Bryan Brake, Amanda Berlin, and Brian Boettcher
BrakeSec Education Podcast
A podcast about the world of Cybersecurity, Privacy, Compliance, and Regulatory issues that arise in today's workplace. Co-hosts Bryan Brake, Brian Boettcher, and Amanda Berlin teach concepts that aspiring Information Security professionals need to know, or refresh the memories of seasoned veterans.
Author
Bryan Brake, Amanda Berlin, and Brian Boettcher
Category
Podcast website
Latest episode
Jul 17, 2025
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
2020-035-ransomware death in Germany, Zerologon woes, drovorub, and corp data on personal devices 29.09.2020 1:09:09
FIND US NOW ON AMAZON MUSIC! https://music.amazon.com/podcasts/51b7da82-c223-4de4-8fc1-d1c3dd61984a/Brakeing-Down-Security-Podcast Shout to the organizers of Bsides Edmonton, Alberta, Canada for a great conference! Amanda's social media take over this week Bryan's plumbing story (A tale of 3 toilets) https://www.infosecurity-magazine.com/news/corporate-data-on-personal-devices/ https://www.infosec...
2020-034-Fortnite account selling, process change agility, IRS wanting to track the 'untrackable' 14.09.2020 53:32
https://www.kitploit.com/2020/05/web-hackers-weapons-collection-of-cool.html https://www.ehackingnews.com/2020/09/hackers-attack-gaming-industry-sell.html https://www.secjuice.com/windows-10-penetration-testing-os/ Nice to see stories about using Win10 as a pentest platform. Was always a PITA to update Kali or whatever. @secjuice One reason I enjoyed Dave Kennedy's 'pentester framework' --brbr...
2020-033-garmin hack, Tesla employee thwarted IP espionage, Slack RCE payout, and more! 31.08.2020 1:13:08
WWFH Class: (Ms. Berlin) "Breaching the Cloud" @dafthack https://www.blackhillsinfosec.com/breaching-the-cloud-perimeter-w-beau-bullock/ https://wildwesthackinfest.com/wwhf-at-secure-wv/ IWCE 2020 panel: "Being a thought leader" ADKAR class Book Club: 03 September 2020 7pm: https://smile.amazon.com/ADKAR-Change-Business-Government-Community/dp/1930885504/ref=sr_1_1?dchild=1&keywords=ADKAR&...
2020-032-Dr. Allan Friedman, SBOM, Software Transparency, and how the sausage is made - Part 2 24.08.2020 57:42
Ms. Berlin: Tabletop D&D exercise Blumira is hiring https://www.blumira.com/career/lead-backend-engineer/ Allan Friedman - Director of Cybersecurity Initiatives, NTIA, US Department of Commerce NTIA.gov - National Telecommunications and Information Administration https://www.ntia.gov/sbom SBOM guidance Healthcare SBOM PoC - https://www.ntia.gov/files/ntia/publications/ntia_sbom_healt...
2020-031-Allan Friedman, SBOM, software transparency, and knowing how the sausage is made 18.08.2020 44:50
Ms. Berlin: Tabletop D&D exercise Blumira is hiring https://www.blumira.com/career/lead-backend-engineer/ Allan Friedman - Director of Cybersecurity Initiatives, NTIA, US Department of Commerce NTIA.gov - National Telecommunications and Information Administration https://www.ntia.gov/sbom SBOM guidance Healthcare SBOM PoC - https://www.ntia.gov/files/ntia/publications/ntia_sbom_healthcare_po...
2020-030- Mick Douglas, Defenses against powercat, offsec tool release, SRUM logs, and more! 10.08.2020 1:23:12
WISP.org donation page: https://wisporg.z2systems.com/np/clients/wisporg/donation.jsp Mick Douglas (@bettersafetynet on Twitter) Powercat: https://github.com/besimorhino/powercat Netcat in a powershell environment https://blog.rapid7.com/2018/09/27/the-powershell-boogeyman-how-to-defend-against-malicious-powershell-attacks/ https://www.hackingarticles.in/powercat-a-powershell-netcat/ Defenses agai...
2020-029- Brad Spengler, Linux kernel security in the past 10 years, software dev practices in Linux, WISP.org PSA 31.07.2020 1:05:34
WISP.org PSA at 35m56s - 37m 19s Agenda: Bio/background Why are you here (topic discussion) What is the Linux Security Summit North America https://grsecurity.net/ Questions from the meeting invite: This only affects people who want to use a custom kernel, correct? This doesn't affect you if you are running bog-standard linux (debian, gentoo, Ubuntu) right? What options do people have in clo...
2020-028-Shlomi Oberman, RIPPLE20, supply chain security discussion, software bill of materials 24.07.2020 1:00:51
Whitepaper: https://www.jsof-tech.com/ripple20/ [blog] Build your own custom TCP/IP stack: https://www.saminiir.com/lets-code-tcp-ip-stack-1-ethernet-arp/ Another custom TCP/IP stack: https://github.com/tass-belgium/picotcp RIPPLE 20 Whitepaper: https://drive.google.com/file/d/1d3NNVCRPVFk0-V0HUO5CxWWVn9pYIvmF/view?usp=sharing Agenda: Part 1: Background on the report Why is it called RIPPLE2...
2020-027-RIPPLE20 Report, supply chain security, responsible disclosure, software development, and vendor care. 16.07.2020 48:34
Whitepaper: https://www.jsof-tech.com/ripple20/ [blog] Build your own custom TCP/IP stack: https://www.saminiir.com/lets-code-tcp-ip-stack-1-ethernet-arp/ Another custom TCP/IP stack: https://github.com/tass-belgium/picotcp RIPPLE 20 Whitepaper: https://drive.google.com/file/d/1d3NNVCRPVFk0-V0HUO5CxWWVn9pYIvmF/view?usp=sharing Agenda: Part 1: Background on the report Why is it called RIPPLE20? W...
2020-026- WISP PSA, PAN-OS vuln redux, F5 has a bad weekend, vuln scoring, Twitter advice, and more! 08.07.2020 58:22
1st: WISP.org PSA from Rachel Tobac (@racheltobac) & @wisporg talking about #shareTheMicInCyber #SAML PAN-OS: https://twitter.com/RyanLNewington/status/1278074919092289537 F5 vulnerability: https://www.wired.com/story/f5-big-ip-networking-vulnerability/ https://research.nccgroup.com/2020/07/05/rift-f5-networks-k52145254-tmui-rce-vulnerability-cve-2020-5902-intelligence/ F5 Mitigation (if patchi...
2020-025-Cognizant breach, maze ransomware, PAN-OS CVE 2020-2021, SAML authentication walkthrough 29.06.2020 46:33
Thank you to Marcus Carey for his excellent guidance and leadership this week. Cognizant breach: https://www.ehackingnews.com/2020/06/cognizant-reveals-employees-data.html Maze ransomware write-up: https://www.mcafee.com/blogs/other-blogs/mcafee-labs/ransomware-maze/ https://www.fireeye.com/blog/threat-research/2020/05/tactics-techniques-procedures-associated-with-maze-ransomware-incidents.html...
2020-024-Bit of news, Ripple20 vulns, IoT Security, windows error codes, captchas used for evil, Marine Momma 24.06.2020 49:51
https://blog.xpnsec.com/hiding-your-dotnet-complus-etwenabled/ https://gist.github.com/Cyb3rWard0g/a4a115fd3ab518a0e593525a379adee3 https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4657 https://www.blumira.com/logmira-windows-logging-policies-for-better-threat-detection/ How would we map this against the MITRE matrix? Are there any MITRE attack types that are...
2020-023-James Nelson from Illumio, cyber resilence, business continuity 17.06.2020 48:43
James Nelson, VP of Infosec, Illumio How has COVID-19 changed cybersecurity? Why is cyber resilience especially important now? What are the most important steps to ensure cyber-resiliency? How do you talk to business leaders about investing in cybersecurity to boost resiliency? The best way for organizations to keep their 'crown jewels' secure is adopting a Zero Trust mindset. Organizations need t...
2020-022-Andrew Shikiar, FIDO Alliance, removing password from IoT, and discussing FIDO implementation 10.06.2020 43:12
Andrew Shikiar, executive director and CMO of the (Fast IDentity Online) FIDO Alliance. What is FIDO? " open industry association launched in February 2013 whose mission is to develop and promote authentication standards that help reduce the world's over-reliance on passwords . FIDO addresses the lack of interoperability among strong authentication devices and reduces the problems users face cre...
2020-021- Derek Rook, redteam tactics, blue/redteam comms, and detection of testing 01.06.2020 1:17:03
**If Derek told you about us at SANS, send a DM to @brakeSec or email bds.podcast@gmail.com for an invite to our slack** OSCP/HtB/VulnHub is a game... d esigned to have a tester find a specific nugget of information to pivot or gain access to greater power on the system. Far different in the 'real' world. Privilege escalation in Windows: *as of June 2020, many of these items still work, may not...
2020-020-Andrew Shikiar - FIDO Alliance - making Cybersecurity more secure 27.05.2020 42:18
Andrew Shikiar, executive director and CMO of the (Fast IDentity Online) FIDO Alliance. What is FIDO? " open industry association launched in February 2013 whose mission is to develop and promote authentication standards that help reduce the world's over-reliance on passwords . FIDO addresses the lack of interoperability among strong authentication devices and reduces the problems users face c...
2020-019-Masha Sedova, customized training, phishing, ransomware, and privacy implications 20.05.2020 39:22
Masha Sedova - Founder, Elevate Security Topic ideas from the PR company: Inability to measure human security behaviors leads to increased risk in our computing environments. For too long, we've accepted training completion and mock phishing data as a sufficient way to measure this risk. But where do the vulnerabilities and strengths truly lie? The secret is, security teams have installed t...
2020-018- Masha Sedova, bespoke security training, useful metrics to tailor training 13.05.2020 44:31
Masha Sedova - Founder, Elevate Security Inability to measure human security behaviors leads to increased risk in our computing environments. For too long, we've accepted training completion and mock phishing data as a sufficient way to measure this risk. But where do the vulnerabilities and strengths truly lie? The secret is, security teams have installed tons of security tooling that can give i...
2020-017-Cameron Smith, business decisions, and how it affects Security 05.05.2020 1:08:05
Cameron Smith @Secnomancer Layer8conference is virtual (https://layer8conference.com/layer-8-is-online-this-year/) https://csrc.nist.gov/publications/detail/sp/800-171/rev-1/final CMMC: https://info.summit7systems.com/blog/cmmc https://www.comptia.org/certifications/project - Project+ Cameron's Smith = www.twitter.com/secnomancer Cybersmith.com - Up by 14 April Ask@thecybersmith.com Camer...
2020-016-Cameron Smith, Business decisions and their (in)secure outcomes - Part 1 29.04.2020 49:20
Cameron Smith @Secnomancer Layer8conference is virtual (https://layer8conference.com/layer-8-is-online-this-year/) https://csrc.nist.gov/publications/detail/sp/800-171/rev-1/final CMMC: https://info.summit7systems.com/blog/cmmc https://www.comptia.org/certifications/project - Project+ Cameron's Smith = www.twitter.com/secnomancer Cybersmith.com - Up by 14 April Ask@thecybersmith.com Cameron@...
2020-015-Tanya_Janca-Using Github Actions in your Devops Environment, workflow automation 21.04.2020 57:03
Github actions - https://github.com/features/actions How are these written? It looks like a marketplace format? How do they maintain code quality? What does it take setup the actions? It looks like IFTTT for DevOps? What kind of integrations does it allow for? Will it handle logins or API calls for you? Is it moderated in some way? What's the acceptance criteria for these? What are you trying to...
2020-014-Server Side Request Forgery defense, Tanya Janca, AppSec discussion 14.04.2020 48:16
Tanya's AppSec Course https://www.shehackspurple.dev/server-side-request-forgery-ssrf-defenses https://www.shehackspurple.dev Server-side request forgery - https://portswigger.net/web-security/ssrf What are differences between Stored XSS and SSRF? This requires a MITM type of issue? Doesn't stored XSS get stored on the server? What conditions must exist for SSRF to be possible? What mitigations n...
2020-013- part 2, education security, ransomware, april mardock, Nathan McNulty, and Jared folkins 07.04.2020 1:02:21
April Mardock - CISO - Seattle Public Schools Jared Folkins - IT Engineer - Bend La Pine Schools Nathan McNulty - Information Security Architect - Beaverton School District OpSecEdu - https://www.opsecedu.com/ Slack https://www.a4l.org/default.aspx https://clever.com/ BEC - https://www.trendmicro.com/vinfo/us/security/definition/business-email-compromise-(bec) https://www.k12cybe...
2020-012-April Mardock, Nathan McNulty, Jared Folkins, school security, ransomware attacks 29.03.2020 48:22
April Mardock - CISO - Seattle Public Schools Jared Folkins - IT Engineer - Bend La Pine Schools Nathan McNulty - Information Security Architect - Beaverton School District OpSecEdu - https://www.opsecedu.com/ Slack https://www.a4l.org/default.aspx https://clever.com/ BEC - https://www.trendmicro.com/vinfo/us/security/definition/business-email-compromise-(bec) https://www.k12cybers...
2020-011-Alyssa miller, deep fakes, threatmodeling for Devops environments, and virtual conferences 25.03.2020 1:10:29
https://twitter.com/AlyssaM_InfoSec/status/1159877471161839617?s=19 Looking forward to sharing my vision for ending the 60 year cycle of bad defense strategies in #infosec and my challenge to think about security in a more effective way. https://sched.co/TAqU @dianainitiative #DianaInitiative2019 #cdwsocial @CDWCorp 1961 - MIT - CTSS - https://en.wikipedia.org/wiki/Compatible_Time-Sharing_Syst...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.