
Sign up to save your podcasts
Or


In this edition of the Exploring Information Security podcast, I discuss with Johnny Xmas how to network in information security.
Johnny (@J0hnnyXm4s) is a penetration tester for Redlegg and an accomplished speaker at security conferences around the United States and Iceland. One of Johnny's more recent talks is titled "That's not my RJ45 Jack" which covers, among other topics, how to interact with people. I saw this talk in April when I went to BSides Nashville and it has a lot of good information that can be applied to networking with people in general.
In part one we discuss:
What is networking?
How can Twitter be leverage to strengthen and improve your network?
[RSS Feed] [iTunes]
In this phishy edition of the Exploring Information Security podcast, Steve Ragan of CSO joins me to discuss business email compromise (BEC) attacks.
Steve (@SteveD3) has been covering BEC types of attacks for the past year at CSO. These types of attacks are increasing. It may get worse with GDPR requirements next month. This ended up being one of the more difficult podcasts to get scheduled. Steve and I had to cancel on each other a few times because of phishing related stuff.
In this episode we discuss:
What are BEC types of attacks?
Who is performing BEC attacks?
How are people falling for them?
What can people do protect against this type of attack?
[RSS Feed] [iTunes]
Sign up with your email address to receive news and updates.
We respect your privacy.
In this crackerjack edition of the Exploring Information Security podcast, Sean Peterson of Parameter Security joins me to discuss password cracking.
Sean (@SeanThePeterson), is one of the most passionate infosec people you don't know. He recently did a talk at ShowMeCon on how to crack passwords. It was his first ever talk and pretty damn good. Sean joined me to give me his insights into password cracking.
In this episode we discuss:
What type of hardware is needed for password cracking
What type of attacks are used for password cracking
How to crack passwords
What's ahead for password cracking
[RSS Feed] [iTunes]
Sign up with your email address to receive news and updates.
We respect your privacy.
In this susceptible edition of the Exploring Information Security podcast, Samy Kamkar joins me to discuss how to find vulnerabilities.
Samy (@samykamkar) shouldn't need too much of an introduction to most people. He's been in the news for hacking garage doors, credit cards, cars, and much much more. Samy likes to hack things and has a knack for finding vulnerabilities in everything from locked machines to wireless doorbells. His site has the full list of vulnerabilities as well as videos and press appearances. Which made him the perfect guess for talking about how to find vulnerabilities.
In this episode we discuss:
What got him started in looking for vulnerabilities
What is a vulnerability
What skills are necessary for finding vulnerabilities
How he decides his next project
The steps to finding vulnerabilities
What he does when he discovers a vulnerability
How long the process takes
[RSS Feed] [iTunes]
In this statistically-inclined edition for the Exploring Information Security podcast, I talk with Bob Rudis co-author of Data Driven Security to answer the questions: "What is data driven security?"
I recently read Data Driven Security: Analysis, Visualization and Dashboards by Jay Jacobs (@jayjacobs) and Bob Rudis (@hrbrmstr). The book is easy to read and a very good introduction into the world of data and security. Both Jay and Bob were kind with their time when I had questions about exercises in the books. After reading the book I decided to have Bob on to talk more about data driven security.
Bob Rudis is also a contributor to the Verizon DBIR and these projects below:
Data Driven Security which features the book, a blog (@DDSecBlog), and a podcast (@ddsecpodcast).
Open Source R Tools For The Cybersecurity Domain
SecRepo.com - Samples of Security Related Data
MLSec - Machine Learning Security
In this episode we discuss:
What is data driven security?
The benefits of data driven security
How it should be implemented
Where it can be applied
Bob also gave me a long list of resources for those looking to get into data-driven security:
The Elements of Statistical Learning: data Mining, Inference, and Prediciton, Second Edition by Trevor Hastie, Robert Tibshirani, and Jerome Friedman.
Data Science Specialization - Coursera
Author Edward R. Tufte
Author Stephen Few
Linear Digressions podcast
[RSS Feed] [iTunes]
In this statistically-inclined edition for the Exploring Information Security podcast, I talk with Bob Rudis co-author of Data Driven Security to answer the questions: "What is data driven security?"
I recently read Data Driven Security: Analysis, Visualization and Dashboards by Jay Jacobs (@jayjacobs) and Bob Rudis (@hrbrmstr). The book is easy to read and a very good introduction into the world of data and security. Both Jay and Bob were kind with their time when I had questions about exercises in the books. After reading the book I decided to have Bob on to talk more about data driven security.
Bob Rudis is also a contributor to the Verizon DBIR and these projects below:
Data Driven Security which features the book, a blog (@DDSecBlog), and a podcast (@ddsecpodcast).
Open Source R Tools For The Cybersecurity Domain
SecRepo.com - Samples of Security Related Data
MLSec - Machine Learning Security
In this episode we discuss:
What is data driven security?
The benefits of data driven security
How it should be implemented
Where it can be applied
Bob also gave me a long list of resources for those looking to get into data-driven security:
The Elements of Statistical Learning: data Mining, Inference, and Prediciton, Second Edition by Trevor Hastie, Robert Tibshirani, and Jerome Friedman.
Data Science Specialization - Coursera
Author Edward R. Tufte
Author Stephen Few
Linear Digressions podcast
[RSS Feed] [iTunes]
In this certifiably awesome episode of the Exploring Information Security podcast, I explore what a Certified Information Systems Security Professional with Javvad Malik.
Javvad Malik (@J4vv4d) doesn't need much introduction. He's done a video on the benefits of being a CISSP. He's also done a music video with his Host Unknown crew on the CISSP. There's also The CISSP companion handbook he wrote. which has a collection of stories and experiences dealing with the 10 domains of the CISSP. Check out his website at j4vv4d.com and his YouTube channel.
In this episode we discuss:
What is a CISSP?
What is the value of having a CISSP?
Who should get the CISSP?
The nuances of the certification test (pay attention to the questions)
More resources:
CCCure.org for practice questions
Videos on YouTube
The Official Guide to the CISSP
[RSS Feed] [iTunes]
In this epic episode of the Exploring Information Security podcast Jayson E. Street (@jaysonstreet), Dave Chronister (@bagomojo), Johnny Xmas (@J0hnnyXm4s), April Wright (@aprilwright), Ben Brown (@ajnachakra), and surprise guests Adrian Crenshaw (@irongeek_adc) and Kevin Johnson (@secureideas)all join me to discuss various security related topics.
ShowMeCon is one of my favorite security conferences. The organizers are awesome and take care of their speakers like no other conference. The venue is fantastic. The content is mind blowing. I can't say enough good things about the even that Dave and Renee Chronister put on every year in St. Louis, Missouri. They know how to put on a conference.
Regular listeners of the podcast will note that I recorded an episode with Dave on ShowMeCon several weeks ago. After that recording he asked if I was interested in doing a recording at the conference. I said yes and thus the birth of this epic episode. This format is experimental. First, it is marked as explicit, because there is swearing. Second, It's over 90 minutes long. I didn't think breaking it up into four or five pieces would serve the recording well. Send me your feedback good or bad on this episode, because I'd like to do more of these. I would really like to hear it for this episode.
In this episode we discuss:
Certificates
Hiring
Interviewing
Where to get started
Soft skills
ShowMeCon and other conferences
Community and giving back
Imposter syndrome
Irongeeks impact on those in attendance
[RSS Feed] [iTunes]
In this episode of Exploring Information Security, host Timothy De Block sits down with Wayne Burke to discuss the crucial and rapidly evolving field of drone tactical forensics and incident response. Wayne sheds light on the increasing proliferation of drones, from law enforcement applications to criminal misuse, and the unique challenges involved in collecting forensic evidence from them. He reveals the dangers of booby-trapped drones and malware on flight controllers, emphasizing the need for caution and specialized techniques. Wayne also shares a fascinating incident involving electronic warfare against a surveillance drone, underscoring the sophisticated threats emerging today. Tune in to learn about essential forensic methods, from accessing flight logs with open-source tools to advanced chip-off forensics, and why collaboration in the cybersecurity community is vital for addressing these new challenges.
What You'll Learn:
What drone tactical forensics entails and its growing importance in today's world of automated robotics.
The diverse and increasing applications of drones, including surveillance and the potential for misuse like extortion.
Significant risks and dangers in drone forensics, such as booby traps and flight controller malware.
Initial steps and varied techniques for drone incident response and forensic evidence collection, depending on the drone type.
How flight logs and telemetry data are analyzed using open-source tools, and methods for advanced forensics like chip-off analysis.
The critical role of community and collaboration in addressing emerging drone security threats.
Use the promo code “ExploringSec” to get $50 off your registration
Showmecon Links and Resources:Learn more about ShowMeCon: showmecon.com
Register for Training or the Conference: Registration Link
Event Venue and Room Block Information: Ameristar Casino & Resort
Connect with the Founder of ShowMeCon Dave Chronister: LinkedIn Profile
Connect with the Head Organizer for ShowMeCon Brooke Deneen: LinkedIn Profile
Enjoyed this episode? Leave us a review and share it with your network! Subscribe for more insightful discussions on information security and privacy.
Contact Information:Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:[RSS Feed] [iTunes] [LinkedIn][YouTube]
Sign up with your email address to receive news and updates.
We respect your privacy.
In this episode of Exploring Information Security, host Timothy De Block speaks with Corey Overstreet, a seasoned pentester from Red Siege. Corey shares insights into the ongoing cat-and-mouse game between red teams and blue teams, revealing common vulnerabilities and unexpected successes in breaching defenses. He discusses his upcoming talk at Show Me Con, titled "That Shouldn't Have Worked," which aims to equip blue teams with practical knowledge on bolstering their defenses against persistent attackers. From the nuances of payload delivery to the surprising resilience of old tricks and the challenges of cloud security, Corey offers a candid look at the daily realities of offensive security and how defenders can truly make a red teamer's life difficult.
What You'll Learn:
The core focus of Corey Overstreet's "That Shouldn't Have Worked" talk at Show Me Con.
Common mistakes red teamers make and how to avoid them.
Effective defensive strategies for blue teams, including the power of application control and network segmentation.
The evolving landscape of EDR and how AI is starting to make red team operations more challenging.
Insights into the surprising ways macros and social engineering continue to be effective entry points, especially in cloud environments.
Advice for aspiring pentesters on learning and problem-solving, emphasizing hands-on practice and diligent note-taking.
Corey's favorite resources for staying up-to-date in cybersecurity, including various subreddits, Discord, and Slack communities.
Use the promo code “ExploringSec” to get $50 off your registration
Showmecon Links and Resources:Learn more about ShowMeCon: showmecon.com
Register for Training or the Conference: Registration Link
Event Venue and Room Block Information: Ameristar Casino & Resort
Connect with the Founder of ShowMeCon Dave Chronister: LinkedIn Profile
Connect with the Head Organizer for ShowMeCon Brooke Deneen: LinkedIn Profile
Enjoyed this episode? Leave us a review and share it with your network! Subscribe for more insightful discussions on information security and privacy.
Contact Information:Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:[RSS Feed] [iTunes] [LinkedIn][YouTube]
Sign up with your email address to receive news and updates.
We respect your privacy.
From the publisher's feed

373 Listeners

1,029 Listeners

8,059 Listeners