738 épisodes
- Hey friends! Today is a tale of pentest pwnage episode, and this one features a path to escalation I have never seen before – one I could only find few references on the entire Internet. It happened completely by accident, but during the report readout I'm absolutely going to say it was intentional and that I totally meant to do that.
Here's what we cover:
A client that's actually doing the things – year two or three of testing this environment, and they had buttoned up so much that I had to dig deep. Great for them, freaking frustrating for me.
Why my Kerberoasting success rate has fallen off a cliff – Microsoft pushed an encryption change earlier this year, and cracking those hashes is a whole different ballgame now.
Selective poisoning vs. poison-all-the-things – a nod to Pretender, which I covered in a TuesdayTOOLSday video over at 7MinSec.club. It doesn't get nearly enough love in blogs and videos.
The relay that fired… and did something completely different than I expected – I saw the ntlmrelayx log scroll by, thought "yes, I've got DA," and then had a "wait, wait, whoa, what?" moment. I was honestly a little panicked.
An ancient Exchange vulnerability comes back to bite – CVE-2021-34470 (vulnerable Exchange schema) turned out to be the fallback that got me a foothold I had no business having.
My favorite evil privesc trick, revisited – queuing up a scheduled task that runs under an interactively logged-in DA's context without ever knowing their password. The MDR alerts that come out of this are equal parts hilarious and terrifying.
A bonus thing to always look for – scheduled tasks running under saved DA creds that point at a script you can edit. Add one little line to fire an evil command of your choice, and you're in like a dirty shirt.
Check us out at 7MinSec.com for pentesting, training, controls assessments and security miscellany, 7MinSec.club for our Substack and weekly TuesdayTOOLSday videos, and 7MinSec.wiki for tips, cheat sheets and scripts (including pages on the scheduled task shenanigans above). - Hey friends! Today I'm talking about Baby's First Neo — and to be crystal clear, I don't mean Keanu, and I don't mean the R&B guy with the hat. I mean the AI-powered pentest assistant from our pals at ProjectDiscovery. Also to be crystal clear: this is not a sponsorship, ad, partnership or anything of the sort. Just me sharing a thing I like so you can decide if you like it too.
Here's what we get into:
Why I didn't renew my ProjectDiscovery cloud subscription after a full year of running it side-by-side with Nessus — including the three things that ground my gears (one of which had me angry like the Hulk inside)
The Palo Alto finding that made me plunk down a credit card and buy PD in the first place
What happened when I actually told their team why I was canceling — and the surprise offer that followed
How I set up my first Neo project, and the multi-paragraph prompt I fed it (spoiler: "please don't go rogue" was in there)
Where Neo beat my manual process — and the two subdomains it found that I flat-out missed
The OSINT recommendation Neo made about a job posting that I thought was genuinely smart
My one big hesitation about the credit-based pricing model, and why a part two of this series is probably coming soon
Then we close out with the tangent portion of the program: Grandma 7MS might be my neighbor soon, she bought a vehicle roughly the size of a small nation, and I'm asking for some good vibes on her house hunt. Also, thank you again to everybody who has sent kind messages since my dad passed — it means more than you know. - Hello friends! Today's tale of pentest pwnage isn't a start-to-finish march to DA – it's me finally emptying out the backlog of "gosh, I've got to share this next time" internal network tips that have been rattling around in my head. Here's what we get into:
Don't skip the boring stuff. Even when I'm testing the same network for the third or fourth time, I've got an ever-growing list of things I check every single time – because config drift has a nasty habit of quietly reintroducing problems that were fixed years ago.
Get a second opinion on your tools. Lately I've had BloodHound tell me a network is squeaky clean, and then gone and checked manually only to find the exact opposite sprawled all over the place. I don't know how to account for it, but it's changed how I work. (If you know the source of truth here, please write in!)
Ghost machines. That innocent little checkbox in Active Directory that turns a computer object into a gift-wrapped present for an attacker. We keep finding these in environments that had zero of them last year – and I share the two-pass trick that shakes even more of them loose.
The weekend freebie. Why I like to get my box lit up on a Friday even when the test doesn't officially start until Monday, and what tends to come wandering into my capture over 48 quiet hours.
SNMP sweeps. I've never been caught doing one, and yet they'll happily hand over the make, model and firmware of some firewalls, switches and storage systems in the building. I think this finding deserves way more attention than it gets. (There are a few little commandlets waiting for you over at 7MinSec.wiki.)
Be a consultant, not a Terminator 1000. Why I run certain checks even when I'm 99% sure I'll find nothing, why "you don't have this thing at all" belongs in the accolades section, and how that one habit has led to some of the most appreciated conversations we've had in report delivery meetings.
Tangent department: the dumb-but-glorious AI project that gave me the giggidies – a fully automated lobby bot for a Steam game that is absolutely, positively not for the kiddos. Also: the one line I won't cross with it, no matter how much my buddy eggs me on.
Got a tip of your own I should be adding to the "always check this" list? I'd love to hear it!
7MinSec.com for security services and show notes | 7MinSec.club for our Substack and weekly TuesdayTOOLSdays | 7MinSec.wiki for pentesting tips, scripts and cheat sheets - Hey friends! Today's another slice of our Securing Your Family During and After a Disaster miniseries, and fair warning — it's a bit of a Friday mood-ruiner. It's been almost two months since my dad passed, and we've moved into a phase nobody prepared me for. Here's what we get into:
The paperwork nobody thinks about — my mom still doesn't know what her monthly income looks like now, and the answer is buried in a box somebody lost the key to.
Divvying up a lifetime of stuff — and why our 2019 house fire completely rewired how I think about possessions.
Dumpster weekend — my wife makes keep-or-toss calls like a Terminator. Also: my dad owned 60 rakes, and a spirited family debate about the resale value of bee spray.
Sell it or pitch it? — why we mostly gave up on Facebook Marketplace mid-cleanout, and my one non-negotiable rule for meeting strangers to hand off your stuff.
The conversation I wish we'd had five years ago — it's short, it's simple, and it's absolutely brutal to bring up with your parents. Do it anyway.
My hope is this nudges you to have some of these talks now, while everybody's healthy and nobody's crying in a garage. Been through it yourself? I'd love to hear what you'd do differently.
And if this is your first time here — we normally talk pentesting, blue teaming, certs and security careers over at 7MinSec.com. Come hang out at 7MinSec.club, our free Substack where TuesdayTOOLSday is getting back to fundamentals, and check out 7MinSec.wiki, where every article is getting paired up with a video.
Have a great week,
Brian - Hey friends! Today's episode has a new-to-me toy up front and some podcast housekeeping on the back half – all recorded with a raging case of the anxious parent giggidies, because my son Atticus had a big audition and I was minutes away from finding out whether we were doing tears of joy or tears of sadness.
Baby's first Cloudflare Tunnel
Not a sponsor, not an ad – just a thing I'd heard about for years and finally had a reason to use. Here's what we get into:
The problem that sent me down this road: I wanted push-button status pages for clients that pull from one source of truth – not just "is the box up," but actual narrative on where a project is at
Why the off-the-shelf status page tools weren't the right shape, and why "just stick it on a web server" was a non-starter for a scraper-and-AI-slop-crawler internet
The auth paths I tried and abandoned before Cloudflare Tunnels entered the chat
How Cloudflare Access one-time PINs put a guard out front – and what happens when fartface@meowmix.com tries to log in
My Chick-fil-A-order-tracker dreams for multi-phase assessments, and why I think it could kill a bunch of clogged-up email threads
Why the code isn't public yet (it's public-facing infrastructure I haven't hardened, and I've got hunches about where the holes are) – but reach out if you want to build something similar and I'm happy to share privately
Where tunnels fit generally: when something genuinely needs to be reachable, but you'd rather not hand it a public IP or expose RDP to the whole internet. It doesn't replace Twingate for me, but it fills a different slot nicely
Bonus tangent: why Claude has become my long-drive road companion, and five enlightening minutes I spent learning how water towers work
Housekeeping: a refreshed jingle and a brand new bumper
A quick history of the 7MS jingle – from just me and an acoustic guitar, to a Fiverr band, to now
Why "security is hard, so let's assume we're probably going to get pwned by noon" has aged frighteningly well (see also: AI agents teaching each other to find previously unknown vulns)
Meet Jacob Davis, the guitar teacher the algorithm dropped in my lap, who recorded a gorgeous all-strings arrangement of the jingle and about 45 seconds of fingerpicking diddly goodness for our new outro bumper. Stick around to the end and give it a listen – and if you're in the market for internet guitar lessons, he rules
And over on 7MinSec.club this week
I show off VoiceInk, a private, local voice dictation utility for Mac that Paul the Unstoppable turned me on to. Lifetime license, no subscription, and it does a great job on live dictation or audio files you feed it. Catch the TuesdayTOOLSday over at 7MinSec.club
Thanks for listening – to the security stuff, the tangents, or both. Come find us at 7MinSec.com, subscribe (free or paid) over at 7MinSec.club, and dig through our notes at 7MinSec.wiki. God bless you, and have a great week!
Plus de podcasts Actualités
Podcasts tendance de Actualités
À propos de 7 Minute Security
7 Minute Security is a weekly information security podcast focusing on penetration testing, blue teaming and building a career in security. The podcast also features in-depth interviews with industry leaders who share their insights, tools, tips and tricks for being a successful security engineer.
Site web du podcastÉcoutez 7 Minute Security, L'Heure du Monde ou d'autres podcasts du monde entier - avec l'app de radio.fr

Obtenez l’app radio.fr gratuite
- Ajout de radios et podcasts en favoris
- Diffusion via Wi-Fi ou Bluetooth
- Carplay & Android Auto compatibles
- Et encore plus de fonctionnalités
Obtenez l’app radio.fr gratuite
- Ajout de radios et podcasts en favoris
- Diffusion via Wi-Fi ou Bluetooth
- Carplay & Android Auto compatibles
- Et encore plus de fonctionnalités


7 Minute Security
Scannez le code,
Téléchargez l’app,
Écoutez.
Téléchargez l’app,
Écoutez.
7 Minute Security: Podcasts du groupe



































