
Sign up to save your podcasts
Or


Summary:
Jayson E. Street
In this engaging episode Jayson E. Street, a renowned cybersecurity expert, joins me to discuss the return of ShowMeCon, the impact of AI in cybersecurity, and innovative strategies for enhancing security and combating threats. Jayson shares his excitement for ShowMeCon, insights on utilizing AI for security enhancements rather than traditional attacks, and offers practical advice for users, executives, and information security professionals.
This podcast sponsored by ShowMeCon.
Episode Highlights:
ShowMeCons return
Utilizing AI in Cybersecurity
Creative Use of AI for Security
Practical Security Tips Across the Board
The Future of AI in Security
Guest Information:
Jayson E. Street referred to in the past as: A "notorious hacker" by FOX25 Boston, "World Class Hacker" by National Geographic Breakthrough Series and described as a "paunchy hacker" by Rolling Stone Magazine.
He however prefers if people refer to him simply as a Hacker, Helper & Human.
Contact Information:
Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:
[RSS Feed] [iTunes] [LinkedIn]
Sign up with your email address to receive news and updates.
We respect your privacy.
Scott Miller
Summary:
Scott Miller, a fresh voice in the cybersecurity arena, joins me to discuss the intricacies of hacking Azure services. Scott shares his journey from a recent college graduate to becoming a speaker at cybersecurity conferences, along with valuable insights into Azure AD (Active Directory), vulnerabilities within cloud services, and the art of escalation.
This episode sponsored by ShowMeCon.
Episode Highlights:
Scott's Entry into Cybersecurity
Focus on Azure AD
Exploring Vulnerabilities
Methodology and Tools
Learning and Resources
The Importance of Entry-Level Accessibility
Scott Miller Penetration Tester at Accenture
Contact Information:
Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:
[RSS Feed] [iTunes] [LinkedIn]
Sign up with your email address to receive news and updates.
We respect your privacy.
Paul Coggin
Summary:
In this captivating episode of the "Exploring Information Security" podcast, cybersecurity expert Paul Coggin discusses the intricate world of threat hunting in SCADA networks and the emerging frontier of space cybersecurity. From the inspiration drawn from Transformers movies to the sophisticated attacks like Stuxnet, Coggin delves deep into how monitoring physical indicators could revolutionize our approach to cybersecurity in both terrestrial and extraterrestrial domains.
This podcast is sponsored by ShowMeCon.
Episode Highlights:
The significance of ShowMeCon in filling the void left by other conferences.
Paul's historical involvement and contribution to the naming of ShowMeCon and DerbyCon.
The Internet of Military Things
Initiating Threat Hunting in New Domains
Case Studies and Practical Applications
Looking Ahead: Cybersecurity in Space
Guest Information:
Paul Coggin is a Cyber SME at nou Systems, Inc.
Contact Information:
Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:
[RSS Feed] [iTunes] [LinkedIn]
Sign up with your email address to receive news and updates.
We respect your privacy.
Arnar Gunnarsson
Summary:
Arnar is not a speaker this year at ShowMeCon but he will be in attendance. He doesn’t work in the security field but he’s doing some really advanced stuff with cooling in cloud environments. We get into a little bit of everything around what he’s doing as well as talk about AI. Surprise!
This podcast is sponsored by ShowMeCon.
Episode Highlights:
What Arnar is looking forward to at ShowMeCon
Some of the cool things he’s doing with his company
AI
Guest Information:
Arnar
Contact Information:
Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:
[RSS Feed] [iTunes] [LinkedIn]
Sign up with your email address to receive news and updates.
We respect your privacy.
Amanda Berlin
Summary:
Amanda Berlin is Lead Incident Detection Engineer at Blumira, where she leads the development of new detections for the Blumira platform, based on threat intelligence and research. In this episode I catch up with her to talk about Sysmon and ShowMeCon. Sysmon is such a great tool for getting more information out of your systems. The best part is it’s free.
This podcast is sponsored by ShowMeCon.
Episode Highlights:
What is Sysmon
How to use Sysmon
ShowMeCon
Guest Information:
Amanda Berlin is Lead Incident Detection Engineer at Blumira
Contact Information:
Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:
[RSS Feed] [iTunes] [LinkedIn]
Sign up with your email address to receive news and updates.
We respect your privacy.
Summary:
Veteran conference speaker Johnny Xmas joins me to discuss ShowMeCon and his talk Couch to Compromise the 2024 edition. His talk is an update from previous years which goes over the latest attacks impacting organizations.
Episode Highlights:
Johnny Xmas with a not a flamethrower
ShowMeCon
Couch to Compromise 2024 talk
Guest Information:
Johnny Xmas: The Most Interesting Man in Information Security
Contact Information:
Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:
[RSS Feed] [iTunes] [LinkedIn]
Sign up with your email address to receive news and updates.
We respect your privacy.
Summary:
Shameer Amir AKA Titan joins me to discuss his upcoming talk on his research into bypassing multifactor authentication (MFA) at the upcoming ShowMeCon conference. In this episode we talk about a variety of different ways of bypassing MFA from human interaction to more technical interactions with the platforms. A lot of what it comes down to is making sure MFA is setup properly.
Episode Highlights:
Why this talk
Response manipulation
SIM jacking
Misconfigurations
Guest Information:
Shameer Amir AKA Titan is a globally recognized bug hunter
Contact Information:
Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:
[RSS Feed] [iTunes] [LinkedIn]
Sign up with your email address to receive news and updates.
We respect your privacy.
Summary:
Micah Hoffman and Griffin Glynn from My OSINT Training join me to talk about the current state of OSINT. Both bring a wealth of knowledge and first meet while working together at the National Child Protection Task Force. They bring a wealth of knowledge and we get into a lot of the ins and outs of OSINT.
Episode Highlights:
What is OSINT?
What tools are used for OSINT
Social media changes?
How do APIs play into OSINT?
How is AI impacting OSINT?
Guest Information:
Micah Hoffman and Griffin Glynn co-owners of My OSINT Training environment and co-workers at National Child Protection Task Force (NCPTF)
https://twitter.com/myosinttrainer
https://www.linkedin.com/company/my-osint-training
https://www.myosint.training
Resources and Mentions:
Free OSINT Newsletter
Free intro to OSINT course
The Ultimate OSINT Collection
Cloud browser desktop for OSINT
Contact Information:
Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:
[RSS Feed] [iTunes] [LinkedIn]
Sign up with your email address to receive news and updates.
We respect your privacy.
Summary:
Rob Fuller AKA Mubix joins me to talk about security tooling every organization should have. This was a result of a discussion Rob and I were having about Thinkst Canary and RunZero. Two fantastic tools that are low cost, easy implementation, and provide a ton of value to a security team.
Episode Highlights:
Lots of tooling to talk about
You might hear Rob mention that he’s used one of the tools I suggest in a pentest engagement
Guest Information:
Rob Fuller aka Mubix - Twitter
https://malicious.link/
Resources and Mentions:
RunZero
https://www.runzero.com/
Canaries (Thinkst)
https://canarytokens.org/
https://canary.tools/
Shodan.io
https://www.shodan.io/
OSQuery / Fleet
https://github.com/fleetdm/fleet
https://fleetdm.com/
Netbird / TailScale
https://netbird.io/
https://tailscale.com/
Sysmon / GrayLog / Logstash / Cribl / Zeek / Wazuh
https://github.com/SwiftOnSecurity/sysmon-config
https://graylog.org/
https://www.elastic.co/logstash
https://cribl.io/
https://zeek.org/get-zeek/
https://wazuh.com/
Security Onion
GoDot - Game Dev -> Security Awareness / Security Appreciation
https://godotengine.org/
PDQ
https://www.pdq.com/
GOAD
https://github.com/Orange-Cyberdefense/GOAD
Velociraptor
https://docs.velociraptor.app/training/
MISP
https://www.misp-project.org/
LinkedIn Suggestions
WisQuas - Lost Rabbit Labs - Noa Park suggestion
https://www.lostrabbitlabs.com/wisquas
Deprovisioning tool - Arvil Nagpal - Abbey Labs
https://www.abbey.io/
Contact Information:
Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:
[RSS Feed] [iTunes] [LinkedIn]
Sign up with your email address to receive news and updates.
We respect your privacy.
This is a sponsored podcast by ShowMeCon which is May 13th & 14th. Tickets are still available! They’re also still looking for sponsors. Don't miss out on this opportunity to be part of the cybersecurity event of the year! Whether you're looking to learn, network, or elevate your brand, ShowMeCon is the place to be.
Summary:
Brandon Potter Chief Technology Officer of ProCircular, Inc.
Brandon Potter joins me to discuss the different ways he’s seeing MFA bypassed as part of his companies work. Attackers are using old and new techniques to discover creative ways to bypass MFA. This is a result of more companies getting onboard with MFA. Unfortunately, that means attackers are going to start to find more ways to bypass MFA. A lot of what Brandon is seeing is coming down to misconfiguration with how MFA is implemented and attackers are starting to use browser in the middle to hijack sessions. Finally, we go over how AI is going to impact MFA.
Episode Highlights:
ShowMeCon one of the few conferences in the Midwest to attend
Bypassing MFA
Misconfigurations in MFA
Browser-in-the-middle
Where is MFA being bypassed?
How is AI going to impact bypassing MFA
Guest Information:
Brandon Potter (CISSP, GSEC, GCIH, CCFP, GWAPT) is the Chief Technology Officer of ProCircular, Inc.,
Brandon Potter LinkedIn
ProCircular Website
ProCircular LinkedIn
Contact Information:
Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:
[RSS Feed] [iTunes] [LinkedIn]
Sign up with your email address to receive news and updates.
We respect your privacy.
From the publisher's feed

373 Listeners

1,029 Listeners

8,059 Listeners