Bryan Brake, Amanda Berlin, and Brian Boettcher

BrakeSec Education Podcast

News EN ↓ 463 episodes

A podcast about the world of Cybersecurity, Privacy, Compliance, and Regulatory issues that arise in today's workplace. Co-hosts Bryan Brake, Brian Boettcher, and Amanda Berlin teach concepts that aspiring Information Security professionals need to know, or refresh the memories of seasoned veterans.

Author

Bryan Brake, Amanda Berlin, and Brian Boettcher

Category

News

Podcast website

www.youtube.com

Latest episode

Jul 17, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

2018-026-insurers gathering data, netflix released a new DFIR tool, and google no longer gets phished? 27.07.2018

Stories and topics we covered: https://krebsonsecurity.com/2018/07/google-security-keys-neutralized-employee-phishing/   https://osquery.io/   https://www.propublica.org/article/health-insurers-are-vacuuming-up-details-about-you-and-it-could-raise-your-r ates   https://medium.com/netflix-techblog/netflix-sirt-releases-diffy-a-differencing-engine-for-digital-forensics-in-the-cloud-37b71abd2698   Jo...

2018-025-BsidesSPFD, threathunting, assessing risk 19.07.2018

Sorry, this week's show took an odd turn, and we don't have much in the way of show notes... Ms. Berlin is recovering from knee surgery, and we wish her a speedy recovery. Bryan B. got back from BsidesSPFD , MO this week, after what was a well-received talk on building community. Lots of other excellent talks from speakers like Ms. Sunny Wear , and impromptu panel with Ben Miller and a whole host...

2018-024- Pacu, a tool for pentesting AWS environments 11.07.2018

Ben Caudill @rhinosecurity Spencer Gietzen @spengietz   Rhino Security - https://rhinosecuritylabs.com/blog/   AWS escalation and mitigation blog - https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation/   What is the difference between this and something like Scout or Lynis?   Is it a forensic or IR tool?   How might offensive people use this tool? What is possible when you...

2018-023: Cydefe interview-DNS enumeration-CTF setup & prep 02.07.2018

Raymond Evans - CTF organizer for nolacon and Founder of CyDefe Labs     @cydefe CTF setup / challenges of setting up a CTF. Beginners & CTFs Types tips/tricks Biggest downfalls of CTF development   https://www.heroku.com/ www.exploit-db.com   BrakeSec DerbyCon     @dragosinc dragos.com   DNS Enumeration: https://github.com/nixawk/pentest-wiki/blob/master/1.Information-Gathering/How-to-gather-dns-...

2018-022-preventing_insider_threat 26.06.2018

After the recent Tesla insider threat event, BrakeSec decided to discuss some of the indicators of insider threat, what can be done to mitigate it, and why it happens.   news stories referenced: https://www.infosecurity-magazine.com/news/teslas-tough-lesson-on-malicious/   https://www.scmagazine.com/tesla-hit-by-insider-saboteur-who-changed-code-exfiltrated-data/article/774472/   https://en.wikipe...

2018-021-TLS 1.3 discussion, Area41 report, wireshark goodness 20.06.2018

Area41 Zurich report Book Club - 4th Tuesday of the month https://www.owasp.org/images/d/d3/TLS_v1.3_Overview_OWASP_Final.pdf   https://www.owasp.org/index.php/TLS_Cipher_String_Cheat_Sheet TLS_DHE_RSA_AES_256_GCM_SHA256   TLS = Protocol DHE = Diffie-Hellman ephemeral (provides Perfect Forward Secrecy)     Perfect Forward Secrecy = session keys won't be compromised, even if server private keys are...

2018-020: NIST's new password reqs, Ms. Berlin talks about ShowMeCon, Pwned Passwords 13.06.2018

https://nostarch.com/packetanalysis3   -- Excellent Book! You must buy it.   DetSEC mention   ShowMe Con panel and keynote   SeaSec East standing room only. Crispin gave a great toalk about running as Standard user   Bsides Cleveland -   https://www.passwordping.com/surprising-new-password-guidelines-nist/ 1Password version 7.1 integrates with Troy Hunt's "Pwned Passwords" service to check for pas...

2018-019-50 good ways to protect your network, brakesec summer reading program 06.06.2018

Ms. Berlin's mega tweet on protecting your network   https://twitter.com/InfoSystir/status/1000109571598364672   Utica College CYB617     I tweeted "utica university" many pardons   Mr. Childress' high school class Laurens, South Carolina   Probably spent as much as a daily coffee at Starbucks… makes all the difference.   CTF Club, and book club (summer reading series)   Patreon SeaSec East   Show...

2018-018-Jack Rhysider, Cryptowars of the 90s, OSINT techniques, and hacking MMOs 30.05.2018

https://darknetdiaries.com/   Jack Rhysider Ok I think these topics should keep us busy for a while. Topics for discussion: Do hospitals have a free pass when being attacked? #OPJUSTINA https://nakedsecurity.sophos.com/2014/04/28/anonymous-takes-on-boston-childrens-hospital-in-opjustina/ https://www.youtube.com/watch?v=eFVBz_ATAlU - when anonymous attacks your hospital   The oldest known vulnerabi...

2018-017- threat models, vuln triage, useless scores, and analysis tools 23.05.2018

Vuln mgmt tools CVE scores suck.   Threat modeling is good.   Forces  you to know your environment   https://en.wikipedia.org/wiki/Kanban   https://blog.jeremiahgrossman.com/2018/05/all-these-vulnerabilities-rarely-matter.html   https://twitter.com/lnxdork/status/998559649271025664 https://www.google.com/search?q=house+centipede&rlz=1C5CHFA_enUS759US759&source=lnms&tbm=isch&sa=X&ved=0ahUKEwiypKyfp...

2018-016- Jack Rhysider, DarkNet Diaries, and a bit of infosec history (Part 1) 15.05.2018

Converge Detroit Jack Rhysider - Podcaster, DarkNet Diaries https://darknetdiaries.com/   Do hospitals have a free pass when being attacked? #OPJUSTINA https://nakedsecurity.sophos.com/2014/04/28/anonymous-takes-on-boston-childrens-hospital-in-opjustina/ https://www.youtube.com/watch?v=eFVBz_ATAlU - when anonymous attacks your hospital   The oldest known vulnerability is still a big problem. Defau...

2018-015-Data labeling, data classification, and GDPR issues 07.05.2018

GDPR will affect any information system that processes or will process people… like it or not.   Derby Tickets     CTF and auction Keynote     Converge Detroit I'll be at nolacon too Boettcher     Recap BDIR #3 https://blog.netwrix.com/2018/05/01/five-reasons-to-ditch-manual-data-classification-methods/ https://blog.networksgroup.com/data-loss-prevention-fundamentals   Join our  #Slack  Channel! E...

2018-014- Container Security with Jay Beale 29.04.2018

    Container security   Jay Beale  @inguardians , @jaybeale   Containers What the heck is a container? Linux distribution with a kernel Containers run on top of that, sharing the kernel, but not the filesystem Namespaces Mount Network Hostname PID IPC Users Somebody said we've had containers since before Docker Containers started in 2005, with OpenVZ Docker was 2013, Kubernetes 2014 Image Securit...

2018-013-Sigma_malware_report, Verizon_DBIR discussion, proper off-boarding of employees 20.04.2018

Report from Bsides Nash - Ms. Berlin New Job Keynote at Bsides Springfield, MO Mr. Boettcher talks about Sigma Malware infection.   http://www.securitybsides.com/w/page/116970567/BSidesSpfd **new website upcoming** Registration is coming and will be updated on next show (hopefully) DBIR - https://www.verizonenterprise.com/resources/reports/rp_DBIR_2018_Report_execsummary_en_xg.pdf   VERIS framewor...

2018-012: SIEM tuning, collection, types of SIEM, and do you even need one? 11.04.2018

Bryan plays 'stump the experts' with Ms. Berlin and Mr. Boettcher this week... We discuss SIEM logging, and tuning... How do SIEM deal with disparate log file types? What logs should be the first to be gathered? Is a SIEM even required, or is just a central log repo enough? Which departments benefit the most from logging? (IT, IR, Compliance?)   Join our  #Slack  Channel! Email us at  bds.podcast@...

2018-011: Creating a Culture of Neurodiversity 04.04.2018

Megan Roddie discusses being a High functioning Autistic, and we discuss how company and management can take advantage of the unique abilities of those with high functioning autism. Direct Link:  http://traffic.libsyn.com/brakeingsecurity/2018-011.mp3   Matt Miller's Assembly and Reverse Engineering Class: Still can sign up! The syllabus is here:  https://drive.google.com/open?id=1alsTUhGwAAnR6BA2...

2018-010 - The ransoming of Atlanta, Facebook slurping PII, Dridex variants 27.03.2018

  Matt Miller's #Assembly and #Reverse #Engineering class $150USD for each class, 250USD for both classes Syllabus :  https://docs.google.com/document/d/1alsTUhGwAAnR6BA27gGo3OdjEHFnq2wtQsynPfeWzd0/edit?usp=sharing Please state which class you'd like to take when ordering in the "Notes" field in Paypal  https://paypal.me/BDSPodcast/150usd To sign up for both classes:  https://paypal.me/BDSPodcast/...

2018-009- Retooling for new infosec jobs, sno0ose, Jay Beale, and mentorship 19.03.2018

Direct Link: http://traffic.libsyn.com/brakeingsecurity/2018-009-internships-mentorships-retooling-finding-that-unicorn-pentester.mp3 Topics discussed: How Jay Beale ( @jaybeale @inguardians ) and Brad A. ( @sno0ose ) do mentorship and apprenticeship in their respective orgs. Best methods to retool yourself if you are trying to move to a new industry Why 'hitting the ground running' isn't the sign...

BDIR-001: Credential stealing emails, How do you protect against it? 12.03.2018

BDIR Episode - 001 Our guests will be: Martin Brough - Manager of the Security Solutions Engineering team in the #email #phishing industry Topic of the Day: CREDENTIAL STEALING EMAILS WHAT CAN YOU DO   Join us for Episode-001, our guest will be: Martin Brough - Manager of the Security Solutions Engineering team in the email phishing industry Topic of the day will be: " CREDENTIAL STEALING EMAILS W...

2018-008- ransomware rubes, Defender does not like Kali, proper backups 12.03.2018

https://www.auditscripts.com/free-resources/critical-security-controls/ Thanks to Slacker Ben Chung, who heard about this from John Strand...   BsidesIndy report - Amanda Bsides Austin - Brian   Log_MD 2.0 - www.log-md.com   https://www.bleepingcomputer.com/news/security/only-half-of-those-who-paid-a-ransomware-ransom-could-recover-their-data/ https://itsfoss.com/kali-linux-debian-wsl/ https://www...

2018-007- Memcached DDoS, Secure Framework Documentation, and chromebook hacking 05.03.2018

Topics: Secure Framework documents Modifying chromebooks so you can use Debian/Ubuntu Memcached is the new DDoS hotness Announcement of the next BrakeSec Training Class (see Show Notes below for more info) Link to secure framework document:  https://drive.google.com/open?id=1xLfY4uI88K2AiA1mosWJ7jFyP100Jv5d Tickets are already on sale for "Hack in the Box" in Amsterdam from 9-13 April 2018, and us...

2018-006- NPM is whacking boxes, code signing, and stability of code 26.02.2018

Topics on today's show: NPM (Node Package Manager) - bug was introduced changing permissions on /etc, /boot, and /usr, breaking many systems, requiring full re-installs. Why was it allowed to be passed, and worse, why did so many run that version on production systems? Code signing - a well known content management system does not sign it's code. What are the risks involved in not signing the code...

2018-005-Securing_your_mobile_devices_and_CMS_against_plugin_attacks 14.02.2018

Direct Link:   http://traffic.libsyn.com/brakeingsecurity/2018-005-Securing_CMS_and_mobile_devices-phishing_story.mp3 Topics: Discussion of Ms. Berlin's course CAPEC discussion RTF malware MS Office A Phishing story... Mobile Supply Chain Security CMS Supply Chain Security Ms. Berlin's course - recap of 2nd session   Brakeing Down IR -date?   Any malware of note? Upgrade your Office!  Just double-...

2018-004 - Discussing Bsides Seattle, and Does Autosploit matter? 05.02.2018

Show Notes: https://docs.google.com/document/d/1CSjskf-3vrguoyIyg8yOK2KLqg7srxYlee4RD6jzgNc/edit?usp=sharing Topics Discussed: New tool : AutoSploit - Does it lower the bar? How should Blue teamers be using Shodan? Discuss WPAD attacks, what WPAD is, and why it's a thing blue teams should worry about.    ANNOUNCEMENTS: Ms. Amanda Berlin is running 4 session of her workshop  "Disrupting the Killcha...

BDIR-000 ; The Beginning 29.01.2018

Here is the inaugural episode of the "Brakeing Down Incident Response"   Please check it out!   BDIR Episode - 000 Our guests will be: Dave Cowen - Forensic Lunch Podcast and G-C Partners Tyler Hudak - Trainer in Malware Analysis and Reverse Engineering Topic of the Day: WHAT IS THIS NEW PODCAST ALL ABOUT, WHAT WILL IT COVER? "Incident Response, Malware Discovery, and Basic Malware Analysis, Detec...

Listen to the BrakeSec Education Podcast podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.