7 Minute Security

Brian Johnson

7 Minute Security is a weekly information security podcast focusing on penetration testing, blue teaming and building a career in security. The podcast also features in-depth interviews with industry leaders who share their insights, tools, tips and tricks for being a successful security engineer.

  1. 23 hr ago

    7MS #740: Tales of Pentest Pwnage - Part 90

    Hey friends! We've been on a bit of a Tales of Pentest Pwnage bender lately, so let's keep it rolling with Part 90. (And Mom, relax — this is not one pentest story chopped into 90 parts.) Today is less of an A-to-Z story and more a pile of tips and tricks pulled from a recent string of SCCM-flavored internals — plus a tangent about a video game and a little robot Claude and I built to get my life back. Multi-tier SCCM is having a moment — I've never administered SCCM a day in my life, but 2026 keeps dropping me into these split-role environments. Here's where I go to figure out my attack surface when all I've got is a low-priv cred. SMB signing on? Cool, I'll go around it — relaying from one SCCM box to the one with SQL on it, and the easy-button tool that vacuums the good stuff out of the database once you're there. (NAA creds, clear-text local admin passwords, install scripts with creds baked in…yes please.) Then relay the other direction — when the loot came back stale, a nudge from a Slack channel had me pointing the relay backwards, and I giggled like a little schoolboy at what popped out. Adding yourself to the local admin group: still weirdly undetected — an old episode of ours reminded me of an Impacket tool I don't see written up on many pentest blogs, and it slipped right by. My favorite cheat code hit a snag — the evil-scheduled-task-under-a-logged-in-DA trick kept coughing up permission errors, so I had to get creative. Plus the defensive recs I'm still trying to sharpen up — if you've got a better way to close this loophole, I'm all ears! Tangent: Halloween (the video game) and the lobby watcher — a million players and I'm still staring into the lobby abyss for 10 minutes at a time. So Claude and I built something that watches the screen and texts me when it's time to sprint back to the keyboard. It's not cheating. It's not! (The Texas Chainsaw crowd disagreed, loudly.)

  2. 11 Sept

    7MS #739: Tales of Pentest Pwnage – Part 89

    Hey friends! Today is a tale of pentest pwnage episode, and this one features a path to escalation I have never seen before – one I could only find few references on the entire Internet. It happened completely by accident, but during the report readout I'm absolutely going to say it was intentional and that I totally meant to do that. Here's what we cover: A client that's actually doing the things – year two or three of testing this environment, and they had buttoned up so much that I had to dig deep. Great for them, freaking frustrating for me. Why my Kerberoasting success rate has fallen off a cliff – Microsoft pushed an encryption change earlier this year, and cracking those hashes is a whole different ballgame now. Selective poisoning vs. poison-all-the-things – a nod to Pretender, which I covered in a TuesdayTOOLSday video over at 7MinSec.club. It doesn't get nearly enough love in blogs and videos. The relay that fired… and did something completely different than I expected – I saw the ntlmrelayx log scroll by, thought "yes, I've got DA," and then had a "wait, wait, whoa, what?" moment. I was honestly a little panicked. An ancient Exchange vulnerability comes back to bite – CVE-2021-34470 (vulnerable Exchange schema) turned out to be the fallback that got me a foothold I had no business having. My favorite evil privesc trick, revisited – queuing up a scheduled task that runs under an interactively logged-in DA's context without ever knowing their password. The MDR alerts that come out of this are equal parts hilarious and terrifying. A bonus thing to always look for – scheduled tasks running under saved DA creds that point at a script you can edit. Add one little line to fire an evil command of your choice, and you're in like a dirty shirt. Check us out at 7MinSec.com for pentesting, training, controls assessments and security miscellany, 7MinSec.club for our Substack and weekly TuesdayTOOLSday videos, and 7MinSec.wiki for tips, cheat sheets and scripts (including pages on the scheduled task shenanigans above).

  3. 4 Sept

    7MS #738: Baby's First ProjectDiscovery Neo

    Hey friends! Today I'm talking about Baby's First Neo — and to be crystal clear, I don't mean Keanu, and I don't mean the R&B guy with the hat. I mean the AI-powered pentest assistant from our pals at ProjectDiscovery. Also to be crystal clear: this is not a sponsorship, ad, partnership or anything of the sort. Just me sharing a thing I like so you can decide if you like it too. Here's what we get into: Why I didn't renew my ProjectDiscovery cloud subscription after a full year of running it side-by-side with Nessus — including the three things that ground my gears (one of which had me angry like the Hulk inside) The Palo Alto finding that made me plunk down a credit card and buy PD in the first place What happened when I actually told their team why I was canceling — and the surprise offer that followed How I set up my first Neo project, and the multi-paragraph prompt I fed it (spoiler: "please don't go rogue" was in there) Where Neo beat my manual process — and the two subdomains it found that I flat-out missed The OSINT recommendation Neo made about a job posting that I thought was genuinely smart My one big hesitation about the credit-based pricing model, and why a part two of this series is probably coming soon Then we close out with the tangent portion of the program: Grandma 7MS might be my neighbor soon, she bought a vehicle roughly the size of a small nation, and I'm asking for some good vibes on her house hunt. Also, thank you again to everybody who has sent kind messages since my dad passed — it means more than you know.

  4. 28 Aug

    7MS #737: Tales of Pentest Pwnage – Part 88

    Hello friends! Today's tale of pentest pwnage isn't a start-to-finish march to DA – it's me finally emptying out the backlog of "gosh, I've got to share this next time" internal network tips that have been rattling around in my head. Here's what we get into: Don't skip the boring stuff. Even when I'm testing the same network for the third or fourth time, I've got an ever-growing list of things I check every single time – because config drift has a nasty habit of quietly reintroducing problems that were fixed years ago. Get a second opinion on your tools. Lately I've had BloodHound tell me a network is squeaky clean, and then gone and checked manually only to find the exact opposite sprawled all over the place. I don't know how to account for it, but it's changed how I work. (If you know the source of truth here, please write in!) Ghost machines. That innocent little checkbox in Active Directory that turns a computer object into a gift-wrapped present for an attacker. We keep finding these in environments that had zero of them last year – and I share the two-pass trick that shakes even more of them loose. The weekend freebie. Why I like to get my box lit up on a Friday even when the test doesn't officially start until Monday, and what tends to come wandering into my capture over 48 quiet hours. SNMP sweeps. I've never been caught doing one, and yet they'll happily hand over the make, model and firmware of some firewalls, switches and storage systems in the building. I think this finding deserves way more attention than it gets. (There are a few little commandlets waiting for you over at 7MinSec.wiki.) Be a consultant, not a Terminator 1000. Why I run certain checks even when I'm 99% sure I'll find nothing, why "you don't have this thing at all" belongs in the accolades section, and how that one habit has led to some of the most appreciated conversations we've had in report delivery meetings. Tangent department: the dumb-but-glorious AI project that gave me the giggidies – a fully automated lobby bot for a Steam game that is absolutely, positively not for the kiddos. Also: the one line I won't cross with it, no matter how much my buddy eggs me on. Got a tip of your own I should be adding to the "always check this" list? I'd love to hear it! 7MinSec.com for security services and show notes | 7MinSec.club for our Substack and weekly TuesdayTOOLSdays | 7MinSec.wiki for pentesting tips, scripts and cheat sheets

  5. 21 Aug

    7MS #736: Securing Your Family During and After a Disaster – Part 9

    Hey friends! Today's another slice of our Securing Your Family During and After a Disaster miniseries, and fair warning — it's a bit of a Friday mood-ruiner. It's been almost two months since my dad passed, and we've moved into a phase nobody prepared me for. Here's what we get into: The paperwork nobody thinks about — my mom still doesn't know what her monthly income looks like now, and the answer is buried in a box somebody lost the key to. Divvying up a lifetime of stuff — and why our 2019 house fire completely rewired how I think about possessions. Dumpster weekend — my wife makes keep-or-toss calls like a Terminator. Also: my dad owned 60 rakes, and a spirited family debate about the resale value of bee spray. Sell it or pitch it? — why we mostly gave up on Facebook Marketplace mid-cleanout, and my one non-negotiable rule for meeting strangers to hand off your stuff. The conversation I wish we'd had five years ago — it's short, it's simple, and it's absolutely brutal to bring up with your parents. Do it anyway. My hope is this nudges you to have some of these talks now, while everybody's healthy and nobody's crying in a garage. Been through it yourself? I'd love to hear what you'd do differently. And if this is your first time here — we normally talk pentesting, blue teaming, certs and security careers over at 7MinSec.com. Come hang out at 7MinSec.club, our free Substack where TuesdayTOOLSday is getting back to fundamentals, and check out 7MinSec.wiki, where every article is getting paired up with a video. Have a great week, Brian

  6. 14 Aug

    7MS #735: Baby's First Cloudflare Tunnel

    Hey friends! Today's episode has a new-to-me toy up front and some podcast housekeeping on the back half – all recorded with a raging case of the anxious parent giggidies, because my son Atticus had a big audition and I was minutes away from finding out whether we were doing tears of joy or tears of sadness. Baby's first Cloudflare Tunnel Not a sponsor, not an ad – just a thing I'd heard about for years and finally had a reason to use. Here's what we get into: The problem that sent me down this road: I wanted push-button status pages for clients that pull from one source of truth – not just "is the box up," but actual narrative on where a project is at Why the off-the-shelf status page tools weren't the right shape, and why "just stick it on a web server" was a non-starter for a scraper-and-AI-slop-crawler internet The auth paths I tried and abandoned before Cloudflare Tunnels entered the chat How Cloudflare Access one-time PINs put a guard out front – and what happens when fartface@meowmix.com tries to log in My Chick-fil-A-order-tracker dreams for multi-phase assessments, and why I think it could kill a bunch of clogged-up email threads Why the code isn't public yet (it's public-facing infrastructure I haven't hardened, and I've got hunches about where the holes are) – but reach out if you want to build something similar and I'm happy to share privately Where tunnels fit generally: when something genuinely needs to be reachable, but you'd rather not hand it a public IP or expose RDP to the whole internet. It doesn't replace Twingate for me, but it fills a different slot nicely Bonus tangent: why Claude has become my long-drive road companion, and five enlightening minutes I spent learning how water towers work Housekeeping: a refreshed jingle and a brand new bumper A quick history of the 7MS jingle – from just me and an acoustic guitar, to a Fiverr band, to now Why "security is hard, so let's assume we're probably going to get pwned by noon" has aged frighteningly well (see also: AI agents teaching each other to find previously unknown vulns) Meet Jacob Davis, the guitar teacher the algorithm dropped in my lap, who recorded a gorgeous all-strings arrangement of the jingle and about 45 seconds of fingerpicking diddly goodness for our new outro bumper. Stick around to the end and give it a listen – and if you're in the market for internet guitar lessons, he rules And over on 7MinSec.club this week I show off VoiceInk, a private, local voice dictation utility for Mac that Paul the Unstoppable turned me on to. Lifetime license, no subscription, and it does a great job on live dictation or audio files you feed it. Catch the TuesdayTOOLSday over at 7MinSec.club Thanks for listening – to the security stuff, the tangents, or both. Come find us at 7MinSec.com, subscribe (free or paid) over at 7MinSec.club, and dig through our notes at 7MinSec.wiki. God bless you, and have a great week!

  7. 7 Aug

    7MS #734: Insight Recon

    Hey friends! Today's episode is a two-parter: some security stuff up front, and then a big ol' personal celebration on the back half. If you're strictly here for the security bits, I love you and you're free to bail after the first half. If you're here for both, God bless you. Part 1: Kicking the tires on Insight Recon What it is: Insight Recon is an Active Directory security assessment tool out of Heath Adams' new venture, Breach Point. I signed up for early access a while back, finally got a login, and took it for a spin this week in my GOAD lab. Not a sponsor, not an ad — just a tool I was curious about. Watch it in action: I covered the install, a couple of hiccups I hit, and some of the report output in this week's TuesdayTOOLSday video over at 7MinSec.club. The setup: Log into the portal, grab the installer, run it on a domain-joined box, then pick whether you want to scan as your current user or specify creds. Say go, wait a few minutes, and your report card shows up on the dashboard. My two nitpicks (and they're mine, not necessarily yours): The download does a full-blown install with an install footprint, and the raw scan data gets shipped back up to Insight Recon so you can view your report. I can't help but compare everything in this space to PingCastle, where you unzip, run the EXE, and your HTML report is sitting right there on the C drive — nothing leaves the building. As someone who tries to be a good data janitor and nuke assessment data after reports go out, cloud storage is just one more place I've got to remember to go scrub. What I really liked: The remediation guidance is legit. I clicked into a few of the critical findings — some ESC/ADCS stuff especially — and it walked me through exactly what to change, why an attacker cares, how to verify the fix afterward, and where to go read more. There's also a "quick wins" view that pares the big list down to the biggest security impact for the least effort. The dashboard and the slide-out detail panes are genuinely pleasant to use. Why this matters even for offense-only folks: We're mostly on the offensive side with a little blue team consulting — we don't do hands-to-keyboard remediation. But I think you become a better pentester when you can speak confidently at delivery time about not just what to fix, but the gotchas that might bite them along the way. Pricing: On the podcast I guessed "a few thousand a year" and admitted that number may have come straight out of my bum cheeks. Turns out I wasn't too far off — there's a free tier to start, and paid runs $3,000/year with founder pricing at $1,500/year locked in for the first 25 customers. See the pricing page for the current details. Verdict so far: A promising first dance. I want to give it a proper workout — run it side by side with PingCastle on a couple of real assessments and see if either one has blind spots the other covers. More on that in a future episode. Part 2: Why I've got the giggidies My son Cam graduated paramedic school! As of tonight he has everything signed off to go take the gargantuan national test. I'm not going to pretend I got through recording this without getting a little watery-eyed. The journey: Senior year of high school, nothing career-wise floated his boat — there were subjects he tolerated and subjects he hated, and that was about it. Then a conversation with a family friend who's a paramedic lit a fire in his belly, and he's been running at it ever since: EMT coursework in high school, then straight into the paramedic program. How he did it: He wrestles with ADHD, so he had to figure out how to hack his own brain to get through a mountain of material. Come home from five or six hours of class, eat dinner, then hit the books again and re-take his own notes. Then he'd sit down with my wife or me and do an Ace Ventura-style verbal dump of everything he'd learned that day — and any time he caught himself glitching on something, he'd write it down, keep going, then go back and shore it up. Every single night. The Mr. Miyagi moment: My wife has been a nurse for 20+ years, and about six months ago she had to tell him she couldn't help anymore because he'd surpassed her in certain areas of healthcare. Yes, AI made a cameo: The night before his final scenario testing, he and I sat down and had Claude generate random practice scenarios so I could prompt him and just watch him talk for two minutes straight about airway management, medication dosing, all of it. The cliffhanger: Four-ish hours of individual scenario testing, an hour-and-a-half drive to the ceremony, and no word either way on if he passed his tests. I hit the front door of the building not knowing whether I was walking into smiles or tears — and right as my hand hit the door handle, a text came in with a giant happy face: I passed. Somebody must have been cutting onions in that parking lot. His people: Cam's the youngest of the bunch — most of his classmates had been working EMTs for years — and from day one they told him "we got you, we'll get through this together." For the group photo on the steps afterward, one of them tried to pick him up solo and just about threw her back out, so it took three of them. That's the little family he's got, and I hope they stay close, because they've all got that beast of a test coming next month. The hard part: If you've listened to the last few episodes, you know my dad passed away at the end of June, and that Cam was the one who found him and sprung into paramedic mode. My dad was a cop and a pilot who had enormous respect for paramedics, EMTs, and nurses, and he was one of Cam's biggest cheerleaders. Whenever I did something my dad was proud of, he'd say, "I'm busting my buttons over here!" That's exactly what he'd have said tonight, and not having him here to say it is a karate kick to the heart. But I'll tell you what — I'm busting my buttons about Cam for the both of us. Thank you: So many of you have reached out with condolences and shared stories of your own losses these past weeks. I'm sorry for every one of them, and I appreciate you more than I can say. Thanks for listening — to the security stuff, the tangents, or both. Come find us at 7MinSec.com, and/or subscribe (free or paid) over at 7MinSec.club, and dig through the our notes at 7MinSec.wiki.

  8. 31 Jul

    7MS #733: Tales of Pentest Pwnage – Part 87

    Hey friends! Today's episode comes to you from a parking lot in the rain, with a mint hot cocoa in hand and your host absolutely dragging his butt (D-R-A-G-G-I-N-G, not D-R-A-G-O-N – I've never seen a dragon's butt and can't speak to how mine compares). I've had a bunch of internals back to back lately and I'm basically a drooling dog who found a frisbee and refuses to put it down. Sleep be darned. So instead of walking through one test start to finish, I want to share a few things that have helped me claw out a foothold in environments that are otherwise really locked down: The "good problem" of a mature client – several of these engagements are third- or fourth-year tests, and the clients actually clear findings off the board. Which is great for them and rough for me, because this year's test shouldn't look anything like last year's. All my favorite go-tos came up empty – machine account quota set to zero, no broadcast traffic tomfoolery (Responder and mitm6 got me nothing), SMB signing on everywhere, ADCS either absent or buttoned up, and a low-priv account that BloodHound says has zero interesting permissions and zero local admin anywhere. Cool cool cool. When the network's clean, go file-hunting – which means firing up Snaffler and letting it comb the shares. Normally that wraps up in about an hour. On these engagements it was running three and four hours. Then Windows told me I was out of disk – I like having Snaffler pull down copies of interesting files so I can review them locally instead of authenticating to each share. Turns out it had grabbed 50-60 gigs and left me with about eight gigs of breathing room. Tip #1: put a 1 TB drive in your drop boxes – I ran with tiny drives for years early in the 7MS days and it was always a pinch. Beyond situations like this one, sometimes you find a giant backup file or VMDK on a share and you need somewhere to put it so you can crack it open and go shopping. Tip #2: you can grow a VM disk on the fly – in Proxmox you can resize the disk on a running VM, then hop into Disk Management inside Windows and extend the C drive. Instant elbow room, no downtime. Death by a million tiny files – the real culprit was one file extension I should have excluded, and the client had hundreds of thousands of them. Rather than restart a run I was already hours into, I had AI whip up a little PowerShell loop that swept the Snaffler dump folder every 10 minutes and deleted the extensions I didn't care about. Woke up the next morning to a finished run and plenty of free space. Making a gig-sized log file readable – I fed the log into Chimas, a slick web interface for Snaffler output that lets you filter down to just the red stuff or just the likely-credential files, and sort by modified date. Watch those timestamps – I kept finding AD creds in documents, then comparing the doc's date against the account's last password reset in BloodHound and discovering the file was a year stale. Son of a biscuit. The tool that actually cracked it open: Copernic Desktop Search – my pal Jeff McJunkin recommended this to me years ago, I talked about it on the show once, and then inexplicably forgot about it. Not a sponsor, no kickbacks, just a paid tool that's earned its keep. It's basically Google for your hard drive. How I use it – install it on the Windows VM, clear out the default indexing scope entirely, and point it only at the Snaffler dump folder. The top tier (about a hundred bucks a year) will chew through PSTs, DWGs, Office docs, PDFs and more, and it OCRs images too. Indexing took the better part of a day on these engagements, but then search is instant, and it previews basically every file type without Office installed.  Years ago this same tool surfaced a photo on a file share of a piece of printer paper where a sysadmin had handwritten a 40-character admin password in Bic pen. OCR for the win. What I search for – the obvious stuff like "password," plus the domain name, "plain text," and things like "=sa" to sniff out SQL admin creds. Nuggets and threads to pull – sometimes a hit is the gold. Other times it just tells you where to go dumpster-diving like a raccoon on the live share. That's how I found upgrade project plans with multiple teams and contractors involved, half-cleaned-up temp work, and high-privilege system, database and local admin creds just sitting there. Worth the hours – these didn't all end in domain admin, but they were rich, real findings, and a great teaching opportunity about what's sitting wide open to Domain Users. (Bonus: Copernic can also point straight at a UNC path with your AD creds and index it live.) Know a free alternative? – one of my favorite parts of doing this podcast is when someone writes in with "hey, there's an open source thing that does that." If that's you, I'd love to hear it! Also, on this week's TuesdayTOOLSday I walked through getting a self-hosted Bitwarden password vault (and file sender) up and running on Linux, and there's now a cheat sheet over at 7MinSec.wiki that'll get you there in about seven minutes – all the commands from the official install guide in one place, with a couple of gotchas flagged. Last thing: subscriptions to 7MinSec.club are free, but paid subs help cover hosting and the time this takes each week, and they're getting some exclusive content soon. No guilt trip here, Mom – I'm going to keep barfing up everything I learn either way. But if you've got the means, I'd sure appreciate it.

About

7 Minute Security is a weekly information security podcast focusing on penetration testing, blue teaming and building a career in security. The podcast also features in-depth interviews with industry leaders who share their insights, tools, tips and tricks for being a successful security engineer.

You Might Also Like