M.G. Vance

CyberLex Blue Team Academy

CyberLex Blue Team Academy is the cinematic, scenario-based podcast that teaches real-world defensive skills for Security+, ISC2 CC, CySA+, and CCSP.Learn to analyze threats, investigate incidents, and build the defensive intuition needed for modern cybersecurity roles. Your journey to becoming a defender starts here.

Author

M.G. Vance

Category

Technology

Podcast website

www.amazon.com

Latest episode

Jan 2, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 10 — The Scheduled Task That Recreated Itself | Security Operations: Persistence & Automated Rebuild Loops 02.01.2026

EPISODE 10 — THE SCHEDULED TASK THAT RECREATED ITSELF Security+ Domain 4 concepts • CySA+ threat analytics • SOC persistence detection Persistence is the attacker’s greatest weapon. And one of the stealthiest forms of persistence is a scheduled task that… won’t stay deleted. Defenders remove it. Minutes later, it reappears. Delete again. It returns again. This isn’t a misconfiguration. It’s a self...

Episode 9 — The DNS Query That Didn’t Match Any Pattern | Security Operations: DNS Analysis & C2 Detection 26.12.2025

EPISODE 9 — THE DNS QUERY THAT DIDN’T MATCH ANY PATTERN Security+ Domain 4 concepts • CySA+ network analytics • SOC DNS anomaly detection DNS is one of the most misunderstood — and most exploited — protocols in cybersecurity. Attackers use it for stealthy command-and-control, tunneling, and low-and-slow exfiltration because most environments treat DNS as “just infrastructure,” not a high-signal de...

Episode 8 — The Process That Hid in Memory | Security Operations: EDR Detection & Fileless Attacks 19.12.2025

EPISODE 8 — THE PROCESS THAT HID IN MEMORY Security+ Domain 4 concepts • CySA+ behavioral analytics • SOC fileless attack detection Modern attackers don’t always drop files. Sometimes the entire attack happens in memory — invisible to antivirus, bypassing traditional scans, and relying on stealth to stay ahead of the SOC. In this cinematic scenario, you’ll see how defenders detect fileless techniq...

Episode 7 — The Cloud Bucket Created at 3:14 A.M. | Security Operations: Cloud Monitoring & Rogue Resource Detection 14.12.2025

CyberLex Blue Team Academy — Where Defenders Are Forged. EPISODE 7 — THE CLOUD BUCKET CREATED AT 3:14 A.M. Security+ Domain 4 concepts • CySA+ cloud analytics • SOC cloud misconfiguration detection Cloud breaches rarely begin with loud signals. Most start with something small — a resource you didn’t create. At 3:14 A.M., a new storage bucket appears. No change request. No automation job. No schedu...

Episode 6 — The Email That Passed Every Check | Security Operations: Email Threat Detection & Identity Attacks 13.12.2025

CyberLex Blue Team Academy — Where Defenders Are Forged. EPISODE 6 — THE EMAIL THAT PASSED EVERY CHECK Security+ Domain 4 concepts • CySA+ email threat analytics • SOC identity attack detection Some of the most dangerous attacks never look dangerous at all. No spelling errors. No suspicious attachments. No fake branding. Everything passes SPF, DKIM, and DMARC. To most users, the email looks perfec...

Episode 5 — The Firewall Rule That Quietly Opened | Security Operations: Enterprise Controls & Outbound Anomalies 12.12.2025

CyberLex Blue Team Academy — Where Defenders Are Forged. EPISODE 5 — THE FIREWALL RULE THAT QUIETLY OPENED Security+ Domain 4 concepts • CySA+ network analytics • SOC enterprise control monitoring Some compromises start with noise. Others start with silence — a quiet adjustment deep in the firewall. A single rule widens outbound access. No ticket. No change request. No approval. Just a subtle shif...

Episode 4 — The Login That Didn’t Belong to the User | Security Operations: IAM Anomalies & Behavioral Detection 11.12.2025

CyberLex Blue Team Academy — Where Defenders Are Forged. EPISODE 4 — THE LOGIN THAT DIDN’T BELONG TO THE USER Security+ Domain 4 concepts • CySA+ authentication analytics • SOC identity anomaly detection Some attacks don’t start with a password guess…They start with a login that looks valid — but doesn’t make sense. A user signs in at a time they never work. From a device they don’t own. From a ne...

Episode 3 — The Vulnerability That Came Back | Security Operations: Vulnerability Lifecycle & Configuration Drift 10.12.2025

CyberLex Blue Team Academy — Where Defenders Are Forged. EPISODE 3 — THE VULNERABILITY THAT CAME BACK Security+ Domain 4 concepts • CySA+ vulnerability analytics • SOC lifecycle investigation In Security Operations, few things are more frustrating—or more dangerous—than a vulnerability that comes back after it was supposedly fixed. A patch shows as “successful.” Logs confirm installation. The scan...

Episode 2 — The Device That Still Had a Name | Security Operations: Asset Management & Rogue Inventory Signals 09.12.2025

CyberLex Blue Team Academy — Where Defenders Are Forged. EPISODE 2 — THE DEVICE THAT STILL HAD A NAME Security+ Domain 4 concepts • CySA+ asset behavior analysis • SOC rogue device detection In Security Operations, the most dangerous device is often the one that shouldn’t exist. A retired laptop that suddenly reappears. An inactive asset that becomes active again. A device authenticating in ways t...

Security Operations | Season 2 Trailer 08.12.2025

CyberLex Blue Team Academy — Where Defenders Are Forged. Season 2 of the CyberLex Blue Team Academy takes you deep into the heart of Security Operations — where defenders watch for subtle shifts in baselines, unusual alerts, configuration drifts, and the quiet signals that reveal something is wrong. These episodes explore real operational patterns SOC analysts face every day: alerting, monitoring,...

Episode 1 — The Baseline That Quietly Shifted | Security Operations: Baseline Drift & Early Detection 08.12.2025

CyberLex Blue Team Academy — Where Defenders Are Forged. EPISODE 1 — THE BASELINE THAT QUIETLY SHIFTED Security+ Domain 4 concepts • CySA+ behavioral detection • SOC baseline analysis Every healthy system has a baseline — a known, expected pattern of behavior. So when that baseline shifts, even slightly, defenders pay attention. In this cinematic scenario, you’ll see how a subtle, quiet change bec...

Scenario 10: The Device That Didn’t Belong on the Network | CyberLex Blue Team Academy 01.12.2025

EPISODE 10 — “The Device That Didn’t Belong on the Network”A device appears on the network with no owner, no registration, and no reason to exist. It connects quietly, probes internal systems subtly, and blends into traffic patterns just enough to avoid basic detection. But not enough to escape a trained defender’s eye. In Episode 10 of CyberLex Blue Team Academy, you investigate a rogue device in...

Scenario 9: The Process That Tried to Hide Itself | CyberLex Blue Team Academy 01.12.2025

EPISODE 9 — “The Process That Tried to Hide Itself” A suspicious background process appears at 3:12 a.m.—quiet, precise, and disguised as a legitimate Windows service. One character off. One behavior out of pattern. One outbound connection too many. Episode 9 of CyberLex Blue Team Academy takes you deep into the world of endpoint detection, stealth malware behavior, process masquerading, and comma...

Scenario 8: The Cloud Bucket Nobody Secured | CyberLex Blue Team Academy 01.12.2025

EPISODE 8 — “The Cloud Bucket Nobody Secured” A storage bucket appears in the cloud at 2:13 a.m. No owner. No encryption. Public access. And external traffic hits it minutes later. Episode 8 of CyberLex Blue Team Academy dives into the quiet world of cloud misconfigurations—one of the most common and most dangerous weaknesses in modern environments. You’ll learn how attackers exploit permissive ro...

Scenario 7: The Login That Happened at the Wrong Time | CyberLex Blue Team Academy 01.12.2025

EPISODE 7 — “The Login That Happened at the Wrong Time” A single login appears at an hour it shouldn’t. Clean on paper, suspicious in context. This is where identity-based attacks reveal themselves. Episode 7 of CyberLex Blue Team Academy takes you into the subtle world of authentication anomalies—where timing, behavior, and micro-patterns matter more than the alert itself. You’ll learn how attack...

Scenario 6: The Email That Looked Too Normal | CyberLex Blue Team Academy 01.12.2025

EPISODE 6 — “The Email That Looked Too Normal” Most phishing emails look sloppy. This one didn’t. And that’s what made it dangerous. In Episode 6 of CyberLex Blue Team Academy, you dissect a highly polished email designed to blend into a real organization’s communication rhythm. You’ll learn how attackers craft near-perfect messages, how to spot the subtle inconsistencies hidden in headers and URL...

Scenario 5: The Firewall Rule That Was Too Perfect | CyberLex Blue Team Academy 01.12.2025

EPISODE 5 — “The Firewall Rule That Was Too Perfect” A firewall rule appears during a routine review—clean, precise, and suspiciously flawless. No ticket. No justification. No context. Just a perfect entry placed exactly where no one was supposed to notice it. In Episode 5 of CyberLex Blue Team Academy, you uncover the subtle art of firewall manipulation and learn how attackers carve hidden pathwa...

Scenario 4: The Access Token That Shouldn’t Exist | CyberLex Blue Team Academy 01.12.2025

EPISODE 4 — “The Access Token That Shouldn’t Exist” A valid access token with no login event attached to it. Clean on the surface, suspicious underneath. Welcome to one of the most dangerous identity attacks in modern cybersecurity. In Episode 4 of CyberLex Blue Team Academy, we break down identity compromise through forged and replayed tokens—one of the quietest, stealthiest, and most effective a...

Scenario 3: The Configuration Change No One Admitted To | CyberLex Blue Team Academy 01.12.2025

EPISODE 3 — “The Configuration Change No One Admitted To” A single configuration change. No ticket. No approval. No explanation. This is where attackers start quiet… and defenders learn to listen. In Episode 3 of CyberLex Blue Team Academy, we investigate a subtle modification that turns into a full lesson in early reconnaissance, privilege misuse, and the psychology of stealth attacks. What looks...

Scenario 2: The Password Reset That Wasn’t Innocent | CyberLex Blue Team Academy 01.12.2025

A simple password reset. A quiet shift. A moment that didn’t feel right. This is where real defenders learn to see beyond the obvious. In Episode 2, you discover the psychology behind identity attacks. In this episode of CyberLex Blue Team Academy, we break down the silent, often-overlooked signals hidden inside routine password resets. What seems ordinary becomes a powerful lesson in identity sec...

Scenario 1: The Alert Nobody Trusted | CyberLex Blue Team Academy 01.12.2025

A low-priority alert. A quiet room. A moment everyone else ignored. This is where real defenders are made. And today, you learn how to see what others miss. In this opening episode of CyberLex Blue Team Academy, you step into the scene with controlled precision—learning how to read subtle signals, question “normal,” and detect the smallest shifts that reveal the start of an attack. What seems like...

Season 1 - The Defender's Mindset | CyberLex Blue Team Academy 01.12.2025

CyberLex Blue Team Academy is the cinematic, real-world cybersecurity podcast designed to build your defensive mindset from the ground up. Through immersive threat scenarios, practical explanations, and modern SOC-style investigations, you’ll learn how real defenders analyze signals, identify threats, and make decisions under pressure. Created for learners pursuing Security+ (SY0-701), ISC2 CC, Cy...

Listen to the CyberLex Blue Team Academy podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.