Securitylab•August 26, 2026•🇷🇺Translated from Russian

Grep_Tribe Blue Team Shares SOC Defense Lessons from Standoff 17 Cyber Battle

The Grep_Tribe blue team returned to Standoff 17 for the third consecutive year, this time protecting the infrastructure of the retail company RetailSTF Group inside the virtual State F. In contrast to routine SOC work with familiar systems and historical context, the cyber battle featured simultaneous attacks from multiple red teams, rapidly changing tactics, and a dramatically higher volume of security events.

Over the course of the exercise the defenders recorded 37 confirmed incidents, 22 detected incidents, five investigated critical events, and sustained an 88 percent average infrastructure availability. Team members who normally work in an internal SOC used the event to stress-test established processes under conditions that cannot be replicated in production environments.

Team Organization and Preparation

Before the competition began, roles were assigned across infrastructure analysis, vulnerability assessment, firewall rule review, and network topology mapping. During the battle the team applied a “tribal” model first tested the previous year: analysts initially triaged the general event stream, while complex attack scenarios triggered the formation of small two- or three-person groups for in-depth investigation and response. Newer participants focused on indicator analysis and basic containment, freeing experienced members for attribution and Threat Intelligence tasks.

Tools and Automation

The primary detection and response stack consisted of Positive Technologies solutions: MaxPatrol SIEM, MaxPatrol VM, MaxPatrol EDR, PT Application Firewall, and PT Sandbox. For the first time the team also operated R-Vision SOAR, using it as a central interface for automated playbooks that blocked IP addresses, submitted files to sandbox analysis, and enforced time-limited blocks that automatically expired to avoid service disruption.

Participants noted that the SOAR platform reduced context switching and allowed analysts to launch common actions in a few clicks while maintaining visibility into every response status. Support from the R-Vision engineering team enabled rapid customization of playbooks during the event.

Key Takeaways

After the competition the team concluded that pre-built automation for repetitive tasks significantly lowers analyst workload during sustained high-intensity periods. They intend to apply the same approach in their daily SOC operations. The event also reinforced the value of early infrastructure reconnaissance and the use of Threat Intelligence to link disparate events to specific red-team actors.

Grep_Tribe’s traditional mascot—frogs in various forms—accompanied the team once again, and several new internal memes were added to the collection. For first-time participants the advice was straightforward: study the rules in advance, ask experienced colleagues questions without hesitation, prepare contingency plans, and enjoy the unique learning opportunity that a live cyber battle provides.

Related articles

AntiMalware•Other

RemoveMacAI Utility Appears on GitHub to Disable Apple Intelligence and Free Disk Space on macOS

A new open-source tool called RemoveMacAI has been released on GitHub, allowing macOS users to fully disable Apple Intelligence features and remove associated AI models from their systems. The utility addresses the lack of a single toggle in macOS 27 for turning off generative AI capabilities while also reclaiming storage space occupied by downloaded models. It supports Apple silicon devices and works by leveraging Apple's own system services rather than directly modifying protected directories. Users can selectively disable components such as Siri, Writing Tools, Genmoji, Image Playground, ChatGPT integration, smart replies, photo cleanup, and Xcode predictive code completion. The tool also installs a configuration profile that prevents models from being redownloaded automatically. Reversion is possible via the removemacai revert command, though this comes at the cost of losing access to certain Apple Intelligence-powered functions in third-party apps and Shortcuts. The project is licensed under MIT and leaves Dictation untouched as it is managed separately.

Habr•Other

Secure Personalization of Java Card Applets Using Issuer Security Domain and SCP02

The article explains how to leverage the Issuer Security Domain mechanisms on GlobalPlatform cards to establish secure channels for applet personalization without implementing custom ECDH-based key exchange. It addresses limitations of prior approaches that lacked authentication and required extensive PKI support. The solution uses SCP02 with specific security levels such as C_MAC and C_DECRYPTION to protect commands that store AES-128 keys and personal data on the card. Detailed code walkthroughs cover the applet constructor, process method, mutual authentication via SecureChannel.processSecurity, and unwrap operations for decrypting and verifying APDUs. Practical testing on NXP Java Cards demonstrates installation via FunGP library scripts that allow configurable security levels during mutual authentication. The implementation ensures that secret key updates enforce C_DECRYPTION while personal data writes accept C_MAC, with encrypted reads performed using AES-CBC.

AntiMalware•Other

IT Jobs at Major Tech Firms Turn Into Dating Red Flags for Some Women

Working in IT used to be seen as a strong advantage in dating due to high salaries and prestigious employers. However, employees at companies like Palantir and Tesla now report that their jobs trigger uncomfortable conversations about ethics and politics instead of romantic interest. A Palantir engineer named Gary has started hiding his employer after facing sharp reactions from women and even requests from friends to avoid mentioning the company at social events. Tesla employee James encounters questions about his political views simply because of his association with Elon Musk's company. Dating specialist Amy Laurent notes that tech giants face backlash over issues like surveillance, inequality, and AI displacing workers, forcing professionals to present their careers with caveats. The article from Wired highlights how an employer's reputation now overshadows individual values during initial meetings. While IT roles remain attractive in many ways, the automatic boost from big tech brands appears to be fading in personal contexts.

Securitylab•Other

Neuromorphic Chips: Event-Driven Architectures Aim to Cut Energy Use in Always-On AI and Sensor Systems

Modern processors and GPUs excel at massive parallel math yet remain inefficient for continuous sensor streams where little changes most of the time. Neuromorphic chips borrow principles such as local memory, sparse spiking communication and threshold-based activation from biological nervous systems to reduce data movement and idle computation. The approach replaces constant matrix multiplications with asynchronous spikes that propagate only when meaningful events occur, lowering both power and latency for edge devices. Spiking neural networks encode information in the timing and frequency of pulses rather than dense numeric tensors, making them suitable for vibration monitoring, robotic vision and wearable health sensors. Hybrid systems are expected to pair conventional CPUs and NPUs for heavy training workloads with neuromorphic accelerators that stay dormant until events arrive. The architecture does not replace existing accelerators but targets the niche of always-on, battery-constrained perception tasks where conventional von Neumann designs hit the memory wall.