Skip to content

Podcasts/Reading paths

If you work in a SOC

For SOC analysts, detection engineers and incident responders. A five-minute morning brief, then threat intelligence from the big response teams, then the shows about detection and investigation craft.

  1. 01

    Morning brief, under 10 minutes

    The SANS Internet Storm Center handlers on what they saw overnight. The closest thing to a shift handover in audio.

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    Johannes B. Ullrich

    Five to eight minutes every weekday morning on what the SANS honeypots and handlers saw overnight.

    Listen if you work in a SOC or run infrastructure and need to know what to patch today.

    solodaily<30m
  2. 02

    Threat intelligence from a big response team

    Microsoft's threat researchers on the actors they track. Vendor-run, and it says so, but the access to the research is real.

    Microsoft Threat Intelligence Podcast

    Elliot Volkman

    Microsoft's own threat hunters on the Blizzards, Typhoons, and crime crews they track, plus the takedowns they run.

    Listen if you work in a SOC or CTI team and want the analyst story behind Microsoft's threat reports.

    interviewbiweekly30–60m
  3. 03

    Incident response from the responders

    Mandiant and Google Threat Intelligence on campaigns they investigated, with dwell times and remediation detail.

    The Defender's Advantage Podcast

    Luke McNamara

    Mandiant and Google Threat Intelligence Group analysts on the intrusions they responded to, in 30 tight minutes.

    Listen if you do incident response or threat hunting and want lessons from Mandiant engagements.

    interviewirregular30–60m
  4. 04

    Blue team craft

    SANS instructors on building and running a defense program, with long practical episodes.

    Blueprint: Build the Best in Cyber Defense

    John Hubbard

    SANS's blue team show: long, teaching-first conversations on running a SOC, from metrics to ransomware negotiation.

    Listen if you work in a SOC or are training for one and want structured, evergreen material.

    interviewirregular60m+
  5. 05

    Detection engineering

    Detection logic, SIEM design and AI in the SOC, from the team behind a cloud SIEM. Releases have slowed, but the archive holds up.

    Detection at Scale

    Jack Naglieri

    Detection and response leaders from Google, Block, and Snowflake on running a modern SOC on cloud-scale data.

    Listen if you are a detection engineer or SOC lead building a detection-as-code practice.

    interviewirregular30–60m
  6. 06

    The week's news with an attacker's view

    Working pentesters react to the news live. Useful for hearing how the other side reads the same headlines.

    Talkin' Bout [Infosec] News

    Corey Ham · John Strand · Ralph May · Wade Wells

    Black Hills Information Security's pentesters riff on the week's security news, live on Monday.

    Listen if you want a weekly news habit with commentary from people who do penetration testing.

    panelweekly60m+