7 Minute Security

  • Autor: Vários
  • Narrador: Vários
  • Editora: Podcast
  • Duração: 317:52:44
  • Mais informações

Informações:

Sinopse

7 Minute Security is a weekly information security podcast focusing on penetration testing, blue teaming and building a career in security. The podcast also features in-depth interviews with industry leaders who share their insights, tools, tips and tricks for being a successful security engineer.

Episódios

  • 7MS #731: CARTP – Cloud Red Team Tactics for Attacking and Defending Azure – THE FINAL CHAPTER!

    17/07/2026 Duração: 53min

    Hey friends! Fair warning: today's episode is a bit of an emotional rollercoaster — we've got a big security win, some honest lab feedback, and a very personal share about my dad's funeral. Buckle up. CARTP certified, baby! — I'm officially a Certified Azure Red Team Professional (CARTP), courtesy of the folks at Altered Security. It's been a long time coming (I originally signed up for the live version and fell off after missing a couple Saturdays), but I came back for the self-paced 30-day version and finally finished the job. The lab experience — the good: — ~25 objectives, a solid lab guide, and a really fun variety of attack paths. Highlights include stealing tokens, enumerating Azure tenants, attacking apps and VMs and key vaults, simulated phishing against real tenant email addresses, popping reverse shells, and some clever OneDrive-based follow-on attacks via session hijacking. There's even some web app pen testing (hello, server-side template injection!) sprinkled in. The lab experience — the not-so

  • 7MS #730: Baby's First Project Swarm

    10/07/2026 Duração: 25min

    Hey friends! Still your grieving pal over here, but also your swarming friend and Protecting My Network Edge host — because this week I've been tinkering with something called Project Swarm and I've got my diapers on regarding it, but I really, really like what I see so far. Then, fair warning, I flip on the tangent light and verbally barf up some personal stuff at the end. I'll make the hand-off super clear, so if you want your free security podcast to do exactly what you want and nothing else — totally fair, and you won't offend me by hopping off. Here's what we cover: What is Project Swarm? This comes to us from our friends over at GreyNoise. It centers around little sensors you deploy to the edges of your network that you can dress up to look like just about anything — attracting flies to the honey, if you catch my drift. You get more enumeration, insight, and logging into whatever shenanigans those flies are using to poke at your edge. Setup was refreshingly easy: You need a very low-powered VM or hardw

  • 7MS #729: Pwning Dracarys

    04/07/2026 Duração: 18min

    Hey friends! Still your grieving pal over here, but also your happy hacking host — because today we're diving into baby's first Dracarys! (Yes, I'm probably pronouncing that wrong. Yes, I'm going to keep saying it anyway.) Quick housekeeping: A few days ago I published a mini-series episode from our How to Secure Your Family During and After a Disaster series, where I shared the news that my dad passed away last Friday. So many of you reached out with condolences — thank you from the bottom of my heart. I'll share a little life update at the end of this episode. But first — Dracarys! I didn't know it existed until recently. If you knew about it and didn't tell me, I'm mad at you. But we made up. We're friends forever. Here's what we cover: What is Dracarys? It's a smaller, CTF-style Active Directory pentesting lab from the same crew that brought us Game of Active Directory (GOAD), GOAD-SCCM, GOAD-Light, and Ninja Hacker Academy. Where GOAD holds your hand through the vulnerabilities, Dracarys and Ninja Hacke

  • 7MS #728: Securing Your Family During and After a Disaster – Part 8

    30/06/2026 Duração: 38min

    Hey friends! This is a tough one to write. My dad passed away on Friday, and instead of the hacker-y tech episode I had planned, I pivoted to something more personal — another installment of our "Securing Your Family During and After a Disaster" series. I talk pretty raw and transparently today about loss, grief, and the practical stuff that makes a hard situation just a little less hard. Fair warning: it's about death and dying, so if that's not where your head is today, it's totally okay to duck out – we'll catch you next week. Here's what I cover: My dad's last day — He spent Thursday doing all his favorite things: chainsaws, ATVs, trap-shooting, mowing, and weed-whipping. Then Chinese food with the family and marveling at modern video games for the first time since the Atari 5200. It was, by all accounts, a perfect day for him. How we found out — My son Cameron, who's finishing up paramedic school, was visiting and sprung into EMT mode when my dad was found unresponsive Friday morning. He did CPR for 10

  • 7MS #727: Securing Your Mental Health – Part 7

    19/06/2026 Duração: 21min

    Hello friends! It's been over a year since we did a dedicated mental health episode, so today I'm doing a big catch-up and running through my 7-point plan for being a more mentally secure me. None of this is professional medical advice (I am most definitely not a doctor or therapist — well, actually, I am in therapy, but that's tip #5), so take what's useful and leave what isn't. Terms and conditions apply. Here's my current mental health toolkit: Drink a ton of water — I try to chug a full Yeti thermos before my morning mint hot cocoa, then keep it going throughout the day. I taper off around dinnertime to minimize, uh, nighttime tinkle stops. Science agrees this does good things for your brain. Brick your phone — I've been using a little Bluetooth device called Brick that hooks into your phone's screen time features so you can block distracting apps on demand or on a schedule. I've got a "Brian Needs Sleepy" timer set for 9 p.m. every night — pretty much everything except the clock app goes dark. Outlook,

  • 7MS #726: Baby's First Hermes

    12/06/2026 Duração: 22min

    Hello friends! I've been on a bit of an AI agent journey lately, and today I'm sharing my experience ditching OpenClaw and going all-in on Hermes — a self-hosted AI agent built by Nous Research. A Network Chuck video sold me on it, I wiped my Mac Mini (again), and baby's first Hermes adventure began! Here's what we get into today: Why I left OpenClaw — After getting the Mac Mini set up, OpenClaw left me feeling pretty meh: burning through API requests, random mid-conversation shutdowns, and a marketplace where the top listings were flagged as "potentially malicious." Hard pass. Network Chuck's five reasons Hermes rocks — His video summarized why Hermes stands out: (1) Nous Research has serious open source model cred predating OpenClaw, (2) more flexible persistent memory via markdown files + optional Honcho integration for building a profile of you over time, (3) a mission around humanistic and democratic AI, (4) a self-improvement loop where it writes its own skills after figuring things out, and (5) it jus

  • 7MS #725: Building a Bulletproof Backup Solution

    05/06/2026 Duração: 21min

    Hey friends! Backups are not as cool as pentesting, but boy do they matter when things go sideways. This week I'm sharing how a Proxmox backup disk space meltdown led me to a completely overhauled — and honestly pretty bulletproof — backup setup for both home and work. Claude played a big role in helping me sort it all out. Here's what we get into: The backup history tour — I've been through CrashPlan, Dropbox, Backblaze (which saved my bacon after my house fire in 2019!), and a mystery one that may or may not have had "Panda" in the name. These days I'm settled on ARQ for personal backups — dead simple, backs up to just about everything (Dropbox, OneDrive, Google Drive, even their own ARQ Cloud for ~$80/year), and all data is encrypted at rest. Not a sponsor, but they should be. The 3-2-1 rule — I actually asked Siri mid-episode, and she initially thought it was a grounding/anxiety technique. (Valid, I guess?) The real answer: three copies, two different media, one offline. I've got a local copy plus On

  • 7MS #724: Tales of Pentest Pwnage - Part 85

    29/05/2026 Duração: 30min

    Hey friends! Today we're going deep on external network pentesting — something I realize we've barely touched in however many episodes we've done. I'm currently in a long stretch of back-to-back external assessments, so it felt like a good time to talk about it. Here's what we get into: Scoping headaches — why the old "count your public IPs and multiply by a big hourly rate" approach drives me crazy, and how we actually scope external tests to be fair to everyone Web apps in scope or not? — this needs its own conversation before the test starts, and skipping it causes pain later Testing under real conditions — the debate around whether to request an allowlist vs. scanning as-is, and why I lean toward creating the best testing environment possible Multi-tool enumeration — why we run Nessus, Project Discovery, and Shodan together, and what each catches that the others miss Reporting the surface — why just walking a customer through what's exposed to the internet (ports, services, screenshots) has more v

  • 7MS #723: CARTP - Cloud Red Team Tactics for Attacking and Defending Azure - Part 1

    23/05/2026 Duração: 32min

    Hello friends! Today's a hybrid episode — some security content up top about a new certification I've kicked off, followed by an aggressively quick trip to Tangent Town. Feel free to bail after the security stuff if tangents aren't your thing! The security part: starting CARTP I've started the Certified Azure Red Team Professional course from Altered Security (enterprisesecurity.io). It's the Azure follow-up to CRTP, which I took a few years back. Quick notes: Why now: Active Directory and internal pentests will always be my first love, but more and more of our customers are shifting to hybrid or full-Azure environments. Time to get some formal training in that lane. Self-paced vs. live: They offer both. I'm past the point of giving up Saturdays to security training, so I went with the ~$500 self-paced 30-day option. You get a portal, a lab manual, and a remote Windows VM with low-priv creds into a target Azure tenancy to attack and enumerate. The catch: The lab manual is thorough on "do this, see this

  • 7MS #722: I Turned My Phone Into a Brick

    15/05/2026 Duração: 23min

    Hey friends! Quasi-vacation week over here, so today's episode is lighter and more personal: just a story about how I turned my phone into a "brick" (kind of) and what that's done for my mental health over the past week. The product is called Brick (getbrick.com). Not sponsored, no discount code — just something I've genuinely been enjoying. It's a $50 NFC dongle + app that lets you "brick" your time-waster apps until you physically tap the brick again. Here's what stood out: The physical separation is the magic. Other digital-wellbeing apps just need a code to unlock — Brick makes you walk to wherever the dongle lives (mine's on the fridge) and tap your phone to it. That extra step is enough to break the habit mid-flight. I caught myself doing three or four Pavlovian pocket checks an hour, on autopilot, with zero notifications waiting. "Junk food for the eyes" realization. First day I bricked socials until end of day → felt great. Then I unbricked, sat down, and spent 25 minutes catching up on everythin

  • 7MS #721: Fun Professional and Personal AI Project Ideas – Part 2

    08/05/2026 Duração: 25min

    Hello friends! Picking up the AI-automation series from a couple weeks back — here's another batch of scripts and integrations that have been giving me precious minutes (and sanity) back. Yes, I had to upgrade to Claude Max. No, I'm not trying to automate myself out of a job — just freeing up bandwidth for the more interesting parts of work/life. QuickBooks invoice automation: Got tired of the eight-factor login plus click-fest just to send a few invoices. Now I run a PowerShell menu — type the client name, pick the project, enter the amount, hit Enter — done in ~30 seconds. The QuickBooks dev onboarding (security questionnaire, IP allowlist) was actually a bigger time sink than the script itself. Password Pusher API integration: A menu-driven PowerShell script that prompts for a label, pops an Explorer window to grab the files, optionally adds a password, then auto-drafts the client email with the secure link filled in. A few minutes saved each time, a couple times a day — adds up to some nice time saved!

  • 7MS #720: Tales of Pentest Pwnage – Part 84

    01/05/2026 Duração: 43min

    Hey friends! Today's another Tales of Pentest Pwnage! Quick tangent first on a couple side projects: I've got a music thing at quack.house (like the duck noise, not the drug) and a podcast with my dancer son Atticus at DadOfADancer.com. Speaking of Atticus — he just landed a spot in Master Ballet Academy's summer program in Phoenix, and I am a very proud dance dad over here. OK, on to the pentest: A weird runas quirk: If your AD test account password ends in a percent sign, runas seems to misbehave (Claude thinks Windows is interpreting the % as a variable delimiter). Workaround: runascs.exe, which wraps your tool launch with creds inline. Worked like a champ — notes over on the 7MinSec.wiki. Standard first pass: PingCastle for the AD overview, then Snaffler for share crawling, with Chimas as a nicer web UI for searching the Snaffler JSON. The "Snaffler missed something" moment: Snaffler is great but it primarily uses pattern matching, so manual review of interesting directories still matters. I found a Powe

  • 7MS #719: Baby's First OpenClaw

    24/04/2026 Duração: 28min

    Hey friends! This week's episode is "Baby's First OpenClaw" – basically me shouting into the void hoping a smart listener will DM me and explain why this thing is supposed to be life-changing. Because right now? I'm a little underwhelmed. Here's the journey so far: The Mac mini quest: After seeing OpenClaw all over my feeds (people curing diseases! solving crimes!), I caved and impulse-bought a Mac mini. They were sold out everywhere, so I ended up paying twice what I wanted. Ick. Surprise MDM: First boot on the shiny new Mac, I found it auto-pre-enrolled in some other company's MDM with full remote control. Massive props to the Amazon seller for getting the serial untagged in Apple's database within an hour, so I could wipe and reinstall fresh. Pro tips for using Claude on projects like this: (1) give it a few paragraphs of context up front about who you are and what you want, and (2) have it maintain a README.md as you go so you don't lose context when you come back to the project later. Security-forward O

  • 7MS #718: Fun Professional and Personal AI Project Ideas

    17/04/2026 Duração: 28min

    Hey friends! After last week's heavy episode about my wife's health scare in Punta Cana, today's is a lighter one. (Quick update: she's doing better – still recovering, but appetite's back and she's got some pep again. Thanks so much to everyone who sent kind messages.) Today I'm gushing about how AI has been making my IT and security life way more efficient: Firewall migration: Had AI walk me through a WatchGuard T15W → T25W migration (no clean config export path). AI captured everything – screenshots, branch office VPN, VLANs, firewall rules, DHCP reservations – all organized and replayed step-by-step. The whole project took ~1 hr 15 min (plus 30 min hunting down a subnet typo that was 100% my fault). GOAD lab automation: Worked with AI to build a script that handles the full lifecycle of my Light Pentest GOAD student lab – tear it down, rebuild from latest, assign Tommy Boy-themed passwords and sync user accounts to the Apache Guacamole and lab connections. Speaking of which – Light Pentest GOAD class w

  • 7MS #717: I Gave Up My Wife's PHI (And I'd Do It Again)

    10/04/2026 Duração: 48min

    Hello friends! Today's episode is a bit of a detour from our usual content — it's part vacation horror story, part security/privacy confession. My wife got seriously ill during our spring break trip to Punta Cana, and in the chaos of navigating a foreign hospital at 2 a.m. with zero sleep and a pile of Spanish medical documents, I threw every privacy best practice I've ever preached straight into the ocean. Here's what we cover: How a dream all-inclusive resort trip turned into an ambulance ride and a 3-day hospital stay faster than you can say "gastroenteritis" Why I uploaded my wife's full medical history, labs, and medication records to AI — unredacted (with no regrets) How AI helped me translate docs, track lab trends, brief stateside nurses, and build a full medication schedule with phone reminders (helpful considering the hospital staff's answer to everything was "sorry, no English") The absolute legend named Luis who got us through Punta Cana airport security in 15 minutes flat Why if you're ever the

  • 7MS #716: Tales of Pentest Pwnage – Part 83

    03/04/2026 Duração: 33min

    Today is my favorite pentest pwnage tale of 2026 – and maybe ever!  It centers around an ADCS abuse via an attack path I'd never seen before.  Tips include: Use Netexec to pull Powershell history Trying to steal reg hives and the EDR is made?  Try copying them out to \\some-other-server.domain.com\share This post featured interesting use of the Responder -N option

  • 7MS #715: Tales of Pentest Pwnage – Part 82

    27/03/2026 Duração: 20min

    Hola friends!  Today's another fun tale of pentest pwnage.  This time we started with no credentials and then set off on the bumpy journey from no-cred zero to domain admin hero!  One specific reference in today's podcast that may be helpful to you is setting up ntlmrelayx to listen on port 3128.

  • 7MS #714: Tales of Pentest Pwnage – Part 81

    20/03/2026 Duração: 22min

    Hello friends!  We're back with a fun tale of internal network pentest pwnage.  This one highlights how AI can be used (with some guardrails!) to automate the boring stuff – and even help you pick part DLLs to find gold nuggets! P.S. – I do recommend you check out our last three episodes that are all about securing your community, and please check out this Rolling Stone article which will give you a full picture of what has been going on in Minnesota as it relates to the occupation of ICE agents.

  • 7MS #713: How to Secure Your Community – Part 3

    13/03/2026 Duração: 31min

    Hello friends, in today's edition of How to Secure Your Community, I give a brief recap of part 1 and part 2, and then dive into some cool phone shortcuts you can setup so that with a single tap, you can alert friends/family that you're having an encounter with law enforcement and may need an assist.  Here's the things/links discussed: This great Rolling Stone article which features interviews and first-hand stories of ICE encounters here in Minnesota Fashlight.org page on security and privacy, which features some cool shortcuts you can setup on iPhone to alert friends/family that you're having a negative encounter with law enforcement (or anyone else) How I allegedly stole somebody's quesadilla while I was at the movie theater seeing Scream 7 The one time my wife had an outburst in the middle of a church service

  • 7MS #712: How to Secure Your Community - Part 2

    06/03/2026 Duração: 37min

    Hello friends.  Today's episode piggybacks off of last week's discussion of Operation Metro Surge and how it has affected the state of Minnesota.  I also highly encourage you to read this Rolling Stone article which features interviews and first-hand stories of ICE encounters.  And for those of you asking for a good org to support here in Minnesota, please support Haven Watch.  They give rides/food to people who are detained by ICE and then cut loose – often without their jackets or phones – into the cold of winter with no ride home. Today I pivot more into the technical weeds and offer some tips on: Securing your Signal app config Hardening your iPhone config via lockdown mode

página 1 de 37