Bryan Brake, Amanda Berlin, and Brian Boettcher
BrakeSec Education Podcast
A podcast about the world of Cybersecurity, Privacy, Compliance, and Regulatory issues that arise in today's workplace. Co-hosts Bryan Brake, Brian Boettcher, and Amanda Berlin teach concepts that aspiring Information Security professionals need to know, or refresh the memories of seasoned veterans.
Author
Bryan Brake, Amanda Berlin, and Brian Boettcher
Category
Podcast website
Latest episode
Jul 17, 2025
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
2020-010-Dave Kennedy, offensive security tool release, Derbycom, and Esports 19.03.2020 46:53
Dave Kennedy (@hackingDave) TrustedSec Released SEToolkit, Pentester Framework (PTF) PoC release for "Shitrix" bug (was disclosed after Google zero initiative India group) Jeff Snover, Lee Holmes - Powershell gods Arguments against release Tools are released are utilized by the 'bad guys' Tooling makes it more difficult to fingerprint who are who they say they are "Fuzzy Weasel Vs. Psycho Toads" M...
2020-009-Dave Kennedy, Offensive Tool release (Part 1) 12.03.2020 34:47
Dave Kennedy (@hackingDave) TrustedSec Released SEToolkit, Pentester Framework (PTF) PoC release for "Shitrix" bug (was disclosed after Google zero initiative India group) Jeff Snover, Lee Holmes - Powershell gods Arguments against release Tools are released are utilized by the 'bad guys' Tooling makes it more difficult to fingerprint who are who they say they are "Fuzzy Weasel Vs. Psycho Toads" M...
2020-008-Nemesis_Taylor Mutch 04.03.2020 53:10
Nemesis: https://github.com/UnityTech/nemesis https://www.techrepublic.com/article/security-concerns-hampering-adoption-of-containers-and-kubernetes/ Nemesis - a auditing tool to check against a set of benchmarks (CIS GCP only) https://en.wikipedia.org/wiki/Center_for_Internet_Security What does CIS do well? What do the CIS benchmarks do poorly? K8s workload identity - GKE specific github....
2020-007-Roberto_Rodriguez-threat_hunting-juypter_notebooks_data-science 26.02.2020 1:03:39
Brakesec Podcast is now on Pandora! Find us here: https:// pandora .app.link/p9AvwdTpT3 Book club Book club is starting up again with Hands-On AWS penetration testing with Kali Linux from Gilbert and Caudill. You read and get together to discuss or demo every Monday. Get the book, start reading and meet us for the kick off Monday the 24 at 10pm eastern. The book club meets virtually on zoom, and...
2020-006-Roberto Rodriguez, threat intel, threat hunting, hunter's forge, mordor setup 19.02.2020 32:11
Full notes and graphics are on www.brakeingsecurity.com Episode 2020-006 Book club "And maybe blurb for the cast could go something like this. Book club is starting up again with Hands-On AWS penetration testing with Kali Linux from Gilbert and Caudill. You read and get together to discuss or demo every Monday. Get the book, start reading and meet us for the kick off Monday the 24 at 10pm eastern....
2020-005-Marcus J Carey, red team automation, and Tribe of Hackers book series 10.02.2020 43:37
Brakeing Down Security Podcast on #Pandora- https://www.pandora.com/podcast/brakeing-down-security-podcast/PC:27866 Marcus Carey https://twitter.com/marcusjcarey Prolific Author, Defender, Enterprise Architect at ReliaQuest https://twitter.com/egyp7 https://www.darkreading.com/vulnerabilities---threats/reliaquest-acquires-threatcare/d/d-id/1335950 "GreyMatter integrates security data fro...
2020-004-Marcus Carey, ShmooCon Report, threat simulation 05.02.2020 31:35
Marcus Carey https://twitter.com/marcusjcarey Prolific Author, Defender, Enterprise Architect at ReliaQuest https://twitter.com/egyp7 https://www.darkreading.com/vulnerabilities---threats/reliaquest-acquires-threatcare/d/d-id/1335950 "GreyMatter integrates security data from security incident and event manager (SIEM), endpoint detection and response (EDR), firewalls, threat intelligence fe...
2020-003- Liz Fong Jones, tracking Pentesters, setting up MFA for SSH, and Developer Advocates 30.01.2020 34:53
What is Honeycomb.io? From the site: "Honeycomb is a tool for introspecting and interrogating your production systems. We can gather data from any source—from your clients (mobile, IoT, browsers), vendored software, or your own code. Single-node debugging tools miss crucial details in a world where infrastructure is dynamic and ephemeral. Honeycomb is a new type of tool, designed and evolved to m...
2020-002-Liz Fong-Jones discusses blog post about Honeycomb.io Incident Response 23.01.2020 36:49
Ms. Berlin's appearance on #misec podcast - https://www.youtube.com/watch?v=Cj2IF0zn_BE with @kentgruber and @quantissIA Blog post: https://www.honeycomb.io/blog/incident-report-running-dry-on-memory-without-noticing/ What is Honeycomb.io? From the site: "Honeycomb is a tool for introspecting and interrogating your production systems. We can gather data from any source—from your clients (mobil...
2020-001- Android malware, ugly citrix bugs, and Snake ransomware 13.01.2020 38:14
Educause conference: https://events.educause.edu/security-professionals-conference/2020/hotel-and-travel Amanda's Training that everyone should come to!!! https://nolacon.com/training/2020/security-detect-and-defense-ttx Follow twitter.com/infosecroleplay Part 1: New year, new things Discussion: What happened over the holidays? What did you get for christmas? PMP test is scheduled for...
2019-046-end of the year, end of the decade, predictions, and how we've all changed 23.12.2019 1:18:08
End of year, end of decade Are things better than 10 years ago? 5 years ago? If there was one thing to change things for the better, what would that be? Good, Bad, Ugly Did naming vulns make things better? Which industries are doing a good job of securing themselves? Finance? What do you wished never happened (security/compliance wise)? Ransomware infections with no bounties...
2019-045-Part 2-Noid, Dave Dittrich, empowered teams, features vs. security 18.12.2019 1:02:20
The day after part 1 Keybase halted the spacedrop the day after the first podcast is complete... Security failures in implementation "We need to push this to market, we'll patch it later!" Risk management discussion for project managers (PMP) CIA Triad… where does 'business goals' fit? Security is at odds with the bottom line **Reference Noid's Bsides Seattle talk and podcast earlier...
2019-044-Noid and Dave Dittrich discusses recent keybase woes - Part 1 10.12.2019 1:01:47
Patreon donor goodness: Scott S. and Ion S. @_noid_ @davedittrich Their response: "it's not a bug, it's a feature" "Don't write a blog post that will point out the issue" "You pointing out our issues makes things more difficult for us" "It's a free service, why are you hurting us?" https://keybase.io/docs/bug_reporting Nov 22nd Noid (@_noid_) Keybase discussion blog post https:/...
2019-043-Bea Hughes, dealing with realistic threats in your org 04.12.2019 1:10:59
Realistic Threats Nation states aren't after you https://twitter.com/beajammingh/status/1191884466752385025 https://twitter.com/beajammingh/status/1198671660150226946 https://twitter.com/beajammingh/status/1198671952824565762 https://www.leviathansecurity.com/blog/the-calculus-of-threat-modeling What are credible threats? Malicious insiders - Non-malicious insiders - https://www.scmagazine...
2019-042-CircuitSwan, Gitlabs, Job descriptions that don't suck, layer8con 27.11.2019 1:00:46
Diana Initiative @circuitswan @dianainitiative https://www.dianainitiative.org/ https://twitter.com/DianaInitiative Conference in Las Vegas (Aug 6-7, 2020) (Thu & Fri) info@dianainitiative.org Topics Diana initiatives Past 2015 - idea at defcon 23 2016-17-18 growing but got too big! 2019 got our own space, ~800 tickets 2020 plans-westin again, 2 speaking tracks and 1 workshop track, sold...
2019-041-circuitswan, diana initiative, diversity initiatives at conferences 21.11.2019 38:37
Diana Initiative @circuitswan https://www.dianainitiative.org/ https://twitter.com/DianaInitiative Conference in Las Vegas (Aug 6-7, 2020) (Thu & Fri) info@dianainitiative.org Topics Diana initiatives Past 2015 - idea at defcon 23 2016-17-18 growing but got too big! 2019 got our own space, ~800 tickets 2020 plans-westin again, 2 speaking tracks and 1 workshop track, solder village, c...
2019-040-vulns in cisco kit, google's project 'nightmare', healthcare data issues, TAGNW conference update 12.11.2019 1:06:47
Tagnw.org Amazon Smile - brakesec.com/smile News: https://www.androidpolice.com/2019/11/11/google-project-nightingale-health-records-collection/ https://www.csoonline.com/article/3439400/secrets-of-latest-smominru-botnet-variant-revealed-in-new-attack.html https://blog.naijasecforce.com/the-jar-based-malware/ - ms. Infosecsherpa mailing list "nuzzle" https://www.axios.com/hospitals-cybersecur...
2019-039-bluekeep_weaponized-npm_security_cracks-grrcon_report 04.11.2019 53:42
Grrcon update 2019-039- bluekeep Weaponized… and more Bluekeep weaponized https://www.bleepingcomputer.com/news/security/bluekeep-remote-code-execution-bug-in-rdp-exploited-en-masse/ https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708 https://www.microsoft.com/security/blog/2019/08/08/protect-against-bluekeep/ https://www.wired.com/story/bluekeep-hacking-crypt...
2019-038-Deveeshree_Nayak-risk_analysis, and OWASP WIA 30.10.2019 1:16:55
OWASP WIA - https://www.youtube.com/watch?v=umnt0qbOPsE https://www.owasp.org/index.php/Women_In_AppSec OWASP Women in AppSec Twitter: 2013_Nayak (reach and ask to be added) https://www.tagnw.org/events/ Risk in Infosec Risk - a situation which involves extreme danger and extensive amount of unrecovered loss What about risks that are positive in nature? PMP calls them 'opportunities' Risk A...
2019-038- Ethical dilemmas with offensive tools, powershell discussion with Lee Holmes - Part2 22.10.2019 52:40
Derbycon9 talk - PowerShell Security Looking Back from the Inside - https://www.youtube.com/watch?v=DYWPtt7qszY&list=PLNhlcxQZJSm_ZDJBksg97I5q1XsdQcyN5&index=27&t=0s Encarta - https://en.wikipedia.org/wiki/Encarta Scott Hanselman's twitter thread about Encarta: https://twitter.com/shanselman/status/1158780839464849409 Congrats on the black badge :) I like that you bring up execution poli...
2019-037-Lee Holmes, Powershell logging, and why there's an 'execution bypass' 17.10.2019 50:01
Derbycon9 talk - PowerShell Security Looking Back from the Inside - https://www.youtube.com/watch?v=DYWPtt7qszY&list=PLNhlcxQZJSm_ZDJBksg97I5q1XsdQcyN5&index=27&t=0s Encarta - https://en.wikipedia.org/wiki/Encarta Scott Hanselman's twitter thread about Encarta: https://twitter.com/shanselman/status/1158780839464849409 Congrats on the black badge :) I like that you bring up execution polici...
2019-036-RvrShell-graphql_defense-Part2 09.10.2019 57:01
Secure Python course: https://brakesec.com/brakesecpythonclass PDF Slides: https://drive.google.com/file/d/1wmxrfgbaHu56kfccLoOd5M3Zz6bNP6Qi/view?usp=sharing GraphQL High Level https://graphql.org/ Designed to replace REST Arch Allow you to make a large request, uses a query language Released by FB in 2012 JSON Learn Enough to be dangerous https://blog.bitsrc.io/13-graphql-tools-and-libr...
2019-035-Matt_szymanski-attack and defense of GraphQL-Part1 02.10.2019 42:29
Derbycon Discussion (bring Matt in) Python course: https://brakesec.com/brakesecpythonclass PDF Slides: https://drive.google.com/file/d/1wmxrfgbaHu56kfccLoOd5M3Zz6bNP6Qi/view?usp=sharing GraphQL High Level https://graphql.org/ Designed to replace REST Arch Allow you to make a large request, uses a query language Released by FB in 2012 JSON Learn Enough to be dangerous https://blog.bits...
2019-034- Tracy Maleeff, empathy as a service, derbycon discussion 22.09.2019 1:23:46
Podcast Interview (Youtube): https://youtu.be/4tdJwBMh3ow Tracy Maleeff (pronounced like may-leaf) - https://twitter.com/InfoSecSherpa https://medium.com/@InfoSecSherpa https://nuzzel.com/InfoSecSherpa Python secure coding class - November 2nd / 5 Saturdays @nxvl Teaching https://www.eventbrite.com/e/secure-python-coding-with-nicolas-valcarcel-registration-72804597511 Derbycon Talk: http...
2019-033-Part 2 of the Kubernetes security audit discussion (Jay Beale & Aaron Small) 16.09.2019 44:26
Topics: Infosec Campout report Jay Beale (co-lead for audit) *Bust-a-Kube* Aaron Small (product mgr at GKE/Google) Atreides Partners Trail of Bits What was the Audit? How did it come about? Who were the players? Kubernetes Working Group Aaron, Craig, Jay, Joel Outside vendors: Atredis: Josh, Nathan Keltner Trail of Bits: Stefan Edwards, Bobby Tonic , D...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.