Brian Johnson

7 Minute Security

7 Minute Security is a weekly information security podcast focusing on penetration testing, blue teaming and building a career in security. The podcast also features in-depth interviews with industry leaders who share their insights, tools, tips and tricks for being a successful security engineer.

Author

Brian Johnson

Category

Technology

Podcast website

7MinSec.com

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

7MS #580: Hacking Tommy Callahan - Part 3 17.07.2023

Today me and my pal Paul from  Project7  did a live hacking session and finally got the  Callahan Auto brake pad Web app  back online! Hopefully you enjoyed this hacking series. The feedback has been great, so we may have to take a crack at  Billy  in the near future as well.

7MS #579: Hacking Tommy Callahan - Part 2 07.07.2023

Hey friends, today we're continuing our series on pwning the  Tommy Boy VM on VulnHub  VM! P.S. did you miss part one? Check it out on  YouTube . Joe "The Machine" Skeen and I had a blast poking and prodding at the VM in hopes to fix the broken Callahan Auto brake-ordering Web app. Some tips/tricks we cover: It's always a good idea to look at a site's  robots.txt  file crunch  is awesome for makin...

7MS #578: Interview with Mike Toole of Blumira 30.06.2023

Today I'm excited to share a featured interview with our new friend Mike Toole of  Blumira . We talk about all things EDR, including: How does it differ from something like Windows Defender? What things do I need to keep in mind if I'm in the market for an EDR purchase? Is Mac EDR any good? How do attackers bypass EDR? Will AI create industructible malware, take over the human race and then use ou...

7MS #577: Tales of Pentest Pwnage - Part 48 16.06.2023

Holy schnikes - this episode is actually 7 minutes long! What a concept! Anyway, today I give you a couple tips that have helped me pwn some internal networks the last few weeks, including: Getting a second (and third?) opinion on Active Directory Certificate Services vulnerabilities! Analyzing the  root  domain object in BloodHound to find some misconfigs that might equal instant domain admin acc...

7MS #575: Annoying Attackers with ADHD - Part 2 09.06.2023

Hey friends! Today we're taking a second look at  ADHD - Active Defense Harbinger Distribution  - a cool VM full of tools designed to annoy/attribute/attack pesky attackers! The tools covered today include: PHP-HTTP-TARPIT A tool to confuse and waste bot/scanner/hacker time. Grab it  here  and check out our setup instructions: sudo git clone https://github.com/msigley/PHP-HTTP-Tarpit.git /opt/tarp...

7MS #574: Annoying Attackers with ADHD 02.06.2023

Hey friends! Today we're looking at  ADHD - Active Defense Harbinger Distribution  - a cool VM full of tools designed to annoy/attribute/attack pesky attackers! ADHD gets you up and running with these tools quickly, but the distro hasn't been updated in a while, so I switched to a vanilla  Kali  system and setup a  cowrie SSH honeypot as follows (see 7ms.us for full list of commands).

7MS #573: Securing Your Mental Health - Part 4 26.05.2023

Today we're talking about reducing anxiety by hacking your mental health with these tips: Using  personal automation  to text people important reminders Using  Remind  to create a personal communication "class" with your family members Using  Smartsheet  (not a sponsor) to create daily email "blasts" to yourself about all the various project todos you need to tackle

7MS #572: Protecting Your Domain Controllers with LDAP Firewall 19.05.2023

Today we look at  LDAP Firewall  - a cool (and free!) way to defend your domain controllers against  SharpHound  enumeration,  LAPS  password enumeration, and the  noPac attack .

7MS #571: Simple Ways to Test Your SIEM - Part 2 12.05.2023

Hey friends! This week I spoke at the Secure360 conference in Minnesota on  Simple Ways to Test Your SIEM . This is something I covered  a while back  on the podcast, but punched up the content a bit and built a refreshed a two-part  GitHub gist  that covers: Questions you can ask a prospective SIEM/SOC solution to figure out which one is the right fit for you All the tools/tips/scripts/etc. you n...

7MS #570: How to Build a Vulnerable Pentest Lab - Part 4 05.05.2023

SafePass.me is the only enterprise solution to protect organizations against credential stuffing and password spraying attacks. Visit  safepass.me  for more details, and tell them 7 Minute Security sent you to get a 10% discount! In today's episode we staged an NTLM relay attack using a  vulnerable SQL server . First we used CrackMapExec (see our two part series on Cracking and Mapping and Execing...

7MS #569: Interview with Jim Simpson of Blumira 28.04.2023

Today we're excited to share a featured interview with our new friend Jim Simpson, CEO of  Blumira . Jim was in security before it was hip/cool/lucrative, working with a number of startups as well as some big names like Duo. Blumira and 7 Minute Security have a shared love for helping SMBs be more secure, so it was great to chat with Jim about the IT/security challenges faced by SMBs, and what we...

7MS #568: Lets Play With the 2023 Local Administrator Password Solution! 21.04.2023

Hey friends, today we're playing with the new (April 2023) version of  Local Administrator Password Solution (LAPS) . Now it's baked right into PowerShell and the AD Users and Tools console. It's awesome, it's a necessary blue team control for any size company, and you should basically stop reading this and install LAPS now.

7MS #567: How to Build an Intentionally Vulnerable SQL Server 14.04.2023

Hey friends, today we're talking about building an intentionally vulnerable SQL server, and here are the key URLs/commands talked about in the episode: Download SQL Server  here Install SQL via  config .ini file Or, install SQL via pure  command line Deploy SQL with a service account while also starting TCP/IP and named pipes automagically: setup.exe /Q /IACCEPTSQLSERVERLICENSETERMS /ACTION="insta...

7MS #566: Tales of Pentest Pwnage - Part 47 31.03.2023

Ok, I know we say this every time, but it is true  this time  yet again: this is our favorite tale of pentest pwnage. It involves a path to DA we've never tried before, and introduced us to a new trick that one of our favorite old tools can do!

7MS #565: How to Simulate Ransomware with a Monkey 24.03.2023

Hey friends, today we talk through how to simulate ransomware (in a  test  environment!) using  Infection Monkey . It's a cool way to show your team and execs just how quick and deadly an infection can be to your business. You can feed the monkey a list of usernames and passwords/hashes to use for lateral movement, test network segmentation, set a UNC path of files to actually encrypt (careful - r...

7MS #564: First Impressions of OVHcloud Hosted vCenter 17.03.2023

Today we offer you some first impressions of  OVHcloud  and how we're  seriously  considering moving our  Light Pentest LITE  training class to it! TLDR: It runs on vCenter, my first and only virtualization love! Unlimited VM "powered on" time and unlimited bandwidth Intergration with PowerShell so you can run a single script to "heal" your environment to a gold image Easy integration with pfSense...

7MS #563: Cracking and Mapping and Execing with CrackMapExec - Part 2 10.03.2023

Hey friends, today we're covering part 2 of our series all about cracking and mapping and execing with CrackMapExec. Specifically we cover: # Enumerate where your user has local admin rights: cme smb x.x.x.x/24 -u user -p password # Set wdigest flag: cme smb x.x.x.x -u user -p password -M wdigest -o ACTION=enable # Dump AD creds: cme smb IP.OF.DOMAIN.CONTROLLER -u user -p password --ntds --enabled...

7MS #562: Cracking and Mapping and Execing with CrackMapExec 03.03.2023

Hey friends, today we covered many things cracking and mapping and execing with  CrackMapExec . Specifically: # General enumeration to see if your account works, and where: cme smb x.x.x.x -u username -p pass # Check if print services are enabled: cme smb x.x.x.x -u username -p pass -M spooler # Check for the nopac vuln: cme smb x.x.x.x -u username -p pass -M nopac # Find GP passwords: cme smb DOM...

7MS #561: Interview with Chris Furner of Blumira 24.02.2023

Today I sat down with Chris Furner of  Blumira  to talk about all things cyber insurance. Many of 7MinSec's clients are renewing their policies this time of year, and many are looking into policies for the first time. Naturally, there are a ton of questions to ask and things to think about to make good coverage decisions for your business: How do I get started in looking for a cyber policy - with...

7MS #560: 7MOOCH - Dolphin Rides Are Done Dude 17.02.2023

Hey friends, I took a mental health break this week and pre-podcasted this episode of a new series called  7MOOCH :  7   M inutes  o f  O nly  Ch uckles. In today's story, we unpack a situation in Hawaii that made me exclaim the following quite loudly: "Dolphin rides are done, dude!"

7MS: #559: Tales of Pentest Pwnage - Part 46 10.02.2023

Ooooo giggidy! Today's episode is about a pentest pwnage path that is super fun and interesting, and I've now seen 3-4 times in the wild. Here are some notes from the audio/video that will help bring this to life for you (oh and read  this article  for a great tech explanation of what's happening under the hood): Change the Responder.conf file like so: ; Custom challenge. ; Use "Random" for genera...

7MS #558: How to Build a Vulnerable Pentest Lab - Part 2 07.02.2023

Today we continue part 2 of a series we started  a few weeks ago  all about building a vulnerable pentesting lab. Check out the video above, and here are the main snippets of code and tips to get you going: Use  Youzer  to import a bunch of bogus users into your Active Directory: sudo python ./youzer.py --generate --generate_length 20 --ou "ou=Contractors,dc=brifly,dc=us" --domain brifly.us --user...

7MS #557: Better Passive Network Visibility Using Teleseer 27.01.2023

Today we're talking about  Teleseer , which is an awesome service to give you better network visibility - whether you're on the blue, red or purple team! It all starts with a simple packet capture, and ends with gorgeous visuals and insight into what the heck is on your network and - from a pentester's perspective - delicious vulnerabilities that may lie within!

7MS #556: How to Build a Vulnerable Pentest Lab 20.01.2023

Today's episode is brought to us by our friends at  Blumira ! Today we kick off a series all about building your own vulnerable pentest lab from scratch, specifically: Spinning up a domain controller with a few lines of PowerShell Installing Active Directory Domain Services Setting up an intentionally cruddy password policy Baking in the  MS14-025  vulnerability P.S. if you're looking for a more a...

7MS #555: Light Pentest eBook 1.1 Release 13.01.2023

Today we're releasing version 1.1 of our  Light Pentest eBook . Changes discussed in today's episode (and shown live in the accompanying  YouTube video ) include: Some typos and bug fixes A new section on finding systems with unconstrained delegation and exploiting them A new section on finding easily pwnable passwords via password spraying A new section relaying credentials with MITM6 (be careful...

Listen to the 7 Minute Security podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.