Brian Johnson

7 Minute Security

7 Minute Security is a weekly information security podcast focusing on penetration testing, blue teaming and building a career in security. The podcast also features in-depth interviews with industry leaders who share their insights, tools, tips and tricks for being a successful security engineer.

Author

Brian Johnson

Category

Technology

Podcast website

7MinSec.com

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

7MS #430: Interview with Dan DeCloss 02.09.2020

Today we're thrilled to have our friend and  PlexTrac  CEO Dan DeCloss back to the program! (P.S. PlexTrac is launching  runbooks  as a feature - and you should definitely check out PlexTrac's  upcoming Webinar about runbooks on September 9! ). We also did a  PlexTrac 101 Webinar  with them recently! You may remember Dan from such podcasts as  this one  when we first  talked to him in 2019 . Dan a...

7MS #429: Cyber News - Free Bitcoin for Everybody Edition 26.08.2020

Hola! We're back again with our amigo Joe "The Machine" Skeen (a.k.a.  Gh0sthax ) who has prepared some awesome and actionable news stories for us to digest. Today's stories include: The Twitter hack that promised free Bitcoin for everybody - with good coverage by  Krebs  and  Threatpost Garmin's personal and painful experience with  ransomware Joe offers 7 tips any org can use to reduce their lik...

7MS #428: Tales of Internal Network Pentest Pwnage - Part 20 19.08.2020

Welcome to another fun tale of internal pentest pwnage! Today's tale includes these helpful informational tidbits: My understanding is that in order for  mitm6  relay attacks to work against DCs, those DCs have to have LDAPS config'd properly. Use  nmap -sV -p646 name.of.domain.controller  to verify this (thanks  this site  for the tip!) PowerView  is awesome when used with  Find-InterestingDomain...

7MS #427: Interview with Ameesh Divatia from Baffle 12.08.2020

Today we're thrilled to welcome Ameesh Divatia from Baffle back to the program. We first met Ameesh back in  episode 349  and today he's back to discuss a slew of additional hot security topics, including: Misconfigured cloud databases Why is this such a common issue, and how can we address it? Wait wait wait...I just spun up a machine in Azure, AWS, Digital Ocean, etc. Isn't it secure because.......

7MS #426: Tales of Internal Pentest Pwnage - Part 19 07.08.2020

This podcast is sponsored by Arctic Wolf, whose Concierge Security teams Monitor, Detect and Respond to Cyber threats 24/7 for thousands of customers around the world. Arctic Wolf. Redefining cybersecurity. Visit  Arcticwolf.com/7MS  to learn more. First and foremost, I have to say that 7 Minute Security's official stance on toads is that nobody should be licking them at any time, for any reason....

7MS #425: DIY Pentest Dropbox Tips - Part 2 30.07.2020

Today's episode is all about creating and deploying your own pentest dropbox! In  part 1  I talked about some "gotchas" but this time around I'm ready to dump a whole slug of specific and updated tips on ya! Below are the tips covered in this episode that are better read than said: For the Windows VM Turn on RDP with PowerShell: Set-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Termin...

7MS #424: Cyber News - Everything is Pwned Edition 22.07.2020

Hello! We're back with our pal Joe "The Machine" Skeen (a.k.a.  Gh0sthax ) who has prepared some awesome and actionable news stories for us to digest. Today's stories include: Hackers are trying to steal admin passwords from F5 devices Secret service reports increase in hacked MSPs Most Popular Home Routers Have 'Critical' Flaws "Sigred" DNS vulnerability in Microsoft DNS

7MS #423: Tales of Internal Pentest Pwnage - Part 18 15.07.2020

This is an especially fun tale of pentest pwnage because it involves D.D.A.D. (Double Domain Admin Dance) and varying T.T.D.A. (Time to Domain Admin). The key takeaways I want to share from these tests are as follows: Responder.py -i eth0 -rPv  is AWESOME. It can make the network rain hashes like manna from heaven! Testing the egress firewall is easy with  this script . Consider  this SANS article...

7MS #422: Eating the Security Dog Food - Part 2 10.07.2020

SafePass.me is the only enterprise solution to protect organizations against credential stuffing and password spraying attacks. Visit [safepass.me]( https://safepass.me/?7ms422  for more details, and tell them 7 Minute Security sent you to get a 10% discount! Today's episode continues the work we started in  episode #419 . We talk about the importance of having a good foundation of security docume...

7MS #421: Cyber News - Verizon DBIR Edition 01.07.2020

Today my pal  Gh0sthax  and I pick apart the  Verizon Data Breach Investigations Report  and help you turn it into actionable items so you can better defend your network! I'm especially excited because today's episode marks two important 7MS firsts: The episode has been crafted by a  professional podcast producer The episode has been transcribed by a  professional transcription service

7MS #420: Tales of Internal Pentest Pwnage - Part 17 26.06.2020

Today's episode is a fun tale of pentest pwnage! Interestingly, to me this pentest had a ton of time-sponging issues on the front end, but the TTDA (Time to Domain Admin) was maybe my fastest ever. I had to actually roll a fresh Kali VM to upload to the customer site, and I learned (the hard way) to make that VM disk as lean as possible. I got away with a 15 gig drive, and the OS+tools+updates too...

7MS #419: Eating the Security Dog Food 17.06.2020

Today we're talking about eating the security dog food! What do I mean by that? Well, a lot of security companies I worked for in the past preached to clients about the importance of having a good security program, but didn't have one of their own! I'm trying to break that pattern now that I'm in a position to lead an information security program for 7MS. In today's episode we talk about getting y...

7MS #418: Securing Your Mental Health 11.06.2020

SafePass.me is the only enterprise solution to protect organizations against credential stuffing and password spraying attacks. Visit  safepass.me  for more details, and tell them 7 Minute Security sent you to get a 10% discount! Today's episode is all about mental health! I talk about some of my challenges with stress/anxiety and how I finally put on my big boy pants, dropped some misconceptions...

7MS #417: Vulnerability Scanning Tips and Tricks 04.06.2020

Today's episode is all about getting the most value out of your vulnerability scans, including: Why, IMHO you should  only  do credentialed scans Policy tweaks that will keep servers from tipping over and printers from printing novels of gibberish ;-) How to make your scan report more actionable and less unruly Turning up logging to 11 (use with caution!) A small tweak to an external scan policy t...

7MS #416: Pi-hole 5.0 28.05.2020

This podcast is sponsored by Arctic Wolf, whose Concierge Security teams Monitor, Detect and Respond to Cyber threats 24/7 for thousands of customers around the world. Arctic Wolf. Redefining cybersecurity. Visit  Arcticwolf.com/7MS  to learn more. Today we're talking about some of my favorite features of  Pi-hole 5.0 . Including: WARNING! WARNING! Upgrading from 4.x is a one-way operation! Per-cl...

7MS #415: Cyber News 21.05.2020

Today's episode kicks off a fun little experiment where my pal Joe Skeen and I cover some of the week's interesting security news stories, how they might affect you, and what you can do to make you and your company more secure. This week's stories: Salt stack RCE ( Daily Swig  /  Cyber Scoop ) Malware uses Corporate MDM as attack vector ( Checkpoint ) Critical vulns in Sharefile ( Citrix ) Shareho...

7MS #414: Tales of Pentest Fail #4 14.05.2020

SafePass.me is the only enterprise solution to protect organizations against credential stuffing and password spraying attacks. Visit  safepass.me  for more details, and tell them 7 Minute Security sent you to get a 10% discount! Today I'm excited to share more tales of pentest FAIL with you. Today's tales include: Accidentally scanning assets that belong to an agency that nobody should be messing...

7MS #413: PCI Professional Certification (PCIP) - Part 3 07.05.2020

Hey everybody! I hope you're hanging in there during quarantine and staying healthy. Today is part 3 of our ongoing series all about becoming a  PCIP . The good news is I'm  finally ,  actually  registered for the cert and have started diving into the training! So in today's episode I want to regurgitate some of what I'm learning to whet your appetite (or not) for this particular certification. Sp...

7MS #412: Tips for Working Safely and Securely From Home 01.05.2020

This podcast is sponsored by Arctic Wolf, whose Concierge Security teams Monitor, Detect and Respond to Cyber threats 24/7 for thousands of customers around the world. Arctic Wolf. Redefining cybersecurity. Visit Arcticwolf.com/7MS to learn more. In today's episode we share some tips for working more safely and securely from home, which for many of us is our new office for the foreseeable future!...

7MS #411: More Fun Stay-at-Home Security Projects 24.04.2020

SafePass.me is the only enterprise solution to protect organizations against credential stuffing and password spraying attacks. Visit safepass.me for more details, and tell them 7 Minute Security sent you to get a 10% discount! Today is sort of a continuation of episode 407 where we covered four fun stay-at-home security projects including FoldingAtHome building a headless pi-hole, redoing your ne...

7MS #410: PCI Professional Certification (PCIP) - Part 2 16.04.2020

This podcast is sponsored by Arctic Wolf, whose Concierge Security teams Monitor, Detect and Respond to Cyber threats 24/7 for thousands of customers around the world. Arctic Wolf. Redefining cybersecurity. Visit Arcticwolf.com/7MS to learn more. I'm gonna love you like coronavirus, I don't know what else to say I'm gonna love you like coronavirus, I'm gonna stand 6 feet away Yes our love was mean...

7MS #409: PCI Professional Certification (PCIP) 09.04.2020

SafePass.me is the only enterprise solution to protect organizations against credential stuffing and password spraying attacks. Visit safepass.me for more details, and tell them 7 Minute Security sent you to get a 10% discount! Today I'm starting a journey to become a PCI Professional (PCIP) , and I'll be periodically updating the status of this journey on the 7MS forums . You don't need to be a Q...

7MS #408: Cell Phone Security for Tweenagers - Part 2 03.04.2020

This episode of the 7MS podcast is brought to you by ITProTV. It's never too late to start a new career in IT or move up the later, and ITProTV has you covered. From CompTIA and Cisco to ECCouncil and VMWare. Get a 7-day free trial and save 30% off all plans by going to itpro.tv/7MS "I think of what the world could be If it did not have COVID-19 A million dreams is all it's gonna taaaaaaaaaaaaaaaa...

7MS #407: Four Fun Stay-at-Home Security Projects 26.03.2020

In today's episode I share four fun stay-at-home security projects - three with a security focus and one centered around music. Let's gooooooooo! FoldingAtHome The Folding At Home project helps use your GPU/CPU cycles for COVID-19 research. From the Web site: We need your help! Folding@home is joining researchers around the world working to better understand the 2019 Coronavirus (2019-nCoV) to acc...

7MS #406: Securing Your Family During and After a Disaster - Part 4 21.03.2020

This episode of the 7MS podcast is brought to you by ITProTV. It's never too late to start a new career in IT or move up the later, and ITProTV has you covered. From CompTIA and Cisco to ECCouncil and VMWare. Get a 7-day free trial and save 30% off all plans by going to itpro.tv/7MS First and foremost, I hope you all are doing well and taking care of yourselves. Today's episode focuses on disaster...

Listen to the 7 Minute Security podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.