Brian Johnson

7 Minute Security

7 Minute Security is a weekly information security podcast focusing on penetration testing, blue teaming and building a career in security. The podcast also features in-depth interviews with industry leaders who share their insights, tools, tips and tricks for being a successful security engineer.

Author

Brian Johnson

Category

Technology

Podcast website

7MinSec.com

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

7MS #554: Simple Ways to Test Your SIEM 06.01.2023

Today we talk about Simple Ways to Test Your SIEM. Feel free to check out the  YouTube version  of this presentation, as well as our  interview with Matt from Blumira  for even more context, but here are the essential tools and commands covered: Port scanning nmap 10.0.7.0/24  - basic nmap scan massscan -p1-65535,U:1-65535 --rate=1000 10.0.7.0/24 -v  - scan all 65k+ TCP and UDP ports! Password spr...

7MS #553: The Artificial Intelligence Throat Burn Episode 30.12.2022

Hey friends, today's episode is hosted by an AI from  Murf.ai  because I suffered a throat injury over the holidays and spent Christmas morning in the emergency room! TLDL: I'm fine, but if you want the (sort of) gory details and an update on my condition after my ENT appointment, check out today's episode. Otherwise, we'll see you next week when our regularly scheduled security content continues...

7MS #552: Tales of Pentest Pwnage - Part 45 24.12.2022

SafePass.me is the only enterprise solution to protect organizations against credential stuffing and password spraying attacks. Visit  safepass.me  for more details, and tell them 7 Minute Security sent you to get a 10% discount! Today's tale of pentest pwnage covers some of the following attacks/tools: Teleseer  for packet capture visualizations on steroids! Copernic Desktop Search Running  Respo...

7MS #551: Interview with Matt Warner of Blumira 16.12.2022

Today we welcome our pal Matthew Warner (CTO and co-founder of  Blumira ) back to the show for a  third  time (his first appearance was  #507  and second was  #529 ). I complained to Matt about how so many SIEM/SOC solutions don't catch early warning signs of evil things lurking in customer networks. Specifically, I whined about 7 specific, oft-missed attacks like port scanning, Kerberoasting, ASR...

7MS #550: Tales of Pentest Fail - Part 5 09.12.2022

This podcast is sponsored by Arctic Wolf, whose Concierge Security teams Monitor, Detect and Respond to Cyber threats 24/7 for thousands of customers around the world. Arctic Wolf. Redefining cybersecurity. Visit  Arcticwolf.com/7MS  to learn more. Hey friends, today's episode is extra special because it's our first episode we've ever done  live  and  with video(!) . Will we do it again? Who knows...

7MS #549: Interview with Christopher Fielder and Daniel Thanos of Arctic Wolf 02.12.2022

This podcast is sponsored by Arctic Wolf, whose Concierge Security teams Monitor, Detect and Respond to Cyber threats 24/7 for thousands of customers around the world. Arctic Wolf. Redefining cybersecurity. Visit  Arcticwolf.com/7MS  to learn more. Today my friends Christopher Fielder and Daniel Thanos from Arctic Wolf chat with me about what kinds of icky things bad guys/gals are doing to our net...

7MS #548: Tales of Pentest Pwnage - Part 44 25.11.2022

SafePass.me is the only enterprise solution to protect organizations against credential stuffing and password spraying attacks. Visit  safepass.me  for more details, and tell them 7 Minute Security sent you to get a 10% discount! Happy belated Thanksgiving! This is  not  a brag or a flex, but this episode covers a coveted achievement I haven't achieved in my whole life...until now:  TDAD: Triple D...

7MS #547: Tales of Pentest Pwnage - Part 43 18.11.2022

This podcast is sponsored by Arctic Wolf, whose Concierge Security teams Monitor, Detect and Respond to Cyber threats 24/7 for thousands of customers around the world. Arctic Wolf. Redefining cybersecurity. Visit  Arcticwolf.com/7MS  to learn more. Today we're talking about tales of pentest pwnage - specifically how much fun  printers can be to get Active Directory creds . TLDL: get into a printer...

7MS #546: Securing Your Mental Health - Part 3 11.11.2022

This podcast is sponsored by Arctic Wolf, whose Concierge Security teams Monitor, Detect and Respond to Cyber threats 24/7 for thousands of customers around the world. Arctic Wolf. Redefining cybersecurity. Visit  Arcticwolf.com/7MS  to learn more. Today we're talking about securing your mental health! I share some behind-the-scenes info about my own mental health challenges, and share a  great ti...

7MS #545: First Impressions of Snipe-IT 04.11.2022

Today's episode of the 7 Minute Security podcast is brought to you by Blumira, which provides easy-to-use automated detection and response that can be set up in…well..about 7 minutes. Detect and resolve security threats faster, and prevent breaches. Try it free today at blumira.com/7ms. Hey friends, today we're giving you a first impressions look at a free easy asset management tool called  Snipe-...

7MS #544: Interview with Nato Riley of Blumira 28.10.2022

Today's episode is brought to us by Blumira, which provides easy to use, automated detection and response that can be setup in…well…about 7 minutes! Detect and resolve security threats faster and prevent breaches. Try it free today at  blumira.com/7ms ! Today we have a really fun interview with Nato Riley of Blumira. He cut his IT/security teeth working for a cell phone company, exorcising malware...

7MS #543: How to Succeed in Business Without Really Crying - Part 12 21.10.2022

This podcast is sponsored by Arctic Wolf, whose Concierge Security teams Monitor, Detect and Respond to Cyber threats 24/7 for thousands of customers around the world. Arctic Wolf. Redefining cybersecurity. Visit  Arcticwolf.com/7MS  to learn more. Hey friends! Today we talk about a SoSaaS (Spreadsheet on Steroids as a Service... not a real thing ) that is helping 7MinSec be more organized - both...

7MS #542: Eating the Security Dog Food - Part 5 14.10.2022

This podcast is sponsored by Arctic Wolf, whose Concierge Security teams Monitor, Detect and Respond to Cyber threats 24/7 for thousands of customers around the world. Arctic Wolf. Redefining cybersecurity. Visit  Arcticwolf.com/7MS  to learn more. In today's episode we talk more about eating the security dog food (following the best practices we preach!). Specifically, we focus on keeping that bl...

7MS #541: Tales of Blue Team Bliss - Part 2 07.10.2022

SafePass.me is the only enterprise solution to protect organizations against credential stuffing and password spraying attacks. Visit SafePass.me for more details, and tell them 7 Minute Security sent you to get a 10% discount! Today we talk about configuring your Active Directory with MFA protection thanks to  AuthLite . In the tangent department, we give you a short, non-spoilery review of the f...

7MS #540: Tales of Blue Team Bliss 30.09.2022

Today we're excited to kick off a new series all about blue team bliss - in other words, we're talking about pentest stories where the blue team controls kicked our butt a little bit! Topics include: The  ms-ds-machineaccount-quota  value is not an "all or nothing" option! Check out  Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > User Rights Assignment...

7MS #539: Eating the Security Dog Food - Part 4 23.09.2022

Today we revisit a series we haven't touched  in a long time  all about eating the security dog food. TLDL about this series is I often find myself preaching security best practices, but don't always follow them as a consultancy. So today we talk about: How the internal 7MS infosec policy development is coming along Why I'm no longer going to be "product agnostic" going forward Some first impressi...

7MS #538: First Impressions of Airlock Digital 16.09.2022

Hey friends! Today we're giving you a first impressions episode all about  Airlock Digital , an application allowlisting solution. They were kind enough to let us play with it in our lab with the intention of exploring its bells and whistles, so we're excited to report back our findings in podcast form. TLDL: we really like this solution! It is easy to deploy (see  this YouTube video  for a quick...

7MS #537: Tales of Pentest Pwnage - Part 42 09.09.2022

In today's episode we share some tips we've picked up in the last few weeks of pentesting, with hopes it will save you from at least a few rounds of smashing your face into the keyboard. Tips include: If you find yourself with "owns" rights to a bajillion hosts in BloodHound, this query will give you a nice list of those systems, one system per line: cat export-from-bloodhound.json | jq '.nodes[]....

7MS #536: Interview with Amanda Berlin of Blumira 02.09.2022

Today we're so excited to welcome  Amanda Berlin , Lead Incident Detection Engineer at  Blumira , back to the show (did you miss Amanda's first appearance on the show?  Check it out  here )!  You might already be familiar with Amanda's awesome  Defensive Security Handbook  or her work with the  Mental Health Hackers  organization.  Today we virtually sat down to tackle a variety of topics and ques...

7MS #535: Rage Against the Remediation 27.08.2022

Today's episode covers three remediation-focused topics that kind of grind my gears and/or get me frustrated with myself. I'm curious for your thoughts on these, so reach out via  Slack  or  Twitter  and maybe we'll do a future  live stream  on this topic. How do you get clients to actually  care  when we explain the threats on their network that are a  literal  10/10 on the CVSS scale? Password p...

7MS #534: Tales of Pentest Pwnage - Part 41 19.08.2022

Hey friends, today we share the (hopefully) thrilling conclusion of  last week's pentest . Here are some key points: If you find you have local admin on a bunch of privileges and want to quickly loop through a secretsdump of ALL systems and save the output to a text file, this little hacky script will do it! #!/bin/bash File="localadmin.txt" Lines=$(cat $File) for Line in $Lines do echo --- $Line...

7MS #533: Tales of Pentest Pwnage - Part 40 12.08.2022

Ok, ok, I know.  I almost always say something like "Today is my favorite tale of pentest pwnage."  And guess what?  Today  is  my favorite tale of pentest pwnage, and I don't even know how it's going to end yet, so stay tuned to next week's (hopefully) exciting conclusion.  For today, though, I've got some pentest tips to hopefully help you in your journeys of pwnage: PowerHuntShares  is awesome...

7MS #532: Tales of Pentest Pwnage - Part 39 05.08.2022

Hey friends, wow...we're up to  thirty-nine  episodes of pwnage? Should we make a cake when we hit the big  4-0 ?! Anyway, today's TLDL is this: If you get a nagging suspicion about something you find during enumeration, make sure to either come back to it later, or exhaust the path right away so you don't miss something! Because I did :-/ A tip that's been helping me speed along my use of  CrackM...

7MS #531: Interview with Christopher Fielder and Eugene Grant of Arctic Wolf 01.08.2022

Today we're joined by some of our friends at Arctic Wolf - Eugene Grant and Christopher Fielder - to talk about compliance. Now hold on - don't leave yet! I know for many folks, compliance makes them want to bleach their eyeballs. But compliance is super important - especially because it is  not  the same as being secure. So we discuss the differences between security and compliance, and practical...

7MS #530: Tales of Pentest Pwnage - Part 38 22.07.2022

Hey friends, we have another fun tale of pwnage for you today. I loved this one because I got to learn some new tools I hadn't used before, such as: Get-InternalSubnets.ps1  - for getting internal subnets Adalanche  for grabbing Active Directory info (similar to SharpHound) This tool worked well for me with this syntax: adalanche-windows-x64-v2022.5.19.exe collect activedirectory --domain victim.d...

Listen to the 7 Minute Security podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.