r/blueteamsec is a subreddit with 72k members. The most common kinds of discussions are advice requests and pain & anger, and the community frequently discusses ai, security, cve, threat, and vulnerability.
We focus on technical intelligence, research and engineering to help operational [blue|purple] teams defend their estates and have awareness of the world.
Our primary home is on Lemmy after the great ban debacle of 2025.
Popular Themes in r/blueteamsec
#1
Advice Requests
: "What are the ai agent security best practices for prioritizing remediation without chasing every finding?"
4 posts
#2
Pain & Anger
: "Passkey-themed social engineering leads to identity and cloud compromise"
3 posts
#3
News
: "Peeling the Sentinel: A Market-Leading EDR Comes Apart With Undergraduate Tools"
3 posts
#4
Solution Requests
: "I have redone CyberMatch so it is now a complete toolkit for cybersecurity go to market and would love your feedback (it is 100% free)"
2 posts
Popular Topics in r/blueteamsec
#1
Ai
: "Kimsuky Uses the Ai Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve"
6 posts
#2
Security
: "bombini: eBPF Security Monitoring and Sandboxing Agent Based on Aya - by information Security researchers at Russia's T-Bank (formerly Tinkoff Bank)"
4 posts
#3
Cve
: "Cve-2026-62832 LegacyHive — Moving on to the next steps"
3 posts
#4
Threat
: "Threat Hunting with JA4/JA4S (+ Practical KQL Queries)"
3 posts
#5
Vulnerability
: "Critical vulnerabilities in MikroTik RouterOS are being actively exploited. Immediate update recommended"
2 posts
#6
Windows
: "Bring Your Own Trusted Caller (BYOTC): A New Way to Exploit Vulnerable Windows Drivers (Part 1)"
2 posts
#7
Llm
: "The arithmetic problem with feeding endpoint telemetry to an Llm"
2 posts
#8
Exploit
: "Bring Your Own Trusted Caller (BYOTC): A New Way to Exploit Vulnerable Windows Drivers (Part 1)"
2 posts
#9
Hunting
: "Threat Hunting with JA4/JA4S (+ Practical KQL Queries)"
2 posts
#10
Shellcode
1 post
Flair Used in r/blueteamsec
#1
intelligence (threat actor activity)
: "Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence"
37 posts
#2
research|capability (we need to defend against)
: "Bring Your Own Trusted Caller (BYOTC): A New Way to Exploit Vulnerable Windows Drivers (Part 1)"
28 posts
#3
tradecraft (how we defend)
: "CISA Releases Updated Insider Threat Guide With New Insights to Mitigate Physical and Cyber Threats"
23 posts
#4
highlevel summary|strategy (maybe technical)
: "LAPSUS$ Group Returns by Challenging Federal Law Enforcement"
22 posts
#5
low level tools|techniques|knowledge (work aids)
: "Peeling the Sentinel: A Market-Leading EDR Comes Apart With Undergraduate Tools"
17 posts
#6
incident writeup (who and how)
: "Security Incident Affecting JetBrains Cadence"
15 posts
#7
vulnerability (attack surface)
: "ShieldCrash: Windows Defender 0day Vulnerability"
12 posts
#8
malware analysis (like butterfly collections)
: "SloppyRAT: A New Tool For Ransomware Attacks"
10 posts
#9
discovery (how we find bad stuff)
: "Linux Detection Engineering - Local Privilege Escalation"
8 posts
#10
exploitation (what's being exploited)
: "Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329"
7 posts
Member Growth in r/blueteamsec
Yearly
+15k members(26.0%)
Similar Subreddits to r/blueteamsec
r/AskNetsec
264k members
15.0% / yr
r/cybersecurity_
677 members
111.6% / yr
r/Cybersecurity101
67k members
212.3% / yr
r/Cyber_Security_News
1k members
35.7% / yr
r/Infosec
39k members
28.6% / yr
r/netsec
572k members
7.0% / yr
r/purpleteamsec
9k members
19.5% / yr
r/SecOpsDaily
15k members
685.2% / yr
r/threatintel
18k members
71.8% / yr
r/websec
8k members
1.8% / yr
About
GummySearch helps people research Reddit communities by organizing activity, growth, themes, and post-level signals into one place.
This page gives a focused view of r/blueteamsec, including current member size, discussion patterns, product reviews, and related communities to explore.
This data is synced periodically so insights stay current and useful for ongoing research.
Last updated: September 15, 2026