TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    7 Minute Security

    7 Minute Security is a weekly information security podcast focusing on penetration testing, blue teaming and building a career in security. The podcast also features in-depth interviews with industry leaders who share their insights, tools, tips and tricks for being a successful security engineer.

    Advertise

    Copyright: © Brian Johnson

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    7MS #520: How to Succeed in Business Without Really Crying - Part 11 May 13, 2022
    Show notes

    Hey friends, today we're giving another peek behind the curtain of what it's like to run a cybersecurity consultancy. Topics include:

    • Setting the right communication cadence - and communication channels - with a customer during a pentest.

    • Tips for collaborating well with contractors so that the customer experience feels like "a single human pane of glass" (insert barf emoji here).

    • How we're using Intercom to publish self-help/FAQ articles for 7MS.


    7MS #519: Tales of Pentest Pwnage - Part 35 May 07, 2022
    Show notes

    Hey friends, it's another fun tale of pentest pwnage today! This one talks about cool things you can do when you have full rights over an OU in Active Directory. Important links to review:

    • BloodHound edges
    • DACL Trouble: Generic All on OUs
    • AD prep bug in Windows Server 2016

    7MS #518: Interview with Amanda Berlin of Blumira Apr 27, 2022
    Show notes

    Today we're pumped to share a featured interview with Amanda Berlin, Lead Incident Detection Engineer at Blumira. You might already be familiar with Amanda's awesome Defensive Security Handbook or fine work with Mental Health Hackers. We polled our Slack friends and structured this interview as an AAA (Ask Amanda Anything). That resulted in a really fun chat that covered many things technical and not technical! Questions we posed to Amanda include:

    • Can you tell us more about your infosec superhero origin story and creation of your book?

    • Will there ever be a new version of the Defensive Security Handbook?

    • What blue team certs/YouTube vids/classes/conferences give the best bang for your buck?

    • Was it a mistake to invent computers?

    • From a logging standpoint, what devices provide blind spots (Linux systems, ioT devices, etc.)?

    • You can wave a magic wand and solve any three security challenges instantly - what do you choose?

    • Infosec Twitter drama. Love it? Leave it? Something inbetween?

    • Tips to prevent business email compromise?

    • How do we keep beloved family/friends (who keep falling prey to social engineering campaigns) safer on their computers and on the Web?

    • Our company had a partial ransomware deployment a few years ago. Is changing Active Directory passwords changed and formatting affected systems enough? (Spoiler alert: no. See Microsoft's advice on the topic)


    7MS #517: DIY Pentest Dropbox Tips - Part 6 Apr 22, 2022
    Show notes

    Today we're continuing a series we haven't done in a while (click here to see the whole series) all about building and deploying pentest dropboxes for customers. Specifically, we cover:

    Auto installing Splashtop This can be done automatically by downloading your splashtop.exe install and issuing this command:

    splashtop.exe prevercheck /s /i confirm_d=0,hidewindow=1,notray=0,req_perm=0,sec_opt=2

    Auto installing Ninite This can be done in a batch script like so:

    agent.msi /quiet ninitepro.exe /select App1 App2 App3 /silent ninite-install-report.txt

    The above command installs App1, App2 and App3 silently and logs output to a file called ninite-install-report.txt

    Auto installing Uptimerobot monitoring We do this by first creating a script called c:\uptimerobot.ps1 that makes the "phone home" call to UptimeRobot:

    Start-Transcript -Path c:\heartbeat.log -Append Invoke-Webrequest https://heartbeat.uptimerobot.com/LONG-UNIQUE-STRING -UseBasicParsing Stop-Transcript

    Then we install the scheduled task itself like so:

    schtasks.exe /create /tn "Heartbeat" /tr "powershell -noprofile -executionpolicy bypass -file c:\uptimerobot.ps1" /rl highest /f /sc minute /mo 5 /ru "NT AUTHORITY\SYSTEM"

    7MS #516: Tips to Travel More Securely Apr 14, 2022
    Show notes

    In today's episode I talk about a cool self-defense class I took a while ago which was all about less lethal methods of protecting/defending yourself. I also talk about some safer ways to handle/hide cash while traveling on vacation.


    7MS #515: Securing Your Family During and After a Disaster - Part 5 Apr 06, 2022
    Show notes

    Today we continue the series we started a few years ago called Security Your Family During and After a Disaster (the last part in this series was from a few years ago. In today's episode we focus on some additional things you should be thinking about to strengthen the "in case of emergency" document you share with your close friends and family.


    7MS #514: Tales of Pentest Pwnage - Part 34 Mar 30, 2022
    Show notes

    Welcome to another fun tale of pentest pwnage! This one isn't a telling of one single pentest, but a collection of helpful tips and tricks I've been using on a bunch of different tests lately. These tips include:

    • I'm seeing nmap scans get flagged a bit more from managed SOC services. Maybe a "quieter" nmap scan will help get enough ports to do a WitnessMe run, but still fly under the logging/alerting radar? Something like: nmap -p80,443,8000,8080 subnet.i.wanna.scan/24 -oA outputfile

    • Using mitm6 in "sniper" mode by targeting just one host with: mitm6 victim-I-want-to-get-juicy-info-from -d victim.domain --ignore-nofqnd

    • Using secretsdump to target a single host: secretsdump.py -target-ip 1.2.3.4 localadmin:@1.2.3.4 -hashes THIS-IS-WHERE-THE:SAM-HASHES-GO. Note the colon after localadmin - it's intentional, NOT an error!

    • Rubeus makes password spraying easy-peasy! Rubeus.exe spray /password:Winter2022 /outfile:output.txt. Get some hits from that effort? Then spray the good password against ALL domain accounts and you might get even more gold!

    • LDAPs relaying not working? Make sure it's config'd right: nmap -p636 -sV -iL txt-file-with-dcs-in-it


    7MS #513: Interview with Christopher Fielder and Jon Crotty of Arctic Wolf Mar 23, 2022
    Show notes

    Today we're joined by our friends Christopher Fielder and Jon Crotty from Arctic Wolf to talk about their interesting report on The State of Cybersecurity: 2022 Trends (note: you can get some of the report's key points here without needing to provide an email address). The three of us dig in to talk about some of the report's specific highlights, including:

    • Many orgs are running the bare minimum (or nothing!) for endpoint protection
    • Cyber insurance costs are going up, and some customers are unable to afford it - or they're getting dropped by their carrier altogether
    • Security is still not getting a seat at the decision-making table in a lot of orgs, and already-overburned IT teams taking on security as part of their job descriptions as well
    • Seems like everybody and their mom is moving infrastructure to the cloud, but few are managing that attack surface, thus increasing risk
    • The cyber skills gap remains a challenge - many security gurus are looking to get out of their current position, leading many orgs to hire inexperienced teams who make rushed/misinformed decisions about security tools and services, thus making the org less secure

    P.S. this is Christopher's fifth time on the program. Be sure to check out his first, second, third and fourth interviews with 7MS.


    7MS #512: First Impressions of InsightIDR Mar 17, 2022
    Show notes

    Today I'm sharing some first impressions of the Rapid 7 InsightIDR as kind of a teaser for an eventual new chapter in our Desperately Seeking a Super SIEM for SMBs series. Disclaimer: remember these are first impressions. There may be some missed detections I talk about today that are a me problem and not the technology. I hope to get to the root of those unresolved issues by the time I talk more formally about InsightIDR in a future episode. Enjoy!


    7MS #511: How to Succeed in Business Without Really Crying - Part 10 Mar 11, 2022
    Show notes

    Today we're continuing our series focused on [owning a security consultancy], talking specifically about:

    • How not to give up on warm sales leads, even if they haven't panned out for 5+ years!

    • Some cool Mac tools that help me manage 7MS - such as Craft and OmniFocus

    • A sneak peek at a SIEM vendor that will soon be featured in an episode of Desperately Seeking a Super SIEM for SMBs


    Previous 1 21 22 23 24 25 75 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights