Bryan Brake, Amanda Berlin, and Brian Boettcher
BrakeSec Education Podcast
A podcast about the world of Cybersecurity, Privacy, Compliance, and Regulatory issues that arise in today's workplace. Co-hosts Bryan Brake, Brian Boettcher, and Amanda Berlin teach concepts that aspiring Information Security professionals need to know, or refresh the memories of seasoned veterans.
Author
Bryan Brake, Amanda Berlin, and Brian Boettcher
Category
Podcast website
Latest episode
Jul 17, 2025
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
the last Derbycon Brakesec podcast 07.09.2019 50:43
This evening, we all came together to spend a bit of time talking about the final Derbycon. We talk to Mic Douglas about his 9 Derbycon appearances, Gary Rimar (piano player Extraordinare) talks about @litmoose's talk on how to tell C-Levels that their applications aren't good. We also got asked about how the show came about, and how we found each other. **Apologies for the echo in some parts....
2019-032-kubernetes security audit dicussion with Jay Beale and Aaron Small 31.08.2019 47:13
Topics: Infosec Campout report Derbycon Pizza Party (with podcast show!) https://www.eventbrite.com/e/brakesec-pizza-party-at-the-derbycon-mental-health-village-tickets-69219271705 Mental health village at Derbycon Jay Beale (co-lead for audit) *Bust-a-Kube* Aaron Small (product mgr at GKE/Google) Atreides Partners Trail of Bits What was the Audit? How did it come about? Who were the pl...
2019-031- Dissecting a Social engineering attack (Part 2) 16.08.2019 50:05
Intro - Ms. DirInfosec "Anna" Call Centers suffer from wanting to give good customer service and need to move the call along. Metrics are tailored to support an environment conducive to these kinds of attacks https://en.wikipedia.org/wiki/Social_engineering_(security) Social engineering will prey on people's altruism "Pregnant woman needing help through the security door" "Person on...
2019-030-news, breach of PHI, sephora data breach 09.08.2019 53:54
https://www.infosecurity-magazine.com/news/95-test-problems/ https://www.databreaches.net/a-misconfigured-aws-bucket-exposed-personal-and-counseling-logs-of-almost-300000-indian-employees/ https://www.scmagazine.com/home/security-news/data-breach/sephora-reports-data-breach-but-few-details/ https://www.infosecurity-magazine.com/news/93-of-organizations-cite-phishing/ https://tresorit.com...
2019-029-dissecting a real Social engineering attack (part 1) 01.08.2019 47:07
Intro - Ms. DirInfosec "Anna" Call Centers suffer from wanting to give good customer service and need to move the call along. Metrics are tailored to support an environment conducive to these kinds of attacks https://en.wikipedia.org/wiki/Social_engineering_(security) Social engineering will prey on people's altruism "Pregnant woman needing help through the security door" "Person on c...
2019-028-fileless_malware_campaign,privacy issues with email integration-new_zip_bomb_record 24.07.2019 59:51
FIleless malware campaign - https://www.microsoft.com/security/blog/2019/07/08/dismantling-a-fileless-campaign-microsoft-defender-atp-next-gen-protection-exposes-astaroth-attack/ https://docs.microsoft.com/en-us/windows/security/threat-protection/intelligence/fileless-threats https://www.andreafortuna.org/2017/12/08/what-is-reflective-dll-injection-and-how-can-be-detected/ https://www.extremetec...
2019-027-GDPR fines for British Airways, FTC fines Facebook, Zooma-palooza 14.07.2019 43:23
MITRE Pre-Attack techniques https://attack.mitre.org/techniques/pre/ https://www.bbc.com/news/business-48905907 Zoom - https://www.wired.com/story/zoom-flaw-web-server-fix/ Check out our Store on Teepub! https://brakesec.com/store Join us on our #Slack Channel! Send a request to @brakesec on Twitter or email bds.podcast@gmail.com # Brakesec Store!: https://www.teepublic.com/user/bdspodcast #Spot...
2019-026-Ben Johnson discusses hanging your shingle, going independent 09.07.2019 38:12
Starting a new business (hanging the shingle) What's a way to become an independent consultant? Especially if you don't have a reputation? Ben's reading list: "Mindset: the New Psychology of success" "Essentialism" "Extreme ownership" "Team of teams" Check out our Store on Teepub! https://brakesec.com/store Join us on our #Slack Channel! Send a request to @brakesec on Twitter or email...
2019-025-Ben Johnson discusses identity rights management, and controlling your AuthN/AuthZ issues 02.07.2019 41:43
Identity analytics "Identity analytics is the next evolution of the IGA (Identity Governance & Administration) market. Identity professionals can use this emerging set of solutions combining big data and advanced analytics to increase identity-related risk awareness and enhance IAM processes such as access certification, access request and role management." --gartner Identity related risk awaren...
2019-024-Tanya_Janca-mentorship-WoSec_organizations_what-makes-a-good-mentor 24.06.2019 53:53
Tanya Janca (@shehackspurple) DevOps Tools for free/cheap. They are all on github right, so they are all free? Python, Docker, k8s, Jenkins Licensing can be a problem Free-mium software, or trialware is useful? OWASP DevSlop Module Nicole Becker Pixie - insecure instagram "Betty Coin" SSLlabs - Qualys Mentoring Monday: What is "Mentoring Monday"? What do...
2019-023-Tanya Janca, Dev Slop, DevOps tools for free or cheap 18.06.2019 40:37
Announcements: InfoSec Campout Conference (Eventbrite, social contract, etc): https://www.infoseccampout.com All Day Devops (https:// www.alldaydevops.com ) free talks online... Next conference starts 06 November 2019 ------ Tanya Janca (@shehackspurple) @wosectweets - Women of Security DevOps Tools for free/cheap. They are all on github right, so they are all free? Python, Docker, k8s, Je...
2019-022-Chris Sanders-Rural_Tech_Fund-embracing_the_ATT&CK_Matrix 09.06.2019 1:01:09
ANNOUNCEMENTS: INFOSEC CAMPOUT TICKETS ARE STILL ON SALE. Go to https://www.infoseccampout.com for Eventbrite link and more information. Part 2 of our Discussion with Chris Sanders (@chrissanders88) Topics discussed: Companies dropping existing frameworks for ATT&CK Matrix, why? Rural Technology Fund - What it is, how does it work, Who can help make it more awesome. https://chrissanders.org/...
2019-021-Chris Sanders discusses a cognitive crisis, mental models, and dependence on tools 04.06.2019 47:55
https://chrissanders.org/2019/05/infosec-mental-models/ I've argued for some time that information security is in a growing state of cognitive crisis… Demand outweighs supply Because so many organizations need experience, they are unable to appropriately invest in entry-level jobs and devote the necessary time for internal training. That's an HR and hiring manager issue, right? --brbr No. --b...
2019-020-email_security_controls-windows_scheduler 29.05.2019 1:03:01
Bryan got phished (almost) - story time! https://isc.sans.edu/forums/diary/Do+you+block+new+domain+names/17564/ Through OpenDNS https://learn-umbrella.cisco.com/product-videos/newly-seen-domains-in-cisco-umbrella Available January 2017, Umbrella filters newly seen or created domains. By using new domains to host malware and other threats, attackers can outsmart security systems that rely on re...
2019-019-Securing your RDP and ElasticSearch, InfoSec Campout news 20.05.2019 53:11
https://static1.squarespace.com/static/556340ece4b0869396f21099/t/5cc9ff79c830253749527277/1556742010186/Red+Team+Practice+Lead.pdf https://www.reddit.com/r/netsec/comments/bonwil/prevent_a_worm_by_updating_remote_desktop/ https://blogs.technet.microsoft.com/msrc/2019/05/14/prevent-a-worm-by-updating-remote-desktop-services-cve-2019-0708/ https://security.berkeley.edu/resources/best-practices-ho...
2019-018-Lesson's I learned, github breach, ransoming github repos 14.05.2019 39:48
Things I learned this week: https://www.securusglobal.com/community/2013/12/20/dumping-windows-credentials/ https://www.helpnetsecurity.com/2019/04/29/docker-hub-breach/ https://www.zdnet.com/article/a-hacker-is-wiping-git-repositories-and-asking-for-a-ransom/ https://attack.mitre.org/techniques/T1003/ https://github.com/giMini/PowerMemory https://en.wikipedia.org/wiki/Local_Security_Authori...
2019-017-K8s Security, Kamus, interview with Omer Levi Hevroni 05.05.2019 49:49
K8s security with Omer Levi Hevroni (@omerlh) service tickets - Super-Dev Omer's requirements for storing secrets: Gitops enabled Kubernetes Native Secure "One-way encryption" Omer's slides and youtube video: https://www.slideshare.net/SolutoTLV/can-kubernetes-keep-a-secret https://www.youtube.com/watch?v=FoM3u8G99pc&&index=14&t=0s We've all experienced it: you're working on a task,...
2019-016-Conference announcement, and password spray defense 29.04.2019 46:11
Agenda: Announce the conference CFP: up soon CFW: up soon Campers: Friday night/Saturday night Like "toorcamp", but if it sucks, you can drive home… :D Limiting tickets, looking for sponsors To support the conference and future initiatives: "Infosec Education Foundation" 501c3 non-profit (we are working on the charity part) www.infoseccampout.com Password spraying https://github.com/...
2019-015-Kevin_johnson-incident_response_aftermath 22.04.2019 1:24:27
Announcements: https://www.workshopcon.com/ SpecterOps (red Team operations) and Tim Tomes (PWAPT) Bsides Nashville https://blog.secureideas.com/2019/04/we-take-security-seriously-and-other-trite-statements.html "We take security seriously and other trite statements" Wordpress infrastructure (supply chain failure) WordPress plugin called Woocommerce was at fault. Vuln late last...
2019-014-Tesla fails encryption, Albany and Sammamish ransomware attacks. 15.04.2019 50:41
Announcements: WorkshopCon Training with SpecterOps and Tim Tomes www.workshopcon.com redteam operations with SpecterOps PWAPT with Tim Tomes Source Boston: [Boston, MA 2019 (April 29 – May 3, 2019) (https://sourceconference.com/events/boston19/)Trainings: April 29 - April 30, 2019 | Conference: May 1 - 3, 2019 Cybernauts CTF meetup in Austin Texas at Indeed offices, 23 April at 5pm Central ti...
2019-013-ASVSv4 discussion with Daniel Cuthbert and Jim Manico - Part 2 07.04.2019 56:35
Announcements: SpecterOps and Tim Tomes are giving training at WorkshopCon https://www.workshopcon.com Rob Cheyne Source Boston - https://sourceconference.com/events/boston19/ Austin Cybernauts meetup - https://www.eventbrite.com/e/cybernauts-ctf-meetup-indeed-tickets-58816141663 SHOW NOTES: Architecture is not an implementation, but a way of thinking about a problem that has potentially many diff...
2019-012: OWASP ASVSv4 discussion with Daniel Cuthbert and Jim Manico - Part 1 01.04.2019 51:51
Show Notes SpecterOps and Tim Tomes are giving training at WorkshopCon https://www.workshopcon.com Rob Cheyne Source Boston - https://sourceconference.com/events/boston19/ Architecture is not an implementation, but a way of thinking about a problem that has potentially many different answers, and no one single "correct" answer. https://github.com/OWASP/ASVS "is to normalize the range in the co...
2019-011-part 2 of our interview with Brian "Noid" Harden 24.03.2019 47:13
Log-MD story SeaSec East meetup Gabe (county Infosec guy) https://www.sammamish.us/government/departments/information-technology/ransomware-attack-information-hub/ New Slack Moderator (@cherokeeJB) Shoutout to "Jerry G" Mike P on Slack: https://www.eventbrite.com/e/adversary-tactics-red-team-operations-training-course-dc-april-2019-tickets-54735183407 www. Workshopcon.com/events and th...
2019-010-Zach_Ruble-building_a_better_cheaper_C2_infra 18.03.2019 1:12:04
Shout-out to Thomas… Tried to meetup while at SEA comic-con Patreon Log-MD Hacker's Health - Ms. Roddie is at TROOPERS (Ms. Berlin?) 4 podcasts? SpecterOps Training / workshopCon - https://www.workshopcon.com/events Zach Ruble- @sendrublez C2 infra using Public WebApps TARCE - Teaching Assistant RCE(?) - they run your code every week, don't check for backdoors before running it... C2 Basics ...
2019-009- Log-MD story, Noid, communicating with Devs and security people-part1 12.03.2019 51:00
Log-MD story (quick one) (you'll like this one, Mr. Boettcher) SeaSec East meetup " Gabe" https://www.sammamish.us/government/departments/information-technology/ransomware-attack-information-hub/ New Slack Moderator (@cherokeeJB) Shoutout to "Jerry G" Mike P on Slack: https://www.eventbrite.com/e/adversary-tactics-red-team-operations-training-course-dc-april-2019-tickets-54735183407...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.