Bryan Brake, Amanda Berlin, and Brian Boettcher

BrakeSec Education Podcast

News EN ↓ 463 episodes

A podcast about the world of Cybersecurity, Privacy, Compliance, and Regulatory issues that arise in today's workplace. Co-hosts Bryan Brake, Brian Boettcher, and Amanda Berlin teach concepts that aspiring Information Security professionals need to know, or refresh the memories of seasoned veterans.

Author

Bryan Brake, Amanda Berlin, and Brian Boettcher

Category

News

Podcast website

www.youtube.com

Latest episode

Jul 17, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

the last Derbycon Brakesec podcast 07.09.2019

This evening, we all came together to spend a bit of time talking about the final Derbycon. We talk to Mic Douglas about his 9 Derbycon appearances, Gary Rimar (piano player Extraordinare) talks about @litmoose's talk on how to tell C-Levels that their applications aren't good.   We also got asked about how the show came about, and how we found each other.   **Apologies for the echo in some parts....

2019-032-kubernetes security audit dicussion with Jay Beale and Aaron Small 31.08.2019

Topics: Infosec Campout report Derbycon Pizza Party (with podcast show!)  https://www.eventbrite.com/e/brakesec-pizza-party-at-the-derbycon-mental-health-village-tickets-69219271705 Mental health village at Derbycon   Jay Beale (co-lead for audit) *Bust-a-Kube*   Aaron Small (product mgr at GKE/Google) Atreides Partners Trail of Bits   What was the Audit?  How did it come about?    Who were the pl...

2019-031- Dissecting a Social engineering attack (Part 2) 16.08.2019

  Intro - Ms. DirInfosec "Anna" Call Centers suffer from wanting to give good customer service and need to move the call along.     Metrics are tailored to support an environment conducive to these kinds of attacks https://en.wikipedia.org/wiki/Social_engineering_(security) Social engineering will prey on people's altruism      "Pregnant woman needing help through the security door"     "Person on...

2019-030-news, breach of PHI, sephora data breach 09.08.2019

https://www.infosecurity-magazine.com/news/95-test-problems/   https://www.databreaches.net/a-misconfigured-aws-bucket-exposed-personal-and-counseling-logs-of-almost-300000-indian-employees/   https://www.scmagazine.com/home/security-news/data-breach/sephora-reports-data-breach-but-few-details/     https://www.infosecurity-magazine.com/news/93-of-organizations-cite-phishing/   https://tresorit.com...

2019-029-dissecting a real Social engineering attack (part 1) 01.08.2019

Intro - Ms. DirInfosec "Anna" Call Centers suffer from wanting to give good customer service and need to move the call along.     Metrics are tailored to support an environment conducive to these kinds of attacks https://en.wikipedia.org/wiki/Social_engineering_(security) Social engineering will prey on people's altruism      "Pregnant woman needing help through the security door"     "Person on c...

2019-028-fileless_malware_campaign,privacy issues with email integration-new_zip_bomb_record 24.07.2019

FIleless malware campaign - https://www.microsoft.com/security/blog/2019/07/08/dismantling-a-fileless-campaign-microsoft-defender-atp-next-gen-protection-exposes-astaroth-attack/ https://docs.microsoft.com/en-us/windows/security/threat-protection/intelligence/fileless-threats   https://www.andreafortuna.org/2017/12/08/what-is-reflective-dll-injection-and-how-can-be-detected/ https://www.extremetec...

2019-027-GDPR fines for British Airways, FTC fines Facebook, Zooma-palooza 14.07.2019

MITRE Pre-Attack techniques https://attack.mitre.org/techniques/pre/ https://www.bbc.com/news/business-48905907 Zoom - https://www.wired.com/story/zoom-flaw-web-server-fix/   Check out our Store on Teepub! https://brakesec.com/store Join us on our #Slack Channel! Send a request to @brakesec on Twitter or email bds.podcast@gmail.com # Brakesec Store!: https://www.teepublic.com/user/bdspodcast #Spot...

2019-026-Ben Johnson discusses hanging your shingle, going independent 09.07.2019

    Starting a new business (hanging the shingle)   What's a way to become an independent consultant? Especially if you don't have a reputation?   Ben's reading list: "Mindset: the New Psychology of success" "Essentialism" "Extreme ownership" "Team of teams"     Check out our Store on Teepub! https://brakesec.com/store Join us on our #Slack Channel! Send a request to @brakesec on Twitter or email...

2019-025-Ben Johnson discusses identity rights management, and controlling your AuthN/AuthZ issues 02.07.2019

Identity analytics   "Identity analytics is the next evolution of the IGA (Identity Governance & Administration) market. Identity professionals can use this emerging set of solutions combining big data and advanced analytics to increase identity-related risk awareness and enhance IAM processes such as access certification, access request and role management." --gartner Identity related risk awaren...

2019-024-Tanya_Janca-mentorship-WoSec_organizations_what-makes-a-good-mentor 24.06.2019

Tanya Janca (@shehackspurple)   DevOps Tools for free/cheap.     They are all on github right, so they are all free?     Python, Docker, k8s, Jenkins     Licensing can be a problem     Free-mium software, or trialware is useful? OWASP DevSlop     Module     Nicole Becker         Pixie - insecure instagram "Betty Coin" SSLlabs - Qualys   Mentoring Monday:     What is "Mentoring Monday"?     What do...

2019-023-Tanya Janca, Dev Slop, DevOps tools for free or cheap 18.06.2019

Announcements: InfoSec Campout Conference (Eventbrite, social contract, etc): https://www.infoseccampout.com All Day Devops (https:// www.alldaydevops.com ) free talks online... Next conference starts 06 November 2019 ------ Tanya Janca (@shehackspurple) @wosectweets - Women of Security DevOps Tools for free/cheap.     They are all on github right, so they are all free?     Python, Docker, k8s, Je...

2019-022-Chris Sanders-Rural_Tech_Fund-embracing_the_ATT&CK_Matrix 09.06.2019

ANNOUNCEMENTS: INFOSEC CAMPOUT TICKETS ARE STILL ON SALE. Go to https://www.infoseccampout.com for Eventbrite link and more information.     Part 2 of our Discussion with Chris Sanders (@chrissanders88) Topics discussed: Companies dropping existing frameworks for ATT&CK Matrix, why? Rural Technology Fund - What it is, how does it work, Who can help make it more awesome.   https://chrissanders.org/...

2019-021-Chris Sanders discusses a cognitive crisis, mental models, and dependence on tools 04.06.2019

https://chrissanders.org/2019/05/infosec-mental-models/   I've argued for some time that information security is in a growing state of cognitive crisis…   Demand outweighs supply Because so many organizations need experience, they are unable to appropriately invest in entry-level jobs and devote the necessary time for internal training. That's an HR and hiring manager issue, right? --brbr  No. --b...

2019-020-email_security_controls-windows_scheduler 29.05.2019

Bryan got phished (almost) - story time!   https://isc.sans.edu/forums/diary/Do+you+block+new+domain+names/17564/   Through OpenDNS https://learn-umbrella.cisco.com/product-videos/newly-seen-domains-in-cisco-umbrella Available January 2017, Umbrella filters newly seen or created domains. By using new domains to host malware and other threats, attackers can outsmart security systems that rely on re...

2019-019-Securing your RDP and ElasticSearch, InfoSec Campout news 20.05.2019

https://static1.squarespace.com/static/556340ece4b0869396f21099/t/5cc9ff79c830253749527277/1556742010186/Red+Team+Practice+Lead.pdf https://www.reddit.com/r/netsec/comments/bonwil/prevent_a_worm_by_updating_remote_desktop/   https://blogs.technet.microsoft.com/msrc/2019/05/14/prevent-a-worm-by-updating-remote-desktop-services-cve-2019-0708/ https://security.berkeley.edu/resources/best-practices-ho...

2019-018-Lesson's I learned, github breach, ransoming github repos 14.05.2019

Things I learned this week:   https://www.securusglobal.com/community/2013/12/20/dumping-windows-credentials/ https://www.helpnetsecurity.com/2019/04/29/docker-hub-breach/   https://www.zdnet.com/article/a-hacker-is-wiping-git-repositories-and-asking-for-a-ransom/ https://attack.mitre.org/techniques/T1003/ https://github.com/giMini/PowerMemory   https://en.wikipedia.org/wiki/Local_Security_Authori...

2019-017-K8s Security, Kamus, interview with Omer Levi Hevroni 05.05.2019

K8s security with Omer Levi Hevroni (@omerlh)   service tickets - Super-Dev   Omer's requirements for storing secrets:   Gitops enabled Kubernetes Native Secure     "One-way encryption"   Omer's slides and youtube video: https://www.slideshare.net/SolutoTLV/can-kubernetes-keep-a-secret https://www.youtube.com/watch?v=FoM3u8G99pc&&index=14&t=0s   We've all experienced it: you're working on a task,...

2019-016-Conference announcement, and password spray defense 29.04.2019

Agenda:   Announce the conference CFP: up soon CFW: up soon Campers: Friday night/Saturday night     Like "toorcamp", but if it sucks, you can drive home… :D   Limiting tickets, looking for sponsors To support the conference and future initiatives: "Infosec Education Foundation"     501c3 non-profit (we are working on the charity part)   www.infoseccampout.com Password spraying https://github.com/...

2019-015-Kevin_johnson-incident_response_aftermath 22.04.2019

Announcements: https://www.workshopcon.com/     SpecterOps (red Team operations) and Tim Tomes (PWAPT)   Bsides Nashville   https://blog.secureideas.com/2019/04/we-take-security-seriously-and-other-trite-statements.html   "We take security seriously and other trite statements"   Wordpress infrastructure (supply chain failure)     WordPress plugin called Woocommerce was at fault.     Vuln late last...

2019-014-Tesla fails encryption, Albany and Sammamish ransomware attacks. 15.04.2019

Announcements: WorkshopCon Training with SpecterOps and Tim Tomes www.workshopcon.com redteam operations with SpecterOps PWAPT with Tim Tomes   Source Boston: [Boston, MA 2019 (April 29 – May 3, 2019) (https://sourceconference.com/events/boston19/)Trainings: April 29 - April 30, 2019 | Conference: May 1 - 3, 2019   Cybernauts CTF meetup in Austin Texas at Indeed offices, 23 April at 5pm Central ti...

2019-013-ASVSv4 discussion with Daniel Cuthbert and Jim Manico - Part 2 07.04.2019

Announcements: SpecterOps and Tim Tomes are giving training at WorkshopCon https://www.workshopcon.com Rob Cheyne Source Boston - https://sourceconference.com/events/boston19/ Austin Cybernauts meetup - https://www.eventbrite.com/e/cybernauts-ctf-meetup-indeed-tickets-58816141663 SHOW NOTES: Architecture is not an implementation, but a way of thinking about a problem that has potentially many diff...

2019-012: OWASP ASVSv4 discussion with Daniel Cuthbert and Jim Manico - Part 1 01.04.2019

Show Notes SpecterOps and Tim Tomes are giving training at WorkshopCon https://www.workshopcon.com Rob Cheyne Source Boston - https://sourceconference.com/events/boston19/   Architecture is not an implementation, but a way of thinking about a problem that has potentially many different answers, and no one single "correct" answer.   https://github.com/OWASP/ASVS "is to normalize the range in the co...

2019-011-part 2 of our interview with Brian "Noid" Harden 24.03.2019

  Log-MD story     SeaSec East meetup     Gabe (county Infosec guy) https://www.sammamish.us/government/departments/information-technology/ransomware-attack-information-hub/ New Slack Moderator (@cherokeeJB) Shoutout to "Jerry G"   Mike P on Slack: https://www.eventbrite.com/e/adversary-tactics-red-team-operations-training-course-dc-april-2019-tickets-54735183407 www. Workshopcon.com/events and th...

2019-010-Zach_Ruble-building_a_better_cheaper_C2_infra 18.03.2019

Shout-out to Thomas…     Tried to meetup while at SEA comic-con Patreon Log-MD Hacker's Health - Ms. Roddie is at TROOPERS (Ms. Berlin?) 4 podcasts? SpecterOps Training / workshopCon  - https://www.workshopcon.com/events Zach Ruble- @sendrublez C2 infra using Public WebApps TARCE - Teaching Assistant RCE(?) - they run your code every week, don't check for backdoors before running it... C2 Basics  ...

2019-009- Log-MD story, Noid, communicating with Devs and security people-part1 12.03.2019

Log-MD story (quick one) (you'll like this one, Mr. Boettcher)     SeaSec East meetup     " Gabe"   https://www.sammamish.us/government/departments/information-technology/ransomware-attack-information-hub/   New Slack Moderator (@cherokeeJB) Shoutout to "Jerry G"   Mike P on Slack: https://www.eventbrite.com/e/adversary-tactics-red-team-operations-training-course-dc-april-2019-tickets-54735183407...

Listen to the BrakeSec Education Podcast podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.