7 Minute Security
Hey friends! We’ve been on a bit of a Tales of Pentest Pwnage bender lately, so let’s keep it rolling with Part 90. (And Mom, relax — this is not one pentest story chopped into 90 parts.) Today is less of an A-to-Z story and more a pile of tips and tricks pulled from a recent string of SCCM-flavored internals — plus a tangent about a video game and a little robot Claude and I built to get my life back. Multi-tier SCCM is having a moment — I’ve never administered SCCM a day in my life, but 2026 keeps dropping me into these split-role environments. Here’s where I go to figure out...
info_outline7 Minute Security
Hey friends! Today is a tale of pentest pwnage episode, and this one features a path to escalation I have never seen before – one I could only find few references on the entire Internet. It happened completely by accident, but during the report readout I’m absolutely going to say it was intentional and that I totally meant to do that. Here’s what we cover: A client that’s actually doing the things – year two or three of testing this environment, and they had buttoned up so much that I had to dig deep. Great for them, freaking frustrating for me. Why my...
info_outline7 Minute Security
Hey friends! Today I’m talking about Baby’s First Neo — and to be crystal clear, I don’t mean Keanu, and I don’t mean the R&B guy with the hat. I mean the AI-powered pentest assistant from our pals at . Also to be crystal clear: this is not a sponsorship, ad, partnership or anything of the sort. Just me sharing a thing I like so you can decide if you like it too. Here’s what we get into: Why I didn’t renew my ProjectDiscovery cloud subscription after a full year of running it side-by-side with Nessus — including the three things that ground my...
info_outline7 Minute Security
Hello friends! Today’s tale of pentest pwnage isn’t a start-to-finish march to DA – it’s me finally emptying out the backlog of “gosh, I’ve got to share this next time” internal network tips that have been rattling around in my head. Here’s what we get into: Don’t skip the boring stuff. Even when I’m testing the same network for the third or fourth time, I’ve got an ever-growing list of things I check every single time – because config drift has a nasty habit of quietly reintroducing problems that were fixed years ago. Get a second opinion on...
info_outline7 Minute Security
Hey friends! Today’s another slice of our Securing Your Family During and After a Disaster miniseries, and fair warning — it’s a bit of a Friday mood-ruiner. It’s been almost two months since my dad passed, and we’ve moved into a phase nobody prepared me for. Here’s what we get into: The paperwork nobody thinks about — my mom still doesn’t know what her monthly income looks like now, and the answer is buried in a box somebody lost the key to. Divvying up a lifetime of stuff — and why our 2019 house fire completely rewired how I think about possessions....
info_outline7 Minute Security
Hey friends! Today’s episode has a new-to-me toy up front and some podcast housekeeping on the back half – all recorded with a raging case of the anxious parent giggidies, because my son Atticus had a big audition and I was minutes away from finding out whether we were doing tears of joy or tears of sadness. Baby’s first Cloudflare Tunnel Not a sponsor, not an ad – just a thing I’d heard about for years and finally had a reason to use. Here’s what we get into: The problem that sent me down this road: I wanted push-button status pages for clients that pull from one source...
info_outline7 Minute Security
Hey friends! Today’s episode is a two-parter: some security stuff up front, and then a big ol’ personal celebration on the back half. If you’re strictly here for the security bits, I love you and you’re free to bail after the first half. If you’re here for both, God bless you. Part 1: Kicking the tires on Insight Recon What it is: is an Active Directory security assessment tool out of Heath Adams’ new venture, . I signed up for early access a while back, finally got a login, and took it for a spin this week in my lab. Not a sponsor, not an ad — just a...
info_outline7 Minute Security
Hey friends! Today’s episode comes to you from a parking lot in the rain, with a mint hot cocoa in hand and your host absolutely dragging his butt (D-R-A-G-G-I-N-G, not D-R-A-G-O-N – I’ve never seen a dragon’s butt and can’t speak to how mine compares). I’ve had a bunch of internals back to back lately and I’m basically a drooling dog who found a frisbee and refuses to put it down. Sleep be darned. So instead of walking through one test start to finish, I want to share a few things that have helped me claw out a foothold in environments that are otherwise really locked...
info_outline7 Minute Security
Hey friends! Welcome back to another Tales of Pentest Pwnage — my favorite mini-series where I share the good, the bad, and the “why didn’t I check THAT first?!” moments from real-world engagements. Today’s story has a little bit of everything: a legit path to domain admin, some late-night rabbit holes, a lesson in humility, and a villain you’ve definitely met before. (Spoiler: it’s DNS.) A couple of quick plugs before we dive in: Private GOAD training is going strong! — We just wrapped a 3-day private session (7 students — that’s max capacity!) of our Active...
info_outline7 Minute Security
Hey friends! Fair warning: today’s episode is a bit of an emotional rollercoaster — we’ve got a big security win, some honest lab feedback, and a very personal share about my dad’s funeral. Buckle up. certified, baby! — I’m officially a , courtesy of the folks at . It’s been a long time coming (I originally signed up for the live version and fell off after missing a couple Saturdays), but I came back for the self-paced 30-day version and finally finished the job. The lab experience — the good: — ~25 objectives, a solid lab guide, and a really fun...
info_outlineHey friends! Backups are not as cool as pentesting, but boy do they matter when things go sideways. This week I’m sharing how a Proxmox backup disk space meltdown led me to a completely overhauled — and honestly pretty bulletproof — backup setup for both home and work. Claude played a big role in helping me sort it all out.
Here’s what we get into:
- The backup history tour — I’ve been through CrashPlan, Dropbox, Backblaze (which saved my bacon after my house fire in 2019!), and a mystery one that may or may not have had “Panda” in the name. These days I’m settled on ARQ for personal backups — dead simple, backs up to just about everything (Dropbox, OneDrive, Google Drive, even their own ARQ Cloud for ~$80/year), and all data is encrypted at rest. Not a sponsor, but they should be.
- The 3-2-1 rule — I actually asked Siri mid-episode, and she initially thought it was a grounding/anxiety technique. (Valid, I guess?) The real answer: three copies, two different media, one offline. I’ve got a local copy plus OneDrive, Google Drive, and Dropbox — so I think I’m covered.
- The work side: Proxmox + PBS — My “data center” is a beefy Hetzner Proxmox box with about a dozen VMs. I had Proxmox Backup Server (PBS) set up on a secondary Hetzner box, happily cranking away… until it ran out of disk space and started yelling at me every night.
- Claude to the rescue — I spun up a Claude project, fed it terminal output and retention configs, and it gave me a straight-up honest assessment: either gut your retention policy (risky) or get more disk. It then walked me through Hetzner’s auctions page — which I didn’t even know existed — to find a storage-heavy, low-horsepower box. Ended up with two mirrored 8TB drives plus a 14TB drive for around $40/month. Not cheap, but totally worth it as a business expense.
- The new setup — PBS is now on its own dedicated Hetzner box. VMs from both my data center and my home NUC Proxmox box back up there nightly. Claude also suggested using that 14TB drive as an SFTP target for ARQ, giving me yet another redundant copy of all my personal data. It’ll take a few weeks to fully sync, but I’m running some flavor of the 4-3-2-1 rule now (I made that up).
- Proxmox forever — Someone wrote in asking if I’d go back to ESXi now that Broadcom brought back the free version. Hard no. I’ve fallen in love with Proxmox and I’m not going back.
- 7MinSec wiki scripts repo — Head over to 7MinSec.wiki and click the Scripts button to find a new GitHub repo where I’m publishing pentesting scripts. First one up: a push-button Exegol installer. More to come — and I’ll probably tease new scripts first over at 7MinSec.club on TuesdayTOOLSday!
Have a backup horror story — or a setup you’re proud of? Hit us up! And if you need assessments, pentesting, training, or other security goodness, find us at 7MinSec.com.