learn: macOS Keychain</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/macos-keychain/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/macos-keychain/#Learn: macOS Keychain</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>macOS Keychain can expose passwords, certificates, keys and application secrets.</description>
    </item>
    <item>
      <title>Learn: Network-device configuration backups</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/network-device-configuration-backups/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/network-device-configuration-backups/#Learn: Network-device configuration backups</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Network-device configuration backups can expose device credentials, addressing, routing, trust relationships and management policy.</description>
    </item>
    <item>
      <title>Learn: NTDS.dit</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/ntds-dit/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/ntds-dit/#Learn: NTDS.dit</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>NTDS.dit is the Active Directory database on a domain controller and contains credential-derived material for domain accounts.</description>
    </item>
    <item>
      <title>Learn: OT engineering-workstation project archives</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/ot-engineering-workstation-project-archives/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/ot-engineering-workstation-project-archives/#Learn: OT engineering-workstation project archives</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>OT engineering-workstation project archives can expose controller projects, tag databases, network layouts and device credentials used for industrial engineering.</description>
    </item>
    <item>
      <title>Learn: Package registry credentials</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/package-registry-credentials/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/package-registry-credentials/#Learn: Package registry credentials</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Package registry credentials can expose tokens and credentials used to publish or retrieve software packages.</description>
    </item>
    <item>
      <title>Learn: Password manager vaults</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/password-manager-vaults/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/password-manager-vaults/#Learn: Password manager vaults</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Password manager vaults can expose concentrated personal and enterprise credentials.</description>
    </item>
    <item>
      <title>Learn: PLC programs and logic backups</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/plc-programs-and-logic-backups/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/plc-programs-and-logic-backups/#Learn: PLC programs and logic backups</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>PLC programs and logic backups can expose approved control logic, tags, hardware configuration and process intent.</description>
    </item>
    <item>
      <title>Learn: Process memory and /proc environment data</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/process-memory-and-proc-environment-data/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/process-memory-and-proc-environment-data/#Learn: Process memory and /proc environment data</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Process memory and /proc environment data can expose runtime tokens, credentials and environment secrets.</description>
    </item>
    <item>
      <title>Learn: PST, OST and MBOX email stores</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/pst-ost-and-mbox-email-stores/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/pst-ost-and-mbox-email-stores/#Learn: PST, OST and MBOX email stores</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>PST, OST and MBOX email stores can expose cached or exported email, attachments, contacts and mailbox metadata.</description>
    </item>
    <item>
      <title>Learn: SAM hive</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/sam-hive/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/sam-hive/#Learn: SAM hive</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>SAM hive can expose local account password hashes and account metadata.</description>
    </item>
    <item>
      <title>Learn: SAML/OIDC signing keys and federation certificates</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/saml-oidc-signing-keys-and-federation-certificates/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/saml-oidc-signing-keys-and-federation-certificates/#Learn: SAML/OIDC signing keys and federation certificates</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>SAML/OIDC signing keys and federation certificates can expose keys that establish trust for federated identity assertions.</description>
    </item>
    <item>
      <title>Learn: Saved RDP credentials</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/saved-rdp-credentials/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/saved-rdp-credentials/#Learn: Saved RDP credentials</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Saved RDP credentials can expose credentials and target history for remote desktop access.</description>
    </item>
    <item>
      <title>Learn: SECURITY hive and LSA secrets</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/security-hive-and-lsa-secrets/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/security-hive-and-lsa-secrets/#Learn: SECURITY hive and LSA secrets</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>SECURITY hive and LSA secrets can expose service credentials, cached secrets and LSA-protected material.</description>
    </item>
    <item>
      <title>Learn: Shell history</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/shell-history/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/shell-history/#Learn: Shell history</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Shell history can expose commands that may expose credentials, targets and administrative actions.</description>
    </item>
    <item>
      <title>Learn: Source repositories containing secrets</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/source-repositories-containing-secrets/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/source-repositories-containing-secrets/#Learn: Source repositories containing secrets</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Source repositories containing secrets can expose credentials, endpoints, signing keys and deployment history.</description>
    </item>
    <item>
      <title>Learn: SSH agent sockets and forwarded identities</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/ssh-agent-sockets-and-forwarded-identities/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/ssh-agent-sockets-and-forwarded-identities/#Learn: SSH agent sockets and forwarded identities</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>SSH agent sockets and forwarded identities can expose live access to signing operations performed by keys held in an SSH agent.</description>
    </item>
    <item>
      <title>Learn: SSH private keys</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/ssh-private-keys/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/ssh-private-keys/#Learn: SSH private keys</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>SSH private keys can expose private keys that authenticate users and services.</description>
    </item>
    <item>
      <title>Learn: SYSTEM hive and boot key material</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/system-hive-and-boot-key-material/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/system-hive-and-boot-key-material/#Learn: SYSTEM hive and boot key material</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>SYSTEM hive and boot key material can expose system configuration and key material needed to protect other Windows stores.</description>
    </item>
    <item>
      <title>Learn: System-state and directory backups</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/system-state-and-directory-backups/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/system-state-and-directory-backups/#Learn: System-state and directory backups</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>System-state and directory backups can expose recoverable identity databases, registry state and keys.</description>
    </item>
    <item>
      <title>Learn: Terraform state files</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/terraform-state-files/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/terraform-state-files/#Learn: Terraform state files</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Terraform state files can expose deployed infrastructure values, resource identifiers and sometimes provider or application secrets.</description>
    </item>
    <item>
      <title>Learn: Unattended installation and Sysprep files</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/unattended-installation-and-sysprep-files/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/unattended-installation-and-sysprep-files/#Learn: Unattended installation and Sysprep files</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Unattended installation and Sysprep files can expose deployment credentials, product configuration and joining secrets.</description>
    </item>
    <item>
      <title>Learn: Vault tokens and response-wrapping tokens</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/vault-tokens-and-response-wrapping-tokens/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/vault-tokens-and-response-wrapping-tokens/#Learn: Vault tokens and response-wrapping tokens</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Vault tokens and response-wrapping tokens can expose bearer material that authorises Vault API operations or unwraps a protected response.</description>
    </item>
    <item>
      <title>Learn: VM snapshots and disk images</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/vm-snapshots-and-disk-images/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/vm-snapshots-and-disk-images/#Learn: VM snapshots and disk images</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>VM snapshots and disk images can expose complete machine state including files, memory and configuration.</description>
    </item>
    <item>
      <title>Learn: VPN profiles, client certificates and recovery material</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/vpn-profiles-client-certificates-and-recovery-material/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/vpn-profiles-client-certificates-and-recovery-material/#Learn: VPN profiles, client certificates and recovery material</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>VPN profiles, client certificates and recovery material can expose connection details and authentication material used to enter protected networks.</description>
    </item>
    <item>
      <title>Learn: Wi-Fi profiles</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/wi-fi-profiles/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/wi-fi-profiles/#Learn: Wi-Fi profiles</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Wi-Fi profiles can expose wireless network names, settings and sometimes recoverable keys.</description>
    </item>
    <item>
      <title>Learn: Windows Credential Manager and Vault</title>
      <link>https://welbournesecurity.com/blue-team/learn/artefacts/windows-credential-manager-and-vault/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/artefacts/windows-credential-manager-and-vault/#Learn: Windows Credential Manager and Vault</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Windows Credential Manager and Vault can expose saved application, network and web credentials.</description>
    </item>
    <item>
      <title>Learn: Port 20: FTP</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/20/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/20/#Learn: Port 20: FTP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 20 is commonly associated with FTP.</description>
    </item>
    <item>
      <title>Learn: Port 21: FTP</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/21/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/21/#Learn: Port 21: FTP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 21 is commonly associated with FTP.</description>
    </item>
    <item>
      <title>Learn: Port 22: SSH</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/22/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/22/#Learn: Port 22: SSH</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 22 is commonly associated with SSH.</description>
    </item>
    <item>
      <title>Learn: Port 23: Telnet</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/23/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/23/#Learn: Port 23: Telnet</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 23 is commonly associated with Telnet.</description>
    </item>
    <item>
      <title>Learn: Port 25: SMTP</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/25/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/25/#Learn: Port 25: SMTP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 25 is commonly associated with SMTP.</description>
    </item>
    <item>
      <title>Learn: Port 49: TACACS+</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/49/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/49/#Learn: Port 49: TACACS+</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 49 is commonly associated with TACACS+.</description>
    </item>
    <item>
      <title>Learn: Port 53: DNS</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/53/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/53/#Learn: Port 53: DNS</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 53 is commonly associated with DNS.</description>
    </item>
    <item>
      <title>Learn: Port 67: DHCP</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/67/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/67/#Learn: Port 67: DHCP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 67 is commonly associated with DHCP.</description>
    </item>
    <item>
      <title>Learn: Port 68: DHCP</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/68/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/68/#Learn: Port 68: DHCP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 68 is commonly associated with DHCP.</description>
    </item>
    <item>
      <title>Learn: Port 69: TFTP</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/69/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/69/#Learn: Port 69: TFTP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 69 is commonly associated with TFTP.</description>
    </item>
    <item>
      <title>Learn: Port 80: HTTP</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/80/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/80/#Learn: Port 80: HTTP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 80 is commonly associated with HTTP.</description>
    </item>
    <item>
      <title>Learn: Port 88: Kerberos</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/88/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/88/#Learn: Port 88: Kerberos</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 88 is commonly associated with Kerberos.</description>
    </item>
    <item>
      <title>Learn: Port 102: Siemens S7comm</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/102/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/102/#Learn: Port 102: Siemens S7comm</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 102 is commonly associated with Siemens S7comm.</description>
    </item>
    <item>
      <title>Learn: Port 110: POP3</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/110/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/110/#Learn: Port 110: POP3</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 110 is commonly associated with POP3.</description>
    </item>
    <item>
      <title>Learn: Port 111: rpcbind</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/111/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/111/#Learn: Port 111: rpcbind</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 111 is commonly associated with rpcbind.</description>
    </item>
    <item>
      <title>Learn: Port 123: NTP</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/123/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/123/#Learn: Port 123: NTP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 123 is commonly associated with NTP.</description>
    </item>
    <item>
      <title>Learn: Port 135: RPC/DCOM Endpoint Mapper</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/135/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/135/#Learn: Port 135: RPC/DCOM Endpoint Mapper</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 135 is commonly associated with RPC/DCOM Endpoint Mapper.</description>
    </item>
    <item>
      <title>Learn: Port 137: NetBIOS</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/137/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/137/#Learn: Port 137: NetBIOS</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 137 is commonly associated with NetBIOS.</description>
    </item>
    <item>
      <title>Learn: Port 138: NetBIOS</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/138/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/138/#Learn: Port 138: NetBIOS</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 138 is commonly associated with NetBIOS.</description>
    </item>
    <item>
      <title>Learn: Port 139: NetBIOS</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/139/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/139/#Learn: Port 139: NetBIOS</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 139 is commonly associated with NetBIOS.</description>
    </item>
    <item>
      <title>Learn: Port 143: IMAP</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/143/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/143/#Learn: Port 143: IMAP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 143 is commonly associated with IMAP.</description>
    </item>
    <item>
      <title>Learn: Port 161: SNMP</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/161/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/161/#Learn: Port 161: SNMP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 161 is commonly associated with SNMP.</description>
    </item>
    <item>
      <title>Learn: Port 162: SNMP</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/162/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/162/#Learn: Port 162: SNMP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 162 is commonly associated with SNMP.</description>
    </item>
    <item>
      <title>Learn: Port 179: BGP</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/179/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/179/#Learn: Port 179: BGP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 179 is commonly associated with BGP.</description>
    </item>
    <item>
      <title>Learn: Port 389: LDAP</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/389/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/389/#Learn: Port 389: LDAP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 389 is commonly associated with LDAP.</description>
    </item>
    <item>
      <title>Learn: Port 443: HTTPS/TLS, Encrypted DNS</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/443/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/443/#Learn: Port 443: HTTPS/TLS, Encrypted DNS</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 443 is commonly associated with HTTPS/TLS, Encrypted DNS.</description>
    </item>
    <item>
      <title>Learn: Port 445: SMB</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/445/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/445/#Learn: Port 445: SMB</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 445 is commonly associated with SMB.</description>
    </item>
    <item>
      <title>Learn: Port 464: Kerberos</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/464/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/464/#Learn: Port 464: Kerberos</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 464 is commonly associated with Kerberos.</description>
    </item>
    <item>
      <title>Learn: Port 465: SMTP</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/465/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/465/#Learn: Port 465: SMTP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 465 is commonly associated with SMTP.</description>
    </item>
    <item>
      <title>Learn: Port 500: IKE/IPsec</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/500/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/500/#Learn: Port 500: IKE/IPsec</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 500 is commonly associated with IKE/IPsec.</description>
    </item>
    <item>
      <title>Learn: Port 502: Modbus/TCP</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/502/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/502/#Learn: Port 502: Modbus/TCP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 502 is commonly associated with Modbus/TCP.</description>
    </item>
    <item>
      <title>Learn: Port 514: Syslog</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/514/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/514/#Learn: Port 514: Syslog</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 514 is commonly associated with Syslog.</description>
    </item>
    <item>
      <title>Learn: Port 546: DHCP</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/546/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/546/#Learn: Port 546: DHCP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 546 is commonly associated with DHCP.</description>
    </item>
    <item>
      <title>Learn: Port 547: DHCP</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/547/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/547/#Learn: Port 547: DHCP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 547 is commonly associated with DHCP.</description>
    </item>
    <item>
      <title>Learn: Port 587: SMTP</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/587/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/587/#Learn: Port 587: SMTP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 587 is commonly associated with SMTP.</description>
    </item>
    <item>
      <title>Learn: Port 623: IPMI/RMCP</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/623/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/623/#Learn: Port 623: IPMI/RMCP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 623 is associated with IPMI/RMCP in the documented deployment model.</description>
    </item>
    <item>
      <title>Learn: Port 636: LDAP</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/636/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/636/#Learn: Port 636: LDAP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 636 is commonly associated with LDAP.</description>
    </item>
    <item>
      <title>Learn: Port 853: Encrypted DNS</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/853/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/853/#Learn: Port 853: Encrypted DNS</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 853 is commonly associated with Encrypted DNS.</description>
    </item>
    <item>
      <title>Learn: Port 873: rsync</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/873/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/873/#Learn: Port 873: rsync</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 873 is commonly associated with rsync.</description>
    </item>
    <item>
      <title>Learn: Port 989: FTPS</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/989/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/989/#Learn: Port 989: FTPS</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 989 is commonly associated with FTPS.</description>
    </item>
    <item>
      <title>Learn: Port 990: FTPS</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/990/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/990/#Learn: Port 990: FTPS</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 990 is commonly associated with FTPS.</description>
    </item>
    <item>
      <title>Learn: Port 993: IMAP</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/993/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/993/#Learn: Port 993: IMAP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 993 is commonly associated with IMAP.</description>
    </item>
    <item>
      <title>Learn: Port 995: POP3</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/995/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/995/#Learn: Port 995: POP3</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 995 is commonly associated with POP3.</description>
    </item>
    <item>
      <title>Learn: Port 1194: OpenVPN</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/1194/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/1194/#Learn: Port 1194: OpenVPN</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 1194 is commonly associated with OpenVPN.</description>
    </item>
    <item>
      <title>Learn: Port 1433: Microsoft SQL Server</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/1433/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/1433/#Learn: Port 1433: Microsoft SQL Server</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 1433 is commonly associated with Microsoft SQL Server.</description>
    </item>
    <item>
      <title>Learn: Port 1434: Microsoft SQL Server</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/1434/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/1434/#Learn: Port 1434: Microsoft SQL Server</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 1434 is commonly associated with Microsoft SQL Server.</description>
    </item>
    <item>
      <title>Learn: Port 1521: Oracle Net</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/1521/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/1521/#Learn: Port 1521: Oracle Net</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 1521 is commonly associated with Oracle Net.</description>
    </item>
    <item>
      <title>Learn: Port 1645: RADIUS</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/1645/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/1645/#Learn: Port 1645: RADIUS</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 1645 is commonly associated with RADIUS.</description>
    </item>
    <item>
      <title>Learn: Port 1646: RADIUS</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/1646/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/1646/#Learn: Port 1646: RADIUS</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 1646 is commonly associated with RADIUS.</description>
    </item>
    <item>
      <title>Learn: Port 1812: RADIUS</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/1812/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/1812/#Learn: Port 1812: RADIUS</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 1812 is commonly associated with RADIUS.</description>
    </item>
    <item>
      <title>Learn: Port 1813: RADIUS</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/1813/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/1813/#Learn: Port 1813: RADIUS</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 1813 is commonly associated with RADIUS.</description>
    </item>
    <item>
      <title>Learn: Port 1883: MQTT</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/1883/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/1883/#Learn: Port 1883: MQTT</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 1883 is commonly associated with MQTT.</description>
    </item>
    <item>
      <title>Learn: Port 2049: NFS</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/2049/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/2049/#Learn: Port 2049: NFS</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 2049 is commonly associated with NFS.</description>
    </item>
    <item>
      <title>Learn: Port 2181: Apache ZooKeeper client</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/2181/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/2181/#Learn: Port 2181: Apache ZooKeeper client</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 2181 is associated with Apache ZooKeeper client in the documented deployment model.</description>
    </item>
    <item>
      <title>Learn: Port 2222: EtherNet/IP</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/2222/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/2222/#Learn: Port 2222: EtherNet/IP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 2222 is commonly associated with EtherNet/IP.</description>
    </item>
    <item>
      <title>Learn: Port 2375: Docker Engine API</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/2375/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/2375/#Learn: Port 2375: Docker Engine API</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 2375 is commonly associated with Docker Engine API.</description>
    </item>
    <item>
      <title>Learn: Port 2376: Docker Engine API</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/2376/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/2376/#Learn: Port 2376: Docker Engine API</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 2376 is commonly associated with Docker Engine API.</description>
    </item>
    <item>
      <title>Learn: Port 2377: Docker Swarm management</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/2377/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/2377/#Learn: Port 2377: Docker Swarm management</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 2377 is associated with Docker Swarm management in the documented deployment model.</description>
    </item>
    <item>
      <title>Learn: Port 2379: etcd</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/2379/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/2379/#Learn: Port 2379: etcd</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 2379 is commonly associated with etcd.</description>
    </item>
    <item>
      <title>Learn: Port 2380: etcd</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/2380/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/2380/#Learn: Port 2380: etcd</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 2380 is commonly associated with etcd.</description>
    </item>
    <item>
      <title>Learn: Port 2404: IEC 60870-5-104</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/2404/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/2404/#Learn: Port 2404: IEC 60870-5-104</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 2404 is commonly associated with IEC 60870-5-104.</description>
    </item>
    <item>
      <title>Learn: Port 2888: Apache ZooKeeper quorum</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/2888/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/2888/#Learn: Port 2888: Apache ZooKeeper quorum</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 2888 is associated with Apache ZooKeeper quorum in the documented deployment model.</description>
    </item>
    <item>
      <title>Learn: Port 3128: HTTP proxy</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/3128/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/3128/#Learn: Port 3128: HTTP proxy</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 3128 is commonly associated with HTTP proxy.</description>
    </item>
    <item>
      <title>Learn: Port 3260: iSCSI</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/3260/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/3260/#Learn: Port 3260: iSCSI</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 3260 is commonly associated with iSCSI.</description>
    </item>
    <item>
      <title>Learn: Port 3268: Global Catalog</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/3268/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/3268/#Learn: Port 3268: Global Catalog</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 3268 is commonly associated with Global Catalog.</description>
    </item>
    <item>
      <title>Learn: Port 3269: Global Catalog</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/3269/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/3269/#Learn: Port 3269: Global Catalog</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 3269 is commonly associated with Global Catalog.</description>
    </item>
    <item>
      <title>Learn: Port 3306: MySQL/MariaDB</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/3306/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/3306/#Learn: Port 3306: MySQL/MariaDB</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 3306 is commonly associated with MySQL/MariaDB.</description>
    </item>
    <item>
      <title>Learn: Port 3389: RDP</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/3389/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/3389/#Learn: Port 3389: RDP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 3389 is commonly associated with RDP.</description>
    </item>
    <item>
      <title>Learn: Port 3888: Apache ZooKeeper leader election</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/3888/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/3888/#Learn: Port 3888: Apache ZooKeeper leader election</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 3888 is associated with Apache ZooKeeper leader election in the documented deployment model.</description>
    </item>
    <item>
      <title>Learn: Port 4222: NATS client</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/4222/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/4222/#Learn: Port 4222: NATS client</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 4222 is associated with NATS client in the documented deployment model.</description>
    </item>
    <item>
      <title>Learn: Port 4500: IKE/IPsec</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/4500/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/4500/#Learn: Port 4500: IKE/IPsec</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 4500 is commonly associated with IKE/IPsec.</description>
    </item>
    <item>
      <title>Learn: Port 4789: VXLAN and Docker overlay traffic</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/4789/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/4789/#Learn: Port 4789: VXLAN and Docker overlay traffic</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 4789 is associated with VXLAN and Docker overlay traffic in the documented deployment model.</description>
    </item>
    <item>
      <title>Learn: Port 4840: OPC UA</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/4840/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/4840/#Learn: Port 4840: OPC UA</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 4840 is commonly associated with OPC UA.</description>
    </item>
    <item>
      <title>Learn: Port 5000: Docker Registry</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/5000/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/5000/#Learn: Port 5000: Docker Registry</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 5000 is associated with Docker Registry in the documented deployment model.</description>
    </item>
    <item>
      <title>Learn: Port 5060: SIP</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/5060/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/5060/#Learn: Port 5060: SIP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 5060 is commonly associated with SIP.</description>
    </item>
    <item>
      <title>Learn: Port 5061: SIP</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/5061/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/5061/#Learn: Port 5061: SIP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 5061 is commonly associated with SIP.</description>
    </item>
    <item>
      <title>Learn: Port 5353: mDNS</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/5353/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/5353/#Learn: Port 5353: mDNS</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 5353 is commonly associated with mDNS.</description>
    </item>
    <item>
      <title>Learn: Port 5355: LLMNR</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/5355/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/5355/#Learn: Port 5355: LLMNR</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 5355 is commonly associated with LLMNR.</description>
    </item>
    <item>
      <title>Learn: Port 5432: PostgreSQL</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/5432/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/5432/#Learn: Port 5432: PostgreSQL</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 5432 is commonly associated with PostgreSQL.</description>
    </item>
    <item>
      <title>Learn: Port 5671: AMQP/RabbitMQ</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/5671/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/5671/#Learn: Port 5671: AMQP/RabbitMQ</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 5671 is commonly associated with AMQP/RabbitMQ.</description>
    </item>
    <item>
      <title>Learn: Port 5672: AMQP/RabbitMQ</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/5672/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/5672/#Learn: Port 5672: AMQP/RabbitMQ</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 5672 is commonly associated with AMQP/RabbitMQ.</description>
    </item>
    <item>
      <title>Learn: Port 5900: VNC</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/5900/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/5900/#Learn: Port 5900: VNC</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 5900 is commonly associated with VNC.</description>
    </item>
    <item>
      <title>Learn: Port 5985: WinRM/WS-Man</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/5985/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/5985/#Learn: Port 5985: WinRM/WS-Man</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 5985 is commonly associated with WinRM/WS-Man.</description>
    </item>
    <item>
      <title>Learn: Port 5986: WinRM/WS-Man</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/5986/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/5986/#Learn: Port 5986: WinRM/WS-Man</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 5986 is commonly associated with WinRM/WS-Man.</description>
    </item>
    <item>
      <title>Learn: Port 6379: Redis</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/6379/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/6379/#Learn: Port 6379: Redis</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 6379 is commonly associated with Redis.</description>
    </item>
    <item>
      <title>Learn: Port 6443: Kubernetes API</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/6443/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/6443/#Learn: Port 6443: Kubernetes API</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 6443 is commonly associated with Kubernetes API.</description>
    </item>
    <item>
      <title>Learn: Port 6514: Syslog</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/6514/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/6514/#Learn: Port 6514: Syslog</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 6514 is commonly associated with Syslog.</description>
    </item>
    <item>
      <title>Learn: Port 7946: Docker Swarm node communication</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/7946/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/7946/#Learn: Port 7946: Docker Swarm node communication</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 7946 is associated with Docker Swarm node communication in the documented deployment model.</description>
    </item>
    <item>
      <title>Learn: Port 8080: HTTP, HTTP proxy</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/8080/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/8080/#Learn: Port 8080: HTTP, HTTP proxy</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 8080 is commonly associated with HTTP, HTTP proxy.</description>
    </item>
    <item>
      <title>Learn: Port 8200: HashiCorp Vault API</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/8200/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/8200/#Learn: Port 8200: HashiCorp Vault API</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 8200 is associated with HashiCorp Vault API in the documented deployment model.</description>
    </item>
    <item>
      <title>Learn: Port 8201: HashiCorp Vault cluster</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/8201/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/8201/#Learn: Port 8201: HashiCorp Vault cluster</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 8201 is associated with HashiCorp Vault cluster in the documented deployment model.</description>
    </item>
    <item>
      <title>Learn: Port 8300: Consul server RPC</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/8300/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/8300/#Learn: Port 8300: Consul server RPC</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 8300 is associated with Consul server RPC in the documented deployment model.</description>
    </item>
    <item>
      <title>Learn: Port 8301: Consul LAN gossip</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/8301/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/8301/#Learn: Port 8301: Consul LAN gossip</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 8301 is associated with Consul LAN gossip in the documented deployment model.</description>
    </item>
    <item>
      <title>Learn: Port 8302: Consul WAN gossip</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/8302/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/8302/#Learn: Port 8302: Consul WAN gossip</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 8302 is associated with Consul WAN gossip in the documented deployment model.</description>
    </item>
    <item>
      <title>Learn: Port 8500: Consul HTTP API</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/8500/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/8500/#Learn: Port 8500: Consul HTTP API</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 8500 is associated with Consul HTTP API in the documented deployment model.</description>
    </item>
    <item>
      <title>Learn: Port 8600: Consul DNS</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/8600/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/8600/#Learn: Port 8600: Consul DNS</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 8600 is associated with Consul DNS in the documented deployment model.</description>
    </item>
    <item>
      <title>Learn: Port 8883: MQTT</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/8883/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/8883/#Learn: Port 8883: MQTT</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 8883 is commonly associated with MQTT.</description>
    </item>
    <item>
      <title>Learn: Port 9042: Apache Cassandra CQL</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/9042/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/9042/#Learn: Port 9042: Apache Cassandra CQL</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 9042 is associated with Apache Cassandra CQL in the documented deployment model.</description>
    </item>
    <item>
      <title>Learn: Port 9090: Prometheus</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/9090/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/9090/#Learn: Port 9090: Prometheus</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 9090 is associated with Prometheus in the documented deployment model.</description>
    </item>
    <item>
      <title>Learn: Port 9092: Apache Kafka broker</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/9092/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/9092/#Learn: Port 9092: Apache Kafka broker</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 9092 is associated with Apache Kafka broker in the documented deployment model.</description>
    </item>
    <item>
      <title>Learn: Port 9200: Elasticsearch</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/9200/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/9200/#Learn: Port 9200: Elasticsearch</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 9200 is commonly associated with Elasticsearch.</description>
    </item>
    <item>
      <title>Learn: Port 9300: Elasticsearch</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/9300/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/9300/#Learn: Port 9300: Elasticsearch</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 9300 is commonly associated with Elasticsearch.</description>
    </item>
    <item>
      <title>Learn: Port 9389: Active Directory Web Services</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/9389/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/9389/#Learn: Port 9389: Active Directory Web Services</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 9389 is commonly associated with Active Directory Web Services.</description>
    </item>
    <item>
      <title>Learn: Port 9418: Git protocol</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/9418/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/9418/#Learn: Port 9418: Git protocol</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 9418 is commonly associated with Git protocol.</description>
    </item>
    <item>
      <title>Learn: Port 10250: kubelet</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/10250/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/10250/#Learn: Port 10250: kubelet</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 10250 is commonly associated with kubelet.</description>
    </item>
    <item>
      <title>Learn: Port 10256: Kubernetes kube-proxy</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/10256/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/10256/#Learn: Port 10256: Kubernetes kube-proxy</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 10256 is associated with Kubernetes kube-proxy in the documented deployment model.</description>
    </item>
    <item>
      <title>Learn: Port 10257: Kubernetes controller manager</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/10257/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/10257/#Learn: Port 10257: Kubernetes controller manager</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 10257 is associated with Kubernetes controller manager in the documented deployment model.</description>
    </item>
    <item>
      <title>Learn: Port 10259: Kubernetes scheduler</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/10259/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/10259/#Learn: Port 10259: Kubernetes scheduler</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 10259 is associated with Kubernetes scheduler in the documented deployment model.</description>
    </item>
    <item>
      <title>Learn: Port 11211: Memcached</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/11211/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/11211/#Learn: Port 11211: Memcached</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 11211 is associated with Memcached in the documented deployment model.</description>
    </item>
    <item>
      <title>Learn: Port 15672: AMQP/RabbitMQ</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/15672/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/15672/#Learn: Port 15672: AMQP/RabbitMQ</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 15672 is commonly associated with AMQP/RabbitMQ.</description>
    </item>
    <item>
      <title>Learn: Port 20000: DNP3</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/20000/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/20000/#Learn: Port 20000: DNP3</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 20000 is commonly associated with DNP3.</description>
    </item>
    <item>
      <title>Learn: Port 27017: MongoDB</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/27017/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/27017/#Learn: Port 27017: MongoDB</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 27017 is commonly associated with MongoDB.</description>
    </item>
    <item>
      <title>Learn: Port 30000-32767: Kubernetes NodePort services</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/30000-32767/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/30000-32767/#Learn: Port 30000-32767: Kubernetes NodePort services</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 30000-32767 is associated with Kubernetes NodePort services in the documented deployment model.</description>
    </item>
    <item>
      <title>Learn: Port 34962-34964: PROFINET</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/34962-34964/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/34962-34964/#Learn: Port 34962-34964: PROFINET</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 34962-34964 is associated with PROFINET in the documented deployment model.</description>
    </item>
    <item>
      <title>Learn: Port 44818: EtherNet/IP</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/44818/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/44818/#Learn: Port 44818: EtherNet/IP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 44818 is commonly associated with EtherNet/IP.</description>
    </item>
    <item>
      <title>Learn: Port 47808: BACnet/IP</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/47808/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/47808/#Learn: Port 47808: BACnet/IP</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 47808 is commonly associated with BACnet/IP.</description>
    </item>
    <item>
      <title>Learn: Port 49152-65535: RPC/DCOM Endpoint Mapper</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/49152-65535/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/49152-65535/#Learn: Port 49152-65535: RPC/DCOM Endpoint Mapper</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 49152-65535 is commonly associated with RPC/DCOM Endpoint Mapper.</description>
    </item>
    <item>
      <title>Learn: Port 51820: WireGuard</title>
      <link>https://welbournesecurity.com/blue-team/learn/ports/51820/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/ports/51820/#Learn: Port 51820: WireGuard</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Port 51820 is commonly associated with WireGuard.</description>
    </item>
    <item>
      <title>Learn collection: Active Directory and Windows Identity</title>
      <link>https://welbournesecurity.com/blue-team/learn/collections/active-directory-and-windows-identity/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/collections/active-directory-and-windows-identity/#Learn collection: Active Directory and Windows Identity</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Understand the services, credential stores and attack paths that shape Windows enterprise identity.</description>
    </item>
    <item>
      <title>Learn collection: Endpoint and DFIR</title>
      <link>https://welbournesecurity.com/blue-team/learn/collections/endpoint-and-dfir/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/collections/endpoint-and-dfir/#Learn collection: Endpoint and DFIR</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Connect endpoint behaviour, valuable local artefacts and investigation evidence across Windows, Linux and macOS.</description>
    </item>
    <item>
      <title>Learn collection: Network and Remote Access</title>
      <link>https://welbournesecurity.com/blue-team/learn/collections/network-and-remote-access/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/collections/network-and-remote-access/#Learn collection: Network and Remote Access</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Move from ports and protocols to the identities, devices and attacks visible across network boundaries.</description>
    </item>
    <item>
      <title>Learn collection: Web and API Security</title>
      <link>https://welbournesecurity.com/blue-team/learn/collections/web-and-api-security/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/collections/web-and-api-security/#Learn collection: Web and API Security</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Follow web requests, identity tokens and application flaws from normal service behaviour to defensive evidence.</description>
    </item>
    <item>
      <title>Learn collection: Cloud Identity and Workloads</title>
      <link>https://welbournesecurity.com/blue-team/learn/collections/cloud-identity-and-workloads/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/collections/cloud-identity-and-workloads/#Learn collection: Cloud Identity and Workloads</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Understand cloud control planes, workload identities, metadata services and the credentials attackers seek.</description>
    </item>
    <item>
      <title>Learn collection: Containers and Kubernetes</title>
      <link>https://welbournesecurity.com/blue-team/learn/collections/containers-and-kubernetes/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/collections/containers-and-kubernetes/#Learn collection: Containers and Kubernetes</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Connect cluster services, runtime trust, orchestration attacks and high-value container credentials.</description>
    </item>
    <item>
      <title>Learn collection: Linux and macOS</title>
      <link>https://welbournesecurity.com/blue-team/learn/collections/linux-and-macos/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/collections/linux-and-macos/#Learn collection: Linux and macOS</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Study Unix-like remote access, persistence, credential stores and investigation evidence.</description>
    </item>
    <item>
      <title>Learn collection: OT and ICS</title>
      <link>https://welbournesecurity.com/blue-team/learn/collections/ot-and-ics/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/learn/collections/ot-and-ics/#Learn collection: OT and ICS</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Understand industrial protocols, engineering trust and attacks that can affect a physical process.</description>
    </item>
    <item>
      <title>Tool Hunting: Hunting Cobalt Strike</title>
      <link>https://welbournesecurity.com/blue-team/tool-hunting/cobalt-strike/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/tool-hunting/cobalt-strike/#Tool Hunting: Hunting Cobalt Strike</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>A practical analyst guide for turning Beacon configuration, packet captures and process memory into a defensible C2 investigation.</description>
    </item>
    <item>
      <title>Fundamentals: From URL to Pixels</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/browser-request/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/browser-request/#Fundamentals: From URL to Pixels</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Follow a browser navigation from the address bar through name resolution, network transport, web infrastructure and the rendering pipeline.</description>
    </item>
    <item>
      <title>Fundamentals: From Power Button to Desktop</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/power-on-and-sign-in/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/power-on-and-sign-in/#Fundamentals: From Power Button to Desktop</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Follow electrical reset, firmware, trusted boot, kernel start, network readiness and Windows sign-in until Explorer owns the interactive desktop.</description>
    </item>
    <item>
      <title>Fundamentals: From Wi-Fi to VPN</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/wifi-and-vpn/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/wifi-and-vpn/#Fundamentals: From Wi-Fi to VPN</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Follow a Windows device from radio discovery and Wi-Fi authentication through IP configuration, VPN policy, tunnel keys and protected application traffic.</description>
    </item>
    <item>
      <title>Fundamentals: From Send to Inbox</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/email-delivery/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/email-delivery/#Fundamentals: From Send to Inbox</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Follow a message from the compose window through MIME construction, authenticated submission, DNS routing, filtering, mailbox storage and recipient synchronisation.</description>
    </item>
    <item>
      <title>Fundamentals: From Network Path to Open File</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/network-file-access/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/network-file-access/#Fundamentals: From Network Path to Open File</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Follow a UNC path through the Windows redirector, name resolution, SMB negotiation, authentication, authorisation, caching and file I/O.</description>
    </item>
    <item>
      <title>Fundamentals: URL input and navigation</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/browser-request/url-navigation/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/browser-request/url-navigation/#Fundamentals: URL input and navigation</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>See how the browser interprets address-bar input, parses a URL and starts a cross-document navigation.</description>
    </item>
    <item>
      <title>Fundamentals: Browser state, cache and policy</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/browser-request/browser-state-and-policy/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/browser-request/browser-state-and-policy/#Fundamentals: Browser state, cache and policy</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Understand the local decisions that can satisfy, alter or stop a request before a new network connection exists.</description>
    </item>
    <item>
      <title>Fundamentals: DNS resolution in the browser</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/browser-request/dns-resolution/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/browser-request/dns-resolution/#Fundamentals: DNS resolution in the browser</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Trace a hostname through local caches, resolvers, recursive queries and authoritative answers without assuming every lookup uses port 53.</description>
    </item>
    <item>
      <title>Fundamentals: Local network and encapsulation</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/browser-request/local-network-and-encapsulation/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/browser-request/local-network-and-encapsulation/#Fundamentals: Local network and encapsulation</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Follow an IP packet through route selection, neighbour discovery and the Ethernet or Wi-Fi frame used on the local link.</description>
    </item>
    <item>
      <title>Fundamentals: Network path and enterprise controls</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/browser-request/network-path-and-enterprise-controls/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/browser-request/network-path-and-enterprise-controls/#Fundamentals: Network path and enterprise controls</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Compare home routing with proxy, VPN, secure-web-gateway, firewall, NAT, BGP and CDN decisions in a managed network.</description>
    </item>
    <item>
      <title>Fundamentals: TCP or QUIC transport</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/browser-request/tcp-and-quic/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/browser-request/tcp-and-quic/#Fundamentals: TCP or QUIC transport</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Compare TCP connection establishment with QUIC over UDP, including reliability, multiplexing, reuse and fallback.</description>
    </item>
    <item>
      <title>Fundamentals: TLS and certificate validation</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/browser-request/tls-and-certificate-validation/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/browser-request/tls-and-certificate-validation/#Fundamentals: TLS and certificate validation</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Follow TLS 1.3 from ClientHello through certificate validation, key establishment, ALPN and protected application data.</description>
    </item>
    <item>
      <title>Fundamentals: HTTP request and response</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/browser-request/http-request-and-response/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/browser-request/http-request-and-response/#Fundamentals: HTTP request and response</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Read the same HTTP semantics across text-based HTTP/1.1, framed HTTP/2 and QUIC-carried HTTP/3.</description>
    </item>
    <item>
      <title>Fundamentals: Edge, origin and application processing</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/browser-request/edge-origin-and-application/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/browser-request/edge-origin-and-application/#Fundamentals: Edge, origin and application processing</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Follow a request through CDN, WAF, reverse proxy, load balancer, web server, application, cache and database components.</description>
    </item>
    <item>
      <title>Fundamentals: Navigation commit and security boundaries</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/browser-request/navigation-commit-and-security-boundaries/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/browser-request/navigation-commit-and-security-boundaries/#Fundamentals: Navigation commit and security boundaries</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>See how the browser accepts a response, chooses a renderer, commits a document and enforces origin and process boundaries.</description>
    </item>
    <item>
      <title>Fundamentals: Browser rendering pipeline</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/browser-request/browser-rendering-pipeline/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/browser-request/browser-rendering-pipeline/#Fundamentals: Browser rendering pipeline</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Turn streamed HTML, CSS, scripts and images into layout, paint records, rasterised tiles and composed pixels.</description>
    </item>
    <item>
      <title>Fundamentals: Evidence and troubleshooting</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/browser-request/evidence-and-troubleshooting/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/browser-request/evidence-and-troubleshooting/#Fundamentals: Evidence and troubleshooting</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Correlate browser, endpoint, DNS, network, proxy, edge and application records to find the stage that diverged.</description>
    </item>
    <item>
      <title>Fundamentals: Power, reset and the CPU reset vector</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/power-on-and-sign-in/power-reset-and-reset-vector/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/power-on-and-sign-in/power-reset-and-reset-vector/#Fundamentals: Power, reset and the CPU reset vector</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Trace the electrical and processor state changes that move a PC from mechanical power-off to its first firmware instruction.</description>
    </item>
    <item>
      <title>Fundamentals: UEFI, POST and device enumeration</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/power-on-and-sign-in/uefi-post-and-device-enumeration/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/power-on-and-sign-in/uefi-post-and-device-enumeration/#Fundamentals: UEFI, POST and device enumeration</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>See how UEFI discovers memory and devices, executes early diagnostics and builds the firmware view of the machine.</description>
    </item>
    <item>
      <title>Fundamentals: TPM measured boot and Secure Boot</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/power-on-and-sign-in/tpm-measured-boot-and-secure-boot/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/power-on-and-sign-in/tpm-measured-boot-and-secure-boot/#Fundamentals: TPM measured boot and Secure Boot</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Separate signature enforcement from measurement and follow the evidence that forms the platform boot trust chain.</description>
    </item>
    <item>
      <title>Fundamentals: Boot manager and operating-system loader</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/power-on-and-sign-in/boot-manager-and-os-loader/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/power-on-and-sign-in/boot-manager-and-os-loader/#Fundamentals: Boot manager and operating-system loader</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Follow UEFI from its boot entry into Windows Boot Manager and the loader that prepares the kernel image.</description>
    </item>
    <item>
      <title>Fundamentals: Kernel initialisation and memory management</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/power-on-and-sign-in/kernel-initialisation-and-memory/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/power-on-and-sign-in/kernel-initialisation-and-memory/#Fundamentals: Kernel initialisation and memory management</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>See how ntoskrnl.exe takes ownership of processors, virtual memory, interrupts, objects and the first system processes.</description>
    </item>
    <item>
      <title>Fundamentals: Drivers, Plug and Play, storage and filesystems</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/power-on-and-sign-in/drivers-pnp-storage-filesystems/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/power-on-and-sign-in/drivers-pnp-storage-filesystems/#Fundamentals: Drivers, Plug and Play, storage and filesystems</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Trace how Windows binds devices to drivers, mounts volumes and makes the system disk available through the I/O stack.</description>
    </item>
    <item>
      <title>Fundamentals: Windows session and service startup</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/power-on-and-sign-in/windows-session-and-service-startup/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/power-on-and-sign-in/windows-session-and-service-startup/#Fundamentals: Windows session and service startup</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Follow smss.exe, csrss.exe, wininit.exe and services.exe as Windows creates sessions and starts configured services.</description>
    </item>
    <item>
      <title>Fundamentals: Network interface and link readiness</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/power-on-and-sign-in/network-interface-and-link-readiness/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/power-on-and-sign-in/network-interface-and-link-readiness/#Fundamentals: Network interface and link readiness</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>See how the NIC driver, NDIS and link technology move an interface from discovered hardware to a usable local link.</description>
    </item>
    <item>
      <title>Fundamentals: IP addressing, routes and neighbour discovery</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/power-on-and-sign-in/ip-addressing-routes-neighbours/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/power-on-and-sign-in/ip-addressing-routes-neighbours/#Fundamentals: IP addressing, routes and neighbour discovery</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Follow DHCP or IPv6 autoconfiguration into address selection, routing-table state and the local next-hop mapping.</description>
    </item>
    <item>
      <title>Fundamentals: DNS, time and domain-controller location</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/power-on-and-sign-in/dns-time-and-dc-location/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/power-on-and-sign-in/dns-time-and-dc-location/#Fundamentals: DNS, time and domain-controller location</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Trace the DNS SRV lookups, site awareness and time checks a domain member uses before authentication.</description>
    </item>
    <item>
      <title>Fundamentals: Machine account and secure channel</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/power-on-and-sign-in/machine-account-and-secure-channel/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/power-on-and-sign-in/machine-account-and-secure-channel/#Fundamentals: Machine account and secure channel</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>See how a domain member proves its computer identity and maintains the Netlogon secure channel used by domain operations.</description>
    </item>
    <item>
      <title>Fundamentals: Credential Provider, Winlogon and secure attention sequence</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/power-on-and-sign-in/credential-provider-winlogon-sas/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/power-on-and-sign-in/credential-provider-winlogon-sas/#Fundamentals: Credential Provider, Winlogon and secure attention sequence</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Follow Ctrl+Alt+Delete, LogonUI and the credential provider boundary before authentication reaches LSASS.</description>
    </item>
    <item>
      <title>Fundamentals: LSASS authentication and access-token creation</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/power-on-and-sign-in/lsass-authentication-and-access-token/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/power-on-and-sign-in/lsass-authentication-and-access-token/#Fundamentals: LSASS authentication and access-token creation</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Trace local, Microsoft-account and domain credentials through authentication packages into a Windows logon session and access token.</description>
    </item>
    <item>
      <title>Fundamentals: User profile, Group Policy and desktop shell</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/power-on-and-sign-in/user-profile-group-policy-desktop/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/power-on-and-sign-in/user-profile-group-policy-desktop/#Fundamentals: User profile, Group Policy and desktop shell</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Follow userinit.exe through profile loading, policy processing, logon scripts and the launch of explorer.exe.</description>
    </item>
    <item>
      <title>Fundamentals: Wireless hardware, driver and radio</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/wifi-and-vpn/wireless-hardware-driver-radio/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/wifi-and-vpn/wireless-hardware-driver-radio/#Fundamentals: Wireless hardware, driver and radio</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Trace a Wi-Fi request from the Windows WLAN service through NDIS and the adapter into a selected radio channel.</description>
    </item>
    <item>
      <title>Fundamentals: Scanning, beacon and probe frames</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/wifi-and-vpn/scanning-beacons-probes/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/wifi-and-vpn/scanning-beacons-probes/#Fundamentals: Scanning, beacon and probe frames</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Compare passive beacon listening with active probe exchanges and inspect the information elements that describe a wireless network.</description>
    </item>
    <item>
      <title>Fundamentals: 802.11 authentication and association</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/wifi-and-vpn/authentication-and-association/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/wifi-and-vpn/authentication-and-association/#Fundamentals: 802.11 authentication and association</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Follow the management-frame exchange that creates a Wi-Fi link before WPA or IP configuration completes.</description>
    </item>
    <item>
      <title>Fundamentals: WPA2, WPA3 and key establishment</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/wifi-and-vpn/wpa2-wpa3-key-establishment/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/wifi-and-vpn/wpa2-wpa3-key-establishment/#Fundamentals: WPA2, WPA3 and key establishment</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>See how personal Wi-Fi turns a passphrase or SAE exchange into per-session keys and protected data frames.</description>
    </item>
    <item>
      <title>Fundamentals: 802.1X, EAP and RADIUS</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/wifi-and-vpn/8021x-eap-radius/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/wifi-and-vpn/8021x-eap-radius/#Fundamentals: 802.1X, EAP and RADIUS</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Follow enterprise Wi-Fi identity from the supplicant through the access point to the RADIUS policy server.</description>
    </item>
    <item>
      <title>Fundamentals: IPv4 and IPv6 configuration</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/wifi-and-vpn/ipv4-ipv6-configuration/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/wifi-and-vpn/ipv4-ipv6-configuration/#Fundamentals: IPv4 and IPv6 configuration</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Trace DHCP, router advertisements and duplicate-address checks into a usable dual-stack interface.</description>
    </item>
    <item>
      <title>Fundamentals: ARP, neighbour discovery, routing and DNS</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/wifi-and-vpn/arp-nd-routing-dns/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/wifi-and-vpn/arp-nd-routing-dns/#Fundamentals: ARP, neighbour discovery, routing and DNS</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Follow an application name from resolver choice through route selection and next-hop link-layer resolution.</description>
    </item>
    <item>
      <title>Fundamentals: Captive portals and connectivity checks</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/wifi-and-vpn/captive-portals-connectivity-checks/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/wifi-and-vpn/captive-portals-connectivity-checks/#Fundamentals: Captive portals and connectivity checks</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>See how Windows distinguishes local Wi-Fi association from Internet access and how a portal redirects unauthenticated clients.</description>
    </item>
    <item>
      <title>Fundamentals: VPN identity, policy and route selection</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/wifi-and-vpn/vpn-identity-policy-routes/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/wifi-and-vpn/vpn-identity-policy-routes/#Fundamentals: VPN identity, policy and route selection</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Trace a VPN profile from user or device identity through policy checks into full-tunnel or split-tunnel route intent.</description>
    </item>
    <item>
      <title>Fundamentals: VPN handshake, keys and virtual adapter creation</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/wifi-and-vpn/vpn-handshake-keys-adapter/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/wifi-and-vpn/vpn-handshake-keys-adapter/#Fundamentals: VPN handshake, keys and virtual adapter creation</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Follow tunnel negotiation from the physical interface to authenticated keys and a virtual network interface.</description>
    </item>
    <item>
      <title>Fundamentals: Tunnel traffic, DNS, MTU and evidence</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/wifi-and-vpn/tunnel-traffic-dns-mtu-evidence/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/wifi-and-vpn/tunnel-traffic-dns-mtu-evidence/#Fundamentals: Tunnel traffic, DNS, MTU and evidence</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Open the nested packet, route and resolver state that governs traffic after the VPN connects.</description>
    </item>
    <item>
      <title>Fundamentals: Compose, draft and local state</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/email-delivery/compose-draft-local-state/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/email-delivery/compose-draft-local-state/#Fundamentals: Compose, draft and local state</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>See how an email client represents recipients, body content and attachments before any submission starts.</description>
    </item>
    <item>
      <title>Fundamentals: Mailbox session, identity and OAuth</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/email-delivery/mailbox-session-identity-oauth/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/email-delivery/mailbox-session-identity-oauth/#Fundamentals: Mailbox session, identity and OAuth</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Trace a modern mail client from cached account state through token acquisition to an authorised mailbox session.</description>
    </item>
    <item>
      <title>Fundamentals: Message format, MIME and attachments</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/email-delivery/message-format-mime-attachments/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/email-delivery/message-format-mime-attachments/#Fundamentals: Message format, MIME and attachments</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Open the message envelope and content tree that turn rich text, alternative bodies and files into Internet Message Format bytes.</description>
    </item>
    <item>
      <title>Fundamentals: Submission-service discovery</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/email-delivery/submission-service-discovery/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/email-delivery/submission-service-discovery/#Fundamentals: Submission-service discovery</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>See how a client finds the right mailbox or SMTP submission endpoint before it sends message content.</description>
    </item>
    <item>
      <title>Fundamentals: SMTP submission, TLS and authentication</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/email-delivery/smtp-submission-tls-authentication/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/email-delivery/smtp-submission-tls-authentication/#Fundamentals: SMTP submission, TLS and authentication</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Follow EHLO, STARTTLS, authentication and the SMTP envelope from a client to a submission server.</description>
    </item>
    <item>
      <title>Fundamentals: Queues, DNS MX and recipient routing</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/email-delivery/queues-dns-mx-recipient-routing/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/email-delivery/queues-dns-mx-recipient-routing/#Fundamentals: Queues, DNS MX and recipient routing</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Trace an accepted message through queue selection, recipient-domain lookup and next-hop calculation.</description>
    </item>
    <item>
      <title>Fundamentals: Server-to-server SMTP and transport security</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/email-delivery/server-to-server-smtp-transport-security/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/email-delivery/server-to-server-smtp-transport-security/#Fundamentals: Server-to-server SMTP and transport security</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Follow Internet mail between autonomous servers and separate opportunistic encryption from authenticated routing policy.</description>
    </item>
    <item>
      <title>Fundamentals: SPF, DKIM and DMARC</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/email-delivery/spf-dkim-dmarc/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/email-delivery/spf-dkim-dmarc/#Fundamentals: SPF, DKIM and DMARC</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Separate source authorisation, message signatures and domain-alignment policy during receiving-mail evaluation.</description>
    </item>
    <item>
      <title>Fundamentals: Gateway filtering, scanning and sandboxing</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/email-delivery/gateway-filtering-scanning-sandboxing/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/email-delivery/gateway-filtering-scanning-sandboxing/#Fundamentals: Gateway filtering, scanning and sandboxing</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Trace message, attachment and URL evidence through layered mail-security decisions before mailbox delivery.</description>
    </item>
    <item>
      <title>Fundamentals: Mailbox delivery, storage and indexing</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/email-delivery/mailbox-delivery-storage-indexing/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/email-delivery/mailbox-delivery-storage-indexing/#Fundamentals: Mailbox delivery, storage and indexing</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Follow the accepted message into mailbox folders, metadata tables, quotas and search indexes.</description>
    </item>
    <item>
      <title>Fundamentals: Synchronisation, notifications, rendering and evidence</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/email-delivery/sync-notifications-rendering-evidence/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/email-delivery/sync-notifications-rendering-evidence/#Fundamentals: Synchronisation, notifications, rendering and evidence</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Trace a delivered item into the recipient client, local cache and rendered message while preserving cross-system correlation.</description>
    </item>
    <item>
      <title>Fundamentals: Path parsing, UNC paths and DFS</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/network-file-access/path-parsing-unc-dfs/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/network-file-access/path-parsing-unc-dfs/#Fundamentals: Path parsing, UNC paths and DFS</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>See how Windows separates a local path, a UNC server-share path and a DFS namespace before network I/O begins.</description>
    </item>
    <item>
      <title>Fundamentals: Client redirector, VFS and local cache</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/network-file-access/client-redirector-vfs-cache/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/network-file-access/client-redirector-vfs-cache/#Fundamentals: Client redirector, VFS and local cache</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Trace a file open from the Windows I/O Manager through the SMB redirector and Client-Side Caching decisions.</description>
    </item>
    <item>
      <title>Fundamentals: Name resolution, site and server discovery</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/network-file-access/name-resolution-site-server-discovery/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/network-file-access/name-resolution-site-server-discovery/#Fundamentals: Name resolution, site and server discovery</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Follow a UNC hostname or DFS namespace through DNS, suffix search, Active Directory site logic and referral selection.</description>
    </item>
    <item>
      <title>Fundamentals: Routing, transport and port 445</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/network-file-access/routing-transport-port-445/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/network-file-access/routing-transport-port-445/#Fundamentals: Routing, transport and port 445</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Trace the selected file server through route lookup, neighbour resolution and TCP connection establishment to SMB Direct Hosting.</description>
    </item>
    <item>
      <title>Fundamentals: SMB negotiation, signing and encryption</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/network-file-access/smb-negotiation-signing-encryption/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/network-file-access/smb-negotiation-signing-encryption/#Fundamentals: SMB negotiation, signing and encryption</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Inspect SMB2 NEGOTIATE fields, dialect choice, capabilities and pre-authentication protection before user authentication.</description>
    </item>
    <item>
      <title>Fundamentals: Session setup, SPNEGO, Kerberos and NTLM</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/network-file-access/session-setup-spnego-kerberos-ntlm/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/network-file-access/session-setup-spnego-kerberos-ntlm/#Fundamentals: Session setup, SPNEGO, Kerberos and NTLM</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Follow SMB SESSION_SETUP through protocol negotiation into Kerberos service-ticket or NTLM challenge-response authentication.</description>
    </item>
    <item>
      <title>Fundamentals: Tree connect, shares and namespaces</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/network-file-access/tree-connect-shares-namespaces/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/network-file-access/tree-connect-shares-namespaces/#Fundamentals: Tree connect, shares and namespaces</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>See how an authenticated SMB session attaches to a named share and turns a relative path into a server-side namespace.</description>
    </item>
    <item>
      <title>Fundamentals: Access tokens, share permissions and ACLs</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/network-file-access/access-tokens-share-permissions-acls/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/network-file-access/access-tokens-share-permissions-acls/#Fundamentals: Access tokens, share permissions and ACLs</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Follow an SMB request through share checks, NTFS security descriptors and the effective access decision.</description>
    </item>
    <item>
      <title>Fundamentals: File open, leases, oplocks, I/O and close</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/network-file-access/file-open-leases-oplocks-io-close/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/network-file-access/file-open-leases-oplocks-io-close/#Fundamentals: File open, leases, oplocks, I/O and close</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Trace SMB CREATE through durable handles, caching leases, reads, writes, flushes and final close semantics.</description>
    </item>
    <item>
      <title>Fundamentals: Audit evidence, failures and troubleshooting</title>
      <link>https://welbournesecurity.com/blue-team/fundamentals/network-file-access/audit-failures-troubleshooting/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/fundamentals/network-file-access/audit-failures-troubleshooting/#Fundamentals: Audit evidence, failures and troubleshooting</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Correlate client, DNS, Kerberos, SMB, server and filesystem evidence to find the first divergent state.</description>
    </item>
    <item>
      <title>Scenario Lab: Power-on to an enterprise website</title>
      <link>https://welbournesecurity.com/blue-team/scenario-lab/power-on-to-enterprise-website/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/scenario-lab/power-on-to-enterprise-website/#Scenario Lab: Power-on to an enterprise website</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description>Trace a managed PC from electrical reset through firmware, network and domain identity to DNS, BGP, TLS, WAF, application and database.</description>
    </item>
    <item>
      <title>Scenario Lab: Windows domain sign-in and Group Policy</title>
      <link>https://welbournesecurity.com/blue-team/scenario-lab/windows-domain-sign-in/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/scenario-lab/windows-domain-sign-in/#Scenario Lab: Windows domain sign-in and Group Policy</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description>Follow DC discovery, machine trust, user authentication, access-token creation and policy application on a Windows endpoint.</description>
    </item>
    <item>
      <title>Scenario Lab: Linux boot to an exposed service</title>
      <link>https://welbournesecurity.com/blue-team/scenario-lab/linux-boot-to-service/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/scenario-lab/linux-boot-to-service/#Scenario Lab: Linux boot to an exposed service</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description>Trace a Linux server from firmware and kernel initialisation through systemd dependencies to a listening and logged network service.</description>
    </item>
    <item>
      <title>Scenario Lab: VM provisioning and monitoring</title>
      <link>https://welbournesecurity.com/blue-team/scenario-lab/vm-provisioning-and-monitoring/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/scenario-lab/vm-provisioning-and-monitoring/#Scenario Lab: VM provisioning and monitoring</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description>Provision a virtual machine through the management plane, virtual network, approved image and security-control bootstrap.</description>
    </item>
    <item>
      <title>Scenario Lab: Wired enterprise onboarding</title>
      <link>https://welbournesecurity.com/blue-team/scenario-lab/wired-enterprise-onboarding/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/scenario-lab/wired-enterprise-onboarding/#Scenario Lab: Wired enterprise onboarding</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description>Connect a new managed device through link state, 802.1X, RADIUS policy, DHCP, DNS and domain discovery.</description>
    </item>
    <item>
      <title>Scenario Lab: Corporate Wi-Fi and 802.1X</title>
      <link>https://welbournesecurity.com/blue-team/scenario-lab/corporate-wifi-and-8021x/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/scenario-lab/corporate-wifi-and-8021x/#Scenario Lab: Corporate Wi-Fi and 802.1X</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description>Join an enterprise wireless network, validate RADIUS identity and recognise an evil-twin diversion.</description>
    </item>
    <item>
      <title>Scenario Lab: Remote worker through VPN to SaaS</title>
      <link>https://welbournesecurity.com/blue-team/scenario-lab/remote-worker-vpn-to-saas/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/scenario-lab/remote-worker-vpn-to-saas/#Scenario Lab: Remote worker through VPN to SaaS</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description>Trace device posture, MFA, VPN routes and DNS through federated SaaS authentication and session audit.</description>
    </item>
    <item>
      <title>Scenario Lab: Mobile enrolment and corporate email</title>
      <link>https://welbournesecurity.com/blue-team/scenario-lab/mobile-enrolment-and-email/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/scenario-lab/mobile-enrolment-and-email/#Scenario Lab: Mobile enrolment and corporate email</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description>Follow a mobile device through MDM enrolment, compliance, certificate-backed access, SaaS identity and mailbox activity.</description>
    </item>
    <item>
      <title>Scenario Lab: Internal client through proxy, NAT, firewalls and BGP</title>
      <link>https://welbournesecurity.com/blue-team/scenario-lab/internal-client-to-internet/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/scenario-lab/internal-client-to-internet/#Scenario Lab: Internal client through proxy, NAT, firewalls and BGP</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description>Separate local forwarding, enterprise policy and external route selection on a normal outbound web session.</description>
    </item>
    <item>
      <title>Scenario Lab: Public user through DNS, CDN, WAF and load balancer</title>
      <link>https://welbournesecurity.com/blue-team/scenario-lab/public-user-to-web-application/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/scenario-lab/public-user-to-web-application/#Scenario Lab: Public user through DNS, CDN, WAF and load balancer</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description>Trace a public request through authoritative DNS, Internet routing, TLS and edge security to a selected application backend.</description>
    </item>
    <item>
      <title>Scenario Lab: Email authentication and delivery</title>
      <link>https://welbournesecurity.com/blue-team/scenario-lab/email-authentication-and-delivery/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/scenario-lab/email-authentication-and-delivery/#Scenario Lab: Email authentication and delivery</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description>Follow message submission, DNS-based sender authentication, filtering, delivery and mailbox audit evidence.</description>
    </item>
    <item>
      <title>Scenario Lab: Branch routing failure</title>
      <link>https://welbournesecurity.com/blue-team/scenario-lab/branch-routing-failure/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/scenario-lab/branch-routing-failure/#Scenario Lab: Branch routing failure</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description>Diagnose link, OSPF, BGP, DNS and time dependencies without assuming every outage is an attack.</description>
    </item>
    <item>
      <title>Scenario Lab: Web session to database</title>
      <link>https://welbournesecurity.com/blue-team/scenario-lab/web-session-to-database/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/scenario-lab/web-session-to-database/#Scenario Lab: Web session to database</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description>Follow browser identity, session state, application authorisation, parameterised queries and database audit evidence.</description>
    </item>
    <item>
      <title>Scenario Lab: Abused API and cloud token</title>
      <link>https://welbournesecurity.com/blue-team/scenario-lab/abused-api-cloud-token/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/scenario-lab/abused-api-cloud-token/#Scenario Lab: Abused API and cloud token</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description>Investigate a stolen cloud token crossing gateway, service authorisation and data-access boundaries.</description>
    </item>
    <item>
      <title>Scenario Lab: CI/CD image to Kubernetes</title>
      <link>https://welbournesecurity.com/blue-team/scenario-lab/cicd-to-kubernetes/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/scenario-lab/cicd-to-kubernetes/#Scenario Lab: CI/CD image to Kubernetes</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description>Trace source and dependencies through a trusted build, registry admission, cluster identity and runtime telemetry.</description>
    </item>
    <item>
      <title>Scenario Lab: Backup failure and ransomware recovery</title>
      <link>https://welbournesecurity.com/blue-team/scenario-lab/backup-failure-and-ransomware-recovery/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/scenario-lab/backup-failure-and-ransomware-recovery/#Scenario Lab: Backup failure and ransomware recovery</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description>Contain active ransomware safely, protect identity and backup control planes, determine clean scope and restore validated services in dependency order.</description>
    </item>
    <item>
      <title>Scenario Lab: Alert through SIEM, SOAR and case queue</title>
      <link>https://welbournesecurity.com/blue-team/scenario-lab/alert-to-case/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/scenario-lab/alert-to-case/#Scenario Lab: Alert through SIEM, SOAR and case queue</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description>Trace raw telemetry through collection, parsing, enrichment and detection into accountable analyst triage.</description>
    </item>
    <item>
      <title>Scenario Lab: Phishing and BEC triage</title>
      <link>https://welbournesecurity.com/blue-team/scenario-lab/phishing-and-bec-triage/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/scenario-lab/phishing-and-bec-triage/#Scenario Lab: Phishing and BEC triage</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description>Preserve a suspicious message, trace delivery and authentication, prove user action, scope identity impact and choose proportionate containment.</description>
    </item>
    <item>
      <title>Scenario Lab: Malware execution, persistence and C2</title>
      <link>https://welbournesecurity.com/blue-team/scenario-lab/malware-persistence-and-c2/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/scenario-lab/malware-persistence-and-c2/#Scenario Lab: Malware execution, persistence and C2</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description>Build a process and network timeline from initial execution through persistence and command-and-control.</description>
    </item>
    <item>
      <title>Scenario Lab: Kerberos, NTLM and LDAP identity compromise</title>
      <link>https://welbournesecurity.com/blue-team/scenario-lab/kerberos-ntlm-ldap-compromise/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/scenario-lab/kerberos-ntlm-ldap-compromise/#Scenario Lab: Kerberos, NTLM and LDAP identity compromise</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description>Separate ticketing, compatibility authentication and directory access while investigating credential and privilege abuse.</description>
    </item>
    <item>
      <title>Scenario Lab: Vulnerability to risk treatment and remediation</title>
      <link>https://welbournesecurity.com/blue-team/scenario-lab/vulnerability-to-remediation/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/scenario-lab/vulnerability-to-remediation/#Scenario Lab: Vulnerability to risk treatment and remediation</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description>Move from a scanner finding to validated exposure, business impact, treatment, control testing and residual risk.</description>
    </item>
    <item>
      <title>Scenario Lab: Evil twin and DNS poisoning</title>
      <link>https://welbournesecurity.com/blue-team/scenario-lab/evil-twin-and-dns-poisoning/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/scenario-lab/evil-twin-and-dns-poisoning/#Scenario Lab: Evil twin and DNS poisoning</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description>Investigate a wireless lookalike, weak server validation, rogue DHCP and poisoned name resolution.</description>
    </item>
    <item>
      <title>Scenario Lab: Data exfiltration and privacy response</title>
      <link>https://welbournesecurity.com/blue-team/scenario-lab/data-exfiltration-and-privacy-response/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/scenario-lab/data-exfiltration-and-privacy-response/#Scenario Lab: Data exfiltration and privacy response</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description>Correlate identity, data and network evidence, contain safely and translate technical scope into privacy and partner decisions.</description>
    </item>
    <item>
      <title>Scenario Lab: Third-party incident and collection gaps</title>
      <link>https://welbournesecurity.com/blue-team/scenario-lab/third-party-incident-and-collection-gaps/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/blue-team/scenario-lab/third-party-incident-and-collection-gaps/#Scenario Lab: Third-party incident and collection gaps</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description>Scope a supplier compromise when direct telemetry is incomplete and reporting duties cross organisational boundaries.</description>
    </item>
    <item>
      <title>Writeup: h4cked</title>
      <link>https://welbournesecurity.com/writeups/thm/purple/thm-h4cked/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/purple/thm-h4cked/#Writeup: h4cked</guid>
      <pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe room using a packet capture to reconstruct an FTP compromise, identify the attacker's web shell path, then replay the intrusion to recover the root flag.</description>
    </item>
    <item>
      <title>Writeup: Reversing ELF</title>
      <link>https://welbournesecurity.com/writeups/thm/purple/thm-reversing-elf/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/purple/thm-reversing-elf/#Writeup: Reversing ELF</guid>
      <pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe beginner reverse-engineering room solving a set of ELF crackmes with execution, strings, Ghidra, Cutter, base64 decoding, XOR, and simple argument checks.</description>
    </item>
    <item>
      <title>Writeup: Lockdown</title>
      <link>https://welbournesecurity.com/writeups/thm/blue/thm-lockdown/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/blue/thm-lockdown/#Writeup: Lockdown</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe AI security room investigating Bastion, an internal assistant with vulnerable retrieval controls, unsafe logging, and broken user-level access isolation.</description>
    </item>
    <item>
      <title>Writeup: Monday Monitor</title>
      <link>https://welbournesecurity.com/writeups/thm/blue/thm-mondaymonitor/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/blue/thm-mondaymonitor/#Writeup: Monday Monitor</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe endpoint monitoring room using Wazuh and Sysmon logs to trace initial access, scheduled task persistence, user creation, credential dumping, and data exfiltration.</description>
    </item>
    <item>
      <title>Writeup: PS Eclipse</title>
      <link>https://welbournesecurity.com/writeups/thm/blue/thm-posheclipse/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/blue/thm-posheclipse/#Writeup: PS Eclipse</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe Splunk investigation room tracing a suspected ransomware incident through PowerShell download activity, scheduled task privilege escalation, C2 callbacks, and BlackSun ransomware IOCs.</description>
    </item>
    <item>
      <title>Writeup: Snapped Phish-ing Line</title>
      <link>https://welbournesecurity.com/writeups/thm/blue/thm-snappedphishingline/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/blue/thm-snappedphishingline/#Writeup: Snapped Phish-ing Line</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe phishing investigation room analysing malicious emails, redirection URLs, an exposed phishing kit, captured credentials, VirusTotal results, and a decoded flag.</description>
    </item>
    <item>
      <title>Writeup: TShark Challenge I - Teamwork</title>
      <link>https://welbournesecurity.com/writeups/thm/blue/thm-tsharkchallenge1-teamwork/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/blue/thm-tsharkchallenge1-teamwork/#Writeup: TShark Challenge I - Teamwork</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe network forensics room using TShark to investigate DNS traffic, identify a suspicious phishing domain, pivot through VirusTotal, and extract an email address from a PCAP.</description>
    </item>
    <item>
      <title>Writeup: TShark Challenge II - Directory</title>
      <link>https://welbournesecurity.com/writeups/thm/blue/thm-tsharkchallenge2-directory/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/blue/thm-tsharkchallenge2-directory/#Writeup: TShark Challenge II - Directory</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe network forensics room using TShark to investigate directory-index browsing, identify a suspicious domain, export HTTP objects, and validate a downloaded executable in VirusTotal.</description>
    </item>
    <item>
      <title>Writeup: Warzone 1</title>
      <link>https://welbournesecurity.com/writeups/thm/blue/thm-warzone1/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/blue/thm-warzone1/#Writeup: Warzone 1</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe SOC triage room investigating an IDS alert with Brim, Wireshark, NetworkMiner, and VirusTotal to confirm malware command and control activity.</description>
    </item>
    <item>
      <title>Writeup: Warzone 2</title>
      <link>https://welbournesecurity.com/writeups/thm/blue/thm-warzone2/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/blue/thm-warzone2/#Writeup: Warzone 2</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe SOC triage room investigating IDS alerts for a network trojan, privacy-policy violations, malicious downloads, and related suspicious infrastructure.</description>
    </item>
    <item>
      <title>Writeup: Checkpoint</title>
      <link>https://welbournesecurity.com/writeups/thm/purple/thm-checkpoint/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/purple/thm-checkpoint/#Writeup: Checkpoint</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe AI security assessment room reviewing four deployment candidates, identifying Candidate A's supply-chain failures, and making the production deployment call.</description>
    </item>
    <item>
      <title>Writeup: Compiled</title>
      <link>https://welbournesecurity.com/writeups/thm/purple/thm-compiled/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/purple/thm-compiled/#Writeup: Compiled</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe reverse-engineering room using Ghidra to inspect a Linux binary, understand scanf input parsing, and recover the required password.</description>
    </item>
    <item>
      <title>Writeup: Sakura Room</title>
      <link>https://welbournesecurity.com/writeups/thm/purple/thm-sakura/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/purple/thm-sakura/#Writeup: Sakura Room</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe OSINT room using source inspection, username pivoting, GitHub history, PGP metadata, blockchain lookup, social media, WiGLE, and travel geolocation.</description>
    </item>
    <item>
      <title>Writeup: Searchlight - IMINT</title>
      <link>https://welbournesecurity.com/writeups/thm/purple/thm-searchlight-imint/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/purple/thm-searchlight-imint/#Writeup: Searchlight - IMINT</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe OSINT room covering imagery intelligence, geolocation, Google dorking, reverse image search, street view checks, and video frame analysis.</description>
    </item>
    <item>
      <title>Writeup: AI Threat Modelling Assessment</title>
      <link>https://welbournesecurity.com/writeups/thm/blue/thm-aithreatmodellingassessment/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/blue/thm-aithreatmodellingassessment/#Writeup: AI Threat Modelling Assessment</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe assessment room testing AI threat modelling knowledge through an interactive application and two completion flags.</description>
    </item>
    <item>
      <title>Writeup: Disgruntled</title>
      <link>https://welbournesecurity.com/writeups/thm/blue/thm-disgruntled/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/blue/thm-disgruntled/#Writeup: Disgruntled</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe Linux forensics room investigating a disgruntled IT user's privileged commands, account creation, script staging, cron persistence, and logic bomb.</description>
    </item>
    <item>
      <title>Writeup: Hide and Seek</title>
      <link>https://welbournesecurity.com/writeups/thm/blue/thm-hideandseek/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/blue/thm-hideandseek/#Writeup: Hide and Seek</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe Linux live-system forensics room uncovering multiple post-compromise persistence mechanisms and reconstructing a split flag from encoded artefacts.</description>
    </item>
    <item>
      <title>Writeup: Infinity Shell</title>
      <link>https://welbournesecurity.com/writeups/thm/blue/thm-infinityshell/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/blue/thm-infinityshell/#Writeup: Infinity Shell</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe webshell forensics room investigating a PHP implant, tracing attacker query strings, and decoding a base64 payload to recover the flag.</description>
    </item>
    <item>
      <title>Writeup: Invite Only</title>
      <link>https://welbournesecurity.com/writeups/thm/blue/thm-inviteonly/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/blue/thm-inviteonly/#Writeup: Invite Only</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe SOC threat-intelligence room pivoting from a flagged IP and SHA256 hash to malware family, dropped files, phishing technique, and campaign reporting.</description>
    </item>
    <item>
      <title>Writeup: Juicy Details</title>
      <link>https://welbournesecurity.com/writeups/thm/blue/thm-juicydetails/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/blue/thm-juicydetails/#Writeup: Juicy Details</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe SOC log-analysis room investigating attacker reconnaissance, brute forcing, SQL injection, file retrieval, and shell access against a Juice Shop environment.</description>
    </item>
    <item>
      <title>Writeup: Letter</title>
      <link>https://welbournesecurity.com/writeups/thm/blue/thm-letter/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/blue/thm-letter/#Writeup: Letter</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe OSINT room using a damaged envelope, handwritten note, and newspaper clipping to identify a historic Penmarc'h rescue figure.</description>
    </item>
    <item>
      <title>Writeup: Memory Forensics</title>
      <link>https://welbournesecurity.com/writeups/thm/blue/thm-memoryforensics/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/blue/thm-memoryforensics/#Writeup: Memory Forensics</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe memory forensics room using Volatility to identify profiles, dump and crack Windows hashes, recover console activity, find shutdown time, and extract a TrueCrypt passphrase.</description>
    </item>
    <item>
      <title>Writeup: Missing Person</title>
      <link>https://welbournesecurity.com/writeups/thm/blue/thm-missingperson/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/blue/thm-missingperson/#Writeup: Missing Person</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe OSINT room using image search, event research, EXIF metadata, social media, and public business details to trace a missing person's travel trail.</description>
    </item>
    <item>
      <title>Writeup: Mr. Phisher</title>
      <link>https://welbournesecurity.com/writeups/thm/blue/thm-mrphisher/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/blue/thm-mrphisher/#Writeup: Mr. Phisher</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe phishing analysis room focused on extracting and decoding a flag hidden inside a macro-enabled Word document attachment.</description>
    </item>
    <item>
      <title>Writeup: Payload</title>
      <link>https://welbournesecurity.com/writeups/thm/blue/thm-payload/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/blue/thm-payload/#Writeup: Payload</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe supply-chain incident room investigating a backdoored ML model, outbound beaconing, and a staged candidate model containing the second half of the campaign ID.</description>
    </item>
    <item>
      <title>Writeup: Phishing Emails 5</title>
      <link>https://welbournesecurity.com/writeups/thm/blue/thm-phishingemails5/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/blue/thm-phishingemails5/#Writeup: Phishing Emails 5</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe phishing analysis room focused on investigating an email sample through headers, sender artifacts, SPF and DMARC checks, attachment hashing, and VirusTotal.</description>
    </item>
    <item>
      <title>Writeup: Shadow Trace</title>
      <link>https://welbournesecurity.com/writeups/thm/blue/thm-shadowtrace/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/blue/thm-shadowtrace/#Writeup: Shadow Trace</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe malware triage room analysing a suspicious Windows updater, extracting IOCs, decoding hidden clues, and correlating EDR alert payloads.</description>
    </item>
    <item>
      <title>Writeup: Sneaky Patch</title>
      <link>https://welbournesecurity.com/writeups/thm/blue/thm-sneakypatch/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/blue/thm-sneakypatch/#Writeup: Sneaky Patch</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe Linux forensics room investigating a suspicious kernel module and recovering a hidden flag from a backdoored `.ko` file.</description>
    </item>
    <item>
      <title>Writeup: Stolen Mount</title>
      <link>https://welbournesecurity.com/writeups/thm/blue/thm-stolenmount/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/blue/thm-stolenmount/#Writeup: Stolen Mount</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe packet forensics room analysing NFS traffic, extracting stolen files from a PCAP, cracking an archive password, and recovering a QR-code flag.</description>
    </item>
    <item>
      <title>Writeup: Confidential</title>
      <link>https://welbournesecurity.com/writeups/thm/blue/thm-confidential/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/blue/thm-confidential/#Writeup: Confidential</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe PDF forensics room focused on uncovering an obscured QR code and decoding it to retrieve the hidden invite flag.</description>
    </item>
    <item>
      <title>Writeup: Committed</title>
      <link>https://welbournesecurity.com/writeups/thm/blue/thm-committed/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/blue/thm-committed/#Writeup: Committed</guid>
      <pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe Git forensics room focused on recovering a sensitive flag from repository history after it was removed in a later commit.</description>
    </item>
    <item>
      <title>Writeup: Disk Analysis &amp; Autopsy</title>
      <link>https://welbournesecurity.com/writeups/thm/blue/thm-disk-analysis-autopsy/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/blue/thm-disk-analysis-autopsy/#Writeup: Disk Analysis &amp; Autopsy</guid>
      <pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe forensic analysis room using Autopsy to investigate a Windows disk image, recover system details, user activity, network artifacts, tools, and flags.</description>
    </item>
    <item>
      <title>Writeup: Investigating Windows</title>
      <link>https://welbournesecurity.com/writeups/thm/blue/thm-investigatingwindows/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/blue/thm-investigatingwindows/#Writeup: Investigating Windows</guid>
      <pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe Windows forensics room investigating a previously compromised Windows Server host through RDP, account activity, scheduled tasks, logs, network artifacts, and web shell evidence.</description>
    </item>
    <item>
      <title>Writeup: Summit</title>
      <link>https://welbournesecurity.com/writeups/thm/blue/thm-summit/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/blue/thm-summit/#Writeup: Summit</guid>
      <pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe purple-team detection engineering challenge using the Pyramid of Pain to detect malware through hashes, IPs, domains, host artifacts, tool behavior, and attacker procedures.</description>
    </item>
    <item>
      <title>Writeup: Crack the Hash</title>
      <link>https://welbournesecurity.com/writeups/thm/red/thm-crackthehash/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/red/thm-crackthehash/#Writeup: Crack the Hash</guid>
      <pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe hash cracking room covering common hashes, CrackStation lookups, and Hashcat modes for bcrypt, SHA-512 crypt, and salted SHA1.</description>
    </item>
    <item>
      <title>Writeup: ToolsRus</title>
      <link>https://welbournesecurity.com/writeups/thm/red/thm-toolsrus/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/red/thm-toolsrus/#Writeup: ToolsRus</guid>
      <pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe room using Feroxbuster, Hydra, Nmap, Nikto, and Metasploit to enumerate and exploit an exposed Apache Tomcat Manager instance.</description>
    </item>
    <item>
      <title>Writeup: Chill Hack</title>
      <link>https://welbournesecurity.com/writeups/thm/red/thm-chillhack/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/red/thm-chillhack/#Writeup: Chill Hack</guid>
      <pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe boot-to-root room covering FTP enumeration, web command injection, reverse shells, and Linux privilege escalation.</description>
    </item>
    <item>
      <title>Writeup: Archangel</title>
      <link>https://welbournesecurity.com/writeups/thm/red/thm-archangel/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/red/thm-archangel/#Writeup: Archangel</guid>
      <pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe boot-to-root room covering hostname discovery, local file inclusion, log poisoning, callback shell access, and Linux privilege escalation.</description>
    </item>
    <item>
      <title>Writeup: Blue</title>
      <link>https://welbournesecurity.com/writeups/thm/red/thm-blue/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/red/thm-blue/#Writeup: Blue</guid>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe beginner Windows exploitation room focused on SMB enumeration, MS17-010 EternalBlue exploitation, Meterpreter migration, hash dumping, and flag discovery.</description>
    </item>
    <item>
      <title>Writeup: Footprinting Lab</title>
      <link>https://welbournesecurity.com/writeups/htb/htb-footprinting/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/htb/htb-footprinting/#Writeup: Footprinting Lab</guid>
      <pubDate>Sun, 05 Apr 2026 00:00:00 GMT</pubDate>
      <description>Hack The Box Academy footprinting lab focused on careful service enumeration, FTP access, SSH key discovery, and retrieving the proof flag.</description>
    </item>
    <item>
      <title>Writeup: Lofi</title>
      <link>https://welbournesecurity.com/writeups/thm/red/thm-lofi/</link>
      <guid isPermaLink="false">https://welbournesecurity.com/writeups/thm/red/thm-lofi/#Writeup: Lofi</guid>
      <pubDate>Sun, 05 Apr 2026 00:00:00 GMT</pubDate>
      <description>TryHackMe beginner web room demonstrating local file inclusion through a vulnerable page parameter to read the flag from the filesystem.</description>
    </item>
  </channel>
</rss>
