Info
This is a periodic audio podcast discussing current events and trends in Information and Cyber Security. Hallway con with a topic!
Episodes & Posts
Episodes
Posts
26 APR 2018 · Killing the Pen Test & BSides Knoxville (with Adrian Sanabria)
Advanced Persistent Security Podcast
Episode 44
Guests: Adrian Sanabria
April 26, 2018
If you enjoy this podcast, be sure to give us a 5 Star Review and "Love Us" on iTunes; Like us on Google Play, Stitcher, Sound Cloud, Spreaker, and YouTube.
NOTE: The opinions expressed in this podcast are ours alone and do not reflect those of our employers
Killing the Pen Test & BSides Knoxville (with Adrian Sanabria)
Show Notes
In this episode, Joe is joined by Adrian Sanabria. Adrian is a co-organizer of BSides Knoxville and one of the founders of dc865. We discuss Adrian's background in technology and how he came into security in the days before PCI. Adrian talks about his transition into working at 451 Research in terms of terminology and industry analysis.
Joe and Adrian talk about Savage Security and RSA Conference. Adrian tells us about his (then forthcoming) presentation at RSA Conference. Adrian's presentation is called It is Time to Kill the Pen Test and why it is important. He cites Haroon Meer's Keynote at 44con in 2011 as a thought provoking idea that spawned this.
Pen testing as a skill is not the problem, it is the service offering that is. Adrian cites inefficiencies like vulnerability scanning and reporting at the same rate as the test. We talk about the advanced attacks versus sticking to the basics. Adrian talks about prioritizing breach simulations and ransomware simulations over a pen test.
We talk about the scoping documents of pen tests and how they are relative to actual attacks and their objectives. The fact that not all adversaries attempt to get domain admin, while others try to perform defacement or exfiltration. Adrian mentions Haroon's quote:
Pen testers are not emulating attackers. They are emulating other pen testers.
Adrian talks about the lack of responsiveness of blue teams during pen tests. We talk about the mentality of many attackers of wanting to "pwn the world" vice enhance the security of an organization. Adrian calls for more "white box testing." Joe mentions the lack of analysis of OSINT as another inefficiency in pen testing. We also discuss the fact that dwell time is so high that expecting a black box test is almost unrealistic.
Adrian talks about some metrics associated with MSSPs detecting him when doing breach simulations. We talk about C2 and other indicators such as the use of TOR. We talk about how to make the industry better.
About Adrian:
12 APR 2018 · Infosec Thoughts (with Jayson E. Street & Tracy Maleeff)
Advanced Persistent Security Podcast
Episode 42
Guests: Jayson E. Street and Tracy "Infosec Sherpa" Maleeff
April 12, 2018
If you enjoy this podcast, be sure to give us a 5 Star Review and "Love Us" on iTunes; Like us on Google Play, Stitcher, Sound Cloud, Spreaker, and YouTube.
NOTE: The opinions expressed in this podcast are ours alone and do not reflect those of our employers
Infosec Thoughts (with Jayson E. Street & Tracy Maleeff)
Show Notes
Segment 1
In this episode, Tracy and Joe introduce Jayson E. Street. Tracy mentions Jayson's talk about failing from Tactical Edge conference. Joe and Tracy agree that people in infosec do not talk enough about their failures. Jayson talks about how to break into infosec. He shares how he would survey his defenses as a security guard (30 years ago) from the lens of someone who would be breaking in.
Bad Guys will break in just like a red teamer, but they won't give you a report to mitigate it.
Brian Krebs should not be your IDS.
Joe hits Jayson with a trick question about which language one should learn to break into infosec. Jayson passes the test with the answer of "English." We continue down the rabbit hole of effective communications with regards to buzzwords and speaking the language of the audience. We talk about the use of the word "cyber" in the sense of cybersecurity in lieu of information security when speaking to the businesses.
Segment 2
Tracy asks Jayson how to approach talking to non-technical, non-security people about the umbrella of information security relative to explaining the various types of security disciplines and the differences in each. Jayson levels with us with regards to the culture of information security based on his travels across the world. Jayson tells us how he would collect information about a company using OSINT to phish the company or gain unauthorized access. He encourages listeners to go out and speak to non-security groups to raise awareness across other verticals.
kittenwar.com
About Jayson
5 APR 2018 · Security of Mainframes (with Cheryl Biswas & Tracy Maleeff)
Advanced Persistent Security Podcast
Episode 41
Guests: Cheryl Biswas and Tracy "Infosec Sherpa" Maleeff
April 5, 2018
If you enjoy this podcast, be sure to give us a 5 Star Review and "Love Us" on iTunes; Like us on Google Play, Stitcher, Sound Cloud, Spreaker, and YouTube.
NOTE: The opinions expressed in this podcast are ours alone and do not reflect those of our employers
Security of Mainframes (with Cheryl Biswas & Tracy Maleeff)
Show Notes
Segment 1
In this episode, Tracy and Joe interview Cheryl Biswas. We introduce Cheryl and she shares what she is seeing in industry from the mainframes and Industrial Control Systems (ICS) perspectives. Cheryl discusses her habits of reading all night and the passion that we all share for security. We share our origin stories. Joe showcases his authentic southern accent. Joe talks about the Navy's mentorship mentality and how he applies it to security mentoring (what eventually will have gone onto become Through The Hacking Glass).
For "current events," we discuss Vault 7. Joe details his "Workplace Crossfit" and "Workplace Yoga" programs in jest. Cheryl shares her insight as a Canadian regarding how the US Intelligence Community operates.
Segment 2
Cheryl begins to discuss the financial sector and how ransomware impacts it. Cheryl shouts out to Soldier of Fortran (@mainframed767) and Big Endian Smalls (@bigendiansmalls). Cheryl talks about the ability to access mainframes from the internet and the relation to another Stuxnet.
Examples as to how Nation States could exploit and disrupt operations using mainframes are explained. For the sake of entry level listeners, Cheryl explains the difference between servers and a mainframes. We get an education about the operating systems of mainframes – Z/OS and how it relates to commercial software like UNIX and Java. To learn about mainframes, Cheryl recommends we check out her blog, Cyber Watch/White Hat Cheryl, Big Endian Smalls' Mainframe Security, and Soldier of Fortran's Mainframe Hacking.
Cheryl talks about ransomware and how it is impacting banks. She talks about fileless ransomware and (the lack of) awareness programs. Joe gets on the user training soapbox regarding the lack of commitment. We agree that it will get worse before it gets better. Joe and Cheryl talk about virtualizing mainframes using Hercules. Joe attempts to sing a Cher cover regarding mainframes, TERRIBLY.
Â
ABOUT Cheryl
30 MAR 2018 · OSINT Techniques (with Michael Bazzell)
Advanced Persistent Security Podcast
Episode 40
Guest:Michael Bazzell
March 30, 2018
If you enjoy this podcast, be sure to give us a 5 Star Review and "Love Us" on iTunes; Like us on Google Play, Stitcher, Sound Cloud, Spreaker, and YouTube.
NOTE: The opinions expressed in this podcast are ours alone and do not reflect those of our employers
OSINT Techniques (with Michael Bazzell)
Show Notes
In this episode, we introduce Caroline Stephens as a new co-host. Our guest, Michael Bazzell discusses his background in OSINT; how he got into OSINT and why he wrote his first book as well as his new book Open Source Intelligence Techniques (6th Edition). Michael talks about what has changed in OSINT since 2001 in terms of collecting everything then versus filtering as much as possible now. We discuss automating OSINT and Buscador Linux. We go over a few tools that we like to use – Recon-ng, Datasploit, and Buscador. Maltego came up and we discuss our use and reservations of usage.
On the topic of Buscador, Michael discusses how it came about, his collaboration with David Wescott, and the need for a linux based OSINT virtual machine. Joe and Michael discuss the ethical requirements and implications of collecting and usage of data gathered using OSINT techniques. Michael talks about his commitment to OPSEC (Operations Security) when working on OSINT investigations.
We talk about proactive OSINT and Privacy; the offense and defense. Facebook Live is discussed. Michael and Joe also talk about spoofing location information and the impact of using a VPN on a cell phone. The usage of Michael's tools for law enforcement and the media is discussed. Michael tells us about his experience working on Mr. Robot.
ABOUT Michael
This is a periodic audio podcast discussing current events and trends in Information and Cyber Security. Hallway con with a topic!
Information
| Author | Advanced Persistent Security |
| Organization | Advanced Persistent Security |
| Categories | Society & Culture |
| Website | - |
| - |
Copyright 2026 - Spreaker Inc. an iHeartMedia Company