Rafal (Wh1t3Rabbit) Los

Down the Security Rabbithole Podcast (DtSR)

News EN ↓ 750 episodes

This is Cybersecurity's premier podcast. Running strong since 2011 Rafal Los, James Jardine, and Jim Tiller bring a no-nonsense, non-commercial approach to our profession. DtSR brings interviews and discussion with people you want to meet, and stories you have to hear. So whether you're just starting out, or are decades deep into your career, you'll always learn something on this show. On Twitter/X: https://twitter.com/@DtSR_Podcast On YouTube: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq On LinkedIn: https://www.linkedin.com/company/down-the-securit...

Author

Rafal (Wh1t3Rabbit) Los

Category

News

Podcast website

blogwh1t3rabbit.medium.com

Latest episode

Jul 7, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

DtSR Episode 637 - Amanda Berlin Build SMB Tools That Don’t Suck 21.01.2025

TL;DR:  On this episode Amanda Berlin , Senior Product manager at Blumira, joins Jim and Rafal to talk about her career, the second edition of her book, and building products for SMBs that "don't suck". The unfortunate fact is that there aren't a lot of products designed for the unique challenges of companies that can't afford an army of security analysts, or consultants....

DtSR Episode 636 - CISO Perspectives Kayla Williams 14.01.2025

TL;DR:  Kayla Williams , CISO of Devo , joins Rafal & James on this episode to talk about her career path, the importance of the "financial perspective" and the need for well-rounded security leaders who understand business first and foremost. A wonderful episode for leaders and those who want to be. YouTube Video: https://youtube.com/live/axl8V-ayMjU Have something to say? Let's...

DtSR Episode 635 - The State of Trust 2025 07.01.2025

TL;DR:  Oh boy. Welcome to 2025, and the first podcast of the year is off to a flyer. Robert "RSnake" Hansen & Patrick Dennis join Jim and I to talk about "trust" - and we touch on everything from AI to politics and everything in between. What state is trust in, and why is it really bad? And ... now what?! Required background reading: Patrick's original post: https://w...

DtSR Episode 634 - The 2024 Year End Episode 31.12.2024

TL;DR:  On this lengthy and  very informal episode of the podcast, James, Jim and I close out the year with James Robinson (CISO of Netskope ) and Rock Lambros (Founder of Rock Cyber, and Author) as we discuss a wide range of topics you're going to have to listen in to get the details of. Wrap up 2024 by joining us for the EOY episode, and spread the new year cheer. YouTube Video: https://you...

DtSR Episode 633 - Getting the Band Back Together 24.12.2024

TL;DR: On this Christmas episode of the podcast, I (Rafal) get together with two of my team from back in the Optiv days - Mark Arnold & MacKenzie Brown - to talk about some of the things we accomplished, and the need to perhaps resurrect some of our work. We have a little fun along the way, too. YouTube Video: https://youtube.com/live/Y5NHMo69T1E Have something to say? Let's hear it. Suppo...

DtSR Episode 632 - The Politics of Detection Response and Security Operations 17.12.2024

TL;DR:  This week is a special show - where Raja Mukerji (Co-Founder, Chief Scientists at ExtraHop ), Paul Farley (Field CTO, TrustedSec ), and Anton Chuvakin (Security Advisor at Office of the CISO, Google Cloud ) join Rafal, James, and Jim to talk about the honest politics of "the operations part of security". Whether you call it SOC, Security Operations, Cyber Defense Center, or whate...

DtSR Episode 631 - Building and Securing Extreme Scale Network Infrastructure 10.12.2024

TL;DR: If you've ever wondered what kind of skill, scale, and engineering goes into building carrier-grade (and bigger) infrastructure this episode is for you. Joe DePalo (Executive Vice President & Chief Platform Officer at Netskope ) joins Jim & Rafal to talk about his time building some networks that just blow our minds. You'll enjoy this episode if you're into networking...

DtSR Episode 630 - We Need to Talk About Algorithm Bias in AI 03.12.2024

TL;DR:   Our guest this week is Marcus Carey , who wrote a piece (with one heck of a clickbait title, as he admitted) that calls out the biases we see in algorithmic (or "AI") processes. The panel including Rock Lambros and Jeff Collins discusses where the trouble lies, how it manifests, what can be done about it, and what's next. YouTube Video: https://youtube.com/live/dopwV5Z2VdM?...

DtSR Episode 629 - What The Hell Is Identity Security 26.11.2024

TL;DR:   New intro alert!   On this episode, we welcome Hed Kovetz from SILVERFORT - a company in the "identity security" space. If you're scratching your head and asking "what the hell is identity security?" - this episode is for you. We asked the same question, and Hed walked us through it. A wonderful primer on Identity Security for security professionals. YouTube Video...

DtSR Episode 628 - Rob Allen Endpoint Security Does Not Have to Suck 19.11.2024

TL;DR: Join us on an adventurous conversation in the wild and wacky world of endpoint security. At a time where evolution seems to have come to a standstill, there are things going on you may not be aware of. Endpoint security doesn't have to suck - this conversation with Rob Allen (Chief Product Officer at ThreatLocker ) may give you some new hope, or at least make you chuckle at Rob's...

DtSR Episode 627 - Talent Gap Lies and Truths 12.11.2024

TL;DR: On this spicy episode where returning guest Erik Bloch joins us, we host Lee Kushner to talk about the talent gap. Is there a talent gap? Who's to blame for the mess we're in right now? And of course, what to do next? For anyone who's job hunting, trying to understand the cyber job market, or trying to hire... this episode and conversation is for you. Sorry about the intermit...

DtSR Episode 626 - Patrick Dennis Investing in CyberSecurity is Hard 05.11.2024

TL;DR:  Today, the podcast takes a meeting in the finance department with Patrick Dennis - current CEO of Avaya and friend of the podcast. Patrick has extensive experience in investments in both tech and beyond, and he's here to dispense some wisdom, caution, and insights.  --> This podcast is packed with information that you can't afford to miss. YouTube Video: https://youtube.com/li...

DtSR Episode 625 - Cyber Ghost Stories to Tell in the Dark 29.10.2024

TL;DR: On this week's episode, Jim, James, and I sit down to a Halloween "scary story" episode. You know the feeling... that sinking feeling of dread when you can't quite put your finger on what's wrong but something is definitely wrong. Something scary, and nefarious is happening... and usually it's coming from  inside the house! YouTube Video: https://youtube.com/li...

DtSR Episode 624 - Kevin Clark One Month A Year That Security Matters 22.10.2024

TL;DR:  This week on the pod, Kevin Clark joins James and I to talk about his career, how his walked his journey to a successful security leader (spoiler alert, it's another roundabout path), and what we generally think of "security awareness month". Great conversation and I think you'll agree, we need Kevin back again soon. YouTube Video: https://youtube.com/live/0KiUwC0RzRQ H...

DtSR Episode 623 - SOC Metrics Suck 15.10.2024

TL;DR: Erik Bloch and  Anton Chuvakin join James, Jim, and myself to talk about why security metrics in the SOC ....suck. It's an interesting predicament, and one I'm sure Anton has been ranting about since he first got his 486/DX2 66. Or maybe not. It's an interesting topic because if we're measuring crap, that means something. Or does it even matter? Link to Erik's epic...

DtSR Episode 622 - Doug Burks Building the Security Onion 08.10.2024

TL;DR: This week's episode is a special one. I've been a fan of Security Onion for a long, long time and this week Jim Tiller and I welcome Doug Burks its creator to the show. Doug gives us his story of how he started the iconic security platform and where it's going next. Don't miss this sit-down that's been far overdue. Congrats to Doug and his team on the longevity and...

DtSR Episode 621 - Cyber Security Has a Data Problem Part 2 01.10.2024

TL;DR:  This is part 2 of the two-part episode with Jason Clark and Nathan Smolenski on data protection. In this episode we tackle the options and solutions to the problem we face - and why (just this one time) AI may be the only way forward. Interesting possibilities, and some real solutions. Don't miss our thee for episode 2 - "Hawaiian shirt day", on the video stream. Jim Tiller...

DtSR Episode 620 - Cyber Security Has a Data Problem Part 1 24.09.2024

TL;DR: This week Jason Clark and Nathan Smolenski join Jim Tiller and I on part 1 of a 2-part series on data security. It's a topic whose time has come, and we're going to start in part 1 with fully analyzing the problem, how we got here, and just how ugly the beast is. YouTube vide: https://youtube.com/live/Qps-4NSEI-4 Have something to say? Let's hear it. Support the show >>&...

DtSR Episode 619 - Aaron Bray The Complete Novice Guide to SBOM 17.09.2024

TL;DR:  This week's episode features Aaron Bray , CEO of Phylum . We use this episode as a complete primer on SBOM (Software Bill of Materials). We cover the typical "lot of ground" but try to answer the question of what SBOMs are, how they're useful, and what you as practitioners can do now that you have them. YouTube video: https://youtube.com/live/KHiDJt8SnZ0 Have something...

DtSR Episode 618 - Jeff Collins Microservices Killed the Vulnerability Scan 10.09.2024

TL;DR:  This week's episode sees the return of Mr Jeff Collins (of WanAware fame) as we talk over the long-prophesied death of vulnerability scanning. Maybe. What does the cloud have to do with the demise of vulnerability scanning? Listen and find out... I think you may find this relevant. This time, YouTube Video, is required viewing...trust me on this. YouTube Video: https://youtube.com/liv...

DtSR Episode 617 - Defending Forgotten but Business Critical Systems (SAP) Part 2 03.09.2024

TL;DR:  This week, part 2 of the SAP ("Critical Enterprise Apps") discussion where Tom Venables & Jay Thoden van Velzen get a little more in-depth on what it takes to secure SAP and ensure that there's more than just a firewall between imminent disaster and your business. Jim TIller guest-hosts this in-depth episode, and we invite you to grab a notepad, and take some notes! Part...

DtSR Episode 616 - A Wh1t3 Rabbit at Black Hat 2024 27.08.2024

TL;DR: This episode is a "walk-around" episode, where I walked around Black Hat 2024 and ran into some friends to talk about what we're seeing, anything that caught their attention, and some other interesting insights in short-form recordings. I hope you enjoy listening to Lamont Orange , Aaron Bray , Alex Humphrey , and Rick Holland as much as I enjoyed the conversations. No video...

DtSR Episode 615 - Doug Cavit Defending a Whole County 20.08.2024

TL;DR: Have you ever wondered what it would be like to be responsible for security for an entire  county ? That job encompasses a massive amount of responsibility - but I'll let Doug Cavit , the CISO of Snohomish County, Washington tell us about it. What a resume, and what an incredible job Doug has. YouTube Video: https://youtube.com/live/selNfh5gQAU Have something to say? Let's hear it....

DtSR Episode 614 - James Robinson Don't Worry SaaS is Probably Secure 13.08.2024

TL;DR:  This episode was one of our awesome LinkedIn Live episodes - if you missed it, join us on LinkedIn and never miss another! On this one, James Robinson (CISO at Netskope) talks with Rafal and James with guest-host Jim TIller about the possibilities we have with SaaS, data protection, and the whole mess we've made over the last 20+ years of "data everywhere". Big thanks to Net...

DtSR Episode 613 - Tim Miller A Frank Conversation on Software Manifests 06.08.2024

TL;DR: Today's episode is all about how we can build better software and systems - from a supply chain perspective. Tim Miller joins us, and it starts as a general conversation but we quickly dive into the world of software development. There's a lot to talk about here, starting with this XKCD that explains it perfectly: https://xkcd.com/2347/ YouTube video: https://youtube.com/live/XOMl...

Listen to the Down the Security Rabbithole Podcast (DtSR) podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.