Brian Johnson

7 Minute Security

7 Minute Security is a weekly information security podcast focusing on penetration testing, blue teaming and building a career in security. The podcast also features in-depth interviews with industry leaders who share their insights, tools, tips and tricks for being a successful security engineer.

Author

Brian Johnson

Category

Technology

Podcast website

7MinSec.com

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

7MS #705: A Phishing Campaign Fail Tale 12.12.2025

This might be obvious, but security is not all domain admin dancing and maximum pwnage. Sometimes, despite my best efforts, a security project does a faceplant. Today's episode focuses on a phishing campaign that had plenty of "bites" but got immediately shut down – for reasons I still don't understand.

7MS #704: DIY Pentest Dropbox Tips – Part 12 05.12.2025

Hola friends!  My week has very much been about trying to turnaround pentest dropboxes as quickly as possible.  In that adventure, I came across two time-saving discoveries: Using a  Proxmox LXC  as a persistent remote access method Writing a Proxmox post-deployment script that installs Splashtop on the Windows VM, and resets the admin passwords on both VMs, all from the Proxmox SSH console withou...

7MS #703: Tales of Pentest Pwnage – Part 79 28.11.2025

Happy Thanksgiving week friends! Today we're celebrating a turkey and pie overload by sharing another fun tale of pentest pwnage! It involves using  pygpoabuse  to hijack a GPO and turn it into our pentesting puppet!  Muahahahahaah!!!!  Also: This week over at  7MinSec.club  we looked at how to  defend  against some common SQL attacks We're  very  close to offering our brand new LPLITE:GOAD 3-day...

7MS #702: Should You Hire AI to Run Your Next Pentest? 21.11.2025

Hello friends, in today's episode I give an audio summary of a talk I gave this week at the MN GOVIT Symposium called "Should You Hire AI to Run Your Next Pentest?"  It's not a  pro- AI celebration, nor is it an  anti- AI bashing.  Rather, the talk focuses on my experiences using both free and paid AI services to guide me through an Active Directory penetration test.

7MS #701: What I'm Working on This Week – Part 5 14.11.2025

Hello friends!  This week I'm talking about what I'm working on this week, including: Preparing a talk called  Should You Hire AI to Run Your Next Pentest  for the  Minnesota GOVIT Symposium . Playing with  Lithnet AD password protection  (I will show this live on next week's  Tuesday TOOLSday ). The Light Pentest logo contest has a winner!

7MS #700: Pretender 07.11.2025

Today is episode 700 of the 7MinSec podcast! Oh my gosh. My mom didn't think we could do it, but we did. Instead of a big blowout with huge news, giveaways and special guests, today is a pretty standard issue episode with a (nearly) 7-minute run time! The topic of today's episode is Pretender (which you can download  here  and read a lot more about  here ).  The tool authors explain the motivation...

7MS #699: Pre-Travel Security Tips 31.10.2025

Today we discuss some pre-travel tips you can use before hopping on a plane to start a work/personal adventure. Tips include: Updating the family DR/BCP plan Lightening your purse/wallet Validating/testing backups and restores Ensuring your auto coverage is up to snuff

7MS #698: Baby's First ProjectDiscovery 24.10.2025

Today I give a quick review of the cloud version of  ProjectDiscovery (not a sponsor!).

7MS #697: Pwning Ninja Hacker Academy – Part 4 18.10.2025

Today your pal and mine Joe "The Machine" Skeen pwn one of the two  Ninja Hacker Academy  domains!  This pwnage included: Swiping service tickets in the name of high-priv users Dumping secrets from wmorkstations Disabling AV Extracting hashes of gMSA accounts We didn't get the second domain pwned, and so I was originally thinking about doing a part 5 in November, but changed my mind.  Going forwar...

7MS #696: Baby's First Security Ticketing System 10.10.2025

In today's episode: I got a new  podcast doodad I really like  JitBit  as a security ticketing system (not a sponsor) The  Threat Hunting with Velociraptor  2-day training was great.   Highly  recommend.  I got inspired to take this class after watching the 1-hour primer  here .

7MS #695: Tales of Pentest Pwnage - Part 78 03.10.2025

Today's tale of pentest pwnage involves: Using  mssqlkaren  to dump sensitive goodies out of SCCM Using a specific fork of  bloodhound  to find machines I could force password resets on (warning: don't do this in prod…read  this !) Don't forget to check out our weekly Tuesday TOOLSday – live every Tuesday at 10 a.m. over at  7MinSec.club !

7MS #694: Tales of Pentest Pwnage – Part 77 26.09.2025

Hey friends, today I talk about how fun it was two combine two cool pentest tactics, put them in a blender, and move from local admin to mid-tier system admin access (with full control over hundreds of systems)! The  Tuesday TOOLSday video we did over at 7minsec.club will help bring this to life as well.

7MS #693: Pwning Ninja Hacker Academy – Part 3 19.09.2025

This week your pal and mine Joe "The Machine" Skeen kept picking away at pwning  Ninja Hacker Academy .  To review where we've been in parts 1 and 2: We found a SQL injection on a box called  SQL,  got a privileged Sliver beacon on it, and dumped mimikatz info From that dump, we used the  SQL  box hash to do a BloodHound run, which revealed that we had excessive permissions over the  Computers  OU...

7MS #692: Tales of Pentest Pwnage – Part 76 12.09.2025

Happy Friday! Today's another hot pile of pentest pwnage. To make it easy on myself I'm going to share the whole narrative that I wrote up for someone else: I was on a pentest where a DA account would sweep the networks every few minutes over SMB and hit my box. But SMB signing was on literally everywhere. The fine folks here recommended I try relaying to something NOT SMB, like MSSQL. This articl...

7MS #691: Tales of Pentest Pwnage – Part 75 05.09.2025

Holy schnikes, today might be my favorite tale of pentest pwnage ever. Do I say that almost every episode? yes. Do I mean it? Yes. Here are all the commands/links to supplement today's episode: Got an SA account to a SQL server through  Snaffler -ing With that SA account, I learned how to coerce Web auth from within a SQL shell – read more about that  here I relayed that Web auth with  ntlmrelayx...

7MS #690: Tales of Pentest Pwnage – Part 74 29.08.2025

Today's tale of pentest pwnage is a classic case of "If your head is buried in the pentest sand, pop it out for a while, touch grass, and re-enumerate what you've already enumerated, because that can lead to absolute GOLD!"

7MS #689: Pwning Ninja Hacker Academy – Part 2 22.08.2025

Hello friends!  Today your friend and mine, Joe "The Machine" Skeen joins me as we keep chipping away at pwning  Ninja Hacker Academy !  Today's pwnage includes: "Upgrading" our Sliver C2 connection to a full system shell using  PrintSpoofer ! Abusing nanodump to do an lsass minidump….and find our first cred. Analyzing BloodHound data to find (and own) excessive permissions against Active Director...

7MS #688: Building a Pentest Training Course Is Fun and Frustrating 16.08.2025

Today I talk about a subject I love while also driving me crazy at the same time: building a pentest training course! Specifically, I dissect a fun/frustrating GPO attack that I need to build very carefully so that every student can pwn it while also not breaking the domain for everybody else. I also talk about how three different flavors of AI failed me in solving a simple task.

7MS #687: A Peek into the 7MS Mail Bag – Part 5 11.08.2025

Hi friends, we're doing something today we haven't done in a hot minute: take a dip into the 7MinSec mail bag! Today we cover these questions: If I'm starting a solo business venture as a security consultancy, is it a good idea to join forces with other solo security business owners and form a consortium of sorts? Have you ever had anything go catastrophically wrong during a pentest?  Yes, and thi...

7MS #686: Our New Pentest Training Course is Almost Ready 01.08.2025

Oh man, I'm so excited I can hardly sleep. Our new three-day (4 hours per day) training is getting closer to general release. I talk about the good/bad/ugly of putting together an attack-sensitive lab that students can abuse (but hopefully not break!), and the technical/curriculum-writing challenges that go along with it.

7MS #685: The Time My Neighbor Almost Got Scammed Out of $13K 25.07.2025

Today's kind of a "story time with your friend Brian" episode: a tale of how my neighbor almost got scammed out of $13k.  The story has a lot of red flags we can all keep in mind to keep ourselves (as well as kids/friends/parents/etc.) safer from these types of shenanigans.

7MS #684: Pwning Ninja Hacker Academy 18.07.2025

Hey friends, today we start pwning  Ninja Hacker Academy  – cool CTF-style lab that has you start with  no  cred and try to conquer domain admin on  two  domains!

7MS #683: What I'm Working on This Week - Part 4 12.07.2025

This week I'm working on a mixed bag of fun security and marketing things: A pentest I'm stuck on My latest lab CTF obsession:  Ninja Hacker Academy A cool "about 7MinSec" marketing video that was recorded in a pro studio!

7MS #682: Securing Your Family During and After a Disaster – Part 7 04.07.2025

Today's episode is a downer! We talk about things you might want to have buttoned up for when you are eventually not alive anymore: Living will Buried vs. cremated? Funeral plans Funeral PHOTOS? I also talk about how my dad broke his ribs while trying to break a chimpmunk, and how a freak 4-wheeler accident also had my ribs in agony.

7MS #681: Pentesting GOAD – Part 3 27.06.2025

Today Joe "The Machine" Skeen and I pwn the third and final realm in the world of  GOAD (Game of Active Directory) : essos.local!  The way we go about it is to do a WinRM connection to our previously-pwned Kingslanding domain, coerce authentication out of MEEREEN (the DC for essos.local) and then capture/abuse the TGT with Rubeus!  Enjoy.

Listen to the 7 Minute Security podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.