r/blueteamsec is a subreddit with 71k members. The most common kinds of discussions are news and solution requests, and the community frequently discusses threat technique, local ai agents, endpoint ai agents, open source, and shellcode.
We focus on technical intelligence, research and engineering to help operational [blue|purple] teams defend their estates and have awareness of the world.
Our primary home is on Lemmy after the great ban debacle of 2025.
Popular Themes in r/blueteamsec
#1
News
: "Incident Report: unsanctioned agent behaviour during cyber testing"
21 posts
#2
Solution Requests
: "Log Export from SIEM"
5 posts
#3
Advice Requests
: "Sources for post-infection PCAP (C2 beaconing, exfiltration) - what am I missing?"
2 posts
#4
Pain & Anger
: "A new extortion cocktail: office printers, small ransoms, and BitLocker"
1 post
Popular Topics in r/blueteamsec
#1
Threat Technique
2 posts
#2
Local Ai Agents
: "Curated catalog of local AI agent abuse techniques and real-world cases"
2 posts
#3
Endpoint Ai Agents
: "Open-Source Visibility, Detection, and Enforcement for Endpoint Ai Agents"
2 posts
#4
Open Source
: "Open-Source Visibility, Detection, and Enforcement for Endpoint AI Agents"
2 posts
#5
Shellcode
1 post
#6
Cyber Resilience
1 post
#7
Cve 2026 16723
1 post
#8
Yara X Rules
1 post
#9
Packetsmith
1 post
Flair Used in r/blueteamsec
#1
intelligence (threat actor activity)
: "JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake"
53 posts
#2
tradecraft (how we defend)
: "ADR: ADR secures enterprise AI agents through observability, security benchmarking, and threat detection. Deployed at Uber."
22 posts
#3
research|capability (we need to defend against)
: "Inside the Falcon How CrowdStrike Catches You"
21 posts
#4
highlevel summary|strategy (maybe technical)
: "Incident Report: unsanctioned agent behaviour during cyber testing"
19 posts
#5
low level tools|techniques|knowledge (work aids)
: "Careful adoption of Agentic AI in cyber defence"
17 posts
#6
malware analysis (like butterfly collections)
: "Dissecting Vanta Stealer, a Python-Based Cross-Platform Information Theft Malware"
15 posts
#7
incident writeup (who and how)
: "Toolkit Installation via SQL Injection Shows the Classics Still Hit
"
11 posts
#8
vulnerability (attack surface)
: "Apple Screen Sharing Pre-Auth RCE (macOS ≤ 26.5)"
11 posts
#9
exploitation (what's being exploited)
: "Context Wash: Evaluating AI SOC Vendors"
10 posts
#10
discovery (how we find bad stuff)
: "AI coding agents store full conversation history as plaintext on endpoints. Open source scanner for the credentials sitting in them."
7 posts
Member Growth in r/blueteamsec
Yearly
+15k members(26.2%)
Similar Subreddits to r/blueteamsec
r/AskNetsec
261k members
14.6% / yr
r/cybersecurity_
665 members
114.5% / yr
r/Cybersecurity101
63k members
207.6% / yr
r/Cyber_Security_News
1k members
37.3% / yr
r/Infosec
38k members
28.7% / yr
r/netsec
570k members
7.0% / yr
r/purpleteamsec
9k members
20.2% / yr
r/SecOpsDaily
13k members
607.1% / yr
r/threatintel
18k members
80.0% / yr
r/websec
8k members
2.0% / yr
About
GummySearch helps people research Reddit communities by organizing activity, growth, themes, and post-level signals into one place.
This page gives a focused view of r/blueteamsec, including current member size, discussion patterns, product reviews, and related communities to explore.
This data is synced periodically so insights stay current and useful for ongoing research.
Last updated: August 12, 2026