Brian Johnson

7 Minute Security

7 Minute Security is a weekly information security podcast focusing on penetration testing, blue teaming and building a career in security. The podcast also features in-depth interviews with industry leaders who share their insights, tools, tips and tricks for being a successful security engineer.

Author

Brian Johnson

Category

Technology

Podcast website

7MinSec.com

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

7MS #605: Navigating the Demands of Tech Leadership with Amanda Berlin of Blumira 05.01.2024

Today our friend  Amanda Berlin , Lead Incident Detection Engineer at  Blumira , joins us to talk about being more mentally healthy in 2024! P.S. - did you miss Amanda's past visits to the program? Then check out episode  518 ,  536  and  588 . Be sure to check out the next edition of Amanda's  Defensive Security Handbook when it comes out in later January, 2024!

7MS #604: A Two Tool Teaser 02.01.2024

Today we tease two upcoming tool releases (shooting for Q1, 2024): TCMLobbyBBQ  - a Python script for PC players of  The Texas Chain Saw Massacre  game to help players get out of lobbies and into live games ASAP! The script uses  PyAutoGUI  to take screenshots of what part of the game you're in, then make appropriate key presses and mouse clicks to get into lobby queues, then alert you when the ga...

7MS #603: Monitoring Your Tailscale Network with Uptime Kuma 24.12.2023

Today I look at potentially replacing  Splashtop  and  UptimeRobot  (check out our episode about it  here ) with  Tailscale  and  Uptime Kuma . The missing link (which I'd love some help with) is answering this security question: how can I setup Tailscale so that my 7MinSec testing box can connect to all these NUCs spread around the globe, but those NUCs  cannot connect to each other (in case one...

7MS #602: How to Succeed in Business Without Really Crying - Part 14 15.12.2023

Today we're talkin' business! Specifically: How to (gently) say "no" to (some) client projects How to (politely) challenge end-of-year deadlines An idea I'm kicking around in the lab - where I might do away with UptimeRobot and Splashtop in favor of  Tailscale  and  Uptime Kuma

7MS #601: Breaking Up With Active Directory 11.12.2023

Today our pal Nate Schmitt (you may remember him from his excellent  Dealing with Rejection: A DMARC Discussion  Webinar) joins us to talk about breaking up with Active Directory. He covers: Why would you want to consider removing AD from your environment? What are common items to plan for? What steps should you take to efficiently plan a migration? What common challenges or considerations will yo...

7MS #600: First Impressions of Using AI on Penetration Tests 01.12.2023

Hey friends, today I share my experience working with ChatGPT,  Ollama.ai ,  PentestGPT  and  privateGPT  to help me pentest Active Directory, as well as a machine called  Pilgrimage from HackTheBox . Will AI replace pentesters as we know them today? In my humble opinion: not quite yet. Check out today's episode to hear more, and please join me on Wednesday, December 6 for my Webinar on this topic...

7MS #599: Baby's First Responsible Disclosure 25.11.2023

Today we talk about our first experience working through the responsible disclosure process after finding vulnerabilities in a security product. We cannot share a whole lot of details as of right now, but wanted to give you some insight into the testing/reporting process thus far, which includes the use of: BulletsPassView MITMsmtp mitmproxy

7MS #598: Hacking Billy Madison - Part 4 17.11.2023

Today our good buddy  Paul  and I keep trying to hack the  VulnHub  machine based on the movie  Billy Madison  (see part  1  and  2  and  3 ). In today's  final  chapter, Paul and I: Find Eric's secret SSH back door Locate and decrypt a hidden file with Billy's homework Build wordlists with  cewl Save Billy from the evil clutches of Eric Gordon!!!

7MS #597: Let's JAMBOREE (Java-Android-Magisk-Burp-Objection-Root-Emulator-Easy) with Robert McCurdy 11.11.2023

Today we had a blast talking with Robert McCurdy about  JAMBOREE (Java-Android-Magisk-Burp-Objection-Root-Emulator-Easy) ! JAMBOREE allows you to quickly spin up a portable Git/Python/Java environment and much more! From a pentesting POV, you can whip up an Android pentesting environment, BloodHound/SharpHound combo, Burp Suite...the list goes on!

7MS #596: How to Succeed in Business Without Really Crying - Part 13 04.11.2023

After about a year break ( last edition of this series was in October, 2022 , we're back with an updated episode of How to Succeed in Business Without Really Crying. We cover: Why we're not planning on selling the business any time soon Fast Google Dorks Scan Using ProtonVPN  via command line Our  pre  first impressions of a pentesting SaaS tool you've almost definitely heard of    

7MS #595: Choosing the Right XDR Strategy with Matt Warner of Blumira 31.10.2023

Today we're joined by Matt Warner of Blumira (remember him from episodes  #551  and  #529  and  #507 ?) to talk about choosing the right XDR strategy! There's a lot to unpack here. Are EDR, MDR and XDR related? Can you get them all from one vendor - and  should  you? Do you run them on-prem, in the cloud, or both? Join us as Matt answers these questions and more!

7MS #594: Using PatchMyPC to Auto-Update Pentest Dropboxes 23.10.2023

Today we're talking about how you can use  PatchMyPc  to keep your home PC and/or pentest dropbox automatically updated with the latest/greatest patches!

7MS #593: Hacking Billy Madison - Part 3 15.10.2023

Hey friends, today my  Paul  and I kept trying to hack the  VulnHub  machine based on the movie  Billy Madison  (see part  1  and  2 ). In our journey we learned some good stuff: Port knocking is awesome using utilities like  knock : /opt/knock/knock 10.0.7.124 1466 67 1469 1514 1981 1986 Sending emails via command line is made (fairly) easy with swaks: swaks --to eric@madisonhotels.com --from vva...

7MS #592: 7 Steps to Recover Your Hacked Facebook Account 06.10.2023

Today we're talking about 7 steps you can take to (hopefully) reclaim a hacked Facebook account. The key steps are: Ask Facebook for help (good luck with that) Put out an SOS on your socials Flag down the FBI Call the cops! Grumble to your attorney general Have patience Lock it down (once you get the account back)! Also, I have to say that  this article  was a  fantastic  resource in helping me cr...

7MS #591: Tales of Pentest Pwnage - Part 52 29.09.2023

Today we talk about an awesome path to internal network pentest pwnage using  downgraded authentication  from a domain controller, a tool called  ntlmv1-multi , and a boatload of cloud-cracking power on the cheap from  vast.ai . Here's my chicken scratch notes for how to take the downgraded authentication hash capture (using  Responder.py -I eth0 --lm ) and eventually tweeze out the NTLM hash of t...

7MS #590: Hacking Billy Madison - Part 2 22.09.2023

Today my  Paul  and I continued hacking  Billy Madison  (see part one  here ) and learned some interesting things: You can fuzz a URL with a specific file type using a format like this: wfuzz -c -z file,/root/Desktop/wordlist.txt --hc 404 http://x.x.x.x/FUZZ.cap To rip .cap files apart and make them "pretty" you can use  tpick : tcpick -C -yP -r tcp_dump.pcap Or tcpflow: apt install tcpflow tcpflo...

7MS #589: Tales of Pentest Pwnage - Part 51 15.09.2023

In today's tale of pentest pwnage we talk about: The importance of local admin and how access to even  one  server might mean instant, full control over their backup or virtualization infrastructure Copying files via WinRM when copying over SMB is blocked: $sess = New-PSSession -Computername SERVER-I-HAVE-LOCAL-ADMIN-ACCESS-ON -Credential * ...then provide your creds...and then: copy-item c:\super...

7MS #588: Becoming a Sysmon Sensei with Amanda Berlin 08.09.2023

Today Amanda Berlin from  Blumira  teaches us how to unlock the power of Sysmon so we can gain insight into the good, bad and ugly things happening on our corporate endpoints!  Key takeaways: Sysmon  turns your windows logging up to 11, and pairs well with a config file like  this one  or  this one . Careful if you are are running sysmon on non-SSD drives - the intense number of writes might bring...

7MS #587: Hacking Billy Madison 01.09.2023

Today my pal Paul from  Project7  and I hack the heck out of  Billy Madison  a vulnerable virtual machine that is celebrating its 7th anniversary this month!

7MS #586: DIY Pentest Dropbox Tips – Part 8 25.08.2023

Today, sadly, might be the last episode of DIY pentest dropbox tips for a while because I found (well, ChatGPT did actually) the missing link to 100% automate a Kali Linux install! Check  episode #449  for more info on building your Kali preseed file, but essentially the last line in my file runs a  kali.sh  script to download/install all the pentest tools I want. The "missing link" part is I figu...

7MS #585: DIY Pentest Dropbox Tips – Part 7 18.08.2023

Hey friends, today I'm super excited to share I found the missing link! Specifically, the missing piece that now allows me to create  fully automated  Windows 10 installs that serve as virtual pentest jumpboxes. Here are the high points: When your deployment script is finishing and you need the system to reboot and run some final commands, temporarily add your account as an auto-login account like...

7MS #584: Tales of Pentest Pwnage - Part 50 11.08.2023

In today's tale of pwnage, we'll talk about how domain trusts can be dangerous because they have...well...trust issues.

7MS #583: Cred-Capturing Phishing with Caddy Server 04.08.2023

Today we talk about crafting cool cred-capturing phishing campaigns with  Caddy server ! Here's a quick set of install commands for Ubuntu: sudo apt install -y debian-keyring debian-archive-keyring apt-transport-https curl -1sLf 'https://dl.cloudsmith.io/public/caddy/stable/gpg.key' | sudo gpg --dearmor -o /usr/share/keyrings/caddy-stable-archive-keyring.gpg curl -1sLf 'https://dl.cloudsmith.io/pu...

7MS #582: Using Wazuh as a SIEM for Work and Home 31.07.2023

Today we had a blast playing with  Wazuh  as a SIEM you can use for work and/or home. Inspiration for this episode came from  Network Chuck . This one-liner will literally get Wazuh installed in about 5 minutes: curl -sO https://packages.wazuh.com/4.4/wazuh-install.sh && sudo bash ./wazuh-install.sh -a P.S. if you accidentally close your command window before writing down the admin password (like...

7MS #581: Tales of Pentest Pwnage - Part 49 21.07.2023

Oooo, giggidy! Today's tale of pentest pwnage is about pwning vCenter with CVE-2021-44228 - a vulnerability that lets us bypass authentication entirely and do/take what we want from vCenter! Key links to make the magic happen: How to exploit log4j manually in vCenter How to automate the attack! Tool to steal the SAML database you extract from vCenter

Listen to the 7 Minute Security podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.