Bryan Brake, Amanda Berlin, and Brian Boettcher

BrakeSec Education Podcast

News EN ↓ 463 episodes

A podcast about the world of Cybersecurity, Privacy, Compliance, and Regulatory issues that arise in today's workplace. Co-hosts Bryan Brake, Brian Boettcher, and Amanda Berlin teach concepts that aspiring Information Security professionals need to know, or refresh the memories of seasoned veterans.

Author

Bryan Brake, Amanda Berlin, and Brian Boettcher

Category

News

Podcast website

www.youtube.com

Latest episode

Jul 17, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

2020-010-Dave Kennedy, offensive security tool release, Derbycom, and Esports 19.03.2020

Dave Kennedy (@hackingDave) TrustedSec Released SEToolkit, Pentester Framework (PTF) PoC release for "Shitrix" bug (was disclosed after Google zero initiative India group) Jeff Snover, Lee Holmes - Powershell gods Arguments against release Tools are released are utilized by the 'bad guys' Tooling makes it more difficult to fingerprint who are who they say they are "Fuzzy Weasel Vs. Psycho Toads" M...

2020-009-Dave Kennedy, Offensive Tool release (Part 1) 12.03.2020

Dave Kennedy (@hackingDave) TrustedSec Released SEToolkit, Pentester Framework (PTF) PoC release for "Shitrix" bug (was disclosed after Google zero initiative India group) Jeff Snover, Lee Holmes - Powershell gods Arguments against release Tools are released are utilized by the 'bad guys' Tooling makes it more difficult to fingerprint who are who they say they are "Fuzzy Weasel Vs. Psycho Toads" M...

2020-008-Nemesis_Taylor Mutch 04.03.2020

Nemesis: https://github.com/UnityTech/nemesis https://www.techrepublic.com/article/security-concerns-hampering-adoption-of-containers-and-kubernetes/   Nemesis - a auditing tool to check against a set of benchmarks (CIS GCP only) https://en.wikipedia.org/wiki/Center_for_Internet_Security What does CIS do well?   What do the CIS benchmarks do poorly?   K8s workload identity - GKE specific   github....

2020-007-Roberto_Rodriguez-threat_hunting-juypter_notebooks_data-science 26.02.2020

Brakesec Podcast is now on Pandora!  Find us here: https:// pandora .app.link/p9AvwdTpT3 Book club Book club is starting up again with Hands-On AWS penetration testing with Kali Linux from Gilbert and Caudill. You read and get together to discuss or demo every Monday. Get the book, start reading and meet us for the kick off Monday the 24 at 10pm eastern. The book club meets virtually on zoom, and...

2020-006-Roberto Rodriguez, threat intel, threat hunting, hunter's forge, mordor setup 19.02.2020

Full notes and graphics are on www.brakeingsecurity.com Episode 2020-006 Book club "And maybe blurb for the cast could go something like this. Book club is starting up again with Hands-On AWS penetration testing with Kali Linux from Gilbert and Caudill. You read and get together to discuss or demo every Monday. Get the book, start reading and meet us for the kick off Monday the 24 at 10pm eastern....

2020-005-Marcus J Carey, red team automation, and Tribe of Hackers book series 10.02.2020

Brakeing Down Security Podcast on #Pandora- https://www.pandora.com/podcast/brakeing-down-security-podcast/PC:27866 Marcus Carey https://twitter.com/marcusjcarey   Prolific Author, Defender, Enterprise Architect at ReliaQuest   https://twitter.com/egyp7     https://www.darkreading.com/vulnerabilities---threats/reliaquest-acquires-threatcare/d/d-id/1335950   "GreyMatter integrates security data fro...

2020-004-Marcus Carey, ShmooCon Report, threat simulation 05.02.2020

  Marcus Carey https://twitter.com/marcusjcarey   Prolific Author, Defender, Enterprise Architect at ReliaQuest https://twitter.com/egyp7   https://www.darkreading.com/vulnerabilities---threats/reliaquest-acquires-threatcare/d/d-id/1335950   "GreyMatter integrates security data from security incident and event manager (SIEM), endpoint detection and response (EDR), firewalls, threat intelligence fe...

2020-003- Liz Fong Jones, tracking Pentesters, setting up MFA for SSH, and Developer Advocates 30.01.2020

What is Honeycomb.io? From the site:  "Honeycomb is a tool for introspecting and interrogating your production systems. We can gather data from any source—from your clients (mobile, IoT, browsers), vendored software, or your own code. Single-node debugging tools miss crucial details in a world where infrastructure is dynamic and ephemeral. Honeycomb is a new type of tool, designed and evolved to m...

2020-002-Liz Fong-Jones discusses blog post about Honeycomb.io Incident Response 23.01.2020

Ms. Berlin's appearance on #misec podcast - https://www.youtube.com/watch?v=Cj2IF0zn_BE with @kentgruber and @quantissIA Blog post:  https://www.honeycomb.io/blog/incident-report-running-dry-on-memory-without-noticing/   What is Honeycomb.io? From the site:  "Honeycomb is a tool for introspecting and interrogating your production systems. We can gather data from any source—from your clients (mobil...

2020-001- Android malware, ugly citrix bugs, and Snake ransomware 13.01.2020

Educause conference: https://events.educause.edu/security-professionals-conference/2020/hotel-and-travel     Amanda's Training that everyone should come to!!! https://nolacon.com/training/2020/security-detect-and-defense-ttx Follow twitter.com/infosecroleplay   Part 1: New year, new things   Discussion:   What happened over the holidays? What did you get for christmas?   PMP test is scheduled for...

2019-046-end of the year, end of the decade, predictions, and how we've all changed 23.12.2019

End of year, end of decade     Are things better than 10 years ago? 5 years ago?     If there was one thing to change things for the better, what would that be?   Good, Bad, Ugly  Did naming vulns make things better?     Which industries are doing a good job of securing themselves? Finance?     What do you wished never happened (security/compliance wise)?     Ransomware infections with no bounties...

2019-045-Part 2-Noid, Dave Dittrich, empowered teams, features vs. security 18.12.2019

The day after part 1 Keybase halted the spacedrop the day after the first podcast is complete...   Security failures in implementation     "We need to push this to market, we'll patch it later!"   Risk management discussion for project managers (PMP)   CIA Triad… where does 'business goals' fit? Security is at odds with the bottom line     **Reference Noid's Bsides Seattle talk and podcast earlier...

2019-044-Noid and Dave Dittrich discusses recent keybase woes - Part 1 10.12.2019

Patreon donor goodness: Scott S. and Ion S. @_noid_ @davedittrich Their response:  "it's not a bug, it's a feature"     "Don't write a blog post that will point out the issue"     "You pointing out our issues makes things more difficult for us"     "It's a free service, why are you hurting us?"     https://keybase.io/docs/bug_reporting Nov 22nd   Noid (@_noid_) Keybase discussion blog post https:/...

2019-043-Bea Hughes, dealing with realistic threats in your org 04.12.2019

Realistic Threats  Nation states aren't after you https://twitter.com/beajammingh/status/1191884466752385025 https://twitter.com/beajammingh/status/1198671660150226946 https://twitter.com/beajammingh/status/1198671952824565762   https://www.leviathansecurity.com/blog/the-calculus-of-threat-modeling     What are credible threats? Malicious insiders -  Non-malicious insiders - https://www.scmagazine...

2019-042-CircuitSwan, Gitlabs, Job descriptions that don't suck, layer8con 27.11.2019

Diana Initiative @circuitswan @dianainitiative https://www.dianainitiative.org/ https://twitter.com/DianaInitiative   Conference in Las Vegas (Aug 6-7, 2020) (Thu & Fri)   info@dianainitiative.org   Topics     Diana initiatives Past 2015 - idea at defcon 23 2016-17-18 growing but got too big! 2019 got our own space, ~800 tickets 2020 plans-westin again, 2 speaking tracks and 1 workshop track, sold...

2019-041-circuitswan, diana initiative, diversity initiatives at conferences 21.11.2019

Diana Initiative   @circuitswan   https://www.dianainitiative.org/ https://twitter.com/DianaInitiative   Conference in Las Vegas (Aug 6-7, 2020) (Thu & Fri)   info@dianainitiative.org   Topics     Diana initiatives Past 2015 - idea at defcon 23 2016-17-18 growing but got too big! 2019 got our own space, ~800 tickets 2020 plans-westin again, 2 speaking tracks and 1 workshop track, solder village, c...

2019-040-vulns in cisco kit, google's project 'nightmare', healthcare data issues, TAGNW conference update 12.11.2019

Tagnw.org Amazon Smile - brakesec.com/smile   News:    https://www.androidpolice.com/2019/11/11/google-project-nightingale-health-records-collection/ https://www.csoonline.com/article/3439400/secrets-of-latest-smominru-botnet-variant-revealed-in-new-attack.html https://blog.naijasecforce.com/the-jar-based-malware/ - ms. Infosecsherpa mailing list "nuzzle" https://www.axios.com/hospitals-cybersecur...

2019-039-bluekeep_weaponized-npm_security_cracks-grrcon_report 04.11.2019

Grrcon update   2019-039-  bluekeep Weaponized… and more   Bluekeep weaponized https://www.bleepingcomputer.com/news/security/bluekeep-remote-code-execution-bug-in-rdp-exploited-en-masse/ https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708 https://www.microsoft.com/security/blog/2019/08/08/protect-against-bluekeep/     https://www.wired.com/story/bluekeep-hacking-crypt...

2019-038-Deveeshree_Nayak-risk_analysis, and OWASP WIA 30.10.2019

OWASP WIA - https://www.youtube.com/watch?v=umnt0qbOPsE https://www.owasp.org/index.php/Women_In_AppSec OWASP Women in AppSec Twitter: 2013_Nayak (reach and ask to be added) https://www.tagnw.org/events/ Risk in Infosec   Risk - a situation which involves extreme danger and extensive amount of unrecovered loss     What about risks that are positive in nature?  PMP calls them 'opportunities' Risk A...

2019-038- Ethical dilemmas with offensive tools, powershell discussion with Lee Holmes - Part2 22.10.2019

  Derbycon9 talk - PowerShell Security Looking Back from the Inside - https://www.youtube.com/watch?v=DYWPtt7qszY&list=PLNhlcxQZJSm_ZDJBksg97I5q1XsdQcyN5&index=27&t=0s   Encarta - https://en.wikipedia.org/wiki/Encarta   Scott Hanselman's twitter thread about Encarta: https://twitter.com/shanselman/status/1158780839464849409   Congrats on the black badge :)   I like that you bring up execution poli...

2019-037-Lee Holmes, Powershell logging, and why there's an 'execution bypass' 17.10.2019

Derbycon9 talk - PowerShell Security Looking Back from the Inside - https://www.youtube.com/watch?v=DYWPtt7qszY&list=PLNhlcxQZJSm_ZDJBksg97I5q1XsdQcyN5&index=27&t=0s   Encarta - https://en.wikipedia.org/wiki/Encarta   Scott Hanselman's twitter thread about Encarta: https://twitter.com/shanselman/status/1158780839464849409   Congrats on the black badge :)   I like that you bring up execution polici...

2019-036-RvrShell-graphql_defense-Part2 09.10.2019

Secure Python course:  https://brakesec.com/brakesecpythonclass   PDF Slides: https://drive.google.com/file/d/1wmxrfgbaHu56kfccLoOd5M3Zz6bNP6Qi/view?usp=sharing     GraphQL High Level https://graphql.org/ Designed to replace REST Arch Allow you to make a large request, uses a query language Released by FB in 2012 JSON    Learn Enough to be dangerous https://blog.bitsrc.io/13-graphql-tools-and-libr...

2019-035-Matt_szymanski-attack and defense of GraphQL-Part1 02.10.2019

Derbycon Discussion (bring Matt in)   Python course:  https://brakesec.com/brakesecpythonclass   PDF Slides: https://drive.google.com/file/d/1wmxrfgbaHu56kfccLoOd5M3Zz6bNP6Qi/view?usp=sharing     GraphQL High Level https://graphql.org/ Designed to replace REST Arch Allow you to make a large request, uses a query language Released by FB in 2012 JSON    Learn Enough to be dangerous https://blog.bits...

2019-034- Tracy Maleeff, empathy as a service, derbycon discussion 22.09.2019

Podcast Interview (Youtube): https://youtu.be/4tdJwBMh3ow Tracy Maleeff (pronounced like may-leaf) - https://twitter.com/InfoSecSherpa https://medium.com/@InfoSecSherpa https://nuzzel.com/InfoSecSherpa       Python secure coding class - November 2nd / 5 Saturdays @nxvl Teaching https://www.eventbrite.com/e/secure-python-coding-with-nicolas-valcarcel-registration-72804597511     Derbycon Talk: http...

2019-033-Part 2 of the Kubernetes security audit discussion (Jay Beale & Aaron Small) 16.09.2019

  Topics: Infosec Campout report   Jay Beale (co-lead for audit) *Bust-a-Kube*   Aaron Small (product mgr at GKE/Google)   Atreides Partners Trail of Bits   What was the Audit?  How did it come about?    Who were the players?     Kubernetes Working Group         Aaron, Craig, Jay, Joel     Outside vendors:         Atredis: Josh, Nathan Keltner         Trail of Bits: Stefan Edwards, Bobby Tonic , D...

Listen to the BrakeSec Education Podcast podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.