
Sign up to save your podcasts
Or


In this building better relationships edition of the Exploring Information Security podcast, I discuss my new presentation and workshop content for this year, Social Engineering for the Blue Team.
I've already written a couple blog posts on the topic:
Social Engineering for the Blue Team
Social Engineering for the Blue Team: My Story
I've also created a GitHub page to track all my resources I intend to use in the presentation and training. The idea of the content is that we can use social engineering (like the red team) in our day-to-day interactions at work. We can use the same techniques to build better relationships and build better security mindsets in our organization. If you prefer soft skills.
In this episode I discuss:
What is social engineering for the blue team
How I came up with the idea
How can this be applied
What techniques we can use to build better relationships
[RSS Feed] [iTunes]
Sign up with your email address to receive news and updates.
We respect your privacy.
In this open edition of the Exploring Information Security podcast, I sit down with Micah Hoffman, Kerby Plessas, and Josh Huff to discuss Open Source INTelligence (OSINT).
Micah Hoffman (@WebBreacher) is a SANS instructor who will be teaching a brand new SANS course, SANS487: Open-Source Intelligence Gathering and Analysis.
Kirby Plessas (@kirbstr) runs her own training company Plessas Experts Network, Inc. There is an online training portal that you can use to learn more about OSINT.
Josh Huff (@baywolf88) is a Digital Forensics Private Investigator and OSINT addict. He runs the Learn All The Things website.
This is a new format for the podcast that I am trying out. It's a lot like the conference episodes I do: It's longer; I allow swearing; and there is no format or direction. I asked for OSINT questions on Twitter and got some pretty good ones back for people to answer. I can turn this into a live show that would allow for people watching to interact with the guests on the show. I need feedback on whether or not this of interest to people. Hit me up on Twitter (@TimothyDeBlock) or email (timothy[.]deblock[@]gmail[.]com)
In this episode we discuss:
Why it's important to automate OSINT
What tools are available for OSINT
Where does OSINT end and breaking the law begin?
Where can OSINT be used in an organization
How to get into OSINT
and much much more
More Resources:
Automating OSINT
Hunchly
OSINT Framework
Spiderfoot
IntelTechniques
SANS Webcast: OSINT for Everyone - Understanding Risks and Protecting Your Data
Deep Dive in the Dark Web OSINT Style
[RSS Feed] [iTunes]
Sign up with your email address to receive news and updates.
We respect your privacy.
In this social episode of the Exploring Information Security podcast, Chris Hadnagy joins me to discuss how to become a social engineer.
Chris (@humanhacker) is the Chief Human Hacker at Social-Engineer, Inc. He's the author of several social engineer books. He also has his own podcast. This past summer he announced the Innocent Lives Foundation, which has the objective of unmasking anonymous online child predators through OSINT and relationships with law enforcement. He is a social engineering Hulk in the field of information security.
In this episode we discuss:
How to practice to become a social engineer
What is toastmasters
What college courses can help
What resources are available.
[RSS Feed] [iTunes]
Sign up with your email address to receive news and updates.
We respect your privacy.
In this social episode of the Exploring Information Security podcast, Chris Hadnagy joins me to discuss how to become a social engineer.
Chris (@humanhacker) is the Chief Human Hacker at Social-Engineer, Inc. He's the author of several social engineer books. He also has his own podcast. This past summer he announced the Innocent Lives Foundation, which has the objective of unmasking anonymous online child predators through OSINT and relationships with law enforcement. He is a social engineering Hulk in the field of information security.
In this episode we discuss:
What is social engineering
What skills are needed to become a social engineer
How much of social engineering is experience
What tools are used for social engineering
[RSS Feed] [iTunes]
Sign up with your email address to receive news and updates.
We respect your privacy.
In this fruity episode of the Exploring Information Security podcast, Wes Widner joins me to discuss how to hack iOS.
Wes (@kai5263499) is a cloud engineer, who loves to dig into Apple product security. Last year (and on a previous episode) he discuss how Macs get malware. He's back again this year to discuss how to hack iOS. He will be speaking at BSides Hunstville February 3, 2018. If you have a chance to go, be sure to check out his talk. Also, check out is OSX security awesome list on GitHub. It's a really useful set of links on This dude is really smart.
In this episode we discuss:
Are we talking NSA level hacking?
What tools are available for hacking iOS
What resources are available for hacking iOS
More resources:
Lib mobile device
Cydia
[RSS Feed] [iTunes]
Sign up with your email address to receive news and updates.
We respect your privacy.
Sign up with your email address to receive news and updates.
We respect your privacy.
In this fruity episode of the Exploring Information Security podcast, Wes Widner joins me to discuss how to hack iOS.
Wes (@kai5263499) is a cloud engineer, who loves to dig into Apple product security. Last year (and on a previous episode) he discuss how Macs get malware. He's back again this year to discuss how to hack iOS. He will be speaking at BSides Hunstville February 3, 2018. If you have a chance to go, be sure to check out his talk. Also, check out is OSX security awesome list on GitHub. It's a really useful set of links on This dude is really smart.
In this episode we discuss:
What is his talk about?
What's the difference between application and device hacking
What skills are needed to hack iOS
How Apple works with law enforcement
More resources:
Lib mobile device
Cydia
[RSS Feed] [iTunes]
Sign up with your email address to receive news and updates.
We respect your privacy.
In this Motor City edition of the Exploring Information Security podcast, Ryan Harp, Kyle Andrus, and Kate Vajda join me to discuss the conferences Converge and BSides Detroit.
Ryan (@th3b00st), Kyle (@chaoticflaws), and Kate (@vajkat) help put on one of the best conferences. Last year was my first year at the conference. I was not disappointed. They had a workshop on application security; a room set aside to get resume feedback; Ham radio exams; and much more. They also had three days of wonderful talks with some really great speakers. At lunch there are multiple treks to go grab a coney dog.
The call for papers is currently open. They're looking for speakers and to add more workshops this year. Tickets are also available now. Make sure to grab yours and I'll see you at Converge and BSides Detroit May 10-12.
In this episode we discuss:
How the conference got started.
Where the conference is at and what's new this year for the layout.
What's unique about the conference.
Coney dogs.
[RSS Feed] [iTunes]
Sign up with your email address to receive news and updates.
We respect your privacy.
In this foundational episode of the Exploring Information Security podcast, Matt Tesauro and Aaron Weaver join me to discuss the AppSec Pipeline.
Matt (@matt_tesauro) and Aaron (@weavera) are the project leads for the OWASP AppSec Pipeline. The project provides resources and guidance for building out your own appsec pipeline within a development team. Building a pipeline is important in helping get security embedded within software.
In this episode we discuss:
What is the OWASP AppSec Pipeline
How did it get started
Who should use the AppSec Pipeline
How to implement the AppSec Pipeline
[RSS Feed] [iTunes]
Sign up with your email address to receive news and updates.
We respect your privacy.
In this reflection edition of the Exploring Information Security podcast, I look back at 2017 and also look ahead to 2018 for the podcast.
2017 was a great year for the podcast. I saw increased listernership. We had a new episode format that involved talking to several security professionals at various conferences. I've also seen an increase in companies and public relation firms reaching out to me to pitch guests. In 2018 I'd like to explore some new formats. There may be a conference panel in the future. I also expect to look at advertising and sponsorship for the podcasts. I also need to work on an archive feed for older episodes.
If you have feedback on any of this or ideas for where I should take the show, I would love to hear them. You can hit me up on Twitter (@TimothyDeBlock), email: timothy.deblock[@]gmail[dot]com, or by leaving a comment below. Thanks for such a great year and I look forward to a fantastic 2018.
[RSS Feed] [iTunes]
Sign up with your email address to receive news and updates.
We respect your privacy.
In this fake episode of the Exploring Information Security podcast, Micah Hoffman joins me to discuss imposter syndrome.
Micah (@WebBreacher), this past year, spoke on imposter syndrome and how to overcome it. It's something we all deal with (even several years into our careers). It's useful, but also dangerous for those of us in the information security community. We need to try and compare ourselves to others less and speak more positively internally.
In this episode we discuss:
What is imposter syndrome?
Why people get imposter syndrome.
How to overcome imposer syndrome.
Stick around until the end to hear some real imposter syndrome.
[RSS Feed] [iTunes]
Sign up with your email address to receive news and updates.
We respect your privacy.
From the publisher's feed

373 Listeners

1,028 Listeners

8,054 Listeners