Exploring Information Security - Exploring Information Security

Exploring Information Security - Exploring Information Security

By Timothy De BlockTechnology
Download on the App Store

Exploring Information Security - Exploring Information Security episodes

  • [RERELEASE] How to network in information security - part 1

    In this edition of the Exploring Information Security podcast, I discuss with Johnny Xmas how to network in information security.

    Johnny (@J0hnnyXm4s) is a penetration tester for Redlegg and an accomplished speaker at security conferences around the United States and Iceland. One of Johnny's more recent talks is titled "That's not my RJ45 Jack" which covers, among other topics, how to interact with people. I saw this talk in April when I went to BSides Nashville and it has a lot of good information that can be applied to networking with people in general.

    In part one we discuss:

    • What is networking?

    • How can Twitter be leverage to strengthen and improve your network?

    How to network in information security - part 1
    With Johnny Xmas

    [RSS Feed] [iTunes]

    18 min
  • [RERELEASE] What are BEC attacks?

    In this phishy edition of the Exploring Information Security podcast, Steve Ragan of CSO joins me to discuss business email compromise (BEC) attacks.

    Steve (@SteveD3) has been covering BEC types of attacks for the past year at CSO. These types of attacks are increasing. It may get worse with GDPR requirements next month. This ended up being one of the more difficult podcasts to get scheduled. Steve and I had to cancel on each other a few times because of phishing related stuff.

    In this episode we discuss:

    • What are BEC types of attacks?

    • Who is performing BEC attacks?

    • How are people falling for them?

    • What can people do protect against this type of attack?

    What are BEC attacks?
    With Steve Ragan
    Download

    [RSS Feed] [iTunes]

    Newsletter Block
    This newsletter signup form needs a storage option. Edit the block and enter a storage location via the Storage tab.
    Subscribe

    Sign up with your email address to receive news and updates.

    Email Address
    Sign Up

    We respect your privacy.

    Thank you!
    28 min
  • [RERELEASE] How to crack passwords

    In this crackerjack edition of the Exploring Information Security podcast, Sean Peterson of Parameter Security joins me to discuss password cracking.

    Sean (@SeanThePeterson), is one of the most passionate infosec people you don't know. He recently did a talk at ShowMeCon on how to crack passwords. It was his first ever talk and pretty damn good. Sean joined me to give me his insights into password cracking.

    In this episode we discuss:

    • What type of hardware is needed for password cracking

    • What type of attacks are used for password cracking

    • How to crack passwords

    • What's ahead for password cracking

    How to crack passwords
    With Sean Peterson
    Download

    [RSS Feed] [iTunes]

     

    Newsletter Block
    This newsletter signup form needs a storage option. Edit the block and enter a storage location via the Storage tab.
    Subscribe

    Sign up with your email address to receive news and updates.

    Email Address
    Sign Up

    We respect your privacy.

    Thank you!
    31 min
  • [RERELEASE] How to find vulnerabilites

    In this susceptible edition of the Exploring Information Security podcast, Samy Kamkar joins me to discuss how to find vulnerabilities.

    Samy (@samykamkar) shouldn't need too much of an introduction to most people. He's been in the news for hacking garage doors, credit cards, cars, and much much more. Samy likes to hack things and has a knack for finding vulnerabilities in everything from locked machines to wireless doorbells. His site has the full list of vulnerabilities as well as videos and press appearances. Which made him the perfect guess for talking about how to find vulnerabilities.

    In this episode we discuss:

    • What got him started in looking for vulnerabilities

    • What is a vulnerability

    • What skills are necessary for finding vulnerabilities

    • How he decides his next project

    • The steps to finding vulnerabilities

    • What he does when he discovers a vulnerability

    • How long the process takes

    How to find vulnerabilties with Samy Kamkar
    With Samy Kamkar
    Download

    [RSS Feed] [iTunes]

    28 min
  • [RERELEASE] What is data driven security?

    In this statistically-inclined edition for the Exploring Information Security podcast, I talk with Bob Rudis co-author of Data Driven Security to answer the questions: "What is data driven security?"

    I recently read Data Driven Security: Analysis, Visualization and Dashboards by Jay Jacobs (@jayjacobs) and Bob Rudis (@hrbrmstr). The book is easy to read and a very good introduction into the world of data and security. Both Jay and Bob were kind with their time when I had questions about exercises in the books. After reading the book I decided to have Bob on to talk more about data driven security. 

    Bob Rudis is also a contributor to the Verizon DBIR and these projects below:

    • Data Driven Security which features the book, a blog (@DDSecBlog), and a podcast (@ddsecpodcast).

    • Open Source R Tools For The Cybersecurity Domain

    • SecRepo.com - Samples of Security Related Data

    • MLSec - Machine Learning Security

    In this episode we discuss:

    • What is data driven security?

    • The benefits of data driven security

    • How it should be implemented

    • Where it can be applied

    Bob also gave me a long list of resources for those looking to get into data-driven security:

    • The Elements of Statistical Learning: data Mining, Inference, and Prediciton, Second Edition by Trevor Hastie, Robert Tibshirani, and Jerome Friedman.

    • Data Science Specialization - Coursera

    • Author Edward R. Tufte

    • Author Stephen Few

    • Linear Digressions podcast

    What is data driven security?
    With Bob Rudis

    [RSS Feed] [iTunes]

    33 min
  • [RERELEASE] What is data driven security?

    In this statistically-inclined edition for the Exploring Information Security podcast, I talk with Bob Rudis co-author of Data Driven Security to answer the questions: "What is data driven security?"

    I recently read Data Driven Security: Analysis, Visualization and Dashboards by Jay Jacobs (@jayjacobs) and Bob Rudis (@hrbrmstr). The book is easy to read and a very good introduction into the world of data and security. Both Jay and Bob were kind with their time when I had questions about exercises in the books. After reading the book I decided to have Bob on to talk more about data driven security. 

    Bob Rudis is also a contributor to the Verizon DBIR and these projects below:

    • Data Driven Security which features the book, a blog (@DDSecBlog), and a podcast (@ddsecpodcast).

    • Open Source R Tools For The Cybersecurity Domain

    • SecRepo.com - Samples of Security Related Data

    • MLSec - Machine Learning Security

    In this episode we discuss:

    • What is data driven security?

    • The benefits of data driven security

    • How it should be implemented

    • Where it can be applied

    Bob also gave me a long list of resources for those looking to get into data-driven security:

    • The Elements of Statistical Learning: data Mining, Inference, and Prediciton, Second Edition by Trevor Hastie, Robert Tibshirani, and Jerome Friedman.

    • Data Science Specialization - Coursera

    • Author Edward R. Tufte

    • Author Stephen Few

    • Linear Digressions podcast

    [RSS Feed] [iTunes]

    33 min
  • [RERELEASE] What is a CISSP?

    In this certifiably awesome episode of the Exploring Information Security podcast, I explore what a Certified Information Systems Security Professional with Javvad Malik.

    Javvad Malik (@J4vv4d) doesn't need much introduction. He's done a video on the benefits of being a CISSP. He's also done a music video with his Host Unknown crew on the CISSP. There's also The CISSP companion handbook he wrote. which has a collection of stories and experiences dealing with the 10 domains of the CISSP. Check out his website at j4vv4d.com and his YouTube channel.

    In this episode we discuss:

    • What is a CISSP?

    • What is the value of having a CISSP?

    • Who should get the CISSP?

    • The nuances of the certification test (pay attention to the questions)

    More resources:

    • CCCure.org for practice questions

    • Videos on YouTube

    • The Official Guide to the CISSP

    What is a CISSP?
    With J4vv4d

    [RSS Feed] [iTunes]

    25 min
  • [RERELEASE] From ShowMeCon 2017: Dave Chronister, Johnny Xmas, April Wright, and Ben Brown talk about Security

    In this epic episode of the Exploring Information Security podcast Jayson E. Street (@jaysonstreet), Dave Chronister (@bagomojo), Johnny Xmas (@J0hnnyXm4s), April Wright (@aprilwright), Ben Brown (@ajnachakra), and surprise guests Adrian Crenshaw (@irongeek_adc) and Kevin Johnson (@secureideas)all join me to discuss various security related topics.

    ShowMeCon is one of my favorite security conferences. The organizers are awesome and take care of their speakers like no other conference. The venue is fantastic. The content is mind blowing. I can't say enough good things about the even that Dave and Renee Chronister put on every year in St. Louis, Missouri. They know how to put on a conference.

    Regular listeners of the podcast will note that I recorded an episode with Dave on ShowMeCon several weeks ago. After that recording he asked if I was interested in doing a recording at the conference. I said yes and thus the birth of this epic episode. This format is experimental. First, it is marked as explicit, because there is swearing. Second, It's over 90 minutes long. I didn't think breaking it up into four or five pieces would serve the recording well. Send me your feedback good or bad on this episode, because I'd like to do more of these. I would really like to hear it for this episode.

    In this episode we discuss:

    • Certificates

    • Hiring

    • Interviewing

    • Where to get started

    • Soft skills

    • ShowMeCon and other conferences

    • Community and giving back

    • Imposter syndrome

    • Irongeeks impact on those in attendance

    What do the organizers and speakers of ShowMeCon think of security?
    Download

    [RSS Feed] [iTunes]

    1 hr 33 min
  • How to Perform Incident Response and Forensics on Drones with Wayne Burke
    Summary:

    In this episode of Exploring Information Security, host Timothy De Block sits down with Wayne Burke to discuss the crucial and rapidly evolving field of drone tactical forensics and incident response. Wayne sheds light on the increasing proliferation of drones, from law enforcement applications to criminal misuse, and the unique challenges involved in collecting forensic evidence from them. He reveals the dangers of booby-trapped drones and malware on flight controllers, emphasizing the need for caution and specialized techniques. Wayne also shares a fascinating incident involving electronic warfare against a surveillance drone, underscoring the sophisticated threats emerging today. Tune in to learn about essential forensic methods, from accessing flight logs with open-source tools to advanced chip-off forensics, and why collaboration in the cybersecurity community is vital for addressing these new challenges.

    What You'll Learn:

    • What drone tactical forensics entails and its growing importance in today's world of automated robotics.

    • The diverse and increasing applications of drones, including surveillance and the potential for misuse like extortion.

    • Significant risks and dangers in drone forensics, such as booby traps and flight controller malware.

    • Initial steps and varied techniques for drone incident response and forensic evidence collection, depending on the drone type.

    • How flight logs and telemetry data are analyzed using open-source tools, and methods for advanced forensics like chip-off analysis.

    • The critical role of community and collaboration in addressing emerging drone security threats.

    Use the promo code “ExploringSec” to get $50 off your registration

    Showmecon Links and Resources:
    • Learn more about ShowMeCon: showmecon.com

    • Register for Training or the Conference: Registration Link

    • Event Venue and Room Block Information: Ameristar Casino & Resort

    • Connect with the Founder of ShowMeCon Dave Chronister: LinkedIn Profile

    • Connect with the Head Organizer for ShowMeCon Brooke Deneen: LinkedIn Profile

    Support the Podcast:

    Enjoyed this episode? Leave us a review and share it with your network! Subscribe for more insightful discussions on information security and privacy.

    Contact Information:

    Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

    Check out our services page and reach out if you see any services that fit your needs.

    Social Media Links:

    [RSS Feed] [iTunes] [LinkedIn][YouTube]

    How to Perform Incident Response and Forensics on Drones
    Wayne Burke
    Newsletter Block
    This newsletter signup form needs a storage option. Edit the block and enter a storage location via the Storage tab.
    Subscribe

    Sign up with your email address to receive news and updates.

    Email Address
    Sign Up

    We respect your privacy.

    Thank you!


    25 min
  • That Shouldn't Have Worked: A Red Teamer's Confessions with Corey Overstreet
    Summary:

    In this episode of Exploring Information Security, host Timothy De Block speaks with Corey Overstreet, a seasoned pentester from Red Siege. Corey shares insights into the ongoing cat-and-mouse game between red teams and blue teams, revealing common vulnerabilities and unexpected successes in breaching defenses. He discusses his upcoming talk at Show Me Con, titled "That Shouldn't Have Worked," which aims to equip blue teams with practical knowledge on bolstering their defenses against persistent attackers. From the nuances of payload delivery to the surprising resilience of old tricks and the challenges of cloud security, Corey offers a candid look at the daily realities of offensive security and how defenders can truly make a red teamer's life difficult.

    What You'll Learn:

    • The core focus of Corey Overstreet's "That Shouldn't Have Worked" talk at Show Me Con.

    • Common mistakes red teamers make and how to avoid them.

    • Effective defensive strategies for blue teams, including the power of application control and network segmentation.

    • The evolving landscape of EDR and how AI is starting to make red team operations more challenging.

    • Insights into the surprising ways macros and social engineering continue to be effective entry points, especially in cloud environments.

    • Advice for aspiring pentesters on learning and problem-solving, emphasizing hands-on practice and diligent note-taking.

    • Corey's favorite resources for staying up-to-date in cybersecurity, including various subreddits, Discord, and Slack communities.

    Use the promo code “ExploringSec” to get $50 off your registration

    Showmecon Links and Resources:
    • Learn more about ShowMeCon: showmecon.com

    • Register for Training or the Conference: Registration Link

    • Event Venue and Room Block Information: Ameristar Casino & Resort

    • Connect with the Founder of ShowMeCon Dave Chronister: LinkedIn Profile

    • Connect with the Head Organizer for ShowMeCon Brooke Deneen: LinkedIn Profile

    Support the Podcast:

    Enjoyed this episode? Leave us a review and share it with your network! Subscribe for more insightful discussions on information security and privacy.

    Contact Information:

    Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

    Check out our services page and reach out if you see any services that fit your needs.

    Social Media Links:

    [RSS Feed] [iTunes] [LinkedIn][YouTube]

    That Shouldn't Have Worked: A Red Teamer's Confessions
    Corey Overstreet
    Newsletter Block
    This newsletter signup form needs a storage option. Edit the block and enter a storage location via the Storage tab.
    Subscribe

    Sign up with your email address to receive news and updates.

    Email Address
    Sign Up

    We respect your privacy.

    Thank you!


    47 min

About Exploring Information Security - Exploring Information Security

From the publisher's feed

The Exploring Information Security podcast interviews a different professional each week exploring topics, ideas, and disciplines within information security. Prepare to learn, explore, and grow your…

More shows like Exploring Information Security - Exploring Information Security

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,029 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,059 Listeners