Blue Security

Blue Security

By Andy Jaw & Adam BrewerTechnology
Download on the App Store

Blue Security episodes

  • Tabletop Scenarios with Special Guests Nate Gardner and Gavin Ashton

    This week's episode, Adam and Andy have a great time chatting with fellow cybersecurity professionals Nate Gardner and Gavin Ashton walking through tabletop scenarios. This is something security defenders should do to test their incident response plan.

    -------------------------------------------

    Youtube Video Link: https://youtu.be/kwxSCd40gWQ

    -------------------------------------------

    Documentation:

    Nate Gardner:

    https://www.linkedin.com/in/nate-gardner-infosec/

    Gavin Ashton: 

    https://twitter.com/gvnshtn

    https://www.linkedin.com/in/gvnshtn/

    -------------------------------------------

    Contact Us:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    Twitch: https://www.twitch.tv/bluesecuritypod

    -------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    -------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    47 min
  • News Smash

    This week's episode, Adam and Andy talk catch up on some infosec news including BadUSB, President Biden's memorandum for National Security Systems, iOS/MacOS vulnerablities, and new hardware with Microsoft's Pluton Security Processor.

    -------------------------------------------

    Youtube Video Link: https://youtu.be/yQebJcb2j3E

    -------------------------------------------

    Documentation:

    https://www.darkreading.com/vulnerabilities-threats/more-security-flaws-found-in-apple-s-OS-technologies

    https://www.whitehouse.gov/briefing-room/presidential-actions/2022/01/19/memorandum-on-improving-the-cybersecurity-of-national-security-department-of-defense-and-intelligence-community-systems/

    https://www.csoonline.com/article/3647173/badusb-explained-how-rogue-usbs-threaten-your-organization.html#tk.rss_all

    https://www.bleepingcomputer.com/news/microsoft/microsoft-disables-excel-40-macros-by-default-to-block-malware/

    https://www.csoonline.com/article/3647170/microsofts-pluton-security-processor-tackles-hardware-firmware-vulnerabilities.html#tk.rss_all

    -------------------------------------------

    Contact Us:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    Twitch: https://www.twitch.tv/bluesecuritypod

    -------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    -------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    34 min
  • Windows Device Management with Special Guest Shannon Fritz

    This week's episode, Adam and Andy talk with special guest Shannon Fritz on Windows Device Management. If you haven't listened to Shannon's episode on Device Identity, we encourage you to listen to it! Following up the conversation on device identity, Shannon talks all about managing devices using co-management and how device identity is related to management but mainly where the device lives does not affect how it is managed. Listen in on what it means to co-manage your Windows devices!

    -------------------------------------------

    Youtube Video Link: https://youtu.be/LtkPvqLvG9Y

    -------------------------------------------

    Documentation:

    Windows 10 Device Management vs Device Identity

    https://mrshannon.wordpress.com/2020/06/24/windows-10-device-management-vs-device-identity/

    https://anchor.fm/blue-security-podcast/episodes/Say-Goodbye-to-Domain-Join-with-Special-Guest-Shannon-Fritz-erudur

    Shannon Fritz: https://twitter.com/mrshannonfritz

    -------------------------------------------

    Contact Us:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    Twitch: https://www.twitch.tv/bluesecuritypod

    -------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    -------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    1 hr
  • F12 and Find Out

    This week's episode, Adam and Andy talk about the importance of the nomenclature we use in information security. They also talk about the perception of information security to those who are not in the field and how that can affect safety when it comes to red teaming.

    -------------------------------------------

    Youtube Video Link: https://youtu.be/nMQC5D_P4qY

    -------------------------------------------

    Documentation:

    https://techcrunch.com/2021/10/15/f12-isnt-hacking-missouri-governor-threatens-to-prosecute-local-journalist-for-finding-exposed-state-data/

    https://boingboing.net/2021/12/30/reporter-likely-to-be-charged-for-using-view-source-feature-on-web-browser.html

    https://arstechnica.com/information-technology/2019/09/iowa-officials-claim-confusion-over-scope-led-to-arrest-of-pen-testers/

    https://abcnews.go.com/US/wireStory/charges-dropped-men-broke-iowa-courthouses-68651855

    https://www.darkreading.com/edge-articles/why-red-teaming-while-black-can-be-risky

    -------------------------------------------

    Contact Us:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    Twitch: https://www.twitch.tv/bluesecuritypod

    -------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    -------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    24 min
  • Digital Asset Management

    This week's episode, Adam and Andy talk about a fundamental important program for security defenders: asset management. It may not be the most exciting aspect of security but knowing what you have makes it a lot easier to protect and response to attacks.

    -------------------------------------------

    Youtube Video Link: https://youtu.be/Kui8x_lCYOk

    -------------------------------------------

    Documentation:

    https://danielmiessler.com/blog/continuous-asset-management-security/

    https://www.darkreading.com/vulnerabilities-threats/log4j-reveals-cybersecurity-s-dirty-little-secret

    -------------------------------------------

    Contact Us:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    Twitch: https://www.twitch.tv/bluesecuritypod

    -------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    -------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    25 min
  • A look back on 2021

    This week's episode, Adam and Andy give an update on Log4j/Log4Shell insights from the Google Security Team. They also look back on some of the vulnerabilities and cyberattacks from 2021 and discuss what's to come in 2022 for defenders.

    -------------------------------------------

    Youtube Video Link: https://youtu.be/3XLwP8GFS3M

    -------------------------------------------

    Documentation:

    https://security.googleblog.com/

    https://www.av-comparatives.org/tests/business-security-test-2021-august-november/#management-summary

    https://news.microsoft.com/on-the-issues/tools-and-weapons/

    -------------------------------------------

    Contact Us:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    Twitch: https://www.twitch.tv/bluesecuritypod

    -------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    -------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    31 min
  • Work Life Balance

    This week's episode, Adam and Andy talk all about a healthy work life balance. With the pandemic still on-going and working from home or hybrid work environments looking like they are not going away, it's time to re-evaluate your boundaries and enforce them. Listen on what's worked for Adam and Andy as they put their mental health ahead of the hustle culture.

    -------------------------------------------

    Youtube Video Link: https://youtu.be/lK147aYqt4k

    -------------------------------------------

    Documentation:

    https://hbr.org/2021/12/hybrid-tanked-work-life-balance-heres-how-microsoft-is-trying-to-fix-it

    -------------------------------------------

    Contact Us:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    Twitch: https://www.twitch.tv/bluesecuritypod

    -------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    -------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    38 min
  • Threat and Vulnerability Management

    This week, Adam and Andy talk all about how to start and run a threat  and vulnerability program at your company. From asset management,  scanning, remediation, and validation, they go over what is involved and how to orchestrate the effort cross-function to avoid down time. A TVM program is a key pillar of your defense so if you do not have one or want to improve your current one, listen in!

    -------------------------------------------

    Youtube Video Link: https://youtu.be/qTvtvfY3CaQ

    -------------------------------------------

    Documentation:

    https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/network-devices?view=o365-worldwide

    https://www.tenable.com/products/nessus

    https://www.qualys.com/

    -------------------------------------------

    Contact Us:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    Twitch: https://www.twitch.tv/bluesecuritypod

    -------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    -------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    30 min
  • Log4Shell

    This week, Adam and Andy talk all about the Log4Shell vulnerability affecting the log4j Java library. They give an overview on how it works and how you as a security defender can secure your environment against it.

    -------------------------------------------

    Youtube Video Link: https://youtu.be/D9KBcIHOQzI

    -------------------------------------------

    Documentation:

    https://gist.github.com/SwitHak/b66db3a06c2955a9cb71a8718970c592

    https://github.com/Neo23x0/log4shell-detector

    https://twitter.com/shehackspurple/status/1469742868952584194

    -------------------------------------------

    Contact Us:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    Twitch: https://www.twitch.tv/bluesecuritypod

    -------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    -------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    35 min
  • Security Champions

    This week, Adam and Andy talk about a security champions program. This is a way to bolster the security culture and develop representatives in each business group to understand security initiatives and evangelize them for you at your company. It's also a way to have a inner ring of testers and even possible a talent pipeline. There's a lot to discuss so listen in!

    -------------------------------------------

    Youtube Video Link: https://youtu.be/sbnppJR-eMo

    -------------------------------------------

    Documentation:

    https://www.darkreading.com/careers-and-people/how-to-implement-a-security-champions-program

    -------------------------------------------

    Contact Us:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    Twitch: https://www.twitch.tv/bluesecuritypod

    -------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    -------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    22 min

About Blue Security

From the publisher's feed

A podcast for information security defenders (blue team) on best practices, tools, and implementation for enterprise security.

More shows like Blue Security

Acquired by Ben Gilbert and David Rosenthal

Acquired

4,836 Listeners

Pivot by New York Magazine

Pivot

9,613 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

WSJ Tech News Briefing by The Wall Street Journal

WSJ Tech News Briefing

1,644 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

Risky Business by Risky Business Media

Risky Business

374 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

650 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,027 Listeners

Smashing Security by Graham Cluley

Smashing Security

317 Listeners

Microsoft Cloud IT Pro Podcast by Ben Stegink, Scott Hoag

Microsoft Cloud IT Pro Podcast

65 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

The Azure Security Podcast by Michael Howard, Sarah Young, Gladys Rodriguez and Mark Simos

The Azure Security Podcast

25 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

137 Listeners

Entra.Chat by Merill Fernando

Entra.Chat

6 Listeners