Blue Security

Blue Security

By Andy Jaw & Adam BrewerTechnology
Download on the App Store

Blue Security episodes

  • Secure Authentication to Azure VMs

    This week, Adam and Andy talk about different methods to modernize the way you authenticate to virtual machines located in Azure. The first is using Azure Active Directory and the second is using Azure Bastion. Listen in on how this will help you securely access your virtual machines.

    -------------------------------------------

    Youtube Video Link: https://youtu.be/n25RmcPUI6M

    -------------------------------------------

    Documentation:

    https://techcommunity.microsoft.com/t5/manufacturing/secure-authentication-to-linux-servers-in-azure/ba-p/3484607

    https://docs.microsoft.com/en-us/azure/active-directory/devices/howto-vm-sign-in-azure-ad-linux

    https://docs.microsoft.com/en-us/azure/active-directory/devices/howto-vm-sign-in-azure-ad-windows

    https://docs.microsoft.com/en-us/azure/bastion/bastion-overview

    -------------------------------------------

    Contact Us:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Linkedin: https://www.linkedin.com/company/bluesecpod

    Youtube: https://www.youtube.com/c/BlueSecurityPodcast

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    Twitch: https://www.twitch.tv/bluesecuritypod

    -------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    -------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    16 min
  • Don't Phish Me, Bro

    This week, Adam and Andy talk about OMB procurement requirements changing due to increased cybersecurity defense, Gartner's thoughts on consolidated security platforms, and internal phishing campaigns.

    -------------------------------------------

    Youtube Video Link: https://youtu.be/OZKS03pmk8M

    -------------------------------------------

    Documentation:

    https://www.whitehouse.gov/omb/briefing-room/2022/03/07/omb-statement-on-enhancing-the-security-of-federally-procured-software/

    https://www.gartner.com/doc/reprints?id=1-28F8N1LT&ct=211213&st=sb

    https://twitter.com/swiftonsecurity/status/1534762545524969473?s=21&t=zH3ZUwsZZVDH6ujtVtxTWw

    -------------------------------------------

    Contact Us:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Linkedin: https://www.linkedin.com/company/bluesecpod

    Youtube: https://www.youtube.com/c/BlueSecurityPodcast

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    Twitch: https://www.twitch.tv/bluesecuritypod

    -------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    -------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    29 min
  • Securing Guest Access to M365

    This week, Adam and Andy talk about how to secure guest access and collaboration in Microsoft 365. They talk about the differences between member and guest users and how guest users are created. They also talk about best practices on how to secure access and collaborations in Sharepoint, Teams, and Azure AD. Finally, they end with talking about managing partner relationships and how that can impact access to an organization's tenant.

    -------------------------------------------

    Youtube Video Link: https://youtu.be/PGjipcS6wiA

    -------------------------------------------

    Documentation:

    https://docs.microsoft.com/en-us/microsoft-365/solutions/create-secure-guest-sharing-environment?view=o365-worldwide

    https://docs.microsoft.com/en-us/microsoft-365/solutions/collaborate-with-people-outside-your-organization?view=o365-worldwide

    https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/users-default-permissions#compare-member-and-guest-default-permissions

    https://docs.microsoft.com/en-US/microsoft-365/commerce/manage-partners?WT.mc_id=365AdminCSH_inproduct&view=o365-worldwide

    https://docs.microsoft.com/en-us/azure/lighthouse/overview

    -------------------------------------------

    Contact Us:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Linkedin: https://www.linkedin.com/company/bluesecpod

    Youtube: https://www.youtube.com/c/BlueSecurityPodcast

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    Twitch: https://www.twitch.tv/bluesecuritypod

    -------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    -------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    27 min
  • Windows Defender Exploit Guard

    This week, Adam and Andy talk about Windows Defender Exploit Guard. This is a set of protections built into Windows Server and 10/11 operating systems that provide additional device hardening rules. This conversation was spawned by the current Follina vulnerability (CVE-2022-30190) where an Attack Surface Reduction (ASR) rule can prevent the attack from happening. ASR rules are part of Window Defender Exploit Guard. Dive in to learn all about it!

    -------------------------------------------

    Youtube Video Link: https://youtu.be/ldFWF9GuMZY

    -------------------------------------------

    Documentation:

    https://msrc-blog.microsoft.com/2022/05/30/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/

    https://www.bleepingcomputer.com/news/security/windows-msdt-zero-day-vulnerability-gets-free-unofficial-patch/

    https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/attack-surface-reduction-rules-reference?view=o365-worldwide

    https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/controlled-folders?view=o365-worldwide

    https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/exploit-protection?view=o365-worldwide

    https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/network-protection?view=o365-worldwide

    -------------------------------------------

    Contact Us:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Linkedin: https://www.linkedin.com/company/bluesecpod

    Youtube: https://www.youtube.com/c/BlueSecurityPodcast

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    Twitch: https://www.twitch.tv/bluesecuritypod

    -------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    -------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    22 min
  • Patch Management

    This week, Adam and Andy talk about patch management. This is basic security and some organizations are still struggling with it. They talk about the explosion of zero days and why continuous monitoring of patching is so important. They also go over some policy that you should review as well as why you should switch to Windows Update for Business. Finally, they go over a new feature called Windows Autopatch announced a few weeks ago.

    -------------------------------------------

    Youtube Video Link: https://youtu.be/KM_2OrB1Wy8

    -------------------------------------------

    Documentation:

    https://www.mandiant.com/resources/zero-days-exploited-2021

    https://techcommunity.microsoft.com/t5/windows-it-pro-blog/the-windows-update-policies-you-should-set-and-why/ba-p/3270914

    https://www.anoopcnair.com/windows-update-for-business-wufb-using-intune/

    https://docs.microsoft.com/en-us/windows/deployment/update/waas-configure-wufb

    https://techcommunity.microsoft.com/t5/windows-it-pro-blog/get-current-and-stay-current-with-windows-autopatch/ba-p/3271839

    -------------------------------------------

    Contact Us:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Linkedin: https://www.linkedin.com/company/bluesecpod

    Youtube: https://www.youtube.com/c/BlueSecurityPodcast

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    Twitch: https://www.twitch.tv/bluesecuritypod

    -------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    -------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    34 min
  • Domain Controller Security

    This week, Adam and Andy talk about some updated guidance for securing domain controllers in a world where the cloud is a security imperative. They also review some of the existing guidance and walk through the most important recommendations.

    -------------------------------------------

    Youtube Video Link: https://youtu.be/AlJ1H7Ud4vc

    -------------------------------------------

    Documentation:

    https://techcommunity.microsoft.com/t5/security-compliance-and-identity/updating-best-practices-for-domain-controllers/ba-p/3263043

    https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/securing-domain-controllers-against-attack

    -------------------------------------------

    Contact Us:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Linkedin: https://www.linkedin.com/company/bluesecpod

    Youtube: https://www.youtube.com/c/BlueSecurityPodcast

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    Twitch: https://www.twitch.tv/bluesecuritypod

    -------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    -------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    24 min
  • Cyber Threat Intelligence with Special Guest Charity Wright

    This week, Adam and Andy talk with threat intelligence expert Charity Wright. Charity talks about her military career and how she got selected as a Chinese linguist and worked with the NSA. Charity works for Recorded Future currently and she talks about how threat intelligence can help bolster your cybersecurity program and why it's important to start gathering intel whether it's an internal team, a vendor, or using open source intelligence (OSINT).

    -------------------------------------------

    Youtube Video Link: https://youtu.be/zkAg_mBp7N4

    -------------------------------------------

    Documentation:

    Charity Wright

    Twitter: https://twitter.com/CharityW4CTI

    Linkedin: https://www.linkedin.com/in/cwillhoite/

    -------------------------------------------

    Contact Us:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Linkedin: https://www.linkedin.com/company/bluesecpod

    Youtube: https://www.youtube.com/c/BlueSecurityPodcast

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    Twitch: https://www.twitch.tv/bluesecuritypod

    -------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    -------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    41 min
  • Andy was hacked!

    This week, Adam and Andy talk about passwordless news released on World Password Day and about how Andy was hacked...listen in to hear the details of what happened!

    -------------------------------------------

    Youtube Video Link: https://youtu.be/Go6cb9pU6ng

    -------------------------------------------

    Documentation:

    https://techcommunity.microsoft.com/t5/azure-active-directory-identity/expansion-of-fido-standard-and-new-updates-for-microsoft/ba-p/3290633

    -------------------------------------------

    Contact Us:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Linkedin: https://www.linkedin.com/company/bluesecpod

    Youtube: https://www.youtube.com/c/BlueSecurityPodcast

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    Twitch: https://www.twitch.tv/bluesecuritypod

    -------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    -------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    21 min
  • MFA Bombing

    This week, Adam and Andy talk about MFA bombing. This tricky compromise circumvents MFA. Listen on what it is and how to protect against it.

    -------------------------------------------

    Youtube Video Link: https://youtu.be/EFg-vw824PY

    -------------------------------------------

    Documentation:

    https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-authentication-passwordless-phone

    -------------------------------------------

    Contact Us:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Linkedin: https://www.linkedin.com/company/bluesecpod

    Youtube: https://www.youtube.com/c/BlueSecurityPodcast

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    Twitch: https://www.twitch.tv/bluesecuritypod

    -------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    -------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    21 min
  • Interview with Special Guest Christina Morillo

    This week, Adam and Andy talk with Christina Morillo about identity, diversity in information security, and her book "97 Things Every Information Security Professional Should Know: Collective Wisdom from the Experts." We had so much fun talking and it was a great interview!

    -------------------------------------------

    Documentation:

    Colors of Infosec: https://podcasts.apple.com/us/podcast/colors-of-infosec-podcast/id1531541552

    Book: https://www.amazon.com/Things-Information-Security-Professional-Should/dp/1098101391

    Christina on Twitter: https://twitter.com/divinetechygirl

    https://www.christinamorillo.com/

    -------------------------------------------

    Contact Us:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Linkedin: https://www.linkedin.com/company/bluesecpod

    Youtube: https://www.youtube.com/c/BlueSecurityPodcast

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    Twitch: https://www.twitch.tv/bluesecuritypod

    -------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    -------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    35 min

About Blue Security

From the publisher's feed

A podcast for information security defenders (blue team) on best practices, tools, and implementation for enterprise security.

More shows like Blue Security

Acquired by Ben Gilbert and David Rosenthal

Acquired

4,836 Listeners

Pivot by New York Magazine

Pivot

9,613 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

WSJ Tech News Briefing by The Wall Street Journal

WSJ Tech News Briefing

1,644 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

Risky Business by Risky Business Media

Risky Business

374 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

650 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,027 Listeners

Smashing Security by Graham Cluley

Smashing Security

317 Listeners

Microsoft Cloud IT Pro Podcast by Ben Stegink, Scott Hoag

Microsoft Cloud IT Pro Podcast

65 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

The Azure Security Podcast by Michael Howard, Sarah Young, Gladys Rodriguez and Mark Simos

The Azure Security Podcast

25 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

137 Listeners

Entra.Chat by Merill Fernando

Entra.Chat

6 Listeners