
Sign up to save your podcasts
Or


Claire (@ClaireTills) doesn’t have your typical roll in infosec. She sits between the security teams and marketing team at Tenable. It’s a fascinating roll and something that gives her a lot of insight into multiple parts of the business. What works and what doesn’t work in communicating security to the different areas. Check her blog out.
In this episode we discuss:
What Claire’s experience is with communication and infosec
What’s ahead for communication in infosec
Why do people do what they do?
What questions to ask
More resources:
Networking with Humans to Create a Culture of Security by Tracy Maleeff - BSides NoVa 2017
Courtney K BsidesLV 2018, Implementing the Three Cs of Courtesy, Clarity, and Comprehension to Optimize End User Engagement (video not available yet)
BSidesWLG 2017 - Katie Ledoux - Communication: An underrated tool in the infosec revolution
Jeff Man, The Art of the Jedi Mind Trick
The Thing Explainer: Complicated Stuff in Simple Words
Chris Roberts, Communication Across Ranges
In this brand new edition of the Exploring Information Security podcast, I have a conversation with Justin Seitz (@jms_dot_py).
When I have guests hop on the podcast, I usually try to break the ice a little and get them warmed up for the episode. Often times these can turn into some really good conversation about the infosec field. I'd like to start capturing those conversation and release them (with the person's permission), because there are some really great insights.
I've released this episode early to the people on my newsletter (check below to get in on the fun). I wanted to get feedback and also give people who sign-up some bonus content, which is something I hope to do more.
In this episode we discuss:
[RSS Feed] [iTunes]
Sign up with your email address to receive news and updates.
We respect your privacy.
In this shipped edition of the Exploring Information Security podcast, Wes Widner joins me to discuss container security.
Wes (@kai5263499) is not a security person. He is a developer. A developer that understands security and why it's important. He deals a lot with automation and working with container technology.
In this episode we discuss:
More Resources:
[RSS Feed] [iTunes]
Sign up with your email address to receive news and updates.
We respect your privacy.
In this shipped edition of the Exploring Information Security podcast, Wes Widner joins me to discuss container security.
Wes (@kai5263499) is not a security person. He is a developer. A developer that understands security and why it's important. He deals a lot with automation and working with container technology.
In this episode we discuss:
More Resources:
[RSS Feed] [iTunes]
Sign up with your email address to receive news and updates.
We respect your privacy.
In this screenshot edition of the Exploring Information Security podcast, Justin Seitz joins me to discuss Hunchly.
Justin (@jms_dot_py) is the creator of Hunchly. I got to know Hunchly at SANS SEC487 OSINT training earlier this year. It's a fantastic tool that takes screenshot as the web is browsed. This is very useful for investigations involving OSINT. I'm also finding it useful for incident response, particularly for clicking on phishing pages. I sometimes forget to take screenshots as I'm investigating a phishing page. Having Hunchly means, I don't have to worry about taking screenshots. I then use the screenshots for reports and training. It's a really useful tool.
In this episode we discuss:
More resources:
[RSS Feed] [iTunes]
Sign up with your email address to receive news and updates.
We respect your privacy.
In this crafting episode of the Exploring Information Security podcast, Paul Johnston Customer Champion at Portswigger joins me to discuss how to make a Burp extension.
Paul (@paulpaj) wrote a blog post on how to make a successful burp extension and get it published in the Burp Store. A lot of the recommendations in the article are from Paul's experience handling extension submissions for the Burp Store.
In this episode we discuss:
[RSS Feed] [iTunes]
Sign up with your email address to receive news and updates.
We respect your privacy.
In this refused episode of the Exploring Information Security podcast, Michael Kavka joins me to discuss how to handle call for presentation rejections.
Michael (@SiliconShecky) wrote a blog post on his site at the beginning of the year titled, It is CFP season... So what. In the article he hit on rejections and I thought it'd make for a great podcast topic. More recently, he wrote a blog post on the, Anatomy of a Rejected CFP. The article walks through his rejected CFP for DerbyCon.
In this episode we discuss:
More resources:
[RSS Feed] [iTunes]
Sign up with your email address to receive news and updates.
We respect your privacy.
In this expedition edition of the Exploring Information Security podcast, Chris Maddalena a senior security consultant joins me to discuss how to create a phishing email.
Chris (@cmaddalena) joins me to discuss crafting a phishing email. This is something I've recently explored at work. Having little to no experience actually crafting a phish, I decided I'd go to someone who does this on a regular basis. Check out Chris' ODIN tool for automating intelligence gathering, asset discovery, and reporting.
In this episode we discuss:
What are the technical steps to creating a phish
What needs to be consider from a technical standpoint
What is GoPhish and GoReporter
How important is timing
Other resources:
gophish
goreporter
[RSS Feed] [iTunes]
Sign up with your email address to receive news and updates.
We respect your privacy.
In this expedition edition of the Exploring Information Security podcast, Chris Maddalena a senior security consultant joins me to discuss how to create a phishing email.
Chris (@cmaddalena) joins me to discuss crafting a phishing email. This is something I've recently explored at work. Having little to no experience actually crafting a phish, I decided I'd go to someone who does this on a regular basis. Check out Chris' ODIN tool for automating intelligence gathering, asset discovery, and reporting.
In this episode we discuss:
[RSS Feed] [iTunes]
Sign up with your email address to receive news and updates.
We respect your privacy.
In this battlefield edition of the Exploring Information Security podcast, Micah Hoffman joins me to discuss OSINT ORCS YOGA.
Micah (@WebBreacher), is a SANS Instructor and author of the SEC487 OSINT course. He recently had his second class in Denver, Colorado (more dates here). During that class he found people asking about how to navigate the waters of OSINT resources. His solution was to start the OSINT Resource Classification System (ORCS). It's a call for the OSINT community to standardize on how resources are categorized. YOGA or Your OSINT Graphical Analyzer is meant to be a visual aid for people looking to navigate the streets of OSINT resources.
In this episode we discuss:
[RSS Feed] [iTunes]
Sign up with your email address to receive news and updates.
We respect your privacy.
From the publisher's feed

373 Listeners

1,029 Listeners

8,059 Listeners