/r/blueteamsec/

r/blueteamsec

70k members
r/blueteamsec is a subreddit with 70k members. The most common kinds of discussions are news and solution requests, and the community frequently discusses cve 2026 16723, yara x rules, packetsmith, local ai agents, and endpoint ai agents.
We focus on technical intelligence, research and engineering to help operational [blue|purple] teams defend their estates and have awareness of the world. Our primary home is on Lemmy after the great ban debacle of 2025.

Popular Themes in r/blueteamsec

#1
News
: "Amazon identifies North Korean hacker group behind open-source supply chain attacks"
10 posts
#2
Solution Requests
: "data-diode: A Data Diode with 2 Raspberry Pi and OpenBSD"
5 posts
#3
Advice Requests
: "Sources for post-infection PCAP (C2 beaconing, exfiltration) - what am I missing?"
3 posts
#4
Pain & Anger
: "DNS Poisoning Tactics Expand to Hospitality Wi-Fi"
1 post

Popular Topics in r/blueteamsec

#1

Cve 2026 16723

2 posts
#2

Yara X Rules

2 posts
#3

Packetsmith

2 posts
#4

Local Ai Agents

: "Curated catalog of local AI agent abuse techniques and real-world cases"
2 posts
#5

Endpoint Ai Agents

: "Open-Source Visibility, Detection, and Enforcement for Endpoint Ai Agents"
2 posts
#6

Open Source

: "Open-Source Visibility, Detection, and Enforcement for Endpoint AI Agents"
2 posts
#7

Shellcode

1 post
#8

Cyber Resilience

1 post

Flair Used in r/blueteamsec

#1
intelligence (threat actor activity)
: "Finding actors that probe a CVE's exploit path before public disclosure in 30M honeypot records."
51 posts
#2
tradecraft (how we defend)
: "ADR: ADR secures enterprise AI agents through observability, security benchmarking, and threat detection. Deployed at Uber."
22 posts
#3
highlevel summary|strategy (maybe technical)
: "Cisco's Transition to a Risk-Based Vulnerability Disclosure Model"
22 posts
#4
low level tools|techniques|knowledge (work aids)
: "Careful adoption of Agentic AI in cyber defence"
20 posts
#5
research|capability (we need to defend against)
: "Inside the Falcon How CrowdStrike Catches You"
17 posts
#6
vulnerability (attack surface)
: "Apple Screen Sharing Pre-Auth RCE (macOS ≤ 26.5)"
16 posts
#7
malware analysis (like butterfly collections)
: "HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels"
11 posts
#8
discovery (how we find bad stuff)
: "The One Chokepoint to Rule Them All: Why I Deleted 50 ClickFix Detection Rules and Replaced Them with One"
10 posts
#9
incident writeup (who and how)
: "We pushed .env files with working canary credentials to public GitHub repos - attacker timeline and the gaps in GitHub/AWS automated response"
9 posts
#10
exploitation (what's being exploited)
: "Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure"
9 posts

Member Growth in r/blueteamsec

Yearly
+15k members(26.2%)

Similar Subreddits to r/blueteamsec

r/AskNetsec

260k members
14.4% / yr
/r/cybersecurity_

r/cybersecurity_

665 members
114.5% / yr
/r/Cybersecurity101

r/Cybersecurity101

62k members
204.2% / yr
/r/Cyber_Security_News

r/Cyber_Security_News

1k members
37.7% / yr

r/Infosec

38k members
28.5% / yr
/r/netsec

r/netsec

569k members
6.9% / yr
/r/purpleteamsec

r/purpleteamsec

9k members
20.5% / yr
/r/pwnhub

r/pwnhub

41k members
398.3% / yr
/r/SecOpsDaily

r/SecOpsDaily

13k members
598.9% / yr

r/threatintel

17k members
81.8% / yr

About

GummySearch helps people research Reddit communities by organizing activity, growth, themes, and post-level signals into one place.

This page gives a focused view of r/blueteamsec, including current member size, discussion patterns, product reviews, and related communities to explore.

This data is synced periodically so insights stay current and useful for ongoing research.

Last updated: August 6, 2026