If you work in a SOC
For SOC analysts, detection engineers and incident responders. A five-minute morning brief, then threat intelligence from the big response teams, then the shows about detection and investigation craft.
- 01
Morning brief, under 10 minutes
The SANS Internet Storm Center handlers on what they saw overnight. The closest thing to a shift handover in audio.
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
Five to eight minutes every weekday morning on what the SANS honeypots and handlers saw overnight.
Listen if you work in a SOC or run infrastructure and need to know what to patch today.
solodaily<30m - 02
Threat intelligence from a big response team
Microsoft's threat researchers on the actors they track. Vendor-run, and it says so, but the access to the research is real.
Microsoft Threat Intelligence Podcast
Elliot Volkman
Microsoft's own threat hunters on the Blizzards, Typhoons, and crime crews they track, plus the takedowns they run.
Listen if you work in a SOC or CTI team and want the analyst story behind Microsoft's threat reports.
interviewbiweekly30–60m - 03
Incident response from the responders
Mandiant and Google Threat Intelligence on campaigns they investigated, with dwell times and remediation detail.
The Defender's Advantage Podcast
Luke McNamara
Mandiant and Google Threat Intelligence Group analysts on the intrusions they responded to, in 30 tight minutes.
Listen if you do incident response or threat hunting and want lessons from Mandiant engagements.
interviewirregular30–60m - 04
Blue team craft
SANS instructors on building and running a defense program, with long practical episodes.
Blueprint: Build the Best in Cyber Defense
John Hubbard
SANS's blue team show: long, teaching-first conversations on running a SOC, from metrics to ransomware negotiation.
Listen if you work in a SOC or are training for one and want structured, evergreen material.
interviewirregular60m+ - 05
Detection engineering
Detection logic, SIEM design and AI in the SOC, from the team behind a cloud SIEM. Releases have slowed, but the archive holds up.
Detection at Scale
Jack Naglieri
Detection and response leaders from Google, Block, and Snowflake on running a modern SOC on cloud-scale data.
Listen if you are a detection engineer or SOC lead building a detection-as-code practice.
interviewirregular30–60m - 06
The week's news with an attacker's view
Working pentesters react to the news live. Useful for hearing how the other side reads the same headlines.
Talkin' Bout [Infosec] News
Corey Ham · John Strand · Ralph May · Wade Wells
Black Hills Information Security's pentesters riff on the week's security news, live on Monday.
Listen if you want a weekly news habit with commentary from people who do penetration testing.
panelweekly60m+