7 Minute Security
Today we’re thrilled to announce the launch of LPLITE:GOAD (Light Pentest Live Interactive Training Experience: Game of Active Directory). The first class is coming up Tuesday, January 27 – Thursday, January 29 (9:00 a.m. – 1:00 p.m. CST each day). More information, pricing information and more can be found at . Today I talk about who should sign up for the course, what you should bring, and some of the awesome things you’ll be doing should you choose to join me on this hacking adventure!
info_outline7 Minute Security
I’m so excited to share today’s tale of pentest pwnage, because it brings back to life a coercion technique I thought wouldn’t work against Windows 11! Spoiler alert: check out , as well as the we did on the topic this week. Also, our January Light Pentest LITE:GOAD class is open for registration !
info_outline7 Minute Security
This might be obvious, but security is not all domain admin dancing and maximum pwnage. Sometimes, despite my best efforts, a security project does a faceplant. Today’s episode focuses on a phishing campaign that had plenty of “bites” but got immediately shut down – for reasons I still don’t understand.
info_outline7 Minute Security
Hola friends! My week has very much been about trying to turnaround pentest dropboxes as quickly as possible. In that adventure, I came across two time-saving discoveries: Using a as a persistent remote access method Writing a Proxmox post-deployment script that installs Splashtop on the Windows VM, and resets the admin passwords on both VMs, all from the Proxmox SSH console without touching the console on either VM If you feel some of this is better seen than said, on this week’s broadcast we show this in more detail.
info_outline7 Minute Security
Happy Thanksgiving week friends! Today we’re celebrating a turkey and pie overload by sharing another fun tale of pentest pwnage! It involves using to hijack a GPO and turn it into our pentesting puppet! Muahahahahaah!!!! Also: This week over at we looked at how to defend against some common SQL attacks We’re very close to offering our brand new LPLITE:GOAD 3-day pentest course (likely in mid-January). It will get announced on first, so please make sure you’re subscribed there (it’s free!) Did you miss our talk called...
info_outline7 Minute Security
Hello friends, in today’s episode I give an audio summary of a talk I gave this week at the MN GOVIT Symposium called “Should You Hire AI to Run Your Next Pentest?” It’s not a pro-AI celebration, nor is it an anti-AI bashing. Rather, the talk focuses on my experiences using both free and paid AI services to guide me through an Active Directory penetration test.
info_outline7 Minute Security
Hello friends! This week I’m talking about what I’m working on this week, including: Preparing a talk called Should You Hire AI to Run Your Next Pentest for the . Playing with (I will show this live on next week’s ). The Light Pentest logo contest has a winner!
info_outline7 Minute Security
Today is episode 700 of the 7MinSec podcast! Oh my gosh. My mom didn’t think we could do it, but we did. Instead of a big blowout with huge news, giveaways and special guests, today is a pretty standard issue episode with a (nearly) 7-minute run time! The topic of today’s episode is Pretender (which you can download and read a lot more about ). The tool authors explain the motivation behind the tool: “We designed pretender with the single purpose to obtain machine-in-the-middle positions combining the techniques of and only the name resolution...
info_outline7 Minute Security
Today we discuss some pre-travel tips you can use before hopping on a plane to start a work/personal adventure. Tips include: Updating the family DR/BCP plan Lightening your purse/wallet Validating/testing backups and restores Ensuring your auto coverage is up to snuff
info_outline7 Minute Security
Today I give a quick review of the cloud version of (not a sponsor!).
info_outlineIn today’s episode:
- I got a new podcast doodad
- I really like JitBit as a security ticketing system (not a sponsor)
- The Threat Hunting with Velociraptor 2-day training was great. Highly recommend. I got inspired to take this class after watching the 1-hour primer here.