Brian Johnson
7 Minute Security
7 Minute Security is a weekly information security podcast focusing on penetration testing, blue teaming and building a career in security. The podcast also features in-depth interviews with industry leaders who share their insights, tools, tips and tricks for being a successful security engineer.
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
7MS #455: Tales of Internal Network Pentest Pwnage - Part 24 19.02.2021 52:22
Hey everybody! Sorry that we're late again with today's episode, but I got COVID shot #2 and it kicked my behind BIG TIME today. But I'm vertical today and back amongst the living and thrilled to be sharing with you another tale of pentest pwnage! Yeah! This might be my favorite tale yet because: I got to use some of my new CRTP skills! Make sure on your pentests that you're looking for "roast...
7MS #454: Cyber News - Lets Switch to Typewriters Edition 11.02.2021 50:33
Happy almost-mid-February! Today Gh0sthax cooked up some great news stories for us to chew on, including: Sudo bug gives root access to mass numbers of Linux systems! What the heck is hammering with GameStop stock? - this tweet does a great job of explaining it in plain English Solarwinds continues to be a gift that keeps on giving malware-laced gifts that people don't want Sonicwall was hack...
7MS #453: Interview with Marcello Salvati 04.02.2021 1:05:39
Today's featured interview is with Marcello Salvati of Black Hills Information Security . Marcello is a.k.a. byt3bl33d3r , and known for his many contributions to the security community. We here at 7MS first became familiar with his work after using CrackMapExec on our penetration tests, and today we sat down with Marcello to discuss: Brian's Chris Farley moment with Marcello Marcello's infose...
7MS #452: Enterprise Attacker Emulation and C2 Implant Development 28.01.2021 39:08
Hey everyone! Hope you're having a great week. Today Gh0sthax and I do a brain dump and recap of a cool (and mind-exploding) course we took last week called Enterprise Attacker Emulation and C2 Implant Development . In the tangent department, we also touch a bit on: The Fargo TV series Our upcoming interview with Marcello (a.k.a. byt3bl33d3r ) from BHIS This Key and Peele sketch I just took...
7MS #451: Deep Freeze 22.01.2021 48:00
Today we talk about a cool product called Deep Freeze , which, as its name implies, can "freeze" your computer in a known/good/frozen state. Then you can do whatever the flip you want to the machine (install icky things, tamper with C:\windows, pack your browser full of shady plugins, and more!), and then just reboot to restore! Note: this is not a sponsored episode, but will probably sound like...
7MS #450: DIY Pentest Dropbox Tips - part 4 15.01.2021 56:22
Hey friends! We're continuing our series on pentest dropbox building - specifically playing off last week's episode where we started talking about automating the OS builds that go on our dropboxes. Today we'll zoom in a little closer and talk about some of the specific scripting we do to get a Windows 2019 Active Directory Domain Controller installed and updated so that it's ready to electro...
7MS #449: DIY Pentest Dropbox Tips - Part 3 07.01.2021 1:06:59
Happy new year! This episode continues our series on DIY pentest dropboxes with a focus on automation - specifically as it relates to automating the build of Windows 10, Windows Server 2019, Kali and Ubuntu VMs. Here's the resources I talk about in more detail on today's episode that helps make the auto magic happen: Windows VMs This article from Windowscentral.com does a great job of walki...
7MS #448: Certified Red Team Professional - Part 3 30.12.2020 48:59
Today, Gh0sthax and I talk about week 3/4 of the CRTP - Certified Red Team Professional training, and how it's kicking our butts a bit. Key points include: We agree this is not a certification for folks who are new to pentesting Don't expect to be following along "live" with the instructor during the training sessions You'll need to do a flippin' ton of studying and practicing on your own...
7MS #447: Cyber News - The End of 2020 as We Know It Edition 23.12.2020 58:34
Merry Christmas! Happy holidays! Please enjoy the last cyber news edition of 2020, brought to us by our good pal Gh0stHax . Stories covered include: You've probably heard this by now, but FireEye had a breach that was truly sophisticated. Here's a really nice plain English breakdown of the situation for folks who may not be interested in the deep technical details. Chris Krebs, former CISA d...
7MS #446: Certified Red Team Professional - Part 2 17.12.2020 41:02
Today's episode continues part 1 of our series on the Certified Red Team Professional certification. Key points from today's episode include: It's probably a better idea to run Bloodhound on your local machine so you don't crush the student VM's resources Running Invoke-Command is one of my new favorite things. Check this post for a bunch of cheatsheet tips for running commands in PowerS...
7MS #445: Certified Red Team Professional 09.12.2020 56:32
Welp, I need another certification like I need a hole in the head, but that didn't stop me from signing up for the Certified Red Team Professional . So I've started a series on sharing what I'm learning as I proceed through the certification path. (We're also talking about this on the 7MS forums ) Here are some of the highlights from week 1: Boy oh boy is PowerView handy for extracting juicy...
7MS #444: Interview with Christopher Fielder of Arctic Wolf 02.12.2020 56:58
Happy December! Today I virtually sat down with Christopher Fielder of Arctic Wolf , who started his career in security at 18 (I was just playing a lot of video games when I was that old)! Christopher has served in the Air Force, worked for a university and SANS, served for some three-letter organizations - and more! Christopher and I had a great chat about a variety of security topics, includi...
7MS #443: Cyber News - Thankful for Patches Edition 26.11.2020 41:12
Happy Thanksgiving! While the turkey and pie settle in your belly, why not also digest some fantastic security news stories with our pal Gh0sthax ? Today's stories include: It was another epic month of patching - both Threatpost and Krebs have great coverage of what you need to know. We don't support software pirating, but it's interesting that we just got a demo of Cobalt Strike spun up, a...
7MS #442: Tales of Internal Network Pentest Pwnage - Part 23 19.11.2020 1:09:11
Hey friends, I dare declare this to be my favorite tale of internal pentest pwnage so far. Why? Because the episode features: Great blue team tools alerting our customer to a lot of the stuff we were doing An EDR that we tried to beat up (but it beat us up instead) SharpGPOAbuse which we talked about extensively last week Separation of "everyday" accounts from privileged accounts Multi-factor...
7MS #441: SharpGPOAbuse 15.11.2020 39:20
Hello friends! Sorry to be late with this episode (again) but we've been heads-down in a lot of cool security work, coming up for air when we can! Today's episode features: A little welcome music that is not the usual scatting of gibberish I torture you with Some cool tools I'm playing with in the lab that we'll do future episodes on in the future: DetectionLab to practice detecting all the bad...
7MS #440: Tales of Internal Network Pentest Pwnage - Part 22 08.11.2020 33:16
Hi! Sorry to be so late with this episode, but I'm excited to share with you another fun tale of pentest pwnage! Key points from today's episode include: We do not do these episodes to brag or put down any company about their security posture. We do do (heh, I said "do do") these episodes to share what we're learning about pentesting it helps you become a better network defender and/or offen...
7MS #439: Cyber News - Ransomware is Definitely Still a Thing Edition 29.10.2020 1:09:27
Happy October and merry Halloween everybody! We're back with our buddy Joe "the machine" Skeen who is also now a Principal Security Engineer for 7MS ! He's also working on a new cert , and speaking of certs, 7MS is now PCIP certified ! Today's great cyber stories include: Azure AD is a single point of failure in many networks Ransomware sophistication continues to grow - as demonstrated in t...
7MS #438: PCI Professional Certification (PCIP) - Part 4 21.10.2020 38:32
Yay - I'm a PCIP now! I welcome you to check out our past episodes on PCIP, but in some ways this will be the be all, end all episode on the topic. Today I cover: Study materials that helped me prepare: PCIP book by Linda Jones (I couldn't actually get this one in time but it looks awesome!) Flashcards from Cram Flashcards from Quizlet My flashcards from Quizlet (I'll need to sanitize t...
7MS #437: Homecoming and Home ioT Security - Part 3 14.10.2020 39:41
Hello! This episode is a true homecoming in that I actually recorded it from home. Yay! WARNING!!! WARNING!!! This episode contains a ton of singing. If you don't like singing, do not listen!!! With that said, I wanted to follow up on part 1 and 2 of this series and share some additional cool tools that others have told me about in regards to securing and monitoring all your ioTs! Home A...
7MS #436: Cleaning Up Your Cloud Clutter 07.10.2020 48:06
Hey, hope you're having a great week! The last few weeks have had somewhat of a homecoming and home cleaning theme. To continue that train of thought, over the last few days I've gotten heavy into cleaning up my cloud clutter - cloud services, email, file sharing, etc. - in an effort to be more secure and have a reduced digital footprint. Today's tips include: Double-check that any device you have...
7MS #435: Homecoming and Home ioT Security - Part 2 02.10.2020 41:10
Hi again! It's sort of fun to release two episodes in one week for a change. If you missed part 1 on our ioT security series, check it out here . Today we dive into some free/cheap monitoring solutions you can use to keep tabs on your ioT network (or any network, really): Nagios - it's old school but gets the job done. This article helped me get it going on an RPi. SolarWinds IP monitor - i...
7MS #434: Homecoming and Home ioT Security 01.10.2020 34:13
WE'RE HOME! After almost a year after our fire , we're back, baby! This episode is somewhat of a homecoming that dovetails into an episode about ioT security. I've basically done a 180 degree spin on ioT stuff. I now love the coolness and convenience of these things while simultaneously being terrified of the security risks. Is there a happy balance somewhere between the two? Maybe. Today we di...
7MS #433: Cyber News - Security Skills Gap Edition 23.09.2020 47:44
Hi! Today our pal Joe "The Machine" Skeen (a.k.a. Gh0sthax has prepared some cyber-licious actionable news stories for us to chew on. Today's stories include: Cybersecurity skills gap (powered by lack of career development!) Which cyber jobs are hot - or not? Mysterious wave of DDoS attacks The Magecart threat group pwns thousands of ecommerce sites On a parting note, don't forget to patch yo...
7MS #432: Tales of Internal Network Pentest Pwnage - Part 21 16.09.2020 44:42
Yay! It's time for another tale of pentest pwnage! Highlights include: Making sure you take multiple rounds of "dumps" to get all the delicious local admin creds. Why lsassy is my new best friend. I gave a try to using a Ubuntu box instead of Kali as my attacking system for this test. I had pretty good results. Here's my script to quickly give Ubuntu a Kali-like flair: sudo apt-get update sudo...
7MS #431: How to Succeed in Business Without Really Crying - Part 8 09.09.2020 49:43
Today we're talking business! We've got some exciting news and updates to share with you since we last did a "crying" episode last fall: 7MS hired a VP of sales and marketing: Clyde Cooper ! We've added some new tools to our tools/services gist : Having a true sales force for the first time has prompted us to invest in Salesforce . There are a few gotchas with signing up for a Salesforce trial...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.