797742806
7 Minute Security

Advertise on podcast: 7 Minute Security

Rating
★★★★★
4.7
from
71 reviews
This podcast has
741 episodes
Language
English
Publisher
Brian Johnson
Explicit
No
Date created
2014/01/15
Latest episode
2026/10/02
Average duration
31 min.
Release period
7 days

Description

7 Minute Security is a weekly information security podcast focusing on penetration testing, blue teaming and building a career in security. The podcast also features in-depth interviews with industry leaders who share their insights, tools, tips and tricks for being a successful security engineer.

Unlock 7 Minute Security podcast Email contact info,
Listeners & Audience details

Email contact information

Direct podcast contact details

Listeners

Audience numbers & engagement insights

Audience details

Podcast Insights

Social media

Check 7 Minute Security social media presence


Podcast episodes

Check latest episodes from 7 Minute Security podcast


7MS #742: Baby's First n8n
2026/10/02
Hey friends! I've got some personal and work travel this week, so I'm skipping the tangents (mostly) and jumping straight into something I'm nerdily excited about: Baby's First n8n. If you're not familiar, n8n is a platform for chaining together and automating just about anything your heart desires – and naturally, my heart desires automating away the boring parts of pentesting. In this episode I cover how I finally got hip to n8n (late to the party, as always), the Black Hills webcast that nudged me into it, how I fed Claude my Frankenstein "Swiss Army" pentest script and asked it to turn push-lots-of-buttons into push-one-button, the clever workaround for firing nmap, EyeWitness, and other tools like it (plus the safety gate I built so my automation can't go rogue and get me in trouble), a full OSINT recon fork powered by Project Discovery Neo that lands report-ready in SysReptor, and the many minutes of my life I get back from each OSINT run – and why that's the whole point. By the way, n8n is not a sponsor or partner – just something I like in case you like it too. Got cool n8n workflows of your own? I'd love to hear 'em!
7MS #741: Tales of Pentest Pwnage - Part 91
2026/09/25
Hey friends! Today's tale of pentest pwnage is brought to you by four hours of sleep, a large mint hot cocoa, and unhealthy levels of giggity. There's a very good reason for all three, but you'll have to hang out to the end of the episode to hear it. First, let's talk about an escalation path I've never walked before: A really tight network is a beautiful and terrible thing — this client went from a C-minus-ish environment in past years to one where I could find basically nothing. No local admin creds laying around, no poisonable protocols, no juicy file shares. Straight into "well, try harder" mode I went. Two new-to-me tools join the arsenal — one that gives you a second opinion on a big pile of pilfered files (Titus), and a one-shot PowerShell command (GPOZaurr) that hands you a report card for everything that's wrong with your GPOs (plus how to fix it). The finding I almost walked right past — an ADCS issue where only a tiny handful of objects could enroll. I said "all right, I'll move on." Then I came back to it, and saw I had missed the (kind of) obvious attack path. A certificate I couldn't authenticate with — and the 0xdf write-up that rescued me from my own gap in knowledge. Machine account quota was set to zero — so of course I tried to add a computer object anyway. Spoiler: it worked like a dirty shirt. The scheduled task trick rides again — my favorite "this is not going to get fixed" Windows behavior. I had a client push back on this one hard: "You had to know the password of the DA you abused, right? You stole the TGT, right?" Nope and nope. How to actually defend against all of this — some ADCS tightening, a checkbox on your high-privilege accounts that a lot of folks don't have ticked, and my new mantra: RDP with purpose. And then it's personal time — my oldest son Cam passed his national paramedic exam, and I am busting my buttons. Stick around for the whole story, including the 4 a.m. potty break that changed everything, the two health care professionals I'd like to hand a party invitation to in person (and why my wife says "I don't know about that, dude").
7MS #740: Tales of Pentest Pwnage - Part 90
2026/09/18
Hey friends! We've been on a bit of a Tales of Pentest Pwnage bender lately, so let's keep it rolling with Part 90. (And Mom, relax — this is not one pentest story chopped into 90 parts.) Today is less of an A-to-Z story and more a pile of tips and tricks pulled from a recent string of SCCM-flavored internals — plus a tangent about a video game and a little robot Claude and I built to get my life back. Multi-tier SCCM is having a moment — I've never administered SCCM a day in my life, but 2026 keeps dropping me into these split-role environments. Here's where I go to figure out my attack surface when all I've got is a low-priv cred. SMB signing on? Cool, I'll go around it — relaying from one SCCM box to the one with SQL on it, and the easy-button tool that vacuums the good stuff out of the database once you're there. (NAA creds, clear-text local admin passwords, install scripts with creds baked in…yes please.) Then relay the other direction — when the loot came back stale, a nudge from a Slack channel had me pointing the relay backwards, and I giggled like a little schoolboy at what popped out. Adding yourself to the local admin group: still weirdly undetected — an old episode of ours reminded me of an Impacket tool I don't see written up on many pentest blogs, and it slipped right by. My favorite cheat code hit a snag — the evil-scheduled-task-under-a-logged-in-DA trick kept coughing up permission errors, so I had to get creative. Plus the defensive recs I'm still trying to sharpen up — if you've got a better way to close this loophole, I'm all ears! Tangent: Halloween (the video game) and the lobby watcher — a million players and I'm still staring into the lobby abyss for 10 minutes at a time. So Claude and I built something that watches the screen and texts me when it's time to sprint back to the keyboard. It's not cheating. It's not! (The Texas Chainsaw crowd disagreed, loudly.)
7MS #739: Tales of Pentest Pwnage – Part 89
2026/09/11
Hey friends! Today is a tale of pentest pwnage episode, and this one features a path to escalation I have never seen before – one I could only find few references on the entire Internet. It happened completely by accident, but during the report readout I'm absolutely going to say it was intentional and that I totally meant to do that. Here's what we cover: A client that's actually doing the things – year two or three of testing this environment, and they had buttoned up so much that I had to dig deep. Great for them, freaking frustrating for me. Why my Kerberoasting success rate has fallen off a cliff – Microsoft pushed an encryption change earlier this year, and cracking those hashes is a whole different ballgame now. Selective poisoning vs. poison-all-the-things – a nod to Pretender, which I covered in a TuesdayTOOLSday video over at 7MinSec.club. It doesn't get nearly enough love in blogs and videos. The relay that fired… and did something completely different than I expected – I saw the ntlmrelayx log scroll by, thought "yes, I've got DA," and then had a "wait, wait, whoa, what?" moment. I was honestly a little panicked. An ancient Exchange vulnerability comes back to bite – CVE-2021-34470 (vulnerable Exchange schema) turned out to be the fallback that got me a foothold I had no business having. My favorite evil privesc trick, revisited – queuing up a scheduled task that runs under an interactively logged-in DA's context without ever knowing their password. The MDR alerts that come out of this are equal parts hilarious and terrifying. A bonus thing to always look for – scheduled tasks running under saved DA creds that point at a script you can edit. Add one little line to fire an evil command of your choice, and you're in like a dirty shirt. Check us out at 7MinSec.com for pentesting, training, controls assessments and security miscellany, 7MinSec.club for our Substack and weekly TuesdayTOOLSday videos, and 7MinSec.wiki for tips, cheat sheets and scripts (including pages on the scheduled task shenanigans above).
7MS #738: Baby's First ProjectDiscovery Neo
2026/09/04
Hey friends! Today I'm talking about Baby's First Neo — and to be crystal clear, I don't mean Keanu, and I don't mean the R&B guy with the hat. I mean the AI-powered pentest assistant from our pals at ProjectDiscovery. Also to be crystal clear: this is not a sponsorship, ad, partnership or anything of the sort. Just me sharing a thing I like so you can decide if you like it too. Here's what we get into: Why I didn't renew my ProjectDiscovery cloud subscription after a full year of running it side-by-side with Nessus — including the three things that ground my gears (one of which had me angry like the Hulk inside) The Palo Alto finding that made me plunk down a credit card and buy PD in the first place What happened when I actually told their team why I was canceling — and the surprise offer that followed How I set up my first Neo project, and the multi-paragraph prompt I fed it (spoiler: "please don't go rogue" was in there) Where Neo beat my manual process — and the two subdomains it found that I flat-out missed The OSINT recommendation Neo made about a job posting that I thought was genuinely smart My one big hesitation about the credit-based pricing model, and why a part two of this series is probably coming soon Then we close out with the tangent portion of the program: Grandma 7MS might be my neighbor soon, she bought a vehicle roughly the size of a small nation, and I'm asking for some good vibes on her house hunt. Also, thank you again to everybody who has sent kind messages since my dad passed — it means more than you know.
7MS #737: Tales of Pentest Pwnage – Part 88
2026/08/28
Hello friends! Today's tale of pentest pwnage isn't a start-to-finish march to DA – it's me finally emptying out the backlog of "gosh, I've got to share this next time" internal network tips that have been rattling around in my head. Here's what we get into: Don't skip the boring stuff. Even when I'm testing the same network for the third or fourth time, I've got an ever-growing list of things I check every single time – because config drift has a nasty habit of quietly reintroducing problems that were fixed years ago. Get a second opinion on your tools. Lately I've had BloodHound tell me a network is squeaky clean, and then gone and checked manually only to find the exact opposite sprawled all over the place. I don't know how to account for it, but it's changed how I work. (If you know the source of truth here, please write in!) Ghost machines. That innocent little checkbox in Active Directory that turns a computer object into a gift-wrapped present for an attacker. We keep finding these in environments that had zero of them last year – and I share the two-pass trick that shakes even more of them loose. The weekend freebie. Why I like to get my box lit up on a Friday even when the test doesn't officially start until Monday, and what tends to come wandering into my capture over 48 quiet hours. SNMP sweeps. I've never been caught doing one, and yet they'll happily hand over the make, model and firmware of some firewalls, switches and storage systems in the building. I think this finding deserves way more attention than it gets. (There are a few little commandlets waiting for you over at 7MinSec.wiki.) Be a consultant, not a Terminator 1000. Why I run certain checks even when I'm 99% sure I'll find nothing, why "you don't have this thing at all" belongs in the accolades section, and how that one habit has led to some of the most appreciated conversations we've had in report delivery meetings. Tangent department: the dumb-but-glorious AI project that gave me the giggidies – a fully automated lobby bot for a Steam game that is absolutely, positively not for the kiddos. Also: the one line I won't cross with it, no matter how much my buddy eggs me on. Got a tip of your own I should be adding to the "always check this" list? I'd love to hear it! 7MinSec.com for security services and show notes | 7MinSec.club for our Substack and weekly TuesdayTOOLSdays | 7MinSec.wiki for pentesting tips, scripts and cheat sheets
7MS #736: Securing Your Family During and After a Disaster – Part 9
2026/08/21
Hey friends! Today's another slice of our Securing Your Family During and After a Disaster miniseries, and fair warning — it's a bit of a Friday mood-ruiner. It's been almost two months since my dad passed, and we've moved into a phase nobody prepared me for. Here's what we get into: The paperwork nobody thinks about — my mom still doesn't know what her monthly income looks like now, and the answer is buried in a box somebody lost the key to. Divvying up a lifetime of stuff — and why our 2019 house fire completely rewired how I think about possessions. Dumpster weekend — my wife makes keep-or-toss calls like a Terminator. Also: my dad owned 60 rakes, and a spirited family debate about the resale value of bee spray. Sell it or pitch it? — why we mostly gave up on Facebook Marketplace mid-cleanout, and my one non-negotiable rule for meeting strangers to hand off your stuff. The conversation I wish we'd had five years ago — it's short, it's simple, and it's absolutely brutal to bring up with your parents. Do it anyway. My hope is this nudges you to have some of these talks now, while everybody's healthy and nobody's crying in a garage. Been through it yourself? I'd love to hear what you'd do differently. And if this is your first time here — we normally talk pentesting, blue teaming, certs and security careers over at 7MinSec.com. Come hang out at 7MinSec.club, our free Substack where TuesdayTOOLSday is getting back to fundamentals, and check out 7MinSec.wiki, where every article is getting paired up with a video. Have a great week, Brian
7MS #735: Baby's First Cloudflare Tunnel
2026/08/14
Hey friends! Today's episode has a new-to-me toy up front and some podcast housekeeping on the back half – all recorded with a raging case of the anxious parent giggidies, because my son Atticus had a big audition and I was minutes away from finding out whether we were doing tears of joy or tears of sadness. Baby's first Cloudflare Tunnel Not a sponsor, not an ad – just a thing I'd heard about for years and finally had a reason to use. Here's what we get into: The problem that sent me down this road: I wanted push-button status pages for clients that pull from one source of truth – not just "is the box up," but actual narrative on where a project is at Why the off-the-shelf status page tools weren't the right shape, and why "just stick it on a web server" was a non-starter for a scraper-and-AI-slop-crawler internet The auth paths I tried and abandoned before Cloudflare Tunnels entered the chat How Cloudflare Access one-time PINs put a guard out front – and what happens when [email protected] tries to log in My Chick-fil-A-order-tracker dreams for multi-phase assessments, and why I think it could kill a bunch of clogged-up email threads Why the code isn't public yet (it's public-facing infrastructure I haven't hardened, and I've got hunches about where the holes are) – but reach out if you want to build something similar and I'm happy to share privately Where tunnels fit generally: when something genuinely needs to be reachable, but you'd rather not hand it a public IP or expose RDP to the whole internet. It doesn't replace Twingate for me, but it fills a different slot nicely Bonus tangent: why Claude has become my long-drive road companion, and five enlightening minutes I spent learning how water towers work Housekeeping: a refreshed jingle and a brand new bumper A quick history of the 7MS jingle – from just me and an acoustic guitar, to a Fiverr band, to now Why "security is hard, so let's assume we're probably going to get pwned by noon" has aged frighteningly well (see also: AI agents teaching each other to find previously unknown vulns) Meet Jacob Davis, the guitar teacher the algorithm dropped in my lap, who recorded a gorgeous all-strings arrangement of the jingle and about 45 seconds of fingerpicking diddly goodness for our new outro bumper. Stick around to the end and give it a listen – and if you're in the market for internet guitar lessons, he rules And over on 7MinSec.club this week I show off VoiceInk, a private, local voice dictation utility for Mac that Paul the Unstoppable turned me on to. Lifetime license, no subscription, and it does a great job on live dictation or audio files you feed it. Catch the TuesdayTOOLSday over at 7MinSec.club Thanks for listening – to the security stuff, the tangents, or both. Come find us at 7MinSec.com, subscribe (free or paid) over at 7MinSec.club, and dig through our notes at 7MinSec.wiki. God bless you, and have a great week!
7MS #734: Insight Recon
2026/08/07
Hey friends! Today's episode is a two-parter: some security stuff up front, and then a big ol' personal celebration on the back half. If you're strictly here for the security bits, I love you and you're free to bail after the first half. If you're here for both, God bless you. Part 1: Kicking the tires on Insight Recon What it is: Insight Recon is an Active Directory security assessment tool out of Heath Adams' new venture, Breach Point. I signed up for early access a while back, finally got a login, and took it for a spin this week in my GOAD lab. Not a sponsor, not an ad — just a tool I was curious about. Watch it in action: I covered the install, a couple of hiccups I hit, and some of the report output in this week's TuesdayTOOLSday video over at 7MinSec.club. The setup: Log into the portal, grab the installer, run it on a domain-joined box, then pick whether you want to scan as your current user or specify creds. Say go, wait a few minutes, and your report card shows up on the dashboard. My two nitpicks (and they're mine, not necessarily yours): The download does a full-blown install with an install footprint, and the raw scan data gets shipped back up to Insight Recon so you can view your report. I can't help but compare everything in this space to PingCastle, where you unzip, run the EXE, and your HTML report is sitting right there on the C drive — nothing leaves the building. As someone who tries to be a good data janitor and nuke assessment data after reports go out, cloud storage is just one more place I've got to remember to go scrub. What I really liked: The remediation guidance is legit. I clicked into a few of the critical findings — some ESC/ADCS stuff especially — and it walked me through exactly what to change, why an attacker cares, how to verify the fix afterward, and where to go read more. There's also a "quick wins" view that pares the big list down to the biggest security impact for the least effort. The dashboard and the slide-out detail panes are genuinely pleasant to use. Why this matters even for offense-only folks: We're mostly on the offensive side with a little blue team consulting — we don't do hands-to-keyboard remediation. But I think you become a better pentester when you can speak confidently at delivery time about not just what to fix, but the gotchas that might bite them along the way. Pricing: On the podcast I guessed "a few thousand a year" and admitted that number may have come straight out of my bum cheeks. Turns out I wasn't too far off — there's a free tier to start, and paid runs $3,000/year with founder pricing at $1,500/year locked in for the first 25 customers. See the pricing page for the current details. Verdict so far: A promising first dance. I want to give it a proper workout — run it side by side with PingCastle on a couple of real assessments and see if either one has blind spots the other covers. More on that in a future episode. Part 2: Why I've got the giggidies My son Cam graduated paramedic school! As of tonight he has everything signed off to go take the gargantuan national test. I'm not going to pretend I got through recording this without getting a little watery-eyed. The journey: Senior year of high school, nothing career-wise floated his boat — there were subjects he tolerated and subjects he hated, and that was about it. Then a conversation with a family friend who's a paramedic lit a fire in his belly, and he's been running at it ever since: EMT coursework in high school, then straight into the paramedic program. How he did it: He wrestles with ADHD, so he had to figure out how to hack his own brain to get through a mountain of material. Come home from five or six hours of class, eat dinner, then hit the books again and re-take his own notes. Then he'd sit down with my wife or me and do an Ace Ventura-style verbal dump of everything he'd learned that day — and any time he caught himself glitching on something, he'd write it down, keep going, then go back and shore it up. Every single night. The Mr. Miyagi moment: My wife has been a nurse for 20+ years, and about six months ago she had to tell him she couldn't help anymore because he'd surpassed her in certain areas of healthcare. Yes, AI made a cameo: The night before his final scenario testing, he and I sat down and had Claude generate random practice scenarios so I could prompt him and just watch him talk for two minutes straight about airway management, medication dosing, all of it. The cliffhanger: Four-ish hours of individual scenario testing, an hour-and-a-half drive to the ceremony, and no word either way on if he passed his tests. I hit the front door of the building not knowing whether I was walking into smiles or tears — and right as my hand hit the door handle, a text came in with a giant happy face: I passed. Somebody must have been cutting onions in that parking lot. His people: Cam's the youngest of the bunch — most of his classmates had been working EMTs for years — and from day one they told him "we got you, we'll get through this together." For the group photo on the steps afterward, one of them tried to pick him up solo and just about threw her back out, so it took three of them. That's the little family he's got, and I hope they stay close, because they've all got that beast of a test coming next month. The hard part: If you've listened to the last few episodes, you know my dad passed away at the end of June, and that Cam was the one who found him and sprung into paramedic mode. My dad was a cop and a pilot who had enormous respect for paramedics, EMTs, and nurses, and he was one of Cam's biggest cheerleaders. Whenever I did something my dad was proud of, he'd say, "I'm busting my buttons over here!" That's exactly what he'd have said tonight, and not having him here to say it is a karate kick to the heart. But I'll tell you what — I'm busting my buttons about Cam for the both of us. Thank you: So many of you have reached out with condolences and shared stories of your own losses these past weeks. I'm sorry for every one of them, and I appreciate you more than I can say. Thanks for listening — to the security stuff, the tangents, or both. Come find us at 7MinSec.com, and/or subscribe (free or paid) over at 7MinSec.club, and dig through the our notes at 7MinSec.wiki.
7MS #733: Tales of Pentest Pwnage – Part 87
2026/07/31
Hey friends! Today's episode comes to you from a parking lot in the rain, with a mint hot cocoa in hand and your host absolutely dragging his butt (D-R-A-G-G-I-N-G, not D-R-A-G-O-N – I've never seen a dragon's butt and can't speak to how mine compares). I've had a bunch of internals back to back lately and I'm basically a drooling dog who found a frisbee and refuses to put it down. Sleep be darned. So instead of walking through one test start to finish, I want to share a few things that have helped me claw out a foothold in environments that are otherwise really locked down: The "good problem" of a mature client – several of these engagements are third- or fourth-year tests, and the clients actually clear findings off the board. Which is great for them and rough for me, because this year's test shouldn't look anything like last year's. All my favorite go-tos came up empty – machine account quota set to zero, no broadcast traffic tomfoolery (Responder and mitm6 got me nothing), SMB signing on everywhere, ADCS either absent or buttoned up, and a low-priv account that BloodHound says has zero interesting permissions and zero local admin anywhere. Cool cool cool. When the network's clean, go file-hunting – which means firing up Snaffler and letting it comb the shares. Normally that wraps up in about an hour. On these engagements it was running three and four hours. Then Windows told me I was out of disk – I like having Snaffler pull down copies of interesting files so I can review them locally instead of authenticating to each share. Turns out it had grabbed 50-60 gigs and left me with about eight gigs of breathing room. Tip #1: put a 1 TB drive in your drop boxes – I ran with tiny drives for years early in the 7MS days and it was always a pinch. Beyond situations like this one, sometimes you find a giant backup file or VMDK on a share and you need somewhere to put it so you can crack it open and go shopping. Tip #2: you can grow a VM disk on the fly – in Proxmox you can resize the disk on a running VM, then hop into Disk Management inside Windows and extend the C drive. Instant elbow room, no downtime. Death by a million tiny files – the real culprit was one file extension I should have excluded, and the client had hundreds of thousands of them. Rather than restart a run I was already hours into, I had AI whip up a little PowerShell loop that swept the Snaffler dump folder every 10 minutes and deleted the extensions I didn't care about. Woke up the next morning to a finished run and plenty of free space. Making a gig-sized log file readable – I fed the log into Chimas, a slick web interface for Snaffler output that lets you filter down to just the red stuff or just the likely-credential files, and sort by modified date. Watch those timestamps – I kept finding AD creds in documents, then comparing the doc's date against the account's last password reset in BloodHound and discovering the file was a year stale. Son of a biscuit. The tool that actually cracked it open: Copernic Desktop Search – my pal Jeff McJunkin recommended this to me years ago, I talked about it on the show once, and then inexplicably forgot about it. Not a sponsor, no kickbacks, just a paid tool that's earned its keep. It's basically Google for your hard drive. How I use it – install it on the Windows VM, clear out the default indexing scope entirely, and point it only at the Snaffler dump folder. The top tier (about a hundred bucks a year) will chew through PSTs, DWGs, Office docs, PDFs and more, and it OCRs images too. Indexing took the better part of a day on these engagements, but then search is instant, and it previews basically every file type without Office installed.  Years ago this same tool surfaced a photo on a file share of a piece of printer paper where a sysadmin had handwritten a 40-character admin password in Bic pen. OCR for the win. What I search for – the obvious stuff like "password," plus the domain name, "plain text," and things like "=sa" to sniff out SQL admin creds. Nuggets and threads to pull – sometimes a hit is the gold. Other times it just tells you where to go dumpster-diving like a raccoon on the live share. That's how I found upgrade project plans with multiple teams and contractors involved, half-cleaned-up temp work, and high-privilege system, database and local admin creds just sitting there. Worth the hours – these didn't all end in domain admin, but they were rich, real findings, and a great teaching opportunity about what's sitting wide open to Domain Users. (Bonus: Copernic can also point straight at a UNC path with your AD creds and index it live.) Know a free alternative? – one of my favorite parts of doing this podcast is when someone writes in with "hey, there's an open source thing that does that." If that's you, I'd love to hear it! Also, on this week's TuesdayTOOLSday I walked through getting a self-hosted Bitwarden password vault (and file sender) up and running on Linux, and there's now a cheat sheet over at 7MinSec.wiki that'll get you there in about seven minutes – all the commands from the official install guide in one place, with a couple of gotchas flagged. Last thing: subscriptions to 7MinSec.club are free, but paid subs help cover hosting and the time this takes each week, and they're getting some exclusive content soon. No guilt trip here, Mom – I'm going to keep barfing up everything I learn either way. But if you've got the means, I'd sure appreciate it.
7MS #732: Tales of Pentest Pwnage – Part 86
2026/07/24
Hey friends! Welcome back to another Tales of Pentest Pwnage — my favorite mini-series where I share the good, the bad, and the "why didn't I check THAT first?!" moments from real-world engagements. Today's story has a little bit of everything: a legit path to domain admin, some late-night rabbit holes, a lesson in humility, and a villain you've definitely met before. (Spoiler: it's DNS.) A couple of quick plugs before we dive in: Private GOAD training is going strong! — We just wrapped a 3-day private session (7 students — that's max capacity!) of our Active Directory pentesting class built on the Game of Active Directory (GOAD) framework. Over three days, students enumerate, attack, and fully pwn three separate AD environments. The private format is just *chef's kiss* — when it's a team from the same company, the conversation gets real fast. Like, "hey I just checked Bloodhound on break and Bob from accounting has full rights over the DC" real. If you want to send 3–7 people from your org, hit up 7MinSec.com/training to line up a private session. Support the show over at 7MinSec.club — That's our Substack, where every Tuesday I drop a short TuesdayTOOLSday video about security tools. Free subscriptions are welcome and mean a lot — you'll just get pinged when new content drops. No spam, no blindly-sent Outlook calendar invites. I promise. Pentest tips and scripts live at 7MinSec.wiki — I reference it throughout today's episode, including some step-by-step guidance on the techniques we'll talk about below. Now — onto the pwnage. Fair warning: I've been burning the candle at three ends lately trying to catch up after a tough few weeks of grief (if you want the backstory, the last couple episodes cover my dad passing away). The good news is my head is semi back on straight and I put it to work on a recurring client environment — one that keeps getting better year over year. Machine account quota locked down? Check. No Kerberoastable or AS-REP roastable users? Check. No local admin rights, no web client running? Check and check. All good signs. And then PingCastle smiled right into my eyeballs with a big red finding: The DC's LAN Manager authentication level was weak enough to coerce and capture a downgraded hash — Specifically, an NTLMv1 SSP hash. Using Coercer to nudge the DC into authenticating to my Kali box (with Responder running), I captured the goods. Pretty little hashes all in a row. Cracking that hash: enter Vast.ai — The old go-to for this type of crack used to be crack.sh, but their cracker has been offline for years. What they do still have is a walkthrough pointing to a tool from EvilMog on GitHub that helps you prep the raw hash material and figure out exactly how to crack it with Hashcat. For the GPU horsepower, I rented a beefy multi-GPU instance on Vast.ai — filter for 16+ GPUs, pick a Hashcat Docker image, and SSH in. The whole crack job took about 16 hours at ~$4/hr. Do the math: $64 to reconstruct the DC's NTLM hash. Worth it. Tmux sidebar — seriously just learn it — Vast.ai is actually what finally got me into tmux, because the Hashcat Docker container drops you right into a tmux session. This is clutch: you can kick off a 16-hour crack job, detach, and reattach later without killing anything. On a pentest, my workflow now is SSH in → tmux → name a few session windows for Responder, Exegol, packet captures, etc. I used to fumble around with Linux screen sessions. Not anymore! From hash to DA — the usual playbook — Once you've got the DC's NTLM hash, you can request a Kerberos ticket and load it up, then run a DCSync to pull the KRBTGT hash. From there it's god mode: dump hashes, pass-the-hash as domain admins, and you have yourself a cool privesc POC. Except this time…the POC didn't work. The part where I Jean-Claude Van Damme helicopter kick myself in the face — DCSync failed immediately. Like, suspiciously fast — barely two lines of output and done. I tried every version of every tool I could get my hands on. I tried Windows, I tried Linux. I even asked the client to check if their endpoint protection was blocking me (it wasn't). I touched grass. I played guitar. I played some Splinter Cell Blacklist (old game, highly recommend if you like the Hitman-style vibes). Came back fresh. Rebooted both VMs. Still nothing. It was DNS. It's always DNS. — The thing that finally caught my eye: the commands were failing too fast. Like it wasn't even reaching the DC. I catted the resolv.conf inside my Exegol instance (heads up: Exegol has its own resolv.conf and hosts file, separate from your base Kali system!) and found a stale DNS entry pointing to an old DC that was no longer serving anything. Nuked the bad entry, added static hosts file entries for the live DC, ran the command again, and — hash rain. Pennies from heaven. It was midnight and I literally pushed back from my desk like a baby pushing away from a high chair going "Baby Brian is all done!" The lesson: — I know the meme. "It's always DNS." I just personally hadn't hit it hard in my security life since my sysadmin days back before 2013. Now I have. So going forward I'll check DNS first (and often). Vacation attempt #3 incoming… pray for me — My wife nearly died in Punta Cana earlier this year. Then our summer cabin trip was cold and rainy with zero water time. And now we've got families flying in from multiple states for a lake weekend — except we just found out our reservation through Booking.com was basically vaporized because the resort changed hands and never updated their website. My wife (who is an absolute saint and my better three-quarters) almost had a 360-degree head spin (like in The Exorcist) talking to customer service. But we scrambled, found a last-minute place, and I'm choosing to believe it's not in Jason Voorhees' back yard. Could this be my last episode? Maybe. But hey — it was a good one. Talk to you next week (hopefully).
7MS #731: CARTP – Cloud Red Team Tactics for Attacking and Defending Azure – THE FINAL CHAPTER!
2026/07/17
Hey friends! Fair warning: today's episode is a bit of an emotional rollercoaster — we've got a big security win, some honest lab feedback, and a very personal share about my dad's funeral. Buckle up. CARTP certified, baby! — I'm officially a Certified Azure Red Team Professional (CARTP), courtesy of the folks at Altered Security. It's been a long time coming (I originally signed up for the live version and fell off after missing a couple Saturdays), but I came back for the self-paced 30-day version and finally finished the job. The lab experience — the good: — ~25 objectives, a solid lab guide, and a really fun variety of attack paths. Highlights include stealing tokens, enumerating Azure tenants, attacking apps and VMs and key vaults, simulated phishing against real tenant email addresses, popping reverse shells, and some clever OneDrive-based follow-on attacks via session hijacking. There's even some web app pen testing (hello, server-side template injection!) sprinkled in. The lab experience — the not-so-good: — The included videos are… not my favorite format. Think notepad-on-screen copy-paste tutorials with zero context. To fill in the gaps, I leaned heavily on Claude — pasting blobs of the lab guide and asking things like "why did stealing this token give me X but not Y?" — and it did a great job standing in where a live instructor would normally add color and context. Exam tips (spoiler-free, I promise): — A few things that helped me: I had Claude build me a CliffsNotes study guide from all our study-session chats — token context, command flags, the works. Before hitting start on the 24-hour clock, I fed Claude a list of all the tools I'd been using in the lab and had it build a one-shot PowerShell script to pull them all down from GitHub onto a fresh Windows VM. If your exam lab environment fails to spin up (as mine did in the US region), just try a different region — UK worked great for me. Enumerate. Enumerate. Enumerate. Know your tools, know which ones cover which areas of an Azure tenancy, and know how to get more verbose/tabular output when you need it. Take screenshots and notes as you go — the lab closes after 24 hours and you've got 48 hours to submit your report, so if you forgot to grab a screenshot of a flag… you are SOL, my friend. The exam itself: — I started around 5:30 p.m., wrapped up around 11 p.m., and had the final flag captured, a full Word report drafted, and was in bed at a reasonable hour. Submitted the report the next morning after the gym and a mint hot cocoa, and had my pass confirmation back well within their 7-business-day window. Private pen test training is happening: — I'm currently running a private 3-day session of our Active Directory pen testing class (version 2.0 — it got a big facelift!). It's built on the Game of Active Directory platform and we fully pwn three separate domains over the course of three days. If you can send 3–7 people, reach out at 7MinSec.com/training to line up a private session. I'm also building an interest list for a public version later this fall (reach out if interested)! Also: check out 7MinSec.club — I dropped a little show-and-tell video over on 7MinSec.club this week giving you a peek at what the training looks like in action. Dad's funeral: — I shared some words at my dad's service this past Saturday and wanted to capture them here while they're fresh, since this podcast is basically my journal at this point. The service was perfect — very "him." He'd actually written funeral instructions (yes, they literally sat in a safety deposit box for years) specifying things like: max 10-minute message from the pastor, specific Bible verses, specific songs, and — my favorite — if the service runs over 45 minutes, someone needs to pull the fire alarm. He came up with that final instruction at his brother's funeral, which ran nearly two hours. He leaned over, squeezed my knee and said, "If my service goes over 45 minutes, pull the fire alarm." The song: — I played and sang at the service. The song was "Jesus Savior Pilot Me" — not a personal favorite of my dad's exactly, but he called it "the one about Jesus flying airplanes" after seeing me perform it years ago at the Minnesota State Fair chapel. I practiced it in the car on the way to Caribou every morning until I could get through it without crying. My guitar teacher's advice: close your eyes, focus on your fingers, and pretend you're just playing a tune in a room. It worked. Mostly. Thank you: — Seriously, so many of you have sent kind messages and I just want you to know it means the world. He taught me a lot about being a good dad, a good husband, and how to live with passion, a good attitude about your work, and a heart for serving others.
7MS #730: Baby's First Project Swarm
2026/07/10
Hey friends! Still your grieving pal over here, but also your swarming friend and Protecting My Network Edge host — because this week I've been tinkering with something called Project Swarm and I've got my diapers on regarding it, but I really, really like what I see so far. Then, fair warning, I flip on the tangent light and verbally barf up some personal stuff at the end. I'll make the hand-off super clear, so if you want your free security podcast to do exactly what you want and nothing else — totally fair, and you won't offend me by hopping off. Here's what we cover: What is Project Swarm? This comes to us from our friends over at GreyNoise. It centers around little sensors you deploy to the edges of your network that you can dress up to look like just about anything — attracting flies to the honey, if you catch my drift. You get more enumeration, insight, and logging into whatever shenanigans those flies are using to poke at your edge. Setup was refreshingly easy: You need a very low-powered VM or hardware device (my understanding is it even works on a Raspberry Pi) mapped to a public IP, plus a free GreyNoise account. You generate an API key, copy-paste a one-line install, and off it goes. I threw mine on a tiny Ubuntu VM. The part where I didn't read the flipping manual: Mid-install my SSH connection dropped and I'm going "what the heck?!" Turns out the installer intentionally moves your real SSH to some arbitrary high port — so you can run a fake SSH honeypot on 22 while your legit connection lives elsewhere. Once I spotted the new port in the console, a quick firewall tweak and I was back in. Profiles give me level 14 giggidies: Once your sensor checks in, you assign it a profile. Vulnerable WordPress, Tomcat, a Cisco AnyConnect VPN, FTP honeypot, SSH honeypot — kind of all the honeypots. I went with a vulnerable WordPress instance. My one complaint: you can only assign one profile per sensor. My dream scenario of an SSH honeypot AND an FTP AND a vulnerable Tomcat all on one box will have to wait (or maybe that'd look too suspicious and scare the baddies off — who knows). The results were wild: Within a couple days I had thousands of connections, several flagged as malicious and tied to known botnets. I could see source IPs, malicious labels, whether they were residential or company or Google, and even download raw packet captures. There's clearly more telemetry to dig into (what people tried to spray into the login portal, etc.) — I meant to go deeper before recording and didn't, so consider this a "to be continued." Why do I care, since I'm not defending some huge infrastructure? Honestly it started as a brain break. But I've been testing a ton of external networks lately and nearly every company site is WordPress — which now powers around 43% of the internet. Running my own WordPress honeypot gives real oomph to those "your out-of-date WordPress is a big deal" conversations, where I can say "I run a WordPress honeypot and here's the aggressive password spraying and plugin/theme enumeration I'm seeing right now." See it, don't just hear it: I show the actual portal, sensor config pages, and more over on 7MinSec.club this week. Why not both, right? It's like that meme. GreyNoise also has a Project Swarm user webinar coming up — check their events page. And to be crystal clear: they are not a sponsor, this is all free, and I just think it's clever. Life update (the tangent portion): About the time you hear this, I'll be on my way to my dad's funeral, where I'm sharing some words and singing a song. I've been practicing like a madman per advice from my music director friend and guitar teacher — including a little brain hack of focusing hard on my fingers to stay a half-step removed from the emotion. And if I cry my face off up there? Who cares. This isn't America's Got Talent; it's the gesture. I'll be honest, 2026 has been a rough one, but I promised two bright spots and here they are: my son Cam (about to finish paramedic school) has been keeping grandpa's spirit alive by wearing my dad's shirts, sunglasses, and Apple watch, and getting a Cessna tattoo with my dad's actual handwriting and birth year. And you all — the kind words, the offers to talk, the shared stories — reminded me there are a whole lot of good people out there. Thank you for that. One more thing on the horizon: My brain's been a squirrel on pixie sticks, but for whatever reason I've been happily grinding the CARTP as a little vacation for my mind. I might take a swing at the exam this week — start it in the evening, grind a few hours, sleep, finish in the morning (I'm too old for 24 hours straight). I might pass, I might fail spectacularly. Either way I'll keep you posted, and if I get the cert, that's probably next week's topic!
7MS #729: Pwning Dracarys
2026/07/04
Hey friends! Still your grieving pal over here, but also your happy hacking host — because today we're diving into baby's first Dracarys! (Yes, I'm probably pronouncing that wrong. Yes, I'm going to keep saying it anyway.) Quick housekeeping: A few days ago I published a mini-series episode from our How to Secure Your Family During and After a Disaster series, where I shared the news that my dad passed away last Friday. So many of you reached out with condolences — thank you from the bottom of my heart. I'll share a little life update at the end of this episode. But first — Dracarys! I didn't know it existed until recently. If you knew about it and didn't tell me, I'm mad at you. But we made up. We're friends forever. Here's what we cover: What is Dracarys? It's a smaller, CTF-style Active Directory pentesting lab from the same crew that brought us Game of Active Directory (GOAD), GOAD-SCCM, GOAD-Light, and Ninja Hacker Academy. Where GOAD holds your hand through the vulnerabilities, Dracarys and Ninja Hacker Academy take more of a "here's your starting point, now figure it out" approach — which I love. The lab setup: One Linux VM, a Windows domain controller, and a Windows application server. Your only hint? Start with the Linux box. That's it. Good luck! TuesdayTOOLSday preview: Over on 7MinSec.club, I did a TuesdayTOOLSday episode walking through initial setup — getting your hosts file configured, running a NetExec sweep to map out the attack surface, and doing some light enumeration on that Linux box. No big spoilers, just enough to get your Kali box ready to rock. What I've learned since: After the TuesdayTOOLSday recording, I kept digging. My methodology has been: nmap to identify open ports and service versions, then research whether any of those versions have known exploits. Once I spotted an interesting web service, AI pointed me toward FeroxBuster for directory and file enumeration — a tool I hadn't used before but am now a huge fan of. It's fast, configurable, and once I got my scan tuned properly… I found a jewel. That jewel feels like the next step deeper into this lab. More on that in future TuesdayTOOLSday episodes! Shameless plug: All of this walkthrough content lives at 7MinSec.club. Subscriptions are free, and subscribing just means you get an email when I publish new content. No spam, no sales pitches — just hacking stuff. (And if you want to financially support the show, there's a paid tier too. Just sayin'.) Life update: We've moved into funeral planning mode. My dad, thankfully, had already mapped out his whole service — the pastor, the verses, everything — which has made things a little easier. We're picking photos for a tribute slideshow and I've been asked to share some words and sing a song. The song I chose is "Jesus, Savior, Pilot Me" — which my dad once described as "that song about Jesus flying airplanes." (He wasn't wrong. Sort of.) I've been practicing it all week and can barely make it through verse two. Prayers, good vibes, and a large supply of Kleenex would be appreciated. Again, you can find the Dracarys lab here. And if you're not already on 7MinSec.club, come hang out — that's where the deeper dives live.
7MS #728: Securing Your Family During and After a Disaster – Part 8
2026/06/30
Hey friends! This is a tough one to write. My dad passed away on Friday, and instead of the hacker-y tech episode I had planned, I pivoted to something more personal — another installment of our "Securing Your Family During and After a Disaster" series. I talk pretty raw and transparently today about loss, grief, and the practical stuff that makes a hard situation just a little less hard. Fair warning: it's about death and dying, so if that's not where your head is today, it's totally okay to duck out – we'll catch you next week. Here's what I cover: My dad's last day — He spent Thursday doing all his favorite things: chainsaws, ATVs, trap-shooting, mowing, and weed-whipping. Then Chinese food with the family and marveling at modern video games for the first time since the Atari 5200. It was, by all accounts, a perfect day for him. How we found out — My son Cameron, who's finishing up paramedic school, was visiting and sprung into EMT mode when my dad was found unresponsive Friday morning. He did CPR for 10 straight minutes — on his grandpa, who was his favorite person in the world. That's the stuff that's going to stay with Cam (and me) for a long time. Getting some closure — Cameron had the presence of mind to ask the paramedics to leave my dad in place so I could have a few minutes with him when we arrived. That was both devastating and, in its own way, healing. Why pre-planning your funeral is a gift to your family — My parents had nearly everything already picked out: the pastor, Bible verses, music, the military honors ceremony, photos for the display board, and even a time limit on service length (45 minutes and no more!). My dad had pre-written his own obituary. When we sat down with the funeral home, the heavy lifting was already done — and that was a genuine gift to all of us in an incredibly hard moment. Storyworth — seriously, do this — Years ago we signed my dad up for Storyworth, a service that sends your loved one a weekly question via email (things like "What's your earliest childhood memory?" or "Do you have any regrets?") and compiles their answers into a hardcover book. It runs about $100. Reading that book the last few nights has been incredibly comforting — including finding out my dad started smoking at age 8 using used cigarette butts rolled in toilet paper. Gross! Get your end-of-life wishes in writing — My wife's mom had verbally told us she wanted to be cremated, but it wasn't documented, and other family members made a different call. My dad put "cremation" right in his paperwork, no ambiguity. My recommendation: have this conversation with your loved ones, write their wishes down and make them official. Funeral home "upsell" moment — I had no idea there were apparently 627 ways to incorporate your loved one's remains into keepsakes — pendants, rings, necklaces with fingerprints, biodegradable urns for water scattering, etc. Some family members were very into this. I was not quite ready to turn my dad into an Atari cartridge, but your mileage may vary. On grief itself — Everybody handles it differently, at different speeds and intensities. My approach is to head straight into it rather than put on a happy face and deal with unprocessed grief years later. I encourage everyone — especially the kids — to not hold back. Ask the questions. Tell the stories. Cry if you need to. Give each other grace. Coming up next week — Back to pentesting content! I'll share details on a new lab from the folks who brought us Game of Active Directory, and I'm getting back on the CARTP (Certified Azure Red Team Professional) horse. I'm also tentatively eyeing the third Thursday of July for an unedited livestream of owning Ninja Hacker Academy from start to finish — Kali setup, tools, Mythic C2, BallisKit obfuscation, the whole thing. More details to come. If you're the thoughts, prayers, and/or good vibes type, I'd really appreciate you sending some my family's way over the next few weeks.

Podcast reviews

Read 7 Minute Security podcast reviews


4.7 out of 5
71 reviews
★☆☆☆☆
TooIllOrEase 2023/06/30
Get to the point
Strange how many podcasts assume listeners already love them and are dying to hear drivel-riffing. No, don't love; found via search for specific topic...
★★★★★
mvelasco07 2023/03/01
Highly recommend!
Can’t thank Brian and the 7MS team enough for putting out such an incredible podcast. Engaging conversations, actionable tips, and insights into the c...
★☆☆☆☆
CyberSecPodFan 2021/05/01
Some gems, getting rare though
A while ago this podcast was a must listen, but now between all the ad sponsored interviews and news summaries it isn’t on my list anymore. The news e...
★☆☆☆☆
Choppers17 2020/12/28
Become too political
I persisted through all the quirkiness of the podcast but Brian has recently saw fit to become political on his podcast. Not what I came here for. Bye...
★★★☆☆
[REDACTED] USER 2020/05/18
Good podcasts
The podcaster has too many pauses and doesn’t keep the momentum up when telling the story, reviews, etc. it’s like listening to someone telling a stor...
★★★★★
Nebblkshts 2019/05/11
Awesome
I thought I knew a few things about being a windows admin until Brian showed me a new world. I was board with where I was now I want to move into secu...
★★★★★
Infinity dreamer 90 2019/02/20
Great small bits of security
Thanks for sharing your security secrets!
★★★★★
jevde 2018/08/02
Definitely a great listen!
This is very straight forward and to the point podcast I ever listen on the Cyber Security. Very informative covering all aspects of Cyber Security.
★★★★★
Spencer-Thank you listeners 2018/06/10
Down to earth - value based podcast
This podcaster is really down to earth and relatable. He sounds super sharp about what he’s talking about and I always end up learning something every...
★★★★★
Caneron Johnson 2018/05/06
Brian Johnson
Hey this is Cameron Luis Fronodo Johnson and I’m your son bye Dad love you!! 👋
check all reviews on apple podcasts

Podcast sponsorship advertising

Start advertising on 7 Minute Security relevant audience podcasts


What do you want to promote?