Brian Johnson

7 Minute Security

7 Minute Security is a weekly information security podcast focusing on penetration testing, blue teaming and building a career in security. The podcast also features in-depth interviews with industry leaders who share their insights, tools, tips and tricks for being a successful security engineer.

Autore

Brian Johnson

Categoria

Technology

Sito del podcast

7MinSec.com

Ultimo episodio

10 lug 2026

Dove ascoltare?

I podcast nell'app Replaio Radio In arrivo

I podcast stanno per arrivare nell'app. Installala ora e scopri per primo un modo tutto nuovo di vivere i podcast

Scaricala su Google Play Installala gratis Android 5 mln+ di download · valutazione 4,8 iOS in arrivo

Episodi

7MS #705: A Phishing Campaign Fail Tale 12.12.2025

This might be obvious, but security is not all domain admin dancing and maximum pwnage. Sometimes, despite my best efforts, a security project does a faceplant. Today's episode focuses on a phishing campaign that had plenty of "bites" but got immediately shut down – for reasons I still don't understand.

7MS #704: DIY Pentest Dropbox Tips – Part 12 05.12.2025

Hola friends!  My week has very much been about trying to turnaround pentest dropboxes as quickly as possible.  In that adventure, I came across two time-saving discoveries: Using a  Proxmox LXC  as a persistent remote access method Writing a Proxmox post-deployment script that installs Splashtop on the Windows VM, and resets the admin passwords on both VMs, all from the Proxmox SSH console withou...

7MS #703: Tales of Pentest Pwnage – Part 79 28.11.2025

Happy Thanksgiving week friends! Today we're celebrating a turkey and pie overload by sharing another fun tale of pentest pwnage! It involves using  pygpoabuse  to hijack a GPO and turn it into our pentesting puppet!  Muahahahahaah!!!!  Also: This week over at  7MinSec.club  we looked at how to  defend  against some common SQL attacks We're  very  close to offering our brand new LPLITE:GOAD 3-day...

7MS #702: Should You Hire AI to Run Your Next Pentest? 21.11.2025

Hello friends, in today's episode I give an audio summary of a talk I gave this week at the MN GOVIT Symposium called "Should You Hire AI to Run Your Next Pentest?"  It's not a  pro- AI celebration, nor is it an  anti- AI bashing.  Rather, the talk focuses on my experiences using both free and paid AI services to guide me through an Active Directory penetration test.

7MS #701: What I'm Working on This Week – Part 5 14.11.2025

Hello friends!  This week I'm talking about what I'm working on this week, including: Preparing a talk called  Should You Hire AI to Run Your Next Pentest  for the  Minnesota GOVIT Symposium . Playing with  Lithnet AD password protection  (I will show this live on next week's  Tuesday TOOLSday ). The Light Pentest logo contest has a winner!

7MS #700: Pretender 07.11.2025

Today is episode 700 of the 7MinSec podcast! Oh my gosh. My mom didn't think we could do it, but we did. Instead of a big blowout with huge news, giveaways and special guests, today is a pretty standard issue episode with a (nearly) 7-minute run time! The topic of today's episode is Pretender (which you can download  here  and read a lot more about  here ).  The tool authors explain the motivation...

7MS #699: Pre-Travel Security Tips 31.10.2025

Today we discuss some pre-travel tips you can use before hopping on a plane to start a work/personal adventure. Tips include: Updating the family DR/BCP plan Lightening your purse/wallet Validating/testing backups and restores Ensuring your auto coverage is up to snuff

7MS #698: Baby's First ProjectDiscovery 24.10.2025

Today I give a quick review of the cloud version of  ProjectDiscovery (not a sponsor!).

7MS #697: Pwning Ninja Hacker Academy – Part 4 18.10.2025

Today your pal and mine Joe "The Machine" Skeen pwn one of the two  Ninja Hacker Academy  domains!  This pwnage included: Swiping service tickets in the name of high-priv users Dumping secrets from wmorkstations Disabling AV Extracting hashes of gMSA accounts We didn't get the second domain pwned, and so I was originally thinking about doing a part 5 in November, but changed my mind.  Going forwar...

7MS #696: Baby's First Security Ticketing System 10.10.2025

In today's episode: I got a new  podcast doodad I really like  JitBit  as a security ticketing system (not a sponsor) The  Threat Hunting with Velociraptor  2-day training was great.   Highly  recommend.  I got inspired to take this class after watching the 1-hour primer  here .

7MS #695: Tales of Pentest Pwnage - Part 78 03.10.2025

Today's tale of pentest pwnage involves: Using  mssqlkaren  to dump sensitive goodies out of SCCM Using a specific fork of  bloodhound  to find machines I could force password resets on (warning: don't do this in prod…read  this !) Don't forget to check out our weekly Tuesday TOOLSday – live every Tuesday at 10 a.m. over at  7MinSec.club !

7MS #694: Tales of Pentest Pwnage – Part 77 26.09.2025

Hey friends, today I talk about how fun it was two combine two cool pentest tactics, put them in a blender, and move from local admin to mid-tier system admin access (with full control over hundreds of systems)! The  Tuesday TOOLSday video we did over at 7minsec.club will help bring this to life as well.

7MS #693: Pwning Ninja Hacker Academy – Part 3 19.09.2025

This week your pal and mine Joe "The Machine" Skeen kept picking away at pwning  Ninja Hacker Academy .  To review where we've been in parts 1 and 2: We found a SQL injection on a box called  SQL,  got a privileged Sliver beacon on it, and dumped mimikatz info From that dump, we used the  SQL  box hash to do a BloodHound run, which revealed that we had excessive permissions over the  Computers  OU...

7MS #692: Tales of Pentest Pwnage – Part 76 12.09.2025

Happy Friday! Today's another hot pile of pentest pwnage. To make it easy on myself I'm going to share the whole narrative that I wrote up for someone else: I was on a pentest where a DA account would sweep the networks every few minutes over SMB and hit my box. But SMB signing was on literally everywhere. The fine folks here recommended I try relaying to something NOT SMB, like MSSQL. This articl...

7MS #691: Tales of Pentest Pwnage – Part 75 05.09.2025

Holy schnikes, today might be my favorite tale of pentest pwnage ever. Do I say that almost every episode? yes. Do I mean it? Yes. Here are all the commands/links to supplement today's episode: Got an SA account to a SQL server through  Snaffler -ing With that SA account, I learned how to coerce Web auth from within a SQL shell – read more about that  here I relayed that Web auth with  ntlmrelayx...

7MS #690: Tales of Pentest Pwnage – Part 74 29.08.2025

Today's tale of pentest pwnage is a classic case of "If your head is buried in the pentest sand, pop it out for a while, touch grass, and re-enumerate what you've already enumerated, because that can lead to absolute GOLD!"

7MS #689: Pwning Ninja Hacker Academy – Part 2 22.08.2025

Hello friends!  Today your friend and mine, Joe "The Machine" Skeen joins me as we keep chipping away at pwning  Ninja Hacker Academy !  Today's pwnage includes: "Upgrading" our Sliver C2 connection to a full system shell using  PrintSpoofer ! Abusing nanodump to do an lsass minidump….and find our first cred. Analyzing BloodHound data to find (and own) excessive permissions against Active Director...

7MS #688: Building a Pentest Training Course Is Fun and Frustrating 16.08.2025

Today I talk about a subject I love while also driving me crazy at the same time: building a pentest training course! Specifically, I dissect a fun/frustrating GPO attack that I need to build very carefully so that every student can pwn it while also not breaking the domain for everybody else. I also talk about how three different flavors of AI failed me in solving a simple task.

7MS #687: A Peek into the 7MS Mail Bag – Part 5 11.08.2025

Hi friends, we're doing something today we haven't done in a hot minute: take a dip into the 7MinSec mail bag! Today we cover these questions: If I'm starting a solo business venture as a security consultancy, is it a good idea to join forces with other solo security business owners and form a consortium of sorts? Have you ever had anything go catastrophically wrong during a pentest?  Yes, and thi...

7MS #686: Our New Pentest Training Course is Almost Ready 01.08.2025

Oh man, I'm so excited I can hardly sleep. Our new three-day (4 hours per day) training is getting closer to general release. I talk about the good/bad/ugly of putting together an attack-sensitive lab that students can abuse (but hopefully not break!), and the technical/curriculum-writing challenges that go along with it.

7MS #685: The Time My Neighbor Almost Got Scammed Out of $13K 25.07.2025

Today's kind of a "story time with your friend Brian" episode: a tale of how my neighbor almost got scammed out of $13k.  The story has a lot of red flags we can all keep in mind to keep ourselves (as well as kids/friends/parents/etc.) safer from these types of shenanigans.

7MS #684: Pwning Ninja Hacker Academy 18.07.2025

Hey friends, today we start pwning  Ninja Hacker Academy  – cool CTF-style lab that has you start with  no  cred and try to conquer domain admin on  two  domains!

7MS #683: What I'm Working on This Week - Part 4 12.07.2025

This week I'm working on a mixed bag of fun security and marketing things: A pentest I'm stuck on My latest lab CTF obsession:  Ninja Hacker Academy A cool "about 7MinSec" marketing video that was recorded in a pro studio!

7MS #682: Securing Your Family During and After a Disaster – Part 7 04.07.2025

Today's episode is a downer! We talk about things you might want to have buttoned up for when you are eventually not alive anymore: Living will Buried vs. cremated? Funeral plans Funeral PHOTOS? I also talk about how my dad broke his ribs while trying to break a chimpmunk, and how a freak 4-wheeler accident also had my ribs in agony.

7MS #681: Pentesting GOAD – Part 3 27.06.2025

Today Joe "The Machine" Skeen and I pwn the third and final realm in the world of  GOAD (Game of Active Directory) : essos.local!  The way we go about it is to do a WinRM connection to our previously-pwned Kingslanding domain, coerce authentication out of MEEREEN (the DC for essos.local) and then capture/abuse the TGT with Rubeus!  Enjoy.

Ascolta il podcast 7 Minute Security su Replaio

Radio e podcast in un'unica app - gratis e senza registrazione. Installala oggi e non perderti il lancio

Scaricala su Google Play

Replaio non è un editore di podcast; i nomi dei programmi, le copertine e l'audio appartengono ai rispettivi autori e vengono distribuiti tramite feed RSS pubblici