SANS Internet Storm Center Daily Stormcast
Access and status
Cost
Free
Free to read or download at source. No account, no purchase.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
A short daily audio briefing, typically five to ten minutes, summarising the Internet Storm Center diaries and the day's notable vulnerabilities and exploitation activity.
Who it is for, and when
The point is the length and the cadence: it is a daily situational-awareness habit rather than something you learn from. Useful in incident response for knowing which vulnerabilities were being actively exploited on a given date, which can matter when you are dating an intrusion. Published every weekday — episode 10090 dated 11 September 2026.
What it does not cover
It is vulnerability and threat news only — no forensic technique, no case discussion, and nothing on evidence handling or expert work.
Go to the source
Open at isc.sans.edu (opens in a new tab)https://isc.sans.edu/podcast.html
Details
- Type
- Podcast
- Written for
- Working examinerWorking examiner
- Topics
- news, threat-hunting, network, incident-response
- Checked at source
Related entries
A daily handler diary — distinct from the SANS DFIR blog — in which a rotating roster of volunteer handlers writes up whatever they are currently seeing in honeypot data, malware samples, exploit traffic and log telemetry.
Blue Team Labs Online
Partly freeA gamified platform, run by Centri, of "security investigations and challenges covering; Incident Response, Digital Forensics, Security Operations, Reverse Engineering, and Threat Hunting". Challenges are downloadable artefacts — memory dumps, phishing emails, packet captures, logs — while investigations run in hosted lab instances.
CyberDefenders
Partly freeA blue-team lab platform hosting scenario-based investigations grouped as endpoint forensics, network forensics, malware analysis, cloud forensics, threat hunting, detection engineering and threat intelligence. Challenges are question-and-answer over supplied evidence, with a scoreboard.
Forensics placed inside the incident response lifecycle: building a response capability, response frameworks, evidence acquisition, volatile memory, disk and network evidence, threat intelligence, malware analysis, threat hunting, and reporting — with this edition reframed around ransomware.
FIRST Conference
PaidThe annual conference of FIRST, the global forum of incident response and security teams, which comprises over 800 member teams in more than 100 countries. The 2026 edition ran 14-19 June 2026 in Denver, Colorado.