Blue Security

Blue Security

By Andy Jaw & Adam BrewerTechnology
Download on the App Store

Blue Security episodes

  • Cloud Application Security Brokers

    This week, Adam and Andy talk about cloud application security brokers (CASB). The podcast is focused more around Microsoft Cloud App Security but the concepts and use cases can be applied to any CASB solution.

    ----------------------------------------------

    Youtube Video Link: https://youtu.be/j43MFpxMsqE

    ----------------------------------------------

    Documentation

    MCAS Ninja Training:

    https://techcommunity.microsoft.com/t5/microsoft-security-and/the-microsoft-cloud-app-security-mcas-ninja-training-is-here/ba-p/1877343

    ----------------------------------------------

    Contact: Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    ----------------------------------------------

    Andy Jaw Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    ----------------------------------------------

    Adam Brewer Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    41 min
  • Password Managers

    This week, Adam and Andy talk about password managers. They discuss on password managers can protect you from phishing attacks, pros/cons of storing your TOTP key within your vault, and compare three different popular password managers on the market: Lastpass, 1Password, and BitWarden.

    ----------------------------------------------

    Youtube Video Link: https://youtu.be/op9TGKlRZDY

    ----------------------------------------------

    Documentation

    https://blog.1password.com/totp-and-1password/

    https://gmail.googleblog.com/2008/03/2-hidden-ways-to-get-more-from-your.html

    https://www.ghacks.net/2013/09/17/can-now-use-email-aliases-outlook-com/

    ----------------------------------------------

    Contact: Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    ----------------------------------------------

    Andy Jaw Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    ----------------------------------------------

    Adam Brewer Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    41 min
  • What is EvilGinx and How do you protect against it?

    This week, Adam and Andy talk about a Red Team/Pentesting tool called EvilGinx. They explain how this tool works and how cyber-criminals can use it to bypass MFA enabled accounts. Most importantly, they provide several ways to mitigate against this using enterprise driven phishing education campaigns, security awareness training, and device-based conditional access.

    ----------------------------------------------
    Youtube Video Link:
    https://youtu.be/a2NLk0GnUJ8
    ----------------------------------------------
    Contact:
    Website: http://bluesecuritypod.com
    Twitter: https://twitter.com/bluesecuritypod
    Instagram: https://www.instagram.com/bluesecuritypodcast/
    Facebook: https://www.facebook.com/bluesecpod
    ----------------------------------------------
    Andy Jaw
    Twitter: https://twitter.com/ajawzero
    LinkedIn: https://www.linkedin.com/in/andyjaw/
    ----------------------------------------------
    Adam Brewer
    Twitter: https://twitter.com/ajbrewer
    LinkedIn: https://www.linkedin.com/in/adamjbrewer/
    42 min
  • Modern Device Management

    This week, Adam and Andy go over modern device management. They discuss how to use device based conditional access to make access decisions on corporate or personal devices spanning different operating systems in the modern "work from home" and post-COVID world.

    ----------------------------------------------

    YouTube Video Link:

    https://youtu.be/s46ZhXnngjg

    ----------------------------------------------

    Documentation:

    Windows Autopilot

    https://docs.microsoft.com/en-us/mem/autopilot/windows-autopilot

    Apple Business Manager

    https://support.apple.com/guide/apple-business-manager/what-is-apple-business-manager-apdd344cdd9d/web

    Android Enterprise Enrollment

    https://www.android.com/enterprise/enrollment/

    Android Device Manager Deprecation

    https://www.blog.google/products/android-enterprise/da-migration/

    JAMF Apple Device Management

    https://www.jamf.com

    ----------------------------------------------

    Contact:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    ----------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/ 

    ----------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    45 min
  • Real-world Ransomware Experience with Special Guest Gavin Ashton

    This week, Adam and Andy speak with Stealthbits security strategist, Gavin Aston. Gavin wrote the blog "Maersk, me & notPetya" and brings a unique percepective to information security defense as someone who's survived a ransomware attack.

    Youtube Video Link

    Documentation:

    Maersk, me & notPetya

    Protecting Microsoft 365 from on-premises attacks

    Contact:

    Gavin Aston

    Twitter: @gvnshtn

    Andy Jaw

    Twitter: @ajawzero

    LinkedIn: andyjaw

    Adam Brewer

    Twitter: @ajbrewer

    LinkedIn: adambrewer

    ----------------------------------------------

    Twitter: @bluesecuritypod

    Instagram: @bluesecuritypodcast

    Facebook: @bluesecpod

    41 min
  • Application Security with Special Guest Tanya Janca

    This week, Adam and Andy speak with application security guru, Tanya Janca, author of Alice and Bob learn Application Security. It was an amazing conversation where they touched on secure app design practices, password requirements, and infosec industry mentorship and education.

    Youtube Video Link

    Documentation:

    Alice and Bob learn Application Security

    We Hack Purple Academy

    We Hack Purple Youtube/Podcast

    Contact:

    Tanya Janca

    Twitter: @shehackspurple

    LinkedIn: tanya-janca

    Andy Jaw

    Twitter: @ajawzero

    LinkedIn: andyjaw

    Adam Brewer

    Twitter: @ajbrewer

    LinkedIn: adambrewer

    ----------------------------------------------

    Twitter: @bluesecuritypod

    Instagram: @bluesecuritypodcast

    Facebook: @bluesecpod

    1 hr
  • Secure Messaging

    This week, Adam and Andy go over some news about Microsoft Defender for Identity and Intel's new CPU ransomware protection. There was also some news about Whatsapp's new privacy policy. Adam and Andy dive into a comparison of the most popular secure messaging apps including an exploit that would affect all secure messengers.

    Documentation:

    Whatsapp's Updated Privacy Policy

    Signal Messenger

    Threem Messenger

    Secure Messaging Apps Comparison

    Contact:

    Twitter: @bluesecuritypod

    Instagram: @bluesecuritypodcast

    Andy Jaw

    Twitter: @ajawzero

    LinkedIn: andyjaw

    Adam Brewer

    Twitter: @ajbrewer

    LinkedIn: adambrewer

    38 min
  • Solarwinds Revisited and Tech Policy under a Biden Administration

    This week, Adam and Andy revisit some more guidance that has come out about Sunburst/Solarigate since the initial breach. Additionally, they share some thoughts about this week's insurrection at the US Capitol and the cybersecurity implications. Finally, with a Biden administration and a Democratic controlled government, Andy and Adam speculate on what might be taken up as priority when it comes to tech policy.

    Documentation:

    Microsoft Solarigate Resource Center

    Using Splunk to Detect Sunburst Backdoor

    Analyzing Solorigate, the compromised DLL file  that started a sophisticated cyberattack, and how Microsoft Defender helps protect customers

    Using Microsoft 365 Defender to protect against Solorigate

    M365 advanced hunting queries

    Understanding "Solorigate"'s Identity IOCs - for Identity Vendors and their customers

    Protecting Microsoft 365 from on-premises attacks

    Contact:

    Twitter: @bluesecuritypod

    Instagram: @bluesecuritypodcast

    Andy Jaw

    Twitter: @ajawzero

    LinkedIn: andyjaw

    Adam Brewer

    Twitter: @ajbrewer

    LinkedIn: adambrewer

    36 min
  • Information Security Tips & Tricks for Parents

    Happy New Year! To ring in the new year, this week's episode focuses on parents who are working from home while having to help home school their kids as well. Adam and Andy go through a lot of tips and tricks that will help secure home networks, devices, and cloud accounts.

    Documentation:

    Setup OpenDNS

    Quad9

    Disney Circle

    Eero Wifi

    How to change your wireless router's admin password

    3-router method (Stacking routers for security)

    Ubiquiti Unifi

    Apple's Data Access when personal safety is at risk

    Microsoft Families

    Apple Families

    Google Families

    Contact:

    Twitter: @bluesecuritypod

    Instagram: @bluesecuritypodcast

    Andy Jaw

    Twitter: @ajawzero

    LinkedIn: andyjaw

    Adam Brewer

    Twitter: @ajbrewer

    LinkedIn: adambrewer

    32 min
  • Merry Christmas! Learn how to spin up your own VM lab and dev environments

    This holiday week, Adam and Andy give you some advice on how to spin up your own virtual machine lab and dev environment. They go through SaaS applications that have free dev environments as well as tools to use to manage VM's. They also give tips on what you can do with that lab environment from testing policies to managing devices in Intune and even learning about tools like Mimikatz and John the Ripper.

    Documentation:

    Lab Building Guide: Virtual Active Directory

    Script to spin up AD controllers quickly

    Microsoft Developer Subscription

    Android Images

    Andy Jaw

    Twitter: @ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    Adam Brewer

    Twitter: @ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    34 min

About Blue Security

From the publisher's feed

A podcast for information security defenders (blue team) on best practices, tools, and implementation for enterprise security.

More shows like Blue Security

Acquired by Ben Gilbert and David Rosenthal

Acquired

4,836 Listeners

Pivot by New York Magazine

Pivot

9,613 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

WSJ Tech News Briefing by The Wall Street Journal

WSJ Tech News Briefing

1,644 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

Risky Business by Risky Business Media

Risky Business

374 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

650 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,027 Listeners

Smashing Security by Graham Cluley

Smashing Security

317 Listeners

Microsoft Cloud IT Pro Podcast by Ben Stegink, Scott Hoag

Microsoft Cloud IT Pro Podcast

65 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

The Azure Security Podcast by Michael Howard, Sarah Young, Gladys Rodriguez and Mark Simos

The Azure Security Podcast

25 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

137 Listeners

Entra.Chat by Merill Fernando

Entra.Chat

6 Listeners