Brian Johnson

7 Minute Security

7 Minute Security is a weekly information security podcast focusing on penetration testing, blue teaming and building a career in security. The podcast also features in-depth interviews with industry leaders who share their insights, tools, tips and tricks for being a successful security engineer.

Author

Brian Johnson

Category

Technology

Podcast website

7MinSec.com

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

7MS #455: Tales of Internal Network Pentest Pwnage - Part 24 19.02.2021

Hey everybody! Sorry that we're late again with today's episode, but I got COVID shot #2 and it kicked my behind BIG TIME today. But I'm vertical today and back amongst the living and  thrilled  to be sharing with you another tale of pentest pwnage! Yeah! This might be my favorite tale yet because: I got to use some of my new  CRTP  skills! Make sure on your pentests that you're looking for "roast...

7MS #454: Cyber News - Lets Switch to Typewriters Edition 11.02.2021

Happy almost-mid-February! Today  Gh0sthax  cooked up some great news stories for us to chew on, including: Sudo bug gives root access to mass numbers of Linux systems! What the heck is hammering with GameStop stock?  - this  tweet  does a great job of explaining it in plain English Solarwinds continues to be a gift that keeps on giving malware-laced gifts that people don't want Sonicwall was hack...

7MS #453: Interview with Marcello Salvati 04.02.2021

Today's featured interview is with  Marcello Salvati of Black Hills Information Security . Marcello is a.k.a.  byt3bl33d3r , and known for his many contributions to the security community. We here at 7MS first became familiar with his work after using  CrackMapExec  on our penetration tests, and today we sat down with Marcello to discuss: Brian's Chris Farley moment with Marcello Marcello's infose...

7MS #452: Enterprise Attacker Emulation and C2 Implant Development 28.01.2021

Hey everyone! Hope you're having a great week. Today  Gh0sthax  and I do a brain dump and recap of a cool (and mind-exploding) course we took last week called  Enterprise Attacker Emulation and C2 Implant Development . In the tangent department, we also touch a bit on: The Fargo TV series Our upcoming interview with Marcello (a.k.a.  byt3bl33d3r ) from  BHIS This  Key and Peele sketch I just took...

7MS #451: Deep Freeze 22.01.2021

Today we talk about a cool product called  Deep Freeze , which, as its name implies, can "freeze" your computer in a known/good/frozen state. Then you can do whatever the flip you want to the machine (install icky things, tamper with C:\windows, pack your browser full of shady plugins, and more!), and then just reboot to restore! Note: this is not a sponsored episode, but will probably sound like...

7MS #450: DIY Pentest Dropbox Tips - part 4 15.01.2021

Hey friends! We're continuing our  series on pentest dropbox building  - specifically playing off  last week's episode  where we started talking about  automating  the OS builds that go on our dropboxes. Today we'll zoom in a little closer and talk about some of the specific scripting we do to get a Windows 2019 Active Directory Domain Controller installed and updated so that it's ready to electro...

7MS #449: DIY Pentest Dropbox Tips - Part 3 07.01.2021

Happy new year! This episode continues our series on  DIY pentest dropboxes  with a focus on  automation  - specifically as it relates to automating the build of Windows 10, Windows Server 2019, Kali and Ubuntu VMs. Here's the resources I talk about in more detail on today's episode that helps make the auto magic  happen: Windows VMs This article from  Windowscentral.com  does a great job of walki...

7MS #448: Certified Red Team Professional - Part 3 30.12.2020

Today,  Gh0sthax  and I talk about week 3/4 of the  CRTP - Certified Red Team Professional  training, and how it's kicking our butts a bit. Key points include: We agree this is  not  a certification for folks who are new to pentesting Don't expect to be following along "live" with the instructor during the training sessions You'll need to do a flippin'  ton  of studying and practicing on your own...

7MS #447: Cyber News - The End of 2020 as We Know It Edition 23.12.2020

Merry Christmas! Happy holidays! Please enjoy the last cyber news edition of 2020, brought to us by our good pal Gh0stHax . Stories covered include: You've probably heard this by now, but  FireEye had a breach  that was  truly  sophisticated. Here's a really nice  plain English breakdown  of the situation for folks who may not be interested in the deep technical details. Chris Krebs, former CISA d...

7MS #446: Certified Red Team Professional - Part 2 17.12.2020

Today's episode continues  part 1  of our series on the  Certified Red Team Professional  certification. Key points from today's episode include: It's probably a better idea to run  Bloodhound  on your local machine so you don't crush the student VM's resources Running  Invoke-Command  is one of my new favorite things. Check  this post  for a bunch of cheatsheet tips for running commands in PowerS...

7MS #445: Certified Red Team Professional 09.12.2020

Welp, I need another certification like I need a hole in the head, but that didn't stop me from signing up for the  Certified Red Team Professional . So I've started a series on sharing what I'm learning as I proceed through the certification path.  (We're also talking about this on the  7MS forums ) Here are some of the highlights from week 1: Boy oh boy is  PowerView  handy for extracting juicy...

7MS #444: Interview with Christopher Fielder of Arctic Wolf 02.12.2020

Happy December! Today I virtually sat down with Christopher Fielder of  Arctic Wolf , who started his career in security at  18  (I was just playing a lot of video games when I was that old)! Christopher has served in the Air Force, worked for a university and SANS, served for some three-letter organizations - and more! Christopher and I had a great chat about a variety of security topics, includi...

7MS #443: Cyber News - Thankful for Patches Edition 26.11.2020

Happy Thanksgiving! While the turkey and pie settle in your belly, why not also digest some fantastic security news stories with our pal  Gh0sthax ? Today's stories include: It was another epic month of patching - both  Threatpost  and  Krebs  have great coverage of what you need to know. We don't support software pirating, but it's interesting that we  just  got a demo of Cobalt Strike spun up, a...

7MS #442: Tales of Internal Network Pentest Pwnage - Part 23 19.11.2020

Hey friends, I dare declare this to be my  favorite  tale of internal pentest pwnage so far. Why? Because the episode features: Great blue team tools alerting our customer to a lot of the stuff we were doing An EDR that we tried to beat up (but it beat us up instead) SharpGPOAbuse  which we talked about extensively  last week Separation of "everyday" accounts from privileged accounts Multi-factor...

7MS #441: SharpGPOAbuse 15.11.2020

Hello friends! Sorry to be late with this episode (again) but we've been heads-down in a lot of cool security work, coming up for air when we can! Today's episode features: A little welcome music that is  not  the usual scatting of gibberish I torture you with Some cool tools I'm playing with in the lab that we'll do future episodes on in the future: DetectionLab  to practice detecting all the bad...

7MS #440: Tales of Internal Network Pentest Pwnage - Part 22 08.11.2020

Hi! Sorry to be so late with this episode, but I'm excited to share with you another fun tale of pentest pwnage! Key points from today's episode include: We do  not  do these episodes to brag  or  put down any company about their security posture. We  do  do (heh, I said "do do") these episodes to share what we're learning about pentesting it helps you become a better network defender and/or offen...

7MS #439: Cyber News - Ransomware is Definitely Still a Thing Edition 29.10.2020

Happy October and merry Halloween everybody! We're back with our buddy  Joe "the machine" Skeen  who is also now a Principal Security Engineer for  7MS ! He's also working on a  new cert , and speaking of certs, 7MS is now  PCIP certified ! Today's great cyber stories include: Azure AD is a single point of failure in many networks Ransomware sophistication continues to grow - as demonstrated in  t...

7MS #438: PCI Professional Certification (PCIP) - Part 4 21.10.2020

Yay - I'm a  PCIP  now! I welcome you to check out our  past episodes  on PCIP, but in some ways this will be the be all, end all episode on the topic. Today I cover: Study materials that helped me prepare: PCIP book by Linda Jones  (I couldn't actually get this one in time but it looks awesome!) Flashcards from  Cram Flashcards from  Quizlet My  flashcards from  Quizlet   (I'll need to sanitize t...

7MS #437: Homecoming and Home ioT Security - Part 3 14.10.2020

Hello! This episode is a  true  homecoming in that I actually recorded it from home. Yay! WARNING!!! WARNING!!! This episode contains a  ton  of singing. If you don't like singing, do  not  listen!!! With that said, I wanted to follow up on  part 1  and  2  of this series and share some additional cool tools that others have told me about in regards to securing and monitoring all your ioTs! Home A...

7MS #436: Cleaning Up Your Cloud Clutter 07.10.2020

Hey, hope you're having a great week! The last few weeks have had somewhat of a homecoming and home cleaning theme. To continue that train of thought, over the last few days I've gotten heavy into cleaning up my cloud clutter - cloud services, email, file sharing, etc. - in an effort to be more secure and have a reduced digital footprint. Today's tips include: Double-check that any device you have...

7MS #435: Homecoming and Home ioT Security - Part 2 02.10.2020

Hi again! It's sort of fun to release  two  episodes in one week for a change. If you missed part 1 on our ioT security series, check it out  here . Today we dive into some free/cheap monitoring solutions you can use to keep tabs on your ioT network (or any network, really): Nagios  - it's old school but gets the job done.  This article  helped me get it going on an RPi. SolarWinds IP monitor  - i...

7MS #434: Homecoming and Home ioT Security 01.10.2020

WE'RE HOME! After almost a year after our  fire , we're back, baby! This episode is somewhat of a homecoming that dovetails into an episode about ioT security. I've basically done a 180 degree spin on ioT stuff. I now  love  the coolness and convenience of these things while simultaneously being terrified of the security risks. Is there a happy balance somewhere between the two? Maybe. Today we di...

7MS #433: Cyber News - Security Skills Gap Edition 23.09.2020

Hi! Today our pal Joe "The Machine" Skeen (a.k.a.  Gh0sthax  has prepared some cyber-licious actionable news stories for us to chew on. Today's stories include: Cybersecurity skills gap (powered by lack of career development!) Which cyber jobs are hot - or not? Mysterious wave of DDoS attacks The Magecart threat group  pwns  thousands of ecommerce sites On a parting note, don't forget to  patch yo...

7MS #432: Tales of Internal Network Pentest Pwnage - Part 21 16.09.2020

Yay! It's time for another tale of pentest pwnage! Highlights include: Making sure you take multiple rounds of "dumps" to get all the delicious local admin creds. Why  lsassy  is my new best friend. I gave a try to using a Ubuntu box instead of Kali as my attacking system for this test. I had  pretty good  results. Here's my script to quickly give Ubuntu a Kali-like flair: sudo apt-get update sudo...

7MS #431: How to Succeed in Business Without Really Crying - Part 8 09.09.2020

Today we're talking business! We've got some exciting news and updates to share with you since we last did a "crying" episode last fall: 7MS hired a VP of sales and marketing:  Clyde Cooper ! We've added some new tools to our  tools/services gist : Having a true sales force for the first time has prompted us to invest in  Salesforce . There are a few gotchas with signing up for a Salesforce trial...

Listen to the 7 Minute Security podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.