r/SecOpsDaily community banner
Subreddit guide

r/SecOpsDaily: rules, karma requirements and posting culture

A security news feed for blue teamers. Most posts are structured summaries of the day's threats and advisories, with light moderation and thin comment sections.

SecOpsDaily · Open on Reddit

Members
16k
Created
2021
New posts a day
33.1
Comments on a typical post
0
New posts removed
<1%

The short answer

r/SecOpsDaily publishes no karma or account age requirement, and there are no written rules beyond a sidebar line asking people to be respectful. Almost nothing is removed: about 99.8% of posts in our sample stayed up. The catch is attention, not access. The feed runs at around 33 posts a day, nearly all of them news summaries, and the typical post gets no comments at all.

Who posts here

Knowledge levelIntermediate to advanced

Posts are written for people who already work in security operations. They use TTPs, IOCs, CVE numbers and MITRE technique IDs without explaining them, and the usual structure is a technical breakdown followed by what defenders should do. Nothing stops a beginner posting, but a basic question is more likely to be ignored than answered, because most posts get no replies.

  • SOC analysts, detection engineers and incident responders skimming the day's threats.
  • Sysadmins and identity admins who turn up when an advisory or a broken patch affects them directly.
  • Small security teams asking how others handle escalation, finding backlogs or tool sprawl.
  • People with a tool or service to mention, mostly in the comments.

Karma and account requirements

What it takes to get a post through in r/SecOpsDaily.

KarmaNot stated publicly. No rules or AutoModerator messages mention a threshold.
Account ageNot stated publicly.
ConductThe only stated expectation is in the sidebar: be civil.Mods' wording: “do not be rude and respect others”
Post flairUsed on about 84% of posts. NEWS is the most common at roughly 43%, then Threat Intel at about 17%. Advisory, Vulnerability and Detection make up most of the rest.
Post typeAll post types are open, but about 96% of posts are text. Links and images are rare.

What you can post

Post typeSubreddit settingShare of recent posts
TextAllowed96%
LinkAllowed3%
ImageAllowed1%
VideoAllowed0%
PollAllowed0%

Post flairs in use

  • NEWS 43%
  • Threat Intel 17%
  • Advisory 4%
  • Vulnerability 4%
  • Detection 4%
  • Cloud Security 3%
  • NetSec 2%
  • Supply Chain 2%
  • Opinion 2%
  • MacOS Security 1%

What happens to a new post

Where the most recent posts ended up. Sample size: 400.

  • Stayed up100%
  • Removed by Reddit's filters<1%

Reddit counts a removal by the subreddit's own AutoModerator rules as a moderator removal, so that share is not all human. Held by AutoModerator means the post is waiting in the mod queue.

What happened when we posted here

We have posted here ourselves. This is how our own posts and comments fared.

Stayed up
100%
Removed by Reddit's filters
0%
Removed by moderators
0%
Period
August 2025 to August 2026

The culture

r/SecOpsDaily is closer to a news wire than a discussion forum. It has under 16,000 members and around 33 posts a day, and the large majority of those are summaries of security news, advisories and vendor research, written to a fixed pattern: a short framing paragraph, a technical breakdown with attack vector, TTPs and indicators, then defensive advice. There is also a daily roundup post that links out to the day's sources.

Because the feed is so regular, human posts stand out. The sample has a handful of them: a small team asking whether a category of cloud security tool really cuts the findings queue, someone asking how to test an escalation playbook after a messy incident, a question about tying code scanning results to production risk. These are the posts that read like a colleague talking, and they are the exception.

Comments are sparse. The median post gets none, and when replies do come they are short, around 14 words, and usually a dry remark about a vendor, a correction, or a practical question such as asking for the indicators on a hosted product. Sidebar aside, there are no published rules and no sign of active gatekeeping.

What lands

  • News that hits admins on Monday morning: an authentication deprecation with a hard deadline, an update that breaks domain logins or remote desktop. These pulled the most comments in the sample.
  • Identity and phishing stories, such as a campaign abusing passkey registration to take over cloud accounts. That was the top post, at about 60 points.
  • Consumer-adjacent flaws people can picture, like a smart TV that can listen while in standby.
  • Operational questions with your own setup stated: cluster count, team size, how big the backlog is, what renewal is coming.

What gets removed or ignored

  • Very little. No moderator removals appear in our sample, and Reddit's own filters caught about 0.3% of posts.
  • There are no published rules to break beyond the sidebar's request not to be rude.
  • Bare image and link posts advertising a product did stay up in the sample, but they are a tiny share of the feed and drew no visible discussion.

The unwritten rules

  • Scores are small. The best posts in the sample sit between 20 and 60 points, and most sit near zero. Getting a post through is easy. Getting it read is the hard part.
  • The house format is a structured breakdown: what happened, technical detail, what to check or patch. A post without that shape looks out of place unless it is a real question.
  • Accuracy gets checked. One of the few long comments in the sample is a reader pointing out where a summary did not match the source article.
  • Comments that name a tool and drop a link exist, about 4% of comments carry one, but they sit alone under posts and nobody replies to them.
  • Expect sarcasm about big vendors. It is the default register in the replies.

Self-promotion

There is no self-promotion rule, because there are no written rules at all. In practice product posts and comments with links are not removed, at least not in our sample. They are also not rewarded: the product image and link posts got no traction, and tool mentions in comments go unanswered. If you have something to share, the format that fits is a technical write-up with indicators and defensive steps, where your product is a detail and not the point.

How people write here

Typical post length
191 words
Typical title length
11 words
Titles phrased as a question
2%
Typical comment length
14 words
Comments that include a link
4%
Posts that carry a flair
84%

When people post

  1. 0:00 UTC, 1
  2. 1:00 UTC, 3
  3. 2:00 UTC, 2
  4. 3:00 UTC, 3
  5. 4:00 UTC, 3
  6. 5:00 UTC, 5
  7. 6:00 UTC, 8
  8. 7:00 UTC, 16
  9. 8:00 UTC, 18
  10. 9:00 UTC, 13
  11. 10:00 UTC, 15
  12. 11:00 UTC, 18
  13. 12:00 UTC, 21
  14. 13:00 UTC, 24
  15. 14:00 UTC, 37
  16. 15:00 UTC, 40
  17. 16:00 UTC, 40
  18. 17:00 UTC, 16
  19. 18:00 UTC, 34
  20. 19:00 UTC, 27
  21. 20:00 UTC, 21
  22. 21:00 UTC, 19
  23. 22:00 UTC, 10
  24. 23:00 UTC, 6

New posts by hour of day, UTC.

Top keywords

The words and phrases that show up far more often here than in other communities, from recent posts in r/SecOpsDaily.

  • technical breakdown 279 posts
  • defense 306 posts
  • iocs 185 posts
  • ttps 124 posts
  • source 251 posts
  • attack vector 85 posts
  • monitor 175 posts
  • initial access 91 posts
  • attack 152 posts
  • anomalous 90 posts
  • vector 136 posts
  • threat 126 posts
  • vulnerability 123 posts
  • hashes 84 posts
  • access 201 posts
  • affected 133 posts
  • attackers 87 posts
  • ips 99 posts
  • attacker 93 posts
  • exploit 97 posts
  • exploitation 95 posts
  • e.g 130 posts
  • malicious 100 posts
  • detection 117 posts
  • likely 146 posts
  • execution 128 posts
  • specific 172 posts
  • patch 102 posts
  • mitre 65 posts
  • targeting 104 posts
  • exfiltration 62 posts
  • critical 103 posts
  • impact 112 posts
  • phishing 76 posts
  • social engineering 47 posts
  • chain 104 posts
  • security 132 posts
  • compromise 71 posts
  • cve 67 posts
  • compromised 76 posts

Common questions

How much karma do you need to post in r/SecOpsDaily?

No requirement is published. The subreddit has no written rules and no AutoModerator messages in our data, and about 99.8% of sampled posts stayed up. Treat it as open, with the caveat that an unpublished filter could still exist.

Can I promote my security product in r/SecOpsDaily?

Nothing in the sidebar forbids it, and promotional posts in our sample were not removed. They also got little or no engagement. The posts that get read are threat and advisory breakdowns, so a technical write-up does better than an announcement.

What kind of posts work in r/SecOpsDaily?

Text posts with a flair. About 96% of posts are text and the median is around 190 words. Stories about identity attacks, exploited flaws in common enterprise products and patches that break things get the most votes and replies.

Is r/SecOpsDaily good for discussion?

Not much. The typical post gets no comments, and only about 2% of titles are questions. It works as a daily feed of security news with summaries. If you want a long thread of answers to a question, a larger security subreddit will give you more replies.

Data as of October 4, 2026. Numbers come from public Reddit data (the Arctic Shift archive and GummySearch) sampled on this date. Removal share counts posts taken down by moderators, AutoModerator or Reddit's own filters. Banner and icon belong to the community. Moderators change rules without notice, so treat the sidebar as the final word.

Retro engraving of two spacecraft dockingFree audit

See what Reddit says about you.

Not a generic audit. Your actual numbers: where you get mentioned, where your three closest competitors get mentioned instead, and what your own analytics say about traffic you are already losing.

Drops your email into the two-minute application.