SecuritylabAugust 26, 2026🇷🇺Translated from Russian

Grep_Tribe Blue Team Shares SOC Defense Lessons from Standoff 17 Cyber Battle

The Grep_Tribe blue team returned to Standoff 17 for the third consecutive year, this time protecting the infrastructure of the retail company RetailSTF Group inside the virtual State F. In contrast to routine SOC work with familiar systems and historical context, the cyber battle featured simultaneous attacks from multiple red teams, rapidly changing tactics, and a dramatically higher volume of security events.

Over the course of the exercise the defenders recorded 37 confirmed incidents, 22 detected incidents, five investigated critical events, and sustained an 88 percent average infrastructure availability. Team members who normally work in an internal SOC used the event to stress-test established processes under conditions that cannot be replicated in production environments.

Team Organization and Preparation

Before the competition began, roles were assigned across infrastructure analysis, vulnerability assessment, firewall rule review, and network topology mapping. During the battle the team applied a “tribal” model first tested the previous year: analysts initially triaged the general event stream, while complex attack scenarios triggered the formation of small two- or three-person groups for in-depth investigation and response. Newer participants focused on indicator analysis and basic containment, freeing experienced members for attribution and Threat Intelligence tasks.

Tools and Automation

The primary detection and response stack consisted of Positive Technologies solutions: MaxPatrol SIEM, MaxPatrol VM, MaxPatrol EDR, PT Application Firewall, and PT Sandbox. For the first time the team also operated R-Vision SOAR, using it as a central interface for automated playbooks that blocked IP addresses, submitted files to sandbox analysis, and enforced time-limited blocks that automatically expired to avoid service disruption.

Participants noted that the SOAR platform reduced context switching and allowed analysts to launch common actions in a few clicks while maintaining visibility into every response status. Support from the R-Vision engineering team enabled rapid customization of playbooks during the event.

Key Takeaways

After the competition the team concluded that pre-built automation for repetitive tasks significantly lowers analyst workload during sustained high-intensity periods. They intend to apply the same approach in their daily SOC operations. The event also reinforced the value of early infrastructure reconnaissance and the use of Threat Intelligence to link disparate events to specific red-team actors.

Grep_Tribe’s traditional mascot—frogs in various forms—accompanied the team once again, and several new internal memes were added to the collection. For first-time participants the advice was straightforward: study the rules in advance, ask experienced colleagues questions without hesitation, prepare contingency plans, and enjoy the unique learning opportunity that a live cyber battle provides.

Related articles

HabrOther

Password Reset Fails to Evict Attackers: What Persists in Compromised Email Accounts

Even after users change passwords and enable two-factor authentication, attackers often retain access through active sessions, application tokens, and forwarding rules. The original password serves only as an entry point, while already-issued session cookies, refresh tokens, and app passwords continue functioning independently. Services like Google, Microsoft, and Yandex provide specific pages to review devices, permissions, and app passwords, yet many users overlook the critical "sign out all devices" option. In corporate environments, Microsoft Entra ID commands can revoke sessions, but access tokens may still remain valid for up to an hour afterward. Attackers frequently replace recovery details and set up mail delegation or hidden forwarding rules to maintain long-term control. The recommended sequence prioritizes session revocation first, followed by password change, MFA review, and recovery data verification to prevent re-entry via forgotten-password flows.

AntiMalwareOther

86% of Large Russian Companies Use or Pilot LLMs While Autonomous AI Agents Remain Rare in Production

A joint study by Infosystems Jet and Smart Ranking reveals that 86% of major Russian organizations are already deploying or testing large language models, with 53% having moved generative AI solutions into full production. Adoption drops sharply for more autonomous systems: only 15% run semi-autonomous AI agents in production, while fully autonomous and multi-agent setups reach just 8% each. The primary barriers are not model availability but insufficient process maturity, data infrastructure readiness, and integration complexity, cited by 44% of respondents. Additional obstacles include server costs (58%), legal risks (56%), budget limits (42%), and talent shortages (40%). Nearly half of surveyed companies report no measurable financial return from AI projects so far, highlighting the gap between pilot success and scalable value. The research covered 52 large firms employing roughly 450,000 people in total.

AntiMalwareOther

Russia to Enforce Smartphone Ban During School Lessons Starting September 2026

From September 1, 2026, Russian school students will be prohibited from using mobile phones during classes under a new ministerial order from the Ministry of Education. The restriction, already outlined in federal law, will be detailed by the order to specify its application in schools, according to Minister Sergey Kravtsov. Phones may only be used in emergencies, such as threats to life or health of students and teachers. Activities like messaging, gaming, social media access, or using AI tools for quick answers are explicitly not permitted. Schools retain flexibility on phone use during breaks, allowing individual institutions to set their own rules. The Ministry of Digital Development has confirmed no nationwide ban on social networks for minors is planned, leaving platforms like TikTok and Telegram accessible outside class hours.

AntiMalwareOther

Generative AI Cuts HR Department Sizes as Russian Job Market Sees Up to 19 Applicants per Vacancy

The Russian labor market for HR professionals has become significantly more competitive since the beginning of 2026. Job seekers have submitted over 520,000 resumes while employers posted only 66,000 openings. Data from hh.ru shows some positions receiving as many as 19 applications. In June, the number of HR vacancies dropped 34 percent year-over-year while the volume of resumes rose 17 percent. Market participants estimate that roughly one in three HR employees has lost their job over the past 18 months. Companies are simultaneously reducing management layers amid cooling business activity, and generative AI tools are accelerating the trend by automating up to 80 percent of routine recruiter tasks. More than one-third of employers already use digital tools that analyze resumes, conduct initial interviews, and deliver structured results, halving hiring times and prompting questions about the need for large HR teams.