SANS Internet Storm Center Diaries
Access and status
Cost
Free
Free to read or download at source. No account, no purchase.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
A daily handler diary — distinct from the SANS DFIR blog — in which a rotating roster of volunteer handlers writes up whatever they are currently seeing in honeypot data, malware samples, exploit traffic and log telemetry.
Who it is for, and when
This is threat-current rather than technique-current: it tells you what is being exploited this week and gives you indicators and parsing notes you can act on the same day. Useful in incident response for dating an intrusion against known exploitation windows. Publishing daily — most recent diary 11 September 2026.
What it does not cover
It is network and threat oriented, not evidentiary: almost nothing on imaging, chain of custody, mobile handsets or anything you would put in an expert report.
Go to the source
Open at isc.sans.edu (opens in a new tab)https://isc.sans.edu/diary/
Details
- Type
- Blog or channel
- Written for
- Working examinerAdvancedWorking examiner, Advanced
- Topics
- news, threat-hunting, network, malware, log-analysis, incident-response
- Checked at source
Related entries
Two complementary open-source network monitoring engines, both actively released. Zeek (formerly Bro) turns traffic into structured, protocol-aware logs — connections, HTTP requests, DNS queries, TLS handshakes, files seen — using its own scripting language. Suricata, from OISF, is a signature and rule-driven IDS/IPS that also produces rich EVE JSON records and can extract files.
CyberDefenders
Partly freeA blue-team lab platform hosting scenario-based investigations grouped as endpoint forensics, network forensics, malware analysis, cloud forensics, threat hunting, detection engineering and threat intelligence. Challenges are question-and-answer over supplied evidence, with a scoreboard.
A short daily audio briefing, typically five to ten minutes, summarising the Internet Storm Center diaries and the day's notable vulnerabilities and exploitation activity.
How to build and run network security monitoring: where to place sensors, what to collect (full packet capture, session data, alert data), and how to work a case from an alert through the collected evidence to a conclusion about scope.
Blue Team Labs Online
Partly freeA gamified platform, run by Centri, of "security investigations and challenges covering; Incident Response, Digital Forensics, Security Operations, Reverse Engineering, and Threat Hunting". Challenges are downloadable artefacts — memory dumps, phishing emails, packet captures, logs — while investigations run in hosted lab instances.