SOC, detection engineering and blue team podcasts
Podcasts for SOC analysts, detection engineers and incident responders: detection logic, triage, threat hunting and what real incident response looks like.
Blue team audio is thinner than red team audio, so this list is short on purpose. Pair one detection-focused show with a daily threat brief and you have most of what a working analyst needs.
9 shows, grouped by level. Each review lists three episodes to start with.
Beginner
Practitioner
Blueprint: Build the Best in Cyber Defense
John Hubbard
SANS's blue team show: long, teaching-first conversations on running a SOC, from metrics to ransomware negotiation.
Listen if you work in a SOC or are training for one and want structured, evergreen material.
interviewirregular60m+Cloud Security Podcast by Google
Anton Chuvakin · Timothy Peacock
293 episodes of Google's cloud, SOC, and SIEM thinking, with Mandiant breach lessons. Ended August 2026; the archive holds up.
Listen if you run or are building a SOC and want sharp takes on SIEM, detection engineering, and AI in the SOC.
interviewcompleted30–60mDetection at Scale
Jack Naglieri
Detection and response leaders from Google, Block, and Snowflake on running a modern SOC on cloud-scale data.
Listen if you are a detection engineer or SOC lead building a detection-as-code practice.
interviewirregular30–60mHacker Valley Studio
Ron Eddings
Upbeat 30-minute conversations about security careers, people and, lately, AI agents.
Listen if you are new to security and want relatable career stories with energy.
interviewweekly30–60mMicrosoft Threat Intelligence Podcast
Elliot Volkman
Microsoft's own threat hunters on the Blizzards, Typhoons, and crime crews they track, plus the takedowns they run.
Listen if you work in a SOC or CTI team and want the analyst story behind Microsoft's threat reports.
interviewbiweekly30–60mResearch Saturday
Dave Bittner
One fresh threat research report a week, explained by the researcher who wrote it, in about 25 minutes.
Listen if you work in a SOC or CTI role and want the week's notable malware and campaign research.
interviewweekly<30mSANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
Five to eight minutes every weekday morning on what the SANS honeypots and handlers saw overnight.
Listen if you work in a SOC or run infrastructure and need to know what to patch today.
solodaily<30mThe Defender's Advantage Podcast
Luke McNamara
Mandiant and Google Threat Intelligence Group analysts on the intrusions they responded to, in 30 tight minutes.
Listen if you do incident response or threat hunting and want lessons from Mandiant engagements.
interviewirregular30–60m