Blueprint: Build the Best in Cyber Defense artwork

Blueprint: Build the Best in Cyber Defense

by SANS Institute

Are you a cyber defender looking to keep up on the newest tools, technology, and security concepts? Then BLUEPRINT is the podcast for you! Tune in to hear the latest in cyber defense and security operations from blue team leaders and experts. With a focus on learning, BLUEPRINT includes interviews with today’s top security practitioners defending the world’s most respected brands, and in-depth explanations on the newest technologies, protocols, and defensive tools. BLUEPRINT, is a podcast hosted by John Hubbard and brought to you by the SANS Institute. BLUEPRINT - your one-stop shop for taking your defense skills to the next level!

Website ↗ RSS Feed

Latest Episodes

Jul 2, 2026 · 44 min
SANS Cloud Security Exchange Summit 2026 - Aug. 17-18, San Francisco: https://www.sans.org/mlp/cloud-security-exchange-2026 Save $50 off registration with special promo code "Cloud_Promo50"! Agentic SOC platforms are no longer a future pitch — they're shipping, and teams are using them to triage and…
Jun 18, 2026 · 55 min
This episode is sponsored by Fig. This episode features a conversation with Nir Loya Dahan, Co-Founder and CPO at Fig, recorded at RSAC 2026. Our discussion covers telemetry health and SOC infrastructure resilience: what breaks in a log pipeline, why silent failures are so hard to catch, and how det…
Feb 9, 2026 · 48 min
What happens after you discover ransomware? You have to talk to the attackers. And that conversation can make or break your entire response. In this episode, Wade Gettle, a professional ransomware negotiator, pulls back the curtain on the high-stakes world of threat actor negotiations. Wade is the p…
Jan 5, 2026 · 1h 36m
This episode is a big one! We kick off 2026 with a critical lessons learned on how to detect and prevent the threat of fake IT workers infiltrating your organization through the story of a REAL compromise. In this episode, repeat guest Zak Stufflebeam shares a detailed case study involving a major i…
Aug 19, 2025 · 1h 6m
In this episode, we sit down with Zak Stufflebeam, Director of Cybersecurity at a publicly traded insurance company. Zak shares his unique journey from the military to leading security operations, emphasizing essential leadership principles learned along the way. From his early days in basic trainin…
Jun 27, 2025 · 52 min
This podcast episode is from the SANS Cyber Leaders Podcast. The episode features Blueprint host John Hubbard, where he talks with hosts James Lyne and Ciaran Martin on the ever-changing threat landscape and how SOC teams can stay ahead. John shares his expertise on spotting threats early, how to te…
Jun 12, 2025 · 1h 6m
In this episode of Blueprint, host John Hubbard sits down with James Spiteri from Elastic to explore the transformative power of AI on the SOC. They delve into how advanced AI technologies, such as agentic AI models, MCP protocol, and automation, are reshaping the SOC landscape. Discover how AI enha…
Apr 9, 2025 · 47 min
In this episode, we sit down with Rich Greene, a former United States Army Special Forces Green Beret and current SANS instructor for SEC275 and SEC301. Rich shares his incredible journey spanning 20 years in the Army, including his transition from military communication roles into the realm of cybe…
Feb 18, 2025 · 1h 3m
In this episode, we sit down with Ryan Thompson, a seasoned expert in building dashboards that actually detect real threats—not just look pretty. With experience at Elastic, Alert Logic, and top EDR vendors, Ryan shares deep insights into the science behind effective dashboards and how security team…
Jan 1, 2025 · 29 min
Surprise!! It's a mini solo episode to kick off the new year and it's on one of the most important topics there is - how to achieve your goals in 2025 and beyond! In this episode I talk about a topic I've never covered anywhere before - my personal system for productivity and how it helps me, and ca…
Dec 2, 2024 · 54 min
Mark Morowczynski returns for his 4th(!) time with his Microsoft coworker and identity and authentication expert Tarek Dawoud in this incredibly insightful conversation on the what, why, and how of  phishing resistant credentials that YOU can implement right now!  This conversation covers: What mak…
Oct 9, 2024 · 1h 35m
In this mega-discussion with Seth Misenar on GenAI and LLM usage for security operations we cover some very interesting questions such as:  - The importance of natural language processing in Sec Ops - How AI is helping us detect phishing email - Where and how AI is lowering the bar for entry-level s…
Oct 9, 2024 · 36 min
In this episode, we take you behind the scenes of a complex gift card fraud investigation. Join host John Hubbard and guest Mark Jeanmougin as they explore the intricate details of uncovering and combating a clever case of cyber fraud. In this episode Mark discusses how the incident was identified, …
Aug 3, 2023 · 1h 31m
Have you ever wondered what it takes to write and publish an information security book? In this special bonus episode following season 4, John discusses with Kathryn, Ingrid, and Carson the challenges and rewards of self-publishing, and the kind of effort that goes into producing a book like "11 Str…
Jul 18, 2023 · 1h 26m
"This final chapter of the book is no simple closer! "Turn Up the Volume by Expanding SOC Functionality" covers testing that your SOC is functioning as intended through activities such as Threat Hunting, Red and Purple Teaming, Adversary Emulation, Breach and Attack Simulation, tabletop exercises an…
Jul 10, 2023 · 52 min
"Metrics, is there any more confusing and contentious topic in cybersecurity? In this episode the authors cover their advice and approach to measuring your team so that issues can be quickly identified and performance can continuously improve! This special season of the Blueprint Podcast is taking a…
Jul 5, 2023 · 1h 3m
"Research has shown that communication is one of the most important factors for success in security incident response teams. In this chapter, the authors discuss the critical types of information that must be shared within the SOC, with the constituency, and with the greater cybersecurity community.…
Jun 26, 2023 · 1h 25m
Tool choice can be a make-or-break decision for security analysts, driving whether getting work done is a struggle, or an efficient, stress-free experience. How can we select the right tools for the job? Which tools are most important? Answers to these questions and more are in this week's episode o…
Jun 22, 2023 · 1h 4m
In this special live recording from the SANS Blue Team Summit 2023, Kathryn Knerler, Ingrid Parker, and Carson Zimmerman joined John Hubbard they share their insights and expertise with attendees by answering their pressing questions. From discussing the most effective strategies for building a succ…
Jun 19, 2023 · 1h 3m
There's no denying that the average security team is completely overwhelmed with options for data to collect. With a deluge of endpoint, network, and cloud data sources to collect, how to do we identify and collect the most useful data sources? That's the topic of this episode. Join Kathryn, Ingrid,…